Here are the new combofix logs and the hjt after combofix was ran.
ComboFix 09-02-10.02 - user 2009-02-11 14:15:12.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3327.2765 [GMT 8:00]
Running from: c:\documents and settings\user\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated)
FW: McAfee Personal Firewall *disabled*
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\gaopdxcounter
.
((((((((((((((((((((((((( Files Created from 2009-01-11 to 2009-02-11 )))))))))))))))))))))))))))))))
.
2009-02-10 18:57 . 2009-02-10 19:00 <DIR> d-------- c:\program files\FFXIP
2009-02-10 13:47 . 2009-02-10 14:05 345 --a------ c:\windows\gmer.ini
2009-02-09 20:46 . 2008-10-16 14:06 268,648 --a------ c:\windows\system32\mucltui.dll
2009-02-09 20:46 . 2008-10-16 14:06 208,744 --a------ c:\windows\system32\muweb.dll
2009-02-09 20:46 . 2008-10-16 14:06 27,496 --a------ c:\windows\system32\mucltui.dll.mui
2009-02-08 23:37 . 2009-02-08 23:37 <DIR> d-------- c:\program files\Windows Live SkyDrive
2009-02-08 23:37 . 2009-02-08 23:37 <DIR> d-------- c:\program files\Microsoft Office Outlook Connector
2009-02-08 23:37 . 2009-02-08 23:37 <DIR> d-------- c:\program files\Microsoft
2009-02-08 23:35 . 2009-02-08 23:35 <DIR> d-------- c:\program files\Common Files\Windows Live
2009-02-08 22:21 . 2009-02-08 22:27 <DIR> d-------- c:\program files\Safer Networking
2009-02-08 22:00 . 2009-02-08 22:00 <DIR> d-------- C:\rsit
2009-02-08 20:07 . 2009-02-08 20:07 <DIR> d-------- c:\program files\Elaborate Bytes
2009-02-08 19:51 . 2009-02-08 19:51 <DIR> d-------- c:\program files\MSXML 4.0
2009-02-03 20:08 . 2009-02-03 20:08 <DIR> d-------- c:\documents and settings\user\Application Data\SolidWorks 2008
2009-02-03 20:00 . 2009-02-03 23:01 <DIR> d-------- c:\documents and settings\user\Application Data\SolidWorks
2009-02-03 18:19 . 2009-02-03 18:34 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Winamp
2009-02-03 17:52 . 2009-02-03 17:52 <DIR> d-------- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-02-03 17:47 . 2009-02-03 17:48 <DIR> d-------- c:\documents and settings\Administrator
2009-02-03 17:25 . 2009-02-03 17:25 23 --ah----- c:\windows\yacht.xws
2009-02-03 17:22 . 2009-02-03 17:22 <DIR> d-------- c:\windows\system32\GroupPolicy
2009-02-03 17:22 . 2009-02-03 20:01 <DIR> d-------- c:\documents and settings\All Users\Application Data\SolidWorks
2009-02-03 17:19 . 2009-02-03 17:19 <DIR> d-------- c:\program files\SolidWorks Viewer
2009-02-03 17:16 . 2009-02-03 17:16 <DIR> d-------- c:\program files\Windows Desktop Search
2009-02-03 17:15 . 2009-02-03 20:00 <DIR> d-------- c:\program files\SolidWorks
2009-02-03 17:14 . 2009-02-03 17:14 <DIR> d-------- c:\program files\Document Manager
2009-02-03 17:12 . 2009-02-03 17:23 <DIR> d-------- c:\program files\Common Files\SolidWorks Shared
2009-02-03 17:12 . 2009-02-03 17:22 <DIR> d-------- c:\program files\Common Files\eDrawings2008
2009-02-03 17:12 . 2009-02-03 17:12 0 --a------ c:\windows\eDrawingOfficeAutomator.INI
2009-02-03 17:11 . 2009-02-03 20:06 <DIR> d-------- c:\program files\DWGeditor
2009-02-03 17:11 . 2009-02-03 17:11 <DIR> d-------- c:\documents and settings\user\Application Data\DWGeditor
2009-02-03 16:08 . 2009-02-03 17:22 <DIR> d-------- C:\SolidWorks Data
2009-02-03 16:04 . 2009-02-03 16:05 <DIR> d-------- c:\program files\Common Files\SolidWorks Installation Manager
2009-02-03 16:03 . 2009-02-03 16:09 <DIR> d-------- c:\windows\SolidWorks
2009-02-03 16:03 . 2009-02-03 20:02 <DIR> d-------- c:\documents and settings\user\Application Data\IM
2009-02-03 15:53 . 2009-02-03 15:53 <DIR> d-------- c:\program files\Classic Menu for Office
2009-02-03 15:53 . 2009-02-11 14:08 <DIR> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2009-02-03 15:35 . 2009-02-03 15:35 <DIR> d-------- c:\documents and settings\user\workspace
2009-02-03 15:31 . 2009-02-03 16:31 <DIR> d-------- c:\windows\SxsCaPendDel
2009-02-03 15:25 . 2009-02-10 21:47 <DIR> d-------- c:\program files\eclipse
2009-01-20 20:33 . 2009-01-20 20:33 <DIR> d-------- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-01-20 20:32 . 2008-08-05 20:10 1,684,736 --a------ c:\windows\system32\drivers\Ambfilt.sys
