ComboFix 09-05-12.04 - 1 05/12/2009 20:19.9 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1014.593 [GMT -8:00]
Running from: c:\documents and settings\1\Desktop\ADWARE & SPYWARE REMOVER\ComboFix.exe
AV: Norton Internet Security 2006 *On-access scanning enabled* (Updated)
FW: Norton Internet Security 2006 *enabled*
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\IE4 Error Log.txt
.
((((((((((((((((((((((((( Files Created from 2009-04-13 to 2009-05-13 )))))))))))))))))))))))))))))))
.
2009-04-24 03:08 . 2008-04-21 10:02 215552 ------w c:\windows\system32\dllcache\wordpad.exe
2009-04-24 02:20 . 2008-05-08 12:28 202752 ------w c:\windows\system32\dllcache\rmcast.sys
2009-04-24 01:38 . 2008-10-16 22:06 268648 ----a-w c:\windows\system32\mucltui.dll
2009-04-16 06:17 . 2009-04-16 06:17 136 ----a-w C:\pch.bat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-11 07:01 . 2006-12-17 17:52 -------- d-----w c:\program files\PokerStars
2009-05-11 05:46 . 2006-12-29 19:16 -------- d-----w c:\program files\Lx_cats
2009-04-23 22:57 . 2008-11-18 17:30 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-04-17 03:59 . 2006-12-18 00:42 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-04-10 04:21 . 2008-06-04 05:11 2048 ----a-w c:\windows\vknt.tmp
2009-04-06 23:32 . 2008-11-18 17:30 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-06 23:32 . 2008-11-18 17:30 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2006-12-14 01:48 . 2006-12-12 10:49 88 --sha-r c:\windows\system32\
04202E8837.sys
2006-12-14 02:01 . 2006-12-12 10:49 2516 --sha-w c:\windows\system32\KGyGaAvL.sys
2007-04-16 15:52 . 2005-08-16 10:18 161768 --sha-r c:\windows\system32\sdckhc.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-04-16_23.01.19 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-25 03:59 . 2007-01-19 20:15 74802 c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\atl.dll
+ 2009-05-12 19:05 . 2009-05-12 19:05 16384 c:\windows\temp\Perflib_Perfdata_6f4.dat
+ 2005-08-16 10:37 . 2006-03-01 19:42 11776 c:\windows\system32\xolehlp.dll
- 2005-08-16 10:37 . 2004-08-10 11:00 11776 c:\windows\system32\xolehlp.dll
+ 2005-08-16 10:18 . 2006-01-04 03:35 68096 c:\windows\system32\webclnt.dll
+ 2008-07-14 11:09 . 2008-07-14 11:09 62976 c:\windows\system32\tzchange.exe
+ 2005-08-16 10:18 . 2005-05-10 23:45 75776 c:\windows\system32\telnet.exe
- 2005-08-16 10:18 . 2004-08-10 11:00 96768 c:\windows\system32\srvsvc.dll
+ 2005-08-16 10:18 . 2004-12-07 19:32 96768 c:\windows\system32\srvsvc.dll
+ 2007-10-22 02:04 . 2007-11-30 12:39 17272 c:\windows\system32\spmsg.dll
+ 2005-08-16 10:18 . 2008-10-16 10:20 39424 c:\windows\system32\pngfilt.dll
- 2005-08-16 10:18 . 2006-05-10 05:25 39424 c:\windows\system32\pngfilt.dll
+ 2005-08-16 10:18 . 2009-04-25 20:24 63016 c:\windows\system32\perfc009.dat
- 2005-08-16 10:18 . 2009-04-06 11:12 63016 c:\windows\system32\perfc009.dat
+ 2005-08-16 10:18 . 2005-07-26 04:39 37888 c:\windows\system32\olecnv32.dll
+ 2005-08-16 10:18 . 2005-07-26 04:39 74752 c:\windows\system32\olecli32.dll
+ 2005-08-16 10:18 . 2006-10-13 12:35 65536 c:\windows\system32\nwwks.dll
+ 2005-08-16 10:18 . 2006-10-13 12:35 64000 c:\windows\system32\nwapi32.dll
+ 2005-08-16 10:37 . 2006-03-01 19:42 91136 c:\windows\system32\mtxoci.dll
+ 2005-08-16 10:18 . 2006-03-01 19:42 66560 c:\windows\system32\mtxclu.dll
- 2005-08-16 10:18 . 2004-08-10 11:00 66560 c:\windows\system32\mtxclu.dll
+ 2005-08-16 10:18 . 2008-03-25 04:50 60192 c:\windows\system32\msjter40.dll
+ 2005-08-16 10:37 . 2004-08-10 11:00 19429 c:\windows\system32\MsDtc\Trace\msdtcvtr.bat
+ 2005-08-16 10:18 . 2007-07-06 12:46 48640 c:\windows\system32\mqupgrd.dll
- 2005-08-16 10:18 . 2004-08-10 11:00 48640 c:\windows\system32\mqupgrd.dll
- 2005-08-16 10:18 . 2004-08-10 11:00 95744 c:\windows\system32\mqsec.dll
+ 2005-08-16 10:18 . 2007-07-06 12:46 95744 c:\windows\system32\mqsec.dll
+ 2005-08-16 10:18 . 2007-07-06 12:46 16896 c:\windows\system32\mqise.dll
- 2005-08-16 10:18 . 2004-08-10 11:00 16896 c:\windows\system32\mqise.dll
+ 2005-08-16 10:18 . 2007-07-06 12:46 47104 c:\windows\system32\mqdscli.dll
- 2005-08-16 10:18 . 2004-08-10 11:00 47104 c:\windows\system32\mqdscli.dll
+ 2005-08-16 10:18 . 2007-03-08 15:36 40960 c:\windows\system32\mf3216.dll
+ 2005-08-16 10:18 . 2008-10-16 10:20 16384 c:\windows\system32\jsproxy.dll
+ 2005-08-16 10:18 . 2008-10-16 10:20 96256 c:\windows\system32\inseng.dll
- 2005-08-16 10:18 . 2006-05-10 05:25 96256 c:\windows\system32\inseng.dll
+ 2005-08-16 10:18 . 2006-07-21 08:24 72704 c:\windows\system32\hlink.dll
+ 2005-08-16 10:40 . 2006-08-21 09:14 23040 c:\windows\system32\fltmc.exe
