ComboFix 08-10-18.01 - Administrator 2008-10-18 21:59:17.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1460 [GMT 1:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrator\Desktop\CFSCRIPT.txt
* Created a new restore point
FILE ::
C:\Documents and Settings\Administrator\delself.bat
C:\WINDOWS\system32\ihmfkpaj.exe
C:\WINDOWS\system32\nt2vbcn.dll
C:\WINDOWS\system32\pabolsbu.exe
C:\WINDOWS\system32\wini104552502.exe
C:\WINDOWS\system32\zmnovqnc.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Administrator\Application Data\Azureus
C:\Documents and Settings\Administrator\Application Data\Azureus\.certs
C:\Documents and Settings\Administrator\Application Data\Azureus\.keystore
C:\Documents and Settings\Administrator\Application Data\Azureus\.lock
C:\Documents and Settings\Administrator\Application Data\Azureus\active\
08E68D2E3812E87403ABB974B40605C503374C26.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\
08E68D2E3812E87403ABB974B40605C503374C26.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\
08E68D2E3812E87403ABB974B40605C503374C26\fmfile1.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\
08E68D2E3812E87403ABB974B40605C503374C26\fmfile10.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\
08E68D2E3812E87403ABB974B40605C503374C26\fmfile17.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\
08E68D2E3812E87403ABB974B40605C503374C26\fmfile18.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\
08E68D2E3812E87403ABB974B40605C503374C26\fmfile19.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\
08E68D2E3812E87403ABB974B40605C503374C26\fmfile20.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\
08E68D2E3812E87403ABB974B40605C503374C26\fmfile3.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\
08E68D2E3812E87403ABB974B40605C503374C26\fmfile4.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\
08E68D2E3812E87403ABB974B40605C503374C26\fmfile5.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\
08E68D2E3812E87403ABB974B40605C503374C26\fmfile6.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\
08E68D2E3812E87403ABB974B40605C503374C26\fmfile7.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\
08E68D2E3812E87403ABB974B40605C503374C26\fmfile8.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\
08E68D2E3812E87403ABB974B40605C503374C26\fmfile9.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\
0BCA512E8CA5C5207108E41D01D0CEC6B40A8DF4.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\
0BCA512E8CA5C5207108E41D01D0CEC6B40A8DF4.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\219EF2D49D43D9C5089A0A4DFED098198A766FE2.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\219EF2D49D43D9C5089A0A4DFED098198A766FE2.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\24DCA2D5C5AD565727CA36F66B182D8F92C495AE.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\24DCA2D5C5AD565727CA36F66B182D8F92C495AE.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\2DD5638A95C4A4B8756FD1B796C12644B543FCE0.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\2DD5638A95C4A4B8756FD1B796C12644B543FCE0.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\30B0F399310CCEB5FDBF0158FC2F8D46B6BE7F0B.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\30B0F399310CCEB5FDBF0158FC2F8D46B6BE7F0B.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\3D98B939904F4759D262B1C29D39E4E77BFE5280.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\3D98B939904F4759D262B1C29D39E4E77BFE5280.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\3D98B939904F4759D262B1C29D39E4E77BFE5280\fmfile1.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\3F7EC5F6E333B6108EA1B5A84975599682DF0884.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\3F7EC5F6E333B6108EA1B5A84975599682DF0884.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\45767D3BF06B1B44F1603C1962B52EBD700700D2.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\45767D3BF06B1B44F1603C1962B52EBD700700D2.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\59F4AB91820E38BDB8023FE9AD764CD7D4F108F4.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\59F4AB91820E38BDB8023FE9AD764CD7D4F108F4.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\5C7A0C305610D2B89B7A857C1664A3DFDB5545B9.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\5C7A0C305610D2B89B7A857C1664A3DFDB5545B9.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\5DB6119D34F1CA6AAE609FFE849582BF4AACDB3D.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\5DB6119D34F1CA6AAE609FFE849582BF4AACDB3D.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\5E33D3F73BECBE416359AD032CB46E16DE146B24.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\5E33D3F73BECBE416359AD032CB46E16DE146B24.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\61CFE790BD87E8AD23C130E5CA044FFEC9ED1672.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\61CFE790BD87E8AD23C130E5CA044FFEC9ED1672.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\62B3660F444A472897ABD20C7130E9F3182451BD.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\62B3660F444A472897ABD20C7130E9F3182451BD.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\672C6823C81AE793D2563A92D07E1B69D64AE99F.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\672C6823C81AE793D2563A92D07E1B69D64AE99F.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\67478A7C353518760BC4B8E64E9C1C7918B05808.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\67478A7C353518760BC4B8E64E9C1C7918B05808.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\7E5D73BBBE956E002486CB0126B1CF359ABA1DE4.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\7E5D73BBBE956E002486CB0126B1CF359ABA1DE4.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\8EA2E2715E273885CB207E7B43D82E88CC3FCCCC.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\8EA2E2715E273885CB207E7B43D82E88CC3FCCCC.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\9790663AC3F9FB447A48B4EE48075F25037388B6.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\9790663AC3F9FB447A48B4EE48075F25037388B6.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\97AB8B91995EB6D18E499A79AE79690223CDF5A6.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\97AB8B91995EB6D18E499A79AE79690223CDF5A6.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\A62FA1C79E7394B889D0D9A80F8E4ADAA911F7F4.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\A62FA1C79E7394B889D0D9A80F8E4ADAA911F7F4.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\AC01364F2EE88AB5F02A3E8B6EFBBDC4F0D9C0D9.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\AC01364F2EE88AB5F02A3E8B6EFBBDC4F0D9C0D9.