today's
------------------
ComboFix 09-06-23.01 - User 25/06/2009 9:01.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.495.166 [GMT 9.5:30]
Running from: c:\documents and settings\User\Desktop\ComboFix.exe
AV: AVG Anti-Virus Network Edition *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2009-05-24 to 2009-06-24 )))))))))))))))))))))))))))))))
.
2009-06-23 04:25 . 2009-03-06 14:22 284160 -c----w- c:\windows\system32\dllcache\pdh.dll
2009-06-23 04:25 . 2009-02-09 12:10 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2009-06-23 04:25 . 2009-02-06 11:11 110592 -c----w- c:\windows\system32\dllcache\services.exe
2009-06-23 04:25 . 2009-02-06 10:39 35328 -c----w- c:\windows\system32\dllcache\sc.exe
2009-06-23 04:24 . 2009-02-09 12:10 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2009-06-23 04:24 . 2009-02-06 10:10 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2009-06-23 04:24 . 2009-02-09 12:10 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2009-06-23 04:24 . 2009-02-09 12:10 729088 -c----w- c:\windows\system32\dllcache\lsasrv.dll
2009-06-23 04:24 . 2009-02-09 12:10 617472 -c----w- c:\windows\system32\dllcache\advapi32.dll
2009-06-23 04:24 . 2009-02-09 12:10 714752 -c----w- c:\windows\system32\dllcache\ntdll.dll
2009-06-23 04:23 . 2008-10-24 11:21 455296 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2009-06-23 04:19 . 2008-09-04 17:15 1106944 -c----w- c:\windows\system32\dllcache\msxml3.dll
2009-06-23 04:18 . 2008-05-03 11:55 2560 ------w- c:\windows\system32\xpsp4res.dll
2009-06-23 04:18 . 2008-04-21 12:08 215552 -c----w- c:\windows\system32\dllcache\wordpad.exe
2009-06-23 03:59 . 2009-06-23 03:59 -------- d-----w- c:\program files\Trend Micro
2009-06-23 03:38 . 2009-06-23 03:38 -------- dc----w- c:\windows\system32\dllcache\cache
2009-06-22 23:39 . 2009-06-22 23:39 -------- d-----w- c:\program files\Common Files\PCSuite
2009-06-22 23:37 . 2008-08-26 00:56 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2009-06-22 23:37 . 2009-06-22 23:37 -------- d-----w- c:\program files\PC Connectivity Solution
2009-06-22 23:36 . 2009-02-08 23:07 7808 ----a-w- c:\windows\system32\drivers\usbser_lowerfltj.sys
2009-06-22 23:36 . 2009-02-08 23:07 7808 ----a-w- c:\windows\system32\drivers\usbser_lowerflt.sys
2009-06-22 23:36 . 2009-02-08 23:07 659968 ----a-w- c:\windows\system32\nmwcdcocls.dll
2009-06-22 23:36 . 2009-02-08 23:07 22016 ----a-w- c:\windows\system32\drivers\ccdcmbo.sys
2009-06-22 23:36 . 2009-02-08 23:07 17664 ----a-w- c:\windows\system32\drivers\ccdcmb.sys
2009-06-22 23:36 . 2009-02-08 23:02 1112288 ----a-w- c:\windows\system32\wdfcoinstaller01007.dll
2009-06-22 23:35 . 2009-06-22 23:33 33775224 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{55495E65-7C5B-48E4-BC7D-DE54F3DE5ED6}\Nokia_PC_Suite_7_1_30_8_eng.exe
2009-06-22 23:35 . 2009-06-22 23:35 95232 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{55495E65-7C5B-48E4-BC7D-DE54F3DE5ED6}\Installer\CommonCustomActions\pcswpcsi.exe
2009-06-22 23:35 . 2009-06-22 23:35 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{55495E65-7C5B-48E4-BC7D-DE54F3DE5ED6}\Installer\CommonCustomActions\UninstCCD.exe
2009-06-22 23:35 . 2009-06-22 23:35 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{55495E65-7C5B-48E4-BC7D-DE54F3DE5ED6}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-06-22 23:35 . 2009-06-22 23:35 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{55495E65-7C5B-48E4-BC7D-DE54F3DE5ED6}\Installer\CommonCustomActions\UninstPCS.exe
2009-06-20 07:24 . 2009-06-17 00:14 2052888 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-06-17 00:14 . 2009-06-11 00:23 3298072 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\setup.exe