- 2005-08-16 10:40 . 2004-08-10 11:00 16896 c:\windows\system32\fltlib.dll
+ 2005-08-16 10:40 . 2006-08-21 12:21 16896 c:\windows\system32\fltlib.dll
+ 2005-08-16 10:18 . 2008-10-16 10:20 55808 c:\windows\system32\extmgr.dll
- 2005-08-16 10:18 . 2006-05-10 05:25 55808 c:\windows\system32\extmgr.dll
+ 2006-12-07 12:26 . 2006-06-14 09:00 82944 c:\windows\system32\drivers\wdmaud.sys
- 2006-12-07 12:26 . 2004-08-04 05:15 82944 c:\windows\system32\drivers\wdmaud.sys
+ 2005-08-16 10:18 . 2007-11-13 10:25 20480 c:\windows\system32\drivers\secdrv.sys
- 2005-08-16 10:18 . 2004-08-10 11:00 72960 c:\windows\system32\drivers\mqac.sys
+ 2005-08-16 10:18 . 2007-07-06 10:05 72960 c:\windows\system32\drivers\mqac.sys
+ 2005-08-16 10:18 . 2008-02-20 05:32 45568 c:\windows\system32\dnsrslvr.dll
- 2005-08-16 10:18 . 2004-08-10 11:00 45568 c:\windows\system32\dnsrslvr.dll
- 2006-12-07 12:26 . 2004-08-04 05:15 82944 c:\windows\system32\dllcache\wdmaud.sys
+ 2006-12-07 12:26 . 2006-06-14 09:00 82944 c:\windows\system32\dllcache\wdmaud.sys
+ 2007-05-16 15:12 . 2007-05-16 15:12 85504 c:\windows\system32\dllcache\wabimp.dll
+ 2006-12-07 12:23 . 2008-10-16 10:20 39424 c:\windows\system32\dllcache\pngfilt.dll
- 2006-12-07 12:23 . 2006-05-10 05:25 39424 c:\windows\system32\dllcache\pngfilt.dll
+ 2006-10-13 12:35 . 2006-10-13 12:35 65536 c:\windows\system32\dllcache\nwwks.dll
+ 2006-10-13 12:35 . 2006-10-13 12:35 64000 c:\windows\system32\dllcache\nwapi32.dll
+ 2008-03-25 04:50 . 2008-03-25 04:50 60192 c:\windows\system32\dllcache\msjter40.dll
+ 2007-07-06 12:46 . 2007-07-06 12:46 48640 c:\windows\system32\dllcache\mqupgrd.dll
+ 2007-07-06 12:46 . 2007-07-06 12:46 95744 c:\windows\system32\dllcache\mqsec.dll
+ 2007-07-06 12:46 . 2007-07-06 12:46 16896 c:\windows\system32\dllcache\mqise.dll
+ 2007-07-06 12:46 . 2007-07-06 12:46 47104 c:\windows\system32\dllcache\mqdscli.dll
+ 2007-07-06 10:05 . 2007-07-06 10:05 72960 c:\windows\system32\dllcache\mqac.sys
+ 2007-03-08 15:36 . 2007-03-08 15:36 40960 c:\windows\system32\dllcache\mf3216.dll
+ 2006-12-07 12:23 . 2008-10-16 10:20 16384 c:\windows\system32\dllcache\jsproxy.dll
+ 2006-12-07 12:23 . 2008-10-16 10:20 96256 c:\windows\system32\dllcache\inseng.dll
- 2006-12-07 12:23 . 2006-05-10 05:25 96256 c:\windows\system32\dllcache\inseng.dll
+ 2006-12-07 12:23 . 2008-10-15 14:18 18432 c:\windows\system32\dllcache\iedw.exe
- 2006-12-07 12:23 . 2006-05-09 11:41 18432 c:\windows\system32\dllcache\iedw.exe
+ 2006-07-21 08:24 . 2006-07-21 08:24 72704 c:\windows\system32\dllcache\hlink.dll
+ 2009-04-25 11:10 . 2006-08-21 09:14 23040 c:\windows\system32\dllcache\fltmc.exe
+ 2009-04-25 11:10 . 2006-08-21 12:21 16896 c:\windows\system32\dllcache\fltlib.dll
- 2006-12-07 12:23 . 2006-05-10 05:25 55808 c:\windows\system32\dllcache\extmgr.dll
+ 2006-12-07 12:23 . 2008-10-16 10:20 55808 c:\windows\system32\dllcache\extmgr.dll
+ 2008-02-20 05:32 . 2008-02-20 05:32 45568 c:\windows\system32\dllcache\dnsrslvr.dll
+ 2007-05-16 15:12 . 2007-05-16 15:12 86528 c:\windows\system32\dllcache\directdb.dll
+ 2006-06-22 05:06 . 2006-06-22 05:06 69120 c:\windows\system32\dllcache\ciodm.dll
+ 2006-10-12 14:02 . 2007-03-09 13:46 57344 c:\windows\system32\dllcache\agentdpv.dll
+ 2006-10-12 14:02 . 2006-10-12 14:02 42496 c:\windows\system32\dllcache\agentdp2.dll
+ 2005-08-16 10:37 . 2005-07-26 04:39 97792 c:\windows\system32\comrepl.dll
+ 2005-08-16 10:37 . 2005-07-26 04:39 60416 c:\windows\system32\colbact.dll
- 2005-08-16 10:18 . 2004-08-10 11:00 69120 c:\windows\system32\ciodm.dll
+ 2005-08-16 10:18 . 2006-06-22 05:06 69120 c:\windows\system32\ciodm.dll
+ 2005-08-16 10:18 . 2007-03-09 13:46 57344 c:\windows\msagent\agentdpv.dll
+ 2005-08-16 10:18 . 2006-10-12 14:02 42496 c:\windows\msagent\agentdp2.dll
+ 2004-09-30 02:04 . 2004-09-30 02:04 61440 c:\windows\Microsoft.NET\Framework\v1.0.3705\gacutil.exe
+ 2006-06-14 09:00 . 2006-06-14 09:00 82944 c:\windows\Driver Cache\i386\wdmaud.sys
+ 2005-08-16 10:18 . 2006-06-26 17:37 8192 c:\windows\system32\rasadhlp.dll
- 2005-08-16 10:18 . 2004-08-10 11:00 8192 c:\windows\system32\rasadhlp.dll
- 2006-12-07 12:26 . 2004-08-04 05:07 6400 c:\windows\system32\drivers\splitter.sys
+ 2006-12-07 12:26 . 2006-06-14 08:47 6400 c:\windows\system32\drivers\splitter.sys
- 2006-12-07 12:26 . 2004-08-04 05:07 6400 c:\windows\system32\dllcache\splitter.sys
+ 2006-12-07 12:26 . 2006-06-14 08:47 6400 c:\windows\system32\dllcache\splitter.sys
+ 2006-06-26 17:37 . 2006-06-26 17:37 8192 c:\windows\system32\dllcache\rasadhlp.dll
+ 2006-06-14 08:47 . 2006-06-14 08:47 6400 c:\windows\Driver Cache\i386\splitter.sys
+ 2009-04-25 03:59 . 2007-01-19 20:15 401462 c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\msvcp60.dll
