Hi Blade81,
Sorry for the delay, I was away working yesterday.
Here are the logs after the latest operations (combofix and dds)
I'll now enable AVG anti-virus and firewall back up and update MS Windows update then run an AVG scan and S&D scan. I'll post the rsults here.
cgobbe
ComboFix 09-06-11.06 - BRAND 12/06/2009 11:07.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1278.873 [GMT 1:00]
Running from: c:\documents and settings\BRAND\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\BRAND\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FILE ::
"c:\windows\system32\c2d.dat"
"c:\windows\system32\ck.dat"
"c:\windows\system32\idm.dat"
"c:\windows\system32\q1.dat"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\c2d.dat
c:\windows\system32\ck.dat
c:\windows\system32\idm.dat
c:\windows\system32\q1.dat
.
((((((((((((((((((((((((( Files Created from 2009-05-12 to 2009-06-12 )))))))))))))))))))))))))))))))
.
2009-06-12 09:38 . 2009-06-07 20:27 325896 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgldx86.sys
2009-06-12 09:38 . 2009-06-07 20:27 3288856 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\setup.exe
2009-06-12 09:38 . 2009-06-07 20:26 2301208 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avguiadv.dll
2009-06-12 09:38 . 2009-06-07 20:26 3401496 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgui.exe
2009-06-12 09:38 . 2009-06-07 20:26 1217816 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgfrw.exe
2009-06-12 09:38 . 2009-06-07 20:26 1947928 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgtray.exe
2009-06-12 09:38 . 2009-06-07 20:26 1205528 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgabout.dll
2009-06-12 09:38 . 2009-06-07 20:26 681752 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgsrmx.dll
2009-06-12 09:38 . 2009-06-07 20:26 341272 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgsrmax.exe
2009-06-12 09:38 . 2009-06-07 20:26 1262880 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgwd.dll
2009-06-12 09:38 . 2009-06-07 20:26 830232 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcfgx.dll
2009-06-12 09:38 . 2009-06-07 20:26 761112 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgscanx.exe
2009-06-12 09:36 . 2009-06-07 20:26 1085208 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.exe
2009-06-12 09:36 . 2009-06-07 20:26 1439488 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.dll
2009-06-11 07:54 . 2006-08-21 12:21 16896 ------w- c:\windows\system32\dllcache\fltlib.dll
2009-06-11 07:54 . 2006-08-21 09:14 23040 ------w- c:\windows\system32\dllcache\fltmc.exe
2009-06-11 07:54 . 2006-08-21 09:14 128896 ------w- c:\windows\system32\dllcache\fltmgr.sys
2009-06-10 23:07 . 2009-06-10 23:07 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-06-10 23:07 . 2009-06-10 23:07 -------- d-----w- c:\program files\Java
2009-06-10 07:09 . 2004-08-04 07:56 50176 ----a-w- c:\windows\system32\proquota.exe
2009-06-10 07:09 . 2004-08-04 07:56 50176 ----a-w- c:\windows\system32\dllcache\proquota.exe
2009-06-10 07:09 . 2004-08-04 07:56 39424 ----a-w- c:\windows\system32\grpconv.exe
2009-06-10 07:09 . 2004-08-04 07:56 39424 ----a-w- c:\windows\system32\dllcache\grpconv.exe
2009-06-09 20:49 . 2009-06-09 23:35 -------- d-----w- c:\windows\system32\NtmsData
2009-06-09 20:48 . 2004-08-03 23:56 1200128 ----a-w- c:\windows\system32\ntbackup.exe
2009-06-09 20:44 . 2009-06-09 20:48 -------- d-----w- C:\NTBACKUP
2009-06-08 13:35 . 2009-06-08 13:35 -------- d-----w- c:\program files\Trend Micro
2009-06-08 13:33 . 2009-06-08 13:34 -------- d-----w- c:\program files\ERUNT
2009-06-08 11:50 . 2009-06-08 19:50 -------- d-----w- c:\windows\system32\CatRoot_bak
2009-06-08 11:43 . 2008-06-13 13:10 272128 ------w- c:\windows\system32\dllcache\bthport.sys
2009-06-08 11:34 . 2008-05-01 14:30 331776 ------w- c:\windows\system32\dllcache\msadce.dll
2009-06-08 11:33 . 2008-04-11 18:50 683520 ------w- c:\windows\system32\dllcache\inetcomm.dll
2009-06-08 11:32 . 2008-04-21 10:02 215552 ------w- c:\windows\system32\dllcache\wordpad.exe
2009-06-08 11:31 . 2008-10-03 10:15 247326 ------w- c:\windows\system32\dllcache\strmdll.dll
