ComboFix 08-11-04.02 - Jody 2008-11-05 9:13:47.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1517 [GMT -6:00]
Running from: c:\documents and settings\Jody\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Jody\Desktop\CFScript.txt
* Created a new restore point
FILE ::
c:\windows\sqlexec32.exe
c:\windows\system32\luxecash354.dat
C:\winupdater.exe
C:\xcodec.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Jody\Application Data\LimeWire
c:\documents and settings\Jody\Application Data\LimeWire\certificate\limewire.keystore
c:\documents and settings\Jody\Application Data\LimeWire\createtimes.cache
c:\documents and settings\Jody\Application Data\LimeWire\downloads.dat
c:\documents and settings\Jody\Application Data\LimeWire\fileurns.bak
c:\documents and settings\Jody\Application Data\LimeWire\fileurns.cache
c:\documents and settings\Jody\Application Data\LimeWire\filters.props
c:\documents and settings\Jody\Application Data\LimeWire\gnutella.net
c:\documents and settings\Jody\Application Data\LimeWire\installation.props
c:\documents and settings\Jody\Application Data\LimeWire\library.dat
c:\documents and settings\Jody\Application Data\LimeWire\limewire.props
c:\documents and settings\Jody\Application Data\LimeWire\mojito.props
c:\documents and settings\Jody\Application Data\LimeWire\promotion\promodb.backup
c:\documents and settings\Jody\Application Data\LimeWire\promotion\promodb.data
c:\documents and settings\Jody\Application Data\LimeWire\promotion\promodb.properties
c:\documents and settings\Jody\Application Data\LimeWire\promotion\promodb.script
c:\documents and settings\Jody\Application Data\LimeWire\questions.props
c:\documents and settings\Jody\Application Data\LimeWire\responses.cache
c:\documents and settings\Jody\Application Data\LimeWire\simpp.xml
c:\documents and settings\Jody\Application Data\LimeWire\spam.dat
c:\documents and settings\Jody\Application Data\LimeWire\tables.props
c:\documents and settings\Jody\Application Data\LimeWire\themes\windows_theme.lwtp
c:\documents and settings\Jody\Application Data\LimeWire\themes\windows_theme\
01_star.gif
c:\documents and settings\Jody\Application Data\LimeWire\themes\windows_theme\
02_star.gif
c:\documents and settings\Jody\Application Data\LimeWire\themes\windows_theme\
03_star.gif
c:\documents and settings\Jody\Application Data\LimeWire\themes\windows_theme\
04_star.gif
c:\documents and settings\Jody\Application Data\LimeWire\themes\windows_theme\
05_star.gif
c:\documents and settings\Jody\Application Data\LimeWire\themes\windows_theme\chat.gif
c:\documents and settings\Jody\Application Data\LimeWire\themes\windows_theme\forward_dn.gif
c:\documents and settings\Jody\Application Data\LimeWire\themes\windows_theme\forward_up.gif
c:\documents and settings\Jody\Application Data\LimeWire\themes\windows_theme\kill.gif
c:\documents and settings\Jody\Application Data\LimeWire\themes\windows_theme\kill_on.gif
c:\documents and settings\Jody\Application Data\LimeWire\themes\windows_theme\pause_dn.gif
c:\documents and settings\Jody\Application Data\LimeWire\themes\windows_theme\pause_up.gif
c:\documents and settings\Jody\Application Data\LimeWire\themes\windows_theme\play_dn.gif
c:\documents and settings\Jody\Application Data\LimeWire\themes\windows_theme\play_up.gif
c:\documents and settings\Jody\Application Data\LimeWire\themes\windows_theme\question.gif
c:\documents and settings\Jody\Application Data\LimeWire\themes\windows_theme\rewind_dn.gif
c:\documents and settings\Jody\Application Data\LimeWire\themes\windows_theme\rewind_up.gif
c:\documents and settings\Jody\Application Data\LimeWire\themes\windows_theme\stop_dn.gif
c:\documents and settings\Jody\Application Data\LimeWire\themes\windows_theme\stop_up.gif
c:\documents and settings\Jody\Application Data\LimeWire\themes\windows_theme\theme.txt
c:\documents and settings\Jody\Application Data\LimeWire\themes\windows_theme\version.txt
c:\documents and settings\Jody\Application Data\LimeWire\themes\windows_theme\warning.gif
c:\documents and settings\Jody\Application Data\LimeWire\version.xml
c:\documents and settings\Jody\Application Data\LimeWire\versions.props
c:\windows\sqlexec32.exe
c:\windows\system32\luxecash354.dat
C:\winupdater.exe
C:\xcodec.exe
J:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-10-05 to 2008-11-05 )))))))))))))))))))))))))))))))
.
