Logging Logs
Here's the list of what I did (again), but with their respective logs (post 1/2)
Ran ComboFix
ComboFix 09-04-29.03 - madPC Apr-09 Thu 23:19.1 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.1.1033.18.2037.1167 [GMT 9.5:30]
Running from: c:\users\madPC\Desktop\ComboFix.exe
AV: Symantec AntiVirus *On-access scanning enabled* (Updated)
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programdata\Microsoft\Network\Downloader\qmgr0.dat
c:\programdata\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\drivers\ovfsthnwawaalkwgxjdtxdrfddfrwlrlxassxn.sys
c:\windows\system32\ovfsthdfjbolsnmxnpmxgoctleouxrwxxmregx.dll
c:\windows\system32\ovfsthpnoujbtpidpaolpodhreuhfxieneiubh.dat
c:\windows\system32\ovfsthqwbluljsxjdmearguumufmykqctxbbem.dat
----- BITS: Possible infected sites -----
hxxp://globalstats.net
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_ovfsthpxajutfymxxiilmgqiipvmspngcojhie
((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-4-30 )))))))))))))))))))))))))))))))
.
2009-04-30 09:59 . 2009-04-30 09:59 -------- d-----w c:\users\Administrator\DoctorWeb
2009-04-30 09:53 . 2009-04-30 09:53 -------- d-----w c:\users\madPC\DoctorWeb
2009-04-29 16:42 . 2009-04-29 16:42 -------- d-----w c:\users\Administrator\AppData\Local\Symantec
2009-04-29 16:41 . 2009-04-29 16:41 109744 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-04-29 16:40 . 2009-04-29 16:41 -------- d-----w c:\program files\Symantec
2009-04-29 16:40 . 2009-04-29 16:42 -------- d-----w c:\progra~2\Symantec
2009-04-29 16:40 . 2009-04-29 16:42 -------- d-----w c:\users\All Users\Symantec
2009-04-29 16:40 . 2009-04-29 16:41 -------- d-----w c:\program files\Common Files\Symantec Shared
2009-04-29 16:40 . 2009-04-29 16:40 -------- d-----w c:\program files\Symantec AntiVirus
2009-04-28 20:04 . 2009-04-28 20:04 -------- d-sh--w c:\windows\system32\%APPDATA%
2009-04-28 12:31 . 2009-04-28 12:31 -------- d-----w c:\program files\CCleaner
2009-04-28 12:17 . 2009-04-28 12:21 -------- dcsh--w c:\program files\Common Files\WindowsLiveInstaller
2009-04-28 12:17 . 2009-04-28 12:22 -------- d-----w c:\program files\Windows Live
2009-04-28 12:17 . 2009-04-28 12:17 -------- d-----w c:\progra~2\WLInstaller
2009-04-28 12:17 . 2009-04-28 12:17 -------- d-----w c:\users\All Users\WLInstaller
2009-04-26 09:08 . 2009-04-26 09:08 -------- d-----w c:\program files\PC Optimizer Pro
2009-04-24 14:35 . 2009-04-24 14:35 -------- d-----w c:\program files\Microsoft Silverlight
2009-04-24 00:34 . 2009-04-24 00:34 155 ----a-w c:\windows\system32\SelfDel.bat
2009-04-23 03:28 . 2009-04-23 03:28 -------- d-----w c:\program files\vLite
2009-04-22 12:17 . 2009-04-22 12:20 -------- d-----w c:\users\madPC\SecurityScans
2009-04-22 12:16 . 2009-04-22 12:16 -------- d-----w c:\program files\Microsoft Baseline Security Analyzer 2
2009-04-21 14:34 . 2009-04-21 14:34 64160 ----a-w c:\windows\system32\drivers\Lbd.sys
2009-04-18 03:16 . 2009-04-18 03:16 -------- d-----w c:\users\Administrator\AppData\Roaming\Malwarebytes
2009-04-18 03:16 . 2009-04-06 06:02 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-04-18 03:16 . 2009-04-06 06:02 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-18 03:16 . 2009-04-18 03:16 -------- d-----w c:\progra~2\Malwarebytes
2009-04-18 03:16 . 2009-04-18 03:16 -------- d-----w c:\users\All Users\Malwarebytes
2009-04-18 03:16 . 2009-04-18 03:16 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-04-16 14:43 . 2008-04-12 03:32 784896 ----a-w c:\windows\system32\rpcrt4.dll
2009-04-16 14:43 . 2008-04-26 08:26 891448 ----a-w c:\windows\system32\drivers\tcpip.sys
2009-04-16 14:43 . 2008-04-05 01:21 72192 ----a-w c:\windows\system32\drivers\pacer.sys
2009-04-16 14:43 . 2008-04-05 03:34 15360 ----a-w c:\windows\system32\pacerprf.dll
2009-04-16 14:42 . 2008-06-26 03:29 565248 ----a-w c:\windows\system32\emdmgmt.dll
2009-04-16 14:42 . 2008-08-02 01:01 625152 ----a-w c:\windows\system32\drivers\dxgkrnl.sys
2009-04-16 14:42 . 2008-06-26 03:29 45056 ----a-w c:\windows\system32\dataclen.dll
2009-04-16 14:42 . 2008-05-20 02:07 148480 ----a-w c:\windows\system32\drivers\nwifi.sys
2009-04-16 14:42 . 2008-08-02 03:26 36864 ----a-w c:\windows\system32\cdd.dll
2009-04-16 14:42 . 2008-05-08 21:59 90112 ----a-w c:\windows\system32\wshext.dll
2009-04-16 14:42 . 2008-05-08 21:59 155648 ----a-w c:\windows\system32\wscript.exe
2009-04-16 14:42 . 2008-05-08 21:58 135168 ----a-w c:\windows\system32\cscript.exe
2009-04-16 14:42 . 2008-05-08 21:59 180224 ----a-w c:\windows\system32\scrobj.dll
2009-04-16 14:42 . 2008-05-08 21:59 172032 ----a-w c:\windows\system32\scrrun.dll
2009-04-16 14:34 . 2009-04-16 14:34 -------- d-----r c:\windows\system32\config\systemprofile\Links
2009-04-16 14:34 . 2009-04-16 14:34 -------- d-----r c:\windows\system32\config\systemprofile\Saved Games
2009-04-16 14:34 . 2009-04-16 14:34 -------- d-----r c:\windows\system32\config\systemprofile\Downloads
2009-04-16 14:34 . 2009-04-16 14:34 -------- d-----r c:\windows\system32\config\systemprofile\Searches
2009-04-16 14:34 . 2009-04-16 14:34 -------- d-----r c:\windows\system32\config\systemprofile\Music
2009-04-16 14:34 . 2009-04-16 14:34 -------- d-----r c:\windows\system32\config\systemprofile\Pictures
2009-04-16 14:34 . 2009-04-16 14:34 -------- d-----r c:\windows\system32\config\systemprofile\Videos
2009-04-16 14:33 . 2009-04-16 14:33 -------- d-----r c:\windows\system32\config\systemprofile\Documents
2009-04-16 14:28 . 2009-04-16 14:28 -------- d-----w C:\PerfLogs
2009-04-16 10:48 . 2008-01-19 07:35 210432 ----a-w c:\windows\system32\msv1_0.dll
2009-04-16 10:47 . 2008-01-19 07:36 222720 ----a-w c:\windows\system32\wavemsp.dll