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\AC90766B6CEF0335C860BD4E394D549781609FA1.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\AC90766B6CEF0335C860BD4E394D549781609FA1.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\AF9B51788A0A5B22176C48B07DCE428F768722F6.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\AF9B51788A0A5B22176C48B07DCE428F768722F6.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\B9E434B69FD761030B3462264B9D7DA748961F3B.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\B9E434B69FD761030B3462264B9D7DA748961F3B.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\cache.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\CB126A3F643E140015B543EA30ABB06BC4390ED9.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\CB126A3F643E140015B543EA30ABB06BC4390ED9.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\D6260E2B69F9C7D0DD5D87A6AEBDD9662F79C040.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\D6260E2B69F9C7D0DD5D87A6AEBDD9662F79C040.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\D882733551FF191F0EA543A29E7A473081528074.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\D882733551FF191F0EA543A29E7A473081528074.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\DBE3F1B0B99C7C3D825BBEA58EB12CD235861EFD.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\DBE3F1B0B99C7C3D825BBEA58EB12CD235861EFD.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\DE5BA75C6A82EDAB575439AB5675251C070583C7.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\DE5BA75C6A82EDAB575439AB5675251C070583C7.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\DF60DC8272724BC2373664FAA9FB02B2E0B18186.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\DF60DC8272724BC2373664FAA9FB02B2E0B18186.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\E408B7B15249293C4C662B22DD4E237342AC766D.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\E408B7B15249293C4C662B22DD4E237342AC766D.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\EC04769E54C2C4DE0A2D2FA25FE180934EA243F2.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\EC04769E54C2C4DE0A2D2FA25FE180934EA243F2.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\F4069C1BD1879798F92485959F95BAAD6A4DD9DC.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\F4069C1BD1879798F92485959F95BAAD6A4DD9DC.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\F60248F57621FDE2F4D87B31814DE4C9635349BA.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\F60248F57621FDE2F4D87B31814DE4C9635349BA.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\FAB5BD4AF7B798A873899D156C21C29109C90821.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\FAB5BD4AF7B798A873899D156C21C29109C90821.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\FEF8ABEE49C444FA762B05767C3D588776FCCF9E.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\FEF8ABEE49C444FA762B05767C3D588776FCCF9E.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\active\FFEE8E5AB9DFF4524079107193071A6E7A9DF64E.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\active\FFEE8E5AB9DFF4524079107193071A6E7A9DF64E.dat.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\azureus.config
C:\Documents and Settings\Administrator\Application Data\Azureus\azureus.config.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\azureus.statistics
C:\Documents and Settings\Administrator\Application Data\Azureus\azureus.statistics.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\banips.config
C:\Documents and Settings\Administrator\Application Data\Azureus\banips.config.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\dht\addresses.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\dht\contacts.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\dht\diverse.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\dht\general.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\dht\version.dat
C:\Documents and Settings\Administrator\Application Data\Azureus\downloads.config
C:\Documents and Settings\Administrator\Application Data\Azureus\downloads.config.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\filters.config
C:\Documents and Settings\Administrator\Application Data\Azureus\ipfilter.cache
C:\Documents and Settings\Administrator\Application Data\Azureus\logs\alerts_1.log
C:\Documents and Settings\Administrator\Application Data\Azureus\logs\debug_1.log
C:\Documents and Settings\Administrator\Application Data\Azureus\logs\debug_2.log
C:\Documents and Settings\Administrator\Application Data\Azureus\logs\seltrace_1.log
C:\Documents and Settings\Administrator\Application Data\Azureus\logs\seltrace_2.log
C:\Documents and Settings\Administrator\Application Data\Azureus\logs\thread_1.log
C:\Documents and Settings\Administrator\Application Data\Azureus\logs\thread_2.log
C:\Documents and Settings\Administrator\Application Data\Azureus\tmp\AZU50750.tmp
C:\Documents and Settings\Administrator\Application Data\Azureus\tmp\AZU50751.tmp
C:\Documents and Settings\Administrator\Application Data\Azureus\tmp\AZU50752.tmp
C:\Documents and Settings\Administrator\Application Data\Azureus\tmp\AZU50753.tmp
C:\Documents and Settings\Administrator\Application Data\Azureus\tmp\AZU50754.tmp
C:\Documents and Settings\Administrator\Application Data\Azureus\tmp\AZU50755.tmp
C:\Documents and Settings\Administrator\Application Data\Azureus\tracker.config
C:\Documents and Settings\Administrator\Application Data\Azureus\tracker.config.bak
C:\Documents and Settings\Administrator\Application Data\Azureus\update.log
C:\Documents and Settings\Administrator\Application Data\Azureus\update.properties
C:\Documents and Settings\Administrator\delself.bat
C:\WINDOWS\system32\32m7jqRH.exe.a_a
C:\WINDOWS\system32\37U7v65n.exe
C:\WINDOWS\system32\37U7v65n.exe.a_a
C:\WINDOWS\system32\37U7v65n.exe_
C:\WINDOWS\system32\ihmfkpaj.exe
C:\WINDOWS\system32\nt2dVbcN.dll
C:\WINDOWS\system32\pabolsbu.exe
C:\WINDOWS\system32\wini104552502.exe
C:\WINDOWS\system32\zmnovqnc.exe
C:\WINDOWS\Tasks\At25.job
C:\WINDOWS\Tasks\At26.job
C:\WINDOWS\Tasks\At27.job
C:\WINDOWS\Tasks\At28.job
C:\WINDOWS\Tasks\At29.job
C:\WINDOWS\Tasks\At30.job
C:\WINDOWS\Tasks\At31.job
C:\WINDOWS\Tasks\At32.job
C:\WINDOWS\Tasks\At33.job
C:\WINDOWS\Tasks\At34.job
C:\WINDOWS\Tasks\At35.job
C:\WINDOWS\Tasks\At36.job
C:\WINDOWS\Tasks\At37.job
C:\WINDOWS\Tasks\At38.job
C:\WINDOWS\Tasks\At39.job
C:\WINDOWS\Tasks\At40.job
C:\WINDOWS\Tasks\At41.job
C:\WINDOWS\Tasks\At42.job
C:\WINDOWS\Tasks\At43.job
C:\WINDOWS\Tasks\At44.job
C:\WINDOWS\Tasks\At45.job
C:\WINDOWS\Tasks\At46.job
C:\WINDOWS\Tasks\At47.job
C:\WINDOWS\Tasks\At48.job
.