2008-11-04 22:33 . 2008-11-04 22:33 <DIR> d-------- c:\windows\system32\QuickTime
2008-11-04 22:16 . 2008-11-04 22:16 <DIR> d-------- c:\windows\PrimoPDF4
2008-11-04 22:16 . 2008-11-04 22:16 <DIR> d-------- c:\program files\activePDF
2008-11-04 20:35 . 2008-11-04 20:35 <DIR> d-------- c:\program files\WebEx
2008-11-04 20:35 . 2008-11-04 20:35 <DIR> d-------- c:\documents and settings\All Users\Application Data\Sage Software
2008-11-04 20:34 . 2008-11-04 20:34 <DIR> d-------- c:\program files\winsim
2008-11-04 20:34 . 2008-11-04 20:34 <DIR> d-------- c:\program files\Seagate Software
2008-11-04 20:34 . 2008-11-04 20:34 <DIR> d-------- c:\program files\Common Files\AnswerWorks 5.0
2008-11-04 20:33 . 2008-11-04 20:35 <DIR> d-------- c:\program files\Simply Accounting Basic 2007
2008-11-04 19:04 . 2008-11-04 19:04 <DIR> d-------- c:\program files\Common Files\Macromedia Shared
2008-11-04 13:51 . 2008-11-04 13:51 <DIR> d-------- c:\program files\MSXML 4.0
2008-11-03 20:29 . 2008-11-03 20:29 <DIR> d-------- c:\program files\Trend Micro
2008-11-03 16:44 . 2008-11-03 16:44 1,664 --a------ c:\windows\system32\tmp.reg
2008-11-03 16:43 . 2007-09-05 23:22 289,144 --a------ c:\windows\system32\VCCLSID.exe
2008-11-03 16:43 . 2006-04-27 16:49 288,417 --a------ c:\windows\system32\SrchSTS.exe
2008-11-03 16:43 . 2008-09-08 22:38 88,576 --a------ c:\windows\system32\AntiXPVSTFix.exe
2008-11-03 16:43 . 2008-10-01 14:51 87,552 --a------ c:\windows\system32\VACFix.exe
2008-11-03 16:43 . 2008-10-10 07:58 82,944 --a------ c:\windows\system32\o4Patch.exe
2008-11-03 16:43 . 2008-05-18 20:40 82,944 --a------ c:\windows\system32\IEDFix.exe
2008-11-03 16:43 . 2008-10-10 07:58 82,944 --a------ c:\windows\system32\IEDFix.C.exe
2008-11-03 16:43 . 2008-08-18 11:19 82,432 --a------ c:\windows\system32\404Fix.exe
2008-11-03 16:43 . 2003-06-05 20:13 53,248 --a------ c:\windows\system32\Process.exe
2008-11-03 16:43 . 2004-07-31 17:50 51,200 --a------ c:\windows\system32\dumphive.exe
2008-11-03 16:43 . 2007-10-03 23:36 25,600 --a------ c:\windows\system32\WS2Fix.exe
2008-11-03 12:14 . 2008-11-03 13:30 <DIR> d-------- C:\Temp
2008-11-03 09:32 . 2008-11-03 09:32 0 --a------ c:\windows\nsreg.dat
2008-11-03 09:03 . 2008-11-04 22:34 <DIR> d-------- c:\program files\Macromedia
2008-11-03 09:03 . 2008-11-03 09:06 <DIR> d-------- c:\program files\Common Files\Macromedia
2008-11-03 09:02 . 2008-11-04 22:33 <DIR> d-------- c:\windows\Downloaded Installations
2008-11-02 23:26 . 2008-11-03 15:05 422 --a------ c:\windows\wininit.ini
2008-11-02 20:18 . 2008-11-03 12:18 <DIR> d-------- c:\program files\Bonjour
2008-11-02 18:16 . 2008-11-02 18:16 <DIR> d-------- c:\documents and settings\All Users\Application Data\Macrovision
2008-11-02 18:16 . 2002-01-05 04:10 57,344 --a------ c:\windows\system32\mfc70enu.dll
2008-11-02 18:09 . 2008-11-02 20:21 <DIR> d-------- c:\documents and settings\All Users\Application Data\FLEXnet
2008-11-02 17:42 . 2008-11-02 17:42 <DIR> d-------- c:\program files\Common Files\Macrovision Shared
2008-11-02 17:02 . 2006-12-11 15:12 176,235 --a------ c:\windows\system32\Primomonnt.dll