2009-04-16 10:46 . 2008-01-19 07:34 246784 ----a-w c:\windows\system32\drvstore.dll
2009-04-16 10:46 . 2008-01-19 07:34 258560 ----a-w c:\windows\system32\dpx.dll
2009-04-16 10:46 . 2008-01-19 07:35 35328 ----a-w c:\windows\system32\mspatcha.dll
2009-04-16 10:46 . 2008-01-19 07:34 305152 ----a-w c:\windows\system32\msdelta.dll
2009-04-15 15:52 . 2009-04-21 14:34 15688 ----a-w c:\windows\system32\lsdelete.exe
2009-04-15 15:19 . 2009-04-15 15:19 -------- dc-h--w c:\progra~2\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-04-15 15:19 . 2009-04-15 15:19 -------- dc-h--w c:\users\All Users\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-04-15 15:19 . 2009-04-15 15:19 -------- d-----w c:\program files\Lavasoft
2009-04-15 15:19 . 2009-04-15 15:22 -------- d-----w c:\progra~2\Lavasoft
2009-04-15 15:19 . 2009-04-15 15:22 -------- d-----w c:\users\All Users\Lavasoft
2009-04-15 07:56 . 2009-04-15 07:56 -------- d-----w c:\program files\Toshiba
2009-04-15 06:46 . 2009-04-15 06:46 376832 ----a-w c:\windows\system32\winhttp.dll
2009-04-15 06:46 . 2009-04-15 06:46 562176 ----a-w c:\windows\system32\msdtcprx.dll
2009-04-15 06:46 . 2009-04-15 06:46 38912 ----a-w c:\windows\system32\xolehlp.dll
2009-04-15 06:38 . 2009-04-15 06:38 -------- d-----w c:\users\Administrator\AppData\Roaming\BitTorrent
2009-04-13 06:28 . 2009-04-28 07:57 -------- d-----w C:\!KillBox
2009-04-13 05:00 . 2009-04-13 05:00 -------- d-----w c:\program files\Apple Software Update
2009-04-13 05:00 . 2009-04-13 05:00 -------- d-----w c:\progra~2\Apple
2009-04-13 05:00 . 2009-04-13 05:00 -------- d-----w c:\users\All Users\Apple
2009-04-13 03:04 . 2009-04-13 03:04 269312 ----a-w c:\windows\system32\es.dll
2009-04-13 02:57 . 2009-04-13 03:14 -------- d-----w c:\users\Administrator\AppData\Roaming\vlc
2009-04-13 02:30 . 2009-04-21 00:58 680 ----a-w c:\users\Administrator\AppData\Local\d3d9caps.dat
2009-04-13 01:31 . 2009-04-13 05:01 -------- d-----w c:\program files\QuickTime
2009-04-13 01:31 . 2009-04-13 05:01 -------- d-----w c:\progra~2\Apple Computer
2009-04-13 01:31 . 2009-04-13 05:01 -------- d-----w c:\users\All Users\Apple Computer
2009-04-04 12:07 . 2009-04-04 12:07 -------- d-----w c:\users\Administrator\AppData\Local\Yahoo
2009-04-04 10:52 . 2009-04-04 12:06 -------- d-----w c:\progra~2\Yahoo!
2009-04-04 10:52 . 2009-04-04 12:06 -------- d-----w c:\users\All Users\Yahoo!
2009-04-04 10:52 . 2009-04-04 12:06 -------- d-----w c:\program files\Yahoo!
2009-04-04 01:57 . 2009-04-04 01:57 -------- d-----w c:\program files\Windows Live Safety Center
2009-04-04 01:39 . 2009-04-04 01:39 -------- d-----w c:\progra~2\Office Genuine Advantage
2009-04-04 01:39 . 2009-04-04 01:39 -------- d-----w c:\users\All Users\Office Genuine Advantage
2009-04-03 18:28 . 2009-04-03 18:28 28672 ----a-w c:\windows\system32\FwRemoteSvr.dll
2009-04-03 18:28 . 2009-04-03 18:28 61440 ----a-w c:\windows\system32\winipsec.dll
2009-04-03 18:28 . 2009-04-03 18:28 361984 ----a-w c:\windows\system32\IPSECSVC.DLL
2009-04-03 18:28 . 2009-04-03 18:28 272896 ----a-w c:\windows\system32\polstore.dll
2009-04-03 18:19 . 2009-04-03 18:19 296960 ----a-w c:\windows\system32\gdi32.dll
2009-04-03 18:17 . 2009-04-03 18:17 212480 ----a-w c:\windows\system32\drivers\mrxsmb10.sys
2009-04-03 18:15 . 2009-04-03 18:15 28672 ----a-w c:\windows\system32\Apphlpdm.dll
2009-04-03 18:15 . 2009-04-03 18:15 4240384 ----a-w c:\windows\system32\GameUXLegacyGDFs.dll
2009-04-03 18:15 . 2009-04-03 18:15 1695744 ----a-w c:\windows\system32\gameux.dll
2009-04-03 18:14 . 2009-04-03 18:14 303616 ----a-w c:\windows\system32\wmpeffects.dll
2009-04-03 18:13 . 2009-04-03 18:13 1191936 ----a-w c:\windows\system32\msxml3.dll
2009-04-03 18:13 . 2009-04-03 18:13 2048 ----a-w c:\windows\system32\msxml3r.dll
2009-04-03 18:09 . 2009-04-03 18:09 8147456 ----a-w c:\windows\system32\wmploc.DLL
2009-04-03 18:09 . 2009-04-03 18:09 7680 ----a-w c:\windows\system32\spwmp.dll
2009-04-03 18:09 . 2009-04-03 18:09 4096 ----a-w c:\windows\system32\dxmasf.dll
2009-04-03 18:07 . 2009-04-03 18:07 -------- d-----w c:\program files\Microsoft CAPICOM 2.1.0.2
2009-04-03 18:04 . 2009-04-03 18:04 2927104 ----a-w c:\windows\explorer.exe
2009-04-03 17:56 . 2009-04-03 17:56 6656 ----a-w c:\windows\system32\kbd106n.dll
2009-04-03 17:56 . 2009-04-03 17:56 927288 ----a-w c:\windows\system32\winresume.exe
2009-04-03 17:56 . 2009-04-03 17:56 988216 ----a-w c:\windows\system32\winload.exe
2009-04-03 17:56 . 2009-04-03 17:56 40960 ----a-w c:\windows\system32\srclient.dll
2009-04-03 17:56 . 2009-04-03 17:56 318464 ----a-w c:\windows\system32\rstrui.exe
2009-04-03 17:56 . 2009-04-03 17:56 378368 ----a-w c:\windows\system32\srcore.dll
2009-04-03 17:56 . 2009-04-03 17:56 14848 ----a-w c:\windows\system32\srdelayed.exe
2009-04-03 17:56 . 2009-04-03 17:56 19000 ----a-w c:\windows\system32\kd1394.dll
2009-04-03 17:56 . 2009-04-03 17:56 46592 ----a-w c:\windows\system32\setbcdlocale.dll
2009-04-03 17:56 . 2009-04-03 17:56 615992 ----a-w c:\windows\system32\ci.dll
2009-04-03 17:51 . 2009-04-03 17:51 37888 ----a-w c:\windows\system32\printcom.dll
2009-04-03 17:51 . 2009-04-03 17:51 443392 ----a-w c:\windows\system32\win32spl.dll
2009-04-03 17:50 . 2009-04-03 17:50 113664 ----a-w c:\windows\system32\drivers\rmcast.sys
2009-04-03 17:50 . 2009-04-03 17:50 14848 ----a-w c:\windows\system32\wshrm.dll
2009-04-03 17:48 . 2009-04-03 17:48 288768 ----a-w c:\windows\system32\drivers\srv.sys
2009-04-03 17:41 . 2009-04-03 17:41 268288 ----a-w c:\windows\system32\schannel.dll
2009-04-03 17:38 . 2009-04-03 17:38 622080 ----a-w c:\windows\system32\icardagt.exe
2009-04-03 17:38 . 2009-04-03 17:38 11264 ----a-w c:\windows\system32\icardres.dll
