Completed all requested tasks; Kaspersky Online Scanner report, new dds.txt log and ComboFix log follow.
> How's the system running?
Most excellent! I'm hoping that it really is clean now...
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0 REPORT
Thursday, April 30, 2009
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Friday, May 01, 2009 02:26:58
Records in database: 2115735
--------------------------------------------------------------------------------
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
C:\
D:\
U:\
Scan statistics:
Files scanned: 69078
Threat name: 0
Infected objects: 0
Suspicious objects: 0
Duration of the scan: 02:09:53
No malware has been detected. The scan area is clean.
The selected area was scanned.
dds.txt log
------------
DDS (Ver_09-03-16.01) - NTFSx86
Run by TW at 22:21:12.81 on Thu 04/30/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.894.502 [GMT -7:00]
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\UPHClean\uphclean.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\CPal\CPBrWtch.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\CPal\CPal.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\TW\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: RoboForm: {724d43a9-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &RoboForm: {724d43a0-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\roboform.dll
uRun: [RoboForm] "c:\program files\siber systems\ai roboform\RoboTaskBarIcon.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [Cookie Pal] "c:\program files\cpal\CPBrWtch.exe"
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [EPSON Stylus CX6600 Series] c:\windows\system32\spool\drivers\w32x86\3\E_FATI9EA.EXE /P26 "EPSON Stylus CX6600 Series" /O6 "USB001" /M "Stylus CX6600"
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1229373649531
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1229371973000
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath -
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-4-30 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-12-4 325640]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-12-4 27656]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-4-26 298264]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-3-9 953168]
=============== Created Last 30 ================
2009-04-30 11:29 64,160 a------- c:\windows\system32\drivers\Lbd.sys
2009-04-30 11:27 <DIR> --d----- c:\docume~1\tw\applic~1\Foxit
2009-04-30 11:27 <DIR> --d----- c:\program files\Foxit Software
2009-04-30 11:20 <DIR> -cd-h--- c:\docume~1\alluse~1\applic~1\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-04-30 11:20 <DIR> --d----- c:\program files\Lavasoft
2009-04-30 10:49 <DIR> --d----- C:\ComboFix
2009-04-30 01:23 <DIR> --d----- c:\docume~1\tw\applic~1\OpenOffice.org
2009-04-30 01:18 <DIR> --d----- c:\program files\OpenOffice.org 3
2009-04-30 01:14 73,728 a------- c:\windows\system32\javacpl.cpl
2009-04-29 11:52 <DIR> a-dshr-- C:\cmdcons
2009-04-29 11:50 161,792 a------- c:\windows\SWREG.exe
2009-04-29 11:50 98,816 a------- c:\windows\sed.exe
2009-04-27 12:35 1,089,593 -c------ c:\windows\system32\dllcache\ntprint.cat
2009-04-26 23:08 <DIR> --d-h--- C:\$AVG8.VAULT$
2009-04-26 23:02 10,520 a------- c:\windows\system32\avgrsstx.dll
2009-04-26 20:48 597,504 -c------ c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-04-26 20:48 575,488 -c------ c:\windows\system32\dllcache\xpsshhdr.dll
2009-04-26 20:48 89,088 -c------ c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-04-26 20:48 575,488 -------- c:\windows\system32\xpsshhdr.dll
2009-04-26 20:48 117,760 -------- c:\windows\system32\prntvpt.dll
2009-04-26 20:48 1,676,288 -c------ c:\windows\system32\dllcache\xpssvcs.dll
2009-04-26 20:48 1,676,288 -------- c:\windows\system32\xpssvcs.dll