2009-01-20 20:32 . 2006-01-04 15:41 1,389,056 --a------ c:\windows\system32\drivers\Monfilt.sys
2009-01-20 20:32 . 2008-10-23 17:42 290,816 --a------ c:\windows\vncutil.exe
2009-01-20 20:32 . 2008-06-24 14:46 104,992 --a------ c:\windows\RtkAudioService.exe
2009-01-20 20:32 . 2009-01-05 16:16 34,816 --a------ c:\windows\system32\RtkCoInstXP.dll
2009-01-20 18:21 . 2009-01-20 18:21 <DIR> d-------- c:\program files\Avanquest update
2009-01-20 18:21 . 2009-01-20 18:21 <DIR> d-------- c:\documents and settings\All Users\Application Data\BVRP Software
2009-01-20 18:20 . 2009-01-20 18:20 <DIR> d-------- c:\program files\Sony Ericsson
2009-01-20 18:20 . 2009-01-20 18:20 <DIR> d-------- c:\documents and settings\user\Application Data\InstallShield
2009-01-20 18:20 . 2009-01-20 18:20 <DIR> d-------- c:\documents and settings\All Users\Application Data\Sony Ericsson
2009-01-20 18:20 . 2008-05-16 12:33 120,744 --a------ c:\windows\system32\drivers\s0016mdm.sys
2009-01-20 18:20 . 2008-05-16 12:33 89,256 --a------ c:\windows\system32\drivers\s0016bus.sys
2009-01-20 18:20 . 2008-05-16 12:33 15,016 --a------ c:\windows\system32\drivers\s0016mdfl.sys
2009-01-20 18:20 . 2008-05-16 12:33 12,200 --a------ c:\windows\system32\drivers\s0016whnt.sys
2009-01-20 18:20 . 2008-05-16 12:33 12,200 --a------ c:\windows\system32\drivers\s0016wh.sys
2009-01-20 18:20 . 2008-05-16 12:33 12,200 --a------ c:\windows\system32\drivers\s0016cmnt.sys
2009-01-20 18:20 . 2008-05-16 12:33 12,200 --a------ c:\windows\system32\drivers\s0016cm.sys
2009-01-20 17:50 . 2009-01-20 17:50 <DIR> d-------- c:\windows\Downloaded Installations
2009-01-20 17:49 . 2009-01-20 17:49 54,156 --ah----- c:\windows\QTFont.qfn
2009-01-20 17:49 . 2009-01-20 17:49 1,409 --a------ c:\windows\QTFont.for
2009-01-20 13:14 . 2009-01-20 13:14 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-20 13:14 . 2009-01-20 13:14 <DIR> d-------- c:\documents and settings\user\Application Data\Malwarebytes
2009-01-20 13:14 . 2009-01-20 13:14 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-20 13:14 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-20 13:14 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-01-18 22:18 . 2009-01-18 22:18 0 --a------ c:\windows\LCDMedia.INI
2009-01-18 22:13 . 2009-01-18 22:13 <DIR> d-------- c:\program files\ERUNT
2009-01-14 01:23 . 2009-01-14 01:23 <DIR> d-------- c:\program files\Trend Micro
2009-01-13 15:00 . 2009-01-13 15:00 <DIR> d-------- c:\program files\Notepad++
2009-01-13 15:00 . 2009-01-13 15:00 <DIR> d-------- c:\documents and settings\user\Application Data\Notepad++
2009-01-13 00:43 . 2009-02-08 22:49 <DIR> d-------- c:\program files\Google
2009-01-12 23:25 . 2009-02-03 15:32 <DIR> d-------- c:\windows\system32\XPSViewer
2009-01-12 23:24 . 2009-01-12 23:24 <DIR> d-------- c:\program files\Reference Assemblies
2009-01-12 23:23 . 2006-06-29 13:07 14,048 --------- c:\windows\system32\spmsg2.dll
2009-01-12 23:19 . 2009-01-12 23:19 <DIR> d-------- c:\program files\MSECache
2009-01-12 22:20 . 2009-01-18 22:48 185 --a------ c:\windows\wininit.ini
2009-01-12 22:19 . 2009-01-12 22:19 <DIR> d-------- c:\program files\PowerISO
2009-01-12 21:53 . 2009-01-12 21:53 <DIR> d-------- c:\documents and settings\user\WINDOWS
2009-01-12 21:46 . 2009-01-12 21:46 288 --a------ c:\windows\ODBC.INI
2009-01-12 21:46 . 2009-01-12 21:46 126 --a------ c:\windows\mdm.ini
2009-01-12 21:43 . 2009-01-12 21:43 <DIR> d-------- c:\program files\Web Publish
2009-01-12 10:49 . 1998-06-02 11:56 313,856 --a------ c:\windows\system32\dx3j.dll
2009-01-12 10:49 . 1998-06-02 14:45 140,048 --a------ c:\windows\system32\jit.dll
2009-01-12 10:49 . 1998-06-02 12:29 135,168 --a------ c:\windows\system32\javaee.dll
2009-01-12 10:49 . 1998-06-02 12:41 42,496 --a------ c:\windows\setdebug.exe
2009-01-12 10:49 . 1998-06-02 12:28 7,356 --a------ c:\windows\system32\javasup.vxd
2009-01-12 10:49 . 1998-06-02 11:57 6,550 --a------ c:\windows\jautoexp.dat
2009-01-12 02:17 . 2009-01-12 02:17 <DIR> d-------- c:\program files\Common Files\Adobe AIR
2009-01-12 02:16 . 2009-01-12 02:17 <DIR> d-------- c:\program files\Common Files\Adobe