2009-06-07 20:33 . 2009-06-07 23:49 -------- d--h--w- C:\$AVG8.VAULT$
2009-06-07 20:27 . 2009-06-07 20:27 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-06-07 20:27 . 2009-06-07 20:27 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-06-07 20:27 . 2009-06-12 09:38 327688 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-07 20:27 . 2009-06-07 20:27 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-07 20:27 . 2009-06-12 09:39 -------- d-----w- c:\windows\system32\drivers\Avg
2009-06-07 20:26 . 2009-06-07 20:26 -------- d-----w- c:\program files\AVG
2009-06-07 20:26 . 2009-06-07 22:15 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-06-07 20:18 . 2009-06-07 20:18 -------- d-----w- c:\windows\system32\wbem\AutoRecover
2009-06-07 19:31 . 2004-08-03 23:56 221184 ----a-w- c:\windows\system32\wmpns.dll
2009-06-07 19:26 . 2009-06-07 19:26 -------- d-----w- c:\windows\ServicePackFiles
2009-06-07 18:50 . 2006-08-21 12:21 16896 ----a-w- c:\windows\system32\fltlib.dll
2009-06-07 18:35 . 2009-06-08 13:27 -------- dc----w- c:\windows\system32\DRVSTORE
2009-06-07 18:34 . 2009-06-08 13:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-06-07 15:08 . 2009-06-07 15:08 -------- d-----w- c:\documents and settings\All Users\Application Data\TomTom
2009-06-07 14:30 . 2004-03-30 01:48 40960 ------w- c:\windows\system32\dllcache\evtgprov.dll
2009-06-07 14:30 . 2004-08-03 23:56 614912 ----a-w- c:\windows\system32\h323msp.dll
2009-06-07 14:30 . 2004-08-03 23:56 331264 ----a-w- c:\windows\system32\ipnathlp.dll
2009-06-07 13:37 . 2003-10-02 13:17 155648 ----a-w- c:\windows\system32\igfxres.dll
2009-06-07 00:53 . 2009-06-07 19:29 -------- d-----w- c:\windows\peernet
2009-06-07 00:53 . 2009-06-07 00:53 -------- d-----w- c:\windows\provisioning
2009-06-07 00:42 . 2006-10-19 13:56 713216 ----a-w- c:\windows\system32\sxs.dll
2009-06-07 00:41 . 2009-06-07 19:20 -------- d-----w- c:\windows\EHome
2009-06-06 14:35 . 2009-06-06 15:06 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-06-06 14:35 . 2009-06-06 14:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-06 14:27 . 2004-08-03 23:56 12288 ----a-w- c:\windows\system32\mstinit.exe
2009-06-06 14:27 . 2004-08-03 23:56 190976 ----a-w- c:\windows\system32\schedsvc.dll
2009-06-06 14:27 . 2004-08-03 23:56 274944 ----a-w- c:\windows\system32\mstask.dll
2009-05-31 12:27 . 2009-05-31 12:27 42496 ----a-w- c:\windows\system32\bekbn.dll
2009-05-15 16:47 . 2009-05-15 17:02 -------- d-----w- c:\documents and settings\BRAND\Application Data\vlc
2009-05-15 16:42 . 2009-05-15 16:42 -------- d-----w- c:\program files\VideoLAN
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-10 22:59 . 2008-05-30 15:31 -------- d-----w- c:\program files\Common Files\Adobe
2009-06-10 08:01 . 2009-04-30 20:18 1 ----a-w- c:\documents and settings\BRAND\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-06-07 20:19 . 2007-07-15 10:31 29600 ----a-w- c:\documents and settings\BRAND\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-07 19:33 . 2002-09-03 08:58 78879 ----a-w- c:\windows\PCHealth\HelpCtr\OfflineCache\index.dat
2009-05-25 06:52 . 2009-05-05 19:08 -------- d-----w- c:\documents and settings\BRAND\Application Data\ErrorFix
2009-05-07 15:44 . 2009-06-07 00:42 344064 ----a-w- c:\windows\system32\localspl.dll
2009-04-30 20:17 . 2009-04-30 20:17 -------- d-----w- c:\documents and settings\BRAND\Application Data\OpenOffice.org
2009-04-30 20:14 . 2009-04-30 20:14 -------- d-----w- c:\program files\OpenOffice.org 3
2009-04-30 20:01 . 2009-04-30 20:01 -------- d-----w- c:\documents and settings\BRAND\Application Data\ImgBurn
2009-04-30 20:00 . 2004-01-15 09:28 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-04-30 20:00 . 2004-01-15 09:25 -------- d-----w- c:\program files\Dell
2009-04-30 19:58 . 2009-04-30 19:58 -------- d-----w- c:\program files\ImgBurn
2009-04-29 04:52 . 2009-06-07 00:42 659456 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:52 . 2009-06-07 19:29 81920 ------w- c:\windows\system32\ieencode.dll