+ 2009-04-25 03:59 . 2007-01-19 20:15 995383 c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42.dll
+ 2005-08-17 03:06 . 2008-10-15 14:00 351744 c:\windows\system32\xpsp3res.dll
- 2005-08-16 10:18 . 2004-08-10 11:00 132096 c:\windows\system32\wkssvc.dll
+ 2005-08-16 10:18 . 2006-08-17 12:28 132096 c:\windows\system32\wkssvc.dll
+ 2005-08-16 10:18 . 2007-03-17 13:43 292864 c:\windows\system32\winsrv.dll
+ 2005-08-16 10:18 . 2008-10-16 10:20 667648 c:\windows\system32\wininet.dll
+ 2005-08-16 10:18 . 2006-12-19 18:16 333824 c:\windows\system32\wiaservc.dll
+ 2005-08-16 10:18 . 2007-12-18 14:40 417792 c:\windows\system32\vbscript.dll
- 2005-08-16 10:18 . 2004-08-10 11:00 417792 c:\windows\system32\vbscript.dll
+ 2005-08-16 10:18 . 2007-03-08 15:36 577536 c:\windows\system32\user32.dll
+ 2005-08-16 10:18 . 2008-10-16 10:20 619008 c:\windows\system32\urlmon.dll
- 2005-08-16 10:18 . 2004-08-10 11:00 185344 c:\windows\system32\upnphost.dll
+ 2005-08-16 10:18 . 2007-02-05 20:17 185344 c:\windows\system32\upnphost.dll
+ 2005-08-16 10:18 . 2005-08-23 03:35 123392 c:\windows\system32\umpnpmgr.dll
- 2005-08-16 10:18 . 2004-08-10 11:00 101376 c:\windows\system32\txflog.dll
+ 2005-08-16 10:18 . 2005-07-26 04:39 101376 c:\windows\system32\txflog.dll
+ 2005-08-16 10:18 . 2005-07-08 16:27 249344 c:\windows\system32\tapisrv.dll
- 2005-08-16 10:18 . 2004-08-10 11:00 713216 c:\windows\system32\sxs.dll
+ 2005-08-16 10:18 . 2006-10-19 13:56 713216 c:\windows\system32\sxs.dll
- 2005-08-16 10:18 . 2004-08-10 11:00 134656 c:\windows\system32\shsvcs.dll
+ 2005-08-16 10:18 . 2006-12-19 21:52 134656 c:\windows\system32\shsvcs.dll
- 2005-08-16 10:18 . 2006-05-10 05:25 474112 c:\windows\system32\shlwapi.dll
+ 2005-08-16 10:18 . 2008-10-16 10:20 474112 c:\windows\system32\shlwapi.dll
+ 2005-08-16 10:18 . 2007-04-25 14:21 144896 c:\windows\system32\schannel.dll
- 2005-08-16 10:18 . 2004-08-10 11:00 144896 c:\windows\system32\schannel.dll
+ 2005-08-16 10:18 . 2005-07-26 04:39 397824 c:\windows\system32\rpcss.dll
+ 2005-08-16 10:18 . 2006-11-27 14:54 433152 c:\windows\system32\riched20.dll
+ 2005-08-16 10:18 . 2006-06-22 10:47 181248 c:\windows\system32\rasmans.dll
+ 2005-08-16 10:18 . 2009-04-25 20:24 402406 c:\windows\system32\perfh009.dat
- 2005-08-16 10:18 . 2009-04-06 11:12 402406 c:\windows\system32\perfh009.dat
+ 2005-08-16 10:18 . 2006-10-16 16:15 122880 c:\windows\system32\oledlg.dll
+ 2005-08-16 10:18 . 2007-12-04 18:38 550912 c:\windows\system32\oleaut32.dll
+ 2005-08-16 10:18 . 2006-10-13 12:35 142336 c:\windows\system32\nwprovau.dll
+ 2005-08-16 10:18 . 2005-08-22 18:29 197632 c:\windows\system32\netman.dll
- 2005-08-16 10:18 . 2006-07-14 15:31 332288 c:\windows\system32\netapi32.dll
+ 2005-08-16 10:18 . 2006-08-17 12:28 332288 c:\windows\system32\netapi32.dll
+ 2005-08-16 10:18 . 2008-03-25 04:50 355104 c:\windows\system32\msxbde40.dll
+ 2005-08-16 10:18 . 2008-03-25 04:50 621344 c:\windows\system32\mswstr10.dll
+ 2005-08-16 10:18 . 2008-03-25 04:50 838432 c:\windows\system32\mswdat10.dll
+ 2005-08-16 10:18 . 2008-10-16 10:20 532480 c:\windows\system32\mstime.dll
- 2005-08-16 10:18 . 2006-05-10 05:25 532480 c:\windows\system32\mstime.dll
+ 2005-08-16 10:18 . 2008-03-25 04:50 264992 c:\windows\system32\mstext40.dll
+ 2005-08-16 10:18 . 2008-03-25 04:50 559904 c:\windows\system32\msrepl40.dll
+ 2005-08-16 10:18 . 2008-03-25 04:50 322336 c:\windows\system32\msrd3x40.dll
+ 2005-08-16 10:18 . 2008-03-25 04:50 432928 c:\windows\system32\msrd2x40.dll
+ 2005-08-16 10:18 . 2008-10-16 10:20 146432 c:\windows\system32\msrating.dll
- 2005-08-16 10:18 . 2006-05-10 05:25 146432 c:\windows\system32\msrating.dll
+ 2005-08-16 10:18 . 2008-03-25 04:50 355104 c:\windows\system32\mspbde40.dll
+ 2005-08-16 10:18 . 2008-03-25 04:50 219936 c:\windows\system32\msltus40.dll
+ 2005-08-16 10:18 . 2008-03-25 04:50 248608 c:\windows\system32\msjtes40.dll
+ 2005-08-16 10:18 . 2008-03-27 08:12 151583 c:\windows\system32\msjint40.dll
- 2005-08-16 10:18 . 2004-08-10 11:00 151583 c:\windows\system32\msjint40.dll
+ 2005-08-16 10:18 . 2008-03-25 04:50 355112 c:\windows\system32\msjetoledb40.dll
+ 2005-08-16 10:18 . 2008-10-16 10:20 449024 c:\windows\system32\mshtmled.dll
+ 2005-08-16 10:18 . 2006-11-27 14:54 539136 c:\windows\system32\msftedit.dll
+ 2005-08-16 10:18 . 2008-03-25 04:50 326432 c:\windows\system32\msexcl40.dll
+ 2005-08-16 10:18 . 2008-03-25 04:50 518944 c:\windows\system32\msexch40.dll
+ 2005-08-16 10:37 . 2006-03-01 19:42 161280 c:\windows\system32\msdtcuiu.dll
- 2005-08-16 10:37 . 2004-08-10 11:00 161280 c:\windows\system32\msdtcuiu.dll
+ 2005-08-16 10:37 . 2006-03-01 19:42 956416 c:\windows\system32\msdtctm.dll
