murphypaul1979
2008-08-07, 17:49
ComboFix 08-08-06.04 - r 2008-08-07 19:57:23.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.578 [GMT 5.5:30]
Running from: C:\Documents and Settings\r\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\Downloaded Program Files\ODCTOOLS
C:\WINDOWS\system32\AutoRun.inf
C:\WINDOWS\system32\bkhwpygq.ini
C:\WINDOWS\system32\Cache
C:\WINDOWS\system32\ebychyuo.ini
C:\WINDOWS\system32\GMlRCJlm.ini
C:\WINDOWS\system32\GMlRCJlm.ini2
C:\WINDOWS\system32\mdm.exe
C:\WINDOWS\system32\prsgrc.dll
C:\WINDOWS\system32\sawkalmy.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IPRIP
-------\Service_Iprip
((((((((((((((((((((((((( Files Created from 2008-07-07 to 2008-08-07 )))))))))))))))))))))))))))))))
.
2008-08-07 17:09 . 2008-08-07 17:10 <DIR> d-------- C:\Program Files\AVI MPEG WMV RM to MP3 Converter
2008-08-07 04:32 . 2008-08-07 17:27 <DIR> d-------- C:\Program Files\OCR-TextScan 2 Word 1
2008-08-07 04:32 . 2008-08-07 04:32 72,192 --a------ C:\WINDOWS\cadkasdeinst01e.exe
2008-08-06 22:18 . 2008-08-06 22:18 184 --a------ C:\WINDOWS\Readiris.ini
2008-08-06 21:02 . 2008-08-06 23:17 <DIR> d-------- C:\Program Files\Readiris Pro 11 Corporate Edition Demo
2008-08-06 18:35 . 2008-08-06 18:35 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-08-06 17:59 . 2008-08-06 17:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\HP Product Assistant
2008-08-06 17:58 . 2008-08-06 17:58 <DIR> d-------- C:\Program Files\Hewlett-Packard
2008-08-06 17:49 . 2008-08-06 18:03 141,147 --a------ C:\WINDOWS\hpoins14.dat
2008-08-06 17:48 . 2007-09-20 06:44 2,000 --------- C:\WINDOWS\hpomdl14.dat
2008-08-06 01:09 . 2008-08-06 01:09 <DIR> d-------- C:\WINDOWS\IIS Temporary Compressed Files
2008-08-06 01:07 . 2006-02-28 17:30 2,178,131 --a--c--- C:\WINDOWS\system32\dllcache\shvlres.dll
2008-08-06 01:06 . 2006-02-28 17:30 562,176 --a------ C:\WINDOWS\system32\fxsst.dll
2008-08-06 01:02 . 2008-08-06 01:08 <DIR> d-------- C:\WINDOWS\system32\msmq
2008-08-06 01:02 . 2008-08-06 01:13 <DIR> d-------- C:\Inetpub
2008-08-05 10:25 . 2008-08-05 10:46 <DIR> d-------- C:\AllokRMFolder
2008-08-05 10:24 . 2008-08-05 10:25 <DIR> d-------- C:\Program Files\Allok RM RMVB to AVI MPEG DVD Converter
2008-08-03 20:17 . 2008-08-03 20:17 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-03 19:30 . 2008-08-03 19:42 1,934 --a------ C:\WINDOWS\system32\tmp.reg
2008-08-03 19:27 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-08-03 19:27 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-08-03 19:27 . 2008-05-29 09:35 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-08-03 19:27 . 2008-07-02 13:33 82,432 --a------ C:\WINDOWS\system32\IEDFix.C.exe
2008-08-03 19:27 . 2008-05-23 18:21 81,920 --a------ C:\WINDOWS\system32\404Fix.exe
2008-08-03 19:27 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-08-03 19:27 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-08-03 19:27 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-08-03 18:44 . 2008-08-06 04:19 <DIR> d--h----- C:\$AVG8.VAULT$
2008-08-02 20:41 . 2008-08-02 20:41 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-08-02 20:41 . 2008-08-02 20:41 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-08-02 20:40 . 2008-08-07 16:46 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-08-02 20:40 . 2008-08-02 20:40 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-08-02 19:52 . 2006-03-23 09:42 139,264 -ra------ C:\WINDOWS\system32\igfxres.dll
2008-08-02 19:49 . 2008-08-02 19:49 <DIR> d-------- C:\WINDOWS\ASUSInstAll
2008-08-02 19:44 . 2008-08-02 19:44 12,889 --a------ C:\WINDOWS\Ascd_tmp.ini
2008-08-02 19:31 . 2006-02-28 17:30 28,288 --a--c--- C:\WINDOWS\system32\dllcache\xjis.nls
2008-08-02 19:29 . 2006-02-28 17:30 1,875,968 --a--c--- C:\WINDOWS\system32\dllcache\msir3jp.lex
2008-08-02 19:28 . 2006-02-28 17:30 13,463,552 --a--c--- C:\WINDOWS\system32\dllcache\hwxjpn.dll
2008-08-02 19:27 . 2006-02-28 17:30 1,677,824 --a--c--- C:\WINDOWS\system32\dllcache\chsbrkr.dll
2008-08-02 19:23 . 2008-08-02 19:23 749 -rah----- C:\WINDOWS\WindowsShell.Manifest
2008-08-02 19:23 . 2008-08-02 19:23 749 -rah----- C:\WINDOWS\system32\wuaucpl.cpl.manifest
2008-08-02 19:23 . 2008-08-02 19:23 749 -rah----- C:\WINDOWS\system32\sapi.cpl.manifest
2008-08-02 19:23 . 2008-08-02 19:23 749 -rah----- C:\WINDOWS\system32\nwc.cpl.manifest
2008-08-02 19:23 . 2008-08-02 19:23 749 -rah----- C:\WINDOWS\system32\ncpa.cpl.manifest
2008-08-02 19:23 . 2008-08-02 19:23 488 -rah----- C:\WINDOWS\system32\logonui.exe.manifest
2008-08-02 19:02 . 2006-02-28 17:30 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2008-08-02 19:02 . 2006-02-28 17:30 24,661 --a--c--- C:\WINDOWS\system32\dllcache\spxcoins.dll
2008-08-02 19:02 . 2006-02-28 17:30 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2008-08-02 19:02 . 2006-02-28 17:30 13,312 --a--c--- C:\WINDOWS\system32\dllcache\irclass.dll
2008-08-02 18:37 . 2008-08-02 19:26 23,392 --a------ C:\WINDOWS\system32\nscompat.tlb
2008-08-02 18:37 . 2008-08-02 19:26 16,832 --a------ C:\WINDOWS\system32\amcompat.tlb
2008-08-02 15:00 . 2008-08-03 19:48 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-08-02 15:00 . 2008-08-04 08:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-28 10:18 . 2007-07-19 18:14 3,727,720 --a------ C:\WINDOWS\system32\d3dx9_35.dll
2008-07-27 23:39 . 2008-07-27 23:39 82,996 --a------ C:\WINDOWS\system32\SpoonUninstall-Jardinains!.bmp
2008-07-27 23:39 . 2008-07-27 23:39 10,960 --a------ C:\WINDOWS\system32\SpoonUninstall-Jardinains!.dat
2008-07-27 23:37 . 2008-07-27 23:37 <DIR> d-------- C:\Program Files\Free RM to MP3 Converter
2008-07-27 20:39 . 2008-07-27 20:39 <DIR> d-------- C:\Program Files\Illustrate
2008-07-27 03:02 . 2008-07-27 03:02 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-07-26 20:18 . 2008-07-26 20:20 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-07-26 10:34 . 2008-07-26 10:34 <DIR> d-------- C:\Program Files\Microsoft WSE
2008-07-26 10:27 . 2007-05-16 16:45 1,124,720 --a------ C:\WINDOWS\system32\D3DCompiler_34.dll
2008-07-26 10:27 . 2007-05-16 16:45 443,752 --a------ C:\WINDOWS\system32\d3dx10_34.dll
2008-07-26 10:26 . 2007-05-16 16:45 3,497,832 --a------ C:\WINDOWS\system32\d3dx9_34.dll
2008-07-26 10:26 . 2006-11-29 13:06 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll
2008-07-26 10:26 . 2006-09-28 16:05 2,414,360 --a------ C:\WINDOWS\system32\d3dx9_31.dll
2008-07-26 10:06 . 2008-07-26 10:06 <DIR> d-------- C:\Program Files\MagicISO
2008-07-25 11:41 . 2006-08-31 10:54 327,680 --a------ C:\WINDOWS\system32\PrmSrvInstall.dll
2008-07-25 11:41 . 1999-06-25 10:55 149,504 --a------ C:\WINDOWS\system32\UNWISE.EXE
2008-07-25 11:41 . 2006-07-14 10:03 65,636 --a------ C:\WINDOWS\system32\PrmSrvUninst.exe
2008-07-25 11:24 . 2008-07-25 11:39 <DIR> d-------- C:\Program Files\Microsoft SQL Server
2008-07-25 11:23 . 2008-07-25 11:23 <DIR> d-------- C:\Program Files\Common Files\Borland Shared
2008-07-22 12:31 . 2008-07-26 17:23 <DIR> d-------- C:\Program Files\Autodesk
2008-07-22 12:31 . 2005-05-26 15:34 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll
2008-07-22 00:42 . 2008-07-28 10:28 <DIR> d-------- C:\Documents and Settings\r\Application Data\Autodesk
2008-07-21 23:48 . 2008-07-28 10:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Autodesk
2008-07-21 14:02 . 2007-04-09 13:23 28,040 --a------ C:\WINDOWS\system32\mdimon.dll
2008-07-21 14:00 . 2008-07-21 14:00 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-07-21 13:58 . 2008-07-21 14:00 <DIR> d--h----- C:\WINDOWS\ShellNew
2008-07-21 13:54 . 2008-07-21 13:54 <DIR> dr-h----- C:\MSOCache
2008-07-15 21:26 . 2008-07-15 21:26 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-07-15 10:58 . 2008-07-15 10:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WEBREG
2008-07-15 10:56 . 2008-08-06 18:01 <DIR> d-------- C:\Documents and Settings\r\Application Data\HPAppData
2008-07-15 10:55 . 2008-07-15 10:55 <DIR> d-------- C:\Program Files\Common Files\HP
2008-07-15 10:55 . 2008-08-06 17:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\HP
2008-07-15 10:54 . 2008-07-15 10:54 <DIR> d-------- C:\Program Files\Common Files\Hewlett-Packard
2008-07-15 10:53 . 2008-07-15 10:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2008-07-15 10:53 . 2007-03-17 21:41 675,840 -ra------ C:\WINDOWS\system32\hpowiax3.dll
2008-07-15 10:53 . 2007-03-17 21:41 569,344 -ra------ C:\WINDOWS\system32\hpotscl3.dll
2008-07-15 10:53 . 2007-03-08 09:50 364,544 -ra------ C:\WINDOWS\system32\hppldcoi.dll
2008-07-15 10:53 . 2007-03-08 09:50 309,760 -ra------ C:\WINDOWS\system32\difxapi.dll
2008-07-15 10:53 . 2007-03-17 21:41 303,104 -ra------ C:\WINDOWS\system32\hpovst10.dll
2008-07-15 10:53 . 2007-03-30 20:37 267,864 -ra------ C:\WINDOWS\system32\hpzids01.dll
2008-07-15 10:53 . 2007-03-28 14:01 117,760 --a------ C:\WINDOWS\system32\hpzll5ha.dll
2008-07-15 10:53 . 2007-03-08 09:50 49,920 -ra------ C:\WINDOWS\system32\drivers\HPZid412.sys
2008-07-15 10:53 . 2007-03-08 09:50 21,568 -ra------ C:\WINDOWS\system32\drivers\HPZius12.sys
2008-07-15 10:53 . 2007-03-08 09:50 16,496 -ra------ C:\WINDOWS\system32\drivers\HPZipr12.sys
2008-07-15 10:51 . 2008-08-06 17:56 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-07-15 10:51 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-07-13 22:44 . 2008-07-28 10:40 <DIR> d-------- C:\Program Files\StarDict
2008-07-07 15:50 . 2008-07-07 15:50 <DIR> d-------- C:\WINDOWS\Favorites
2008-07-07 15:50 . 2008-07-07 15:50 <DIR> d-------- C:\Program Files\ElefunMultimedia
2008-07-07 15:34 . 2008-07-13 11:09 445 --a------ C:\WINDOWS\EntPack.dat
2008-07-07 15:34 . 2008-07-13 11:09 51 --a------ C:\WINDOWS\EntPack.ini
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-07 13:57 --------- d-----w C:\Documents and Settings\r\Application Data\uTorrent
2008-08-07 12:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-08-06 18:29 --------- d-----w C:\Program Files\WinASO
2008-08-06 12:31 --------- d-----w C:\Program Files\HP
2008-08-04 15:20 --------- d-----w C:\Program Files\DivX
2008-08-04 15:19 --------- d-----w C:\Program Files\Google
2008-08-04 15:17 --------- d-----w C:\Program Files\Replay Media Catcher
2008-08-02 15:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg8
2008-08-02 14:23 --------- d-----w C:\Program Files\Realtek
2008-08-02 13:02 --------- d-----w C:\Program Files\Gabest
2008-08-02 12:57 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-07-27 18:09 --------- d-----w C:\Program Files\Jardinains!