2009-06-17 00:14 . 2009-06-11 00:23 1261344 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgwd.dll
2009-06-17 00:14 . 2009-06-11 00:23 829208 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcfgx.dll
2009-06-15 01:31 . 2009-06-15 01:31 -------- d-----w- c:\program files\SIW
2009-06-14 23:32 . 2009-06-14 23:32 -------- d-----w- c:\program files\Winamp
2009-06-14 11:58 . 2009-06-14 11:58 -------- d-----w- c:\documents and settings\User\Application Data\COWON
2009-06-14 11:52 . 2009-06-14 11:52 -------- d-----w- c:\program files\Common Files\COWON
2009-06-14 11:52 . 2009-06-14 11:52 -------- d-----w- c:\program files\JetAudio
2009-06-11 00:22 . 2009-06-11 00:22 1452312 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.dll
2009-06-10 00:28 . 2009-06-10 00:28 152576 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-24 23:19 . 2007-10-07 01:15 -------- d-----w- c:\documents and settings\User\Application Data\MailWasherPro
2009-06-23 02:48 . 2009-03-11 06:17 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-23 02:38 . 2009-04-22 03:29 3561743 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-23 01:10 . 2007-10-07 03:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-22 23:45 . 2009-06-22 23:45 0 ---ha-w- c:\windows\system32\drivers\Msft_User_PCCSWpdDriver_01_07_00.Wdf
2009-06-22 23:45 . 2009-06-22 23:45 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_user_01_07_00.Wdf
2009-06-22 23:44 . 2008-02-10 08:26 -------- d-----w- c:\documents and settings\User\Application Data\Nokia
2009-06-22 23:38 . 2008-08-22 00:29 -------- d-----w- c:\program files\Common Files\Nokia
2009-06-22 23:37 . 2008-02-10 08:26 -------- d-----w- c:\program files\DIFX
2009-06-22 23:36 . 2008-02-10 08:25 -------- d-----w- c:\program files\Nokia
2009-06-22 23:35 . 2008-02-10 08:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2009-06-17 01:57 . 2009-03-11 06:17 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 01:57 . 2009-03-11 06:17 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-17 00:14 . 2009-01-12 07:19 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-14 11:52 . 2003-05-21 21:28 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-11 00:23 . 2009-01-12 07:19 327688 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-10 00:30 . 2007-10-07 03:15 -------- d-----w- c:\program files\Java
2009-05-21 02:03 . 2009-02-09 23:03 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-05-15 13:15 . 2009-05-15 13:15 -------- d-----w- c:\program files\ANI
2009-05-15 13:14 . 2009-05-15 13:14 -------- d-----w- c:\program files\D-Link
2009-05-15 13:11 . 2009-05-15 13:11 -------- d-----w- c:\documents and settings\User\Application Data\InstallShield
2009-05-15 12:54 . 2009-05-15 12:54 -------- d-----w- c:\documents and settings\All Users\Application Data\InstallShield
2009-05-12 23:34 . 2009-05-12 23:34 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-05-12 23:34 . 2009-05-12 23:34 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstCCD.exe
2009-05-12 23:34 . 2009-05-12 23:34 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCS.exe
2009-05-12 23:33 . 2009-05-12 23:34 34396584 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Nokia_PC_Suite_7_1_26_0_eng.exe
2009-05-11 03:17 . 2009-05-11 03:17 1302600 ----a-w- c:\windows\system32\WUDFUpdate_01007.dll
2009-05-07 15:32 . 2003-05-21 19:03 345600 ----a-w- c:\windows\system32\localspl.dll
2009-04-29 04:46 . 2003-05-21 19:04 666624 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:46 . 2007-10-07 00:23 81920 ------w- c:\windows\system32\ieencode.dll