2008-11-02 16:43 . 2008-04-14 05:42 159,232 --a------ c:\windows\system32\ptpusd.dll
2008-11-02 16:43 . 2001-08-17 22:36 5,632 --a------ c:\windows\system32\ptpusb.dll
2008-11-02 16:40 . 2008-11-02 21:10 <DIR> d-------- c:\program files\CoreFTP
2008-11-02 16:40 . 2008-11-05 09:12 <DIR> d-------- c:\documents and settings\Jody\Application Data\CoreFTP
2008-11-02 15:59 . 2008-11-02 15:59 <DIR> d-------- c:\documents and settings\Jody\Contacts
2008-11-02 15:53 . 2008-11-02 15:57 <DIR> d-------- c:\program files\Windows Live
2008-11-02 15:53 . 2008-11-02 15:57 <DIR> d--hsc--- c:\program files\Common Files\WindowsLiveInstaller
2008-11-02 15:53 . 2008-11-02 15:53 <DIR> d-------- c:\documents and settings\All Users\Application Data\WLInstaller
2008-11-02 15:50 . 2008-11-02 15:50 <DIR> d-------- c:\program files\Common Files\Hewlett-Packard
2008-11-02 15:50 . 2003-12-11 11:15 626,960 -ra------ c:\windows\system32\hpvaut32.dll
2008-11-02 15:50 . 2003-12-11 11:15 487,424 -ra------ c:\windows\system32\hpvcp70.dll
2008-11-02 15:50 . 2003-12-11 11:15 344,064 -ra------ c:\windows\system32\hpvcr70.dll
2008-11-02 15:50 . 2003-12-11 11:15 44,544 -ra------ c:\windows\system32\MSXML4a.dll
2008-11-02 15:48 . 2008-11-02 15:48 <DIR> d-------- c:\program files\Common Files\HP
2008-11-02 15:46 . 2004-02-26 00:18 51,056 -ra------ c:\windows\system32\drivers\hpzid412.sys
2008-11-02 15:46 . 2004-02-26 00:18 21,488 -ra------ c:\windows\system32\drivers\HPZius12.sys
2008-11-02 15:46 . 2004-02-26 00:18 16,496 -ra------ c:\windows\system32\drivers\HPZipr12.sys
2008-11-02 15:46 . 2008-04-14 00:15 15,104 --a------ c:\windows\system32\drivers\usbscan.sys
2008-11-02 15:46 . 2008-04-14 00:15 15,104 --a--c--- c:\windows\system32\dllcache\usbscan.sys
2008-11-02 15:44 . 2008-11-02 15:50 <DIR> d-------- c:\program files\HP
2008-11-02 15:43 . 2004-02-26 00:17 38,868 --------- c:\windows\hpomdl03.dat
2008-11-02 15:43 . 2008-11-02 15:51 29,385 --a------ c:\windows\hpoins03.dat
2008-11-02 15:22 . 2008-04-14 05:41 21,504 --a------ c:\windows\system32\hidserv.dll
2008-11-02 15:22 . 2008-04-14 05:41 21,504 --a--c--- c:\windows\system32\dllcache\hidserv.dll
2008-11-02 15:22 . 2008-04-14 00:09 14,592 --a------ c:\windows\system32\drivers\kbdhid.sys
2008-11-02 15:22 . 2008-04-14 00:09 14,592 --a--c--- c:\windows\system32\dllcache\kbdhid.sys
2008-11-02 15:22 . 2001-08-17 13:48 12,160 --a------ c:\windows\system32\drivers\mouhid.sys
2008-11-02 15:22 . 2001-08-17 13:48 12,160 --a--c--- c:\windows\system32\dllcache\mouhid.sys
2008-11-02 15:18 . 2008-04-14 00:17 25,856 --a------ c:\windows\system32\drivers\usbprint.sys
2008-11-02 15:18 . 2008-04-14 00:17 25,856 --a--c--- c:\windows\system32\dllcache\usbprint.sys
2008-11-02 15:18 . 2008-04-14 00:15 10,368 --a------ c:\windows\system32\drivers\hidusb.sys
2008-11-02 15:18 . 2008-04-14 00:15 10,368 --a--c--- c:\windows\system32\dllcache\hidusb.sys
2008-11-02 15:15 . 2008-04-14 00:15 32,128 --a------ c:\windows\system32\drivers\usbccgp.sys
2008-11-02 15:15 . 2008-04-14 00:15 32,128 --a--c--- c:\windows\system32\dllcache\usbccgp.sys