((((((((((((((((((((((((( Files Created from 2008-09-18 to 2008-10-18 )))))))))))))))))))))))))))))))
.
2008-10-13 01:34 . 2008-10-13 01:34 230 --a------ C:\WINDOWS\system32\spupdsvc.inf
2008-10-12 02:26 . 2008-10-18 15:14 69,632 --a------ C:\WINDOWS\system32\nt2dVbcN.dl_
2008-10-11 19:49 . 2008-10-11 19:48 30,272 --a------ C:\WINDOWS\system32\32m7jqRH.exe
2008-10-08 21:12 . 2008-10-08 21:19 3,104 --a------ C:\WINDOWS\system32\tmp.reg
2008-10-08 20:52 . 2008-10-08 20:52 <DIR> d-------- C:\VundoFix Backups
2008-10-08 20:44 . 2008-10-18 21:53 4,224 --a------ C:\WINDOWS\system32\drivers\beep.sys
2008-10-08 20:44 . 2008-10-18 21:53 4,224 --a--c--- C:\WINDOWS\system32\dllcache\beep.sys
2008-10-08 19:03 . 2008-10-08 19:03 <DIR> d-------- E:\Program Files\Lavasoft
2008-10-08 19:03 . 2008-10-08 19:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-10-08 18:15 . 2008-10-08 18:15 <DIR> d-------- E:\Program Files\AVG
2008-10-08 18:15 . 2008-10-08 18:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-10-05 08:14 . 2008-10-05 08:14 1,152 --a------ C:\WINDOWS\system32\windrv.sys
2008-10-05 08:13 . 2008-10-05 08:13 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-10-05 07:48 . 2008-10-05 07:48 <DIR> d-------- E:\Program Files\TeaTimer (Spybot - Search & Destroy)
2008-10-05 07:48 . 2008-10-05 07:48 <DIR> d-------- E:\Program Files\SDHelper (Spybot - Search & Destroy)
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-16 23:54 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Orbit
2008-10-13 19:19 --------- d-----w E:\Program Files\Utils
2008-10-13 19:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-10-08 18:03 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-10-08 17:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avg7
2008-10-05 06:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-05 05:10 183,120 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2008-10-05 05:10 137,480 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-10-01 14:51 87,552 ----a-w C:\WINDOWS\system32\VACFix.exe
2008-09-19 11:26 82,944 ----a-w C:\WINDOWS\system32\o4Patch.exe
2008-09-19 11:26 82,944 ----a-w C:\WINDOWS\system32\IEDFix.C.exe
2008-09-15 21:55 --------- d-----w E:\Program Files\RdDrv001
2008-09-11 18:44 --------- d-----w C:\Program Files\Common Files\Realtime Soft
2008-09-11 18:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\Realtime Soft
2008-09-11 18:44 --------- d-----w C:\Documents and Settings\Administrator\Application Data\Realtime Soft
2008-09-10 22:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-09-08 22:38 88,576 ----a-w C:\WINDOWS\system32\AntiXPVSTFix.exe
2008-08-22 01:00 453,152 ----a-w C:\WINDOWS\system32\NVUNINST.EXE
2008-08-18 11:19 82,432 ----a-w C:\WINDOWS\system32\404Fix.exe
2008-07-22 00:42 42,320 ----a-w C:\WINDOWS\system32\xfcodec.dll
2008-07-18 21:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 21:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 21:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 21:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 21:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 21:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 21:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 21:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-12-03 22:58 22,328 ----a-w C:\Documents and Settings\Administrator\Application Data\PnkBstrK.sys
2007-09-25 02:26 19,912 ----a-w C:\Documents and Settings\Administrator\Application Data\GDIPFONTCACHEV1.DAT
.
------- Sigcheck -------
2006-05-30 08:28 668672 e8183db3295a0d7104b978351418b51f C:\WINDOWS\system32\wininet.dll
2006-05-30 08:28 1289728 cca49b59735bb6efe1f22ac414ff4041 C:\WINDOWS\explorer.exe
.