2008-07-27 15:09 --------- d-----w C:\Program Files\One-click Audio Converter
2008-07-26 14:50 --------- d-----w C:\Program Files\Conduit
2008-07-25 12:14 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-25 06:35 --------- d-----w C:\Program Files\Microsoft.NET
2008-07-15 05:47 --------- d-----w C:\Documents and Settings\r\Application Data\HP
2008-07-01 13:53 2,788,800 ----a-w C:\Program Files\FLV PlayerFCSetup.exe
2008-07-01 13:51 7,710,016 ----a-w C:\Program Files\FLV PlayerRCATSetup.exe
2008-07-01 13:47 --------- d-----w C:\Documents and Settings\r\Application Data\GetRightToGo
2008-07-01 13:35 411,248 ----a-w C:\Program Files\FLV PlayerRCSetup.exe
2008-06-28 11:11 --------- d-----w C:\Program Files\YouTube Downloader
2008-05-21 09:37 120 ----a-w C:\drmHeader.bin
2008-04-04 23:20 0 ----a-w C:\Documents and Settings\r\run.bat
1765-05-30 03:37 4,263 --sha-w C:\WINDOWS\windllreg1c.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-03-23 09:47 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-03-23 09:43 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-03-23 09:47 118784]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-08-02 20:40 1232152]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06 40048]
"SkyTel"="SkyTel.EXE" [2006-05-16 15:34 2879488 C:\WINDOWS\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-11-14 14:51 16270848 C:\WINDOWS\RTHDCPL.EXE]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{A5949E07-8536-4625-A3D0-2DD83F559990}"= "C:\WINDOWS\system32\ShellHook.dll" [2007-12-13 03:29 86016]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=oykher.dll,zkrgkw.dll,avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.VDOM"= vdowave.drv
"VIDC.TR20"= tr2032.dll
"vidc.vivo"= ivvideo.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^LoadRunner Agent Process.lnk]
backup=C:\WINDOWS\pss\LoadRunner Agent Process.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AsusStartupHelp]
-ra--c--- 2006-11-14 11:55 363008 C:\Program Files\ASUS\AASP\1.00.17\AsRunHelp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a--c--- 2006-12-23 18:05 143360 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
--a------ 2006-11-10 16:19 1051648 C:\Program Files\Nero\Nero 7\InCD\InCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
--a--c--- 2006-12-05 22:55 54832 C:\Program Files\CyberLink\PowerDVD\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a--c--- 2006-01-12 15:40 155648 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a--c--- 2006-11-23 15:10 56928 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"CheckTestDirectorUserAccount"=3 (0x3)
"SandraTheSrv"=3 (0x3)
"SandraDataSrv"=3 (0x3)
"RichVideo"=2 (0x2)
"NMIndexingService"=3 (0x3)
"NBService"=3 (0x3)
"InCDsrv"=2 (0x2)
"gusvc"=2 (0x2)
"SCardSvr"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\uTorrent\\utorrent.exe"=
"C:\\Program Files\\Mercury\\LoadRunner\\launch_service\\bin\\magentproc.exe"=
"C:\\Program Files\\Mercury\\LoadRunner\\WebTours\\xigui32.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"C:\\Program Files\\HP\\QuickTest Professional\\bin\\AQTRmtAgent.exe"=
"C:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\WINDOWS\\system32\\mqsvc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"135:TCP"= 135:TCP:DCOM
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP:Peer Name Resolution Protocol (PNRP)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-08-02 20:40]
R2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-08-02 20:40]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-02 20:40]
R2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-08-02 20:41]
R2 paldrv;paldrv;C:\WINDOWS\system32\pal_drv.sys [2005-07-27 18:03]
S3 p2pgasvc;Peer Networking Group Authentication;C:\WINDOWS\system32\svchost.exe [2006-02-28 17:30]
S3 p2pimsvc;Peer Networking Identity Manager;C:\WINDOWS\system32\svchost.exe [2006-02-28 17:30]
S3 p2psvc;Peer Networking;C:\WINDOWS\system32\svchost.exe [2006-02-28 17:30]
S3 PNRPSvc;Peer Name Resolution Protocol;C:\WINDOWS\system32\svchost.exe [2006-02-28 17:30]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cf55fbcf-8ce7-11dc-a788-001a929060e6}]
\Shell\Auto\command - MicrosoftPowerPoint.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL MicrosoftPowerPoint.exe
.
Contents of the 'Scheduled Tasks' folder
2008-08-07 C:\WINDOWS\Tasks\WinASORegistryOptimizerForr.job
- C:\Program Files\WinASO\Registry Optimizer 3.0\RegOpt.exe []
.
- - - - ORPHANS REMOVED - - - -
Notify-geBqRige - geBqRige.dll
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\r\Application Data\Mozilla\Firefox\Profiles\v2rzr5nz.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com/
FF -: plugin - C:\Program Files\Yahoo!\Shared\npYState.dll
FF -: plugin - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-07 20:07:00
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\msdtc.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\snmp.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-08-07 20:13:21 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-07 14:43:18
Pre-Run: 10,855,993,344 bytes free
Post-Run: 10,783,682,560 bytes free
289 --- E O F --- 2008-07-26 21:32:19
murphypaul1979
2008-08-11, 13:29
Hi Shaba,
This is the log you mentioned.
regards.
ComboFix 08-08-10.02 - r 2008-08-11 15:30:43.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.596 [GMT 5.5:30]
Running from: C:\Documents and Settings\r\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2008-07-11 to 2008-08-11 )))))))))))))))))))))))))))))))
.
2008-08-08 19:10 . 2006-02-28 17:30 538,624 --a------ C:\WINDOWS\system32\spider.exe
2008-08-08 19:10 . 2006-02-28 17:30 538,624 --a--c--- C:\WINDOWS\system32\dllcache\spider.exe
2008-08-08 03:41 . 2008-08-09 04:49 <DIR> d-------- C:\VideoConverterOutput
2008-08-08 03:40 . 2008-08-08 03:41 <DIR> d-------- C:\Program Files\Ultra Video Converter
2008-08-08 03:40 . 2006-05-05 06:59 421,888 --a------ C:\WINDOWS\system32\Mpeg2DecFilter.ax
2008-08-08 03:40 . 2006-07-18 22:11 376,832 --a------ C:\WINDOWS\system32\MpegSplitter.ax
2008-08-08 03:26 . 2008-08-08 03:42 <DIR> d-------- C:\Program Files\321 Xvid Converter
2008-08-08 03:26 . 2008-08-08 03:26 66 --a------ C:\WINDOWS\321 Xvid Converter.INI
2008-08-08 02:58 . 2008-08-08 02:58 66 --a------ C:\WINDOWS\PowerVideoConverter.INI
2008-08-08 02:19 . 2008-08-08 02:19 66 --a------ C:\WINDOWS\Power Video Converter.INI
2008-08-07 17:09 . 2008-08-07 17:10 <DIR> d-------- C:\Program Files\AVI MPEG WMV RM to MP3 Converter
2008-08-07 04:32 . 2008-08-07 17:27 <DIR> d-------- C:\Program Files\OCR-TextScan 2 Word 1
2008-08-07 04:32 . 2008-08-07 04:32 72,192 --a------ C:\WINDOWS\cadkasdeinst01e.exe
2008-08-06 22:18 . 2008-08-06 22:18 184 --a------ C:\WINDOWS\Readiris.ini
2008-08-06 21:02 . 2008-08-06 23:17 <DIR> d-------- C:\Program Files\Readiris Pro 11 Corporate Edition Demo
2008-08-06 18:35 . 2008-08-06 18:35 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-08-06 17:59 . 2008-08-06 17:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\HP Product Assistant
2008-08-06 17:58 . 2008-08-06 17:58 <DIR> d-------- C:\Program Files\Hewlett-Packard
2008-08-06 17:49 . 2008-08-06 18:03 141,147 --a------ C:\WINDOWS\hpoins14.dat
2008-08-06 17:48 . 2007-09-20 06:44 2,000 --------- C:\WINDOWS\hpomdl14.dat
2008-08-06 01:09 . 2008-08-06 01:09 <DIR> d-------- C:\WINDOWS\IIS Temporary Compressed Files
2008-08-06 01:08 . 2001-08-17 22:36 65,536 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_mailmsg.dll
2008-08-06 01:08 . 2001-08-17 22:36 57,856 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_scripto.dll
2008-08-06 01:08 . 2001-08-17 22:36 45,056 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_aqadmin.dll
2008-08-06 01:08 . 2001-08-17 22:36 43,520 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_fcachdll.dll
2008-08-06 01:08 . 2001-08-17 22:36 38,912 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_ntfsdrv.dll
2008-08-06 01:08 . 2001-08-17 22:36 26,112 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_seos.dll
2008-08-06 01:08 . 2001-08-17 22:36 23,040 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_regtrace.exe
2008-08-06 01:08 . 2001-08-17 22:36 12,288 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_smtpctrs.dll
2008-08-06 01:08 . 2001-08-17 22:36 7,168 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_snprfdll.dll
2008-08-06 01:08 . 2001-08-17 22:36 5,632 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_adsiisex.dll
2008-08-06 01:06 . 2006-02-28 17:30 562,176 --a--c--- C:\WINDOWS\system32\dllcache\fxsst.dll
2008-08-06 01:02 . 2008-08-06 01:08 <DIR> d-------- C:\WINDOWS\system32\msmq
2008-08-06 01:02 . 2008-08-08 19:11 <DIR> d-------- C:\Inetpub
2008-08-05 10:25 . 2008-08-05 10:46 <DIR> d-------- C:\AllokRMFolder
2008-08-05 10:24 . 2008-08-05 10:25 <DIR> d-------- C:\Program Files\Allok RM RMVB to AVI MPEG DVD Converter
2008-08-03 20:17 . 2008-08-03 20:17 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-03 19:30 . 2008-08-03 19:42 1,934 --a------ C:\WINDOWS\system32\tmp.reg
2008-08-03 19:27 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-08-03 19:27 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-08-03 19:27 . 2008-05-29 09:35 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-08-03 19:27 . 2008-07-02 13:33 82,432 --a------ C:\WINDOWS\system32\IEDFix.C.exe
2008-08-03 19:27 . 2008-05-23 18:21 81,920 --a------ C:\WINDOWS\system32\404Fix.exe