2009-04-17 09:58 . 2009-06-07 00:42 1846656 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 15:11 . 2009-06-07 00:43 584192 ----a-w- c:\windows\system32\rpcrt4.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-06-10_07.13.45 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-11 06:55 . 2007-01-19 20:15 74802 c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\atl.dll
+ 2009-06-12 09:34 . 2009-06-12 09:34 16384 c:\windows\temp\Perflib_Perfdata_6d8.dat
+ 2004-01-15 09:17 . 2008-07-09 07:38 17272 c:\windows\SYSTEM32\spmsg.dll
- 2004-01-15 09:17 . 2007-11-30 11:18 17272 c:\windows\SYSTEM32\spmsg.dll
- 2009-06-07 00:43 . 2009-02-20 08:30 39424 c:\windows\SYSTEM32\pngfilt.dll
+ 2009-06-07 00:43 . 2009-04-29 04:52 39424 c:\windows\SYSTEM32\pngfilt.dll
+ 2004-01-15 09:10 . 2009-06-12 09:36 40664 c:\windows\SYSTEM32\PERFC009.DAT
- 2004-01-15 09:10 . 2009-06-08 13:27 40664 c:\windows\SYSTEM32\PERFC009.DAT
+ 2009-06-07 14:27 . 2008-03-25 04:50 60192 c:\windows\SYSTEM32\msjter40.dll
+ 2009-06-07 00:43 . 2007-03-08 15:36 40960 c:\windows\SYSTEM32\mf3216.dll
+ 2009-06-07 00:43 . 2009-04-29 04:52 16384 c:\windows\SYSTEM32\jsproxy.dll
- 2009-06-07 00:43 . 2009-02-20 08:30 16384 c:\windows\SYSTEM32\jsproxy.dll
+ 2009-06-07 00:43 . 2009-04-29 04:52 96256 c:\windows\SYSTEM32\inseng.dll
- 2009-06-07 00:43 . 2009-02-20 08:30 96256 c:\windows\SYSTEM32\inseng.dll
+ 2009-06-07 19:29 . 2006-08-21 09:14 23040 c:\windows\SYSTEM32\fltmc.exe
+ 2009-06-07 19:29 . 2009-04-29 04:52 55808 c:\windows\SYSTEM32\extmgr.dll
- 2009-06-07 19:29 . 2009-02-20 08:30 55808 c:\windows\SYSTEM32\extmgr.dll
- 2009-06-07 00:42 . 2004-08-03 22:15 82944 c:\windows\SYSTEM32\DRIVERS\wdmaud.sys
+ 2009-06-07 00:42 . 2006-06-14 09:00 82944 c:\windows\SYSTEM32\DRIVERS\wdmaud.sys
+ 2002-08-29 05:00 . 2007-11-13 10:25 20480 c:\windows\SYSTEM32\DRIVERS\secdrv.sys
- 2009-06-07 00:43 . 2004-08-03 23:56 45568 c:\windows\SYSTEM32\dnsrslvr.dll
+ 2009-06-07 00:43 . 2008-02-20 05:32 45568 c:\windows\SYSTEM32\dnsrslvr.dll
+ 2006-06-14 09:00 . 2006-06-14 09:00 82944 c:\windows\SYSTEM32\DLLCACHE\wdmaud.sys
+ 2007-05-16 15:12 . 2007-05-16 15:12 85504 c:\windows\SYSTEM32\DLLCACHE\wabimp.dll
- 2009-02-20 08:30 . 2009-02-20 08:30 39424 c:\windows\SYSTEM32\DLLCACHE\pngfilt.dll
+ 2009-02-20 08:30 . 2009-04-29 04:52 39424 c:\windows\SYSTEM32\DLLCACHE\pngfilt.dll
+ 2008-03-25 04:50 . 2008-03-25 04:50 60192 c:\windows\SYSTEM32\DLLCACHE\msjter40.dll
+ 2007-03-08 15:36 . 2007-03-08 15:36 40960 c:\windows\SYSTEM32\DLLCACHE\mf3216.dll
+ 2009-02-20 08:30 . 2009-04-29 04:52 16384 c:\windows\SYSTEM32\DLLCACHE\jsproxy.dll
- 2009-02-20 08:30 . 2009-02-20 08:30 16384 c:\windows\SYSTEM32\DLLCACHE\jsproxy.dll
+ 2009-02-20 08:30 . 2009-04-29 04:52 96256 c:\windows\SYSTEM32\DLLCACHE\inseng.dll
- 2009-02-20 08:30 . 2009-02-20 08:30 96256 c:\windows\SYSTEM32\DLLCACHE\inseng.dll
+ 2009-02-20 08:30 . 2009-04-29 04:52 81920 c:\windows\SYSTEM32\DLLCACHE\ieencode.dll
- 2009-02-20 08:30 . 2009-02-20 08:30 81920 c:\windows\SYSTEM32\DLLCACHE\ieencode.dll
+ 2009-02-19 09:58 . 2009-04-27 09:17 18432 c:\windows\SYSTEM32\DLLCACHE\iedw.exe
- 2009-02-19 09:58 . 2009-02-19 09:58 18432 c:\windows\SYSTEM32\DLLCACHE\iedw.exe
- 2009-02-20 08:30 . 2009-02-20 08:30 55808 c:\windows\SYSTEM32\DLLCACHE\extmgr.dll
+ 2009-02-20 08:30 . 2009-04-29 04:52 55808 c:\windows\SYSTEM32\DLLCACHE\extmgr.dll
+ 2008-02-20 05:32 . 2008-02-20 05:32 45568 c:\windows\SYSTEM32\DLLCACHE\dnsrslvr.dll
+ 2007-05-16 15:12 . 2007-05-16 15:12 86528 c:\windows\SYSTEM32\DLLCACHE\directdb.dll
+ 2006-10-12 14:02 . 2007-03-09 13:46 57344 c:\windows\SYSTEM32\DLLCACHE\agentdpv.dll
+ 2006-10-12 14:02 . 2006-10-12 14:02 42496 c:\windows\SYSTEM32\DLLCACHE\agentdp2.dll
- 2005-04-22 05:20 . 2005-04-22 05:06 57344 c:\windows\MSAGENT\agentdpv.dll
+ 2005-04-22 05:20 . 2007-03-09 13:46 57344 c:\windows\MSAGENT\agentdpv.dll
+ 2009-06-07 00:44 . 2006-10-12 14:02 42496 c:\windows\MSAGENT\agentdp2.dll
+ 2006-06-14 09:00 . 2006-06-14 09:00 82944 c:\windows\Driver Cache\I386\wdmaud.sys
- 2009-06-07 00:42 . 2004-08-03 22:07 6400 c:\windows\SYSTEM32\DRIVERS\splitter.sys