2009-01-12 02:06 . 2009-01-12 11:20 <DIR> d-------- c:\program files\NOS
2009-01-12 02:06 . 2009-01-12 11:20 <DIR> d-------- c:\documents and settings\All Users\Application Data\NOS
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-09 12:54 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-02-03 09:22 --------- d-----w c:\program files\AGEIA Technologies
2009-01-20 10:21 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-09 14:17 --------- d-----w c:\program files\CDisplay
2009-01-09 03:07 --------- d-----w c:\program files\Java
2009-01-09 02:54 --------- d-----w c:\documents and settings\user\Application Data\CyberLink
2009-01-09 02:54 --------- d-----w c:\documents and settings\All Users\Application Data\CyberLink
2009-01-07 17:35 --------- d-----w c:\program files\Project64 1.6
2009-01-07 17:03 --------- d-----w c:\program files\MagicDVDRipper
2009-01-07 15:14 --------- d-----w c:\program files\Karen's Power Tools
2009-01-07 15:14 --------- d-----w c:\documents and settings\All Users\Application Data\Karen's Power Tools
2009-01-07 14:12 --------- d-----w c:\program files\Nidesoft Studio
2009-01-07 13:58 --------- d-----w c:\program files\Aglare DVD to AVI WMV MP4 MPEG Converter
2009-01-07 02:12 --------- d-----w c:\program files\Easy MPEG AVI DIVX WMV RM to DVD
2009-01-06 11:00 4,968,448 ----a-w c:\windows\system32\drivers\RtkHDAud.sys
2009-01-01 08:23 --------- d-----w c:\program files\McAfee
2009-01-01 08:19 --------- d-----w c:\program files\FFXiBench3
2009-01-01 07:54 --------- d-----w c:\documents and settings\user\Application Data\mjusbsp
2008-12-30 23:10 --------- d-----w c:\documents and settings\LocalService\Application Data\SACore
2008-12-30 06:58 18,082,304 ----a-w c:\windows\RTHDCPL.EXE
2008-12-30 06:47 --------- d-----w c:\documents and settings\All Users\Application Data\SiteAdvisor
2008-12-30 06:47 --------- d-----w c:\documents and settings\All Users\Application Data\McAfee
2008-12-29 06:00 --------- d-----w c:\program files\Transparent
2008-12-29 05:47 --------- d-----w c:\documents and settings\user\Application Data\Winamp
2008-12-29 04:36 --------- d-----w c:\documents and settings\user\Application Data\DivX
2008-12-29 03:53 --------- d-----w c:\program files\Common Files\LightScribe
2008-12-29 03:51 --------- d-----w c:\program files\Common Files\Ahead
2008-12-29 03:51 --------- d-----w c:\program files\Ahead
2008-12-29 03:50 --------- d-----w c:\program files\CyberLink DVD Solution
2008-12-29 03:49 --------- d-----w c:\program files\CyberLink
2008-12-29 03:48 --------- d-----w c:\program files\Common Files\InstallShield
2008-12-29 03:18 --------- d-----w c:\program files\MSBuild
2008-12-29 03:18 --------- d-----w c:\program files\Microsoft Works
2008-12-29 03:08 --------- d-----w c:\program files\Alcohol Soft
2008-12-29 02:49 --------- d-----w c:\program files\PlayOnline
2008-12-28 06:57 --------- d-----w c:\program files\Common Files\McAfee
2008-12-28 06:57 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-28 06:57 --------- d-----w c:\documents and settings\All Users\Application Data\OrbNetworks
2008-12-28 06:56 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-12-28 06:47 --------- d-----w c:\program files\Winamp Toolbar
2008-12-28 06:47 --------- d-----w c:\program files\Winamp Remote
2008-12-28 06:47 --------- d-----w c:\program files\Winamp
2008-12-28 06:47 --------- d-----w c:\documents and settings\All Users\Application Data\Winamp Toolbar
2008-12-28 06:42 --------- d-----w c:\program files\DivX
2008-12-28 06:32 --------- d-----w c:\program files\McAfee.com
2008-12-28 05:54 --------- d-----w c:\program files\Logitech
2008-12-28 05:54 --------- d-----w c:\documents and settings\All Users\Application Data\Logitech
2008-12-28 03:36 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-12-28 03:31 --------- d-----w c:\program files\Intel
2008-12-28 03:30 --------- d-----w c:\program files\Realtek
2008-12-28 03:24 --------- d-----w c:\program files\microsoft frontpage
2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys
2006-06-24 06:48 32,768 ----a-r c:\windows\inf\UpdateUSB.exe
2004-10-01 23:00 40,960 ----a-w c:\program files\Uninstall_CDS.exe
.