2008-08-03 19:27 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-08-03 19:27 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-08-03 19:27 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-08-03 18:44 . 2008-08-11 14:42 <DIR> d--h----- C:\$AVG8.VAULT$
2008-08-02 20:41 . 2008-08-02 20:41 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-08-02 20:41 . 2008-08-02 20:41 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-08-02 20:40 . 2008-08-10 10:19 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-08-02 20:40 . 2008-08-02 20:40 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-08-02 19:52 . 2006-03-23 09:42 139,264 -ra------ C:\WINDOWS\system32\igfxres.dll
2008-08-02 19:49 . 2008-08-02 19:49 <DIR> d-------- C:\WINDOWS\ASUSInstAll
2008-08-02 19:44 . 2008-08-02 19:44 12,889 --a------ C:\WINDOWS\Ascd_tmp.ini
2008-08-02 19:31 . 2006-02-28 17:30 28,288 --a--c--- C:\WINDOWS\system32\dllcache\xjis.nls
2008-08-02 19:29 . 2006-02-28 17:30 1,875,968 --a--c--- C:\WINDOWS\system32\dllcache\msir3jp.lex
2008-08-02 19:28 . 2006-02-28 17:30 13,463,552 --a--c--- C:\WINDOWS\system32\dllcache\hwxjpn.dll
2008-08-02 19:27 . 2006-02-28 17:30 1,677,824 --a--c--- C:\WINDOWS\system32\dllcache\chsbrkr.dll
2008-08-02 19:23 . 2008-08-02 19:23 749 -rah----- C:\WINDOWS\WindowsShell.Manifest
2008-08-02 19:23 . 2008-08-02 19:23 749 -rah----- C:\WINDOWS\system32\wuaucpl.cpl.manifest
2008-08-02 19:23 . 2008-08-02 19:23 749 -rah----- C:\WINDOWS\system32\sapi.cpl.manifest
2008-08-02 19:23 . 2008-08-02 19:23 749 -rah----- C:\WINDOWS\system32\nwc.cpl.manifest
2008-08-02 19:23 . 2008-08-02 19:23 749 -rah----- C:\WINDOWS\system32\ncpa.cpl.manifest
2008-08-02 19:23 . 2008-08-02 19:23 488 -rah----- C:\WINDOWS\system32\logonui.exe.manifest
2008-08-02 19:02 . 2006-02-28 17:30 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2008-08-02 19:02 . 2006-02-28 17:30 24,661 --a--c--- C:\WINDOWS\system32\dllcache\spxcoins.dll
2008-08-02 19:02 . 2006-02-28 17:30 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2008-08-02 19:02 . 2006-02-28 17:30 13,312 --a--c--- C:\WINDOWS\system32\dllcache\irclass.dll
2008-08-02 18:37 . 2008-08-08 02:19 23,392 --a------ C:\WINDOWS\system32\nscompat.tlb
2008-08-02 18:37 . 2008-08-08 02:19 16,832 --a------ C:\WINDOWS\system32\amcompat.tlb
2008-08-02 15:00 . 2008-08-03 19:48 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-08-02 15:00 . 2008-08-04 08:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-28 10:18 . 2007-07-19 18:14 3,727,720 --a------ C:\WINDOWS\system32\d3dx9_35.dll
2008-07-27 23:39 . 2008-07-27 23:39 82,996 --a------ C:\WINDOWS\system32\SpoonUninstall-Jardinains!.bmp
2008-07-27 23:39 . 2008-07-27 23:39 10,960 --a------ C:\WINDOWS\system32\SpoonUninstall-Jardinains!.dat
2008-07-27 23:37 . 2008-07-27 23:37 <DIR> d-------- C:\Program Files\Free RM to MP3 Converter
2008-07-27 20:39 . 2008-07-27 20:39 <DIR> d-------- C:\Program Files\Illustrate
2008-07-27 03:02 . 2008-07-27 03:02 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-07-26 20:18 . 2008-07-26 20:20 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-07-26 10:34 . 2008-07-26 10:34 <DIR> d-------- C:\Program Files\Microsoft WSE
2008-07-26 10:27 . 2007-05-16 16:45 1,124,720 --a------ C:\WINDOWS\system32\D3DCompiler_34.dll
2008-07-26 10:27 . 2007-05-16 16:45 443,752 --a------ C:\WINDOWS\system32\d3dx10_34.dll
2008-07-26 10:26 . 2007-05-16 16:45 3,497,832 --a------ C:\WINDOWS\system32\d3dx9_34.dll
2008-07-26 10:26 . 2006-11-29 13:06 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll
2008-07-26 10:26 . 2006-09-28 16:05 2,414,360 --a------ C:\WINDOWS\system32\d3dx9_31.dll
2008-07-26 10:06 . 2008-07-26 10:06 <DIR> d-------- C:\Program Files\MagicISO
2008-07-25 11:41 . 2006-08-31 10:54 327,680 --a------ C:\WINDOWS\system32\PrmSrvInstall.dll
2008-07-25 11:41 . 1999-06-25 10:55 149,504 --a------ C:\WINDOWS\system32\UNWISE.EXE
2008-07-25 11:41 . 2006-07-14 10:03 65,636 --a------ C:\WINDOWS\system32\PrmSrvUninst.exe
2008-07-25 11:24 . 2008-07-25 11:39 <DIR> d-------- C:\Program Files\Microsoft SQL Server
2008-07-25 11:23 . 2008-07-25 11:23 <DIR> d-------- C:\Program Files\Common Files\Borland Shared
2008-07-22 12:31 . 2008-07-26 17:23 <DIR> d-------- C:\Program Files\Autodesk
2008-07-22 12:31 . 2005-05-26 15:34 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll
2008-07-22 00:42 . 2008-07-28 10:28 <DIR> d-------- C:\Documents and Settings\r\Application Data\Autodesk
2008-07-21 23:48 . 2008-07-28 10:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Autodesk
2008-07-21 14:02 . 2007-04-09 13:23 28,040 --a------ C:\WINDOWS\system32\mdimon.dll
2008-07-21 14:00 . 2008-07-21 14:00 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-07-21 13:58 . 2008-07-21 14:00 <DIR> d--h----- C:\WINDOWS\ShellNew
2008-07-21 13:54 . 2008-07-21 13:54 <DIR> dr-h----- C:\MSOCache
2008-07-15 21:26 . 2008-07-15 21:26 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-07-15 10:58 . 2008-07-15 10:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WEBREG
2008-07-15 10:56 . 2008-08-06 18:01 <DIR> d-------- C:\Documents and Settings\r\Application Data\HPAppData
2008-07-15 10:55 . 2008-07-15 10:55 <DIR> d-------- C:\Program Files\Common Files\HP
2008-07-15 10:55 . 2008-08-06 17:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\HP
2008-07-15 10:54 . 2008-07-15 10:54 <DIR> d-------- C:\Program Files\Common Files\Hewlett-Packard
2008-07-15 10:53 . 2008-07-15 10:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2008-07-15 10:53 . 2007-03-17 21:41 675,840 -ra------ C:\WINDOWS\system32\hpowiax3.dll
2008-07-15 10:53 . 2007-03-17 21:41 569,344 -ra------ C:\WINDOWS\system32\hpotscl3.dll
2008-07-15 10:53 . 2007-03-08 09:50 364,544 -ra------ C:\WINDOWS\system32\hppldcoi.dll
2008-07-15 10:53 . 2007-03-08 09:50 309,760 -ra------ C:\WINDOWS\system32\difxapi.dll
2008-07-15 10:53 . 2007-03-17 21:41 303,104 -ra------ C:\WINDOWS\system32\hpovst10.dll
2008-07-15 10:53 . 2007-03-30 20:37 267,864 -ra------ C:\WINDOWS\system32\hpzids01.dll
2008-07-15 10:53 . 2007-03-28 14:01 117,760 --a------ C:\WINDOWS\system32\hpzll5ha.dll
2008-07-15 10:53 . 2007-03-08 09:50 49,920 -ra------ C:\WINDOWS\system32\drivers\HPZid412.sys
2008-07-15 10:53 . 2007-03-08 09:50 21,568 -ra------ C:\WINDOWS\system32\drivers\HPZius12.sys
2008-07-15 10:53 . 2007-03-08 09:50 16,496 -ra------ C:\WINDOWS\system32\drivers\HPZipr12.sys
2008-07-15 10:51 . 2008-08-06 17:56 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-07-15 10:51 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-07-13 22:44 . 2008-07-28 10:40 <DIR> d-------- C:\Program Files\StarDict
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-07 21:20 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-07 21:19 --------- d-----w C:\Program Files\DivX
2008-08-07 12:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-08-06 18:29 --------- d-----w C:\Program Files\WinASO
2008-08-06 12:31 --------- d-----w C:\Program Files\HP
2008-08-04 15:19 --------- d-----w C:\Program Files\Google
2008-08-04 15:17 --------- d-----w C:\Program Files\Replay Media Catcher
2008-08-02 15:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg8
2008-08-02 14:23 --------- d-----w C:\Program Files\Realtek
2008-08-02 13:02 --------- d-----w C:\Program Files\Gabest
2008-08-02 12:57 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-07-27 18:09 164,352 ----a-w C:\WINDOWS\system32\SpoonUninstall.exe
2008-07-27 18:09 --------- d-----w C:\Program Files\Jardinains!
2008-07-27 15:09 --------- d-----w C:\Program Files\One-click Audio Converter
2008-07-26 14:50 --------- d-----w C:\Program Files\Conduit
2008-07-25 06:35 --------- d-----w C:\Program Files\Microsoft.NET
2008-07-15 05:47 --------- d-----w C:\Documents and Settings\r\Application Data\HP
2008-07-07 10:20 --------- d-----w C:\Program Files\ElefunMultimedia
2008-07-01 13:53 2,788,800 ----a-w C:\Program Files\FLV PlayerFCSetup.exe
2008-07-01 13:51 7,710,016 ----a-w C:\Program Files\FLV PlayerRCATSetup.exe
2008-07-01 13:47 --------- d-----w C:\Documents and Settings\r\Application Data\GetRightToGo
2008-07-01 13:35 411,248 ----a-w C:\Program Files\FLV PlayerRCSetup.exe
2008-06-28 11:11 --------- d-----w C:\Program Files\YouTube Downloader
2008-05-30 23:22 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-05-30 23:22 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2008-05-30 23:22 815,104 ----a-w C:\WINDOWS\system32\divx_xx0a.dll
2008-05-30 23:22 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2008-05-30 23:22 683,520 ----a-w C:\WINDOWS\system32\DivX.dll
2008-05-30 23:22 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-05-30 23:22 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2008-05-30 23:22 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-05-30 23:22 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2008-05-30 23:22 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2008-05-30 23:22 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2008-05-22 22:22 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-05-22 22:22 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-05-22 22:20 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-05-22 22:20 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-05-22 22:19 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-05-22 22:19 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2008-05-22 22:19 161,096 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-05-22 22:18 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-05-21 09:37 120 ----a-w C:\drmHeader.bin
2008-04-04 23:20 0 ----a-w C:\Documents and Settings\r\run.bat
1765-05-30 03:37 4,263 --sha-w C:\WINDOWS\windllreg1c.sys
.
