tiffanyle2000
2009-03-07, 01:01
ComboFix 09-03-04.01 - U_C 2009-03-06 14:48:25.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1014.735 [GMT -8:00]
Running from: c:\documents and settings\U_C\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Outdated)
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\U_C\LOCALS~1\Temp\tmp1.tmp
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\U_C\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus 2009.lnk
c:\windows\IE4 Error Log.txt
c:\windows\system32\bohotute.dll
c:\windows\system32\butazaji.dll
c:\windows\system32\drivers\TDSSpaxt.sys
c:\windows\system32\ekahaluh.ini
c:\windows\system32\elepaleg.ini
c:\windows\system32\gebojele.dll
c:\windows\system32\hejitavo.dll
c:\windows\system32\holiwaga.dll
c:\windows\system32\ivahalak.ini
c:\windows\system32\kalahavi.dll
c:\windows\system32\kobitaka.dll
c:\windows\system32\lewiyidi.dll
c:\windows\system32\mesekaho.dll
c:\windows\system32\milokira.dll
c:\windows\system32\mzjezf.dll
c:\windows\system32\namogizu.dll
c:\windows\system32\nezovefo.dll
c:\windows\system32\nojalite.dll
c:\windows\system32\nonabefa.dll
c:\windows\system32\odisinad.ini
c:\windows\system32\ogayotez.ini
c:\windows\system32\opikumon.ini
c:\windows\system32\ovatijeh.ini
c:\windows\system32\pozimadu.dll
c:\windows\system32\sirifiwi.dll
c:\windows\system32\TDSScfum.dll
c:\windows\system32\TDSSfxmp.dll
c:\windows\system32\TDSSnmxh.log
c:\windows\system32\TDSSnrsr.dll
c:\windows\system32\TDSSofxh.dll
c:\windows\system32\TDSSosvd.dat
c:\windows\system32\TDSSrhym.log
c:\windows\system32\TDSSriqp.dll
c:\windows\system32\TDSSsbhc.dll
c:\windows\system32\TDSStkdv.log
c:\windows\system32\tojowebo.dll
c:\windows\system32\umeyanol.ini
c:\windows\system32\unojitef.ini
c:\windows\system32\usajuhig.ini
c:\windows\system32\vomuganu.dll
c:\windows\system32\weluyiki.dll
c:\windows\system32\wumoyuvo.dll
c:\windows\system32\yohilite.dll
----- BITS: Possible infected sites -----
hxxp://82.98.235.205
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_TDSSserv.sys
-------\Legacy_TDSSserv.sys
((((((((((((((((((((((((( Files Created from 2009-02-06 to 2009-03-06 )))))))))))))))))))))))))))))))
.
2009-03-05 18:44 . 2009-03-06 12:05 <DIR> d--h----- C:\$AVG8.VAULT$
2009-03-05 18:25 . 2009-03-05 18:25 <DIR> d-------- c:\windows\system32\drivers\Avg
2009-03-05 18:25 . 2009-03-05 18:28 <DIR> d-------- c:\documents and settings\All Users\Application Data\avg8
2009-03-05 18:25 . 2009-03-05 18:25 97,928 --a------ c:\windows\system32\drivers\avgldx86.sys
2009-03-05 18:25 . 2009-03-05 18:25 10,520 --a------ c:\windows\system32\avgrsstx.dll
2009-03-05 14:01 . 2009-03-05 21:14 1,406 --a------ c:\windows\SysMech6.INI
2009-03-05 13:18 . 2009-03-05 13:18 406 --a------ c:\windows\system32\ioloBootDefrag.cfg
2009-03-05 13:07 . 2005-10-24 17:07 41,472 --a------ c:\windows\system32\iolobtdfg.exe
2009-03-05 13:07 . 2005-09-12 20:20 25,264 --a------ c:\windows\system32\smrgdf.exe
2009-03-05 13:06 . 2009-03-05 13:06 <DIR> d-------- c:\program files\iolo
2009-03-05 13:06 . 2006-02-02 18:42 1,211,904 --a------ c:\windows\system32\Incinerator.dll
2009-03-05 10:52 . 2009-03-05 10:52 <DIR> d-------- c:\program files\AVG
2009-03-05 10:52 . 2009-03-05 10:57 10,520 --------- c:\windows\system32\avgrsstx.dll.install_backup_2
2009-03-05 10:52 . 2009-03-05 10:52 10,520 --------- c:\windows\system32\avgrsstx.dll.install_backup_1
2009-03-05 10:35 . 2009-03-05 10:35 <DIR> d-------- c:\documents and settings\All Users\Application Data\AT&T
2009-03-05 10:30 . 2009-03-05 10:30 2,098 ---hs---- c:\windows\system32\rimuwuka.dll
2009-03-05 10:30 . 2009-03-05 10:30 2,098 ---hs---- c:\windows\system32\mibevilo.dll
2009-03-04 21:40 . 2009-03-04 21:40 10,520 --------- c:\windows\system32\avgrsstx.dll.install_backup
2009-03-04 20:28 . 2009-03-04 20:28 <DIR> d-------- c:\documents and settings\All Users\Application Data\Prism
2009-03-04 20:27 . 2009-03-04 20:42 <DIR> d-------- c:\program files\Dell Wireless
2009-03-04 20:27 . 2004-08-31 11:53 1,364,036 -ra------ c:\windows\system32\PRISME5.dll
2009-03-04 20:27 . 2004-10-04 14:05 405,593 --a------ c:\windows\system32\PRISMAPI.dll
2009-03-04 20:27 . 2004-10-04 14:10 327,769 --a------ c:\windows\system32\PRISMSVR.exe
2009-03-04 20:27 . 2004-10-04 14:12 57,344 --a------ c:\windows\system32\PRISMSVC.exe
2009-03-04 20:27 . 2004-09-01 14:39 16,979 --a------ c:\windows\system32\drivers\AEGISP.sys
2009-03-04 19:52 . 2004-09-26 19:42 345,184 --a------ c:\windows\system32\drivers\PRISMA02.sys
2009-03-04 19:52 . 2004-08-18 11:01 49,152 --a------ c:\windows\system32\CoPrism.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-05 04:27 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-06 17:29 87,605 ------w c:\windows\system32\lonayemu.dll
2008-09-06 17:29 63,029 --sha-w c:\windows\system32\hupabubi.dll
2008-09-06 17:29 11,264 --sha-w c:\windows\system32\suhahebu.dll
2008-09-06 17:29 63,029 --sha-w c:\windows\system32\tesifoti.dll