((((((((((((((((((((((((((((( snapshot@2009-02-03_22.24.00.96 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-02-03 15:18:57 842,240 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\b5b2feadc3943e3976daebc0bcd2b5e2\AspNetMMCExt.ni.dll
+ 2009-02-03 15:18:32 410,112 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\12629e2f3e315459bee67cbbaac85cb2\ComSvcConfig.ni.exe
+ 2009-02-03 15:19:06 220,672 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\9bea05938bee3555c5aa8763d89a68f9\CustomMarshalers.ni.dll
+ 2009-02-03 15:19:00 14,336 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\dfsvc\f4e38208e88cb4cc314a1d6543b9fcc6\dfsvc.ni.exe
+ 2009-02-03 15:19:07 222,720 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\9b321ebf67587237f576df6104a32588\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2009-02-03 15:19:05 1,888,768 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\6cfe582681724965fb817e8ece5f0909\Microsoft.Build.Engine.ni.dll
+ 2009-02-03 15:19:09 839,680 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\96825c34d7e1f7df1923ff2123bed8da\Microsoft.Build.Engine.ni.dll
+ 2009-02-03 15:19:03 74,752 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Fra#\28343d470d992f169ca0e7cdb3cc3117\Microsoft.Build.Framework.ni.dll
+ 2009-02-03 15:19:19 1,966,080 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\a47100d8f4574bed2d49d83d0ab8964e\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2009-02-03 15:19:17 1,620,992 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\bd241492d96db39f20e758c13c845033\Microsoft.Build.Tasks.ni.dll
+ 2009-02-03 15:19:21 175,104 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\4217124db1ea5de5f1a1f3eea75e8d32\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2009-02-03 15:20:20 2,332,160 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\b261961046545831aa60963e84905968\Microsoft.JScript.ni.dll
+ 2009-02-03 15:18:37 386,560 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\1820d6a012fc0e16c3e1d29d973cd2d0\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2009-02-03 15:18:34 1,093,120 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\6b2f62f5e981913fce1d223f645d9ddf\Microsoft.Transactions.Bridge.ni.dll
+ 2009-02-03 15:19:24 1,712,128 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\1c86afc399d0fdd8e069266ffbe748d1\Microsoft.VisualBasic.ni.dll
+ 2009-02-03 15:20:22 55,296 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\790cf1edb17ee41b59be62ecbd59613b\Microsoft.Vsa.ni.dll
+ 2009-02-03 15:19:03 133,632 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\6d38e317128608bc4516ea46ab94590e\MSBuild.ni.exe
+ 2009-02-03 15:18:40 320,512 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\10a0c9707876fc1f65e64b811a28b020\ServiceModelReg.ni.exe
+ 2009-02-03 15:18:41 256,000 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\9790551187e294b4ed3aaa1c221891c7\SMDiagnostics.ni.dll
+ 2009-02-03 15:18:42 366,080 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\
045dd501b7257b1cc26083538ae69045\SMSvcHost.ni.exe
+ 2009-02-03 15:20:32 232,448 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\sysglobl\45067d0793a09d3431d26bfa55c5a76a\sysglobl.ni.dll
+ 2009-02-03 15:19:26 82,944 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\597b20e1b053d6a510cfe033c07a63e6\System.AddIn.Contract.ni.dll
+ 2009-02-03 15:19:26 633,856 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\ce984d754e3c0b6be4504b785cc43574\System.AddIn.ni.dll
+ 2009-02-03 15:19:28 94,208 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.ComponentMod#\532438e2acfcadc469a4d468c51f8451\System.ComponentModel.DataAnnotations.ni.dll
+ 2009-02-03 15:19:32 135,680 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\1db495ff00bbd14df4af6680c4de0653\System.Data.DataSetExtensions.ni.dll
+ 2009-02-03 15:20:05 756,736 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\392de34573f9f8ec885714f2f3e7f07f\System.Data.Entity.Design.ni.dll
+ 2009-02-03 15:20:01 9,924,096 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\6479f975b105808a8d9e7a7fdc762551\System.Data.Entity.ni.dll
+ 2009-02-03 15:20:13 354,816 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\1cf3acad6553d6c59df576794f4e8bd6\System.Data.Services.Design.ni.dll
+ 2009-02-03 15:20:12 939,008 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\a4b887f476fa4b8746a93a9fc2208560\System.Data.Services.Client.ni.dll
+ 2009-02-03 15:20:10 1,328,128 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\956a513dcbd44d5a6801840ef2b0b47b\System.Data.Services.ni.dll
+ 2009-02-03 15:20:15 881,152 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\8b3bb7a2c2f3ffe94c866283f1cd5957\System.DirectoryServices.AccountManagement.ni.dll
+ 2009-02-03 15:17:42 212,992 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\68e71147704ef0d34d9a4bece7767fc5\System.IdentityModel.Selectors.ni.dll
+ 2009-02-03 15:17:40 1,056,768 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\c2de8479e54852f56996f79bc93acb13\System.IdentityModel.ni.dll
+ 2009-02-03 15:17:43 381,440 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\7c367a96b10d626ec8cbf8149272d845\System.IO.Log.ni.dll
+ 2009-02-03 15:20:17 330,752 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\1d3fbbd23ce1e8637ef4f40a8d23cd32\System.Management.Instrumentation.ni.dll
+ 2009-02-03 15:20:18 998,400 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\8642fdfbf02a6cb6f01169fe6fdb5d11\System.Management.ni.dll
+ 2009-02-03 15:21:21 593,408 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Messaging\f48e3419fb2cb012fd160ae801600ae7\System.Messaging.ni.dll
+ 2009-02-03 15:20:23 621,056 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\519d9c618341b136f9b963ffb7495308\System.Net.ni.dll
