ComboFix 10-02-12.01 - Admin 02/14/2010 17:52:57.4.4 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2309 [GMT -5:00]
Running from: c:\documents and settings\Admin\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Admin\Desktop\CFScript.txt
FILE ::
"c:\documents and settings\Admin\Application Data\Sun\Java\Deployment\cache\6.0\37\4076ba25-7573e311"
"c:\documents and settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\APTemp\APQ802.tmp"
"c:\documents and settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\APTemp\APQ803.tmp"
"c:\documents and settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\APTemp\APQ804.tmp"
"c:\documents and settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\02400000.VBN"
"c:\documents and settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07AC0000.VBN"
"c:\documents and settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07AC0002.VBN"
"c:\documents and settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07AC0004.VBN"
"c:\documents and settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07AC0006.VBN"
"c:\documents and settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\07AC0008.VBN"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Admin\Application Data\Sun\Java\Deployment\cache\6.0\37\4076ba25-7573e311
.
((((((((((((((((((((((((( Files Created from 2010-01-14 to 2010-02-14 )))))))))))))))))))))))))))))))
.
2010-02-14 18:31 . 2010-02-14 18:31 23906 ----a-w- C:\ComboFix.zip
2010-02-14 18:30 . 2010-02-14 18:30 -------- d-----w- c:\documents and settings\All Users\Application Data\WinZip
2010-02-14 15:40 . 2010-02-14 15:40 -------- d-----w- C:\f9e1a342ef2bc6421138
2010-02-14 14:29 . 2008-04-13 18:40 96512 ------w- c:\windows\system32\drivers\atapi.sys
2010-02-14 12:58 . 2009-10-15 16:28 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2010-02-14 12:58 . 2009-10-15 16:28 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2010-02-14 12:58 . 2009-06-21 21:44 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2010-02-14 12:57 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2010-02-11 04:15 . 2010-02-11 04:16 -------- d-----w- c:\program files\Rasputin's Curse
2010-02-11 03:10 . 2010-02-11 03:10 -------- d-----w- c:\documents and settings\Sellner\Application Data\BigFishGames
2010-02-10 04:12 . 2010-02-10 05:14 -------- d-----w- c:\program files\Nightfall Mysteries - Curse of the Opera
2010-02-10 03:07 . 2010-02-10 03:07 -------- d-----w- c:\documents and settings\Sellner\Application Data\Gestalt Games
2010-02-09 22:21 . 2010-02-09 22:21 -------- d-----w- c:\documents and settings\Sellner\Application Data\Virtual Prophecy
2010-02-07 20:58 . 2010-02-07 20:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Million
2010-02-07 05:13 . 2010-02-07 05:13 -------- d-----w- c:\documents and settings\Sellner\Application Data\GameMill
2010-02-07 05:13 . 2010-02-07 05:13 -------- d-----w- c:\documents and settings\All Users\Application Data\GameMill
2010-02-07 04:10 . 2010-02-07 04:10 -------- d-----w- c:\documents and settings\Sellner\Application Data\LaJangada
2010-02-07 02:51 . 2010-02-07 02:51 -------- d-----w- c:\documents and settings\Sellner\Application Data\2monkeys
2010-02-05 22:52 . 2010-02-05 22:52 -------- d-----w- c:\documents and settings\Justin\Application Data\Malwarebytes
2010-02-04 23:34 . 2010-02-04 23:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-02-04 23:34 . 2010-02-04 23:37 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-02-04 23:17 . 2010-02-04 23:17 -------- d-----w- c:\program files\Trend Micro
2010-02-04 23:17 . 2010-02-04 23:17 -------- d-----w- c:\program files\ERUNT
2010-02-01 09:38 . 2010-02-01 09:39 -------- d-----w- c:\program files\Green Moon
2010-02-01 07:11 . 2010-02-01 07:11 -------- d-----w- c:\documents and settings\Sellner\Application Data\Valusoft
2010-02-01 07:11 . 2010-02-01 07:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Valusoft
2010-02-01 00:58 . 2010-02-01 00:58 348160 ----a-w- c:\documents and settings\Sellner\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-30dcfae9-n\msvcr71.dll
2010-02-01 00:58 . 2010-02-01 00:58 503808 ----a-w- c:\documents and settings\Sellner\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-30dcfae9-n\msvcp71.dll
2010-02-01 00:58 . 2010-02-01 00:58 499712 ----a-w- c:\documents and settings\Sellner\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-30dcfae9-n\jmc.dll
2010-02-01 00:58 . 2010-02-01 00:58 61440 ----a-w- c:\documents and settings\Sellner\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-7f3758a1-n\decora-sse.dll
2010-02-01 00:58 . 2010-02-01 00:58 12800 ----a-w- c:\documents and settings\Sellner\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-7f3758a1-n\decora-d3d.dll
2010-01-29 20:24 . 2010-01-29 20:24 -------- d-----w- c:\program files\Yahoo!