+ 2009-06-07 00:42 . 2006-06-14 08:47 6400 c:\windows\SYSTEM32\DRIVERS\splitter.sys
+ 2006-06-14 08:47 . 2006-06-14 08:47 6400 c:\windows\SYSTEM32\DLLCACHE\splitter.sys
+ 2006-06-14 08:47 . 2006-06-14 08:47 6400 c:\windows\Driver Cache\I386\splitter.sys
+ 2009-06-11 06:55 . 2007-01-19 20:15 401462 c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\msvcp60.dll
+ 2009-06-11 06:55 . 2007-01-19 20:15 995383 c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42.dll
- 2005-05-17 00:43 . 2009-02-19 09:47 351744 c:\windows\SYSTEM32\xpsp3res.dll
+ 2005-05-17 00:43 . 2009-04-27 09:18 351744 c:\windows\SYSTEM32\xpsp3res.dll
+ 2009-06-07 00:42 . 2007-10-27 16:39 230912 c:\windows\SYSTEM32\wmasf.dll
+ 2009-06-07 00:42 . 2006-08-17 12:28 132096 c:\windows\SYSTEM32\wkssvc.dll
- 2009-06-07 00:42 . 2004-08-03 23:56 132096 c:\windows\SYSTEM32\wkssvc.dll
+ 2009-06-07 00:42 . 2007-03-17 13:43 292864 c:\windows\SYSTEM32\winsrv.dll
+ 2009-06-07 00:42 . 2006-12-19 18:16 333824 c:\windows\SYSTEM32\wiaservc.dll
+ 2009-06-07 00:42 . 2007-03-08 15:36 577536 c:\windows\SYSTEM32\user32.dll
+ 2009-06-07 00:42 . 2009-04-29 04:52 616448 c:\windows\SYSTEM32\urlmon.dll
- 2009-06-07 00:42 . 2009-02-20 08:30 616448 c:\windows\SYSTEM32\urlmon.dll
+ 2009-06-07 00:42 . 2007-02-05 20:17 185344 c:\windows\SYSTEM32\upnphost.dll
- 2009-06-07 00:42 . 2004-08-03 23:56 185344 c:\windows\SYSTEM32\upnphost.dll
+ 2009-06-07 00:43 . 2006-12-19 21:52 134656 c:\windows\SYSTEM32\shsvcs.dll
- 2009-06-07 00:43 . 2004-08-03 23:56 134656 c:\windows\SYSTEM32\shsvcs.dll
- 2009-06-07 00:43 . 2009-02-20 08:30 474112 c:\windows\SYSTEM32\shlwapi.dll
+ 2009-06-07 00:43 . 2009-04-29 04:52 474112 c:\windows\SYSTEM32\shlwapi.dll
+ 2009-06-07 00:43 . 2006-11-27 14:54 433152 c:\windows\SYSTEM32\riched20.dll
- 2004-01-15 09:10 . 2009-06-08 13:27 312946 c:\windows\SYSTEM32\PERFH009.DAT
+ 2004-01-15 09:10 . 2009-06-12 09:36 312946 c:\windows\SYSTEM32\PERFH009.DAT
+ 2002-08-29 05:00 . 2006-10-16 16:15 122880 c:\windows\SYSTEM32\oledlg.dll
+ 2009-06-07 00:42 . 2007-12-04 18:38 550912 c:\windows\SYSTEM32\oleaut32.dll
+ 2009-06-07 00:42 . 2006-10-13 12:35 142336 c:\windows\SYSTEM32\nwprovau.dll
+ 2009-06-07 14:27 . 2008-03-25 04:50 355104 c:\windows\SYSTEM32\msxbde40.dll
+ 2009-06-07 14:27 . 2008-03-25 04:50 621344 c:\windows\SYSTEM32\mswstr10.dll
+ 2009-06-07 14:27 . 2008-03-25 04:50 838432 c:\windows\SYSTEM32\mswdat10.dll
+ 2009-06-07 00:43 . 2009-04-29 04:52 532480 c:\windows\SYSTEM32\mstime.dll
- 2009-06-07 00:43 . 2009-02-20 08:30 532480 c:\windows\SYSTEM32\mstime.dll
+ 2009-06-07 14:27 . 2008-03-25 04:50 264992 c:\windows\SYSTEM32\mstext40.dll
+ 2009-06-07 14:27 . 2008-03-25 04:50 559904 c:\windows\SYSTEM32\msrepl40.dll
+ 2009-06-07 14:27 . 2008-03-25 04:50 322336 c:\windows\SYSTEM32\msrd3x40.dll
+ 2009-06-07 14:27 . 2008-03-25 04:50 432928 c:\windows\SYSTEM32\msrd2x40.dll
- 2009-06-07 00:43 . 2009-02-20 08:30 146432 c:\windows\SYSTEM32\msrating.dll
+ 2009-06-07 00:43 . 2009-04-29 04:52 146432 c:\windows\SYSTEM32\msrating.dll
+ 2009-06-07 14:27 . 2008-03-25 04:50 355104 c:\windows\SYSTEM32\mspbde40.dll
+ 2009-06-07 14:27 . 2008-03-25 04:50 219936 c:\windows\SYSTEM32\msltus40.dll
+ 2009-06-07 14:27 . 2008-03-25 04:50 248608 c:\windows\SYSTEM32\msjtes40.dll
- 2009-06-07 14:27 . 2004-08-03 23:56 151583 c:\windows\SYSTEM32\msjint40.dll
+ 2009-06-07 14:27 . 2008-03-27 08:12 151583 c:\windows\SYSTEM32\msjint40.dll
+ 2009-06-07 14:27 . 2008-03-25 04:50 355112 c:\windows\SYSTEM32\msjetoledb40.dll
+ 2009-06-07 00:43 . 2009-04-29 04:52 449024 c:\windows\SYSTEM32\mshtmled.dll
- 2009-06-07 00:43 . 2009-02-20 08:30 449024 c:\windows\SYSTEM32\mshtmled.dll
+ 2009-06-07 00:44 . 2006-11-27 14:54 539136 c:\windows\SYSTEM32\msftedit.dll
+ 2009-06-07 14:27 . 2008-03-25 04:50 326432 c:\windows\SYSTEM32\msexcl40.dll
+ 2009-06-07 14:27 . 2008-03-25 04:50 518944 c:\windows\SYSTEM32\msexch40.dll
+ 2009-06-07 00:43 . 2006-10-14 08:13 981760 c:\windows\SYSTEM32\mfc42u.dll
+ 2002-08-29 05:00 . 2006-11-01 19:17 927504 c:\windows\SYSTEM32\mfc40u.dll
+ 2009-06-10 23:07 . 2009-06-10 23:07 148888 c:\windows\SYSTEM32\javaws.exe