+ 2005-08-16 10:37 . 2006-03-01 19:42 426496 c:\windows\system32\msdtcprx.dll
- 2005-08-16 10:18 . 2004-08-10 11:00 471552 c:\windows\system32\mqutil.dll
+ 2005-08-16 10:18 . 2007-07-06 12:46 471552 c:\windows\system32\mqutil.dll
- 2005-08-16 10:18 . 2004-08-10 11:00 177152 c:\windows\system32\mqrt.dll
+ 2005-08-16 10:18 . 2007-07-06 12:46 177152 c:\windows\system32\mqrt.dll
+ 2005-08-16 10:18 . 2007-07-06 12:46 660992 c:\windows\system32\mqqm.dll
- 2005-08-16 10:18 . 2004-08-10 11:00 660992 c:\windows\system32\mqqm.dll
+ 2005-08-16 10:18 . 2007-07-06 12:46 138240 c:\windows\system32\mqad.dll
- 2005-08-16 10:18 . 2004-08-10 11:00 138240 c:\windows\system32\mqad.dll
+ 2005-08-16 10:18 . 2006-10-14 08:13 981760 c:\windows\system32\mfc42u.dll
+ 2005-08-16 10:18 . 2006-11-01 19:17 927504 c:\windows\system32\mfc40u.dll
- 2005-08-16 10:18 . 2004-10-28 01:21 721920 c:\windows\system32\lsasrv.dll
+ 2005-08-16 10:18 . 2007-11-07 09:26 721920 c:\windows\system32\lsasrv.dll
+ 2005-08-16 10:18 . 2007-04-16 15:52 984576 c:\windows\system32\kernel32.dll
+ 2005-08-16 10:18 . 2005-06-15 17:49 295936 c:\windows\system32\kerberos.dll
- 2005-08-16 10:18 . 2006-05-18 05:24 450560 c:\windows\system32\jscript.dll
+ 2005-08-16 10:18 . 2007-12-18 14:40 450560 c:\windows\system32\jscript.dll
+ 2005-08-16 10:40 . 2007-08-21 06:15 683520 c:\windows\system32\inetcomm.dll
- 2005-08-16 10:18 . 2006-05-10 05:25 251904 c:\windows\system32\iepeers.dll
+ 2005-08-16 10:18 . 2008-10-16 10:20 251904 c:\windows\system32\iepeers.dll
+ 2005-08-16 10:18 . 2008-02-20 06:51 282624 c:\windows\system32\gdi32.dll
- 2005-08-16 10:27 . 2009-01-16 19:48 348992 c:\windows\system32\FNTCACHE.DAT
+ 2005-08-16 10:27 . 2009-04-25 20:20 348992 c:\windows\system32\FNTCACHE.DAT
+ 2005-08-16 10:18 . 2008-07-07 20:32 253952 c:\windows\system32\es.dll
- 2005-08-16 10:18 . 2006-05-10 05:25 205312 c:\windows\system32\dxtrans.dll
+ 2005-08-16 10:18 . 2008-10-16 10:20 205312 c:\windows\system32\dxtrans.dll
+ 2005-08-16 10:18 . 2008-10-16 10:20 357888 c:\windows\system32\dxtmsft.dll
- 2005-08-16 10:18 . 2006-05-10 05:25 357888 c:\windows\system32\dxtmsft.dll
+ 2005-08-16 10:18 . 2007-04-23 10:32 364160 c:\windows\system32\drivers\update.sys
+ 2005-08-16 10:18 . 2006-08-16 09:37 225664 c:\windows\system32\drivers\tcpip6.sys
+ 2005-08-16 10:18 . 2007-10-30 17:20 360064 c:\windows\system32\drivers\tcpip.sys
+ 2005-08-16 10:18 . 2008-05-08 12:28 202752 c:\windows\system32\drivers\rmcast.sys
- 2005-08-16 10:18 . 2004-10-28 01:13 174592 c:\windows\system32\drivers\rdbss.sys
+ 2005-08-16 10:18 . 2006-05-05 09:47 174592 c:\windows\system32\drivers\rdbss.sys
- 2005-08-16 10:18 . 2004-08-10 11:00 163584 c:\windows\system32\drivers\nwrdr.sys
+ 2005-08-16 10:18 . 2006-10-13 10:23 163584 c:\windows\system32\drivers\nwrdr.sys
+ 2005-08-16 10:18 . 2007-02-09 11:10 574464 c:\windows\system32\drivers\ntfs.sys
+ 2005-08-16 10:18 . 2006-05-05 09:41 453120 c:\windows\system32\drivers\mrxsmb.sys
+ 2005-08-16 10:18 . 2007-12-18 09:51 179584 c:\windows\system32\drivers\mrxdav.sys
+ 2006-12-07 12:26 . 2006-06-14 08:47 172416 c:\windows\system32\drivers\kmixer.sys
+ 2005-08-16 10:18 . 2004-09-29 22:28 134912 c:\windows\system32\drivers\ipnat.sys
- 2005-08-16 10:18 . 2004-08-10 11:00 134912 c:\windows\system32\drivers\ipnat.sys
+ 2004-08-04 05:00 . 2006-03-17 00:33 262784 c:\windows\system32\drivers\http.sys
+ 2005-08-16 10:40 . 2006-08-21 09:14 128896 c:\windows\system32\drivers\fltmgr.sys
- 2006-12-07 12:26 . 2004-08-04 04:39 142464 c:\windows\system32\drivers\aec.sys
+ 2006-12-07 12:26 . 2006-02-15 00:22 142464 c:\windows\system32\drivers\aec.sys
+ 2005-08-16 10:18 . 2008-02-20 05:32 148992 c:\windows\system32\dnsapi.dll
+ 2006-08-17 12:28 . 2006-08-17 12:28 132096 c:\windows\system32\dllcache\wkssvc.dll
+ 2007-03-17 13:43 . 2007-03-17 13:43 292864 c:\windows\system32\dllcache\winsrv.dll
+ 2006-12-07 12:23 . 2008-10-16 10:20 667648 c:\windows\system32\dllcache\wininet.dll
+ 2006-12-19 18:16 . 2006-12-19 18:16 333824 c:\windows\system32\dllcache\wiaservc.dll
+ 2007-05-16 15:12 . 2007-05-16 15:12 510976 c:\windows\system32\dllcache\wab32.dll
+ 2007-06-26 15:13 . 2007-06-26 15:13 851968 c:\windows\system32\dllcache\vgx.dll
+ 2007-12-18 14:40 . 2007-12-18 14:40 417792 c:\windows\system32\dllcache\vbscript.dll
+ 2007-03-08 15:36 . 2007-03-08 15:36 577536 c:\windows\system32\dllcache\user32.dll
+ 2006-12-07 12:23 . 2008-10-16 10:20 619008 c:\windows\system32\dllcache\urlmon.dll
+ 2007-02-05 20:17 . 2007-02-05 20:17 185344 c:\windows\system32\dllcache\upnphost.dll
+ 2007-04-23 10:32 . 2007-04-23 10:32 364160 c:\windows\system32\dllcache\update.sys