+ 2009-02-03 15:17:48 2,338,304 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\
034c91b133dee73d452652c52767b5ea\System.Runtime.Serialization.ni.dll
+ 2009-02-03 15:20:27 1,706,496 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\340cad17fe57947eacbc8fa2cea780da\System.ServiceModel.Web.ni.dll
+ 2009-02-03 15:18:14 17,317,888 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\4146033013edebd7e0cb604e504ebfee\System.ServiceModel.ni.dll
+ 2009-02-03 15:20:30 1,917,440 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\63cf639b6e0a3c25c1643c85016e7422\System.Speech.ni.dll
+ 2009-02-03 15:20:33 141,312 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\
00ec08741a765c707bd9169346064a81\System.Web.Abstractions.ni.dll
+ 2009-02-03 15:20:40 36,864 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\19ca1747c1ea18a3b639b302bca8df93\System.Web.DynamicData.Design.ni.dll
+ 2009-02-03 15:20:39 547,328 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\b7891f5659db299dbd1b3c72db7edb9f\System.Web.DynamicData.ni.dll
+ 2009-02-03 15:20:42 301,056 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\d3d65e34fa60f0b6c72ca0d12ec89933\System.Web.Entity.Design.ni.dll
+ 2009-02-03 15:20:41 328,704 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\79c29ac85dd57dd485ab60118ac292ff\System.Web.Entity.ni.dll
+ 2009-02-03 15:20:44 859,648 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\58f62044fa702ea6f936071aa5520baa\System.Web.Extensions.Design.ni.dll
+ 2009-02-03 15:20:37 2,403,328 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\7f64c9d25471b72e1e957bdfe67947c8\System.Web.Extensions.ni.dll
+ 2009-02-03 15:20:46 2,209,280 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\81197e32ec931f439b3114e9031b65d6\System.Web.Mobile.ni.dll
+ 2009-02-03 15:20:34 129,536 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\bb77ea11f46ab438b2b7ed7c180011a1\System.Web.Routing.ni.dll
+ 2009-02-03 15:21:03 37,888 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Pres#\423f794d1f4ed6e120fbb02e436491cb\System.Windows.Presentation.ni.dll
+ 2009-02-03 15:21:08 2,992,640 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\cc99fbbac0b6e4e9ca62093e49b0c16b\System.Workflow.Activities.ni.dll
+ 2009-02-03 15:21:15 4,514,304 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\693a8fbe6f7ad6e4e429052da4317e59\System.Workflow.ComponentModel.ni.dll
+ 2009-02-03 15:21:19 1,908,224 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\d265da36954fcb4cb7ad5adc693ea0f2\System.Workflow.Runtime.ni.dll
+ 2009-02-03 15:21:24 1,356,288 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\ac1750e78d79520dcf19195772eff1b6\System.WorkflowServices.ni.dll
+ 2009-02-03 15:21:25 400,896 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\c338a470b14851ce5987bb0f0869c310\System.Xml.Linq.ni.dll
+ 2009-02-03 15:18:44 321,536 ----a-w c:\windows\assembly\NativeImages_v2.0.50727_32\WsatConfig\2ef5bc3a2edd7570bb23886a4f32294a\WsatConfig.ni.exe
+ 2005-10-20 12:02:28 163,328 ----a-w c:\windows\ERDNT\subs\ERDNT.EXE
+ 2009-02-10 05:47:25 884,736 ----a-w c:\windows\gmer.dll
+ 2008-04-17 13:13:02 811,008 ----a-w c:\windows\gmer.exe
+ 2006-10-27 04:55:38 138,024 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109110000000000000000F01FEC\12.0.4518\IMPMAIL.DLL
+ 2006-09-16 00:25:18 3,611,416 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109110000000000000000F01FEC\12.0.4518\OUTLFLTR.DAT
+ 2006-10-27 23:16:36 46,864 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109110000000000000000F01FEC\12.0.4518\OUTLRPC.DLL
+ 2007-08-29 07:19:32 136,064 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109110000000000000000F01FEC\12.0.6215\CONTAB32.DLL
+ 2007-08-24 12:49:12 89,976 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109110000000000000000F01FEC\12.0.6215\DLGSETP.DLL
+ 2007-10-06 04:37:38 17,927,192 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109110000000000000000F01FEC\12.0.6215\EXCEL.EXE
+ 2007-08-24 12:49:40 342,888 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109110000000000000000F01FEC\12.0.6215\MIMEDIR.DLL
+ 2007-08-29 07:38:10 500,648 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109110000000000000000F01FEC\12.0.6215\MORPH9.DLL
+ 2007-09-15 05:45:58 16,901,168 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109110000000000000000F01FEC\12.0.6215\MSO.DLL
+ 2007-08-29 07:38:46 9,584,512 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109110000000000000000F01FEC\12.0.6215\MSPUB.EXE
+ 2007-08-29 07:20:20 2,949,512 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109110000000000000000F01FEC\12.0.6215\OLMAPI32.DLL
+ 2007-08-24 13:42:40 663,432 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109110000000000000000F01FEC\12.0.6215\OMSMAIN.DLL
+ 2007-08-24 13:42:44 195,480 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109110000000000000000F01FEC\12.0.6215\OMSXP32.DLL
+ 2007-08-29 07:20:44 600,992 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109110000000000000000F01FEC\12.0.6215\OUTLMIME.DLL
+ 2007-09-07 02:01:10 12,836,728 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109110000000000000000F01FEC\12.0.6215\OUTLOOK.EXE
+ 2007-08-29 07:22:04 180,128 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109110000000000000000F01FEC\12.0.6215\OUTLPH.DLL
+ 2007-08-29 07:06:16 467,840 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109110000000000000000F01FEC\12.0.6215\POWERPNT.EXE
+ 2007-08-29 07:06:44 7,990,144 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109110000000000000000F01FEC\12.0.6215\PPCORE.DLL
+ 2007-08-24 11:43:28 138,648 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109110000000000000000F01FEC\12.0.6215\PRTF9.DLL
+ 2007-08-24 12:51:48 416,112 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109110000000000000000F01FEC\12.0.6215\PSTPRX32.DLL
