silversun
2009-01-15, 04:37
ComboFix 09-01-13.04 - Sam 2009-01-14 18:28:32.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.546 [GMT -8:00]
Running from: C:\Combo-Fix.exe
Command switches used :: C:\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Sam\Application Data\Google\spclrp.dll
c:\documents and settings\Sam\Application Data\uTorrent
c:\documents and settings\Sam\Application Data\uTorrent\1965 - Highway 61 Revisited.torrent
c:\documents and settings\Sam\Application Data\uTorrent\1966 - Blonde On Blonde.torrent
c:\documents and settings\Sam\Application Data\uTorrent\1975 - Blood On The Tracks.torrent
c:\documents and settings\Sam\Application Data\uTorrent\A Colbert Christmas - The Greatest Gift of All! - v0 vbr.torrent
c:\documents and settings\Sam\Application Data\uTorrent\A Hundred Things Keep Me Up At Night.torrent
c:\documents and settings\Sam\Application Data\uTorrent\a.c. newman - 2009 - get guilty.torrent
c:\documents and settings\Sam\Application Data\uTorrent\All We Could Do Was Sing (V0).torrent
c:\documents and settings\Sam\Application Data\uTorrent\Alone II_ The Home Recordings of Rivers Cuomo.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Andrew Bird-Noble Beast.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Animal Collective - Campfire Songs.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Animal Collective - Danse Manatee.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Animal Collective - Merriweather Post Pavilon (V0).torrent
c:\documents and settings\Sam\Application Data\uTorrent\Animal Collective - Spirit They're Gone, Spirit They've Vanished.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Anna Ternheim - 2008 - Anna Sings Sinatra (Leaving On A Mayday Bonus Disc)_.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Anna Ternheim - 2008 - Leaving On A Mayday.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Antarctica_Takes_It-The_Penguin_League-(CDR)-2006.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Arcade Fire - Neon Bible (V0).torrent
c:\documents and settings\Sam\Application Data\uTorrent\Are We Not Horses.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Art Brut - 2005 - Bang Bang Rock & Roll - V0.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Ballast[2008]DvDrip-aXXo.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Band of Horses - Everything All the Time.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Beach House - Devotion [2008].torrent
c:\documents and settings\Sam\Application Data\uTorrent\Beach House.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Belle & Sebastian - The Boy With The Arab Strap (1998).torrent
c:\documents and settings\Sam\Application Data\uTorrent\Belle and Sebastian - Tigermilk.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Bloc Party - A Weekend In The City Instrumentals.torrent
c:\documents and settings\Sam\Application Data\uTorrent\bloc_party-silent_alarm-[2005].torrent
c:\documents and settings\Sam\Application Data\uTorrent\Brand New - Your Favorite Weapon [V0].torrent
c:\documents and settings\Sam\Application Data\uTorrent\Cat Spectacular FLAC.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Cut_Copy-In_Ghost_Colours-2008.torrent
c:\documents and settings\Sam\Application Data\uTorrent\dht.dat
c:\documents and settings\Sam\Application Data\uTorrent\dht.dat.old
c:\documents and settings\Sam\Application Data\uTorrent\Do You Believe in Gosh.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Dog House Music.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Drum's Not Dead.torrent
c:\documents and settings\Sam\Application Data\uTorrent\empire! empire! (i was a lonely estate) - when the sea became a giant (2007).torrent
c:\documents and settings\Sam\Application Data\uTorrent\Exposion (V0).torrent
c:\documents and settings\Sam\Application Data\uTorrent\Fall_Out_Boy-Folie_A_Deux-2008-FALLOUTBOY.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Fleet Foxes (2008) [V0].torrent
c:\documents and settings\Sam\Application Data\uTorrent\Fleet Foxes.torrent
c:\documents and settings\Sam\Application Data\uTorrent\For Emma, Forever Ago.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Frightened Rabbit - Liver! Lung! FR!.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Fringe.S01E01.HDTV.XviD-NoTV.avi.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Gang Gang Dance Saint Dymphna 2008.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Ghostface Killah - Fishscale (2006) [MP3 V0(VBR)].torrent
c:\documents and settings\Sam\Application Data\uTorrent\Gimme Fiction.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Glasvegas.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Grouper - Dragging a Dead Deer Up a Hill V0.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Here Comes The Indian.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Here We Go Magic.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Heroes.S03E01.HDTV.XviD-0TV.avi.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Heroes.S03E02.HDTV.XviD-XOR.avi.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Hold On Now Youngster.torrent