2010-01-29 20:23 . 2010-01-29 20:29 -------- d-----w- c:\program files\2Wire
2010-01-29 00:38 . 2010-01-29 00:38 -------- d-----w- c:\documents and settings\All Users\Application Data\SOS
2010-01-27 22:30 . 2010-01-27 22:30 503808 ----a-w- c:\documents and settings\Justin\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-2fc45657-n\msvcp71.dll
2010-01-27 22:30 . 2010-01-27 22:30 499712 ----a-w- c:\documents and settings\Justin\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-2fc45657-n\jmc.dll
2010-01-27 22:30 . 2010-01-27 22:30 348160 ----a-w- c:\documents and settings\Justin\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-2fc45657-n\msvcr71.dll
2010-01-27 22:30 . 2010-01-27 22:30 61440 ----a-w- c:\documents and settings\Justin\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-5eea7553-n\decora-sse.dll
2010-01-27 22:30 . 2010-01-27 22:30 12800 ----a-w- c:\documents and settings\Justin\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-5eea7553-n\decora-d3d.dll
2010-01-27 21:11 . 2010-01-27 21:11 -------- d-----w- c:\documents and settings\Sellner\Application Data\IronCode
2010-01-27 11:21 . 2010-01-27 11:21 348160 ----a-w- c:\documents and settings\Admin\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4915d82f-n\msvcr71.dll
2010-01-27 11:21 . 2010-01-27 11:21 503808 ----a-w- c:\documents and settings\Admin\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4915d82f-n\msvcp71.dll
2010-01-27 11:21 . 2010-01-27 11:21 499712 ----a-w- c:\documents and settings\Admin\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4915d82f-n\jmc.dll
2010-01-27 11:21 . 2010-01-27 11:21 61440 ----a-w- c:\documents and settings\Admin\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-768c093b-n\decora-sse.dll
2010-01-27 11:21 . 2010-01-27 11:21 12800 ----a-w- c:\documents and settings\Admin\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-768c093b-n\decora-d3d.dll
2010-01-16 05:16 . 2010-01-16 05:17 -------- d-----w- c:\program files\Veronica Rivers - The Order Of Conspiracy
2010-01-16 01:24 . 2010-02-14 07:43 664 ----a-w- c:\windows\system32\d3d9caps.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-14 19:42 . 2008-07-03 21:12 -------- d-----w- c:\program files\DashHawk v2
2010-02-14 18:34 . 2007-09-22 02:00 330568 ----a-w- c:\documents and settings\Admin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-14 16:13 . 2007-09-25 10:53 -------- d-----w- c:\program files\Java
2010-02-14 16:13 . 2007-09-25 10:53 -------- d-----w- c:\program files\Common Files\Java
2010-02-14 15:30 . 2007-10-12 02:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-02-14 15:26 . 2007-10-12 02:23 -------- d-----w- c:\program files\Microsoft Works
2010-02-11 04:55 . 2009-05-10 15:09 -------- d-----w- c:\documents and settings\All Users\Application Data\BigFishGamesCache
2010-02-11 04:55 . 2008-06-04 05:46 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-02-07 02:12 . 2009-05-11 07:13 -------- d-----w- c:\documents and settings\Sellner\Application Data\PlayFirst