2009-04-27 00:16 . 2009-01-12 07:19 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-04-27 00:16 . 2009-01-12 07:19 12552 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2009-04-27 00:15 . 2009-01-12 07:19 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-04-26 05:14 . 2009-04-26 05:14 -------- d-----w- c:\program files\CCleaner
2009-04-26 04:34 . 2009-04-26 04:34 -------- d-----w- c:\documents and settings\User\Application Data\TrojanHunter
2009-04-17 12:26 . 2003-05-21 19:04 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2003-05-21 19:04 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-02 23:37 . 2009-04-02 23:37 152576 ----a-w- c:\documents and settings\User\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-06-23_03.37.04 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-09-30 07:15 . 2008-09-30 07:15 91656 c:\windows\WinSxS\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.1.0_x-ww_2a41bceb\msxml4r.dll
+ 2009-06-24 23:09 . 2009-06-24 23:09 16384 c:\windows\Temp\Perflib_Perfdata_e0.dat
+ 2008-11-10 23:47 . 2008-10-16 04:39 43544 c:\windows\system32\wups2.dll
+ 2007-10-07 00:23 . 2008-10-16 04:38 34328 c:\windows\system32\wups.dll
+ 2003-05-21 19:16 . 2008-10-16 04:39 51224 c:\windows\system32\wuauclt.exe
+ 2008-04-24 01:28 . 2008-10-23 10:06 62976 c:\windows\system32\tzchange.exe
- 2008-04-24 01:28 . 2008-07-11 12:42 62976 c:\windows\system32\tzchange.exe
+ 2007-10-07 00:17 . 2008-07-09 07:38 26488 c:\windows\system32\spupdsvc.exe
- 2007-10-07 00:17 . 2007-08-10 11:16 26488 c:\windows\system32\spupdsvc.exe
+ 2009-04-08 02:19 . 2007-11-30 12:39 17272 c:\windows\system32\spmsg.dll
+ 2009-06-23 04:16 . 2008-10-16 04:39 43544 c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.2.6001.788\wups2.dll
+ 2009-06-23 04:16 . 2008-10-16 04:38 34328 c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.2.6001.788\wups.dll
+ 2003-05-21 19:04 . 2009-02-03 19:59 56832 c:\windows\system32\secur32.dll
+ 2003-05-21 19:04 . 2009-02-06 10:39 35328 c:\windows\system32\sc.exe
+ 2003-05-21 19:04 . 2009-06-24 00:20 59900 c:\windows\system32\perfc009.dat
- 2003-05-21 19:04 . 2009-05-21 11:51 59900 c:\windows\system32\perfc009.dat
- 2003-05-21 19:16 . 2008-04-13 20:12 91648 c:\windows\system32\mtxoci.dll
+ 2003-05-21 19:16 . 2008-06-12 14:23 91648 c:\windows\system32\mtxoci.dll
+ 2003-05-21 19:03 . 2008-06-12 14:23 66560 c:\windows\system32\mtxclu.dll
- 2003-05-21 19:03 . 2008-04-13 20:12 66560 c:\windows\system32\mtxclu.dll
+ 2003-05-21 19:16 . 2008-06-12 14:23 58880 c:\windows\system32\msdtclog.dll
- 2003-05-21 19:16 . 2008-04-13 20:12 58880 c:\windows\system32\msdtclog.dll
+ 2007-10-07 00:23 . 2008-10-16 04:38 34328 c:\windows\system32\dllcache\wups.dll
+ 2003-05-21 19:16 . 2008-10-16 04:39 51224 c:\windows\system32\dllcache\wuauclt.exe
+ 2009-02-03 19:59 . 2009-02-03 19:59 56832 c:\windows\system32\dllcache\secur32.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 91648 c:\windows\system32\dllcache\mtxoci.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 66560 c:\windows\system32\dllcache\mtxclu.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 58880 c:\windows\system32\dllcache\msdtclog.dll
+ 2009-04-29 04:46 . 2009-04-29 04:46 81920 c:\windows\system32\dllcache\ieencode.dll
+ 2003-05-21 19:03 . 2008-10-16 04:39 92696 c:\windows\system32\dllcache\cdm.dll
+ 2003-05-21 19:03 . 2008-10-16 04:39 92696 c:\windows\system32\cdm.dll
+ 2004-07-14 13:03 . 2004-07-14 13:03 20480 c:\windows\Microsoft.NET\Framework\v1.0.3705\SHADOW2772\_PerfCounter.dll
+ 2004-07-14 12:20 . 2004-07-14 12:20 69632 c:\windows\Microsoft.NET\Framework\v1.0.3705\SHADOW2772\_mscorsn.dll