2008-09-06 17:29 63,029 --sha-w c:\windows\system32\tukejavi.dll
2008-11-19 20:52 608 --sha-w c:\windows\system32\winzvprt5.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"SMSystemAnalyzer"="c:\program files\iolo\System Mechanic 6\SMSystemAnalyzer.exe" [2006-02-02 578048]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-04 1667584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 32768]
"ToolBoxFX"="c:\program files\HP\ToolBoxFX\bin\HPTLBXFX.exe" [2008-01-10 53248]
"HPUsageTracking"="c:\program files\HP\HP UT\bin\hppusg.exe" [2007-08-31 36864]
"SpySweeper"="c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2007-01-25 4865600]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-03-05 1261336]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 c:\windows\system32\HdAShCut.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-07-25 c:\windows\SOUNDMAN.EXE]
"AlcWzrd"="ALCWZRD.EXE" [2005-07-25 c:\windows\ALCWZRD.EXE]
c:\documents and settings\U_C\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Wireless USB 2.0 WLAN Card Utility.lnk - c:\program files\Dell Wireless\PRISMCFG.exe [2009-03-04 917611]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0smrgdf c:\program files\iolo\System Mechanic 6"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ cli
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\HP\\hp laserjet m1522\\Fax Config utility1.exe"=
"c:\\Program Files\\Dell Wireless\\PRISMCFG.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Combo-Fix\\NirCmd.cfexe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-03-05 97928]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-03-05 231704]
S3 HPFXFAX;HPFXFAX;c:\windows\system32\drivers\hpfxfax.sys [2008-11-19 20504]
S3 SWNC8U56;Sierra Wireless MUX NDIS Driver (UMTS56);c:\windows\system32\drivers\swnc8u56.sys [2008-11-13 101248]
S3 SWUMX56;Sierra Wireless USB MUX Driver (UMTS56);c:\windows\system32\drivers\swumx56.sys [2008-11-13 73856]
S4 PRISMSVC;PRISMSVC;c:\windows\system32\PRISMSVC.exe [2009-03-04 57344]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1c78e50d-b1d9-11dd-afd0-0013204ee5da}]
\Shell\AutoRun\command - i:\win\setup.exe
.
- - - - ORPHANS REMOVED - - - -
BHO-{453d3f41-54a7-4340-b582-c0ad6ba384e5} - c:\windows\system32\mzjezf.dll
BHO-{fc7bfae2-c34a-4321-aa42-31760b97964b} - c:\windows\system32\yohilite.dll
WebBrowser-{A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} - (no file)
HKLM-Run-d41a9194 - c:\windows\system32\zetoyago.dll
SharedTaskScheduler-{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\sirifiwi.dll
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{CCF00E14-7C5E-4420-9BF3-AA4809CFAA13} - c:\program files\ClickClean\ClickClean.exe
.
.
------- File Associations -------
.
JSEFile=NOTEPAD.EXE %1
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-06 14:53:29
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(920)
c:\windows\system32\WRLogonNTF.dll
c:\windows\system32\PRISMAPI.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\PRISMSVR.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-03-06 14:54:35 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-06 22:54:32
Pre-Run: 203,207,286,784 bytes free
Post-Run: 203,121,442,816 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
207
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:59:15 PM, on 3/6/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\PRISMSVR.EXE
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe
C:\Program Files\HP\HP UT\bin\hppusg.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Dell Wireless\PRISMCFG.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [ToolBoxFX] "C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /fl:on /fr:on /appData:on /tmcp:on
O4 - HKLM\..\Run: [HPUsageTracking] "C:\Program Files\HP\HP UT\bin\hppusg.exe" "C:\Program Files\HP\HP UT\"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - S-1-5-18 Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Wireless USB 2.0 WLAN Card Utility.lnk = C:\Program Files\Dell Wireless\PRISMCFG.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Cleaner - {CCF00E14-7C5E-4420-9BF3-AA4809CFAA13} - C:\Program Files\ClickClean\ClickClean.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O24 - Desktop Component 0: (no name) - http://l.yimg.com/a/i/ww/thm/1/grd-1px_1.4.gif
--
End of file - 4907 bytes
tiffanyle2000
2009-03-07, 23:02
ComboFix 09-03-04.01 - U_C 2009-03-07 12:18:37.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1014.568 [GMT -8:00]
Running from: c:\documents and settings\U_C\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\U_C\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point
FILE ::
c:\windows\system32\hupabubi.dll
c:\windows\system32\lonayemu.dll
c:\windows\system32\rimuwuka.dll
c:\windows\system32\suhahebu.dll
c:\windows\system32\tesifoti.dll
c:\windows\system32\tukejavi.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\rimuwuka.dll
.