2010-02-07 02:12 . 2007-09-28 03:58 -------- d-----w- c:\documents and settings\All Users\Application Data\PlayFirst
2010-02-05 16:27 . 2009-07-07 18:13 -------- d-----w- c:\program files\Bonjour
2010-02-01 09:01 . 2007-11-13 12:24 -------- d-----w- c:\program files\Google
2010-01-16 04:10 . 2009-06-10 06:15 -------- d-----w- c:\documents and settings\Sellner\Application Data\Gold Casual Games
2010-01-15 22:54 . 2010-01-15 22:54 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-05 20:26 . 2009-07-12 01:27 -------- d-----w- c:\documents and settings\Jason\Application Data\Apple Computer
2010-01-05 10:00 . 2006-02-28 12:00 832512 ------w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2006-02-28 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2006-02-28 12:00 17408 ------w- c:\windows\system32\corpol.dll
2010-01-05 02:51 . 2009-07-26 23:58 -------- d-----w- c:\documents and settings\Jordan\Application Data\Apple Computer
2009-12-31 16:50 . 2006-02-28 12:00 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-28 04:52 . 2009-12-28 04:52 -------- d-----w- c:\documents and settings\Sellner\Application Data\GamersDigital
2009-12-28 04:52 . 2009-12-28 04:52 -------- d-----w- c:\documents and settings\All Users\Application Data\GamersDigital
2009-12-28 02:25 . 2009-12-28 02:25 -------- d-----w- c:\documents and settings\All Users\Application Data\EscapeTheMuseum2
2009-12-26 10:29 . 2009-12-26 10:28 -------- d-----w- c:\documents and settings\All Users\Application Data\The Mirror Mysteries
2009-12-26 10:24 . 2009-12-26 09:23 -------- d-----w- c:\program files\Samantha Swift - Mystery From Atlantis
2009-12-26 09:24 . 2007-09-28 03:08 -------- d-----w- c:\documents and settings\All Users\Application Data\MumboJumbo
2009-12-26 08:17 . 2009-05-28 07:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Intenium
2009-12-26 07:12 . 2009-05-13 13:19 -------- d-----w- c:\documents and settings\Sellner\Application Data\Friday's games
2009-12-24 04:53 . 2009-12-24 04:52 -------- d-----w- c:\program files\The Otherside - Realm of Eons
2009-12-24 04:47 . 2009-12-24 04:46 -------- d-----w- c:\program files\The Dark Hills of Cherai
2009-12-24 03:20 . 2009-12-24 03:19 -------- d-----w- c:\documents and settings\Sellner\Application Data\GhostFleet
2009-12-24 01:54 . 2009-07-28 04:54 -------- d-----w- c:\documents and settings\Sellner\Application Data\JoyBits
2009-12-24 00:44 . 2009-12-24 00:44 -------- d-----w- c:\documents and settings\Sellner\Application Data\BrokenHearts
2009-12-21 07:02 . 2009-12-21 07:02 -------- d-----w- c:\documents and settings\Sellner\Application Data\CaribbeanHideaway
2009-12-21 04:51 . 2009-12-21 04:51 -------- d-----w- c:\documents and settings\Sellner\Application Data\Burdaloo
2009-12-21 03:49 . 2009-12-21 03:49 -------- d-----w- c:\documents and settings\Sellner\Application Data\Tandem Games