((((((((((((((((((((((((((((( snapshot@2008-10-09_18.42.52.37 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-08-13 18:39:20 71,680 ----a-w C:\WINDOWS\system32\admparse.dll
+ 2006-05-30 07:28:14 61,440 ----a-w C:\WINDOWS\system32\admparse.dll
- 2007-08-13 18:39:00 123,904 ----a-w C:\WINDOWS\system32\advpack.dll
+ 2006-05-30 07:28:14 99,840 ----a-w C:\WINDOWS\system32\advpack.dll
- 2006-09-23 13:12:50 1,022,976 ----a-w C:\WINDOWS\system32\browseui.dll
+ 2006-05-30 07:28:14 1,025,024 ----a-w C:\WINDOWS\system32\browseui.dll
- 2007-08-13 18:42:54 17,408 ----a-w C:\WINDOWS\system32\corpol.dll
+ 2006-05-30 07:28:14 35,328 ----a-w C:\WINDOWS\system32\corpol.dll
- 2007-08-13 18:39:20 71,680 -c--a-w C:\WINDOWS\system32\dllcache\admparse.dll
+ 2006-05-30 07:28:14 61,440 -c--a-w C:\WINDOWS\system32\dllcache\admparse.dll
- 2007-08-13 18:39:00 123,904 -c--a-w C:\WINDOWS\system32\dllcache\advpack.dll
+ 2006-05-30 07:28:14 99,840 -c--a-w C:\WINDOWS\system32\dllcache\advpack.dll
- 2006-05-30 07:28:14 66,560 -c--a-w C:\WINDOWS\system32\dllcache\cdm.dll
+ 2008-07-18 21:10:48 94,920 -c--a-w C:\WINDOWS\system32\dllcache\cdm.dll
- 2007-08-13 18:42:54 17,408 -c--a-w C:\WINDOWS\system32\dllcache\corpol.dll
+ 2006-05-30 07:28:14 35,328 -c--a-w C:\WINDOWS\system32\dllcache\corpol.dll
- 2007-08-13 18:35:46 346,624 -c--a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
+ 2006-05-30 07:28:14 357,888 -c--a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
- 2007-08-13 18:35:38 214,528 -c--a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
+ 2006-05-30 07:28:14 205,312 -c--a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
- 2007-08-13 18:54:10 131,584 -c--a-w C:\WINDOWS\system32\dllcache\extmgr.dll
+ 2006-05-30 07:28:14 55,808 -c--a-w C:\WINDOWS\system32\dllcache\extmgr.dll
- 2007-08-13 18:39:06 54,784 -c--a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
+ 2006-05-30 07:28:14 34,304 -c--a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
- 2007-08-13 18:39:26 152,064 -c--a-w C:\WINDOWS\system32\dllcache\ieakeng.dll
+ 2006-05-30 07:28:14 139,264 -c--a-w C:\WINDOWS\system32\dllcache\ieakeng.dll
- 2007-08-13 17:56:54 161,792 -c--a-w C:\WINDOWS\system32\dllcache\ieakui.dll
+ 2006-05-30 07:28:14 221,184 -c--a-w C:\WINDOWS\system32\dllcache\ieakui.dll
- 2007-08-13 18:39:50 382,976 -c--a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll
+ 2006-05-30 07:28:14 323,584 -c--a-w C:\WINDOWS\system32\dllcache\iedkcs32.dll
- 2007-08-13 18:44:02 69,120 -c--a-w C:\WINDOWS\system32\dllcache\iedw.exe
+ 2006-05-30 07:28:14 18,432 -c--a-w C:\WINDOWS\system32\dllcache\iedw.exe
- 2007-08-13 18:45:18 78,336 -c--a-w C:\WINDOWS\system32\dllcache\ieencode.dll
+ 2006-05-30 07:28:14 81,920 -c--a-w C:\WINDOWS\system32\dllcache\ieencode.dll
- 2007-08-13 18:54:10 191,488 -c--a-w C:\WINDOWS\system32\dllcache\iepeers.dll
+ 2006-05-30 07:28:14 251,392 -c--a-w C:\WINDOWS\system32\dllcache\iepeers.dll
- 2007-08-13 18:39:12 55,296 -c--a-w C:\WINDOWS\system32\dllcache\iesetup.dll
+ 2006-05-30 07:28:14 62,976 -c--a-w C:\WINDOWS\system32\dllcache\iesetup.dll
- 2007-08-13 18:36:06 36,352 -c--a-w C:\WINDOWS\system32\dllcache\imgutil.dll
+ 2006-05-30 07:28:14 35,840 -c--a-w C:\WINDOWS\system32\dllcache\imgutil.dll
- 2007-08-13 18:39:02 92,672 -c--a-w C:\WINDOWS\system32\dllcache\inseng.dll
+ 2006-05-30 07:28:14 96,256 -c--a-w C:\WINDOWS\system32\dllcache\inseng.dll
- 2007-08-13 18:38:04 491,520 -c--a-w C:\WINDOWS\system32\dllcache\jscript.dll
+ 2006-05-30 07:28:14 450,560 -c--a-w C:\WINDOWS\system32\dllcache\jscript.dll
- 2007-08-13 18:54:10 27,136 -c--a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
+ 2006-05-30 07:28:14 15,872 -c--a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
- 2007-08-13 18:44:18 40,960 -c--a-w C:\WINDOWS\system32\dllcache\licmgr10.dll
+ 2006-05-30 07:28:14 22,016 -c--a-w C:\WINDOWS\system32\dllcache\licmgr10.dll
- 2007-08-13 18:32:30 45,568 -c--a-w C:\WINDOWS\system32\dllcache\mshta.exe