+ 2004-07-14 12:20 . 2004-07-14 12:20 69632 c:\windows\Microsoft.NET\Framework\v1.0.3705\SHADOW2772\_CORPerfMonExt.dll
+ 2007-01-15 06:41 . 2007-01-15 06:41 73728 c:\windows\Microsoft.NET\Framework\v1.0.3705\netfxupdate.exe
- 2004-07-14 12:20 . 2004-07-14 12:20 86016 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorld.dll
+ 2007-01-02 06:59 . 2007-01-02 06:59 86016 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorld.dll
+ 2007-01-02 06:59 . 2007-01-02 06:59 73728 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorie.dll
- 2004-07-14 12:20 . 2004-07-14 12:20 73728 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorie.dll
+ 2007-01-02 07:04 . 2007-01-02 07:04 32768 c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_wp.exe
- 2004-07-14 13:06 . 2004-07-14 13:06 32768 c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_wp.exe
+ 2009-06-24 00:02 . 2009-06-24 00:02 32768 c:\windows\Installer\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}\icon.exe
+ 2009-06-24 00:07 . 2009-06-24 00:07 90112 c:\windows\assembly\NativeImages1_v1.0.3705\System.Drawing.Design\1.0.3300.0__b03f5f7f11d50a3a_49d72b4b\System.Drawing.Design.dll
+ 2009-06-24 00:07 . 2009-06-24 00:07 61440 c:\windows\assembly\NativeImages1_v1.0.3705\CustomMarshalers\1.0.3300.0__b03f5f7f11d50a3a_98587074\CustomMarshalers.dll
+ 2007-01-02 06:59 . 2007-01-02 06:59 8192 c:\windows\Microsoft.NET\Framework\v1.0.3705\IEExec.exe
+ 2007-10-07 00:23 . 2008-10-16 04:43 202776 c:\windows\system32\wuweb.dll
+ 2007-10-07 00:23 . 2008-10-16 04:42 323608 c:\windows\system32\wucltui.dll
+ 2007-10-07 00:23 . 2008-10-16 04:42 561688 c:\windows\system32\wuapi.dll
+ 2006-10-18 12:17 . 2008-06-24 08:42 295936 c:\windows\system32\wmpeffects.dll
- 2006-10-18 12:17 . 2006-10-18 12:17 295936 c:\windows\system32\wmpeffects.dll
+ 2003-05-21 21:27 . 2008-06-17 19:33 938496 c:\windows\system32\WMNetmgr.dll
+ 2003-05-21 21:27 . 2007-10-27 08:10 222720 c:\windows\system32\wmasf.dll
- 2003-05-21 19:04 . 2008-04-13 20:12 354304 c:\windows\system32\winhttp.dll
+ 2003-05-21 19:04 . 2008-12-16 12:30 354304 c:\windows\system32\winhttp.dll
+ 2008-09-05 12:59 . 2009-03-10 12:48 934792 c:\windows\system32\WgaTray.exe
+ 2008-09-05 13:00 . 2009-03-10 12:48 239496 c:\windows\system32\WgaLogon.dll
+ 2003-05-21 19:16 . 2009-02-06 10:10 227840 c:\windows\system32\wbem\wmiprvse.exe
+ 2003-05-21 19:16 . 2009-02-09 12:10 453120 c:\windows\system32\wbem\wmiprvsd.dll
+ 2003-05-21 19:16 . 2009-02-09 12:10 473600 c:\windows\system32\wbem\fastprox.dll
+ 2003-02-09 00:24 . 2009-04-29 04:46 620032 c:\windows\system32\urlmon.dll
+ 2003-05-21 19:04 . 2008-10-03 10:02 247326 c:\windows\system32\strmdll.dll
+ 2003-05-21 19:04 . 2009-02-06 11:11 110592 c:\windows\system32\services.exe
+ 2003-05-21 19:04 . 2008-12-05 06:54 144896 c:\windows\system32\schannel.dll
+ 2003-05-21 19:04 . 2009-02-09 12:10 401408 c:\windows\system32\rpcss.dll
+ 2003-05-21 19:04 . 2009-06-24 00:20 396208 c:\windows\system32\perfh009.dat
- 2003-05-21 19:04 . 2009-05-21 11:51 396208 c:\windows\system32\perfh009.dat
+ 2003-05-21 19:04 . 2009-03-06 14:22 284160 c:\windows\system32\pdh.dll
- 2003-05-21 19:04 . 2008-04-13 20:12 284160 c:\windows\system32\pdh.dll
+ 2003-05-21 19:03 . 2009-02-09 12:10 714752 c:\windows\system32\ntdll.dll
+ 2003-05-21 19:03 . 2008-06-20 17:46 245248 c:\windows\system32\mswsock.dll
- 2003-05-21 19:03 . 2008-04-13 20:12 245248 c:\windows\system32\mswsock.dll
+ 2003-05-21 21:22 . 2006-12-04 06:51 414720 c:\windows\system32\msscp.dll
- 2003-05-21 19:16 . 2008-04-13 20:12 161792 c:\windows\system32\msdtcuiu.dll