+ 2009-06-10 23:07 . 2009-06-10 23:07 144792 c:\windows\SYSTEM32\javaw.exe
+ 2009-06-10 23:07 . 2009-06-10 23:07 144792 c:\windows\SYSTEM32\java.exe
- 2009-06-07 00:43 . 2009-02-20 08:30 251392 c:\windows\SYSTEM32\iepeers.dll
+ 2009-06-07 00:43 . 2009-04-29 04:52 251392 c:\windows\SYSTEM32\iepeers.dll
- 2002-09-03 09:05 . 2009-06-08 13:22 144424 c:\windows\SYSTEM32\FNTCACHE.DAT
+ 2002-09-03 09:05 . 2009-06-12 09:33 144424 c:\windows\SYSTEM32\FNTCACHE.DAT
- 2009-06-07 00:43 . 2009-02-20 08:30 205312 c:\windows\SYSTEM32\dxtrans.dll
+ 2009-06-07 00:43 . 2009-04-29 04:52 205312 c:\windows\SYSTEM32\dxtrans.dll
- 2009-06-07 00:43 . 2009-02-20 08:30 357888 c:\windows\SYSTEM32\dxtmsft.dll
+ 2009-06-07 00:43 . 2009-04-29 04:52 357888 c:\windows\SYSTEM32\dxtmsft.dll
+ 2009-06-07 00:43 . 2006-08-22 03:05 498742 c:\windows\SYSTEM32\dxmasf.dll
+ 2009-06-07 00:42 . 2007-04-23 10:32 364160 c:\windows\SYSTEM32\DRIVERS\update.sys
+ 2009-06-07 00:42 . 2007-02-09 11:10 574464 c:\windows\SYSTEM32\DRIVERS\ntfs.sys
+ 2009-06-07 00:42 . 2007-12-18 09:51 179584 c:\windows\SYSTEM32\DRIVERS\mrxdav.sys
+ 2009-06-07 00:42 . 2006-06-14 08:47 172416 c:\windows\SYSTEM32\DRIVERS\kmixer.sys
- 2009-06-07 00:42 . 2004-08-03 22:04 134912 c:\windows\SYSTEM32\DRIVERS\ipnat.sys
+ 2009-06-07 00:42 . 2004-09-29 22:28 134912 c:\windows\SYSTEM32\DRIVERS\ipnat.sys
+ 2009-06-07 19:29 . 2006-03-17 00:33 262784 c:\windows\SYSTEM32\DRIVERS\http.sys
+ 2009-06-07 19:29 . 2006-08-21 09:14 128896 c:\windows\SYSTEM32\DRIVERS\fltmgr.sys
- 2009-06-07 00:42 . 2004-08-03 21:39 142464 c:\windows\SYSTEM32\DRIVERS\aec.sys
+ 2009-06-07 00:42 . 2006-02-15 00:22 142464 c:\windows\SYSTEM32\DRIVERS\aec.sys
+ 2007-10-27 16:39 . 2007-10-27 16:39 230912 c:\windows\SYSTEM32\DLLCACHE\wmasf.dll
+ 2006-08-17 12:28 . 2006-08-17 12:28 132096 c:\windows\SYSTEM32\DLLCACHE\wkssvc.dll
+ 2007-03-17 13:43 . 2007-03-17 13:43 292864 c:\windows\SYSTEM32\DLLCACHE\winsrv.dll
+ 2009-02-20 08:30 . 2009-04-29 04:52 659456 c:\windows\SYSTEM32\DLLCACHE\wininet.dll
- 2009-02-20 08:30 . 2009-02-20 08:30 659456 c:\windows\SYSTEM32\DLLCACHE\wininet.dll
+ 2006-12-19 18:16 . 2006-12-19 18:16 333824 c:\windows\SYSTEM32\DLLCACHE\wiaservc.dll
+ 2007-05-16 15:12 . 2007-05-16 15:12 510976 c:\windows\SYSTEM32\DLLCACHE\wab32.dll
+ 2007-06-26 15:13 . 2007-06-26 15:13 851968 c:\windows\SYSTEM32\DLLCACHE\vgx.dll
+ 2007-03-08 15:36 . 2007-03-08 15:36 577536 c:\windows\SYSTEM32\DLLCACHE\user32.dll
+ 2009-02-20 08:30 . 2009-04-29 04:52 616448 c:\windows\SYSTEM32\DLLCACHE\urlmon.dll
- 2009-02-20 08:30 . 2009-02-20 08:30 616448 c:\windows\SYSTEM32\DLLCACHE\urlmon.dll
+ 2007-02-05 20:17 . 2007-02-05 20:17 185344 c:\windows\SYSTEM32\DLLCACHE\upnphost.dll
+ 2007-04-23 10:32 . 2007-04-23 10:32 364160 c:\windows\SYSTEM32\DLLCACHE\update.sys
+ 2006-10-19 13:56 . 2006-10-19 13:56 713216 c:\windows\SYSTEM32\DLLCACHE\sxs.dll
+ 2006-12-19 21:52 . 2006-12-19 21:52 134656 c:\windows\SYSTEM32\DLLCACHE\shsvcs.dll
+ 2009-02-20 08:30 . 2009-04-29 04:52 474112 c:\windows\SYSTEM32\DLLCACHE\shlwapi.dll
- 2009-02-20 08:30 . 2009-02-20 08:30 474112 c:\windows\SYSTEM32\DLLCACHE\shlwapi.dll
+ 2009-04-15 15:11 . 2009-04-15 15:11 584192 c:\windows\SYSTEM32\DLLCACHE\rpcrt4.dll
+ 2006-11-27 14:54 . 2006-11-27 14:54 433152 c:\windows\SYSTEM32\DLLCACHE\riched20.dll
+ 2006-10-16 16:15 . 2006-10-16 16:15 122880 c:\windows\SYSTEM32\DLLCACHE\oledlg.dll
+ 2007-12-04 18:38 . 2007-12-04 18:38 550912 c:\windows\SYSTEM32\DLLCACHE\oleaut32.dll
+ 2006-10-13 12:35 . 2006-10-13 12:35 142336 c:\windows\SYSTEM32\DLLCACHE\nwprovau.dll
+ 2007-02-09 11:10 . 2007-02-09 11:10 574464 c:\windows\SYSTEM32\DLLCACHE\ntfs.sys
+ 2008-03-25 04:50 . 2008-03-25 04:50 355104 c:\windows\SYSTEM32\DLLCACHE\msxbde40.dll
+ 2008-03-25 04:50 . 2008-03-25 04:50 621344 c:\windows\SYSTEM32\DLLCACHE\mswstr10.dll
+ 2008-03-25 04:50 . 2008-03-25 04:50 838432 c:\windows\SYSTEM32\DLLCACHE\mswdat10.dll
- 2009-02-20 08:30 . 2009-02-20 08:30 532480 c:\windows\SYSTEM32\DLLCACHE\mstime.dll
+ 2009-02-20 08:30 . 2009-04-29 04:52 532480 c:\windows\SYSTEM32\DLLCACHE\mstime.dll
+ 2008-03-25 04:50 . 2008-03-25 04:50 264992 c:\windows\SYSTEM32\DLLCACHE\mstext40.dll