2009-04-26 20:29 <DIR> --d----- c:\program files\Windows Media Connect 2
2009-04-26 20:27 <DIR> --d----- c:\windows\system32\LogFiles
2009-04-26 20:26 <DIR> --d----- c:\windows\system32\URTTEMP
2009-04-26 20:17 331,776 -c------ c:\windows\system32\dllcache\msadce.dll
2009-04-26 20:08 <DIR> --dsh--- c:\documents and settings\tw\PrivacIE
2009-04-26 20:08 <DIR> --dsh--- c:\documents and settings\tw\IECompatCache
2009-04-26 20:04 <DIR> --dsh--- c:\documents and settings\tw\IETldCache
2009-04-26 20:02 <DIR> --d----- c:\windows\ie8updates
2009-04-26 19:59 <DIR> -cd-h--- c:\windows\ie8
2009-04-26 19:57 105,984 -c------ c:\windows\system32\dllcache\iecompat.dll
2009-04-26 18:58 <DIR> --d-h--- c:\windows\system32\GroupPolicy
2009-04-26 17:45 138 a------- c:\windows\wininit.ini
2009-04-26 16:04 221,184 a------- c:\windows\system32\wmpns.dll
==================== Find3M ====================
2009-04-30 01:13 410,984 a------- c:\windows\system32\deploytk.dll
2009-04-26 23:02 325,640 a------- c:\windows\system32\drivers\avgldx86.sys
2009-04-26 21:26 15,472 a------- c:\windows\system32\GDIPFONTCACHEV1.DAT
2009-04-20 21:09 14,336 a------- c:\windows\system32\svchost.exe
2009-03-08 04:34 914,944 a------- c:\windows\system32\wininet.dll
2009-03-08 04:34 43,008 a------- c:\windows\system32\licmgr10.dll
2009-03-08 04:33 18,944 a------- c:\windows\system32\corpol.dll
2009-03-08 04:33 420,352 a------- c:\windows\system32\vbscript.dll
2009-03-08 04:32 72,704 a------- c:\windows\system32\admparse.dll
2009-03-08 04:32 71,680 a------- c:\windows\system32\iesetup.dll
2009-03-08 04:31 34,816 a------- c:\windows\system32\imgutil.dll
2009-03-08 04:31 48,128 a------- c:\windows\system32\mshtmler.dll
2009-03-08 04:31 45,568 a------- c:\windows\system32\mshta.exe
2009-03-08 04:22 156,160 a------- c:\windows\system32\msls31.dll
2009-03-06 07:22 284,160 a------- c:\windows\system32\pdh.dll
2009-02-09 05:10 729,088 a------- c:\windows\system32\lsasrv.dll
2009-02-09 05:10 714,752 a------- c:\windows\system32\ntdll.dll
2009-02-09 05:10 617,472 a------- c:\windows\system32\advapi32.dll
2009-02-09 05:10 401,408 a------- c:\windows\system32\rpcss.dll
2009-02-09 04:13 1,846,784 a------- c:\windows\system32\win32k.sys
2009-02-07 19:02 2,066,048 a------- c:\windows\system32\ntkrnlpa.exe
2009-02-06 04:11 110,592 a------- c:\windows\system32\services.exe
2009-02-06 04:08 2,189,056 a------- c:\windows\system32\ntoskrnl.exe
2009-02-06 03:39 35,328 a------- c:\windows\system32\sc.exe
2009-02-03 12:59 56,832 a------- c:\windows\system32\secur32.dll
============= FINISH: 22:22:36.17 ===============
ComboFix log
---------------
ComboFix 09-04-29.07 - TW 04/30/2009 10:50.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.894.518 [GMT -7:00]
Running from: c:\documents and settings\TW\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\TW\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point
FILE ::
c:\windows\Dyufulej.dat
c:\windows\Kneniredoxirakip.bin
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\TW\Local Settings\Application Data\{D1F81526-328C-4EFD-8C9B-9B9E28E1AF58}
c:\documents and settings\TW\Local Settings\Application Data\{D1F81526-328C-4EFD-8C9B-9B9E28E1AF58}\chrome.manifest
c:\documents and settings\TW\Local Settings\Application Data\{D1F81526-328C-4EFD-8C9B-9B9E28E1AF58}\chrome\content\_cfg.js
c:\documents and settings\TW\Local Settings\Application Data\{D1F81526-328C-4EFD-8C9B-9B9E28E1AF58}\chrome\content\c.js
c:\documents and settings\TW\Local Settings\Application Data\{D1F81526-328C-4EFD-8C9B-9B9E28E1AF58}\chrome\content\overlay.xul
c:\documents and settings\TW\Local Settings\Application Data\{D1F81526-328C-4EFD-8C9B-9B9E28E1AF58}\install.rdf
c:\windows\Dyufulej.dat
c:\windows\Kneniredoxirakip.bin
.
((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-4-30 )))))))))))))))))))))))))))))))
.