+ 2006-08-16 09:37 . 2006-08-16 09:37 225664 c:\windows\system32\dllcache\tcpip6.sys
+ 2007-10-30 17:20 . 2007-10-30 17:20 360064 c:\windows\system32\dllcache\tcpip.sys
+ 2006-10-19 13:56 . 2006-10-19 13:56 713216 c:\windows\system32\dllcache\sxs.dll
+ 2006-12-19 21:52 . 2006-12-19 21:52 134656 c:\windows\system32\dllcache\shsvcs.dll
- 2006-12-07 12:23 . 2006-05-10 05:25 474112 c:\windows\system32\dllcache\shlwapi.dll
+ 2006-12-07 12:23 . 2008-10-16 10:20 474112 c:\windows\system32\dllcache\shlwapi.dll
+ 2007-04-25 14:21 . 2007-04-25 14:21 144896 c:\windows\system32\dllcache\schannel.dll
+ 2006-11-27 14:54 . 2006-11-27 14:54 433152 c:\windows\system32\dllcache\riched20.dll
+ 2006-05-05 09:47 . 2006-05-05 09:47 174592 c:\windows\system32\dllcache\rdbss.sys
+ 2006-06-22 10:47 . 2006-06-22 10:47 181248 c:\windows\system32\dllcache\rasmans.dll
+ 2006-10-16 16:15 . 2006-10-16 16:15 122880 c:\windows\system32\dllcache\oledlg.dll
+ 2007-12-04 18:38 . 2007-12-04 18:38 550912 c:\windows\system32\dllcache\oleaut32.dll
+ 2006-10-13 10:23 . 2006-10-13 10:23 163584 c:\windows\system32\dllcache\nwrdr.sys
+ 2006-10-13 12:35 . 2006-10-13 12:35 142336 c:\windows\system32\dllcache\nwprovau.dll
+ 2007-02-09 11:10 . 2007-02-09 11:10 574464 c:\windows\system32\dllcache\ntfs.sys
+ 2006-12-07 12:04 . 2006-08-17 12:28 332288 c:\windows\system32\dllcache\netapi32.dll
- 2006-12-07 12:04 . 2006-07-14 15:31 332288 c:\windows\system32\dllcache\netapi32.dll
+ 2008-03-25 04:50 . 2008-03-25 04:50 355104 c:\windows\system32\dllcache\msxbde40.dll
+ 2008-03-25 04:50 . 2008-03-25 04:50 621344 c:\windows\system32\dllcache\mswstr10.dll
+ 2008-03-25 04:50 . 2008-03-25 04:50 838432 c:\windows\system32\dllcache\mswdat10.dll
- 2006-12-07 12:23 . 2006-05-10 05:25 532480 c:\windows\system32\dllcache\mstime.dll
+ 2006-12-07 12:23 . 2008-10-16 10:20 532480 c:\windows\system32\dllcache\mstime.dll
+ 2008-03-25 04:50 . 2008-03-25 04:50 264992 c:\windows\system32\dllcache\mstext40.dll
+ 2008-03-25 04:50 . 2008-03-25 04:50 559904 c:\windows\system32\dllcache\msrepl40.dll
+ 2008-03-25 04:50 . 2008-03-25 04:50 322336 c:\windows\system32\dllcache\msrd3x40.dll
+ 2008-03-25 04:50 . 2008-03-25 04:50 432928 c:\windows\system32\dllcache\msrd2x40.dll
- 2006-12-07 12:23 . 2006-05-10 05:25 146432 c:\windows\system32\dllcache\msrating.dll
+ 2006-12-07 12:23 . 2008-10-16 10:20 146432 c:\windows\system32\dllcache\msrating.dll
+ 2008-03-25 04:50 . 2008-03-25 04:50 355104 c:\windows\system32\dllcache\mspbde40.dll
+ 2008-03-25 04:50 . 2008-03-25 04:50 219936 c:\windows\system32\dllcache\msltus40.dll
+ 2008-03-25 04:50 . 2008-03-25 04:50 248608 c:\windows\system32\dllcache\msjtes40.dll
+ 2006-12-26 13:07 . 2006-12-26 13:07 102400 c:\windows\system32\dllcache\msjro.dll
+ 2008-03-27 08:12 . 2008-03-27 08:12 151583 c:\windows\system32\dllcache\msjint40.dll
+ 2008-03-25 04:50 . 2008-03-25 04:50 355112 c:\windows\system32\dllcache\msjetol1.dll
+ 2006-12-07 12:23 . 2008-10-16 10:20 449024 c:\windows\system32\dllcache\mshtmled.dll
+ 2006-11-27 14:54 . 2006-11-27 14:54 539136 c:\windows\system32\dllcache\msftedit.dll
+ 2008-03-25 04:50 . 2008-03-25 04:50 326432 c:\windows\system32\dllcache\msexcl40.dll
+ 2008-03-25 04:50 . 2008-03-25 04:50 518944 c:\windows\system32\dllcache\msexch40.dll
+ 2006-12-26 13:07 . 2006-12-26 13:07 200704 c:\windows\system32\dllcache\msadox.dll
+ 2006-12-26 13:07 . 2006-12-26 13:07 180224 c:\windows\system32\dllcache\msadomd.dll
+ 2006-12-26 13:07 . 2006-12-26 13:07 536576 c:\windows\system32\dllcache\msado15.dll
+ 2006-05-05 09:41 . 2006-05-05 09:41 453120 c:\windows\system32\dllcache\mrxsmb.sys
+ 2007-12-18 09:51 . 2007-12-18 09:51 179584 c:\windows\system32\dllcache\mrxdav.sys
+ 2007-07-06 12:46 . 2007-07-06 12:46 471552 c:\windows\system32\dllcache\mqutil.dll
+ 2007-07-06 12:46 . 2007-07-06 12:46 177152 c:\windows\system32\dllcache\mqrt.dll
+ 2007-07-06 12:46 . 2007-07-06 12:46 660992 c:\windows\system32\dllcache\mqqm.dll
+ 2007-07-06 12:46 . 2007-07-06 12:46 138240 c:\windows\system32\dllcache\mqad.dll
+ 2006-10-14 08:13 . 2006-10-14 08:13 981760 c:\windows\system32\dllcache\mfc42u.dll
+ 2006-11-01 19:17 . 2006-11-01 19:17 927504 c:\windows\system32\dllcache\mfc40u.dll
+ 2007-11-07 09:26 . 2007-11-07 09:26 721920 c:\windows\system32\dllcache\lsasrv.dll
+ 2006-12-07 12:26 . 2006-06-14 08:47 172416 c:\windows\system32\dllcache\kmixer.sys
+ 2007-04-16 15:52 . 2007-04-16 15:52 984576 c:\windows\system32\dllcache\kernel32.dll
- 2006-12-07 12:23 . 2006-05-18 05:24 450560 c:\windows\system32\dllcache\jscript.dll
+ 2006-12-07 12:23 . 2007-12-18 14:40 450560 c:\windows\system32\dllcache\jscript.dll