((((((((((((((((((((((((( Files Created from 2009-02-07 to 2009-03-07 )))))))))))))))))))))))))))))))
.
2009-03-06 20:46 . 2009-03-06 20:46 <DIR> d-------- c:\program files\Windows Installer Clean Up
2009-03-06 20:45 . 2009-03-06 20:47 <DIR> d-------- c:\program files\MSECACHE
2009-03-06 19:43 . 2009-03-06 19:43 <DIR> d-------- c:\program files\CONEXANT
2009-03-06 19:39 . 2009-03-06 19:39 <DIR> d-------- c:\windows\Downloaded Installations
2009-03-06 19:39 . 2009-03-06 19:39 <DIR> d-------- c:\program files\eMachines Bay Reader
2009-03-06 17:35 . 2009-03-06 17:35 <DIR> d-------- c:\program files\Western Digital Technologies
2009-03-06 16:36 . 2009-03-06 16:36 10,520 --a------ c:\windows\system32\avgrsstx.dll
2009-03-06 16:15 . 2009-03-06 17:05 <DIR> d-------- c:\windows\system32\NtmsData
2009-03-06 16:03 . 2009-03-06 16:24 <DIR> d-------- c:\windows\system32\CatRoot_bak
2009-03-06 15:57 . 2009-03-06 15:57 <DIR> d-------- c:\program files\MSXML 4.0
2009-03-06 15:56 . 2008-08-14 02:00 2,180,352 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2009-03-06 15:56 . 2008-08-14 01:58 2,136,064 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-03-06 15:56 . 2008-08-14 01:22 2,057,728 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-03-06 15:56 . 2008-08-14 01:22 2,015,744 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2009-03-06 15:44 . 2009-03-06 16:45 <DIR> d--h----- c:\windows\$hf_mig$
2009-03-06 15:39 . 2008-10-24 03:10 453,632 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2009-03-06 14:59 . 2009-03-06 14:59 <DIR> d-------- c:\program files\Trend Micro
2009-03-05 18:44 . 2009-03-07 12:18 <DIR> d--h----- C:\$AVG8.VAULT$
2009-03-05 18:25 . 2009-03-06 15:11 <DIR> d-------- c:\windows\system32\drivers\Avg
2009-03-05 18:25 . 2009-03-06 16:31 <DIR> d-------- c:\documents and settings\All Users\Application Data\avg8
2009-03-05 18:25 . 2009-03-06 16:36 325,128 --a------ c:\windows\system32\drivers\avgldx86.sys
2009-03-05 14:01 . 2009-03-06 19:10 1,696 --a------ c:\windows\SysMech6.INI
2009-03-05 13:18 . 2009-03-05 13:18 406 --a------ c:\windows\system32\ioloBootDefrag.cfg
2009-03-05 13:07 . 2005-10-24 17:07 41,472 --a------ c:\windows\system32\iolobtdfg.exe
2009-03-05 13:07 . 2005-09-12 20:20 25,264 --a------ c:\windows\system32\smrgdf.exe
2009-03-05 13:06 . 2009-03-05 13:06 <DIR> d-------- c:\program files\iolo
2009-03-05 13:06 . 2006-02-02 18:42 1,211,904 --a------ c:\windows\system32\Incinerator.dll
2009-03-05 10:52 . 2009-03-05 10:52 <DIR> d-------- c:\program files\AVG
2009-03-05 10:52 . 2009-03-05 10:57 10,520 --------- c:\windows\system32\avgrsstx.dll.install_backup_2
2009-03-05 10:52 . 2009-03-05 10:52 10,520 --------- c:\windows\system32\avgrsstx.dll.install_backup_1
2009-03-05 10:35 . 2009-03-05 10:35 <DIR> d-------- c:\documents and settings\All Users\Application Data\AT&T
2009-03-05 10:30 . 2009-03-05 10:30 2,098 ---hs---- c:\windows\system32\mibevilo.dll
2009-03-04 21:40 . 2009-03-04 21:40 10,520 --------- c:\windows\system32\avgrsstx.dll.install_backup
2009-03-04 20:28 . 2009-03-04 20:28 <DIR> d-------- c:\documents and settings\All Users\Application Data\Prism
2009-03-04 20:27 . 2009-03-04 20:42 <DIR> d-------- c:\program files\Dell Wireless
2009-03-04 20:27 . 2004-08-31 11:53 1,364,036 -ra------ c:\windows\system32\PRISME5.dll
2009-03-04 20:27 . 2004-10-04 14:05 405,593 --a------ c:\windows\system32\PRISMAPI.dll
2009-03-04 20:27 . 2004-10-04 14:10 327,769 --a------ c:\windows\system32\PRISMSVR.exe
2009-03-04 20:27 . 2004-10-04 14:12 57,344 --a------ c:\windows\system32\PRISMSVC.exe
2009-03-04 20:27 . 2004-09-01 14:39 16,979 --a------ c:\windows\system32\drivers\AEGISP.sys
2009-03-04 19:52 . 2004-09-26 19:42 345,184 --a------ c:\windows\system32\drivers\PRISMA02.sys
2009-03-04 19:52 . 2004-08-18 11:01 49,152 --a------ c:\windows\system32\CoPrism.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-07 03:39 --------- d-----w c:\program files\Common Files\InstallShield
2009-03-07 00:13 --------- d-----w c:\program files\HP
2009-03-05 04:27 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-19 20:52 608 --sha-w c:\windows\system32\winzvprt5.sys
.