c:\documents and settings\Sam\Application Data\uTorrent\hold s v0.torrent
c:\documents and settings\Sam\Application Data\uTorrent\HSBoys&Girls.torrent
c:\documents and settings\Sam\Application Data\uTorrent\If You're Feeling Sinister.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Illinois (2005).torrent
c:\documents and settings\Sam\Application Data\uTorrent\Jens Lekman - Night Falls Over Kortedala (V0 MP3).torrent
c:\documents and settings\Sam\Application Data\uTorrent\Joanna Newsom - Ys.torrent
c:\documents and settings\Sam\Application Data\uTorrent\John Frusciante - Shadows collide with people.torrent
c:\documents and settings\Sam\Application Data\uTorrent\John Frusciante - Smile From The Streets You Hold.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Kanye_West-Robocop_(Promo_CDS)-2008-.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Laura Marling - [2008] - Cross Your Fingers [single].torrent
c:\documents and settings\Sam\Application Data\uTorrent\Laura Marling Alas I Cannot Swin V0.torrent
c:\documents and settings\Sam\Application Data\uTorrent\LCD Soundsystem - 4533.torrent
c:\documents and settings\Sam\Application Data\uTorrent\LCD Soundsystem - LCD Soundsystem (V0).torrent
c:\documents and settings\Sam\Application Data\uTorrent\LCD Soundsystem - Sound Of Silver (2007) [V0].torrent
c:\documents and settings\Sam\Application Data\uTorrent\Liars - Liars (V0).torrent
c:\documents and settings\Sam\Application Data\uTorrent\Lisa Hannigan - Sea Sew (2008).torrent
c:\documents and settings\Sam\Application Data\uTorrent\Los_Campesinos-We_Are_Beautiful_We_Are_Doomed-(Promo)-2008-DV8.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Ludacris - Theater of the Mind [V0].torrent
c:\documents and settings\Sam\Application Data\uTorrent\Man Man - Little Torments.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Man Man - Rabbit Habits [2008].torrent
c:\documents and settings\Sam\Application Data\uTorrent\Man Man - Six Demon Bag [2006].torrent
c:\documents and settings\Sam\Application Data\uTorrent\Man Man - The Man in a Blue Turban with a Face [V0] (2004).torrent
c:\documents and settings\Sam\Application Data\uTorrent\Marching_Band-Spark_Large-2008-RTB.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Margot & the Nuclear So and So's~Not Animal (V0)-2008-iNK.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Margot and the Nuclear So & So's - Animal! [V0].torrent
c:\documents and settings\Sam\Application Data\uTorrent\Marnie Stern - This Is It And I Am It And You Are It And So Is That And He Is It And She Is It And It Is It And That Is That [KRS].torrent
c:\documents and settings\Sam\Application Data\uTorrent\Math and Physics Club - Math and Physics Club.torrent
c:\documents and settings\Sam\Application Data\uTorrent\mewithoutYou- Brother, Sister [V0].torrent
c:\documents and settings\Sam\Application Data\uTorrent\Miwa Gemini - This Is How I Found You (2008).torrent
c:\documents and settings\Sam\Application Data\uTorrent\Mother Mother - O My Heart V2.torrent
c:\documents and settings\Sam\Application Data\uTorrent\MPP.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Muppet Show Album 1 (1977).torrent
c:\documents and settings\Sam\Application Data\uTorrent\No Age- Nouns 320.torrent
c:\documents and settings\Sam\Application Data\uTorrent\No Age.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Noah And The Whale - Peaceful, The World Lays Me Down - 2008 V0.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Notorious B.I.G (Acapella).torrent
c:\documents and settings\Sam\Application Data\uTorrent\Of Montreal - Hissing Fauna, Are You the Destroyer (V0).torrent
c:\documents and settings\Sam\Application Data\uTorrent\Of Montreal - Skeletal Lamping.torrent
c:\documents and settings\Sam\Application Data\uTorrent\One Piece 1 - 300.torrent
c:\documents and settings\Sam\Application Data\uTorrent\One Piece.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Panda Bear - [2007] Person Pitch.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Portishead - Third (2008) [MP3-V0].torrent
c:\documents and settings\Sam\Application Data\uTorrent\Post-War.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Raconteurs - Consolers Of The Lonely (V0).torrent
c:\documents and settings\Sam\Application Data\uTorrent\Relient K - mmhmm.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Relient_K-AP_Acoustic_Session-(EP)-2007-MP3_INT.torrent
c:\documents and settings\Sam\Application Data\uTorrent\resume.dat
c:\documents and settings\Sam\Application Data\uTorrent\resume.dat.1.bad