2009-04-03 17:38 . 2009-04-03 17:38 97800 ----a-w c:\windows\system32\infocardapi.dll
2009-04-03 17:38 . 2009-04-03 17:38 105016 ----a-w c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-04-03 17:38 . 2009-04-03 17:38 326160 ----a-w c:\windows\system32\PresentationHost.exe
2009-04-03 17:38 . 2009-04-03 17:38 43544 ----a-w c:\windows\system32\PresentationHostProxy.dll
2009-04-03 17:38 . 2009-04-03 17:38 781344 ----a-w c:\windows\system32\PresentationNative_v0300.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-30 13:55 . 2009-02-24 16:36 12 ----a-w c:\windows\bthservsdp.dat
2009-04-30 12:21 . 2009-02-25 12:30 -------- d-----w c:\program files\DNA
2009-04-29 16:41 . 2009-04-29 16:41 805 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-04-29 16:41 . 2009-04-29 16:41 8014 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-04-28 12:22 . 2009-02-24 16:14 -------- d-----w c:\program files\MSN Messenger
2009-04-28 12:22 . 2006-11-02 10:25 51200 ----a-w c:\windows\inf\infpub.dat
2009-04-28 12:22 . 2006-11-02 10:25 86016 ----a-w c:\windows\inf\infstor.dat
2009-04-28 12:22 . 2006-11-02 10:25 143360 ----a-w c:\windows\inf\infstrng.dat
2009-04-16 15:16 . 2009-04-16 15:16 0 ---ha-w c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2009-04-16 14:36 . 2006-11-02 12:48 174 --sha-w c:\program files\desktop.ini
2009-04-16 14:29 . 2006-11-02 12:35 -------- d-----w c:\program files\Windows Sidebar
2009-04-16 14:29 . 2006-11-02 12:35 -------- d-----w c:\program files\Windows Photo Gallery
2009-04-16 14:29 . 2006-11-02 12:35 -------- d-----w c:\program files\Windows Collaboration
2009-04-16 14:29 . 2006-11-02 12:35 -------- d-----w c:\program files\Windows Calendar
2009-04-16 14:29 . 2006-11-02 11:18 -------- d-----w c:\program files\Windows Mail
2009-04-16 14:28 . 2006-11-02 12:35 -------- d-----w c:\program files\Windows Defender
2009-04-16 14:28 . 2006-11-02 10:25 665600 ----a-w c:\windows\inf\drvindex.dat
2009-04-16 12:06 . 2006-11-02 10:32 101888 ----a-w c:\windows\system32\ifxcardm.dll
2009-04-16 12:06 . 2006-11-02 10:32 82432 ----a-w c:\windows\system32\axaltocm.dll
2009-04-04 03:44 . 2007-04-17 20:09 -------- d-----w c:\program files\Java
2009-04-03 18:15 . 2009-04-03 18:15 2560 ----a-w c:\windows\AppPatch\AcRes.dll
2009-04-03 18:15 . 2009-04-03 18:15 541696 ----a-w c:\windows\AppPatch\AcLayers.dll
2009-04-03 18:15 . 2009-04-03 18:15 460288 ----a-w c:\windows\AppPatch\AcSpecfc.dll
2009-04-03 18:15 . 2009-04-03 18:15 2154496 ----a-w c:\windows\AppPatch\AcGenral.dll
2009-04-03 18:15 . 2009-04-03 18:15 173056 ----a-w c:\windows\AppPatch\AcXtrnal.dll
2009-04-03 18:15 . 2009-04-03 18:15 52736 ----a-w c:\windows\AppPatch\iebrshim.dll
2009-03-13 12:29 . 2009-02-24 12:58 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-03-08 18:49 . 2009-03-13 13:16 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-08 11:34 . 2009-04-23 03:57 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 11:34 . 2009-04-23 03:57 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 11:33 . 2009-04-23 03:57 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 11:33 . 2009-04-23 03:57 109056 ----a-w c:\windows\system32\iesysprep.dll
2009-03-08 11:33 . 2009-04-23 03:57 109568 ----a-w c:\windows\system32\PDMSetup.exe
2009-03-08 11:33 . 2009-04-23 03:57 132608 ----a-w c:\windows\system32\ieUnatt.exe
2009-03-08 11:33 . 2009-04-23 03:57 107520 ----a-w c:\windows\system32\RegisterIEPKEYs.exe
2009-03-08 11:33 . 2009-04-23 03:57 107008 ----a-w c:\windows\system32\SetIEInstalledDate.exe
2009-03-08 11:33 . 2009-04-23 03:57 103936 ----a-w c:\windows\system32\SetDepNx.exe
2009-03-08 11:33 . 2009-04-23 03:57 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 11:32 . 2009-04-23 03:57 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 11:32 . 2009-04-23 03:57 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 11:32 . 2009-04-23 03:57 66560 ----a-w c:\windows\system32\wextract.exe
2009-03-08 11:32 . 2009-04-23 03:57 169472 ----a-w c:\windows\system32\iexpress.exe
2009-03-08 11:31 . 2009-04-23 03:57 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 11:31 . 2009-04-23 03:57 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 11:31 . 2009-04-23 03:57 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 11:22 . 2009-04-23 03:57 156160 ----a-w c:\windows\system32\msls31.dll
2009-02-24 15:53 . 2009-02-24 15:53 0 ----a-w c:\windows\nsreg.dat
2009-02-24 15:35 . 2009-02-24 15:35 99864 ----a-w c:\users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2009-02-24 12:58 . 2009-02-24 12:58 51224 ----a-w c:\windows\system32\wuauclt.exe
2009-02-24 12:58 . 2009-02-24 12:58 43544 ----a-w c:\windows\system32\wups2.dll
2009-02-24 12:58 . 2009-02-24 12:58 1809944 ----a-w c:\windows\system32\wuaueng.dll
2009-02-24 12:58 . 2009-02-24 12:58 1524736 ----a-w c:\windows\system32\wucltux.dll
2009-02-24 12:58 . 2009-02-24 12:58 83456 ----a-w c:\windows\system32\wudriver.dll
2009-02-24 12:58 . 2009-02-24 12:58 561688 ----a-w c:\windows\system32\wuapi.dll
2009-02-24 12:58 . 2009-02-24 12:58 34328 ----a-w c:\windows\system32\wups.dll
2009-02-24 12:57 . 2009-02-24 12:57 31232 ----a-w c:\windows\system32\wuapp.exe
2009-02-24 12:57 . 2009-02-24 12:57 162064 ----a-w c:\windows\system32\wuwebv.dll
2009-02-12 11:39 . 2009-02-12 11:39 12712 ----a-w c:\windows\system32\drivers\FJGSDisk.sys
2009-02-12 11:04 . 2009-02-12 11:04 99864 ----a-w c:\windows\system32\config\systemprofile\AppData\Local\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LoadFUJ02E3"="c:\program files\Fujitsu\FUJ02E3\FUJ02E3.exe" [2006-11-17 80688]