+ 2008-03-25 04:50 . 2008-03-25 04:50 559904 c:\windows\SYSTEM32\DLLCACHE\msrepl40.dll
+ 2008-03-25 04:50 . 2008-03-25 04:50 322336 c:\windows\SYSTEM32\DLLCACHE\msrd3x40.dll
+ 2008-03-25 04:50 . 2008-03-25 04:50 432928 c:\windows\SYSTEM32\DLLCACHE\msrd2x40.dll
+ 2009-02-20 08:30 . 2009-04-29 04:52 146432 c:\windows\SYSTEM32\DLLCACHE\msrating.dll
- 2009-02-20 08:30 . 2009-02-20 08:30 146432 c:\windows\SYSTEM32\DLLCACHE\msrating.dll
+ 2008-03-25 04:50 . 2008-03-25 04:50 355104 c:\windows\SYSTEM32\DLLCACHE\mspbde40.dll
+ 2008-03-25 04:50 . 2008-03-25 04:50 219936 c:\windows\SYSTEM32\DLLCACHE\msltus40.dll
+ 2008-03-25 04:50 . 2008-03-25 04:50 248608 c:\windows\SYSTEM32\DLLCACHE\msjtes40.dll
+ 2006-12-26 13:07 . 2006-12-26 13:07 102400 c:\windows\SYSTEM32\DLLCACHE\msjro.dll
+ 2008-03-27 08:12 . 2008-03-27 08:12 151583 c:\windows\SYSTEM32\DLLCACHE\msjint40.dll
+ 2009-06-07 14:27 . 2008-03-25 04:50 355112 c:\windows\SYSTEM32\DLLCACHE\msjetol1.dll
+ 2009-02-20 08:30 . 2009-04-29 04:52 449024 c:\windows\SYSTEM32\DLLCACHE\mshtmled.dll
- 2009-02-20 08:30 . 2009-02-20 08:30 449024 c:\windows\SYSTEM32\DLLCACHE\mshtmled.dll
+ 2006-11-27 14:54 . 2006-11-27 14:54 539136 c:\windows\SYSTEM32\DLLCACHE\msftedit.dll
+ 2008-03-25 04:50 . 2008-03-25 04:50 326432 c:\windows\SYSTEM32\DLLCACHE\msexcl40.dll
+ 2008-03-25 04:50 . 2008-03-25 04:50 518944 c:\windows\SYSTEM32\DLLCACHE\msexch40.dll
+ 2006-12-26 13:07 . 2006-12-26 13:07 200704 c:\windows\SYSTEM32\DLLCACHE\msadox.dll
+ 2006-12-26 13:07 . 2006-12-26 13:07 180224 c:\windows\SYSTEM32\DLLCACHE\msadomd.dll
+ 2006-12-26 13:07 . 2006-12-26 13:07 536576 c:\windows\SYSTEM32\DLLCACHE\msado15.dll
+ 2007-12-18 09:51 . 2007-12-18 09:51 179584 c:\windows\SYSTEM32\DLLCACHE\mrxdav.sys
+ 2006-10-14 08:13 . 2006-10-14 08:13 981760 c:\windows\SYSTEM32\DLLCACHE\mfc42u.dll
+ 2006-11-01 19:17 . 2006-11-01 19:17 927504 c:\windows\SYSTEM32\DLLCACHE\mfc40u.dll
+ 2009-05-07 15:44 . 2009-05-07 15:44 344064 c:\windows\SYSTEM32\DLLCACHE\localspl.dll
+ 2006-06-14 08:47 . 2006-06-14 08:47 172416 c:\windows\SYSTEM32\DLLCACHE\kmixer.sys
- 2009-02-20 08:30 . 2009-02-20 08:30 251392 c:\windows\SYSTEM32\DLLCACHE\iepeers.dll
+ 2009-02-20 08:30 . 2009-04-29 04:52 251392 c:\windows\SYSTEM32\DLLCACHE\iepeers.dll
+ 2009-02-20 08:30 . 2009-04-29 04:52 205312 c:\windows\SYSTEM32\DLLCACHE\dxtrans.dll
- 2009-02-20 08:30 . 2009-02-20 08:30 205312 c:\windows\SYSTEM32\DLLCACHE\dxtrans.dll
+ 2009-02-20 08:30 . 2009-04-29 04:52 357888 c:\windows\SYSTEM32\DLLCACHE\dxtmsft.dll
- 2009-02-20 08:30 . 2009-02-20 08:30 357888 c:\windows\SYSTEM32\DLLCACHE\dxtmsft.dll
+ 2006-08-22 03:05 . 2006-08-22 03:05 498742 c:\windows\SYSTEM32\DLLCACHE\dxmasf.dll
+ 2008-03-25 04:50 . 2008-03-25 04:50 554008 c:\windows\SYSTEM32\DLLCACHE\dao360.dll
+ 2009-02-20 08:30 . 2009-04-29 04:52 151040 c:\windows\SYSTEM32\DLLCACHE\cdfview.dll
- 2009-02-20 08:30 . 2009-02-20 08:30 151040 c:\windows\SYSTEM32\DLLCACHE\cdfview.dll
+ 2006-10-12 11:09 . 2006-10-12 11:09 256512 c:\windows\SYSTEM32\DLLCACHE\agentsvr.exe
+ 2009-06-07 00:43 . 2009-04-29 04:52 151040 c:\windows\SYSTEM32\cdfview.dll
- 2009-06-07 00:43 . 2009-02-20 08:30 151040 c:\windows\SYSTEM32\cdfview.dll
- 2009-06-07 00:44 . 2004-08-03 23:56 256512 c:\windows\MSAGENT\agentsvr.exe
+ 2009-06-07 00:44 . 2006-10-12 11:09 256512 c:\windows\MSAGENT\agentsvr.exe
+ 2009-06-12 09:35 . 2009-06-12 09:35 163840 c:\windows\ERDNT\AutoBackup\12-06-2009\Users\
00000002\UsrClass.dat
+ 2009-06-12 09:35 . 2005-10-20 11:02 163328 c:\windows\ERDNT\AutoBackup\12-06-2009\ERDNT.EXE
+ 2009-06-10 23:01 . 2009-06-10 23:01 151552 c:\windows\ERDNT\AutoBackup\11-06-2009\Users\
00000002\UsrClass.dat
+ 2009-06-10 23:01 . 2005-10-20 11:02 163328 c:\windows\ERDNT\AutoBackup\11-06-2009\ERDNT.EXE
+ 2006-06-14 08:47 . 2006-06-14 08:47 172416 c:\windows\Driver Cache\I386\kmixer.sys
+ 2006-03-17 00:33 . 2006-03-17 00:33 262784 c:\windows\Driver Cache\I386\http.sys
+ 2006-02-15 00:22 . 2006-02-15 00:22 142464 c:\windows\Driver Cache\I386\aec.sys
+ 2009-06-11 06:55 . 2007-01-19 20:15 1011774 c:\windows\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.9792.0_x-ww_08a6620a\mfc42u.dll