2008-10-31 11:12 . 2008-11-04 14:17 8,627 --a------ c:\windows\system32\PAV_FOG.OPC
2008-10-31 11:08 . 2008-10-31 11:08 <DIR> d-------- c:\windows\system32\PAV
2008-10-31 11:08 . 2008-10-31 11:08 <DIR> d-------- c:\program files\Panda Security
2008-10-31 11:08 . 2008-10-31 11:08 <DIR> d-------- c:\documents and settings\Jody\Application Data\Panda Security
2008-10-31 11:08 . 2008-10-31 11:08 <DIR> d-------- c:\documents and settings\All Users\Application Data\Panda Security
2008-10-31 11:08 . 2008-06-18 18:03 520,448 --a------ c:\windows\system32\PavSHook.dll
2008-10-31 11:08 . 2006-06-01 23:00 446,464 --------- c:\windows\system32\HHActiveX.dll
2008-10-31 11:08 . 2008-06-24 14:48 193,280 --a------ c:\windows\system32\TpUtil.dll
2008-10-31 11:08 . 2007-02-08 11:53 107,568 --a------ c:\windows\system32\SYSTOOLS.DLL
2008-10-31 11:08 . 2008-06-18 18:03 87,296 --a------ c:\windows\system32\PavLspHook.dll
2008-10-31 11:08 . 2008-04-28 17:35 84,024 --a------ c:\windows\system32\drivers\pavdrv51.sys
2008-10-31 11:08 . 2008-03-18 16:58 58,672 --a------ c:\windows\system32\avldr.dll
2008-10-31 11:08 . 2008-06-18 18:03 55,552 --a------ c:\windows\system32\pavipc.dll
2008-10-31 11:08 . 2007-03-15 19:38 54,832 --a------ c:\windows\system32\pavcpl.cpl
2008-10-31 11:08 . 2008-06-19 17:24 28,544 --a------ c:\windows\system32\drivers\pavboot.sys
2008-10-31 11:08 . 2008-10-31 11:08 249 --a------ c:\windows\system32\PavCPL.dat
2008-10-31 11:07 . 2008-10-31 11:07 <DIR> d-------- c:\program files\Common Files\Panda Security
2008-10-31 11:07 . 2008-02-07 12:03 179,640 --a------ c:\windows\system32\drivers\PavProc.sys
2008-10-31 11:07 . 2008-03-04 15:59 41,144 --a------ c:\windows\system32\drivers\ShlDrv51.sys
2008-10-31 10:59 . 2008-11-03 12:24 <DIR> d-------- c:\program files\Microsoft IntelliType Pro
2008-10-31 10:59 . 2008-11-03 12:24 <DIR> d-------- c:\program files\Microsoft IntelliPoint
2008-10-31 10:45 . 2007-07-30 19:19 271,224 --a------ c:\windows\system32\mucltui.dll
2008-10-31 10:45 . 2007-07-30 19:19 30,072 --a------ c:\windows\system32\mucltui.dll.mui
2008-10-31 09:46 . 2007-04-09 13:23 28,040 --a------ c:\windows\system32\mdimon.dll
2008-10-31 09:46 . 2008-11-04 23:48 980 --a------ c:\windows\ODBC.INI
2008-10-31 09:45 . 2008-10-31 09:45 <DIR> d-------- c:\program files\Common Files\L&H
2008-10-31 09:44 . 2008-10-31 09:44 <DIR> d-------- c:\program files\Microsoft ActiveSync
2008-10-31 09:43 . 2008-10-31 09:45 <DIR> d-------- c:\windows\SHELLNEW
2008-10-31 09:43 . 2008-10-31 09:44 <DIR> d-------- c:\program files\Microsoft Works
2008-10-31 09:42 . 2008-10-31 09:42 <DIR> d-------- c:\program files\Microsoft.NET
2008-10-31 09:41 . 2008-10-31 09:41 <DIR> d-------- c:\program files\TheWeatherNetwork
2008-10-31 09:40 . 2008-10-31 09:40 <DIR> d-------- c:\program files\XP Codec Pack
2008-10-31 09:38 . 2008-10-31 09:40 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2008-10-31 09:38 . 2008-10-31 09:40 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-31 09:36 . 2008-10-31 09:36 <DIR> d-------- c:\program files\Lavasoft