2009-12-20 09:52 . 2009-07-07 18:14 -------- d-----w- c:\documents and settings\Admin\Application Data\Apple Computer
2009-12-20 04:46 . 2009-12-20 04:46 115968 ---ha-w- c:\windows\system32\mlfcache.dat
2009-12-20 04:21 . 2009-07-09 22:04 -------- d-----w- c:\documents and settings\Sellner\Application Data\Apple Computer
2009-12-20 04:17 . 2009-12-20 04:16 -------- d-----w- c:\program files\iTunes
2009-12-20 04:17 . 2009-12-20 04:16 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-12-20 04:16 . 2009-12-20 04:16 -------- d-----w- c:\program files\iPod
2009-12-20 04:16 . 2009-07-07 18:28 -------- d-----w- c:\program files\Common Files\Apple
2009-12-20 04:16 . 2009-07-07 18:13 -------- d-----w- c:\program files\QuickTime
2009-12-20 04:13 . 2009-12-20 04:13 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-12-20 04:11 . 2009-07-17 00:40 -------- d-----w- c:\program files\Safari
2009-12-20 04:09 . 2009-12-20 04:09 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.21.10\SetupAdmin.exe
2009-12-18 04:57 . 2009-12-18 03:59 -------- d-----w- c:\documents and settings\Sellner\Application Data\Babylonia
2009-12-17 22:14 . 2008-11-25 09:55 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-17 02:17 . 2009-05-10 11:54 -------- d-----w- c:\documents and settings\All Users\Application Data\PlayPond
2009-12-16 18:43 . 2007-09-21 21:45 343040 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:08 . 2006-02-28 12:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-13 09:41 . 2008-08-01 05:10 26 ----a-w- c:\windows\popcinfo.dat
2009-12-04 18:22 . 2006-02-28 12:00 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-12-03 06:22 . 2009-12-03 06:22 143976 ----a-w- c:\documents and settings\Justin\Application Data\Move Networks\uninstall.exe
2009-12-03 06:22 . 2009-10-15 00:50 5642688 ----a-w- c:\documents and settings\Justin\Application Data\Move Networks\plugins\npqmp071701000002.dll
2009-11-27 17:11 . 2006-02-28 12:00 1291776 ----a-w- c:\windows\system32\quartz.dll
2009-11-27 17:11 . 2004-08-04 00:56 17920 ----a-w- c:\windows\system32\msyuv.dll
2009-11-27 16:07 . 2006-02-28 12:00 28672 ----a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:07 . 2001-08-17 22:36 8704 ----a-w- c:\windows\system32\tsbyuv.dll
2009-11-27 16:07 . 2006-02-28 12:00 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-11-27 16:07 . 2006-02-28 12:00 11264 ----a-w- c:\windows\system32\msrle32.dll
2009-11-27 16:07 . 2004-08-04 00:56 48128 ----a-w- c:\windows\system32\iyuv_32.dll
2009-11-21 15:51 . 2006-02-28 12:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-20 20:23 . 2009-12-02 21:59 52224 ----a-w- c:\documents and settings\Justin\Application Data\Mozilla\Firefox\Profiles\erhzkt1s.default\extensions\{a0729639-d831-46c9-811b-9b0aa79fb45a}\components\FFExternalAlert.dll
2009-11-20 20:23 . 2009-12-02 21:59 114688 ----a-w- c:\documents and settings\Justin\Application Data\Mozilla\Firefox\Profiles\erhzkt1s.default\extensions\{a0729639-d831-46c9-811b-9b0aa79fb45a}\components\npmozax.dll
.