+ 2003-05-21 19:16 . 2008-06-12 14:23 161792 c:\windows\system32\msdtcuiu.dll
- 2003-05-21 19:16 . 2008-04-13 20:12 956928 c:\windows\system32\msdtctm.dll
+ 2003-05-21 19:16 . 2008-06-12 14:23 956928 c:\windows\system32\msdtctm.dll
+ 2003-05-21 19:16 . 2008-06-12 14:23 428032 c:\windows\system32\msdtcprx.dll
+ 2003-05-21 19:03 . 2009-02-09 12:10 729088 c:\windows\system32\lsasrv.dll
- 2003-05-21 21:27 . 2006-10-18 10:33 100864 c:\windows\system32\logagent.exe
+ 2003-05-21 21:27 . 2008-06-17 15:39 100864 c:\windows\system32\logagent.exe
- 2003-05-21 19:03 . 2008-04-13 20:11 989696 c:\windows\system32\kernel32.dll
+ 2003-05-21 19:03 . 2009-03-21 14:06 989696 c:\windows\system32\kernel32.dll
+ 2003-05-21 19:03 . 2008-10-23 12:36 286720 c:\windows\system32\gdi32.dll
- 2003-05-21 12:10 . 2008-11-11 00:12 241536 c:\windows\system32\FNTCACHE.DAT
+ 2003-05-21 12:10 . 2009-06-24 00:15 241536 c:\windows\system32\FNTCACHE.DAT
+ 2003-05-21 19:04 . 2008-06-20 11:08 225856 c:\windows\system32\drivers\tcpip6.sys
+ 2003-05-21 19:04 . 2008-06-20 11:51 361600 c:\windows\system32\drivers\tcpip.sys
+ 2003-05-21 19:04 . 2008-12-11 10:57 333952 c:\windows\system32\drivers\srv.sys
+ 2003-05-21 19:03 . 2008-10-24 11:21 455296 c:\windows\system32\drivers\mrxsmb.sys
+ 2003-05-21 19:03 . 2008-06-20 17:46 147968 c:\windows\system32\dnsapi.dll
- 2003-05-21 19:03 . 2008-04-13 20:11 147968 c:\windows\system32\dnsapi.dll
+ 2007-10-07 00:23 . 2008-10-16 04:43 202776 c:\windows\system32\dllcache\wuweb.dll
+ 2007-10-07 00:23 . 2008-10-16 04:42 323608 c:\windows\system32\dllcache\wucltui.dll
+ 2007-10-07 00:23 . 2008-10-16 04:42 561688 c:\windows\system32\dllcache\wuapi.dll
+ 2008-04-24 01:24 . 2008-06-17 19:33 938496 c:\windows\system32\dllcache\WMNetmgr.dll
+ 2008-04-24 01:24 . 2007-10-27 08:10 222720 c:\windows\system32\dllcache\wmasf.dll
+ 2008-08-20 05:30 . 2009-04-29 04:46 666624 c:\windows\system32\dllcache\wininet.dll
+ 2008-12-16 12:30 . 2008-12-16 12:30 354304 c:\windows\system32\dllcache\winhttp.dll
+ 2008-09-05 12:59 . 2009-03-10 12:48 934792 c:\windows\system32\dllcache\WgaTray.exe
+ 2008-09-05 13:00 . 2009-03-10 12:48 239496 c:\windows\system32\dllcache\wgaLogon.dll
+ 2008-08-20 05:30 . 2009-04-29 04:46 620032 c:\windows\system32\dllcache\urlmon.dll
+ 2008-04-24 01:24 . 2007-06-26 12:40 317440 c:\windows\system32\dllcache\unregmp2.exe
+ 2008-06-20 11:08 . 2008-06-20 11:08 225856 c:\windows\system32\dllcache\tcpip6.sys
+ 2008-06-20 11:51 . 2008-06-20 11:51 361600 c:\windows\system32\dllcache\tcpip.sys
+ 2008-04-24 01:24 . 2008-10-03 10:02 247326 c:\windows\system32\dllcache\strmdll.dll
+ 2008-11-11 00:01 . 2008-12-11 10:57 333952 c:\windows\system32\dllcache\srv.sys
+ 2008-12-05 06:54 . 2008-12-05 06:54 144896 c:\windows\system32\dllcache\schannel.dll
+ 2009-04-15 14:51 . 2009-04-15 14:51 585216 c:\windows\system32\dllcache\rpcrt4.dll
+ 2008-06-20 17:46 . 2008-06-20 17:46 245248 c:\windows\system32\dllcache\mswsock.dll
+ 2008-04-24 01:24 . 2006-12-04 06:51 414720 c:\windows\system32\dllcache\msscp.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 161792 c:\windows\system32\dllcache\msdtcuiu.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 956928 c:\windows\system32\dllcache\msdtctm.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 428032 c:\windows\system32\dllcache\msdtcprx.dll
- 2008-04-24 01:24 . 2006-10-18 10:33 100864 c:\windows\system32\dllcache\logagent.exe
+ 2008-04-24 01:24 . 2008-06-17 15:39 100864 c:\windows\system32\dllcache\logagent.exe
+ 2009-05-07 15:32 . 2009-05-07 15:32 345600 c:\windows\system32\dllcache\localspl.dll
+ 2009-03-21 14:06 . 2009-03-21 14:06 989696 c:\windows\system32\dllcache\kernel32.dll