2008-10-31 09:36 . 2008-10-31 09:36 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2008-10-31 09:36 . 2008-10-31 09:36 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2008-10-31 09:34 . 2008-10-31 09:34 <DIR> d-------- c:\windows\system32\Adobe
2008-10-31 09:34 . 2008-08-06 15:27 499,712 --a------ c:\windows\system32\msvcp71.dll
2008-10-31 09:34 . 2008-08-06 15:29 348,160 --a------ c:\windows\system32\msvcr71.dll
2008-10-31 09:33 . 2008-10-31 09:33 <DIR> d-------- c:\program files\Common Files\Adobe AIR
2008-10-31 09:32 . 2008-11-03 01:00 <DIR> d-------- c:\program files\Common Files\Adobe
2008-10-31 09:31 . 2008-10-31 10:03 <DIR> d-------- c:\program files\NOS
2008-10-31 09:31 . 2008-10-31 10:41 <DIR> d-------- c:\documents and settings\All Users\Application Data\NOS
2008-10-31 09:30 . 2008-10-31 09:30 <DIR> d-------- c:\windows\Sun
2008-10-31 09:30 . 2008-10-31 09:30 <DIR> d-------- c:\program files\Java
2008-10-31 09:30 . 2008-10-31 09:30 410,976 --a------ c:\windows\system32\deploytk.dll
2008-10-31 09:30 . 2008-10-31 09:30 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-10-31 08:39 . 2008-10-31 08:39 <DIR> d-------- c:\program files\Microsoft Silverlight
2008-10-31 08:32 . 2008-10-31 08:32 <DIR> d-------- c:\program files\Windows Media Connect 2
2008-10-31 08:31 . 2008-10-31 08:31 <DIR> d-------- c:\windows\system32\LogFiles
2008-10-31 08:31 . 2008-10-31 08:31 <DIR> d-------- c:\windows\system32\drivers\UMDF
2008-10-31 08:27 . 2008-06-13 05:05 272,128 --a------ c:\windows\system32\drivers\bthport.sys
2008-10-31 08:27 . 2008-06-13 05:05 272,128 -----c--- c:\windows\system32\dllcache\bthport.sys
2008-10-31 08:25 . 2008-10-31 10:15 <DIR> d--h----- c:\windows\$hf_mig$
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-05 02:34 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-03 15:02 --------- d-----w c:\program files\Common Files\InstallShield
2008-10-30 22:44 16,608 ----a-w c:\windows\gdrv.sys
2008-10-30 22:44 --------- d-----w c:\program files\Realtek
2008-10-30 22:42 319,488 ----a-w c:\windows\HideWin.exe
2008-10-30 22:41 --------- d-----w c:\program files\AMD
2008-10-30 22:41 --------- d-----w c:\documents and settings\Jody\Application Data\InstallShield
2008-10-30 22:26 --------- d-----w c:\program files\microsoft frontpage
2008-09-23 23:46 245,408 ----a-w c:\windows\system32\unicows.dll
2008-09-15 12:12 1,846,400 ----a-w c:\windows\system32\win32k.sys
2008-09-08 10:41 333,824 ----a-w c:\windows\system32\drivers\srv.sys
2008-08-26 07:24 826,368 ----a-w c:\windows\system32\wininet.dll
2008-08-26 05:51 16,851,456 ----a-w c:\windows\RTHDCPL.EXE
2008-08-19 05:26 77,824 ----a-w c:\windows\SOUNDMAN.EXE
2008-08-14 10:09 2,145,280 ----a-w c:\windows\system32\ntoskrnl.exe
2008-08-14 09:33 2,023,936 ----a-w c:\windows\system32\ntkrnlpa.exe
2008-08-07 03:38 9,728 ----a-r c:\windows\system32\RtNicProp32.dll
2008-08-06 07:51 1,200,128 ----a-w c:\windows\RtlUpd.exe
2008-08-06 07:51 1,200,128 ----a-w c:\windows\RtkUpd.exe
2008-04-14 12:00 305,674 --sha-r c:\windows\system32\hdqdaseqgylvi.exe
.