((((((((((((((((((((((((((((( SnapShot@2009-03-06_14.54.02.57 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-11-19 20:53:38 10,752 ------w c:\windows\assembly\temp\N14NSZ39TT\interop.hpqusg.dll
+ 2008-06-13 13:10:50 272,128 ------w c:\windows\Driver Cache\i386\bthport.sys
+ 2008-10-24 11:10:42 453,632 ------w c:\windows\Driver Cache\i386\mrxsmb.sys
+ 2008-08-14 09:58:27 2,136,064 ------w c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2008-08-14 09:22:13 2,057,728 ------w c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2008-08-14 09:22:14 2,015,744 ------w c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2008-08-14 10:00:45 2,180,352 ------w c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2009-03-07 03:39:12 25,214 ----a-r c:\windows\Installer\{81EED1A1-AE78-4B11-BE47-C6AE9F5E87F1}\ARPPRODUCTICON.exe
+ 2009-03-06 23:57:41 32,768 ----a-r c:\windows\Installer\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}\icon.exe
- 2004-08-03 22:56:42 100,352 ----a-w c:\windows\system32\6to4svc.dll
+ 2006-08-16 11:58:05 100,352 ----a-w c:\windows\system32\6to4svc.dll
- 2004-08-03 22:56:42 1,016,832 ----a-w c:\windows\system32\browseui.dll
+ 2008-10-16 10:37:04 1,023,488 ----a-w c:\windows\system32\browseui.dll
- 2004-08-03 22:56:42 150,528 ----a-w c:\windows\system32\cdfview.dll
+ 2008-10-16 10:37:02 151,040 ----a-w c:\windows\system32\cdfview.dll
- 2004-08-03 22:56:42 1,053,696 ----a-w c:\windows\system32\danim.dll
+ 2008-10-16 10:37:02 1,054,208 ----a-w c:\windows\system32\danim.dll
+ 2003-12-24 21:45:30 221,184 ----a-w c:\windows\system32\diconxp.dll
- 2004-08-03 22:56:42 100,352 -c--a-w c:\windows\system32\dllcache\6to4svc.dll
+ 2006-08-16 11:58:05 100,352 -c--a-w c:\windows\system32\dllcache\6to4svc.dll
- 2004-08-03 21:14:16 138,496 -c--a-w c:\windows\system32\dllcache\afd.sys
+ 2008-08-14 09:51:43 138,368 -c--a-w c:\windows\system32\dllcache\afd.sys
- 2004-08-03 22:56:42 1,016,832 -c--a-w c:\windows\system32\dllcache\browseui.dll
+ 2008-10-16 10:37:04 1,023,488 -c--a-w c:\windows\system32\dllcache\browseui.dll
+ 2008-06-13 13:10:50 272,128 -c----w c:\windows\system32\dllcache\bthport.sys
- 2004-08-03 22:56:42 150,528 -c--a-w c:\windows\system32\dllcache\cdfview.dll
+ 2008-10-16 10:37:02 151,040 -c--a-w c:\windows\system32\dllcache\cdfview.dll
- 2004-08-03 22:56:42 1,053,696 -c--a-w c:\windows\system32\dllcache\danim.dll
+ 2008-10-16 10:37:02 1,054,208 -c--a-w c:\windows\system32\dllcache\danim.dll
- 2004-08-03 22:56:44 148,480 -c--a-w c:\windows\system32\dllcache\dnsapi.dll
+ 2008-06-21 07:11:12 148,992 -c--a-w c:\windows\system32\dllcache\dnsapi.dll
- 2004-08-03 22:56:44 357,888 -c--a-w c:\windows\system32\dllcache\dxtmsft.dll
+ 2008-10-16 10:37:02 357,888 -c--a-w c:\windows\system32\dllcache\dxtmsft.dll
- 2004-08-03 22:56:44 201,728 -c--a-w c:\windows\system32\dllcache\dxtrans.dll
+ 2008-10-16 10:37:02 205,312 -c--a-w c:\windows\system32\dllcache\dxtrans.dll
- 2004-08-03 22:56:44 243,200 -c--a-w c:\windows\system32\dllcache\es.dll
+ 2008-07-07 20:32:22 253,952 -c--a-w c:\windows\system32\dllcache\es.dll
- 2004-08-03 22:56:44 55,808 -c--a-w c:\windows\system32\dllcache\extmgr.dll
+ 2008-10-16 10:37:02 55,808 -c--a-w c:\windows\system32\dllcache\extmgr.dll
- 2004-08-03 22:56:44 278,016 -c--a-w c:\windows\system32\dllcache\gdi32.dll
+ 2008-10-23 13:01:36 283,648 -c--a-w c:\windows\system32\dllcache\gdi32.dll
- 2004-08-03 22:56:52 18,432 -c--a-w c:\windows\system32\dllcache\iedw.exe
+ 2008-10-15 09:45:01 18,432 -c--a-w c:\windows\system32\dllcache\iedw.exe
- 2004-08-03 22:56:44 249,344 -c--a-w c:\windows\system32\dllcache\iepeers.dll
+ 2008-10-16 10:37:02 251,392 -c--a-w c:\windows\system32\dllcache\iepeers.dll
- 2004-08-03 22:56:44 678,400 -c--a-w c:\windows\system32\dllcache\inetcomm.dll
+ 2008-04-11 18:50:43 683,520 -c--a-w c:\windows\system32\dllcache\inetcomm.dll
- 2004-08-03 22:56:44 96,256 -c--a-w c:\windows\system32\dllcache\inseng.dll
+ 2008-10-16 10:37:02 96,256 -c--a-w c:\windows\system32\dllcache\inseng.dll
- 2004-08-03 22:56:44 450,560 -c--a-w c:\windows\system32\dllcache\jscript.dll