+ 2006-05-30 07:28:14 29,184 -c--a-w C:\WINDOWS\system32\dllcache\mshta.exe
- 2007-08-13 18:54:10 475,648 -c--a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
+ 2006-05-30 07:28:14 448,512 -c--a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
- 2007-08-13 18:01:12 48,128 -c--a-w C:\WINDOWS\system32\dllcache\mshtmler.dll
+ 2006-05-30 07:28:14 56,832 -c--a-w C:\WINDOWS\system32\dllcache\mshtmler.dll
- 2007-08-13 18:54:10 156,160 -c--a-w C:\WINDOWS\system32\dllcache\msls31.dll
+ 2006-05-30 07:28:14 146,432 -c--a-w C:\WINDOWS\system32\dllcache\msls31.dll
- 2007-08-13 18:44:26 192,000 -c--a-w C:\WINDOWS\system32\dllcache\msrating.dll
+ 2006-05-30 07:28:14 146,432 -c--a-w C:\WINDOWS\system32\dllcache\msrating.dll
- 2007-08-13 18:54:10 670,720 -c--a-w C:\WINDOWS\system32\dllcache\mstime.dll
+ 2006-05-30 07:28:14 532,480 -c--a-w C:\WINDOWS\system32\dllcache\mstime.dll
- 2007-08-13 18:36:12 44,544 -c--a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
+ 2006-05-30 07:28:14 39,424 -c--a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
- 2007-08-13 18:54:10 413,696 -c--a-w C:\WINDOWS\system32\dllcache\vbscript.dll
+ 2006-05-30 07:28:14 417,792 -c--a-w C:\WINDOWS\system32\dllcache\vbscript.dll
- 2007-08-13 18:54:10 765,952 -c--a-w C:\WINDOWS\system32\dllcache\vgx.dll
+ 2006-05-30 07:28:14 848,384 -c--a-w C:\WINDOWS\system32\dllcache\vgx.dll
- 2006-05-30 07:28:14 430,592 -c--a-w C:\WINDOWS\system32\dllcache\wuapi.dll
+ 2008-07-18 21:09:44 563,912 -c--a-w C:\WINDOWS\system32\dllcache\wuapi.dll
- 2006-05-30 07:28:14 111,104 -c--a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
+ 2008-07-18 21:10:42 53,448 -c--a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
- 2006-05-30 07:28:14 1,134,592 -c--a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
+ 2008-07-18 21:09:42 1,811,656 -c--a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
- 2006-05-30 07:28:14 112,640 -c--a-w C:\WINDOWS\system32\dllcache\wucltui.dll
+ 2008-07-18 21:09:46 325,832 -c--a-w C:\WINDOWS\system32\dllcache\wucltui.dll
- 2006-05-30 07:28:14 36,864 -c--a-w C:\WINDOWS\system32\dllcache\wups.dll
+ 2008-07-18 21:10:20 36,552 -c--a-w C:\WINDOWS\system32\dllcache\wups.dll
- 2006-05-30 07:28:14 120,320 -c--a-w C:\WINDOWS\system32\dllcache\wuweb.dll
+ 2008-07-18 21:09:44 205,000 -c--a-w C:\WINDOWS\system32\dllcache\wuweb.dll
- 2007-08-13 18:35:46 346,624 ----a-w C:\WINDOWS\system32\dxtmsft.dll
+ 2006-05-30 07:28:14 357,888 ----a-w C:\WINDOWS\system32\dxtmsft.dll
- 2007-08-13 18:35:38 214,528 ----a-w C:\WINDOWS\system32\dxtrans.dll
+ 2006-05-30 07:28:14 205,312 ----a-w C:\WINDOWS\system32\dxtrans.dll
- 2007-08-13 18:54:10 131,584 ----a-w C:\WINDOWS\system32\extmgr.dll
+ 2006-05-30 07:28:14 55,808 ----a-w C:\WINDOWS\system32\extmgr.dll
- 2007-08-13 18:39:06 54,784 ----a-w C:\WINDOWS\system32\ie4uinit.exe
+ 2006-05-30 07:28:14 34,304 ----a-w C:\WINDOWS\system32\ie4uinit.exe
- 2007-08-13 18:39:26 152,064 ----a-w C:\WINDOWS\system32\ieakeng.dll
+ 2006-05-30 07:28:14 139,264 ----a-w C:\WINDOWS\system32\ieakeng.dll
- 2007-08-13 18:39:54 229,376 ----a-w C:\WINDOWS\system32\ieaksie.dll
+ 2006-05-30 07:28:14 233,472 ----a-w C:\WINDOWS\system32\ieaksie.dll
- 2007-08-13 17:56:54 161,792 ----a-w C:\WINDOWS\system32\ieakui.dll
+ 2006-05-30 07:28:14 221,184 ----a-w C:\WINDOWS\system32\ieakui.dll
- 2007-08-13 18:39:50 382,976 ----a-w C:\WINDOWS\system32\iedkcs32.dll
+ 2006-05-30 07:28:14 323,584 ----a-w C:\WINDOWS\system32\iedkcs32.dll
- 2007-08-13 18:45:18 78,336 ----a-w C:\WINDOWS\system32\ieencode.dll
+ 2006-05-30 07:28:14 81,920 ----a-w C:\WINDOWS\system32\ieencode.dll
- 2007-08-13 18:54:10 191,488 ----a-w C:\WINDOWS\system32\iepeers.dll
+ 2006-05-30 07:28:14 251,392 ----a-w C:\WINDOWS\system32\iepeers.dll
- 2007-08-13 18:39:10 43,008 ----a-w C:\WINDOWS\system32\iernonce.dll
+ 2006-05-30 07:28:14 62,976 ----a-w C:\WINDOWS\system32\iernonce.dll