+ 2008-10-23 12:36 . 2008-10-23 12:36 286720 c:\windows\system32\dllcache\gdi32.dll
+ 2008-06-20 17:46 . 2008-06-20 17:46 147968 c:\windows\system32\dllcache\dnsapi.dll
- 2003-05-21 19:03 . 2008-04-13 20:11 617472 c:\windows\system32\advapi32.dll
+ 2003-05-21 19:03 . 2009-02-09 12:10 617472 c:\windows\system32\advapi32.dll
+ 2002-01-05 10:37 . 2002-01-05 10:37 344064 c:\windows\Microsoft.NET\Framework\v1.0.3705\SHADOW2772\_msvcr70.dll
+ 2004-07-14 12:18 . 2004-07-14 12:18 303104 c:\windows\Microsoft.NET\Framework\v1.0.3705\SHADOW2772\_mscorjit.dll
+ 2004-07-14 12:18 . 2004-07-14 12:18 233472 c:\windows\Microsoft.NET\Framework\v1.0.3705\SHADOW2772\_fusion.dll
+ 2004-07-14 13:06 . 2004-07-14 13:06 200704 c:\windows\Microsoft.NET\Framework\v1.0.3705\SHADOW2772\_aspnet_isapi.dll
- 2004-07-14 13:06 . 2004-07-14 13:06 200704 c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_isapi.dll
+ 2007-01-02 07:04 . 2007-01-02 07:04 200704 c:\windows\Microsoft.NET\Framework\v1.0.3705\aspnet_isapi.dll
+ 2003-05-21 21:22 . 2007-06-26 12:40 317440 c:\windows\inf\unregmp2.exe
+ 2009-06-23 04:23 . 2008-10-24 11:21 455296 c:\windows\Driver Cache\i386\mrxsmb.sys
+ 2009-06-24 00:07 . 2009-06-24 00:07 847872 c:\windows\assembly\NativeImages1_v1.0.3705\System.Drawing\1.0.3300.0__b03f5f7f11d50a3a_009bd04c\System.Drawing.dll
+ 2008-09-30 07:12 . 2008-09-30 07:12 1286152 c:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9870.0_x-ww_a32d74cf\msxml4.dll
+ 2003-05-21 19:16 . 2008-10-16 04:43 1809944 c:\windows\system32\wuaueng.dll
+ 2003-05-21 21:27 . 2008-06-17 19:33 2458112 c:\windows\system32\WMVCore.dll
- 2002-11-27 18:50 . 2008-04-13 20:12 8461312 c:\windows\system32\shell32.dll
+ 2002-11-27 18:50 . 2008-06-17 19:02 8461312 c:\windows\system32\shell32.dll
- 2003-01-07 23:37 . 2008-08-20 05:30 1499136 c:\windows\system32\shdocvw.dll
+ 2003-01-07 23:37 . 2009-04-29 04:46 1499136 c:\windows\system32\shdocvw.dll
+ 2002-12-12 07:14 . 2008-12-20 22:14 1288192 c:\windows\system32\quartz.dll
- 2002-12-12 07:14 . 2008-05-07 05:12 1288192 c:\windows\system32\quartz.dll
+ 2003-05-21 19:03 . 2009-02-06 11:08 2189056 c:\windows\system32\ntoskrnl.exe
- 2002-08-29 01:04 . 2008-08-14 09:33 2066048 c:\windows\system32\ntkrnlpa.exe
+ 2002-08-29 01:04 . 2009-02-07 09:32 2066048 c:\windows\system32\ntkrnlpa.exe
+ 2008-04-24 01:29 . 2008-09-10 01:14 1307648 c:\windows\system32\msxml6.dll
+ 2008-09-30 07:13 . 2008-09-30 07:13 1286152 c:\windows\system32\msxml4.dll
+ 2003-05-21 19:03 . 2008-09-04 17:15 1106944 c:\windows\system32\msxml3.dll
+ 2002-12-02 17:06 . 2009-04-29 04:46 3068928 c:\windows\system32\mshtml.dll
+ 2008-03-20 07:36 . 2009-03-10 12:48 1482112 c:\windows\system32\LegitCheckControl.dll
+ 2003-05-21 19:16 . 2008-10-16 04:43 1809944 c:\windows\system32\dllcache\wuaueng.dll
+ 2008-04-24 01:24 . 2008-06-17 19:33 2458112 c:\windows\system32\dllcache\WMVCore.dll
+ 2008-11-11 00:00 . 2009-04-17 12:26 1847168 c:\windows\system32\dllcache\win32k.sys
+ 2008-06-17 19:02 . 2008-06-17 19:02 8461312 c:\windows\system32\dllcache\shell32.dll
- 2008-08-20 05:30 . 2008-08-20 05:30 1499136 c:\windows\system32\dllcache\shdocvw.dll
+ 2008-08-20 05:30 . 2009-04-29 04:46 1499136 c:\windows\system32\dllcache\shdocvw.dll
- 2008-05-07 05:12 . 2008-05-07 05:12 1288192 c:\windows\system32\dllcache\quartz.dll
+ 2008-05-07 05:12 . 2008-12-20 22:14 1288192 c:\windows\system32\dllcache\quartz.dll
+ 2008-11-11 00:01 . 2009-02-06 11:08 2189056 c:\windows\system32\dllcache\ntoskrnl.exe
- 2008-11-11 00:01 . 2008-08-14 09:33 2023936 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2008-11-11 00:01 . 2009-02-06 10:32 2023936 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2008-11-11 00:01 . 2009-02-07 09:32 2066048 c:\windows\system32\dllcache\ntkrnlpa.exe