((((((((((((((((((((((((((((( snapshot@2008-08-07_20.13.01.92 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-08-05 19:46:32 91,968 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-08-08 13:41:57 75,142 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-08-05 19:46:32 502,732 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-08-08 13:41:57 454,016 ----a-w C:\WINDOWS\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-03-23 09:43 77824]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-08-02 20:40 1232152]
"SkyTel"="SkyTel.EXE" [2006-05-16 15:34 2879488 C:\WINDOWS\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-11-14 14:51 16270848 C:\WINDOWS\RTHDCPL.EXE]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{A5949E07-8536-4625-A3D0-2DD83F559990}"= "C:\WINDOWS\system32\ShellHook.dll" [2007-12-13 03:29 86016]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geBqRige]
[BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=oykher.dll,zkrgkw.dll,avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.VDOM"= vdowave.drv
"VIDC.TR20"= tr2032.dll
"vidc.vivo"= ivvideo.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^LoadRunner Agent Process.lnk]
backup=C:\WINDOWS\pss\LoadRunner Agent Process.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AsusStartupHelp]
-ra--c--- 2006-11-14 11:55 363008 C:\Program Files\ASUS\AASP\1.00.17\AsRunHelp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a--c--- 2006-12-23 18:05 143360 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
--a------ 2006-11-10 16:19 1051648 C:\Program Files\Nero\Nero 7\InCD\InCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
--a--c--- 2006-12-05 22:55 54832 C:\Program Files\CyberLink\PowerDVD\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a--c--- 2006-01-12 15:40 155648 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a--c--- 2006-11-23 15:10 56928 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"CheckTestDirectorUserAccount"=3 (0x3)
"SandraTheSrv"=3 (0x3)
"SandraDataSrv"=3 (0x3)
"RichVideo"=2 (0x2)
"NMIndexingService"=3 (0x3)
"NBService"=3 (0x3)
"InCDsrv"=2 (0x2)
"gusvc"=2 (0x2)
"SCardSvr"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"igfxtray"=C:\WINDOWS\system32\igfxtray.exe
"igfxpers"=C:\WINDOWS\system32\igfxpers.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\uTorrent\\utorrent.exe"=
"C:\\Program Files\\Mercury\\LoadRunner\\launch_service\\bin\\magentproc.exe"=
"C:\\Program Files\\Mercury\\LoadRunner\\WebTours\\xigui32.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"C:\\Program Files\\HP\\QuickTest Professional\\bin\\AQTRmtAgent.exe"=
"C:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\WINDOWS\\system32\\mqsvc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"135:TCP"= 135:TCP:DCOM
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-08-02 20:40]
R2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-08-02 20:40]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-02 20:40]
R2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-08-02 20:41]
R2 paldrv;paldrv;C:\WINDOWS\system32\pal_drv.sys [2005-07-27 18:03]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cf55fbcf-8ce7-11dc-a788-001a929060e6}]
\Shell\Auto\command - MicrosoftPowerPoint.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL MicrosoftPowerPoint.exe
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
2008-08-11 C:\WINDOWS\Tasks\WinASORegistryOptimizerForr.job
- C:\Program Files\WinASO\Registry Optimizer 3.0\RegOpt.exe []
.
- - - - ORPHANS REMOVED - - - -
BHO-{318F134D-1627-48A5-909A-8D1D9C82BDE0} - (no file)
BHO-{77ec9d57-249a-41a7-ad4a-5b9950a3f879} - (no file)
BHO-{83445c84-ddaa-4754-b246-dd10275cb6ea} - (no file)
BHO-{8658825D-21E5-4F04-8DB7-1AB67C8E8F6E} - (no file)
BHO-{C893C01E-6875-4AEE-AFC7-E33CC4A5B91F} - (no file)
BHO-{DCA900CF-450B-4E35-9169-66767F2F9D67} - (no file)
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\r\Application Data\Mozilla\Firefox\Profiles\v2rzr5nz.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com/
FF -: plugin - C:\Program Files\Yahoo!\Shared\npYState.dll
FF -: plugin - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-11 15:33:26
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-08-11 15:35:42
ComboFix-quarantined-files.txt 2008-08-11 10:05:38
ComboFix2.txt 2008-08-07 14:43:22
Pre-Run: 16,255,246,336 bytes free
Post-Run: 16,227,975,168 bytes free
301 --- E O F --- 2008-07-26 21:32:19
murphypaul1979
2008-08-12, 21:33
ComboFix 08-08-10.02 - r 2008-08-12 21:30:24.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.654 [GMT 5.5:30]
Running from: C:\Documents and Settings\r\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\r\Desktop\CFScript.txt
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2008-07-12 to 2008-08-12 )))))))))))))))))))))))))))))))
.
2008-08-12 21:10 . 2008-04-23 09:46 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-08-12 21:10 . 2007-04-17 15:02 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-08-12 21:10 . 2007-03-08 10:40 991,232 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-08-12 21:10 . 2008-04-23 09:46 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-08-12 21:10 . 2008-04-23 09:46 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-08-12 21:10 . 2008-04-23 09:46 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-08-12 21:10 . 2008-04-23 09:46 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-08-12 21:10 . 2008-04-23 09:46 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-08-12 21:10 . 2008-04-22 13:09 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-08-12 20:47 . 2008-06-13 18:40 272,128 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-08-08 19:10 . 2006-02-28 17:30 538,624 --a------ C:\WINDOWS\system32\spider.exe
2008-08-08 19:10 . 2006-02-28 17:30 538,624 --a--c--- C:\WINDOWS\system32\dllcache\spider.exe
2008-08-08 03:41 . 2008-08-09 04:49 <DIR> d-------- C:\VideoConverterOutput
2008-08-08 03:40 . 2008-08-08 03:41 <DIR> d-------- C:\Program Files\Ultra Video Converter
2008-08-08 03:40 . 2006-05-05 06:59 421,888 --a------ C:\WINDOWS\system32\Mpeg2DecFilter.ax
2008-08-08 03:40 . 2006-07-18 22:11 376,832 --a------ C:\WINDOWS\system32\MpegSplitter.ax
2008-08-08 03:26 . 2008-08-08 03:42 <DIR> d-------- C:\Program Files\321 Xvid Converter
2008-08-08 03:26 . 2008-08-08 03:26 66 --a------ C:\WINDOWS\321 Xvid Converter.INI
2008-08-08 02:58 . 2008-08-08 02:58 66 --a------ C:\WINDOWS\PowerVideoConverter.INI
2008-08-08 02:19 . 2008-08-08 02:19 66 --a------ C:\WINDOWS\Power Video Converter.INI
2008-08-07 17:09 . 2008-08-07 17:10 <DIR> d-------- C:\Program Files\AVI MPEG WMV RM to MP3 Converter
2008-08-07 04:32 . 2008-08-07 17:27 <DIR> d-------- C:\Program Files\OCR-TextScan 2 Word 1
2008-08-07 04:32 . 2008-08-07 04:32 72,192 --a------ C:\WINDOWS\cadkasdeinst01e.exe
2008-08-06 22:18 . 2008-08-06 22:18 184 --a------ C:\WINDOWS\Readiris.ini
2008-08-06 21:02 . 2008-08-06 23:17 <DIR> d-------- C:\Program Files\Readiris Pro 11 Corporate Edition Demo
2008-08-06 18:35 . 2008-08-06 18:35 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-08-06 17:59 . 2008-08-06 17:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\HP Product Assistant
2008-08-06 17:58 . 2008-08-06 17:58 <DIR> d-------- C:\Program Files\Hewlett-Packard
2008-08-06 17:49 . 2008-08-06 18:03 141,147 --a------ C:\WINDOWS\hpoins14.dat
2008-08-06 17:48 . 2007-09-20 06:44 2,000 --------- C:\WINDOWS\hpomdl14.dat
2008-08-06 01:09 . 2008-08-06 01:09 <DIR> d-------- C:\WINDOWS\IIS Temporary Compressed Files
2008-08-06 01:08 . 2001-08-17 22:36 65,536 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_mailmsg.dll
2008-08-06 01:08 . 2001-08-17 22:36 57,856 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_scripto.dll
2008-08-06 01:08 . 2001-08-17 22:36 45,056 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_aqadmin.dll
2008-08-06 01:08 . 2001-08-17 22:36 43,520 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_fcachdll.dll
2008-08-06 01:08 . 2001-08-17 22:36 38,912 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_ntfsdrv.dll
2008-08-06 01:08 . 2001-08-17 22:36 26,112 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_seos.dll
2008-08-06 01:08 . 2001-08-17 22:36 23,040 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_regtrace.exe
2008-08-06 01:08 . 2001-08-17 22:36 12,288 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_smtpctrs.dll
2008-08-06 01:08 . 2001-08-17 22:36 7,168 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_snprfdll.dll
2008-08-06 01:08 . 2001-08-17 22:36 5,632 --a--c--- C:\WINDOWS\system32\dllcache\EXCH_adsiisex.dll
2008-08-06 01:06 . 2006-02-28 17:30 562,176 --a--c--- C:\WINDOWS\system32\dllcache\fxsst.dll
2008-08-06 01:02 . 2008-08-06 01:08 <DIR> d-------- C:\WINDOWS\system32\msmq
2008-08-06 01:02 . 2008-08-08 19:11 <DIR> d-------- C:\Inetpub
2008-08-05 10:25 . 2008-08-05 10:46 <DIR> d-------- C:\AllokRMFolder
2008-08-05 10:24 . 2008-08-05 10:25 <DIR> d-------- C:\Program Files\Allok RM RMVB to AVI MPEG DVD Converter
2008-08-03 20:17 . 2008-08-03 20:17 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-03 19:30 . 2008-08-03 19:42 1,934 --a------ C:\WINDOWS\system32\tmp.reg
2008-08-03 19:27 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-08-03 19:27 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-08-03 19:27 . 2008-05-29 09:35 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-08-03 19:27 . 2008-07-02 13:33 82,432 --a------ C:\WINDOWS\system32\IEDFix.C.exe
2008-08-03 19:27 . 2008-05-23 18:21 81,920 --a------ C:\WINDOWS\system32\404Fix.exe