+ 2007-12-18 14:40:58 450,560 -c--a-w c:\windows\system32\dllcache\jscript.dll
- 2004-08-03 22:56:44 15,872 -c--a-w c:\windows\system32\dllcache\jsproxy.dll
+ 2008-10-16 10:37:03 16,384 -c--a-w c:\windows\system32\dllcache\jsproxy.dll
- 2004-08-03 22:56:52 103,936 -c--a-w c:\windows\system32\dllcache\logagent.exe
+ 2008-06-10 09:31:06 103,936 -c--a-w c:\windows\system32\dllcache\logagent.exe
- 2004-08-03 22:56:44 331,776 -c--a-w c:\windows\system32\dllcache\msadce.dll
+ 2008-05-01 14:30:33 331,776 -c--a-w c:\windows\system32\dllcache\msadce.dll
- 2004-08-03 22:56:44 73,728 -c--a-w c:\windows\system32\dllcache\mscms.dll
+ 2008-06-24 16:23:05 74,240 -c--a-w c:\windows\system32\dllcache\mscms.dll
- 2004-08-03 22:56:44 3,003,392 -c--a-w c:\windows\system32\dllcache\mshtml.dll
+ 2008-12-12 17:33:23 3,060,224 -c--a-w c:\windows\system32\dllcache\mshtml.dll
- 2004-08-03 22:56:44 448,512 -c--a-w c:\windows\system32\dllcache\mshtmled.dll
+ 2008-10-16 10:37:03 449,024 -c--a-w c:\windows\system32\dllcache\mshtmled.dll
- 2004-08-03 22:56:44 146,432 -c--a-w c:\windows\system32\dllcache\msrating.dll
+ 2008-10-16 10:37:02 146,432 -c--a-w c:\windows\system32\dllcache\msrating.dll
- 2004-08-03 22:56:44 530,432 -c--a-w c:\windows\system32\dllcache\mstime.dll
+ 2008-10-16 10:37:02 532,480 -c--a-w c:\windows\system32\dllcache\mstime.dll
- 2004-08-03 22:56:46 245,248 -c--a-w c:\windows\system32\dllcache\mswsock.dll
+ 2008-06-20 17:41:10 245,248 -c--a-w c:\windows\system32\dllcache\mswsock.dll
- 2004-08-03 22:56:46 1,236,480 -c--a-w c:\windows\system32\dllcache\msxml3.dll
+ 2008-09-04 16:42:02 1,106,944 -c--a-w c:\windows\system32\dllcache\msxml3.dll
- 2004-08-03 22:56:46 332,288 -c--a-w c:\windows\system32\dllcache\netapi32.dll
+ 2008-10-15 16:57:55 332,800 -c--a-w c:\windows\system32\dllcache\netapi32.dll
- 2004-08-03 22:56:46 39,424 -c--a-w c:\windows\system32\dllcache\pngfilt.dll
+ 2008-10-16 10:37:02 39,424 -c--a-w c:\windows\system32\dllcache\pngfilt.dll
- 2004-08-03 22:56:46 1,287,680 -c--a-w c:\windows\system32\dllcache\quartz.dll
+ 2008-05-07 05:18:48 1,287,680 -c--a-w c:\windows\system32\dllcache\quartz.dll
- 2001-08-23 12:00:00 200,064 -c--a-w c:\windows\system32\dllcache\rmcast.sys
+ 2008-05-08 12:28:49 202,752 -c--a-w c:\windows\system32\dllcache\rmcast.sys
- 2004-08-03 22:56:46 1,483,264 -c--a-w c:\windows\system32\dllcache\shdocvw.dll
+ 2008-10-16 10:37:03 1,494,528 -c--a-w c:\windows\system32\dllcache\shdocvw.dll
- 2004-08-03 22:56:46 8,384,000 -c--a-w c:\windows\system32\dllcache\shell32.dll
+ 2008-07-03 13:16:57 8,454,656 -c--a-w c:\windows\system32\dllcache\shell32.dll
- 2004-08-03 22:56:46 473,600 -c--a-w c:\windows\system32\dllcache\shlwapi.dll
+ 2008-10-16 10:37:03 474,112 -c--a-w c:\windows\system32\dllcache\shlwapi.dll
- 2004-08-03 21:14:46 336,256 -c--a-w c:\windows\system32\dllcache\srv.sys
+ 2008-12-11 11:57:21 333,184 -c--a-w c:\windows\system32\dllcache\srv.sys
- 2004-08-03 22:56:46 246,302 -c--a-w c:\windows\system32\dllcache\strmdll.dll
+ 2008-10-03 10:15:47 247,326 -c--a-w c:\windows\system32\dllcache\strmdll.dll
- 2004-08-03 21:14:42 359,040 -c--a-w c:\windows\system32\dllcache\tcpip.sys
+ 2008-06-20 10:45:13 360,320 -c--a-w c:\windows\system32\dllcache\tcpip.sys
- 2004-08-03 21:07:46 223,616 -c--a-w c:\windows\system32\dllcache\tcpip6.sys
+ 2008-06-20 23:22:08 225,920 -c--a-w c:\windows\system32\dllcache\tcpip6.sys
- 2004-08-03 22:56:48 601,088 -c--a-w c:\windows\system32\dllcache\urlmon.dll
+ 2008-10-16 10:37:04 615,936 -c--a-w c:\windows\system32\dllcache\urlmon.dll
- 2004-08-03 22:56:48 417,792 -c--a-w c:\windows\system32\dllcache\vbscript.dll
+ 2007-12-18 14:40:58 417,792 -c--a-w c:\windows\system32\dllcache\vbscript.dll
- 2004-08-03 21:17:42 1,835,904 -c--a-w c:\windows\system32\dllcache\win32k.sys
+ 2008-09-15 11:57:41 1,846,016 -c--a-w c:\windows\system32\dllcache\win32k.sys
- 2004-08-03 22:56:48 656,384 -c--a-w c:\windows\system32\dllcache\wininet.dll
+ 2008-10-16 10:37:03 659,456 -c--a-w c:\windows\system32\dllcache\wininet.dll
- 2004-08-03 22:56:48 1,050,624 -c--a-w c:\windows\system32\dllcache\wmnetmgr.dll
+ 2008-06-11 02:18:18 1,053,696 -c--a-w c:\windows\system32\dllcache\WMNetmgr.dll