- 2008-11-11 00:01 . 2008-08-14 09:33 2066048 c:\windows\system32\dllcache\ntkrnlpa.exe
+ 2008-11-11 00:01 . 2009-02-06 11:06 2145280 c:\windows\system32\dllcache\ntkrnlmp.exe
- 2008-11-11 00:01 . 2008-08-14 10:09 2145280 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2008-04-24 01:29 . 2008-09-10 01:14 1307648 c:\windows\system32\dllcache\msxml6.dll
+ 2008-08-20 05:30 . 2009-04-29 04:46 3068928 c:\windows\system32\dllcache\mshtml.dll
- 2004-07-15 00:35 . 2004-07-15 00:35 1200128 c:\windows\Microsoft.NET\Framework\v1.0.3705\System.Web.dll
+ 2007-01-02 07:10 . 2007-01-02 07:10 1200128 c:\windows\Microsoft.NET\Framework\v1.0.3705\System.Web.dll
+ 2004-07-14 12:19 . 2004-07-14 12:19 2269184 c:\windows\Microsoft.NET\Framework\v1.0.3705\SHADOW2772\_mscorwks.dll
+ 2004-07-14 12:19 . 2004-07-14 12:19 2265088 c:\windows\Microsoft.NET\Framework\v1.0.3705\SHADOW2772\_mscorsvr.dll
+ 2004-07-15 00:35 . 2004-07-15 00:35 1998848 c:\windows\Microsoft.NET\Framework\v1.0.3705\SHADOW2772\_mscorlib.dll
+ 2007-01-02 06:58 . 2007-01-02 06:58 2281472 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
+ 2007-01-02 06:58 . 2007-01-02 06:58 2273280 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorsvr.dll
+ 2007-01-02 06:51 . 2007-01-02 06:51 1998848 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorlib.dll
- 2004-07-15 00:35 . 2004-07-15 00:35 1998848 c:\windows\Microsoft.NET\Framework\v1.0.3705\mscorlib.dll
+ 2003-05-21 21:17 . 2006-08-21 06:27 1077321 c:\windows\Help\SBSI\Training\orun32.exe
+ 2008-11-11 00:01 . 2009-02-06 11:08 2189056 c:\windows\Driver Cache\i386\ntoskrnl.exe
- 2008-11-11 00:01 . 2008-08-14 09:33 2023936 c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2008-11-11 00:01 . 2009-02-06 10:32 2023936 c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2008-11-11 00:01 . 2008-08-14 09:33 2066048 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2008-11-11 00:01 . 2009-02-07 09:32 2066048 c:\windows\Driver Cache\i386\ntkrnlpa.exe
- 2008-11-11 00:01 . 2008-08-14 10:09 2145280 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2008-11-11 00:01 . 2009-02-06 11:06 2145280 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2009-06-24 00:07 . 2009-06-24 00:07 1855488 c:\windows\assembly\NativeImages1_v1.0.3705\System\1.0.3300.0__b77a5c561934e089_3de4633b\System.dll
+ 2009-06-24 00:07 . 2009-06-24 00:07 2027520 c:\windows\assembly\NativeImages1_v1.0.3705\System.Xml\1.0.3300.0__b77a5c561934e089_0ee7e37c\System.Xml.dll
+ 2009-06-24 00:07 . 2009-06-24 00:07 2953216 c:\windows\assembly\NativeImages1_v1.0.3705\System.Windows.Forms\1.0.3300.0__b77a5c561934e089_6e9d5b16\System.Windows.Forms.dll
+ 2009-06-24 00:07 . 2009-06-24 00:07 1454080 c:\windows\assembly\NativeImages1_v1.0.3705\System.Design\1.0.3300.0__b03f5f7f11d50a3a_3f1b915f\System.Design.dll
+ 2009-06-24 00:07 . 2009-06-24 00:07 3301376 c:\windows\assembly\NativeImages1_v1.0.3705\mscorlib\1.0.3300.0__b77a5c561934e089_d530e96e\mscorlib.dll
+ 2009-06-24 00:07 . 2009-06-24 00:07 1200128 c:\windows\assembly\GAC\System.Web\1.0.3300.0__b03f5f7f11d50a3a\System.Web.dll
- 2008-11-11 00:03 . 2008-11-11 00:03 1200128 c:\windows\assembly\GAC\System.Web\1.0.3300.0__b03f5f7f11d50a3a\System.Web.dll
+ 2003-05-21 21:22 . 2008-11-11 09:04 10838016 c:\windows\system32\wmp.dll
+ 2008-11-11 00:07 . 2009-06-01 00:21 23635392 c:\windows\system32\MRT.exe