- 2007-08-13 18:39:12 55,296 ----a-w C:\WINDOWS\system32\iesetup.dll
+ 2006-05-30 07:28:14 62,976 ----a-w C:\WINDOWS\system32\iesetup.dll
- 2007-08-13 18:36:06 36,352 ----a-w C:\WINDOWS\system32\imgutil.dll
+ 2006-05-30 07:28:14 35,840 ----a-w C:\WINDOWS\system32\imgutil.dll
- 2007-08-13 18:39:02 92,672 ----a-w C:\WINDOWS\system32\inseng.dll
+ 2006-05-30 07:28:14 96,256 ----a-w C:\WINDOWS\system32\inseng.dll
- 2007-08-13 18:38:04 491,520 ----a-w C:\WINDOWS\system32\jscript.dll
+ 2006-05-30 07:28:14 450,560 ----a-w C:\WINDOWS\system32\jscript.dll
- 2007-08-13 18:54:10 27,136 ----a-w C:\WINDOWS\system32\jsproxy.dll
+ 2006-05-30 07:28:14 15,872 ----a-w C:\WINDOWS\system32\jsproxy.dll
- 2007-08-13 18:44:18 40,960 ----a-w C:\WINDOWS\system32\licmgr10.dll
+ 2006-05-30 07:28:14 22,016 ----a-w C:\WINDOWS\system32\licmgr10.dll
- 2007-08-13 18:32:30 45,568 ----a-w C:\WINDOWS\system32\mshta.exe
+ 2006-05-30 07:28:14 29,184 ----a-w C:\WINDOWS\system32\mshta.exe
- 2007-08-13 18:54:12 3,578,368 ----a-w C:\WINDOWS\system32\mshtml.dll
+ 2006-05-30 07:28:14 3,123,712 ----a-w C:\WINDOWS\system32\mshtml.dll
- 2007-08-13 18:54:10 475,648 ----a-w C:\WINDOWS\system32\mshtmled.dll
+ 2006-05-30 07:28:14 448,512 ----a-w C:\WINDOWS\system32\mshtmled.dll
- 2007-08-13 18:01:12 48,128 ----a-w C:\WINDOWS\system32\mshtmler.dll
+ 2006-05-30 07:28:14 56,832 ----a-w C:\WINDOWS\system32\mshtmler.dll
- 2007-08-13 18:54:10 156,160 ----a-w C:\WINDOWS\system32\msls31.dll
+ 2006-05-30 07:28:14 146,432 ----a-w C:\WINDOWS\system32\msls31.dll
- 2007-08-13 18:44:26 192,000 ----a-w C:\WINDOWS\system32\msrating.dll
+ 2006-05-30 07:28:14 146,432 ----a-w C:\WINDOWS\system32\msrating.dll
- 2007-08-13 18:54:10 670,720 ----a-w C:\WINDOWS\system32\mstime.dll
+ 2006-05-30 07:28:14 532,480 ----a-w C:\WINDOWS\system32\mstime.dll
- 2007-08-13 18:44:06 101,376 ----a-w C:\WINDOWS\system32\occache.dll
+ 2006-05-30 07:28:14 387,584 ----a-w C:\WINDOWS\system32\occache.dll
- 2007-08-13 18:36:12 44,544 ----a-w C:\WINDOWS\system32\pngfilt.dll
+ 2006-05-30 07:28:14 39,424 ----a-w C:\WINDOWS\system32\pngfilt.dll
- 2006-09-23 13:12:50 1,497,088 ----a-w C:\WINDOWS\system32\shdocvw.dll
+ 2006-05-30 07:28:14 2,099,200 ----a-w C:\WINDOWS\system32\shdocvw.dll
- 2006-09-23 13:12:50 474,112 ----a-w C:\WINDOWS\system32\shlwapi.dll
+ 2006-05-30 07:28:14 477,696 ----a-w C:\WINDOWS\system32\shlwapi.dll
+ 2008-07-18 21:10:20 36,552 ----a-w C:\WINDOWS\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.2.6001.784\wups.dll
- 2007-08-13 18:44:30 105,984 ----a-w C:\WINDOWS\system32\url.dll
+ 2006-05-30 07:28:14 49,664 ----a-w C:\WINDOWS\system32\url.dll
- 2007-08-13 18:54:10 1,162,240 ----a-w C:\WINDOWS\system32\urlmon.dll
+ 2006-05-30 07:28:14 623,616 ----a-w C:\WINDOWS\system32\urlmon.dll
- 2007-08-13 18:54:10 413,696 ----a-w C:\WINDOWS\system32\vbscript.dll
+ 2006-05-30 07:28:14 417,792 ----a-w C:\WINDOWS\system32\vbscript.dll
- 2007-08-13 18:54:10 231,424 ----a-w C:\WINDOWS\system32\webcheck.dll
+ 2006-05-30 07:28:14 439,808 ----a-w C:\WINDOWS\system32\webcheck.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-05-30 15360]
"Steam"="F:\Program Files\Steam\Steam.exe" [2008-10-07 1410296]
"Veoh"="F:\Program Files\veoh\VeohClient.exe" [2008-08-13 3660848]
"SetDefaultMIDI"="MIDIDef.exe" [2005-10-22 C:\WINDOWS\MIDIDEF.EXE]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdReg"="C:\WINDOWS\UpdReg.EXE" [2000-05-10 90112]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
"DAEMON Tools"="E:\Program Files\DAEMON Tools\daemon.exe" [2006-09-14 157592]
"IntelliPoint"="E:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2007-02-05 849280]
"DeathAdder"="E:\Program Files\Razer\DeathAdder\razerhid.exe" [2007-09-07 159744]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-10-11 8527872]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-10-11 81920]
"RivaTuner"="F:\Program Files\RivaTuner v2.06\RivaTuner.exe" [2007-10-30 2650112]
"QuickTime Task"="F:\Program Files\QuickTime\QTTask.exe" [2008-03-28 413696]