- 2004-08-03 22:57:04 2,105,344 -c--a-w c:\windows\system32\dllcache\wmvcore.dll
+ 2008-11-08 02:32:20 2,109,440 -c--a-w c:\windows\system32\dllcache\WMVCore.dll
- 2004-08-03 22:56:44 148,480 ----a-w c:\windows\system32\dnsapi.dll
+ 2008-06-21 07:11:12 148,992 ----a-w c:\windows\system32\dnsapi.dll
- 2004-08-03 21:14:16 138,496 ----a-w c:\windows\system32\drivers\afd.sys
+ 2008-08-14 09:51:43 138,368 ----a-w c:\windows\system32\drivers\afd.sys
- 2009-03-06 02:25:44 26,824 ----a-w c:\windows\system32\drivers\avgmfx86.sys
+ 2009-03-07 00:36:48 27,656 ----a-w c:\windows\system32\drivers\avgmfx86.sys
+ 2008-06-13 13:10:50 272,128 ------w c:\windows\system32\drivers\bthport.sys
+ 2005-07-22 19:01:00 717,952 ----a-w c:\windows\system32\drivers\HSF_CNXT.sys
+ 2005-07-22 19:02:12 1,035,008 ----a-w c:\windows\system32\drivers\HSF_DPV.sys
+ 2005-07-22 19:01:10 231,168 ----a-w c:\windows\system32\drivers\HSFHWBS2.sys
+ 2005-10-05 23:57:08 12,544 ----a-w c:\windows\system32\drivers\mdmxsdk.sys
- 2004-08-03 21:15:18 451,456 ----a-w c:\windows\system32\drivers\mrxsmb.sys
+ 2008-10-24 11:10:42 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
- 2001-08-23 12:00:00 200,064 ----a-w c:\windows\system32\drivers\RMCast.sys
+ 2008-05-08 12:28:49 202,752 ----a-w c:\windows\system32\drivers\rmcast.sys
- 2004-08-03 21:14:46 336,256 ----a-w c:\windows\system32\drivers\srv.sys
+ 2008-12-11 11:57:21 333,184 ----a-w c:\windows\system32\drivers\srv.sys
+ 2004-03-22 19:01:38 40,564 ----a-w c:\windows\system32\drivers\Sunkfilt.sys
+ 2004-03-22 19:27:20 42,936 ----a-w c:\windows\system32\drivers\Sunkfilt39.sys
- 2004-08-03 21:14:42 359,040 ----a-w c:\windows\system32\drivers\tcpip.sys
+ 2008-06-20 10:45:13 360,320 ----a-w c:\windows\system32\drivers\tcpip.sys
- 2004-08-03 21:07:46 223,616 ----a-w c:\windows\system32\drivers\tcpip6.sys
+ 2008-06-20 23:22:08 225,920 ----a-w c:\windows\system32\drivers\tcpip6.sys
- 2004-08-03 22:56:44 357,888 ----a-w c:\windows\system32\dxtmsft.dll
+ 2008-10-16 10:37:02 357,888 ----a-w c:\windows\system32\dxtmsft.dll
- 2004-08-03 22:56:44 201,728 ----a-w c:\windows\system32\dxtrans.dll
+ 2008-10-16 10:37:02 205,312 ----a-w c:\windows\system32\dxtrans.dll
- 2004-08-03 22:56:44 243,200 ----a-w c:\windows\system32\es.dll
+ 2008-07-07 20:32:22 253,952 ----a-w c:\windows\system32\es.dll
- 2004-08-03 22:56:44 55,808 ----a-w c:\windows\system32\extmgr.dll
+ 2008-10-16 10:37:02 55,808 ----a-w c:\windows\system32\extmgr.dll
- 2008-11-19 20:54:58 321,136 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2009-03-07 00:01:06 321,136 ----a-w c:\windows\system32\FNTCACHE.DAT
- 2004-08-03 22:56:44 278,016 ----a-w c:\windows\system32\gdi32.dll
+ 2008-10-23 13:01:36 283,648 ----a-w c:\windows\system32\gdi32.dll
+ 2003-12-25 00:10:08 139,264 ----a-w c:\windows\system32\hpicon.dll
- 2004-08-03 22:56:44 249,344 ----a-w c:\windows\system32\iepeers.dll
+ 2008-10-16 10:37:02 251,392 ----a-w c:\windows\system32\iepeers.dll
- 2004-08-03 22:56:44 678,400 ----a-w c:\windows\system32\inetcomm.dll
+ 2008-04-11 18:50:43 683,520 ----a-w c:\windows\system32\inetcomm.dll
- 2004-08-03 22:56:44 96,256 ----a-w c:\windows\system32\inseng.dll
+ 2008-10-16 10:37:02 96,256 ----a-w c:\windows\system32\inseng.dll
- 2004-08-03 22:56:44 450,560 ----a-w c:\windows\system32\jscript.dll
+ 2007-12-18 14:40:58 450,560 ----a-w c:\windows\system32\jscript.dll
- 2004-08-03 22:56:44 15,872 ----a-w c:\windows\system32\jsproxy.dll
+ 2008-10-16 10:37:03 16,384 ----a-w c:\windows\system32\jsproxy.dll
+ 2003-12-03 22:51:28 61,440 ----a-w c:\windows\system32\ldamfilt.dll
+ 2004-01-18 04:31:04 49,152 ----a-w c:\windows\system32\ldamfilt39.dll
- 2004-08-03 22:56:52 103,936 ----a-w c:\windows\system32\logagent.exe
+ 2008-06-10 09:31:06 103,936 ----a-w c:\windows\system32\logagent.exe
+ 2005-10-05 23:56:44 86,016 ----a-w c:\windows\system32\mdmxsdk.dll
- 2004-08-03 22:56:44 73,728 ----a-w c:\windows\system32\mscms.dll
+ 2008-06-24 16:23:05 74,240 ----a-w c:\windows\system32\mscms.dll
- 2004-08-03 22:56:44 3,003,392 ----a-w c:\windows\system32\mshtml.dll