+ 2008-04-24 01:29 . 2008-11-11 09:04 10838016 c:\windows\system32\dllcache\wmp.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-06-12 1414144]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2003-04-06 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2003-04-06 114688]
"PmProxy"="c:\program files\Analog Devices\SoundMAX\PmProxy.exe" [2003-02-28 40960]
"00THotkey"="c:\windows\System32\00THotkey.exe" [2003-04-16 258048]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2002-12-25 159744]
"TouchED"="c:\program files\TOSHIBA\TouchED\TouchED.Exe" [2003-01-22 126976]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-28 286720]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2004-04-14 57393]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2004-04-14 40960]
"ControlCenter2.0"="c:\program files\Brother\ControlCenter2\brctrcen.exe" [2004-07-20 851968]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-11 1948440]
"PRISMSVR.EXE"="c:\windows\system32\PRISMSVR.EXE" [2005-04-12 368726]
"D-Link AirPlus XtremeG DWL-G122"="c:\program files\D-Link\AirPlus XtremeG DWL-G122\AirGCFG.exe" [2008-12-18 1556480]
"ANIWZCS2Service"="c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2007-01-19 49152]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"000StTHK"="000StTHK.exe" - c:\windows\system32\000StTHK.exe [2001-06-24 24576]
"TFNF5"="TFNF5.exe" - c:\windows\system32\TFNF5.exe [2001-08-03 73728]
"Tpwrtray"="TPWRTRAY.EXE" - c:\windows\system32\TPWRTRAY.EXE [2002-12-10 237568]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\agrsmmsg.exe [2003-04-18 88363]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2003-5-22 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-04-27 00:16 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PRISMGNA.DLL]
2005-04-12 15:02 233558 ----a-w- c:\windows\system32\PRISMGNA.DLL
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SpeedTouch 121g Wireless USB Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\SpeedTouch 121g Wireless USB Monitor.lnk
backup=c:\windows\pss\SpeedTouch 121g Wireless USB Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"c:\\Program Files\\Common Files\\Nokia\\Service Layer\\A\\nsl_host_process.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [12/01/2009 4:49 PM 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [12/01/2009 4:49 PM 327688]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [12/01/2009 4:49 PM 108552]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [12/01/2009 4:48 PM 298776]
R2 PRISMSVC;PRISMSVC;c:\windows\system32\PRISMSVC.exe [13/04/2005 12:30 AM 61526]
S3 BT4501G;SpeedTouch 121g Wireless USB Adapter Driver;c:\windows\system32\drivers\BT4501G.sys [21/03/2009 12:06 PM 357568]
S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\windows\system32\DNINDIS5.SYS [24/11/2007 10:46 AM 17149]
S3 NETGEAR NETGEAR MA101 USB Adapter(A);NETGEAR NETGEAR MA101 USB Adapter(A) Service for NETGEAR MA101 USB Adapter;c:\windows\system32\DRIVERS\ma1012ka.sys --> c:\windows\system32\DRIVERS\ma1012ka.sys [?]
S3 UltraMonMirror;UltraMonMirror;c:\windows\system32\DRIVERS\UltraMonMirror.sys --> c:\windows\system32\DRIVERS\UltraMonMirror.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2009-04-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-06-03 04:12]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.bigpond.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-06-25 09:07
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(644)
c:\windows\system32\PRISMGNA.DLL
- - - - - - - > 'explorer.exe'(3456)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-06-24 9:10
ComboFix-quarantined-files.txt 2009-06-24 23:40
Pre-Run: 65,848,713,216 bytes free
Post-Run: 65,830,793,216 bytes free
385 --- E O F --- 2009-06-24 00:14