((((((((((((((((((((((((((((( snapshot@2008-11-04_14.05.55.32 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-06-02 05:00:00 270,336 ------w c:\windows\Crystal\crxf_pdf.dll
+ 2006-06-02 05:00:00 180,275 ------w c:\windows\Crystal\crxf_rtf.dll
+ 2006-06-02 05:00:00 28,672 ------w c:\windows\Crystal\u2ddisk.dll
+ 2006-06-02 05:00:00 40,960 ------w c:\windows\Crystal\u2dmapi.dll
+ 2005-08-31 10:31:28 120,464 ----a-w c:\windows\Downloaded Installations\Macromedia Flash 8\FL_Client_Installer.exe
+ 2005-04-04 20:49:16 2,003,176 ----a-w c:\windows\Downloaded Installations\Macromedia Flash 8\WindowsInstaller-KB884016-v2-x86.exe
+ 2008-11-05 04:34:57 65,536 ----a-r c:\windows\Installer\{2BD5C305-1B27-4D41-B690-7A61172D2FEB}\ARPPRODUCTICONFL8.exe
+ 2008-11-05 04:33:52 53,248 ----a-r c:\windows\Installer\{8BF2C401-02CE-424D-BC26-6C4F9FB446B6}\ARPPRODUCTICONFLV1.exe
+ 2008-11-05 04:16:39 473,600 ----a-w c:\windows\PrimoPDF4\uninstall.exe
+ 2006-05-20 19:22:00 184,897 ----a-w c:\windows\system32\atasnt40.dll
+ 2006-06-02 05:00:00 622,592 ------w c:\windows\system32\Crpaig80.dll
+ 2006-06-02 05:00:00 5,034,041 ------w c:\windows\system32\crpe32.dll
+ 2006-06-02 05:00:00 66,560 ------w c:\windows\system32\crwrap32.dll
+ 2006-05-20 19:44:46 51,392 ----a-w c:\windows\system32\drivers\atnt40k.sys
+ 2006-06-02 05:00:00 40,448 ------w c:\windows\system32\dsofile.dll
+ 2006-06-02 05:00:00 17,920 ------w c:\windows\system32\Implode.dll
+ 2005-11-14 04:35:14 39,424 ----a-w c:\windows\system32\JETCOMP.exe
- 2008-10-05 03:24:02 3,695,008 ----a-w c:\windows\system32\Macromed\Flash\NPSWF32.dll
+ 2005-08-27 20:08:06 1,398,408 ----a-w c:\windows\system32\Macromed\Flash\NPSWF32.dll
+ 2005-11-14 04:35:04 344,064 ----a-w c:\windows\system32\msexch35.dll
+ 2005-11-14 04:35:06 252,688 ----a-w c:\windows\system32\msexcl35.dll
+ 2005-11-14 04:35:06 1,050,896 ----a-w c:\windows\system32\msjet35.dll
+ 2005-11-14 04:35:10 139,264 ----a-w c:\windows\system32\msjint35.dll
+ 2005-11-14 04:35:06 1,238,288 ----a-w c:\windows\system32\msjt4jlt.dll
+ 2005-11-14 04:35:14 24,848 ----a-w c:\windows\system32\msjter35.dll
+ 2005-11-14 04:35:06 168,720 ----a-w c:\windows\system32\msltus35.dll
+ 2005-11-14 04:35:08 250,128 ----a-w c:\windows\system32\mspdox35.dll
+ 2005-11-14 04:35:08 262,144 ----a-w c:\windows\system32\msrd2x35.dll
+ 2005-11-14 04:35:14 415,504 ----a-w c:\windows\system32\msrepl35.dll
+ 2005-11-14 04:35:14 44,304 ----a-w c:\windows\system32\msrpfs35.dll
+ 2005-11-14 04:35:08 166,672 ----a-w c:\windows\system32\mstext35.dll
+ 2005-11-14 04:35:08 294,912 ----a-w c:\windows\system32\msxbse35.dll
+ 2005-11-14 04:39:54 72,704 ----a-w c:\windows\system32\odbctl32.dll
+ 2006-06-02 05:00:00 188,416 ------w c:\windows\system32\P2smon.dll
+ 2006-06-02 05:00:00 303,104 ------w c:\windows\system32\p2sodbc.dll
- 2008-11-04 19:57:44 63,732 ----a-w c:\windows\system32\perfc009.dat
+ 2008-11-05 14:19:43 63,732 ----a-w c:\windows\system32\perfc009.dat
- 2008-11-04 19:57:44 406,658 ----a-w c:\windows\system32\perfh009.dat
+ 2008-11-05 14:19:43 406,658 ----a-w c:\windows\system32\perfh009.dat
+ 2005-08-05 14:52:14 1,642,496 ----a-w c:\windows\system32\QuickTime\MMxptResources.dll
- 2006-08-31 16:46:24 106,256 ----a-w c:\windows\system32\spool\drivers\w32x86\3\ps5ui.dll