c:\documents and settings\Sam\Application Data\uTorrent\resume.dat.old
c:\documents and settings\Sam\Application Data\uTorrent\rivers_cuomo-acoustic_session-2004-fnx.torrent
c:\documents and settings\Sam\Application Data\uTorrent\rss.dat
c:\documents and settings\Sam\Application Data\uTorrent\rss.dat.old
c:\documents and settings\Sam\Application Data\uTorrent\Seasick Steve - 2008 - I Started Out With Nothing And I Still Got Most Of It Left (Die Cut Limited Edition).torrent
c:\documents and settings\Sam\Application Data\uTorrent\Separation Sunday [V0].torrent
c:\documents and settings\Sam\Application Data\uTorrent\settings.dat
c:\documents and settings\Sam\Application Data\uTorrent\settings.dat.old
c:\documents and settings\Sam\Application Data\uTorrent\She & Him - Volume One V0.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Silent Shout.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Silver Jews - Lookout Mountain, Lookout Sea [V0].torrent
c:\documents and settings\Sam\Application Data\uTorrent\Six Feet Under Season3 (XviD asd) EnglishV+NapisyPL - www.tvshows.yoyo.pl.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Snoop_Dogg_Presents_Christmas_In_Tha_Dogg_House-2008.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Space Ghost's Surf & Turf.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Space Ghost- Musical Bar-B-Que.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Space Ghost - The Brak Album.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Steel Train (2007) Trampoline.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Sticking Fingers into Sockets [EP].torrent
c:\documents and settings\Sam\Application Data\uTorrent\Studio-Yearbook 1.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Sufjan Stevens.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Sunset Rubdown - 2006 - Shut Up, I Am Dreaming.torrent
c:\documents and settings\Sam\Application Data\uTorrent\T.V. on the Radio - Dear Science (V0).torrent
c:\documents and settings\Sam\Application Data\uTorrent\Tennesee Pusher.torrent
c:\documents and settings\Sam\Application Data\uTorrent\That's Stupid (The Mixtape) [2008].torrent
c:\documents and settings\Sam\Application Data\uTorrent\The City On Christmas.torrent
c:\documents and settings\Sam\Application Data\uTorrent\The Dodos - Beware of the Maniacs.torrent
c:\documents and settings\Sam\Application Data\uTorrent\The Dodos - Visiter.torrent
c:\documents and settings\Sam\Application Data\uTorrent\The Field - From Here We Go Sublime.torrent
c:\documents and settings\Sam\Application Data\uTorrent\The Flaming Lips - Silent Night 7_ (V0).torrent
c:\documents and settings\Sam\Application Data\uTorrent\The Flaming Lips - Yoshimi Battles The Pink Robots [Instrumental].torrent
c:\documents and settings\Sam\Application Data\uTorrent\The Flaming Lips - Yoshimi Battles The Pink Robots.torrent
c:\documents and settings\Sam\Application Data\uTorrent\The Grates - Teeth Won, Hearts Lost (2008) (V0).torrent
c:\documents and settings\Sam\Application Data\uTorrent\The Kids Don't Stand A Chance EP.torrent
c:\documents and settings\Sam\Application Data\uTorrent\The Places You Have Come To Fear The Most.torrent
c:\documents and settings\Sam\Application Data\uTorrent\The Very Best.torrent
c:\documents and settings\Sam\Application Data\uTorrent\The Weepies [2008] Hideaway.torrent
c:\documents and settings\Sam\Application Data\uTorrent\The White Stripes - Elephant.torrent
c:\documents and settings\Sam\Application Data\uTorrent\The.Foot.Fist.Way.LIMITED.DVDRip.XviD-SAPHiRE.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Twin Cinema.torrent
c:\documents and settings\Sam\Application Data\uTorrent\utorrent.lng
c:\documents and settings\Sam\Application Data\uTorrent\Various Artists - 2001 - Colonel Jeffrey Pumpernickel - A Concept Album [V0].torrent
c:\documents and settings\Sam\Application Data\uTorrent\Verbs (V0).torrent
c:\documents and settings\Sam\Application Data\uTorrent\Vivian Girls — Vivian Girls [2008-V0].torrent
c:\documents and settings\Sam\Application Data\uTorrent\Water curses2.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Weezer - [1994] Blue Album.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Weezer - [1996] Pinkerton.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Weezer - Christmas with Weezer 2008.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Who Killed Amanda Palmer v0 MP3.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Why - Alopecia (2008) [V0].torrent
c:\documents and settings\Sam\Application Data\uTorrent\Wolf Parade~At Mount Zoomer-2008 (V0)-iNK.torrent
c:\documents and settings\Sam\Application Data\uTorrent\Yellow House (2006).torrent
.
((((((((((((((((((((((((( Files Created from 2008-12-15 to 2009-01-15 )))))))))))))))))))))))))))))))
.