((((((((((((((((((((((((((((( SnapShot_2010-02-14_15.57.18 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-02-14 18:30 . 2010-02-14 18:30 29184 c:\windows\Installer\{CD95F661-A5C4-44F5-A6AA-ECDD91C240BB}\IconCD95F6617.exe
+ 2010-02-14 16:08 . 2010-02-14 16:08 37888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\423f794d1f4ed6e120fbb02e436491cb\System.Windows.Presentation.ni.dll
+ 2010-02-14 16:08 . 2010-02-14 16:08 36864 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\19ca1747c1ea18a3b639b302bca8df93\System.Web.DynamicData.Design.ni.dll
+ 2010-02-14 16:07 . 2010-02-14 16:07 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\532438e2acfcadc469a4d468c51f8451\System.ComponentModel.DataAnnotations.ni.dll
- 2010-02-14 15:55 . 2010-02-14 15:55 94208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\532438e2acfcadc469a4d468c51f8451\System.ComponentModel.DataAnnotations.ni.dll
- 2010-02-14 15:55 . 2010-02-14 15:55 82944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\597b20e1b053d6a510cfe033c07a63e6\System.AddIn.Contract.ni.dll
+ 2010-02-14 16:07 . 2010-02-14 16:07 82944 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\597b20e1b053d6a510cfe033c07a63e6\System.AddIn.Contract.ni.dll
+ 2010-02-14 16:07 . 2010-02-14 16:07 55296 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\790cf1edb17ee41b59be62ecbd59613b\Microsoft.Vsa.ni.dll
+ 2010-02-14 16:07 . 2010-02-14 16:07 65536 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\5b6dc3197a6ba43fcc421f4161ab0469\Microsoft.Build.Framework.ni.dll
+ 2006-02-28 12:00 . 2009-11-21 15:51 471552 c:\windows\system32\dllcache\aclayers.dll
- 2010-02-14 12:58 . 2009-11-21 15:51 471552 c:\windows\system32\dllcache\aclayers.dll
+ 2010-02-14 18:30 . 2010-02-14 18:30 632320 c:\windows\Installer\{CD95F661-A5C4-44F5-A6AA-ECDD91C240BB}\IconCD95F66110.exe
+ 2010-02-14 16:08 . 2010-02-14 16:08 400896 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\c338a470b14851ce5987bb0f0869c310\System.Xml.Linq.ni.dll
+ 2010-02-14 16:08 . 2010-02-14 16:08 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\bb77ea11f46ab438b2b7ed7c180011a1\System.Web.Routing.ni.dll
+ 2010-02-14 16:08 . 2010-02-14 16:08 202240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\6ee255220d90dcbe80c990e443051cc5\System.Web.RegularExpressions.ni.dll
+ 2010-02-14 16:08 . 2010-02-14 16:08 859648 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\58f62044fa702ea6f936071aa5520baa\System.Web.Extensions.Design.ni.dll
+ 2010-02-14 16:08 . 2010-02-14 16:08 328704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\79c29ac85dd57dd485ab60118ac292ff\System.Web.Entity.ni.dll
+ 2010-02-14 16:08 . 2010-02-14 16:08 301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\d3d65e34fa60f0b6c72ca0d12ec89933\System.Web.Entity.Design.ni.dll
+ 2010-02-14 16:08 . 2010-02-14 16:08 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\b7891f5659db299dbd1b3c72db7edb9f\System.Web.DynamicData.ni.dll
+ 2010-02-14 16:08 . 2010-02-14 16:08 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\00ec08741a765c707bd9169346064a81\System.Web.Abstractions.ni.dll
+ 2010-02-14 16:08 . 2010-02-14 16:08 627200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\5a555c9ae6984c40157cf940bb519f7c\System.Transactions.ni.dll
+ 2010-02-14 16:08 . 2010-02-14 16:08 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\ea3366939280c1715f1c620e33ee3c8a\System.ServiceProcess.ni.dll
+ 2010-02-14 16:07 . 2010-02-14 16:07 311296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\bfd6e16d8c3589cd2bd3f8d46f0a5402\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2010-02-14 16:08 . 2010-02-14 16:08 621056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\519d9c618341b136f9b963ffb7495308\System.Net.ni.dll
+ 2010-02-14 16:07 . 2010-02-14 16:07 998400 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\8642fdfbf02a6cb6f01169fe6fdb5d11\System.Management.ni.dll
+ 2010-02-14 16:07 . 2010-02-14 16:07 330752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\1d3fbbd23ce1e8637ef4f40a8d23cd32\System.Management.Instrumentation.ni.dll
+ 2010-02-14 16:07 . 2010-02-14 16:07 280064 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\4267bd908175603006c6c90bb5d900c7\System.EnterpriseServices.Wrapper.dll