+ 2009-06-07 00:42 . 2007-10-27 16:37 2109440 c:\windows\SYSTEM32\wmvcore.dll
- 2009-06-07 00:42 . 2008-11-07 17:32 2109440 c:\windows\SYSTEM32\WMVCore.dll
+ 2009-06-07 19:29 . 2007-04-30 01:22 4734976 c:\windows\SYSTEM32\wmp.dll
+ 2009-06-07 00:43 . 2009-04-29 04:52 1495552 c:\windows\SYSTEM32\shdocvw.dll
- 2009-06-07 00:43 . 2009-03-02 23:52 1495552 c:\windows\SYSTEM32\shdocvw.dll
+ 2009-06-07 14:27 . 2008-03-25 04:50 1516568 c:\windows\SYSTEM32\msjet40.dll
+ 2002-08-29 05:00 . 2007-04-18 16:12 2854400 c:\windows\SYSTEM32\msi.dll
+ 2009-06-07 00:43 . 2009-04-29 04:52 3060736 c:\windows\SYSTEM32\mshtml.dll
- 2008-11-07 17:32 . 2008-11-07 17:32 2109440 c:\windows\SYSTEM32\DLLCACHE\WMVCore.dll
+ 2008-11-07 17:32 . 2007-10-27 16:37 2109440 c:\windows\SYSTEM32\DLLCACHE\wmvcore.dll
+ 2009-02-09 10:19 . 2009-04-17 09:58 1846656 c:\windows\SYSTEM32\DLLCACHE\win32k.sys
- 2006-09-04 06:08 . 2009-03-02 23:52 1495552 c:\windows\SYSTEM32\DLLCACHE\shdocvw.dll
+ 2006-09-04 06:08 . 2009-04-29 04:52 1495552 c:\windows\SYSTEM32\DLLCACHE\shdocvw.dll
+ 2007-05-16 15:12 . 2007-05-16 15:12 1314816 c:\windows\SYSTEM32\DLLCACHE\msoe.dll
+ 2008-03-25 04:50 . 2008-03-25 04:50 1516568 c:\windows\SYSTEM32\DLLCACHE\msjet40.dll
+ 2009-02-20 08:30 . 2009-04-29 04:52 3060736 c:\windows\SYSTEM32\DLLCACHE\mshtml.dll
+ 2007-06-13 10:23 . 2007-06-13 10:23 1033216 c:\windows\SYSTEM32\DLLCACHE\explorer.exe
+ 2009-02-20 08:30 . 2009-04-29 04:52 1054208 c:\windows\SYSTEM32\DLLCACHE\danim.dll
- 2009-02-20 08:30 . 2009-02-20 08:30 1054208 c:\windows\SYSTEM32\DLLCACHE\danim.dll
- 2009-02-20 08:30 . 2009-02-20 08:30 1023488 c:\windows\SYSTEM32\DLLCACHE\browseui.dll
+ 2009-02-20 08:30 . 2009-04-29 04:52 1023488 c:\windows\SYSTEM32\DLLCACHE\browseui.dll
- 2002-08-29 05:00 . 2009-02-20 08:30 1054208 c:\windows\SYSTEM32\danim.dll
+ 2002-08-29 05:00 . 2009-04-29 04:52 1054208 c:\windows\SYSTEM32\danim.dll
+ 2009-06-07 00:43 . 2009-04-29 04:52 1023488 c:\windows\SYSTEM32\browseui.dll
- 2009-06-07 00:43 . 2009-02-20 08:30 1023488 c:\windows\SYSTEM32\browseui.dll
+ 2009-06-07 00:44 . 2007-06-13 10:23 1033216 c:\windows\explorer.exe
+ 2009-06-12 09:35 . 2009-06-12 09:35 6021120 c:\windows\ERDNT\AutoBackup\12-06-2009\Users\
00000001\NTUSER.DAT
+ 2009-06-10 23:01 . 2009-06-10 23:01 6037504 c:\windows\ERDNT\AutoBackup\11-06-2009\Users\
00000001\NTUSER.DAT
+ 2009-06-03 05:50 . 2009-06-01 16:51 23635392 c:\windows\SYSTEM32\MRT.exe
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{10C0B0C0-FC01-473b-8EBB-4376353F96E4}]
2009-05-31 12:27 42496 ----a-w- c:\windows\SYSTEM32\bekbn.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-06 39408]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"dcom"="bekbn.dll" - c:\windows\SYSTEM32\bekbn.dll [2009-05-31 42496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2003-10-02 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2003-10-02 118784]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2003-08-06 114741]
"StorageGuard"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-02-13 155648]
"DVDSentry"="c:\windows\System32\DSentry.exe" [2003-08-13 28672]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2004-01-15 26112]
"Dell AIO Printer A920"="c:\program files\Dell AIO Printer A920\dlbkbmgr.exe" [2003-06-02 270336]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-12 1948440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-10 148888]
"BCMSMMSG"="BCMSMMSG.exe" - c:\windows\BCMSMMSG.exe [2003-08-29 122880]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\BRAND\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-06-07 20:27 11952 ----a-w- c:\windows\SYSTEM32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [07/06/2009 21:27 327688]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [07/06/2009 21:27 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [07/06/2009 21:26 908568]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [07/06/2009 21:26 298776]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{AC018590-FBBD-4789-A15B-FFBBBE6C8965}]
rundll32 bekbn.dll,InitO
.