2010-07-02 12:30 . 2008-06-13 03:05 272,128 --a------ c:\windows\system32\drivers\bthport.sys
2010-07-02 12:29 . 2009-01-14 03:25 <DIR> d--h----- c:\windows\$hf_mig$
2010-07-02 12:28 . 2010-07-02 12:29 <DIR> d-------- c:\windows\I386
2009-01-11 17:20 . 2009-01-11 17:20 <DIR> d-------- c:\windows\system32\LogFiles
2009-01-11 17:20 . 2009-01-11 17:20 <DIR> d-------- c:\windows\system32\drivers\UMDF
2009-01-11 17:17 . 2009-01-11 17:17 <DIR> d-------- c:\program files\Netflix
2009-01-11 14:58 . 2009-01-14 18:26 3,039,899 -ra------ C:\Combo-Fix.exe
2009-01-10 22:05 . 2009-01-10 22:12 <DIR> d-------- C:\gmer
2009-01-05 14:39 . 2009-01-05 14:39 <DIR> d-------- c:\program files\Trend Micro
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-12 22:44 --------- d-----w c:\documents and settings\Sam\Application Data\OpenOffice.org2
2009-01-12 02:30 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-12 02:28 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-01-12 01:01 --------- d-----w c:\documents and settings\Sam\Application Data\Skype
2009-01-11 05:59 --------- d-----w c:\documents and settings\Sam\Application Data\skypePM
2008-12-29 09:32 1,760 ----a-w c:\documents and settings\Sam\Application Data\wklnhst.dat
2008-12-14 01:02 --------- d-----w c:\program files\Common Files\Adobe
2008-12-14 00:59 --------- d-----w c:\program files\Common Files\Adobe Systems Shared
2008-12-14 00:54 --------- d-----w c:\documents and settings\Sam\Application Data\DAEMON Tools Lite
2008-12-14 00:53 --------- d-----w c:\documents and settings\Sam\Application Data\DAEMON Tools Pro
2008-12-14 00:53 --------- d-----w c:\documents and settings\Sam\Application Data\DAEMON Tools
2008-12-14 00:52 --------- d-----w c:\program files\DAEMON Tools Lite
2008-12-14 00:52 --------- d-----w c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2008-12-14 00:49 717,296 ----a-w c:\windows\system32\drivers\sptd.sys
2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys
2008-12-01 05:43 --------- d-----w c:\documents and settings\All Users\Application Data\STOPzilla!
2008-12-01 05:36 --------- d-----w c:\documents and settings\All Users\Application Data\SITEguard
2008-12-01 05:35 --------- d-----w c:\program files\Common Files\iS3
2008-11-26 07:23 --------- d-----w c:\documents and settings\All Users\Application Data\avg8
2008-11-26 07:20 76,040 ----a-w c:\windows\system32\drivers\avgtdix.sys
2008-11-26 07:20 10,520 ----a-w c:\windows\system32\avgrsstx.dll
2008-11-26 07:19 97,928 ----a-w c:\windows\system32\drivers\avgldx86.sys
2008-11-26 07:19 --------- d-----w c:\program files\AVG
2008-11-26 07:19 --------- d-----w c:\documents and settings\Sam\Application Data\AVGTOOLBAR
2008-11-26 07:02 --------- d-----w c:\documents and settings\Sam\Application Data\InstallShield
2008-11-26 07:02 --------- d-----w c:\documents and settings\Sam\Application Data\Final Draft
2008-11-26 07:02 --------- d-----w c:\documents and settings\Sam\Application Data\Apple Computer
2008-11-26 07:02 --------- d-----w c:\documents and settings\Sam\Application Data\acccore
2008-11-26 06:54 295,424 ----a-w c:\windows\system32\termsrv.dll
2008-11-21 10:24 --------- d-----w c:\program files\iTunes
2008-11-21 10:24 --------- d-----w c:\program files\iPod
2008-11-21 10:24 --------- d-----w c:\program files\Common Files\Apple
2008-11-21 10:24 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-21 10:22 --------- d-----w c:\program files\QuickTime
2008-11-19 09:28 --------- d-----w c:\program files\coolpro2
2008-10-27 03:25 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 22:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 22:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 22:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 22:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 22:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 22:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 22:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 22:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 22:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 22:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-16 01:00 666,112 ----a-w c:\windows\system32\wininet.dll
2008-05-07 23:34 15,523,560 ----a-w c:\program files\U1 Setup.exe
.
------- Sigcheck -------
2008-11-25 22:54 295424 63999d0abd8dabfd76a9c07f6e104868 c:\windows\system32\termsrv.dll
2008-04-14 04:00 295424 ff3477c03be7201c294c35f684b3479f c:\windows\system32\dllcache\termsrv.dll
.
((((((((((((((((((((((((((((( snapshot@2009-01-11_15.13.46.01 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-10-05 04:16:46 1,887,080 ----a-w c:\windows\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe
- 2000-08-31 16:00:00 28,672 ----a-w c:\windows\NIRCMD.exe
+ 2000-08-31 16:00:00 29,696 ----a-w c:\windows\NIRCMD.exe