+ 2010-02-14 16:07 . 2010-02-14 16:07 627712 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\4267bd908175603006c6c90bb5d900c7\System.EnterpriseServices.ni.dll
+ 2010-02-14 16:07 . 2010-02-14 16:07 455680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\c434a07332ce490711c27fd0edb7562f\System.DirectoryServices.Protocols.ni.dll
+ 2010-02-14 16:07 . 2010-02-14 16:07 881152 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\8b3bb7a2c2f3ffe94c866283f1cd5957\System.DirectoryServices.AccountManagement.ni.dll
+ 2010-02-14 16:07 . 2010-02-14 16:07 939008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\a4b887f476fa4b8746a93a9fc2208560\System.Data.Services.Client.ni.dll
+ 2010-02-14 16:07 . 2010-02-14 16:07 354816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\1cf3acad6553d6c59df576794f4e8bd6\System.Data.Services.Design.ni.dll
+ 2010-02-14 16:07 . 2010-02-14 16:07 756736 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\392de34573f9f8ec885714f2f3e7f07f\System.Data.Entity.Design.ni.dll
- 2010-02-14 15:55 . 2010-02-14 15:55 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\1db495ff00bbd14df4af6680c4de0653\System.Data.DataSetExtensions.ni.dll
+ 2010-02-14 16:07 . 2010-02-14 16:07 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\1db495ff00bbd14df4af6680c4de0653\System.Data.DataSetExtensions.ni.dll
+ 2010-02-14 16:07 . 2010-02-14 16:07 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\de514e484e49b04b016949d57ffac03e\System.Configuration.Install.ni.dll
+ 2010-02-14 16:07 . 2010-02-14 16:07 633856 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\ce984d754e3c0b6be4504b785cc43574\System.AddIn.ni.dll
- 2010-02-14 15:55 . 2010-02-14 15:55 633856 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\ce984d754e3c0b6be4504b785cc43574\System.AddIn.ni.dll
- 2010-02-14 15:55 . 2010-02-14 15:55 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\55b9eff9e23359faed4351386c062238\Microsoft.Build.Utilities.ni.dll
+ 2010-02-14 16:07 . 2010-02-14 16:07 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\55b9eff9e23359faed4351386c062238\Microsoft.Build.Utilities.ni.dll
- 2010-02-14 15:55 . 2010-02-14 15:55 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\4217124db1ea5de5f1a1f3eea75e8d32\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2010-02-14 16:07 . 2010-02-14 16:07 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\4217124db1ea5de5f1a1f3eea75e8d32\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2010-02-14 18:30 . 2010-02-14 18:30 1544192 c:\windows\Installer\8ca66b.msi
+ 2010-02-14 16:08 . 2010-02-14 16:08 1356288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\ac1750e78d79520dcf19195772eff1b6\System.WorkflowServices.ni.dll
+ 2010-02-14 16:08 . 2010-02-14 16:08 1908224 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\d265da36954fcb4cb7ad5adc693ea0f2\System.Workflow.Runtime.ni.dll
+ 2010-02-14 16:08 . 2010-02-14 16:08 4514304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\693a8fbe6f7ad6e4e429052da4317e59\System.Workflow.ComponentModel.ni.dll
+ 2010-02-14 16:08 . 2010-02-14 16:08 2992640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\cc99fbbac0b6e4e9ca62093e49b0c16b\System.Workflow.Activities.ni.dll
+ 2010-02-14 16:08 . 2010-02-14 16:08 1840640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\b57bb002a655920cbfa2bee29d1e22b7\System.Web.Services.ni.dll
+ 2010-02-14 16:08 . 2010-02-14 16:08 2209280 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\81197e32ec931f439b3114e9031b65d6\System.Web.Mobile.ni.dll
+ 2010-02-14 16:08 . 2010-02-14 16:08 2403328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\7f64c9d25471b72e1e957bdfe67947c8\System.Web.Extensions.ni.dll
+ 2010-02-14 16:08 . 2010-02-14 16:08 1917440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\63cf639b6e0a3c25c1643c85016e7422\System.Speech.ni.dll
+ 2010-02-14 16:08 . 2010-02-14 16:08 1706496 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\340cad17fe57947eacbc8fa2cea780da\System.ServiceModel.Web.ni.dll