"IndicatorUtility"="c:\program files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe" [2006-11-07 97072]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-04-09 154392]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-04-09 133912]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-01-23 827392]
"LoadFujitsuQuickTouch"="c:\program files\Fujitsu\Application Panel\QuickTouch.exe" [2005-07-21 242688]
"LoadBtnHnd"="c:\program files\Fujitsu\BtnHnd\BtnHnd.exe" [2005-07-21 61440]
"PSUtility"="c:\program files\Fujitsu\PSUtility\TrayManager.exe" [2006-12-22 136744]
"LVCOMSX"="c:\program files\Common Files\LogiShrd\LComMgr\LVComSX.exe" [2007-04-02 252704]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-05-08 174872]
"IaNvSrv"="c:\program files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe" [2007-05-08 33048]
"SSUtility"="c:\program files\Fujitsu\SSUtility\FJSSDMN.exe" [2009-02-12 193832]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-03-01 4390912]
c:\progra~2\MICROS~1\Windows\STARTM~1\Programs\Startup\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2007-11-1 421888]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\rundisabled]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{F01CE1E2-9A47-42F9-AD30-7B2AD8E08A94}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{7A0C6B10-FF15-4B5E-85EB-C851E3DF9E79}"= c:\program files\CyberLink\PowerDVD\PowerDVD.EXE:CyberLink PowerDVD
"{B65B13F6-BBD4-4FAB-97B8-D1406988A316}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{15F91AE0-0A6A-4AD0-BC13-E97CF52E271F}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"TCP Query User{F4F47E1E-E573-4114-BC3B-21FD4448FC36}c:\\program files\\windows mobile developer power toys\\activesync_remote_display\\asrdisp.exe"= UDP:c:\program files\windows mobile developer power toys\activesync_remote_display\asrdisp.exe:ASRDisp
"UDP Query User{241244E8-A714-4A26-8033-A8DC16D0C898}c:\\program files\\windows mobile developer power toys\\activesync_remote_display\\asrdisp.exe"= TCP:c:\program files\windows mobile developer power toys\activesync_remote_display\asrdisp.exe:ASRDisp
"{DDC82CFA-D149-4A61-8FEE-0F5D7501CC0A}"= UDP:c:\program files\DNA\btdna.exe

NA (TCP-In)
"{7DD80389-BAEB-42DD-A05F-880619A84500}"= TCP:c:\program files\DNA\btdna.exe

NA (UDP-In)
"{4C2B38A4-E717-43A4-BC01-3A065B2B9A3F}"= UDP:c:\program files\BitTorrent\BitTorrent.exe:BitTorrent (TCP-In)
"{3935BD02-4B40-439B-86EA-B4F99566E630}"= TCP:c:\program files\BitTorrent\BitTorrent.exe:BitTorrent (UDP-In)
"TCP Query User{A7928B77-F859-453F-ACE0-E4419FFFEE0A}c:\\program files\\bittorrent\\bittorrent.exe"= UDP:c:\program files\bittorrent\bittorrent.exe:BitTorrent
"UDP Query User{A3C6541E-F6AD-46D5-A349-82A8756C8428}c:\\program files\\bittorrent\\bittorrent.exe"= TCP:c:\program files\bittorrent\bittorrent.exe:BitTorrent
"{4CE5628A-E049-4199-BD14-F3ACB0188262}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{5DBFBFA1-FF9F-4CA0-8CC1-F91FE82A7997}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"TCP Query User{DF9E080F-A2A6-4E03-928C-D7AAE5BFF5AE}c:\\program files\\yahoo!\\messenger\\yahoomessenger.exe"= UDP:c:\program files\yahoo!\messenger\yahoomessenger.exe:Yahoo! Messenger
"UDP Query User{04C91E26-0A58-4EB0-A38E-FB81F0A09A68}c:\\program files\\yahoo!\\messenger\\yahoomessenger.exe"= TCP:c:\program files\yahoo!\messenger\yahoomessenger.exe:Yahoo! Messenger
"{87C95383-720C-4E36-92C1-5A596BE3F1FC}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{E108B469-D439-4A90-B0DD-3AF139C46756}"= UDP:c:\program files\Symantec AntiVirus\Rtvscan.exe:Symantec Antivirus
"{134FFABB-69CF-4FC7-8226-909F636B2E28}"= TCP:c:\program files\Symantec AntiVirus\Rtvscan.exe:Symantec Antivirus
"{124D1410-FC14-44BE-939D-2D67F33C0F7C}"= UDP:c:\program files\Common Files\Symantec Shared\ccApp.exe:Symantec Email
"{1779AE8C-BFEB-457A-99BB-C18BC6585906}"= TCP:c:\program files\Common Files\Symantec Shared\ccApp.exe:Symantec Email
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R0 omnipass;omnipass; [x]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-04-21 953168]
R2 LvIBTSvr;Logitech IBT Service;c:\program files\Common Files\LogiShrd\LvIBTSvr\LvIBTSvr.exe [2007-04-02 76576]
R3 ADVNTDRV;ADVNTDRV;c:\windows\System32\drivers\ADVNTDRV.SYS [1999-11-18 3872]
R3 SavRoam;SavRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [2006-11-27 122008]
S0 FJGSDisk;G-Sensor Application Filter Driver;c:\windows\system32\DRIVERS\FJGSDisk.sys [2009-02-12 12712]
S0 iaNvStor;Intel(R) Turbo Memory Technology NAND Controller;c:\windows\system32\DRIVERS\iaNvStor.sys [2007-05-04 208896]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2009-04-21 64160]
S0 O2MDRDR;O2MDRDR;c:\windows\system32\DRIVERS\o2media.sys [2006-10-03 36640]
S0 O2SDRDR;O2SDRDR;c:\windows\system32\DRIVERS\o2sd.sys [2006-10-12 33152]
S2 PowerSavingUtilityService;PowerSavingUtilityService;c:\program files\Fujitsu\PSUtility\PSUService.exe [2006-12-22 63016]
S2 UpdateNaviInstallService;UpdateNaviInstallService;c:\program files\Fujitsu\updnavi\updnvsrv.exe [2007-01-11 12288]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-04-15 101936]
S3 FUJ02E3;Fujitsu FUJ02E3 Device Driver;c:\windows\system32\DRIVERS\FUJ02E3.sys [2006-11-01 5632]
S3 SMSCIRDA;SMSC Infrared Device Driver;c:\windows\system32\DRIVERS\SMSCirda.sys [2006-11-02 30720]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{af316a4d-0271-11de-ab37-000000000000}]
\shell\AutoRun\command - H:\LaunchU3.exe -a
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-04-29 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 14:33]
2009-04-30 c:\windows\Tasks\User_Feed_Synchronization-{3D592E6A-7BAD-4227-B6C4-7E801F98E40E}.job
- c:\windows\system32\msfeedssync.exe [2009-04-23 11:31]
.
.