+ 2007-08-29 07:39:14 625,560 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109110000000000000000F01FEC\12.0.6215\PTXT9.DLL
+ 2007-08-24 11:43:36 593,296 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109110000000000000000F01FEC\12.0.6215\PUBCONV.DLL
+ 2007-08-24 12:52:08 266,160 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109110000000000000000F01FEC\12.0.6215\SCNPST32.DLL
+ 2007-08-24 12:52:10 275,896 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109110000000000000000F01FEC\12.0.6215\SCNPST64.DLL
+ 2007-08-29 07:16:00 350,064 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109110000000000000000F01FEC\12.0.6215\WINWORD.EXE
+ 2007-09-07 02:03:02 4,280,176 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109110000000000000000F01FEC\12.0.6215\WRD12CNV.DLL
+ 2007-08-29 08:07:58 24,928 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109110000000000000000F01FEC\12.0.6215\WRD12EXE.EXE
+ 2007-09-07 01:56:32 17,490,800 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109110000000000000000F01FEC\12.0.6215\WWLIB.DLL
+ 2007-10-03 04:00:06 14,708,760 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109110000000000000000F01FEC\12.0.6215\XL12CNV.EXE
+ 2007-08-24 13:14:14 13,712 ----a-r c:\windows\Installer\$PatchCache$\Managed\
00002109110000000000000000F01FEC\12.0.6215\XLCALL32.DLL
+ 2006-10-26 12:30:12 7,042,880 ----a-r c:\windows\Installer\$PatchCache$\Managed\
000021094A0090400000000000F01FEC\12.0.4518\OWC11.DLL
+ 2007-08-29 08:19:24 1,654,648 ----a-r c:\windows\Installer\$PatchCache$\Managed\
000021094A0090400000000000F01FEC\12.0.6213\OGL.DLL
+ 2009-02-08 11:51:22 32,768 ----a-r c:\windows\Installer\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}\icon.exe
- 2008-12-29 05:35:19 1,165,584 ----a-r c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\accicons.exe
+ 2009-02-09 12:54:57 1,165,584 ----a-r c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\accicons.exe
- 2008-12-29 05:35:19 20,240 ----a-r c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\cagicon.exe
+ 2009-02-09 12:54:57 20,240 ----a-r c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\cagicon.exe
- 2008-12-29 05:35:19 159,504 ----a-r c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\inficon.exe
+ 2009-02-09 12:54:57 159,504 ----a-r c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\inficon.exe
- 2008-12-29 05:35:19 217,864 ----a-r c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\misc.exe
+ 2009-02-09 12:54:57 217,864 ----a-r c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\misc.exe
- 2008-12-29 05:35:19 18,704 ----a-r c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\mspicons.exe
+ 2009-02-09 12:54:57 18,704 ----a-r c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\mspicons.exe
- 2008-12-29 05:35:19 35,088 ----a-r c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\oisicon.exe
+ 2009-02-09 12:54:57 35,088 ----a-r c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\oisicon.exe
- 2008-12-29 05:35:19 845,584 ----a-r c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\outicon.exe
+ 2009-02-09 12:54:57 845,584 ----a-r c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\outicon.exe
- 2008-12-29 05:35:19 922,384 ----a-r c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\pptico.exe
+ 2009-02-09 12:54:57 922,384 ----a-r c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\pptico.exe
- 2008-12-29 05:35:19 272,648 ----a-r c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\pubs.exe
+ 2009-02-09 12:54:57 272,648 ----a-r c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\pubs.exe
- 2008-12-29 05:35:19 888,080 ----a-r c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\wordicon.exe
+ 2009-02-09 12:54:57 888,080 ----a-r c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\wordicon.exe
- 2008-12-29 05:35:19 1,172,240 ----a-r c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\xlicons.exe
+ 2009-02-09 12:54:57 1,172,240 ----a-r c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\xlicons.exe
- 2009-01-12 15:19:49 217,864 ----a-r c:\windows\Installer\{90120000-00A4-0409-0000-0000000FF1CE}\misc.exe
+ 2009-02-09 12:53:59 217,864 ----a-r c:\windows\Installer\{90120000-00A4-0409-0000-0000000FF1CE}\misc.exe
+ 2009-02-08 15:38:44 29,316 ----a-r c:\windows\Installer\{95120000-0120-0409-0000-0000000FF1CE}\olc_setup.exe
- 2009-02-03 13:34:23 32,768 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-02-11 05:36:26 32,768 ----a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-02-03 13:34:23 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-02-11 05:36:26 32,768 ----a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-02-11 05:36:26 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-05-07 09:07:23 135,168 ----a-w c:\windows\system32\cscript.exe
+ 2004-08-09 13:27:08 98,304 ----a-w c:\windows\system32\cscript.exe
- 2008-04-14 13:41:54 32,768 ----a-w c:\windows\system32\dispex.dll
+ 2004-08-09 13:27:00 28,672 ----a-w c:\windows\system32\dispex.dll
- 2008-05-07 09:07:23 135,168 -c----w c:\windows\system32\dllcache\cscript.exe
+ 2004-08-09 13:27:08 98,304 -c--a-w c:\windows\system32\dllcache\cscript.exe
+ 2004-08-09 13:27:00 28,672 -c--a-w c:\windows\system32\dllcache\dispex.dll
- 2008-05-09 10:53:39 512,000 -c----w c:\windows\system32\dllcache\jscript.dll
+ 2004-08-09 13:27:02 466,944 -c--a-w c:\windows\system32\dllcache\jscript.dll
- 2008-05-09 10:53:39 180,224 -c----w c:\windows\system32\dllcache\scrobj.dll
+ 2004-08-09 13:27:04 151,552 -c--a-w c:\windows\system32\dllcache\scrobj.dll
- 2008-05-09 10:53:40 172,032 -c----w c:\windows\system32\dllcache\scrrun.dll
+ 2004-08-09 13:27:04 151,552 -c--a-w c:\windows\system32\dllcache\scrrun.dll