+ 2008-12-12 17:33:23 3,060,224 ----a-w c:\windows\system32\mshtml.dll
- 2004-08-03 22:56:44 448,512 ----a-w c:\windows\system32\mshtmled.dll
+ 2008-10-16 10:37:03 449,024 ----a-w c:\windows\system32\mshtmled.dll
- 2004-08-03 22:56:44 146,432 ----a-w c:\windows\system32\msrating.dll
+ 2008-10-16 10:37:02 146,432 ----a-w c:\windows\system32\msrating.dll
- 2004-08-03 22:56:44 530,432 ----a-w c:\windows\system32\mstime.dll
+ 2008-10-16 10:37:02 532,480 ----a-w c:\windows\system32\mstime.dll
- 2004-08-03 22:56:46 245,248 ----a-w c:\windows\system32\mswsock.dll
+ 2008-06-20 17:41:10 245,248 ----a-w c:\windows\system32\mswsock.dll
- 2005-01-25 16:33:00 1,049,088 ----a-w c:\windows\system32\msxml3.dll
+ 2008-09-04 16:42:02 1,106,944 ----a-w c:\windows\system32\msxml3.dll
- 2008-01-29 19:32:44 1,230,336 ----a-w c:\windows\system32\msxml4.dll
+ 2008-10-01 00:43:34 1,286,152 ----a-w c:\windows\system32\msxml4.dll
- 2004-08-03 22:56:46 332,288 ----a-w c:\windows\system32\netapi32.dll
+ 2008-10-15 16:57:55 332,800 ----a-w c:\windows\system32\netapi32.dll
- 2004-08-03 23:05:44 2,015,232 ----a-w c:\windows\system32\ntkrnlpa.exe
+ 2008-08-14 09:22:14 2,015,744 ----a-w c:\windows\system32\ntkrnlpa.exe
- 2004-08-03 21:18:32 2,148,352 ----a-w c:\windows\system32\ntoskrnl.exe
+ 2008-08-14 09:58:27 2,136,064 ----a-w c:\windows\system32\ntoskrnl.exe
- 2009-03-05 04:40:16 58,596 ----a-w c:\windows\system32\perfc009.dat
+ 2009-03-07 04:40:56 58,596 ----a-w c:\windows\system32\perfc009.dat
- 2009-03-05 04:40:16 392,296 ----a-w c:\windows\system32\perfh009.dat
+ 2009-03-07 04:40:56 392,296 ----a-w c:\windows\system32\perfh009.dat
- 2004-08-03 22:56:46 39,424 ----a-w c:\windows\system32\pngfilt.dll
+ 2008-10-16 10:37:02 39,424 ----a-w c:\windows\system32\pngfilt.dll
- 2004-08-03 22:56:46 1,287,680 ----a-w c:\windows\system32\quartz.dll
+ 2008-05-07 05:18:48 1,287,680 ----a-w c:\windows\system32\quartz.dll
- 2004-08-03 22:56:46 1,483,264 ----a-w c:\windows\system32\shdocvw.dll
+ 2008-10-16 10:37:03 1,494,528 ----a-w c:\windows\system32\shdocvw.dll
- 2004-08-03 22:56:46 8,384,000 ----a-w c:\windows\system32\shell32.dll
+ 2008-07-03 13:16:57 8,454,656 ----a-w c:\windows\system32\shell32.dll
- 2004-08-03 22:56:46 473,600 ----a-w c:\windows\system32\shlwapi.dll
+ 2008-10-16 10:37:03 474,112 ----a-w c:\windows\system32\shlwapi.dll
- 2005-05-04 22:45:26 13,536 ------w c:\windows\system32\spmsg.dll
+ 2007-11-30 11:18:51 17,272 ------w c:\windows\system32\spmsg.dll
- 2004-11-18 18:42:52 22,752 ----a-w c:\windows\system32\spupdsvc.exe
+ 2005-02-25 03:35:05 22,752 ----a-w c:\windows\system32\spupdsvc.exe
- 2004-08-03 22:56:46 246,302 ----a-w c:\windows\system32\strmdll.dll
+ 2008-10-03 10:15:47 247,326 ----a-w c:\windows\system32\strmdll.dll
+ 2008-10-22 09:47:07 62,976 ------w c:\windows\system32\tzchange.exe
+ 2005-11-16 23:41:26 114,688 ----a-w c:\windows\system32\uci32103.dll
- 2004-08-03 22:56:48 601,088 ----a-w c:\windows\system32\urlmon.dll
+ 2008-10-16 10:37:04 615,936 ----a-w c:\windows\system32\urlmon.dll
- 2004-08-03 22:56:48 417,792 ----a-w c:\windows\system32\vbscript.dll
+ 2007-12-18 14:40:58 417,792 ----a-w c:\windows\system32\vbscript.dll
- 2004-08-03 21:17:42 1,835,904 ----a-w c:\windows\system32\win32k.sys
+ 2008-09-15 11:57:41 1,846,016 ----a-w c:\windows\system32\win32k.sys
- 2004-08-03 22:56:48 656,384 ----a-w c:\windows\system32\wininet.dll
+ 2008-10-16 10:37:03 659,456 ----a-w c:\windows\system32\wininet.dll
- 2004-08-03 22:56:48 1,050,624 ----a-w c:\windows\system32\wmnetmgr.dll
+ 2008-06-11 02:18:18 1,053,696 ----a-w c:\windows\system32\WMNetmgr.dll
- 2004-08-03 22:57:04 2,105,344 ----a-w c:\windows\system32\wmvcore.dll
+ 2008-11-08 02:32:20 2,109,440 ----a-w c:\windows\system32\WMVCore.dll
+ 2008-10-15 14:00:41 351,744 ------w c:\windows\system32\xpsp3res.dll
+ 2008-10-01 00:42:08 1,286,152 ----a-w c:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9870.0_x-ww_a32d74cf\msxml4.dll
+ 2008-10-01 00:45:12 91,656 ----a-w c:\windows\WinSxS\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.1.0_x-ww_2a41bceb\msxml4r.dll