- 2008-09-08 10:41:42 333,824 -c--a-w c:\windows\system32\dllcache\srv.sys
+ 2008-12-11 10:57:09 333,952 -c--a-w c:\windows\system32\dllcache\srv.sys
+ 2006-09-29 02:55:50 77,568 ------w c:\windows\system32\drivers\WudfPf.sys
+ 2006-09-29 03:00:34 82,944 ------w c:\windows\system32\drivers\WudfRd.sys
+ 2008-10-05 03:16:26 235,936 ----a-r c:\windows\system32\Macromed\Flash\FlashUtil10a.exe
+ 2009-01-12 01:14:43 89,102 ----a-w c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
- 2008-12-09 23:24:37 17,593,280 ----a-w c:\windows\system32\MRT.exe
+ 2009-01-10 01:35:28 20,853,704 ----a-w c:\windows\system32\MRT.exe
- 2009-01-11 23:08:42 53,684 ----a-w c:\windows\system32\perfc009.dat
+ 2009-01-14 21:57:16 53,684 ----a-w c:\windows\system32\perfc009.dat
- 2009-01-11 23:08:42 381,794 ----a-w c:\windows\system32\perfh009.dat
+ 2009-01-14 21:57:16 381,794 ----a-w c:\windows\system32\perfh009.dat
- 2005-02-25 03:35:05 22,752 ----a-w c:\windows\system32\spupdsvc.exe
+ 2006-09-16 09:05:22 23,856 ----a-w c:\windows\system32\spupdsvc.exe
+ 2006-09-29 04:13:26 95,344 ------w c:\windows\system32\WUDFCoinstaller.dll
+ 2006-09-29 02:56:38 146,432 ------w c:\windows\system32\WudfHost.exe
+ 2006-09-29 02:56:16 165,376 ------w c:\windows\system32\WudfPlatform.dll
+ 2006-09-29 02:56:14 55,808 ------w c:\windows\system32\WudfSvc.dll
+ 2006-09-29 02:56:38 316,416 ------w c:\windows\system32\WUDFx.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Google Update"="c:\documents and settings\Sam\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-11-12 133104]
"HPsetm"="c:\documents and settings\Sam\Application Data\Google\ijdkq13324484.exe" [2008-11-25 102912]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-10 216520]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072]
"AsusTray"="c:\program files\EeePC\ACPI\AsTray.exe" [2008-06-03 98304]
"AsusACPIServer"="c:\program files\EeePC\ACPI\AsAcpiSvr.exe" [2008-06-03 479232]
"AsusEPCMonitor"="c:\program files\EeePC\ACPI\AsEPCMon.exe" [2008-05-21 94208]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 144784]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2008-05-20 335872]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-11 1261336]
"RTHDCPL"="RTHDCPL.EXE" [2008-05-26 c:\windows\RTHDCPL.exe]
"SoundMan"="SOUNDMAN.EXE" [2006-07-21 c:\windows\SoundMan.exe]
"AlcWzrd"="ALCWZRD.EXE" [2006-05-04 c:\windows\alcwzrd.exe]
c:\documents and settings\Sam\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-04-14 596584]
SuperHybridEngine.lnk - c:\program files\Asus\EeePC\Super Hybrid Engine\SuperHybridEngine.exe [2008-06-26 294912]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2007-10-10 18:51 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 10:34 5724184 c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Documents and Settings\\Sam\\Desktop\\utorrent.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-11-25 97928]
R3 AsusACPI;ASUS ACPI Driver;c:\windows\system32\drivers\ASUSACPI.SYS [2008-06-26 11264]
R3 Ktp;Elantech Smart-Pad;c:\windows\system32\drivers\ETD.sys [2008-05-21 25088]
R3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1e51x86.sys [2008-06-26 36864]
R3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [2008-06-26 625024]
R4 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-11-25 875288]
R4 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-11-25 231704]
R4 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-11-25 76040]
R4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2008-09-12 24652]
.
Contents of the 'Scheduled Tasks' folder
2009-01-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2009-01-15 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 10:20]
2009-01-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2241859383-359463628-3350175285-1006.job
- c:\documents and settings\Sam\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-12 12:41]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://eeepc.asus.com/global
uInternet Connection Wizard,ShellNext = hxxp://eeepc.asus.com/global
uInternet Settings,ProxyOverride = *.local
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\documents and settings\Sam\Application Data\Mozilla\Firefox\Profiles\gh273u37.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.ihatemylife.us/jobs/
FF - plugin: c:\documents and settings\Sam\Local Settings\Application Data\Google\Update\1.2.133.33\npGoogleOneClick7.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-14 18:33:11
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•A~*]
"AB141C35E9F4BF344B9FC010BB17F68A"=""
.
------------------------ Other Running Processes ------------------------
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\wbem\wmiadap.exe
.
**************************************************************************
.