- 2008-05-09 10:53:40 430,080 -c----w c:\windows\system32\dllcache\vbscript.dll
+ 2004-08-09 13:27:06 438,272 -c--a-w c:\windows\system32\dllcache\vbscript.dll
- 2008-05-08 11:24:44 155,648 -c----w c:\windows\system32\dllcache\wscript.exe
+ 2004-08-09 13:27:16 114,688 -c--a-w c:\windows\system32\dllcache\wscript.exe
+ 2004-08-09 13:27:06 28,672 -c--a-w c:\windows\system32\dllcache\wshcon.dll
- 2008-05-09 10:53:40 90,112 -c----w c:\windows\system32\dllcache\wshext.dll
+ 2004-08-09 13:27:06 65,536 -c--a-w c:\windows\system32\dllcache\wshext.dll
+ 2002-11-29 11:38:16 16,320 ----a-w c:\windows\system32\drivers\ElbyCDIO.sys
+ 2009-02-10 05:47:25 85,969 ----a-w c:\windows\system32\drivers\gmer.sys
+ 2002-11-27 21:46:55 6,400 ----a-w c:\windows\system32\drivers\RegKill.sys
+ 2002-12-03 13:54:56 65,536 ----a-w c:\windows\system32\ElbyCDIO.dll
- 2008-05-09 10:53:39 512,000 ----a-w c:\windows\system32\jscript.dll
+ 2004-08-09 13:27:02 466,944 ----a-w c:\windows\system32\jscript.dll
- 2003-04-18 08:46:22 1,233,920 ----a-w c:\windows\system32\msxml4.dll
+ 2008-09-30 08:43:34 1,286,152 ----a-w c:\windows\system32\msxml4.dll
- 2009-02-03 11:52:42 74,570 ----a-w c:\windows\system32\perfc009.dat
+ 2009-02-11 05:35:48 75,414 ----a-w c:\windows\system32\perfc009.dat
- 2009-02-03 11:52:42 453,730 ----a-w c:\windows\system32\perfh009.dat
+ 2009-02-11 05:35:48 456,634 ----a-w c:\windows\system32\perfh009.dat
- 2008-05-09 10:53:39 180,224 ----a-w c:\windows\system32\scrobj.dll
+ 2004-08-09 13:27:04 151,552 ----a-w c:\windows\system32\scrobj.dll
- 2008-05-09 10:53:40 172,032 ----a-w c:\windows\system32\scrrun.dll
+ 2004-08-09 13:27:04 151,552 ----a-w c:\windows\system32\scrrun.dll
- 2008-05-09 10:53:40 430,080 ----a-w c:\windows\system32\vbscript.dll
+ 2004-08-09 13:27:06 438,272 ----a-w c:\windows\system32\vbscript.dll
- 2008-05-08 11:24:44 155,648 ----a-w c:\windows\system32\wscript.exe
+ 2004-08-09 13:27:16 114,688 ----a-w c:\windows\system32\wscript.exe
- 2008-04-14 13:42:12 36,864 ----a-w c:\windows\system32\wshcon.dll
+ 2004-08-09 13:27:06 28,672 ----a-w c:\windows\system32\wshcon.dll
- 2008-05-09 10:53:40 90,112 ----a-w c:\windows\system32\wshext.dll
+ 2004-08-09 13:27:06 65,536 ----a-w c:\windows\system32\wshext.dll
+ 2009-02-11 06:19:46 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_c84.dat
+ 2008-09-30 08:42:08 1,286,152 ----a-w c:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9870.0_x-ww_a32d74cf\msxml4.dll
+ 2008-09-30 08:45:12 91,656 ----a-w c:\windows\WinSxS\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.1.0_x-ww_2a41bceb\msxml4r.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cdloader"="c:\documents and settings\user\Application Data\mjusbsp\cdloader2.exe" [2008-12-18 50520]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-17 1833296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-11-13 86016]
"Launch LGDCore"="c:\program files\Logitech\G-series Software\LGDCore.exe" [2006-03-06 1122304]
"Launch LCDMon"="c:\program files\Logitech\G-series Software\LCDMon.exe" [2006-03-06 497152]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2008-07-12 641208]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-04 36352]
"RemoteControl"="c:\program files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2004-11-03 32768]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2005-07-08 1397760]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-10 155648]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-09 136600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"Google IME Autoupdater"="c:\program files\Google\Google Pinyin\GooglePinyinDaemon.exe" [2008-10-17 308720]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-11-13 13672448]
"RegKillElbyCheck"="c:\program files\Elaborate Bytes\DVD Region Killer\ElbyCheck.exe" [2002-11-02 45056]
"RegKillTray"="c:\program files\Elaborate Bytes\DVD Region Killer\RegKillTray.exe" [2002-11-28 49152]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-02-08 30192]
"nwiz"="nwiz.exe" [2008-11-13 c:\windows\system32\nwiz.exe]
c:\documents and settings\user\Start Menu\Programs\Startup\
SolidWorks Task Scheduler Engine.lnk - c:\program files\SolidWorks\swScheduler\swBOEngine.exe [2007-09-09 488728]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Windows Desktop Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2007-02-05 118784]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2008-04-14 21:42 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2008-11-13 06:54 13672448 c:\windows\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
--a------ 2008-03-15 07:50 233472 c:\program files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SolidWorks_CheckForUpdates]
-ra------ 2007-09-10 14:15 6460696 c:\program files\Common Files\SolidWorks Installation Manager\Scheduler\sldIMScheduler.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\alcmtr]
--a------ 2008-06-19 16:20 57344 c:\windows\ALCMTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2008-11-13 06:54 1630208 c:\windows\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\rthdcpl]
--a------ 2008-12-30 14:58 18082304 c:\windows\RTHDCPL.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Documents and Settings\\user\\Application Data\\mjusbsp\\magicJack.exe"=
R2 mcafee siteadvisor service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2008-12-30 206096]
R3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1e51x86.sys [2008-12-28 36864]
R3 RegKill;RegKill;c:\windows\system32\drivers\RegKill.sys [2002-11-28 6400]
S2 gupdate1c989fb9fbc9a4;Google Update Service (gupdate1c989fb9fbc9a4);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-08 133104]
S3 getplus(r) helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe --> c:\program files\NOS\bin\getPlus_HelperSvc.exe [?]