------- Supplementary Scan -------
.
uStart Page = about:tabs
TCP: {01573F81-6C25-441E-983B-581898952A67} = 192.231.203.132,192.231.203.3
TCP: {7E4FEBD3-21C7-4D81-AEF7-1619DC39AC99} = 192.231.203.132,192.231.203.3
FF - ProfilePath - c:\users\madPC\AppData\Roaming\Mozilla\Firefox\Profiles\34qxd13h.default\
FF - prefs.js: keyword.URL - hxxp://www.google.com.au/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-04-30 23:44
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\windows\system32\drivers\ovfsthnwawaalkwgxjdtxdrfddfrwlrlxassxn.sys 83968 bytes executable
c:\windows\system32\ovfsthcettpcbilowcpvbnbrrtoxuskymsmlpq.dat 2418 bytes
c:\windows\system32\ovfsthcqwtjumvsbmiftubdoffvqylchcbxsts.dll 19456 bytes executable
c:\windows\system32\ovfstheepxdcrrgqbynuertsfkdmteyxngdrmp.dll 17920 bytes executable
c:\windows\system32\ovfsthldbowyvnoponfggajnivdmqoykldkjxj.dll 17920 bytes executable
c:\windows\system32\ovfsthqfrvipyftqqurimqilppwtmdmctqvgbv.dll 61440 bytes executable
c:\windows\system32\ovfsthyenaicmkengblcuyxqsdpjpmepvhsruj.dll 19456 bytes executable
c:\users\madPC\AppData\Local\Temp\ovfsth000 0 bytes
c:\windows\TEMP\ovfsthjrxxsbdkny.tmp 23040 bytes executable
scan completed successfully
hidden files: 9
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\software\Classes\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10b.exe,-101"
[HKEY_USERS\software\Classes\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
[HKEY_USERS\software\Classes\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10b.exe"
[HKEY_USERS\software\Classes\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
[HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\Flash10b.ocx"
"ThreadingModel"="Apartment"
[HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
[HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
[HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\system32\\Macromed\\Flash\\Flash10b.ocx, 1"
[HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
[HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
[HKEY_USERS\software\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
[HKEY_USERS\software\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
[HKEY_USERS\software\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\Flash10b.ocx"
"ThreadingModel"="Apartment"
[HKEY_USERS\software\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
[HKEY_USERS\software\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\system32\\Macromed\\Flash\\Flash10b.ocx, 1"
[HKEY_USERS\software\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
[HKEY_USERS\software\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
[HKEY_USERS\software\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
[HKEY_USERS\software\Classes\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}]
@Denied: (A 2) (Everyone)
@="IFlashBroker2"
[HKEY_USERS\software\Classes\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_USERS\software\Classes\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_USERS\software\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
[HKEY_USERS\software\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
[HKEY_USERS\software\Classes\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
[HKEY_USERS\software\Classes\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
[HKEY_USERS\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_USERS\system\ControlSet001\Services\ovfsthpxajutfymxxiilmgqiipvmspngcojhie]
@DACL=(02 0000)
"start"=dword:00000001
"type"=dword:00000001
"group"="file system"
"imagepath"=expand:"\\systemroot\\system32\\drivers\\ovfsthnwawaalkwgxjdtxdrfddfrwlrlxassxn.sys"
"inst"=dword:00000000
[HKEY_USERS\system\ControlSet002\Services\ovfsthpxajutfymxxiilmgqiipvmspngcojhie]
@DACL=(02 0000)
"start"=dword:00000001
"type"=dword:00000001
"group"="file system"
"imagepath"=expand:"\\systemroot\\system32\\drivers\\ovfsthnwawaalkwgxjdtxdrfddfrwlrlxassxn.sys"
"inst"=dword:00000000
[HKEY_USERS\system\ControlSet003\Services\ovfsthpxajutfymxxiilmgqiipvmspngcojhie]
@DACL=(02 0000)
"start"=dword:00000001
"type"=dword:00000001
"group"="file system"
"imagepath"=expand:"\\systemroot\\system32\\drivers\\ovfsthnwawaalkwgxjdtxdrfddfrwlrlxassxn.sys"
[HKEY_USERS\system\ControlSet004\Services\ovfsthpxajutfymxxiilmgqiipvmspngcojhie]
@DACL=(02 0000)
"start"=dword:00000001
"type"=dword:00000001
"group"="file system"
"imagepath"=expand:"\\systemroot\\system32\\drivers\\ovfsthnwawaalkwgxjdtxdrfddfrwlrlxassxn.sys"
"inst"=dword:00000000
[HKEY_USERS\system\ControlSet005\Services\ovfsthpxajutfymxxiilmgqiipvmspngcojhie]
@DACL=(02 0000)
"start"=dword:00000001
"type"=dword:00000001
"group"="file system"
"imagepath"=expand:"\\systemroot\\system32\\drivers\\ovfsthnwawaalkwgxjdtxdrfddfrwlrlxassxn.sys"
[HKEY_USERS\system\ControlSet006\Services\ovfsthpxajutfymxxiilmgqiipvmspngcojhie]
@DACL=(02 0000)
"start"=dword:00000001
"type"=dword:00000001
"group"="file system"
"imagepath"=expand:"\\systemroot\\system32\\drivers\\ovfsthnwawaalkwgxjdtxdrfddfrwlrlxassxn.sys"
[HKEY_USERS\system\ControlSet007\Services\ovfsthpxajutfymxxiilmgqiipvmspngcojhie]
@DACL=(02 0000)
"start"=dword:00000001
"type"=dword:00000001
"group"="file system"
"imagepath"=expand:"\\systemroot\\system32\\drivers\\ovfsthnwawaalkwgxjdtxdrfddfrwlrlxassxn.sys"
"inst"=dword:00000000
[HKEY_USERS\system\ControlSet008\Services\ovfsthpxajutfymxxiilmgqiipvmspngcojhie]
@DACL=(02 0000)
"start"=dword:00000001
"type"=dword:00000001
"group"="file system"
"imagepath"=expand:"\\systemroot\\system32\\drivers\\ovfsthnwawaalkwgxjdtxdrfddfrwlrlxassxn.sys"
[HKEY_USERS\system\ControlSet009\Services\ovfsthpxajutfymxxiilmgqiipvmspngcojhie]
@DACL=(02 0000)
"start"=dword:00000001
"type"=dword:00000001
"group"="file system"
"imagepath"=expand:"\\systemroot\\system32\\drivers\\ovfsthnwawaalkwgxjdtxdrfddfrwlrlxassxn.sys"
[HKEY_USERS\system\ControlSet010\Services\ovfsthpxajutfymxxiilmgqiipvmspngcojhie]
@DACL=(02 0000)
"start"=dword:00000001
"type"=dword:00000001
"group"="file system"
"imagepath"=expand:"\\systemroot\\system32\\drivers\\ovfsthnwawaalkwgxjdtxdrfddfrwlrlxassxn.sys"
"inst"=dword:00000000
[HKEY_USERS\system\ControlSet011\Services\ovfsthpxajutfymxxiilmgqiipvmspngcojhie]