+ 2010-02-14 16:07 . 2010-02-14 16:07 1116672 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\543aced762f6b0c3f8e037955941afc6\System.DirectoryServices.ni.dll
+ 2010-02-14 16:07 . 2010-02-14 16:07 1801216 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\a6b58624486714fa71e5e35186850ff0\System.Deployment.ni.dll
+ 2010-02-14 16:07 . 2010-02-14 16:07 1328128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\956a513dcbd44d5a6801840ef2b0b47b\System.Data.Services.ni.dll
+ 2010-02-14 16:07 . 2010-02-14 16:07 9924096 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\6479f975b105808a8d9e7a7fdc762551\System.Data.Entity.ni.dll
- 2010-02-14 15:55 . 2010-02-14 15:55 1712128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\1c86afc399d0fdd8e069266ffbe748d1\Microsoft.VisualBasic.ni.dll
+ 2010-02-14 16:07 . 2010-02-14 16:07 1712128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\1c86afc399d0fdd8e069266ffbe748d1\Microsoft.VisualBasic.ni.dll
+ 2010-02-14 16:07 . 2010-02-14 16:07 2332160 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\b261961046545831aa60963e84905968\Microsoft.JScript.ni.dll
- 2010-02-14 15:55 . 2010-02-14 15:55 1620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\bd241492d96db39f20e758c13c845033\Microsoft.Build.Tasks.ni.dll
+ 2010-02-14 16:07 . 2010-02-14 16:07 1620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\bd241492d96db39f20e758c13c845033\Microsoft.Build.Tasks.ni.dll
- 2010-02-14 15:55 . 2010-02-14 15:55 1966080 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\a47100d8f4574bed2d49d83d0ab8964e\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2010-02-14 16:07 . 2010-02-14 16:07 1966080 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\a47100d8f4574bed2d49d83d0ab8964e\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2010-02-14 16:08 . 2010-02-14 16:08 11796992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\3963ce03d445a8619abbf388d590134b\System.Web.ni.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ABIT uGuruIII"="c:\program files\ABIT\uGuru\uGuru.exe" [2006-10-24 417792]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-12-23 143360]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"EPSON Stylus Photo R200 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE" [2003-07-08 99840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-19 8429568]
"nwiz"="nwiz.exe" [2007-04-19 1626112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-04-19 81920]
"RTHDCPL"="RTHDCPL.EXE" [2006-11-14 16270848]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"JMB36X IDE Setup"="c:\windows\JM\JMInsIDE.exe" [2006-10-30 36864]
"36X Raid Configurer"="c:\windows\system32\JMRaidSetup.exe" [2006-11-16 1953792]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"vptray"="c:\progra~1\SYMANT~1\SYMANT~1\vptray.exe" [2002-07-30 77824]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
c:\documents and settings\Sellner\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]
Printkey2000.lnk - c:\program files\PrintKey2000\Printkey2000.exe [2007-9-24 869376]
c:\documents and settings\Justin\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]
c:\documents and settings\Admin\Start Menu\Programs\Startup\
Printkey2000.lnk - c:\program files\PrintKey2000\Printkey2000.exe [2007-9-24 869376]
Shortcut to Core Temp.exe.lnk - c:\core temp\Core Temp.exe [2007-3-17 183296]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Printkey2000.lnk - c:\program files\PrintKey2000\Printkey2000.exe [2007-9-24 869376]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2009-11-18 495432]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
Source= c:\program files\e-AA\DesktopSobrietyCheck.htm
FriendlyName=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\mpiexec.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R0 UGURU;UGURU;c:\windows\system32\drivers\uGuru.sys [9/21/2007 8:42 PM 14592]
R3 TCCrystalCpuInfo;TCCrystalCpuInfo;\??\c:\docume~1\Admin\LOCALS~1\Temp\TCCpuInfo.sys --> c:\docume~1\Admin\LOCALS~1\Temp\TCCpuInfo.sys [?]
S2 FAH@C:+Documents and Settings+Admin+fah.exe;FAH@C:+Documents and Settings+Admin+fah.exe;c:\documents and settings\Admin\fah.exe -svcstart --> c:\documents and settings\Admin\fah.exe -svcstart [?]