+ 2007-08-21 06:15 . 2007-08-21 06:15 683520 c:\windows\system32\dllcache\inetcomm.dll
- 2006-12-07 12:23 . 2006-05-10 05:25 251904 c:\windows\system32\dllcache\iepeers.dll
+ 2006-12-07 12:23 . 2008-10-16 10:20 251904 c:\windows\system32\dllcache\iepeers.dll
+ 2008-02-20 06:51 . 2008-02-20 06:51 282624 c:\windows\system32\dllcache\gdi32.dll
+ 2009-04-25 11:10 . 2006-08-21 09:14 128896 c:\windows\system32\dllcache\fltmgr.sys
+ 2008-07-07 20:32 . 2008-07-07 20:32 253952 c:\windows\system32\dllcache\es.dll
- 2006-12-07 12:23 . 2006-05-10 05:25 205312 c:\windows\system32\dllcache\dxtrans.dll
+ 2006-12-07 12:23 . 2008-10-16 10:20 205312 c:\windows\system32\dllcache\dxtrans.dll
- 2006-12-07 12:23 . 2006-05-10 05:25 357888 c:\windows\system32\dllcache\dxtmsft.dll
+ 2006-12-07 12:23 . 2008-10-16 10:20 357888 c:\windows\system32\dllcache\dxtmsft.dll
+ 2006-12-07 12:21 . 2008-02-20 05:32 148992 c:\windows\system32\dllcache\dnsapi.dll
+ 2008-03-25 04:50 . 2008-03-25 04:50 554008 c:\windows\system32\dllcache\dao360.dll
+ 2006-08-25 15:45 . 2006-08-25 15:45 617472 c:\windows\system32\dllcache\comctl32.dll
+ 2006-12-07 12:23 . 2008-10-16 10:20 151040 c:\windows\system32\dllcache\cdfview.dll
- 2006-12-07 12:23 . 2006-05-10 05:25 151040 c:\windows\system32\dllcache\cdfview.dll
+ 2006-10-12 11:09 . 2006-10-12 11:09 256512 c:\windows\system32\dllcache\agentsvr.exe
- 2006-12-07 12:26 . 2004-08-04 04:39 142464 c:\windows\system32\dllcache\aec.sys
+ 2006-12-07 12:26 . 2006-02-15 00:22 142464 c:\windows\system32\dllcache\aec.sys
+ 2006-08-16 11:58 . 2006-08-16 11:58 100352 c:\windows\system32\dllcache\6to4svc.dll
+ 2005-08-16 10:37 . 2005-07-26 04:39 540160 c:\windows\system32\comuid.dll
- 2005-08-16 10:37 . 2004-08-10 11:00 540160 c:\windows\system32\comuid.dll
+ 2005-08-16 10:18 . 2006-08-25 15:45 617472 c:\windows\system32\comctl32.dll
+ 2005-08-16 10:37 . 2005-07-26 04:39 195072 c:\windows\system32\Com\comadmin.dll
+ 2005-08-16 10:37 . 2005-07-26 04:39 498688 c:\windows\system32\clbcatq.dll
+ 2005-08-16 10:37 . 2005-07-26 04:39 110080 c:\windows\system32\clbcatex.dll
- 2005-08-16 10:37 . 2004-08-10 11:00 110080 c:\windows\system32\clbcatex.dll
- 2005-08-16 10:18 . 2006-05-10 05:25 151040 c:\windows\system32\cdfview.dll
+ 2005-08-16 10:18 . 2008-10-16 10:20 151040 c:\windows\system32\cdfview.dll
+ 2005-08-16 10:37 . 2005-07-26 04:39 625152 c:\windows\system32\catsrvut.dll
+ 2005-08-16 10:37 . 2005-07-26 04:39 225792 c:\windows\system32\catsrv.dll
+ 2005-08-16 10:18 . 2006-08-16 11:58 100352 c:\windows\system32\6to4svc.dll
- 2005-08-16 10:18 . 2004-08-10 11:00 100352 c:\windows\system32\6to4svc.dll
+ 2005-08-16 10:18 . 2006-10-12 11:09 256512 c:\windows\msagent\agentsvr.exe
- 2005-08-16 10:18 . 2004-08-10 11:00 256512 c:\windows\msagent\agentsvr.exe
+ 2004-09-30 02:11 . 2004-09-30 02:11 118784 c:\windows\Microsoft.NET\Framework\v1.0.3705\ToGac.exe
+ 2004-10-08 01:36 . 2004-10-08 01:36 102400 c:\windows\Microsoft.NET\Framework\v1.0.3705\SetRegNI.exe
+ 2004-09-30 02:11 . 2004-09-30 02:11 106496 c:\windows\Microsoft.NET\Framework\v1.0.3705\netfxupdate.exe
+ 2006-12-07 12:21 . 2006-05-05 09:41 453120 c:\windows\Driver Cache\i386\mrxsmb.sys
+ 2006-06-14 08:47 . 2006-06-14 08:47 172416 c:\windows\Driver Cache\i386\kmixer.sys
+ 2006-03-17 00:33 . 2006-03-17 00:33 262784 c:\windows\Driver Cache\i386\http.sys
+ 2006-02-15 00:22 . 2006-02-15 00:22 142464 c:\windows\Driver Cache\i386\aec.sys
+ 2009-04-25 01:39 . 2006-08-25 15:45 1054208 c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
+ 2009-04-25 03:59 . 2007-01-19 20:15 1011774 c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42u.dll
+ 2005-08-16 10:18 . 2007-03-08 13:47 1843584 c:\windows\system32\win32k.sys
+ 2005-08-16 10:18 . 2007-10-26 03:36 8454656 c:\windows\system32\shell32.dll
+ 2005-08-16 10:18 . 2008-10-16 10:20 1499136 c:\windows\system32\shdocvw.dll
+ 2005-08-16 10:18 . 2006-06-22 05:06 1435648 c:\windows\system32\query.dll
- 2005-08-16 10:18 . 2004-08-10 11:00 1435648 c:\windows\system32\query.dll
+ 2005-08-16 10:18 . 2008-05-07 04:55 1288192 c:\windows\system32\quartz.dll
+ 2005-08-16 10:18 . 2005-07-26 04:39 1285120 c:\windows\system32\ole32.dll
+ 2005-08-16 10:18 . 2007-06-26 06:08 1104896 c:\windows\system32\msxml3.dll
+ 2005-08-16 10:18 . 2008-03-25 04:50 1516568 c:\windows\system32\msjet40.dll
+ 2005-08-16 10:18 . 2008-12-12 17:27 3067392 c:\windows\system32\mshtml.dll
- 2005-08-16 10:18 . 2004-08-10 11:00 1082368 c:\windows\system32\esent.dll
+ 2005-08-16 10:18 . 2005-10-20 22:20 1082368 c:\windows\system32\esent.dll
+ 2007-03-08 13:47 . 2007-03-08 13:47 1843584 c:\windows\system32\dllcache\win32k.sys
+ 2006-12-19 21:52 . 2007-10-26 03:36 8454656 c:\windows\system32\dllcache\shell32.dll