+ 2008-04-15 17:54:19 1,724,416 ----a-w c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.3352_x-ww_81af8e88\GdiPlus.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"SMSystemAnalyzer"="c:\program files\iolo\System Mechanic 6\SMSystemAnalyzer.exe" [2006-02-02 578048]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 32768]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-03-06 1601304]
"SunKistEM"="c:\program files\eMachines Bay Reader\shwiconem.exe" [2004-03-11 135168]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 c:\windows\system32\HdAShCut.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-07-25 c:\windows\SOUNDMAN.EXE]
"AlcWzrd"="ALCWZRD.EXE" [2005-07-25 c:\windows\ALCWZRD.EXE]
c:\documents and settings\U_C\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Wireless USB 2.0 WLAN Card Utility.lnk - c:\program files\Dell Wireless\PRISMCFG.exe [2009-03-04 917611]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-03-06 16:36 10520 c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0smrgdf c:\program files\iolo\System Mechanic 6
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ cli
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Dell Wireless\\PRISMCFG.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Combo-Fix\\NirCmd.cfexe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-03-05 325128]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-03-06 298264]
S3 HPFXFAX;HPFXFAX;c:\windows\system32\drivers\hpfxfax.sys [2008-11-19 20504]
S3 SWNC8U56;Sierra Wireless MUX NDIS Driver (UMTS56);c:\windows\system32\drivers\swnc8u56.sys [2008-11-13 101248]
S3 SWUMX56;Sierra Wireless USB MUX Driver (UMTS56);c:\windows\system32\drivers\swumx56.sys [2008-11-13 73856]
S4 PRISMSVC;PRISMSVC;c:\windows\system32\PRISMSVC.exe [2009-03-04 57344]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1c78e50d-b1d9-11dd-afd0-0013204ee5da}]
\Shell\AutoRun\command - i:\win\setup.exe
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{CCF00E14-7C5E-4420-9BF3-AA4809CFAA13} - c:\program files\ClickClean\ClickClean.exe
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-07 12:21:33
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(916)
c:\windows\system32\PRISMAPI.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVG\AVG8\avgrsx.exe
c:\windows\system32\PRISMSVR.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-03-07 12:23:01 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-07 20:22:59
ComboFix2.txt 2009-03-06 22:54:36
Pre-Run: 201,641,529,344 bytes free
Post-Run: 201,618,440,192 bytes free
375 --- E O F --- 2009-03-07 00:45:58
--------------------------------------------------------------------------
Malwarebytes' Anti-Malware 1.34
Database version: 1749
Windows 5.1.2600 Service Pack 2
3/7/2009 12:56:16 PM
mbam-log-2009-03-07 (12-56-16).txt
Scan type: Full Scan (C:\|)
Objects scanned: 87591
Time elapsed: 8 minute(s), 58 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\mibevilo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
-------------------------------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:58:22 PM, on 3/7/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\PRISMSVR.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\eMachines Bay Reader\shwiconem.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe
C:\Program Files\Dell Wireless\PRISMCFG.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\internet explorer\iexplore.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\eMachines Bay Reader\shwiconem.exe
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SMSystemAnalyzer] "C:\Program Files\iolo\System Mechanic 6\SMSystemAnalyzer.exe"
O4 - S-1-5-18 Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'SYSTEM')
O4 - .DEFAULT Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: Wireless USB 2.0 WLAN Card Utility.lnk = C:\Program Files\Dell Wireless\PRISMCFG.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Cleaner - {CCF00E14-7C5E-4420-9BF3-AA4809CFAA13} - C:\Program Files\ClickClean\ClickClean.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O24 - Desktop Component 0: (no name) - http://l.yimg.com/a/i/ww/thm/1/grd-1px_1.4.gif
--
End of file - 4653 bytes