S2 FAH@C:+Program Files+Folding@Home Windows SMP Client V1.01+fah.exe;FAH@C:+Program Files+Folding@Home Windows SMP Client V1.01+fah.exe;c:\program files\Folding@Home Windows SMP Client V1.01\fah.exe -svcstart --> c:\program files\Folding@Home Windows SMP Client V1.01\fah.exe -svcstart [?]
S2 gupdate1c9a8b5f9328c5a;Google Update Service (gupdate1c9a8b5f9328c5a);c:\program files\Google\Update\GoogleUpdate.exe [3/19/2009 12:13 PM 133104]
S2 mpich2_smpd;MPICH2 Process Manager, Argonne National Lab;c:\program files\Folding@Home Windows SMP Client V1.01\smpd.exe --> c:\program files\Folding@Home Windows SMP Client V1.01\smpd.exe [?]
.
Contents of the 'Scheduled Tasks' folder
2010-02-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-19 17:13]
2010-02-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-19 17:13]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://att.yahoo.com
uInternet Connection Wizard,ShellNext = hxxp://www.broderbund.com/jump.jsp?itemID=442&itemType=CATEGORY
IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-us\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://aolsvc.aol.com/onlinegames/free-trial-text-express-2-deluxe/zylomplayer.cab
DPF: {D410AFBD-4E26-4D5F-840F-0412D6F6BB8D} - hxxp://aolsvc.aol.com/onlinegames/free-trial-sandscript/SandScript.1.0.0.21.cab
FF - ProfilePath - c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\8ns8dvz4.default\
FF - prefs.js: browser.startup.homepage - hxxp://google.com
FF - plugin: c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\8ns8dvz4.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071303000006.dll
FF - plugin: c:\documents and settings\All Users\Application Data\RealArcade\npraclient.dll
FF - plugin: c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft Research\HDView for Firefox\nphdview.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npraclient.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-02-14 17:59
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
EPSON Stylus Photo R200 Series = c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2H1.EXE /P30 "EPSON Stylus Photo R200 Series" /M "Stylus Photo R200" /EF "HKCU"?'???G????????????IB~??e?????????????p????????????????????JB~????p???????????8?????????????C~????p?????????C~p??????????????|???????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
"ServiceDll"="c:\windows\system32\es.dll"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\FAH@C:+Documents and Settings+Admin+fah.exe]
"ImagePath"="c:\documents and settings\Admin\fah.exe -svcstart"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\FAH@C:+Program Files+Folding@Home Windows SMP Client V1.01+fah.exe]
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1482476501-1035525444-725345543-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\ActiveSync]
"Name"="ActiveSync"
"DisplayName"="Microsoft ActiveSync"
"Param1"="ActiveSync"
"Type"="wellknown"
"Order"=dword:00000000
"State"=dword:0000000b
[HKEY_USERS\S-1-5-21-1482476501-1035525444-725345543-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\IESettings]
"Name"="IESettings"
"Type"="IESettings"
"Order"=dword:00000003
"State"=dword:0000000b
[HKEY_USERS\S-1-5-21-1482476501-1035525444-725345543-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\MediaFiles]
"Name"="MediaFiles"
"Type"="MediaFiles"
"Order"=dword:00000002
"State"=dword:0000000b
[HKEY_USERS\S-1-5-21-1482476501-1035525444-725345543-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\NPW]
"Name"="NPW"
"Param1"="NPW"
"Type"="wellknown"
"Order"=dword:00000001
"State"=dword:0000000b
.
Completion time: 2010-02-14 18:00:12
ComboFix-quarantined-files.txt 2010-02-14 23:00
ComboFix2.txt 2010-02-14 16:01
ComboFix3.txt 2010-02-14 14:43
ComboFix4.txt 2010-02-13 23:51
Pre-Run: 281,652,793,344 bytes free
Post-Run: 281,720,168,448 bytes free
- - End Of File - - 10CFF4F3D998978D695B21B79F90AB1C