@DACL=(02 0000)
"start"=dword:00000001
"type"=dword:00000001
"group"="file system"
"imagepath"=expand:"\\systemroot\\system32\\drivers\\ovfsthnwawaalkwgxjdtxdrfddfrwlrlxassxn.sys"
[HKEY_USERS\system\ControlSet012\Services\ovfsthpxajutfymxxiilmgqiipvmspngcojhie]
@DACL=(02 0000)
"start"=dword:00000001
"type"=dword:00000001
"group"="file system"
"imagepath"=expand:"\\systemroot\\system32\\drivers\\ovfsthnwawaalkwgxjdtxdrfddfrwlrlxassxn.sys"
[HKEY_USERS\system\ControlSet013\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_USERS\system\ControlSet013\Services\ovfsthpxajutfymxxiilmgqiipvmspngcojhie]
@DACL=(02 0000)
"start"=dword:00000001
"type"=dword:00000001
"group"="file system"
"imagepath"=expand:"\\systemroot\\system32\\drivers\\ovfsthnwawaalkwgxjdtxdrfddfrwlrlxassxn.sys"
"inst"=dword:00000000
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Softex\OmniPass\OmniServ.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\agrsmsvc.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\program files\Common Files\microsoft shared\VS7DEBUG\mdm.exe
c:\windows\System32\o2flash.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\program files\Softex\OmniPass\opvapp.exe
c:\windows\System32\wbem\unsecapp.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
c:\windows\System32\igfxsrvc.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2009-04-30 23:46 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-30 14:16
Pre-Run: 36,160,290,816 bytes free
Post-Run: 35,685,863,424 bytes free
511 --- E O F --- 2009-04-21 02:21
Ran Malwarebytes - detected 6 trojans of win32.tdss.rtk
Uninstalled adobe 8.3
Installed adobe 9.1
Uninstall java
Installed java
Ran ATF cleaner
Ran dds
DDS (Ver_09-03-16.01) - NTFSx86
Run by madPC at 1:41:40.72 on 01-May-09 Fri
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.1.1033.18.2037.1156 [GMT 9.5:30]
AV: Symantec AntiVirus *On-access scanning disabled* (Updated)
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files\Softex\OmniPass\OmniServ.exe
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\agrsmsvc.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Windows\system32\o2flash.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Fujitsu\PSUtility\PSUService.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Program Files\Fujitsu\updnavi\updnvsrv.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Softex\OmniPass\opvapp.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Fujitsu\FUJ02E3\FUJ02E3.exe
C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
C:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Fujitsu\PSUtility\TrayManager.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Fujitsu\SSUtility\FJSSDMN.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Windows\system32\svchost.exe -k WindowsMobile
C:\Windows\System32\mobsync.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Internet Explorer\IELowutil.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\madPC\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = about:tabs
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common
files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1
\SDHelper.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program
files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program
files\java\jre6\bin\jp2ssv.dll
mRun: [LoadFUJ02E3] c:\program files\fujitsu\fuj02e3\FUJ02E3.exe
mRun: [IndicatorUtility] c:\program files\fujitsu\fujitsu hotkey utility\IndicatorUty.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [LoadFujitsuQuickTouch] c:\program files\fujitsu\application panel\QuickTouch.exe
mRun: [LoadBtnHnd] c:\program files\fujitsu\btnhnd\BtnHnd.exe
mRun: [PSUtility] c:\program files\fujitsu\psutility\TrayManager.exe
mRun: [LVCOMSX] "c:\program files\common files\logishrd\lcommgr\LVComSX.exe"
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [IaNvSrv] c:\program files\intel\intel matrix storage manager\orom\ianvsrv\IaNvSrv.exe
mRun: [SSUtility] c:\program files\fujitsu\ssutility\FJSSDMN.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk -
c:\program files\toshiba\bluetooth toshiba stack\TosBtMng1.exe
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
dPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} -
c:\windows\windowsmobile\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} -
c:\windows\windowsmobile\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} -
c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} -
c:\progra~1\spybot~1\SDHelper.dll
DPF: {17492023-C23A-453E-A040-C7C580BBF700} -
hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-
1719D1177202/LegitCheckControl.cab
DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} -
hxxp://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} -
hxxp://cdn.scan.onecare.live.com/resource/download/scanner/en-au/wlscctrl2.cab
DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} -
hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-
1_6_0_13-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} -
hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-
1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-
1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} -
hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {EA1B8527-E422-4909-825A-70BE0694F18E} -
hxxps://online.westpac.com.au/wtoa/wtOtherAccounts/portfoliomanagerwt.cab
TCP: {01573F81-6C25-441E-983B-581898952A67} = 192.231.203.132,192.231.203.3
TCP: {7E4FEBD3-21C7-4D81-AEF7-1619DC39AC99} = 192.231.203.132,192.231.203.3
Handler: x-excid - {9D6CC632-1337-4a33-9214-2DA092E776F4} - c:\windows\downloaded program
files\mimectl.dll
Notify: igfxcui - igfxdev.dll
================= FIREFOX ===================
FF - ProfilePath - c:\users\madPC\appdata\roaming\mozilla\firefox\profiles\34qxd13h.default\
FF - prefs.js: keyword.URL - hxxp://www.google.com.au/search?ie=UTF-8&oe=UTF-
8&sourceid=navclient&gfns=1&q=
FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll
============= SERVICES / DRIVERS ===============
R0 FJGSDisk;G-Sensor Application Filter Driver;c:\windows\system32\drivers\FJGSDisk.sys [2009
-2-12 12712]