2008-08-03 19:27 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-08-03 19:27 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-08-03 19:27 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-08-03 18:44 . 2008-08-11 14:42 <DIR> d--h----- C:\$AVG8.VAULT$
2008-08-02 20:41 . 2008-08-02 20:41 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-08-02 20:41 . 2008-08-02 20:41 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-08-02 20:40 . 2008-08-12 16:16 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-08-02 20:40 . 2008-08-02 20:40 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-08-02 19:52 . 2006-03-23 09:42 139,264 -ra------ C:\WINDOWS\system32\igfxres.dll
2008-08-02 19:49 . 2008-08-02 19:49 <DIR> d-------- C:\WINDOWS\ASUSInstAll
2008-08-02 19:44 . 2008-08-02 19:44 12,889 --a------ C:\WINDOWS\Ascd_tmp.ini
2008-08-02 19:31 . 2006-02-28 17:30 28,288 --a--c--- C:\WINDOWS\system32\dllcache\xjis.nls
2008-08-02 19:29 . 2006-02-28 17:30 1,875,968 --a--c--- C:\WINDOWS\system32\dllcache\msir3jp.lex
2008-08-02 19:28 . 2006-02-28 17:30 13,463,552 --a--c--- C:\WINDOWS\system32\dllcache\hwxjpn.dll
2008-08-02 19:27 . 2006-02-28 17:30 1,677,824 --a--c--- C:\WINDOWS\system32\dllcache\chsbrkr.dll
2008-08-02 19:23 . 2008-08-02 19:23 749 -rah----- C:\WINDOWS\WindowsShell.Manifest
2008-08-02 19:23 . 2008-08-02 19:23 749 -rah----- C:\WINDOWS\system32\wuaucpl.cpl.manifest
2008-08-02 19:23 . 2008-08-02 19:23 749 -rah----- C:\WINDOWS\system32\sapi.cpl.manifest
2008-08-02 19:23 . 2008-08-02 19:23 749 -rah----- C:\WINDOWS\system32\nwc.cpl.manifest
2008-08-02 19:23 . 2008-08-02 19:23 749 -rah----- C:\WINDOWS\system32\ncpa.cpl.manifest
2008-08-02 19:23 . 2008-08-02 19:23 488 -rah----- C:\WINDOWS\system32\logonui.exe.manifest
2008-08-02 19:02 . 2006-02-28 17:30 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2008-08-02 19:02 . 2006-02-28 17:30 24,661 --a--c--- C:\WINDOWS\system32\dllcache\spxcoins.dll
2008-08-02 19:02 . 2006-02-28 17:30 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2008-08-02 19:02 . 2006-02-28 17:30 13,312 --a--c--- C:\WINDOWS\system32\dllcache\irclass.dll
2008-08-02 18:37 . 2008-08-08 02:19 23,392 --a------ C:\WINDOWS\system32\nscompat.tlb
2008-08-02 18:37 . 2008-08-08 02:19 16,832 --a------ C:\WINDOWS\system32\amcompat.tlb
2008-08-02 15:00 . 2008-08-03 19:48 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-08-02 15:00 . 2008-08-04 08:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-28 10:18 . 2007-07-19 18:14 3,727,720 --a------ C:\WINDOWS\system32\d3dx9_35.dll
2008-07-27 23:39 . 2008-07-27 23:39 82,996 --a------ C:\WINDOWS\system32\SpoonUninstall-Jardinains!.bmp
2008-07-27 23:39 . 2008-07-27 23:39 10,960 --a------ C:\WINDOWS\system32\SpoonUninstall-Jardinains!.dat
2008-07-27 23:37 . 2008-07-27 23:37 <DIR> d-------- C:\Program Files\Free RM to MP3 Converter
2008-07-27 20:39 . 2008-07-27 20:39 <DIR> d-------- C:\Program Files\Illustrate
2008-07-27 03:02 . 2008-07-27 03:02 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-07-26 20:18 . 2008-07-26 20:20 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-07-26 10:34 . 2008-07-26 10:34 <DIR> d-------- C:\Program Files\Microsoft WSE
2008-07-26 10:27 . 2007-05-16 16:45 1,124,720 --a------ C:\WINDOWS\system32\D3DCompiler_34.dll
2008-07-26 10:27 . 2007-05-16 16:45 443,752 --a------ C:\WINDOWS\system32\d3dx10_34.dll
2008-07-26 10:26 . 2007-05-16 16:45 3,497,832 --a------ C:\WINDOWS\system32\d3dx9_34.dll
2008-07-26 10:26 . 2006-11-29 13:06 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll
2008-07-26 10:26 . 2006-09-28 16:05 2,414,360 --a------ C:\WINDOWS\system32\d3dx9_31.dll
2008-07-26 10:06 . 2008-07-26 10:06 <DIR> d-------- C:\Program Files\MagicISO
2008-07-25 11:41 . 2006-08-31 10:54 327,680 --a------ C:\WINDOWS\system32\PrmSrvInstall.dll
2008-07-25 11:41 . 1999-06-25 10:55 149,504 --a------ C:\WINDOWS\system32\UNWISE.EXE
2008-07-25 11:41 . 2006-07-14 10:03 65,636 --a------ C:\WINDOWS\system32\PrmSrvUninst.exe
2008-07-25 11:24 . 2008-07-25 11:39 <DIR> d-------- C:\Program Files\Microsoft SQL Server
2008-07-25 11:23 . 2008-07-25 11:23 <DIR> d-------- C:\Program Files\Common Files\Borland Shared
2008-07-22 12:31 . 2008-07-26 17:23 <DIR> d-------- C:\Program Files\Autodesk
2008-07-22 12:31 . 2005-05-26 15:34 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll
2008-07-22 00:42 . 2008-07-28 10:28 <DIR> d-------- C:\Documents and Settings\r\Application Data\Autodesk
2008-07-21 23:48 . 2008-07-28 10:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Autodesk
2008-07-21 14:02 . 2007-04-09 13:23 28,040 --a------ C:\WINDOWS\system32\mdimon.dll
2008-07-21 14:00 . 2008-07-21 14:00 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-07-21 13:58 . 2008-07-21 14:00 <DIR> d--h----- C:\WINDOWS\ShellNew
2008-07-21 13:54 . 2008-07-21 13:54 <DIR> dr-h----- C:\MSOCache
2008-07-15 21:26 . 2008-07-15 21:26 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-07-15 10:58 . 2008-07-15 10:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WEBREG
2008-07-15 10:56 . 2008-08-06 18:01 <DIR> d-------- C:\Documents and Settings\r\Application Data\HPAppData
2008-07-15 10:55 . 2008-07-15 10:55 <DIR> d-------- C:\Program Files\Common Files\HP
2008-07-15 10:55 . 2008-08-06 17:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\HP
2008-07-15 10:54 . 2008-07-15 10:54 <DIR> d-------- C:\Program Files\Common Files\Hewlett-Packard
2008-07-15 10:53 . 2008-07-15 10:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2008-07-15 10:53 . 2007-03-17 21:41 675,840 -ra------ C:\WINDOWS\system32\hpowiax3.dll
2008-07-15 10:53 . 2007-03-17 21:41 569,344 -ra------ C:\WINDOWS\system32\hpotscl3.dll
2008-07-15 10:53 . 2007-03-08 09:50 364,544 -ra------ C:\WINDOWS\system32\hppldcoi.dll
2008-07-15 10:53 . 2007-03-08 09:50 309,760 -ra------ C:\WINDOWS\system32\difxapi.dll
2008-07-15 10:53 . 2007-03-17 21:41 303,104 -ra------ C:\WINDOWS\system32\hpovst10.dll
2008-07-15 10:53 . 2007-03-30 20:37 267,864 -ra------ C:\WINDOWS\system32\hpzids01.dll
2008-07-15 10:53 . 2007-03-28 14:01 117,760 --a------ C:\WINDOWS\system32\hpzll5ha.dll
2008-07-15 10:53 . 2007-03-08 09:50 49,920 -ra------ C:\WINDOWS\system32\drivers\HPZid412.sys
2008-07-15 10:53 . 2007-03-08 09:50 21,568 -ra------ C:\WINDOWS\system32\drivers\HPZius12.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-07 21:20 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-07 21:19 --------- d-----w C:\Program Files\DivX
2008-08-07 12:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-08-06 18:29 --------- d-----w C:\Program Files\WinASO
2008-08-06 12:31 --------- d-----w C:\Program Files\HP
2008-08-04 15:19 --------- d-----w C:\Program Files\Google
2008-08-04 15:17 --------- d-----w C:\Program Files\Replay Media Catcher
2008-08-02 15:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg8
2008-08-02 14:23 --------- d-----w C:\Program Files\Realtek
2008-08-02 13:02 --------- d-----w C:\Program Files\Gabest
2008-08-02 12:57 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-07-27 18:09 164,352 ----a-w C:\WINDOWS\system32\SpoonUninstall.exe
2008-07-27 18:09 --------- d-----w C:\Program Files\Jardinains!
2008-07-27 15:09 --------- d-----w C:\Program Files\One-click Audio Converter
2008-07-26 14:50 --------- d-----w C:\Program Files\Conduit
2008-07-25 06:35 --------- d-----w C:\Program Files\Microsoft.NET
2008-07-15 05:47 --------- d-----w C:\Documents and Settings\r\Application Data\HP
2008-07-07 10:20 --------- d-----w C:\Program Files\ElefunMultimedia
2008-07-01 13:53 2,788,800 ----a-w C:\Program Files\FLV PlayerFCSetup.exe
2008-07-01 13:51 7,710,016 ----a-w C:\Program Files\FLV PlayerRCATSetup.exe
2008-07-01 13:47 --------- d-----w C:\Documents and Settings\r\Application Data\GetRightToGo
2008-07-01 13:35 411,248 ----a-w C:\Program Files\FLV PlayerRCSetup.exe
2008-06-28 11:11 --------- d-----w C:\Program Files\YouTube Downloader
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-13 13:10 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-05-30 23:22 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2008-05-30 23:22 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2008-05-30 23:22 815,104 ----a-w C:\WINDOWS\system32\divx_xx0a.dll
2008-05-30 23:22 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2008-05-30 23:22 683,520 ----a-w C:\WINDOWS\system32\DivX.dll
2008-05-30 23:22 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2008-05-30 23:22 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2008-05-30 23:22 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2008-05-30 23:22 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2008-05-30 23:22 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2008-05-30 23:22 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2008-05-22 22:22 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-05-22 22:22 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-05-22 22:20 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-05-22 22:20 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-05-22 22:19 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-05-22 22:19 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2008-05-22 22:19 161,096 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2008-05-22 22:18 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-05-21 09:37 120 ----a-w C:\drmHeader.bin
2008-04-04 23:20 0 ----a-w C:\Documents and Settings\r\run.bat
1765-05-30 03:37 4,263 --sha-w C:\WINDOWS\windllreg1c.sys
.
((((((((((((((((((((((((((((( snapshot@2008-08-07_20.13.01.92 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-11-13 11:02:46 60,416 ----a-w C:\WINDOWS\$hf_mig$\KB942763\SP2QFE\tzchange.exe