Contents of the 'Scheduled Tasks' folder
2007-07-09 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\System32\OOBE\OOBEBALN.EXE [2009-06-07 23:56]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.tiscali.co.uk/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mStart Page = hxxp://www.euro.dell.com/countries/uk/enu/gen/default.htm
uInternet Settings,ProxyOverride = <local>
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-06-12 11:10
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-06-12 11:12
ComboFix-quarantined-files.txt 2009-06-12 10:12
ComboFix2.txt 2009-06-10 22:51
ComboFix3.txt 2009-06-10 07:20
Pre-Run: 27,245,473,792 bytes free
Post-Run: 27,305,054,208 bytes free
411 --- E O F --- 2009-06-11 07:59
DDS (Ver_09-05-14.01) - NTFSx86
Run by BRAND at 11:16:15.37 on 12/06/2009
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1278.837 [GMT 1:00]
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\explorer.exe
E:\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.tiscali.co.uk/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mStart Page = hxxp://www.euro.dell.com/countries/uk/enu/gen/default.htm
uInternet Settings,ProxyOverride = <local>
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: MSN helper: {10c0b0c0-fc01-473b-8ebb-4376353f96e4} - bekbn.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [BCMSMMSG] BCMSMMSG.exe
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [StorageGuard] "c:\program files\common files\sonic\update manager\sgtray.exe" /r
mRun: [DVDSentry] c:\windows\system32\DSentry.exe
mRun: [RealTray] c:\program files\real\realplayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
mRun: [Dell AIO Printer A920] "c:\program files\dell aio printer a920\dlbkbmgr.exe"
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\brand\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
uPolicies-system: DisableTaskMgr = 1 (0x1)
uPolicies-system: DisableRegistryTools = 1 (0x1)
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxsrvc.dll
============= SERVICES / DRIVERS ===============
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-6-7 327688]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-6-7 27784]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-6-7 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-6-7 908568]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-6-7 298776]
=============== Created Last 30 ================
2009-06-12 10:39 <DIR> --ds---- C:\ComboFix
2009-06-11 00:07 410,984 a------- c:\windows\system32\deploytk.dll
2009-06-11 00:07 73,728 a------- c:\windows\system32\javacpl.cpl
2009-06-10 23:47 <DIR> a-dshr-- C:\cmdcons
2009-06-10 08:09 50,176 a------- c:\windows\system32\proquota.exe
2009-06-10 08:09 50,176 a------- c:\windows\system32\dllcache\proquota.exe
2009-06-10 08:09 39,424 a------- c:\windows\system32\grpconv.exe
2009-06-10 08:09 39,424 a------- c:\windows\system32\dllcache\grpconv.exe
2009-06-10 08:04 161,792 a------- c:\windows\SWREG.exe
2009-06-10 08:04 155,136 a------- c:\windows\PEV.exe
2009-06-10 08:04 98,816 a------- c:\windows\sed.exe
2009-06-09 21:49 <DIR> --d----- c:\windows\system32\NtmsData
2009-06-09 21:48 1,200,128 a------- c:\windows\system32\ntbackup.exe
2009-06-09 21:44 <DIR> --d----- C:\NTBACKUP
2009-06-08 14:35 <DIR> --d----- c:\program files\Trend Micro
2009-06-08 12:50 <DIR> --d----- c:\windows\system32\CatRoot_bak
2009-06-08 12:43 272,128 -------- c:\windows\system32\dllcache\bthport.sys
2009-06-08 12:34 331,776 -------- c:\windows\system32\dllcache\msadce.dll
2009-06-08 12:33 683,520 -------- c:\windows\system32\dllcache\inetcomm.dll
2009-06-08 12:32 1,193,414 -------- c:\windows\system32\dllcache\sysmain.sdb
2009-06-08 12:32 215,552 -------- c:\windows\system32\dllcache\wordpad.exe
2009-06-08 12:31 247,326 -------- c:\windows\system32\dllcache\strmdll.dll
2009-06-07 22:16 250,032 -------- C:\ntldr
2009-06-07 21:33 <DIR> --d-h--- C:\$AVG8.VAULT$
2009-06-07 21:27 108,552 a------- c:\windows\system32\drivers\avgtdix.sys
2009-06-07 21:27 11,952 a------- c:\windows\system32\avgrsstx.dll
2009-06-07 21:27 327,688 a------- c:\windows\system32\drivers\avgldx86.sys
2009-06-07 21:27 <DIR> --d----- c:\windows\system32\drivers\Avg
2009-06-07 21:26 <DIR> --d----- c:\program files\AVG
2009-06-07 21:26 <DIR> --d----- c:\docume~1\alluse~1\applic~1\avg8
2009-06-07 21:18 <DIR> --d----- c:\windows\system32\wbem\AutoRecover
2009-06-07 20:31 221,184 a------- c:\windows\system32\wmpns.dll
2009-06-07 20:31 316,640 a------- c:\windows\WMSysPr9.prx
2009-06-07 20:26 <DIR> --d----- c:\windows\ServicePackFiles
2009-06-07 20:23 19,528 a------- c:\windows\002288_.tmp
2009-06-07 19:50 16,896 a------- c:\windows\system32\fltlib.dll
2009-06-07 16:08 <DIR> --d----- c:\docume~1\alluse~1\applic~1\TomTom
2009-06-07 15:30 40,960 -------- c:\windows\system32\dllcache\evtgprov.dll
2009-06-07 15:30 614,912 a------- c:\windows\system32\h323msp.dll
2009-06-07 15:30 331,264 a------- c:\windows\system32\ipnathlp.dll
2009-06-07 15:30 265,728 a------- c:\windows\system32\h323.tsp
2009-06-07 14:37 155,648 a------- c:\windows\system32\igfxres.dll
2009-06-07 01:53 <DIR> --d----- c:\windows\peernet
2009-06-07 01:53 <DIR> --d----- c:\windows\provisioning
2009-06-07 01:45 19,528 a------- c:\windows\002247_.tmp
2009-06-07 01:42 858,624 a------- c:\windows\system32\tapi3.dll
2009-06-07 01:41 <DIR> --d----- c:\windows\EHome
2009-06-06 15:35 <DIR> --d----- c:\program files\Spybot - Search & Destroy
2009-06-06 15:35 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-06-06 15:27 274,944 a------- c:\windows\system32\mstask.dll
2009-06-06 15:27 190,976 a------- c:\windows\system32\schedsvc.dll
2009-06-06 15:27 12,288 a------- c:\windows\system32\mstinit.exe
2009-06-03 06:51 118 a------- c:\windows\system32\MRT.INI
2009-05-31 13:27 42,496 a------- c:\windows\system32\bekbn.dll
2009-05-31 13:27 16,164 a------- c:\windows\system32\fkas
2009-05-15 17:42 <DIR> --d----- c:\program files\VideoLAN
==================== Find3M ====================
2009-06-07 20:33 78,879 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-05-07 16:44 344,064 a------- c:\windows\system32\localspl.dll
2009-05-07 16:44 344,064 -------- c:\windows\system32\dllcache\localspl.dll
2009-04-27 10:17 18,432 -------- c:\windows\system32\dllcache\iedw.exe
2009-04-17 10:58 1,846,656 a------- c:\windows\system32\win32k.sys
2009-04-17 10:58 1,846,656 -------- c:\windows\system32\dllcache\win32k.sys
2009-04-15 16:11 584,192 a------- c:\windows\system32\rpcrt4.dll
2009-04-15 16:11 584,192 -------- c:\windows\system32\dllcache\rpcrt4.dll
2009-03-21 15:18 986,112 -------- c:\windows\system32\dllcache\kernel32.dll
============= FINISH: 11:16:33.29 ===============