R0 iaNvStor;Intel(R) Turbo Memory Technology NAND Controller;c:\windows\system32
\drivers\iaNvStor.sys [2007-5-15 208896]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-4-22 64160]
R0 O2MDRDR;O2MDRDR;c:\windows\system32\drivers\o2media.sys [2006-10-4 36640]
R0 O2SDRDR;O2SDRDR;c:\windows\system32\drivers\o2sd.sys [2006-10-13 33152]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-
aware\AAWService.exe [2009-3-10 953168]
R2 PowerSavingUtilityService;PowerSavingUtilityService;c:\program
files\fujitsu\psutility\PSUService.exe [2006-12-22 63016]
R2 UpdateNaviInstallService;UpdateNaviInstallService;c:\program
files\fujitsu\updnavi\updnvsrv.exe [2007-1-11 12288]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec
shared\eengine\EraserUtilRebootDrv.sys [2009-4-30 101936]
R3 FUJ02E3;Fujitsu FUJ02E3 Device Driver;c:\windows\system32\drivers\fuj02e3.sys [2007-5-15
5632]
R3 SMSCIRDA;SMSC Infrared Device Driver;c:\windows\system32\drivers\smscirda.sys [2006-11-2
30720]
S2 LvIBTSvr;Logitech IBT Service;c:\program files\common files\logishrd\lvibtsvr\LvIBTSvr.exe
[2007-4-3 76576]
S3 ADVNTDRV;ADVNTDRV;c:\windows\system32\drivers\ADVNTDRV.SYS [2009-2-24 3872]
S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2006-11-28 122008]
=============== Created Last 30 ================
2009-04-30 23:37 284,748,436 a------- c:\windows\MEMORY.DMP
2009-04-30 21:49 161,792 a------- c:\windows\SWREG.exe
2009-04-30 21:49 98,816 a------- c:\windows\sed.exe
2009-04-30 19:23 <DIR> --d----- c:\users\madPC\DoctorWeb
2009-04-30 02:11 109,744 a------- c:\windows\system32\drivers\SYMEVENT.SYS
2009-04-30 02:11 8,014 a------- c:\windows\system32\drivers\SYMEVENT.CAT
2009-04-30 02:11 805 a------- c:\windows\system32\drivers\SYMEVENT.INF
2009-04-30 02:10 <DIR> --d----- c:\program files\Symantec
2009-04-30 02:10 <DIR> --d----- c:\programdata\Symantec
2009-04-30 02:10 <DIR> --d----- c:\program files\Symantec AntiVirus
2009-04-30 02:10 <DIR> --d----- c:\program files\common files\Symantec Shared
2009-04-30 02:10 <DIR> --d----- c:\progra~2\Symantec
2009-04-30 01:50 549 a------- c:\windows\wininit.ini
2009-04-29 05:34 <DIR> --dsh--- c:\windows\system32\%APPDATA%
2009-04-28 22:01 <DIR> --d----- c:\program files\CCleaner
2009-04-28 21:57 268 a---h--- C:\sqmdata01.sqm
2009-04-28 21:57 244 a---h--- C:\sqmnoopt01.sqm
2009-04-28 21:52 268 a---h--- C:\sqmdata00.sqm
2009-04-28 21:52 244 a---h--- C:\sqmnoopt00.sqm
2009-04-28 21:47 <DIR> -cdsh--- c:\program files\common
files\WindowsLiveInstaller
2009-04-28 21:47 <DIR> --d----- c:\programdata\WLInstaller
2009-04-26 18:38 440,352 a------- c:\windows\system32\mshflxgd.ocx
2009-04-26 18:38 212,240 a------- c:\windows\system32\richtx32.ocx
2009-04-26 18:38 224,016 a------- c:\windows\system32\tabctl32.ocx
2009-04-26 18:38 18,728 a------- c:\windows\system32\ishf_Ex.TLB
2009-04-26 18:38 7,752 a------- c:\windows\system32\shelllink.TLB
2009-04-26 18:38 <DIR> --d----- c:\program files\PC Optimizer Pro
2009-04-24 10:04 155 a------- c:\windows\system32\SelfDel.bat
2009-04-23 12:58 <DIR> --d----- c:\program files\vLite
2009-04-22 21:47 <DIR> --d----- c:\users\madPC\SecurityScans
2009-04-22 21:46 <DIR> --d----- c:\program files\Microsoft Baseline Security
Analyzer 2
2009-04-22 00:04 64,160 a------- c:\windows\system32\drivers\Lbd.sys
2009-04-19 03:18 <DIR> --d----- c:\users\madPC\appdata\roaming\Malwarebytes
2009-04-18 12:46 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-04-18 12:46 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-18 12:46 <DIR> --d----- c:\programdata\Malwarebytes
2009-04-18 12:46 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-04-18 12:46 <DIR> --d----- c:\progra~2\Malwarebytes
2009-04-17 00:46 0 a---h--- c:\windows\system32
\drivers\Msft_User_WpdFs_01_00_00.Wdf
2009-04-17 00:13 784,896 a------- c:\windows\system32\rpcrt4.dll
2009-04-17 00:13 891,448 a------- c:\windows\system32\drivers\tcpip.sys
2009-04-17 00:13 72,192 a------- c:\windows\system32\drivers\pacer.sys
2009-04-17 00:13 15,360 a------- c:\windows\system32\pacerprf.dll
2009-04-17 00:12 625,152 a------- c:\windows\system32\drivers\dxgkrnl.sys
2009-04-17 00:12 565,248 a------- c:\windows\system32\emdmgmt.dll
2009-04-17 00:12 148,480 a------- c:\windows\system32\drivers\nwifi.sys
2009-04-17 00:12 45,056 a------- c:\windows\system32\dataclen.dll
2009-04-17 00:12 36,864 a------- c:\windows\system32\cdd.dll
2009-04-17 00:12 180,224 a------- c:\windows\system32\scrobj.dll
2009-04-17 00:12 172,032 a------- c:\windows\system32\scrrun.dll
2009-04-17 00:12 155,648 a------- c:\windows\system32\wscript.exe
2009-04-17 00:12 135,168 a------- c:\windows\system32\wshom.ocx
2009-04-17 00:12 135,168 a------- c:\windows\system32\cscript.exe
2009-04-17 00:12 90,112 a------- c:\windows\system32\wshext.dll
2009-04-16 23:58 <DIR> --d----- C:\PerfLogs
2009-04-16 20:18 866,816 a------- c:\windows\system32\wmpmde.dll
2009-04-16 20:17 222,720 a------- c:\windows\system32\wavemsp.dll
2009-04-16 20:16 246,784 a------- c:\windows\system32\drvstore.dll
2009-04-16 20:16 305,152 a------- c:\windows\system32\msdelta.dll
2009-04-16 20:16 258,560 a------- c:\windows\system32\dpx.dll
2009-04-16 20:16 35,328 a------- c:\windows\system32\mspatcha.dll
2009-04-16 01:22 15,688 a------- c:\windows\system32\lsdelete.exe
2009-04-16 00:49 <DIR> -cd-h--- c:\programdata\{7972B2E5-3E09-4E5E-81B7-
FE5819D6772F}
2009-04-16 00:49 <DIR> -cd-h--- c:\progra~2\{7972B2E5-3E09-4E5E-81B7-
FE5819D6772F}
2009-04-16 00:49 <DIR> --d----- c:\programdata\Lavasoft
2009-04-16 00:49 <DIR> --d----- c:\program files\Lavasoft
2009-04-15 17:26 <DIR> --d----- c:\program files\Toshiba
2009-04-15 16:16 376,832 a------- c:\windows\system32\winhttp.dll
2009-04-15 16:16 562,176 a------- c:\windows\system32\msdtcprx.dll
2009-04-15 16:16 38,912 a------- c:\windows\system32\xolehlp.dll
2009-04-15 16:15 118 a------- c:\windows\system32\MRT.INI
2009-04-13 15:58 <DIR> --d----- C:\!KillBox
2009-04-13 14:30 <DIR> --d----- c:\programdata\Apple
2009-04-13 12:34 269,312 a------- c:\windows\system32\es.dll
2009-04-13 11:01 <DIR> --d----- c:\programdata\Apple Computer
2009-04-04 20:22 <DIR> --d----- c:\programdata\Yahoo!
2009-04-04 20:22 <DIR> --d----- c:\program files\Yahoo!