+ 2006-12-07 12:23 . 2008-10-16 10:20 1499136 c:\windows\system32\dllcache\shdocvw.dll
+ 2006-06-22 05:06 . 2006-06-22 05:06 1435648 c:\windows\system32\dllcache\query.dll
+ 2008-05-07 04:55 . 2008-05-07 04:55 1288192 c:\windows\system32\dllcache\quartz.dll
+ 2007-06-26 06:08 . 2007-06-26 06:08 1104896 c:\windows\system32\dllcache\msxml3.dll
+ 2007-05-16 15:12 . 2007-05-16 15:12 1314816 c:\windows\system32\dllcache\msoe.dll
+ 2008-03-25 04:50 . 2008-03-25 04:50 1516568 c:\windows\system32\dllcache\msjet40.dll
+ 2006-12-07 12:23 . 2008-12-12 17:27 3067392 c:\windows\system32\dllcache\mshtml.dll
+ 2007-06-13 10:23 . 2007-06-13 10:23 1033216 c:\windows\system32\dllcache\explorer.exe
- 2006-12-07 12:23 . 2006-05-10 05:25 1054208 c:\windows\system32\dllcache\danim.dll
+ 2006-12-07 12:23 . 2008-10-16 10:20 1054208 c:\windows\system32\dllcache\danim.dll
+ 2006-12-07 12:23 . 2008-10-16 10:20 1024000 c:\windows\system32\dllcache\browseui.dll
+ 2005-08-16 10:18 . 2008-10-16 10:20 1054208 c:\windows\system32\danim.dll
- 2005-08-16 10:18 . 2006-05-10 05:25 1054208 c:\windows\system32\danim.dll
+ 2005-08-16 10:37 . 2005-07-26 04:39 1267200 c:\windows\system32\comsvcs.dll
+ 2005-08-16 10:18 . 2008-10-16 10:20 1024000 c:\windows\system32\browseui.dll
+ 2005-08-16 10:38 . 2004-10-07 21:28 1200128 c:\windows\Microsoft.NET\Framework\v1.0.3705\System.Web.dll
- 2005-08-16 10:38 . 2004-07-20 00:54 1200128 c:\windows\Microsoft.NET\Framework\v1.0.3705\System.Web.dll
+ 2005-08-16 10:18 . 2007-06-13 10:23 1033216 c:\windows\explorer.exe
+ 2009-04-25 11:11 . 2009-04-25 11:11 1454080 c:\windows\assembly\NativeImages1_v1.0.3705\System.Design\1.0.3300.0__b03f5f7f11d50a3a_c68c6f62\System.Design.dll
- 2005-08-16 10:39 . 2005-08-16 10:39 1200128 c:\windows\assembly\GAC\System.Web\1.0.3300.0__b03f5f7f11d50a3a\System.Web.dll
+ 2009-04-25 11:11 . 2009-04-25 11:11 1200128 c:\windows\assembly\GAC\System.Web\1.0.3300.0__b03f5f7f11d50a3a\System.Web.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-10 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"LXCCCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll" [2005-07-20 73728]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-12-07 98304]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-06-27 143360]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-06-27 163840]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-06-27 135168]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-07-24 282624]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-5-30 113664]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-12 83360]
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave"= serwvdrv.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
backup=c:\windows\pss\Adobe Gamma Loader.exe.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Dell Network Assistant.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Dell Network Assistant.lnk
backup=c:\windows\pss\Dell Network Assistant.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2 (0x2)
"mnmsrvc"=3 (0x3)
"Symantec Core LC"=3 (0x3)
"SNDSrvc"=3 (0x3)
"NSCService"=3 (0x3)
"ERSvc"=2 (0x2)
"ehSched"=2 (0x2)
"ehRecvr"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"rpcapd"=3 (0x3)
"MDM"=2 (0x2)
"comHost"=3 (0x3)
"ccISPwdSvc"=3 (0x3)
"SPBBCSvc"=2 (0x2)
"LiveUpdate"=3 (0x3)
"Automatic LiveUpdate Scheduler"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires II\\age2_x1\\age2_x1.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\PokerStars\\PokerStars.exe"=
"c:\\Program Files\\PokerStars\\PokerStarsCommunicate.exe"=
"c:\\Program Files\\PokerStars\\PokerStarsUpdate.exe"=
"c:\\Program Files\\PokerStars\\Tracer.exe"=
"c:\\Program Files\\WildTangent\\Apps\\Dell Game Console\\GameConsole.exe"=
"c:\\WINDOWS\\system32\\lxcccoms.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxccpswx.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires II\\age2_x1\\age2_x1.icd"=
"c:\\Program Files\\Microsoft Games\\Age of Empires II\\EMPIRES2.ICD"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\age3x.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Shareaza\\Shareaza.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 1942\\BF1942.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires II\\empires2.exe"=
"c:\\Program Files\\IGZones\\IGZones.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\GamePark\\gameparkclient_en.exe"=
"c:\\Program Files\\GamePark\\gameparkloader_en.exe"=
"c:\\Program Files\\GamePark\\GameparkUpdate.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
"10426:UDP"= 10426:UDP:SingleClick ICC
"135:TCP"= 135:TCP:TCP Port 135
"5000:TCP"= 5000:TCP:*