+ 2008-03-27 09:22:32 60,416 ----a-w C:\WINDOWS\$hf_mig$\KB942763\SP2QFE\tzchange.exe
+ 2008-03-27 10:40:24 60,416 ----a-w C:\WINDOWS\$hf_mig$\KB942763\SP3GDR\tzchange.exe
+ 2008-03-27 10:46:15 60,416 ----a-w C:\WINDOWS\$hf_mig$\KB942763\SP3QFE\tzchange.exe
- 2007-03-06 01:22:36 14,048 ----a-w C:\WINDOWS\$hf_mig$\KB942763\spmsg.dll
+ 2007-11-30 11:18:51 17,272 ----a-w C:\WINDOWS\$hf_mig$\KB942763\spmsg.dll
- 2007-03-06 01:22:41 213,216 ----a-w C:\WINDOWS\$hf_mig$\KB942763\spuninst.exe
+ 2007-11-30 11:18:51 231,288 ----a-w C:\WINDOWS\$hf_mig$\KB942763\spuninst.exe
- 2007-03-06 01:22:34 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB942763\update\spcustom.dll
+ 2007-11-30 11:18:51 26,488 ----a-w C:\WINDOWS\$hf_mig$\KB942763\update\spcustom.dll
- 2007-03-06 01:22:59 716,000 ----a-w C:\WINDOWS\$hf_mig$\KB942763\update\update.exe
+ 2007-11-30 11:18:51 755,576 ----a-w C:\WINDOWS\$hf_mig$\KB942763\update\update.exe
- 2007-03-06 01:23:51 371,424 ----a-w C:\WINDOWS\$hf_mig$\KB942763\update\updspapi.dll
+ 2007-11-30 11:18:51 382,840 ----a-w C:\WINDOWS\$hf_mig$\KB942763\update\updspapi.dll
+ 2008-06-13 13:10:50 272,128 ------w C:\WINDOWS\Driver Cache\i386\bthport.sys
+ 2007-03-06 01:22:34 22,752 -c----w C:\WINDOWS\ie7updates\KB938127-IE7\spcustom.dll
+ 2007-03-06 01:22:36 14,048 -c----w C:\WINDOWS\ie7updates\KB938127-IE7\spmsg.dll
+ 2007-03-06 01:22:41 213,216 -c----w C:\WINDOWS\ie7updates\KB938127-IE7\spuninst.exe
+ 2007-03-06 01:22:59 716,000 -c----w C:\WINDOWS\ie7updates\KB938127-IE7\update.exe
+ 2007-03-06 01:23:51 371,424 -c----w C:\WINDOWS\ie7updates\KB938127-IE7\updspapi.dll
- 2006-12-22 05:19:12 765,952 -c--a-w C:\WINDOWS\ie7updates\KB938127-IE7\vgx.dll
+ 2007-08-13 13:24:10 765,952 -c----w C:\WINDOWS\ie7updates\KB938127-IE7\vgx.dll
- 2008-03-01 13:06:20 124,928 -c--a-w C:\WINDOWS\ie7updates\KB950759-IE7\advpack.dll
+ 2007-08-13 13:09:00 123,904 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\advpack.dll
- 2008-03-01 13:06:21 347,136 -c--a-w C:\WINDOWS\ie7updates\KB950759-IE7\dxtmsft.dll
+ 2007-08-13 13:05:46 346,624 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\dxtmsft.dll
- 2008-03-01 13:06:21 214,528 -c--a-w C:\WINDOWS\ie7updates\KB950759-IE7\dxtrans.dll
+ 2007-08-13 13:05:38 214,528 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\dxtrans.dll
- 2008-03-01 13:06:21 133,120 -c--a-w C:\WINDOWS\ie7updates\KB950759-IE7\extmgr.dll
+ 2007-08-13 13:24:10 131,584 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\extmgr.dll
- 2008-02-29 08:55:23 70,656 -c--a-w C:\WINDOWS\ie7updates\KB950759-IE7\ie4uinit.exe
+ 2007-08-13 13:09:06 54,784 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ie4uinit.exe
- 2008-03-01 13:06:21 153,088 -c--a-w C:\WINDOWS\ie7updates\KB950759-IE7\ieakeng.dll
+ 2007-08-13 13:09:26 152,064 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ieakeng.dll
- 2008-03-01 13:06:21 230,400 -c--a-w C:\WINDOWS\ie7updates\KB950759-IE7\ieaksie.dll
+ 2007-08-13 13:09:54 229,376 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ieaksie.dll
- 2008-02-15 05:44:25 161,792 -c--a-w C:\WINDOWS\ie7updates\KB950759-IE7\ieakui.dll
+ 2007-08-13 12:26:54 161,792 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ieakui.dll
- 2008-03-01 13:06:22 384,512 -c--a-w C:\WINDOWS\ie7updates\KB950759-IE7\iedkcs32.dll
+ 2007-08-13 13:09:50 382,976 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\iedkcs32.dll
- 2008-03-01 13:06:24 44,544 -c--a-w C:\WINDOWS\ie7updates\KB950759-IE7\iernonce.dll
+ 2007-08-13 13:09:10 43,008 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\iernonce.dll
- 2008-02-22 10:00:51 13,824 -c--a-w C:\WINDOWS\ie7updates\KB950759-IE7\ieudinit.exe
+ 2007-08-13 13:09:10 13,312 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\ieudinit.exe
- 2008-02-29 08:55:46 625,664 -c--a-w C:\WINDOWS\ie7updates\KB950759-IE7\iexplore.exe
+ 2007-08-13 13:13:56 622,080 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\iexplore.exe
- 2008-03-01 13:06:25 27,648 -c--a-w C:\WINDOWS\ie7updates\KB950759-IE7\jsproxy.dll
+ 2007-08-13 13:24:10 27,136 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\jsproxy.dll
- 2008-03-01 13:06:30 3,591,680 -c--a-w C:\WINDOWS\ie7updates\KB950759-IE7\mshtml.dll
+ 2007-08-13 13:24:12 3,578,368 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\mshtml.dll
- 2008-03-01 13:06:28 478,208 -c--a-w C:\WINDOWS\ie7updates\KB950759-IE7\mshtmled.dll
+ 2007-08-13 13:24:10 475,648 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\mshtmled.dll
- 2008-03-01 13:06:28 193,024 -c--a-w C:\WINDOWS\ie7updates\KB950759-IE7\msrating.dll
+ 2007-08-13 13:14:26 192,000 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\msrating.dll
- 2008-03-01 13:06:29 671,232 -c--a-w C:\WINDOWS\ie7updates\KB950759-IE7\mstime.dll
+ 2007-08-13 13:24:10 670,720 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\mstime.dll
- 2008-03-01 13:06:29 102,912 -c--a-w C:\WINDOWS\ie7updates\KB950759-IE7\occache.dll
+ 2007-08-13 13:14:06 101,376 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\occache.dll
- 2008-03-01 13:06:29 44,544 -c--a-w C:\WINDOWS\ie7updates\KB950759-IE7\pngfilt.dll
+ 2007-08-13 13:06:12 44,544 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\pngfilt.dll
+ 2007-03-06 01:22:31 22,752 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\spcustom.dll
+ 2007-03-06 01:22:33 14,048 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\spmsg.dll
+ 2007-03-06 01:22:39 213,216 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\spuninst.exe
+ 2007-03-06 01:22:56 716,000 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\update.exe
+ 2007-03-06 01:23:51 371,424 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\updspapi.dll
- 2008-03-01 13:06:29 105,984 -c--a-w C:\WINDOWS\ie7updates\KB950759-IE7\url.dll
+ 2007-08-13 13:14:30 105,984 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\url.dll
- 2008-03-01 13:06:30 1,159,680 -c--a-w C:\WINDOWS\ie7updates\KB950759-IE7\urlmon.dll
+ 2007-08-13 13:24:10 1,162,240 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\urlmon.dll
- 2008-03-01 13:06:30 233,472 -c--a-w C:\WINDOWS\ie7updates\KB950759-IE7\webcheck.dll
+ 2007-08-13 13:24:10 231,424 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\webcheck.dll
- 2008-03-01 13:06:31 826,368 -c--a-w C:\WINDOWS\ie7updates\KB950759-IE7\wininet.dll
+ 2007-08-13 13:24:10 818,688 -c----w C:\WINDOWS\ie7updates\KB950759-IE7\wininet.dll
- 2006-02-28 12:00:00 100,352 ----a-w C:\WINDOWS\system32\6to4svc.dll
+ 2006-08-16 11:58:05 100,352 ----a-w C:\WINDOWS\system32\6to4svc.dll
- 2007-08-13 13:09:00 123,904 ----a-w C:\WINDOWS\system32\advpack.dll
+ 2008-04-23 04:16:28 124,928 ----a-w C:\WINDOWS\system32\advpack.dll
- 2006-02-28 12:00:00 66,560 ----a-w C:\WINDOWS\system32\cdm.dll
+ 2007-07-30 13:49:20 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
- 2006-02-28 12:00:00 100,352 -c--a-w C:\WINDOWS\system32\dllcache\6to4svc.dll
+ 2006-08-16 11:58:05 100,352 -c--a-w C:\WINDOWS\system32\dllcache\6to4svc.dll
- 2007-08-13 13:09:00 123,904 -c--a-w C:\WINDOWS\system32\dllcache\advpack.dll
+ 2008-04-23 04:16:28 124,928 -c--a-w C:\WINDOWS\system32\dllcache\advpack.dll
- 2006-02-28 12:00:00 138,496 -c--a-w C:\WINDOWS\system32\dllcache\afd.sys
+ 2008-06-20 10:44:38 138,368 -c--a-w C:\WINDOWS\system32\dllcache\afd.sys
- 2006-02-28 12:00:00 66,560 -c--a-w C:\WINDOWS\system32\dllcache\cdm.dll
+ 2007-07-30 13:49:20 92,504 -c--a-w C:\WINDOWS\system32\dllcache\cdm.dll
- 2006-02-28 12:00:00 561,179 -c--a-w C:\WINDOWS\system32\dllcache\dao360.dll
+ 2008-03-25 04:50:25 554,008 -c--a-w C:\WINDOWS\system32\dllcache\dao360.dll
- 2006-02-28 12:00:00 148,480 -c--a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
+ 2008-06-20 17:41:10 148,992 -c--a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
- 2007-08-13 13:05:46 346,624 -c--a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
+ 2008-04-23 04:16:28 347,136 -c--a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
- 2007-08-13 13:05:38 214,528 -c--a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
+ 2008-04-23 04:16:28 214,528 -c--a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
- 2007-08-13 13:24:10 131,584 -c--a-w C:\WINDOWS\system32\dllcache\extmgr.dll
+ 2008-04-23 04:16:28 133,120 -c--a-w C:\WINDOWS\system32\dllcache\extmgr.dll
- 2007-08-13 13:09:06 54,784 -c--a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
+ 2008-04-22 07:39:58 70,656 -c--a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
- 2007-08-13 13:09:26 152,064 -c--a-w C:\WINDOWS\system32\dllcache\ieakeng.dll
+ 2008-04-23 04:16:28 153,088 -c--a-w C:\WINDOWS\system32\dllcache\ieakeng.dll
- 2007-08-13 13:09:54 229,376 -c--a-w C:\WINDOWS\system32\dllcache\ieaksie.dll
+ 2008-04-23 04:16:28 230,400 -c--a-w C:\WINDOWS\system32\dllcache\ieaksie.dll
- 2007-08-13 12:26:54 161,792 -c--a-w C:\WINDOWS\system32\dllcache\ieakui.dll
+ 2008-04-20 05:07:51 161,792 -c--a-w C:\WINDOWS\system32\dllcache\ieakui.dll
- 2007-08-13 13:09:50 382,976 -c--a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll
+ 2008-04-23 04:16:28 384,512 -c--a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll
- 2007-08-13 13:09:10 43,008 -c--a-w C:\WINDOWS\system32\dllcache\iernonce.dll
+ 2008-04-23 04:16:28 44,544 -c--a-w C:\WINDOWS\system32\dllcache\iernonce.dll
- 2007-08-13 13:13:56 622,080 -c--a-w C:\WINDOWS\system32\dllcache\iexplore.exe
+ 2008-04-22 07:40:18 625,664 -c--a-w C:\WINDOWS\system32\dllcache\iexplore.exe
- 2007-08-13 13:24:10 27,136 -c--a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
+ 2008-04-23 04:16:28 27,648 -c--a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
- 2006-02-28 12:00:00 72,704 -c--a-w C:\WINDOWS\system32\dllcache\magnify.exe