"iTunesHelper"="F:\ProgramFiles\iTunes\iTunesHelper.exe" [2008-03-30 267048]
"UltraMon"="F:\Program Files\UltraMon\UltraMon.exe" [2007-04-01 299520]
"CTHelper"="CTHELPER.EXE" [2005-10-22 C:\WINDOWS\CTHELPER.EXE]
"RTHDCPL"="RTHDCPL.EXE" [2007-09-19 C:\WINDOWS\RTHDCPL.exe]
"nwiz"="nwiz.exe" [2007-10-11 C:\WINDOWS\system32\nwiz.exe]
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - E:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
ASUS WiFi-AP Solo.lnk - C:\Program Files\ASUS WiFi-AP Solo\RtWLan.exe [2006-08-15 995328]
Microsoft Office.lnk - E:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.XFR1"= xfcodec.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ai Quicker Help]
--a------ 2006-06-01 16:27 3167232 E:\Program Files\ASUS\ASUS DH Remote\AsRc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core]
--a------ 2007-07-19 08:02 2887680 E:\Program Files\Electronic Arts\EA Link\Core.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H2O]
--a------ 2005-05-11 02:46 200069 E:\Program Files\Syncrosoft\POS\H2O\cledx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
--a------ 2006-05-18 11:29 49152 F:\video\powerdvd\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2006-05-30 08:28 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--------- 2005-12-07 22:57 30208 F:\video\powerdvd\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2006-10-19 19:22 185784 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ATI Smart"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"F:\\ProgramFiles\\3DsMax8\\3dsmax.exe"=
"F:\\video\\Backburner\\monitor.exe"=
"F:\\video\\Backburner\\manager.exe"=
"F:\\video\\Backburner\\server.exe"=
"E:\\Program Files\\Sierra\\SWAT 4\\ContentExpansion\\System\\Swat4X.exe"=
"E:\\Program Files\\Sierra\\SWAT 4\\ContentExpansion\\System\\Swat4XDedicatedServer.exe"=
"F:\\ProgramFiles\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"F:\\Program Files\\Orbitdownloader\\orbitdm.exe"=
"F:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
"E:\\Program Files\\Xfire\\xfire.exe"=
"E:\\Program Files\\mIRC\\mirc.exe"=
"E:\\Program Files\\Electronic Arts\\Battlefield 2142\\BF2142.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"F:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"F:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"F:\\Program Files\\THQ\\S.T.A.L.K.E.R. - Shadow of Chernobyl\\bin\\XR_3DA.exe"=
"F:\\Program Files\\THQ\\S.T.A.L.K.E.R. - Shadow of Chernobyl\\bin\\dedicated\\XR_3DA.exe"=
"F:\\Program Files\\Stardock Games\\Sins of a Solar Empire\\Sins of a Solar Empire.exe"=
"E:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"F:\\ProgramFiles\\iTunes\\iTunes.exe"=
"F:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
R2 UltraMonUtility;UltraMon Utility Driver;C:\Program Files\Common Files\Realtime Soft\UltraMonMirrorDrv\x32\UltraMonUtility.sys [2006-09-24 11776]
R3 CLEDX;Team H2O CLEDX service;C:\WINDOWS\system32\DRIVERS\cledx.sys [2005-05-09 33792]
R3 DAdderFltr;DeathAdder Mouse;C:\WINDOWS\system32\drivers\dadder.sys [2007-08-02 22784]
R3 UltraMonMirror;UltraMonMirror;C:\WINDOWS\system32\DRIVERS\UltraMonMirror.sys [2006-09-24 3584]
S3 CyUsb;Cypress Generic USB Driver;C:\WINDOWS\system32\Drivers\CyUsb.sys [2005-03-03 31104]
S3 MayPro;TigerGame SuperJoy Box Pro Filter Service;C:\WINDOWS\system32\Drivers\MayPro.sys [2006-05-05 12160]
S3 PEEK5;PEEK5 Protocol Driver;F:\MYDOCS~1\AIRCRA~1.2-W\bin\PEEK5.SYS [ ]
S3 RDID1027;EDIROL PCR;C:\WINDOWS\system32\Drivers\rdwm1027.sys [2006-09-28 79393]
S3 RTLWUSB;Realtek RTL8187 Wireless 802.11g 54Mbps USB 2.0 Network Adapter;C:\WINDOWS\system32\DRIVERS\RTL8187.sys [2006-05-22 175872]
S3 SjyPkt;SjyPkt;C:\WINDOWS\System32\Drivers\SjyPkt.sys [2006-03-31 13532]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c157a676-3430-11dc-b7a6-001731c4429a}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL
http://www.scienceofsleep.net
.