isabled:TCP Port 5000
"5001:TCP"= 5001:TCP:*

isabled:TCP Port 5001
"5002:TCP"= 5002:TCP:*

isabled:TCP Port 5002
"5003:TCP"= 5003:TCP:*

isabled:TCP Port 5003
"5004:TCP"= 5004:TCP:*

isabled:TCP Port 5004
"5005:TCP"= 5005:TCP:*

isabled:TCP Port 5005
"5006:TCP"= 5006:TCP:*

isabled:TCP Port 5006
"5007:TCP"= 5007:TCP:*

isabled:TCP Port 5007
"5008:TCP"= 5008:TCP:*

isabled:TCP Port 5008
"5009:TCP"= 5009:TCP:*

isabled:TCP Port 5009
"5010:TCP"= 5010:TCP:*

isabled:TCP Port 5010
"5011:TCP"= 5011:TCP:*

isabled:TCP Port 5011
"5012:TCP"= 5012:TCP:*

isabled:TCP Port 5012
"5013:TCP"= 5013:TCP:*

isabled:TCP Port 5013
"5014:TCP"= 5014:TCP:*

isabled:TCP Port 5014
"5015:TCP"= 5015:TCP:*

isabled:TCP Port 5015
"5016:TCP"= 5016:TCP:*

isabled:TCP Port 5016
"5017:TCP"= 5017:TCP:*

isabled:TCP Port 5017
"5018:TCP"= 5018:TCP:*

isabled:TCP Port 5018
"5019:TCP"= 5019:TCP:*

isabled:TCP Port 5019
"5020:TCP"= 5020:TCP:*

isabled:TCP Port 5020
"2713:TCP"= 2713:TCP:mlxuzhn
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowOutboundDestinationUnreachable"= 0 (0x0)
"AllowOutboundSourceQuench"= 0 (0x0)
"AllowOutboundParameterProblem"= 0 (0x0)
R2 hnmwrlspkt;HomeNet Manager Wireless Protocol;c:\windows\system32\drivers\hnm_wrls_pkt.sys [7/13/2006 11:01 PM 13824]
R2 wsppkt;Wireless Security Protocol;c:\windows\system32\drivers\wsp_pkt.sys [7/13/2006 11:02 PM 13696]
S0 qikio;qikio;c:\windows\system32\drivers\lxvye.sys --> c:\windows\system32\drivers\lxvye.sys [?]
S2 zlyrk;Windows Image;c:\windows\system32\svchost.exe -k netsvcs [8/16/2005 2:18 AM 14336]
S3 ATHFMWDL;NETGEAR WG111T bootloader driver;c:\windows\system32\drivers\athfmwdl.sys [3/13/2007 9:33 PM 43392]
S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\windows\system32\DNINDIS5.sys [3/11/2007 10:00 PM 17149]
S4 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - COMHOST
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
vemjuxce
zlyrk
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe
.
Contents of the 'Scheduled Tasks' folder
2009-05-10 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 03:20]
2009-05-09 c:\windows\Tasks\Norton AntiVirus - Run Full System Scan - 1.job
- c:\progra~1\NORTON~1\NORTON~1\Navw32.exe [2005-11-17 09:32]
2008-11-18 c:\windows\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SDUpdate.exe [2008-11-08 23:31]
.
.
------- Supplementary Scan -------
.
uStart Page =
https://my.cms.csulb.edu/psp/pa88prd/EMPLOYEE/EMPL/h/?tab=PAPP_GUEST
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office10\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-05-12 20:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\zlyrk]
"ServiceDll"="c:\windows\system32\sdckhc.dll"
.
Completion time: 2009-05-13 20:23
ComboFix-quarantined-files.txt 2009-05-13 04:23
ComboFix2.txt 2009-04-16 23:03
ComboFix3.txt 2009-04-16 08:48
ComboFix4.txt 2009-04-16 07:36
ComboFix5.txt 2009-05-13 04:19
Pre-Run: 87,770,820,608 bytes free
Post-Run: 88,037,609,472 bytes free
543 --- E O F --- 2009-04-26 10:40