+ 2006-10-04 08:48:36 72,704 -c--a-w C:\WINDOWS\system32\dllcache\magnify.exe
- 2006-02-28 12:00:00 294,400 -c--a-w C:\WINDOWS\system32\dllcache\msctf.dll
+ 2008-02-26 11:59:50 294,912 -c--a-w C:\WINDOWS\system32\dllcache\msctf.dll
- 2006-02-28 12:00:00 512,029 -c--a-w C:\WINDOWS\system32\dllcache\msexch40.dll
+ 2008-03-25 04:50:28 518,944 -c--a-w C:\WINDOWS\system32\dllcache\msexch40.dll
- 2006-02-28 12:00:00 319,517 -c--a-w C:\WINDOWS\system32\dllcache\msexcl40.dll
+ 2008-03-25 04:50:30 326,432 -c--a-w C:\WINDOWS\system32\dllcache\msexcl40.dll
- 2007-08-13 13:24:12 3,578,368 -c--a-w C:\WINDOWS\system32\dllcache\mshtml.dll
+ 2008-04-23 16:46:30 3,591,680 -c--a-w C:\WINDOWS\system32\dllcache\mshtml.dll
- 2007-08-13 13:24:10 475,648 -c--a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
+ 2008-04-23 04:16:28 478,208 -c--a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
- 2006-02-28 12:00:00 1,507,356 -c--a-w C:\WINDOWS\system32\dllcache\msjet40.dll
+ 2008-03-25 04:50:34 1,516,568 -c--a-w C:\WINDOWS\system32\dllcache\msjet40.dll
- 2006-02-28 12:00:00 358,976 -c--a-w C:\WINDOWS\system32\dllcache\msjetol1.dll
+ 2008-03-25 04:50:40 355,112 -c--a-w C:\WINDOWS\system32\dllcache\msjetol1.dll
- 2006-02-28 12:00:00 151,583 -c--a-w C:\WINDOWS\system32\dllcache\msjint40.dll
+ 2008-03-27 08:12:54 151,583 -c--a-w C:\WINDOWS\system32\dllcache\msjint40.dll
- 2006-02-28 12:00:00 53,279 -c--a-w C:\WINDOWS\system32\dllcache\msjter40.dll
+ 2008-03-25 04:50:42 60,192 -c--a-w C:\WINDOWS\system32\dllcache\msjter40.dll
- 2006-02-28 12:00:00 241,693 -c--a-w C:\WINDOWS\system32\dllcache\msjtes40.dll
+ 2008-03-25 04:50:42 248,608 -c--a-w C:\WINDOWS\system32\dllcache\msjtes40.dll
- 2006-02-28 12:00:00 213,023 -c--a-w C:\WINDOWS\system32\dllcache\msltus40.dll
+ 2008-03-25 04:50:44 219,936 -c--a-w C:\WINDOWS\system32\dllcache\msltus40.dll
- 2006-02-28 12:00:00 348,189 -c--a-w C:\WINDOWS\system32\dllcache\mspbde40.dll
+ 2008-03-25 04:50:45 355,104 -c--a-w C:\WINDOWS\system32\dllcache\mspbde40.dll
- 2007-08-13 13:14:26 192,000 -c--a-w C:\WINDOWS\system32\dllcache\msrating.dll
+ 2008-04-23 04:16:28 193,024 -c--a-w C:\WINDOWS\system32\dllcache\msrating.dll
- 2006-02-28 12:00:00 421,919 -c--a-w C:\WINDOWS\system32\dllcache\msrd2x40.dll
+ 2008-03-25 04:50:47 432,928 -c--a-w C:\WINDOWS\system32\dllcache\msrd2x40.dll
- 2006-02-28 12:00:00 315,423 -c--a-w C:\WINDOWS\system32\dllcache\msrd3x40.dll
+ 2008-03-25 04:50:49 322,336 -c--a-w C:\WINDOWS\system32\dllcache\msrd3x40.dll
- 2006-02-28 12:00:00 552,989 -c--a-w C:\WINDOWS\system32\dllcache\msrepl40.dll
+ 2008-03-25 04:50:52 559,904 -c--a-w C:\WINDOWS\system32\dllcache\msrepl40.dll
- 2006-02-28 12:00:00 258,077 -c--a-w C:\WINDOWS\system32\dllcache\mstext40.dll
+ 2008-03-25 04:50:55 264,992 -c--a-w C:\WINDOWS\system32\dllcache\mstext40.dll
- 2007-08-13 13:24:10 670,720 -c--a-w C:\WINDOWS\system32\dllcache\mstime.dll
+ 2008-04-23 04:16:28 671,232 -c--a-w C:\WINDOWS\system32\dllcache\mstime.dll
- 2006-02-28 12:00:00 831,519 -c--a-w C:\WINDOWS\system32\dllcache\mswdat10.dll
+ 2008-03-25 04:50:57 838,432 -c--a-w C:\WINDOWS\system32\dllcache\mswdat10.dll
- 2006-02-28 12:00:00 245,248 -c--a-w C:\WINDOWS\system32\dllcache\mswsock.dll
+ 2008-06-20 17:41:10 245,248 -c--a-w C:\WINDOWS\system32\dllcache\mswsock.dll
- 2006-02-28 12:00:00 614,429 -c--a-w C:\WINDOWS\system32\dllcache\mswstr10.dll
+ 2008-03-25 04:50:58 621,344 -c--a-w C:\WINDOWS\system32\dllcache\mswstr10.dll
- 2006-02-28 12:00:00 348,189 -c--a-w C:\WINDOWS\system32\dllcache\msxbde40.dll
+ 2008-03-25 04:50:58 355,104 -c--a-w C:\WINDOWS\system32\dllcache\msxbde40.dll
- 2006-02-28 12:00:00 53,760 -c--a-w C:\WINDOWS\system32\dllcache\narrator.exe
+ 2006-10-04 08:48:36 53,760 -c--a-w C:\WINDOWS\system32\dllcache\narrator.exe
- 2007-08-13 13:14:06 101,376 -c--a-w C:\WINDOWS\system32\dllcache\occache.dll
+ 2008-04-23 04:16:28 102,912 -c--a-w C:\WINDOWS\system32\dllcache\occache.dll
- 2006-02-28 12:00:00 215,552 -c--a-w C:\WINDOWS\system32\dllcache\osk.exe
+ 2006-10-04 08:48:37 215,552 -c--a-w C:\WINDOWS\system32\dllcache\osk.exe
- 2007-08-13 13:06:12 44,544 -c--a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
+ 2008-04-23 04:16:28 44,544 -c--a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
- 2006-02-28 12:00:00 1,287,680 -c--a-w C:\WINDOWS\system32\dllcache\quartz.dll
+ 2008-05-07 05:18:48 1,287,680 -c--a-w C:\WINDOWS\system32\dllcache\quartz.dll
- 2006-02-28 12:00:00 200,064 -c--a-w C:\WINDOWS\system32\dllcache\rmcast.sys
+ 2008-05-08 12:28:49 202,752 -c--a-w C:\WINDOWS\system32\dllcache\rmcast.sys
- 2006-02-28 12:00:00 359,040 -c--a-w C:\WINDOWS\system32\dllcache\tcpip.sys
+ 2008-06-20 10:45:13 360,320 -c--a-w C:\WINDOWS\system32\dllcache\tcpip.sys
- 2006-02-28 12:00:00 223,616 -c--a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
+ 2008-06-20 09:52:06 225,920 -c--a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
- 2006-02-28 12:00:00 35,840 -c--a-w C:\WINDOWS\system32\dllcache\umandlg.dll
+ 2006-10-04 13:33:38 35,840 -c--a-w C:\WINDOWS\system32\dllcache\umandlg.dll
- 2007-08-13 13:14:30 105,984 -c--a-w C:\WINDOWS\system32\dllcache\url.dll
+ 2008-04-23 04:16:28 105,984 -c--a-w C:\WINDOWS\system32\dllcache\url.dll
- 2007-08-13 13:24:10 1,162,240 -c--a-w C:\WINDOWS\system32\dllcache\urlmon.dll
+ 2008-04-23 04:16:29 1,159,680 -c--a-w C:\WINDOWS\system32\dllcache\urlmon.dll
- 2006-02-28 12:00:00 50,176 -c--a-w C:\WINDOWS\system32\dllcache\utilman.exe
+ 2006-10-04 08:48:37 50,176 -c--a-w C:\WINDOWS\system32\dllcache\utilman.exe
- 2007-08-13 13:24:10 765,952 -c--a-w C:\WINDOWS\system32\dllcache\VGX.dll
+ 2007-07-12 23:31:54 765,952 -c--a-w C:\WINDOWS\system32\dllcache\vgx.dll
- 2007-08-13 13:24:10 231,424 -c--a-w C:\WINDOWS\system32\dllcache\webcheck.dll
+ 2008-04-23 04:16:29 233,472 -c--a-w C:\WINDOWS\system32\dllcache\webcheck.dll
- 2007-08-13 13:24:10 818,688 -c--a-w C:\WINDOWS\system32\dllcache\wininet.dll
+ 2008-04-23 04:16:29 826,368 -c--a-w C:\WINDOWS\system32\dllcache\wininet.dll
- 2005-01-28 08:14:28 224,768 -c--a-w C:\WINDOWS\system32\dllcache\wmasf.dll
+ 2007-10-27 12:10:06 227,328 -c--a-w C:\WINDOWS\system32\dllcache\wmasf.dll
- 2005-01-28 08:14:28 2,370,296 -c--a-w C:\WINDOWS\system32\dllcache\wmvcore.dll
+ 2006-12-07 05:29:34 2,374,472 -c--a-w C:\WINDOWS\system32\dllcache\wmvcore.dll
- 2006-02-28 12:00:00 430,592 -c--a-w C:\WINDOWS\system32\dllcache\wuapi.dll
+ 2007-07-30 13:49:36 549,720 -c--a-w C:\WINDOWS\system32\dllcache\wuapi.dll
- 2006-02-28 12:00:00 111,104 -c--a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
+ 2007-07-30 13:49:16 53,080 -c--a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
- 2006-02-28 12:00:00 1,134,592 -c--a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
+ 2007-07-30 13:49:42 1,712,984 -c--a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
- 2006-02-28 12:00:00 112,640 -c--a-w C:\WINDOWS\system32\dllcache\wucltui.dll
+ 2007-07-30 13:49:32 325,976 -c--a-w C:\WINDOWS\system32\dllcache\wucltui.dll
- 2006-02-28 12:00:00 36,864 -c--a-w C:\WINDOWS\system32\dllcache\wups.dll
+ 2007-07-30 13:48:40 33,624 -c--a-w C:\WINDOWS\system32\dllcache\wups.dll
- 2006-02-28 12:00:00 120,320 -c--a-w C:\WINDOWS\system32\dllcache\wuweb.dll
+ 2007-07-30 13:49:28 203,096 -c--a-w C:\WINDOWS\system32\dllcache\wuweb.dll
- 2006-02-28 12:00:00 148,480 ----a-w C:\WINDOWS\system32\dnsapi.dll
+ 2008-06-20 17:41:10 148,992 ----a-w C:\WINDOWS\system32\dnsapi.dll
- 2006-02-28 12:00:00 200,064 ----a-w C:\WINDOWS\system32\drivers\RMCast.sys
+ 2008-05-08 12:28:49 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
- 2007-08-13 13:05:46 346,624 ----a-w C:\WINDOWS\system32\dxtmsft.dll
+ 2008-04-23 04:16:28 347,136 ----a-w C:\WINDOWS\system32\dxtmsft.dll
- 2007-08-13 13:05:38 214,528 ----a-w C:\WINDOWS\system32\dxtrans.dll
+ 2008-04-23 04:16:28 214,528 ----a-w C:\WINDOWS\system32\dxtrans.dll
- 2007-08-13 13:24:10 131,584 ----a-w C:\WINDOWS\system32\extmgr.dll
+ 2008-04-23 04:16:28 133,120 ----a-w C:\WINDOWS\system32\extmgr.dll
- 2007-08-13 13:09:06 54,784 ----a-w C:\WINDOWS\system32\ie4uinit.exe
+ 2008-04-22 07:39:58 70,656 ----a-w C:\WINDOWS\system32\ie4uinit.exe
- 2007-08-13 13:09:26 152,064 ----a-w C:\WINDOWS\system32\ieakeng.dll
+ 2008-04-23 04:16:28 153,088 ----a-w C:\WINDOWS\system32\ieakeng.dll
- 2007-08-13 13:09:54 229,376 ----a-w C:\WINDOWS\system32\ieaksie.dll
+ 2008-04-23 04:16:28 230,400 ----a-w C:\WINDOWS\system32\ieaksie.dll
- 2007-08-13 12:26:54 161,792 ----a-w C:\WINDOWS\system32\ieakui.dll
+ 2008-04-20 05:07:51 161,792 ----a-w C:\WINDOWS\system32\ieakui.dll
- 2007-08-13 13:09:50 382,976 ----a-w C:\WINDOWS\system32\iedkcs32.dll
+ 2008-04-23 04:16:28 384,512 ----a-w C:\WINDOWS\system32\iedkcs32.dll
- 2007-08-13 13:09:10 43,008 ----a-w C:\WINDOWS\system32\iernonce.dll
+ 2008-04-23 04:16:28 44,544 ----a-w C:\WINDOWS\system32\iernonce.dll
- 2007-08-13 13:09:10 13,312 ----a-w C:\WINDOWS\system32\ieudinit.exe
+ 2008-04-22 07:39:58 13,824 ----a-w C:\WINDOWS\system32\ieudinit.exe
- 2007-08-13 13:24:10 27,136 ----a-w C:\WINDOWS\system32\jsproxy.dll
+ 2008-04-23 04:16:28 27,648 ----a-w C:\WINDOWS\system32\jsproxy.dll
- 2006-02-28 12:00:00 72,704 ----a-w C:\WINDOWS\system32\magnify.exe
+ 2006-10-04 08:48:36 72,704 ----a-w C:\WINDOWS\system32\magnify.exe
- 2006-02-28 12:00:00 294,400 ----a-w C:\WINDOWS\system32\MSCTF.dll
+ 2008-02-26 11:59:50 294,912 ----a-w C:\WINDOWS\system32\msctf.dll
- 2006-02-28 12:00:00 512,029 ----a-w C:\WINDOWS\system32\msexch40.dll
+ 2008-03-25 04:50:28 518,944 ----a-w C:\WINDOWS\system32\msexch40.dll
- 2006-02-28 12:00:00 319,517 ----a-w C:\WINDOWS\system32\msexcl40.dll