+ 2006-11-06 23:55:04 106,256 ----a-w c:\windows\system32\spool\drivers\w32x86\3\ps5ui.dll
- 2006-08-31 16:46:26 383,248 ----a-w c:\windows\system32\spool\drivers\w32x86\3\pscript5.dll
+ 2006-11-06 23:55:05 383,248 ----a-w c:\windows\system32\spool\drivers\w32x86\3\pscript5.dll
- 2006-08-31 16:46:24 106,256 ----a-w c:\windows\system32\spool\drivers\w32x86\ps5ui.dll
+ 2006-11-06 23:55:04 106,256 ----a-w c:\windows\system32\spool\drivers\w32x86\ps5ui.dll
- 2006-08-31 16:46:26 383,248 ----a-w c:\windows\system32\spool\drivers\w32x86\pscript5.dll
+ 2006-11-06 23:55:05 383,248 ----a-w c:\windows\system32\spool\drivers\w32x86\pscript5.dll
+ 2005-11-14 04:40:12 89,360 ----a-w c:\windows\system32\VB5DB.DLL
+ 2005-11-14 04:35:14 368,912 ----a-w c:\windows\system32\VBAR332.DLL
+ 2008-11-05 14:15:30 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_480.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WeatherEye"="c:\program files\TheWeatherNetwork\WeatherEye\WeatherEye" [X]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GEST"="=" [X]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-10-31 136600]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2006-11-21 813912]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-02-05 849280]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd.exe" [2003-08-04 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 241664]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"RTHDCPL"="RTHDCPL.EXE" [2008-08-25 c:\windows\RTHDCPL.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 237568]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]
2008-03-18 16:58 58672 c:\windows\system32\avldr.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=nkpuoq.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= ffdshow.ax
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PskSvcRetail]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\CoreFTP\\coreftp.exe"=
"c:\\WINDOWS\\system32\\hdqdaseqgylvi.exe"=
R0 pavboot;Panda boot driver;c:\windows\system32\Drivers\pavboot.sys [2008-06-19 28544]
R1 ShldDrv;Panda File Shield Driver;c:\windows\system32\DRIVERS\ShlDrv51.sys [2008-03-04 41144]
R2 Gwmsrv;Panda Goodware Cache Manager;c:\windows\system32\svchost -k Panda [ ]
R2 JavaQuickStarterService;Java Quick Starter;c:\program files\Java\jre6\bin\jqs.exe [2008-10-31 152984]
R2 PavProc;Panda Process Protection Driver;c:\windows\system32\DRIVERS\PavProc.sys [2008-02-07 179640]
R2 PskSvcRetail;Panda PSK service;c:\program files\Panda Security\Panda Antivirus Pro 2009\PskSvc.exe [2008-06-25 28928]
R3 AvFlt;Antivirus Filter Driver;c:\windows\system32\drivers\av5flt.sys [ ]
R3 PavSRK.sys;PavSRK.sys;c:\windows\system32\PavSRK.sys [ ]
R3 PavTPK.sys;PavTPK.sys;c:\windows\system32\PavTPK.sys [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
panda REG_MULTI_SZ Gwmsrv
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4515c0a2-a6d5-11dd-af6d-001fd09d591c}]
\Shell\AutoRun\command - J:\Menu.exe
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-05 09:15:24
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-11-05 9:16:14
ComboFix-quarantined-files.txt 2008-11-05 15:15:51
ComboFix2.txt 2008-11-04 20:06:19
Pre-Run: 488,846,110,720 bytes free
Post-Run: 488,913,666,048 bytes free
341 --- E O F --- 2008-11-04 19:51:43