Completion time: 2009-01-14 18:36:19 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-15 02:36:13
ComboFix2.txt 2009-01-11 23:16:03
Pre-Run: 8,022,114,304 bytes free
Post-Run: 8,045,408,256 bytes free
374 --- E O F --- 2009-01-14 11:25:53
silversun
2009-01-18, 01:56
File termsrv.dll received on 01.18.2009 00:51:40 (CET)
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED
Result: 0/39 (0%)
File termsrv.dll received on 01.18.2009 00:51:40 (CET)
Antivirus Version Last Update Result
a-squared 4.0.0.73 2009.01.17 -
AhnLab-V3 2009.1.15.0 2009.01.17 -
AntiVir 7.9.0.57 2009.01.17 -
Authentium 5.1.0.4 2009.01.17 -
Avast 4.8.1281.0 2009.01.16 -
AVG 8.0.0.229 2009.01.17 -
BitDefender 7.2 2009.01.18 -
CAT-QuickHeal 10.00 2009.01.17 -
ClamAV 0.94.1 2009.01.17 -
Comodo 934 2009.01.17 -
DrWeb 4.44.0.09170 2009.01.18 -
eSafe 7.0.17.0 2009.01.15 -
eTrust-Vet 31.6.6312 2009.01.17 -
F-Prot 4.4.4.56 2009.01.17 -
F-Secure 8.0.14470.0 2009.01.17 -
Fortinet 3.117.0.0 2009.01.15 -
GData 19 2009.01.18 -
Ikarus T3.1.1.45.0 2009.01.17 -
K7AntiVirus 7.10.594 2009.01.17 -
Kaspersky 7.0.0.125 2009.01.18 -
McAfee 5498 2009.01.17 -
McAfee+Artemis 5498 2009.01.17 -
Microsoft 1.4205 2009.01.17 -
NOD32 3774 2009.01.17 -
Norman 5.93.01 2009.01.16 -
nProtect 2009.1.8.0 2009.01.16 -
Panda 9.5.1.2 2009.01.17 -
PCTools 4.4.2.0 2009.01.17 -
Prevx1 V2 2009.01.18 -
Rising 21.12.52.00 2009.01.17 -
SecureWeb-Gateway 6.7.6 2009.01.17 -
Sophos 4.37.0 2009.01.17 -
Sunbelt 3.2.1835.2 2009.01.16 -
Symantec 10 2009.01.18 -
TheHacker 6.3.1.5.222 2009.01.17 -
TrendMicro 8.700.0.1004 2009.01.16 -
VBA32 3.12.8.10 2009.01.17 -
ViRobot 2009.1.17.1563 2009.01.17 -
VirusBuster 4.5.11.0 2009.01.17 -
Additional information
File size: 295424 bytes
MD5...: 63999d0abd8dabfd76a9c07f6e104868
SHA1..: 509689ba3edd2cfad361773708b72dc35f1c77b8
SHA256: 5f6f0507b9ec1e8843363ea312475e9e6dd129e03ecb5308db285cd15fdfd482
SHA512: 2b13e8fecc4970fc2a812ff8f71e56cc3398aba89b97b99c865181de1e92ea34<br>96aeb602f4bda58cf35f01a09f49059334f63ea6aae02b4861b42375ebf408bb<br>
ssdeep: 6144:BRp6fWMV1Adl7LQup17zettU8kY0c0XwJs/nE0fiLitmNGAM:BPvMV1/ixe<br>ttmXwu/nHtc8<br>
PEiD..: -
TrID..: File type identification<br>Win64 Executable Generic (80.9%)<br>Win32 Executable Generic (8.0%)<br>Win32 Dynamic Link Library (generic) (7.1%)<br>Generic Win/DOS Executable (1.8%)<br>DOS Executable Generic (1.8%)
PEInfo: PE Structure information<br><br>( base data )<br>entrypointaddress.: 0x761119fd<br>timedatestamp.....: 0x4802a11c (Mon Apr 14 00:11:08 2008)<br>machinetype.......: 0x14c (I386)<br><br>( 4 sections )<br>name viradd virsiz rawdsiz ntrpy md5<br>.text 0x1000 0x3f7ca 0x3f800 6.62 d12183a6fa34bf7974abe33c87bdee41<br>.data 0x41000 0x9838 0x1200 5.40 2c69a08d65ee8234c239668dd7d86937<br>.rsrc 0x4b000 0x3e50 0x4000 3.25 07385c44d1453e3272809960a81ac436<br>.reloc 0x4f000 0x32ee 0x3400 6.19 c59c84e9cda7289330e30d991fa19248<br><br>( 17 imports ) <br>> msvcrt.dll: wcscpy, wcscmp, _except_handler3, _wcsnicmp, wcscat, swscanf, wcsncpy, wcslen, wcsncat, swprintf, wcsrchr, memmove, _snwprintf, wcschr, sprintf, qsort, strncpy, gmtime, time, mktime, _mbslen, mbstowcs, __3@YAXPAX@Z, __2@YAPAXI@Z, free, _initterm, malloc, _adjust_fdiv, _ftol, _snprintf, strncmp, iswdigit, _wcsupr, wcstok, _wtol, _stricmp, __CxxFrameHandler, _purecall, _wcsicmp<br>> ntdll.dll: NtOpenProcessToken, NtQueryInformationToken, RtlLengthSid, RtlCopySid, NtAllocateVirtualMemory, NtFreeVirtualMemory, RtlAcquireResourceShared, NtDelayExecution, DbgBreakPoint, RtlPrefixUnicodeString, NtResetEvent, NtWaitForMultipleObjects, RtlInitializeGenericTable, RtlDeleteCriticalSection, NtOpenProcess, NtQueryVirtualMemory, RtlLookupElementGenericTable, RtlCompareMemory, RtlInsertElementGenericTable, RtlDeleteElementGenericTable, RtlInitializeResource, NtCreateEvent, NtDuplicateObject, NtQuerySystemTime, RtlEqualSid, RtlAdjustPrivilege, RtlInitializeCriticalSection, NtTerminateProcess, RtlLengthRequiredSid, NtReleaseMutant, NtWaitForSingleObject, NtCreateMutant, NtQueryInformationProcess, NtDuplicateToken, NtSetInformationThread, RtlpNtEnumerateSubKey, NtRequestPort, NtConnectPort, NtSetEvent, RtlEnterCriticalSection, RtlAllocateHeap, NtOpenThreadToken, NtReplyPort, NtCompleteConnectPort, NtAcceptConnectPort, NtCreateSection, NtReplyWaitReceivePort, RtlFreeUnicodeString, NtCreatePort, RtlAnsiStringToUnicodeString, RtlInitAnsiString, RtlQueryRegistryValues, NtDeviceIoControlFile, RtlExtendedLargeIntegerDivide, RtlConvertExclusiveToShared, RtlConvertSharedToExclusive, RtlDeleteResource, NtRequestWaitReplyPort, RtlFreeHeap, RtlLeaveCriticalSection, RtlAcquireResourceExclusive, RtlReleaseResource, RtlInitUnicodeString, NtOpenKey, NtQueryValueKey, NtClose, VerSetConditionMask, RtlCreateEnvironment, RtlSetProcessIsCritical, DbgPrint, NtQuerySystemInformation, NtSetTimer, NtCreateTimer, RtlCopySecurityDescriptor, RtlNtStatusToDosError, RtlDeleteAce, RtlGetAce, RtlQueryInformationAcl, RtlGetDaclSecurityDescriptor, RtlMapGenericMask, RtlSubAuthoritySid, RtlInitializeSid, RtlCreateUserSecurityObject, RtlSetDaclSecurityDescriptor, RtlAddAccessAllowedAce, RtlCreateAcl, RtlCreateSecurityDescriptor, RtlWriteRegistryValue, RtlCreateRegistryKey, RtlLengthSecurityDescriptor, RtlSetGroupSecurityDescriptor, RtlGetGroupSecurityDescriptor, RtlGetOwnerSecurityDescriptor, NtSetSecurityObject, NtQuerySecurityObject, NtOpenSymbolicLinkObject, NtQueryDirectoryObject, NtCreateDirectoryObject, RtlFreeSid, RtlAllocateAndInitializeSid, RtlIntegerToUnicodeString, RtlAppendUnicodeToString, NtQueryMutant<br>> ICAAPI.dll: IcaOpen, IcaStackCallback, IcaStackConnectionWait, IcaStackConnectionRequest, IcaStackConnectionAccept, _IcaStackIoControl, IcaStackUnlock, IcaStackReconnect, IcaStackTerminate, IcaChannelClose, IcaStackIoControl, IcaPushConsoleStack, IcaChannelOpen, IcaChannelIoControl, IcaStackConnectionClose, IcaStackClose, IcaClose, IcaIoControl, IcaStackOpen, IcaStackDisconnect<br>> SHELL32.dll: SHGetFolderPathA<br>> SETUPAPI.dll: SetupDiGetDeviceRegistryPropertyA, SetupDiGetClassDevsA, SetupDiEnumDeviceInfo, SetupDiDestroyDeviceInfoList<br>> SHLWAPI.dll: PathAppendA<br>> WINTRUST.dll: CryptCATAdminCalcHashFromFileHandle, CryptCATAdminEnumCatalogFromHash, CryptCATCatalogInfoFromContext, CryptCATAdminReleaseCatalogContext, CryptCATAdminReleaseContext, WTHelperProvDataFromStateData, WTHelperGetProvSignerFromChain, CryptCATAdminAcquireContext, WinVerifyTrust<br>> RPCRT4.dll: RpcServerInqDefaultPrincNameW, RpcServerRegisterAuthInfoW, RpcServerRegisterIfEx, RpcBindingToStringBindingW, RpcServerListen, RpcImpersonateClient, I_RpcBindingIsClientLocal, RpcRevertToSelf, RpcServerUseProtseqEpW, I_RpcBindingInqLocalClientPID, RpcStringFreeW, RpcRaiseException, RpcSsContextLockExclusive, NdrServerCall2, RpcServerRegisterIf, RpcStringBindingParseW<br>> KERNEL32.dll: GetLocalTime, GetDiskFreeSpaceA, GetDateFormatW, FileTimeToSystemTime, InitializeCriticalSection, GetVersion, CreateMutexW, GetModuleHandleA, InterlockedExchange, OutputDebugStringA, GetProcessAffinityMask, SetThreadAffinityMask, ResumeThread, GetExitCodeThread, GetSystemInfo, GetLogicalDriveStringsA, GetDriveTypeA, GetVolumeInformationW, GetVolumeInformationA, GlobalMemoryStatus, lstrlenA, lstrcpyA, GetFileSize, WriteFile, SetFilePointer, ReadFile, CreateFileA, HeapAlloc, HeapFree, CompareFileTime, CreateWaitableTimerW, SetWaitableTimer, FormatMessageW, LeaveCriticalSection, GetSystemDefaultLCID, SystemTimeToFileTime, LoadLibraryExA, GetVersionExA, SetUnhandledExceptionFilter, UnhandledExceptionFilter, TerminateProcess, GetCurrentThreadId, QueryPerformanceCounter, LoadLibraryA, InterlockedCompareExchange, DelayLoadFailureHook, lstrcpynW, GetACP, MultiByteToWideChar, SetLastError, lstrlenW, LocalFree, LocalAlloc, GetProcessHeap, DisableThreadLibraryCalls, DebugBreak, Sleep, CloseHandle, CreateProcessW, GetCurrentProcessId, IsDebuggerPresent, GetVersionExW, ResetEvent, SetEvent, VerifyVersionInfoW, CreateEventW, GetLastError, ReleaseMutex, UnmapViewOfFile, MapViewOfFile, OpenFileMappingW, WaitForMultipleObjects, OpenEventW, OpenMutexW, InterlockedDecrement, CreateThread, CreateFileW, GetSystemDirectoryW, GetSystemTime, GetComputerNameA, GetSystemTimeAsFileTime, UnregisterWait, WaitForSingleObject, InterlockedIncrement, lstrcpyW, ExitThread, QueryDosDeviceW, ProcessIdToSessionId, IsBadReadPtr, IsBadWritePtr, OpenProcess, GetComputerNameW, FreeLibrary, GetProcAddress, LoadLibraryW, GetProfileStringW, GetTickCount, RegisterWaitForSingleObject, lstrcatW, lstrcmpiW, GetProfileIntW, GetWindowsDirectoryW, SetThreadPriority, GetCurrentThread, LocalSize, GetCurrentProcess, PulseEvent, GetComputerNameExW, WideCharToMultiByte, InitializeCriticalSectionAndSpinCount, EnterCriticalSection, DeleteCriticalSection<br>> USER32.dll: GetCursorPos, wvsprintfA, BroadcastSystemMessageA, wsprintfA, GetSystemMetrics, wsprintfW, ExitWindowsEx, LoadStringW, MessageBeep, GetMessageTime<br>> Secur32.dll: GetUserNameExW<br>> WS2_32.dll: -, -, -, getaddrinfo, -, -<br>> ADVAPI32.dll: GetSidSubAuthorityCount, GetSidSubAuthority, AccessCheckAndAuditAlarmW, AllocateAndInitializeSid, SetEntriesInAclW, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, RegEnumKeyW, DeregisterEventSource, CryptAcquireContextW, CryptCreateHash, CryptImportKey, CryptVerifySignatureW, CryptDestroyKey, CryptDestroyHash, CryptReleaseContext, AddAce, GetAce, GetAclInformation, GetUserNameA, CryptHashData, RegisterServiceCtrlHandlerW, GetSidIdentifierAuthority, IsValidSid, GetTokenInformation, EqualSid, LookupAccountSidW, RegSetValueExW, CryptGenRandom, RegisterEventSourceW, ReportEventW, SetServiceBits, RegOpenKeyW, GetUserNameW, SetServiceStatus, RegOpenKeyExW, GetSecurityDescriptorDacl, LsaDelete, LsaSetSecret, LsaClose, LsaOpenSecret, LsaCreateSecret, LsaOpenPolicy, LsaFreeMemory, LsaQuerySecret, GetEventLogInformation, LsaQueryInformationPolicy, RegQueryValueExW, RegCloseKey, LogonUserW, AddAccessAllowedAce, InitializeAcl, GetLengthSid, OpenThreadToken, CheckTokenMembership, MakeSelfRelativeSD, MakeAbsoluteSD, IsValidSecurityDescriptor, ElfReportEventW, ElfRegisterEventSourceW, I_ScSendTSMessage, RegNotifyChangeKeyValue, RegCreateKeyExW, RegQueryValueExA, RegOpenKeyExA, GetCurrentHwProfileA, RegEnumKeyExA, RegEnumKeyExW, LsaStorePrivateData, LsaNtStatusToWinError, LsaRetrievePrivateData, RegDeleteValueW, OpenProcessToken<br>> CRYPT32.dll: CertCloseStore, CertCreateCertificateContext, CertOpenStore, CertDuplicateCertificateContext, CertFreeCertificateContext, CertGetIssuerCertificateFromStore, CertVerifySubjectCertificateContext, CryptExportPublicKeyInfo, CertEnumCertificatesInStore, CertFindExtension, CertVerifyCertificateChainPolicy, CertComparePublicKeyInfo, CryptDecodeObject, CryptVerifyCertificateSignature, CryptBinaryToStringW<br>> OLEAUT32.dll: -, -, -, -, -, -, -, -, -, -<br>> AUTHZ.dll: AuthzFreeResourceManager, AuthziAllocateAuditParams, AuthziInitializeAuditParamsWithRM, AuthziInitializeAuditEvent, AuthziLogAuditEvent, AuthzFreeAuditEvent, AuthziFreeAuditParams, AuthzInitializeResourceManager, AuthziInitializeAuditEventType, AuthziFreeAuditEventType<br>> mstlsapi.dll: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -<br><br>( 1 exports ) <br>ServiceMain<br>
CWSandbox info: <a href='http://research.sunbelt-software.com/partnerresource/MD5.aspx?md5=63999d0abd8dabfd76a9c07f6e104868' target='_blank'>http://research.sunbelt-software.com/partnerresource/MD5.aspx?md5=63999d0abd8dabfd76a9c07f6e104868</a>