+ 2008-03-25 04:50:30 326,432 ----a-w C:\WINDOWS\system32\msexcl40.dll
- 2007-08-13 13:24:12 3,578,368 ----a-w C:\WINDOWS\system32\mshtml.dll
+ 2008-04-23 16:46:30 3,591,680 ----a-w C:\WINDOWS\system32\mshtml.dll
- 2007-08-13 13:24:10 475,648 ----a-w C:\WINDOWS\system32\mshtmled.dll
+ 2008-04-23 04:16:28 478,208 ----a-w C:\WINDOWS\system32\mshtmled.dll
- 2006-02-28 12:00:00 1,507,356 ----a-w C:\WINDOWS\system32\msjet40.dll
+ 2008-03-25 04:50:34 1,516,568 ----a-w C:\WINDOWS\system32\msjet40.dll
- 2006-02-28 12:00:00 358,976 ----a-w C:\WINDOWS\system32\msjetoledb40.dll
+ 2008-03-25 04:50:40 355,112 ----a-w C:\WINDOWS\system32\msjetoledb40.dll
- 2006-02-28 12:00:00 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
+ 2008-03-27 08:12:54 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
- 2006-02-28 12:00:00 53,279 ----a-w C:\WINDOWS\system32\msjter40.dll
+ 2008-03-25 04:50:42 60,192 ----a-w C:\WINDOWS\system32\msjter40.dll
- 2006-02-28 12:00:00 241,693 ----a-w C:\WINDOWS\system32\msjtes40.dll
+ 2008-03-25 04:50:42 248,608 ----a-w C:\WINDOWS\system32\msjtes40.dll
- 2006-02-28 12:00:00 213,023 ----a-w C:\WINDOWS\system32\msltus40.dll
+ 2008-03-25 04:50:44 219,936 ----a-w C:\WINDOWS\system32\msltus40.dll
- 2006-02-28 12:00:00 348,189 ----a-w C:\WINDOWS\system32\mspbde40.dll
+ 2008-03-25 04:50:45 355,104 ----a-w C:\WINDOWS\system32\mspbde40.dll
- 2007-08-13 13:14:26 192,000 ----a-w C:\WINDOWS\system32\msrating.dll
+ 2008-04-23 04:16:28 193,024 ----a-w C:\WINDOWS\system32\msrating.dll
- 2006-02-28 12:00:00 421,919 ----a-w C:\WINDOWS\system32\msrd2x40.dll
+ 2008-03-25 04:50:47 432,928 ----a-w C:\WINDOWS\system32\msrd2x40.dll
- 2006-02-28 12:00:00 315,423 ----a-w C:\WINDOWS\system32\msrd3x40.dll
+ 2008-03-25 04:50:49 322,336 ----a-w C:\WINDOWS\system32\msrd3x40.dll
- 2006-02-28 12:00:00 552,989 ----a-w C:\WINDOWS\system32\msrepl40.dll
+ 2008-03-25 04:50:52 559,904 ----a-w C:\WINDOWS\system32\msrepl40.dll
- 2006-02-28 12:00:00 258,077 ----a-w C:\WINDOWS\system32\mstext40.dll
+ 2008-03-25 04:50:55 264,992 ----a-w C:\WINDOWS\system32\mstext40.dll
- 2007-08-13 13:24:10 670,720 ----a-w C:\WINDOWS\system32\mstime.dll
+ 2008-04-23 04:16:28 671,232 ----a-w C:\WINDOWS\system32\mstime.dll
- 2006-02-28 12:00:00 831,519 ----a-w C:\WINDOWS\system32\mswdat10.dll
+ 2008-03-25 04:50:57 838,432 ----a-w C:\WINDOWS\system32\mswdat10.dll
- 2006-02-28 12:00:00 614,429 ----a-w C:\WINDOWS\system32\mswstr10.dll
+ 2008-03-25 04:50:58 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
- 2006-02-28 12:00:00 348,189 ----a-w C:\WINDOWS\system32\msxbde40.dll
+ 2008-03-25 04:50:58 355,104 ----a-w C:\WINDOWS\system32\msxbde40.dll
- 2006-02-28 12:00:00 53,760 ----a-w C:\WINDOWS\system32\narrator.exe
+ 2006-10-04 08:48:36 53,760 ----a-w C:\WINDOWS\system32\narrator.exe
- 2007-08-13 13:14:06 101,376 ----a-w C:\WINDOWS\system32\occache.dll
+ 2008-04-23 04:16:28 102,912 ----a-w C:\WINDOWS\system32\occache.dll
- 2006-02-28 12:00:00 215,552 ----a-w C:\WINDOWS\system32\osk.exe
+ 2006-10-04 08:48:37 215,552 ----a-w C:\WINDOWS\system32\osk.exe
- 2008-08-05 19:46:32 91,968 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-08-08 13:41:57 75,142 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-08-05 19:46:32 502,732 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-08-08 13:41:57 454,016 ----a-w C:\WINDOWS\system32\perfh009.dat
- 2007-08-13 13:06:12 44,544 ----a-w C:\WINDOWS\system32\pngfilt.dll
+ 2008-04-23 04:16:28 44,544 ----a-w C:\WINDOWS\system32\pngfilt.dll
- 2006-02-28 12:00:00 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
+ 2008-05-07 05:18:48 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
- 2007-11-30 12:39:22 17,272 ----a-w C:\WINDOWS\system32\spmsg.dll
+ 2007-11-30 11:18:51 17,272 ------w C:\WINDOWS\system32\spmsg.dll
- 2007-11-13 11:31:11 60,416 ----a-w C:\WINDOWS\system32\tzchange.exe
+ 2008-03-27 09:24:20 60,416 ----a-w C:\WINDOWS\system32\tzchange.exe
- 2006-02-28 12:00:00 35,840 ----a-w C:\WINDOWS\system32\umandlg.dll
+ 2006-10-04 13:33:38 35,840 ----a-w C:\WINDOWS\system32\umandlg.dll
- 2007-08-13 13:14:30 105,984 ----a-w C:\WINDOWS\system32\url.dll
+ 2008-04-23 04:16:28 105,984 ----a-w C:\WINDOWS\system32\url.dll
- 2007-08-13 13:24:10 1,162,240 ----a-w C:\WINDOWS\system32\urlmon.dll
+ 2008-04-23 04:16:29 1,159,680 ----a-w C:\WINDOWS\system32\urlmon.dll
- 2006-02-28 12:00:00 50,176 ----a-w C:\WINDOWS\system32\utilman.exe
+ 2006-10-04 08:48:37 50,176 ----a-w C:\WINDOWS\system32\utilman.exe
- 2007-08-13 13:24:10 231,424 ----a-w C:\WINDOWS\system32\webcheck.dll
+ 2008-04-23 04:16:29 233,472 ----a-w C:\WINDOWS\system32\webcheck.dll
- 2007-08-13 13:24:10 818,688 ----a-w C:\WINDOWS\system32\wininet.dll
+ 2008-04-23 04:16:29 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
- 2005-01-28 08:14:28 224,768 ----a-w C:\WINDOWS\system32\wmasf.dll
+ 2007-10-27 12:10:06 227,328 ----a-w C:\WINDOWS\system32\wmasf.dll
- 2005-01-28 08:14:28 2,370,296 ----a-w C:\WINDOWS\system32\wmvcore.dll
+ 2006-12-07 05:29:34 2,374,472 ----a-w C:\WINDOWS\system32\wmvcore.dll
- 2006-02-28 12:00:00 430,592 ----a-w C:\WINDOWS\system32\wuapi.dll
+ 2007-07-30 13:49:36 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
- 2006-02-28 12:00:00 111,104 ----a-w C:\WINDOWS\system32\wuauclt.exe
+ 2007-07-30 13:49:16 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
- 2006-02-28 12:00:00 1,134,592 ----a-w C:\WINDOWS\system32\wuaueng.dll
+ 2007-07-30 13:49:42 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll
- 2006-02-28 12:00:00 112,640 ----a-w C:\WINDOWS\system32\wucltui.dll
+ 2007-07-30 13:49:32 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
- 2006-02-28 12:00:00 36,864 ----a-w C:\WINDOWS\system32\wups.dll
+ 2007-07-30 13:48:40 33,624 ----a-w C:\WINDOWS\system32\wups.dll
- 2006-02-28 12:00:00 120,320 ----a-w C:\WINDOWS\system32\wuweb.dll
+ 2007-07-30 13:49:28 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-03-23 09:43 77824]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-08-02 20:40 1232152]
"SkyTel"="SkyTel.EXE" [2006-05-16 15:34 2879488 C:\WINDOWS\SkyTel.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-11-14 14:51 16270848 C:\WINDOWS\RTHDCPL.EXE]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{A5949E07-8536-4625-A3D0-2DD83F559990}"= "C:\WINDOWS\system32\ShellHook.dll" [2007-12-13 03:29 86016]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=oykher.dll,zkrgkw.dll,avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.VDOM"= vdowave.drv
"VIDC.TR20"= tr2032.dll
"vidc.vivo"= ivvideo.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^LoadRunner Agent Process.lnk]
backup=C:\WINDOWS\pss\LoadRunner Agent Process.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AsusStartupHelp]
-ra--c--- 2006-11-14 11:55 363008 C:\Program Files\ASUS\AASP\1.00.17\AsRunHelp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a--c--- 2006-12-23 18:05 143360 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
--a------ 2006-11-10 16:19 1051648 C:\Program Files\Nero\Nero 7\InCD\InCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
--a--c--- 2006-12-05 22:55 54832 C:\Program Files\CyberLink\PowerDVD\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a--c--- 2006-01-12 15:40 155648 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a--c--- 2006-11-23 15:10 56928 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"CheckTestDirectorUserAccount"=3 (0x3)
"SandraTheSrv"=3 (0x3)
"SandraDataSrv"=3 (0x3)
"RichVideo"=2 (0x2)
"NMIndexingService"=3 (0x3)
"NBService"=3 (0x3)
"InCDsrv"=2 (0x2)
"gusvc"=2 (0x2)
"SCardSvr"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"igfxtray"=C:\WINDOWS\system32\igfxtray.exe
"igfxpers"=C:\WINDOWS\system32\igfxpers.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\uTorrent\\utorrent.exe"=
"C:\\Program Files\\Mercury\\LoadRunner\\launch_service\\bin\\magentproc.exe"=
"C:\\Program Files\\Mercury\\LoadRunner\\WebTours\\xigui32.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"=
"C:\\Program Files\\HP\\QuickTest Professional\\bin\\AQTRmtAgent.exe"=
"C:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\WINDOWS\\system32\\mqsvc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"135:TCP"= 135:TCP:DCOM
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-08-02 20:40]
R2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-08-02 20:40]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-02 20:40]
R2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-08-02 20:41]
R2 paldrv;paldrv;C:\WINDOWS\system32\pal_drv.sys [2005-07-27 18:03]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cf55fbcf-8ce7-11dc-a788-001a929060e6}]
\Shell\Auto\command - MicrosoftPowerPoint.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL MicrosoftPowerPoint.exe
.
Contents of the 'Scheduled Tasks' folder
2008-08-12 C:\WINDOWS\Tasks\WinASORegistryOptimizerForr.job
- C:\Program Files\WinASO\Registry Optimizer 3.0\RegOpt.exe []
.
- - - - ORPHANS REMOVED - - - -
BHO-{318F134D-1627-48A5-909A-8D1D9C82BDE0} - (no file)
BHO-{77ec9d57-249a-41a7-ad4a-5b9950a3f879} - (no file)
BHO-{83445c84-ddaa-4754-b246-dd10275cb6ea} - (no file)
BHO-{8658825D-21E5-4F04-8DB7-1AB67C8E8F6E} - (no file)
BHO-{C893C01E-6875-4AEE-AFC7-E33CC4A5B91F} - (no file)
BHO-{DCA900CF-450B-4E35-9169-66767F2F9D67} - (no file)
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-12 21:33:27
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-08-12 21:35:27
ComboFix-quarantined-files.txt 2008-08-12 16:04:58
ComboFix2.txt 2008-08-11 10:05:43
ComboFix3.txt 2008-08-07 14:43:22
Pre-Run: 13,574,078,464 bytes free
Post-Run: 13,578,428,416 bytes free
624 --- E O F --- 2008-08-12 15:54:26