2009-04-04 11:09 <DIR> --d----- c:\programdata\Office Genuine Advantage
2009-04-04 03:58 361,984 a------- c:\windows\system32\IPSECSVC.DLL
2009-04-04 03:58 272,896 a------- c:\windows\system32\polstore.dll
2009-04-04 03:58 61,440 a------- c:\windows\system32\winipsec.dll
2009-04-04 03:58 28,672 a------- c:\windows\system32\FwRemoteSvr.dll
2009-04-04 03:49 296,960 a------- c:\windows\system32\gdi32.dll
2009-04-04 03:47 212,480 a------- c:\windows\system32\drivers\mrxsmb10.sys
2009-04-04 03:45 28,672 a------- c:\windows\system32\Apphlpdm.dll
2009-04-04 03:45 4,240,384 a------- c:\windows\system32
\GameUXLegacyGDFs.dll
2009-04-04 03:45 1,695,744 a------- c:\windows\system32\gameux.dll
2009-04-04 03:44 303,616 a------- c:\windows\system32\wmpeffects.dll
2009-04-04 03:43 1,191,936 a------- c:\windows\system32\msxml3.dll
2009-04-04 03:43 2,048 a------- c:\windows\system32\msxml3r.dll
2009-04-04 03:39 8,147,456 a------- c:\windows\system32\wmploc.DLL
2009-04-04 03:39 7,680 a------- c:\windows\system32\spwmp.dll
2009-04-04 03:39 4,096 a------- c:\windows\system32\msdxm.ocx
2009-04-04 03:39 4,096 a------- c:\windows\system32\dxmasf.dll
2009-04-04 03:37 <DIR> --d----- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-04-04 03:34 2,927,104 a------- c:\windows\explorer.exe
2009-04-04 03:26 6,656 a------- c:\windows\system32\kbd106n.dll
2009-04-04 03:26 988,216 a------- c:\windows\system32\winload.exe
2009-04-04 03:26 927,288 a------- c:\windows\system32\winresume.exe
2009-04-04 03:26 378,368 a------- c:\windows\system32\srcore.dll
2009-04-04 03:26 318,464 a------- c:\windows\system32\rstrui.exe
2009-04-04 03:26 40,960 a------- c:\windows\system32\srclient.dll
2009-04-04 03:26 14,848 a------- c:\windows\system32\srdelayed.exe
2009-04-04 03:26 615,992 a------- c:\windows\system32\ci.dll
2009-04-04 03:26 46,592 a------- c:\windows\system32\setbcdlocale.dll
2009-04-04 03:26 19,000 a------- c:\windows\system32\kd1394.dll
2009-04-04 03:21 443,392 a------- c:\windows\system32\win32spl.dll
2009-04-04 03:21 37,888 a------- c:\windows\system32\printcom.dll
2009-04-04 03:20 113,664 a------- c:\windows\system32\drivers\rmcast.sys
2009-04-04 03:20 14,848 a------- c:\windows\system32\wshrm.dll
2009-04-04 03:18 288,768 a------- c:\windows\system32\drivers\srv.sys
2009-04-04 03:11 268,288 a------- c:\windows\system32\schannel.dll
2009-04-04 03:08 622,080 a------- c:\windows\system32\icardagt.exe
2009-04-04 03:08 11,264 a------- c:\windows\system32\icardres.dll
2009-04-04 03:08 97,800 a------- c:\windows\system32\infocardapi.dll
2009-04-04 03:08 37,384 a------- c:\windows\system32\infocardcpl.cpl
2009-04-04 03:08 105,016 a------- c:\windows\system32
\PresentationCFFRasterizerNative_v0300.dll
2009-04-04 03:08 781,344 a------- c:\windows\system32
\PresentationNative_v0300.dll
2009-04-04 03:08 326,160 a------- c:\windows\system32\PresentationHost.exe
2009-04-04 03:08 43,544 a------- c:\windows\system32\PresentationHostProxy.dll
2009-04-04 02:54 15,138,816 a------- c:\windows\ocsetup_install_NetFx3.etl
2009-04-04 02:54 196,608 a------- c:\windows\ocsetup_cbs_install_NetFx3.perf
2009-04-04 02:54 65,536 a------- c:\windows\ocsetup_cbs_install_NetFx3.dpx
2009-04-04 02:52 96,760 a------- c:\windows\system32\dfshim.dll
2009-04-04 02:52 41,984 a------- c:\windows\system32\netfxperf.dll
2009-04-04 02:52 282,112 a------- c:\windows\system32\mscoree.dll
2009-04-04 02:52 158,720 a------- c:\windows\system32\mscorier.dll
2009-04-04 02:52 83,968 a------- c:\windows\system32\mscories.dll
2009-04-04 02:37 2,868,736 a------- c:\windows\system32\mf.dll
2009-04-04 02:37 996,352 a------- c:\windows\system32\WMNetMgr.dll
2009-04-04 02:37 98,816 a------- c:\windows\system32\mfps.dll
2009-04-04 02:37 94,720 a------- c:\windows\system32\logagent.exe
2009-04-04 02:37 53,248 a------- c:\windows\system32\rrinstaller.exe
2009-04-04 02:37 24,576 a------- c:\windows\system32\mfpmp.exe
2009-04-04 02:37 2,048 a------- c:\windows\system32\mferror.dll
2009-04-04 02:36 84,480 a------- c:\windows\system32\INETRES.dll
2009-04-04 02:36 738,304 a------- c:\windows\system32\inetcomm.dll
2009-04-04 02:36 1,314,816 a------- c:\windows\system32\quartz.dll
2009-04-04 02:35 2,048 a------- c:\windows\system32\tzres.dll
2009-04-04 02:35 2,033,152 a------- c:\windows\system32\win32k.sys
2009-04-04 02:35 <DIR> --d----- c:\program files\MSXML 4.0
2009-04-04 02:34 1,334,272 a------- c:\windows\system32\msxml6.dll
2009-04-04 02:34 2,048 a------- c:\windows\system32\msxml6r.dll
==================== Find3M ====================
2009-05-01 01:32 410,984 a------- c:\windows\system32\deploytk.dll
2009-04-28 21:52 51,200 a------- c:\windows\inf\infpub.dat
2009-04-28 21:52 143,360 a------- c:\windows\inf\infstrng.dat
2009-04-28 21:52 86,016 a------- c:\windows\inf\infstor.dat
2009-04-17 00:06 174 a--sh--- c:\program files\desktop.ini
2009-04-16 23:58 665,600 a------- c:\windows\inf\drvindex.dat
2009-04-16 21:36 101,888 a------- c:\windows\system32\ifxcardm.dll
2009-04-16 21:36 82,432 a------- c:\windows\system32\axaltocm.dll
2009-04-04 03:45 2,560 a------- c:\windows\apppatch\AcRes.dll
2009-04-04 03:45 2,154,496 a------- c:\windows\apppatch\AcGenral.dll
2009-04-04 03:45 541,696 a------- c:\windows\apppatch\AcLayers.dll
2009-04-04 03:45 460,288 a------- c:\windows\apppatch\AcSpecfc.dll
2009-04-04 03:45 173,056 a------- c:\windows\apppatch\AcXtrnal.dll
2009-04-04 03:45 52,736 a------- c:\windows\apppatch\iebrshim.dll
2009-03-08 21:04 914,944 a------- c:\windows\system32\wininet.dll
2009-03-08 21:04 43,008 a------- c:\windows\system32\licmgr10.dll
2009-03-08 21:03 18,944 a------- c:\windows\system32\corpol.dll
2009-03-08 21:03 109,056 a------- c:\windows\system32\iesysprep.dll
2009-03-08 21:03 109,568 a------- c:\windows\system32\PDMSetup.exe
2009-03-08 21:03 132,608 a------- c:\windows\system32\ieUnatt.exe
2009-03-08 21:03 107,520 a------- c:\windows\system32\RegisterIEPKEYs.exe
2009-03-08 21:03 107,008 a------- c:\windows\system32\SetIEInstalledDate.exe
2009-03-08 21:03 103,936 a------- c:\windows\system32\SetDepNx.exe
2009-03-08 21:03 420,352 a------- c:\windows\system32\vbscript.dll
2009-03-08 21:02 72,704 a------- c:\windows\system32\admparse.dll
2009-03-08 21:02 71,680 a------- c:\windows\system32\iesetup.dll
2009-03-08 21:02 66,560 a------- c:\windows\system32\wextract.exe
2009-03-08 21:02 169,472 a------- c:\windows\system32\iexpress.exe
2009-03-08 21:01 34,816 a------- c:\windows\system32\imgutil.dll
2009-03-08 21:01 48,128 a------- c:\windows\system32\mshtmler.dll
2009-03-08 21:01 45,568 a------- c:\windows\system32\mshta.exe
2009-03-08 20:52 156,160 a------- c:\windows\system32\msls31.dll
2009-02-24 22:28 1,524,736 a------- c:\windows\system32\wucltux.dll
2009-02-24 22:28 83,456 a------- c:\windows\system32\wudriver.dll
2009-02-24 22:27 162,064 a------- c:\windows\system32\wuwebv.dll
2009-02-24 22:27 31,232 a------- c:\windows\system32\wuapp.exe
2006-11-02 22:09 287,440 a------- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 22:09 287,440 a------- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 22:09 30,674 a------- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 22:09 30,674 a------- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 18:50 287,440 a------- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 18:50 287,440 a------- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 18:50 30,674 a------- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 18:50 30,674 a------- c:\windows\inf\perflib\0000\perfc.dat
============= FINISH: 1:42:35.86 ===============
Created own cfscript
DDS::
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=-