S3 GoogleDesktopManager-092308-165331;Google Desktop Manager 5.8.809.23506;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2009-02-08 30192]
S3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\drivers\s0016bus.sys [2009-01-20 89256]
S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\drivers\s0016mdfl.sys [2009-01-20 15016]
S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\drivers\s0016mdm.sys [2009-01-20 120744]
.
Contents of the 'Scheduled Tasks' folder
2009-02-11 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-08 22:39]
2008-12-28 c:\windows\Tasks\McDefragTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2008-07-10 10:10]
2008-12-31 c:\windows\Tasks\McQcTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2008-07-10 10:10]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: &Winamp Search - c:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: e&xport to microsoft excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {06D3657C-3AB2-4B4B-9116-79D53A357EEF} = 168.95.192.1 168.95.1.1
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-02-11 14:20:13
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Ahead\InCD\InCDsrv.exe
c:\windows\system32\rundll32.exe
c:\program files\Logitech\G-series Software\Applets\LCDClock.exe
c:\docume~1\user\LOCALS~1\temp\SolidWorksLicTemp.0001
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\program files\Common Files\McAfee\MNA\McNASvc.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\program files\McAfee\MPF\MpfSrv.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\searchindexer.exe
c:\program files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
.
**************************************************************************
.
Completion time: 2009-02-11 14:22:41 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-11 06:22:38
ComboFix2.txt 2009-02-03 14:36:11
ComboFix3.txt 2009-02-03 14:24:45
ComboFix4.txt 2009-01-20 05:05:40
Pre-Run: 74,458,439,680 bytes free
Post-Run: 74,445,705,216 bytes free
Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4
468 --- E O F --- 2009-02-09 12:54:59
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:25:02 PM, on 2/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Logitech\G-series Software\LGDCore.exe
C:\Program Files\Logitech\G-series Software\LCDMon.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Logitech\G-series Software\Applets\LCDClock.exe
C:\Program Files\Google\Google Pinyin\GooglePinyinDaemon.exe
C:\Program Files\Elaborate Bytes\DVD Region Killer\RegKillTray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\SolidWorks\swScheduler\swBOEngine.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\DOCUME~1\user\LOCALS~1\Temp\SolidWorksLicTemp.0001
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll
O2 - BHO: JQSIEStartDetectorImpl - {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Logitech\G-series Software\LCDMon.exe"
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Google IME Autoupdater] "C:\Program Files\Google\Google Pinyin\GooglePinyinDaemon.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RegKillElbyCheck] "C:\Program Files\Elaborate Bytes\DVD Region Killer\ElbyCheck.exe" /L RegKill
O4 - HKLM\..\Run: [RegKillTray] "C:\Program Files\Elaborate Bytes\DVD Region Killer\RegKillTray.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [cdloader] "C:\Documents and Settings\user\Application Data\mjusbsp\cdloader2.exe" MAGICJACK
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: SolidWorks Task Scheduler Engine.lnk = C:\Program Files\SolidWorks\swScheduler\swBOEngine.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: e&xport to microsoft excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll
O9 - Extra 'Tools' menuitem: &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll
O9 - Extra button: Research - {92780b25-18cc-41c8-b9be-3c9c571a8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [java_sun] Java (Sun)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) -
http://www.pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1230435719625
O16 - DPF: {8ad9c840-044e-11d1-b3e9-00805f499d93} (Java Runtime Environment 1.6.0) -
http://sdlc-esd.sun.com/ESD5/JSCDL/...6u11-windows-i586-jc.cab&BHost=javadl.sun.com
O16 - DPF: {cf40acc5-e1bb-4aff-ac72-04c2f616bca7} -
O17 - HKLM\System\CCS\Services\Tcpip\..\{06D3657C-3AB2-4B4B-9116-79D53A357EEF}: NameServer = 168.95.192.1 168.95.1.1
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O23 - Service: getPlus(R) Helper (getplus(r) helper) - Unknown owner - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (file missing)
O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate1c989fb9fbc9a4) (gupdate1c989fb9fbc9a4) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (incdsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Java Quick Starter (javaquickstarterservice) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (lightscribeservice) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee SiteAdvisor Service (mcafee siteadvisor service) - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
--
End of file - 10774 bytes