Contents of the 'Scheduled Tasks' folder
2008-06-13 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- E:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 15:57]
2008-10-17 C:\WINDOWS\Tasks\At1.job
- C:\WINDOWS\system32\32m7jqRH.exe [2008-10-11 19:48]
2008-10-11 C:\WINDOWS\Tasks\At10.job
- C:\WINDOWS\system32\32m7jqRH.exe [2008-10-11 19:48]
2008-10-11 C:\WINDOWS\Tasks\At11.job
- C:\WINDOWS\system32\32m7jqRH.exe [2008-10-11 19:48]
2008-10-11 C:\WINDOWS\Tasks\At12.job
- C:\WINDOWS\system32\32m7jqRH.exe [2008-10-11 19:48]
2008-10-11 C:\WINDOWS\Tasks\At13.job
- C:\WINDOWS\system32\32m7jqRH.exe [2008-10-11 19:48]
2008-10-18 C:\WINDOWS\Tasks\At14.job
- C:\WINDOWS\system32\32m7jqRH.exe [2008-10-11 19:48]
2008-10-18 C:\WINDOWS\Tasks\At15.job
- C:\WINDOWS\system32\32m7jqRH.exe [2008-10-11 19:48]
2008-10-18 C:\WINDOWS\Tasks\At16.job
- C:\WINDOWS\system32\32m7jqRH.exe [2008-10-11 19:48]
2008-10-18 C:\WINDOWS\Tasks\At17.job
- C:\WINDOWS\system32\32m7jqRH.exe [2008-10-11 19:48]
2008-10-18 C:\WINDOWS\Tasks\At18.job
- C:\WINDOWS\system32\32m7jqRH.exe [2008-10-11 19:48]
2008-10-18 C:\WINDOWS\Tasks\At19.job
- C:\WINDOWS\system32\32m7jqRH.exe [2008-10-11 19:48]
2008-10-18 C:\WINDOWS\Tasks\At2.job
- C:\WINDOWS\system32\32m7jqRH.exe [2008-10-11 19:48]
2008-10-18 C:\WINDOWS\Tasks\At20.job
- C:\WINDOWS\system32\32m7jqRH.exe [2008-10-11 19:48]
2008-10-18 C:\WINDOWS\Tasks\At21.job
- C:\WINDOWS\system32\32m7jqRH.exe [2008-10-11 19:48]
2008-10-18 C:\WINDOWS\Tasks\At22.job
- C:\WINDOWS\system32\32m7jqRH.exe [2008-10-11 19:48]
2008-10-17 C:\WINDOWS\Tasks\At23.job
- C:\WINDOWS\system32\32m7jqRH.exe [2008-10-11 19:48]
2008-10-17 C:\WINDOWS\Tasks\At24.job
- C:\WINDOWS\system32\32m7jqRH.exe [2008-10-11 19:48]
2008-10-18 C:\WINDOWS\Tasks\At3.job
- C:\WINDOWS\system32\32m7jqRH.exe [2008-10-11 19:48]
2008-10-12 C:\WINDOWS\Tasks\At4.job
- C:\WINDOWS\system32\32m7jqRH.exe [2008-10-11 19:48]
2008-10-11 C:\WINDOWS\Tasks\At5.job
- C:\WINDOWS\system32\32m7jqRH.exe [2008-10-11 19:48]
2008-10-11 C:\WINDOWS\Tasks\At6.job
- C:\WINDOWS\system32\32m7jqRH.exe [2008-10-11 19:48]
2008-10-11 C:\WINDOWS\Tasks\At7.job
- C:\WINDOWS\system32\32m7jqRH.exe [2008-10-11 19:48]
2008-10-11 C:\WINDOWS\Tasks\At8.job
- C:\WINDOWS\system32\32m7jqRH.exe [2008-10-11 19:48]
2008-10-11 C:\WINDOWS\Tasks\At9.job
- C:\WINDOWS\system32\32m7jqRH.exe [2008-10-11 19:48]
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-admshui - C:\WINDOWS\system32\ihmfkpaj.exe
MSConfigStartUp-chkinfomsg - C:\WINDOWS\system32\zmnovqnc.exe
MSConfigStartUp-utilaplsys - C:\WINDOWS\system32\pabolsbu.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-18 22:01:07
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-10-18 22:01:54
ComboFix-quarantined-files.txt 2008-10-18 21:01:26
ComboFix2.txt 2008-10-09 17:43:19
Pre-Run: 3,572,858,880 bytes free
Post-Run: 3,847,086,080 bytes free
543