2009-04-30 08:23 . 2009-04-30 08:23 -------- d-----w c:\documents and settings\TW\Application Data\OpenOffice.org
2009-04-30 08:18 . 2009-04-30 08:18 -------- d-----w c:\program files\OpenOffice.org 3
2009-04-27 22:52 . 2009-04-27 22:52 -------- d-sh--w c:\documents and settings\LocalService\IETldCache
2009-04-27 17:52 . 2009-04-27 17:52 -------- d-----w c:\program files\ERUNT
2009-04-27 06:08 . 2009-04-29 22:39 -------- d--h--w C:\$AVG8.VAULT$
2009-04-27 06:02 . 2009-04-27 06:02 10520 ----a-w c:\windows\system32\avgrsstx.dll
2009-04-27 04:46 . 2009-04-27 04:46 -------- d-----w c:\documents and settings\TW\Local Settings\Application Data\ApplicationHistory
2009-04-27 03:55 . 2009-04-27 03:55 -------- d-----w c:\program files\Microsoft Silverlight
2009-04-27 03:48 . 2008-07-06 12:06 117760 ------w c:\windows\system32\prntvpt.dll
2009-04-27 03:48 . 2008-07-06 12:06 89088 -c----w c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-04-27 03:48 . 2008-07-06 10:50 597504 -c----w c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-04-27 03:48 . 2008-07-06 12:06 575488 -c----w c:\windows\system32\dllcache\xpsshhdr.dll
2009-04-27 03:48 . 2008-07-06 12:06 575488 ------w c:\windows\system32\xpsshhdr.dll
2009-04-27 03:48 . 2008-07-06 12:06 1676288 -c----w c:\windows\system32\dllcache\xpssvcs.dll
2009-04-27 03:48 . 2008-07-06 12:06 1676288 ------w c:\windows\system32\xpssvcs.dll
2009-04-27 03:29 . 2009-04-27 03:29 -------- d-----w c:\program files\Windows Media Connect 2
2009-04-27 03:27 . 2009-04-27 03:27 -------- d-----w c:\windows\system32\LogFiles
2009-04-27 03:26 . 2009-04-27 03:26 -------- d-----w c:\windows\system32\URTTEMP
2009-04-27 03:24 . 2009-03-06 14:22 284160 -c----w c:\windows\system32\dllcache\pdh.dll
2009-04-27 03:24 . 2009-02-09 12:10 401408 -c----w c:\windows\system32\dllcache\rpcss.dll
2009-04-27 03:24 . 2009-02-06 11:11 110592 -c----w c:\windows\system32\dllcache\services.exe
2009-04-27 03:24 . 2009-02-09 12:10 473600 -c----w c:\windows\system32\dllcache\fastprox.dll
2009-04-27 03:24 . 2009-02-06 10:10 227840 -c----w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-27 03:24 . 2009-02-09 12:10 453120 -c----w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-27 03:24 . 2009-02-09 12:10 729088 -c----w c:\windows\system32\dllcache\lsasrv.dll
2009-04-27 03:24 . 2009-02-09 12:10 617472 -c----w c:\windows\system32\dllcache\advapi32.dll
2009-04-27 03:24 . 2009-02-09 12:10 714752 -c----w c:\windows\system32\dllcache\ntdll.dll
2009-04-27 03:24 . 2008-05-03 11:55 2560 ------w c:\windows\system32\xpsp4res.dll
2009-04-27 03:24 . 2008-04-21 12:08 215552 -c----w c:\windows\system32\dllcache\wordpad.exe
2009-04-27 03:17 . 2008-05-01 14:33 331776 -c----w c:\windows\system32\dllcache\msadce.dll
2009-04-27 03:08 . 2009-04-27 03:08 -------- d-sh--w c:\documents and settings\TW\PrivacIE
2009-04-27 03:08 . 2009-04-27 03:08 -------- d-sh--w c:\documents and settings\TW\IECompatCache
2009-04-27 03:04 . 2009-04-27 03:04 -------- d-sh--w c:\documents and settings\TW\IETldCache
2009-04-27 03:02 . 2009-04-27 03:02 -------- d-----w c:\windows\ie8updates
2009-04-27 02:59 . 2009-04-27 03:01 -------- dc-h--w c:\windows\ie8
2009-04-27 02:57 . 2009-02-28 04:55 105984 -c----w c:\windows\system32\dllcache\iecompat.dll
2009-04-27 01:58 . 2009-04-27 01:58 -------- d--h--w c:\windows\system32\GroupPolicy
2009-04-26 23:04 . 2009-04-26 23:40 -------- d-----w c:\documents and settings\Administrator
2009-04-21 04:21 . 2009-04-26 22:47 -------- d-----w c:\documents and settings\TW\Local Settings\Application Data\{F4F8E28E-5934-4361-B5A6-886343DEE4A1}
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-30 08:13 . 2008-12-10 23:36 410984 ----a-w c:\windows\system32\deploytk.dll
2009-04-27 06:02 . 2008-12-04 09:14 325640 ----a-w c:\windows\system32\drivers\avgldx86.sys
2009-04-27 05:41 . 2008-12-04 08:57 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-04-27 04:26 . 2008-12-04 09:25 15472 ----a-w c:\windows\system32\GDIPFONTCACHEV1.DAT
2009-04-26 22:48 . 2009-02-24 05:50 -------- d-----w c:\program files\TaxCut08
2009-04-26 22:48 . 2008-12-04 09:59 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-26 22:48 . 2009-03-15 05:02 -------- d-----w c:\program files\Amazon
2009-04-21 04:09 . 2004-08-04 12:00 14336 ----a-w c:\windows\system32\svchost.exe
2009-03-22 22:05 . 2009-02-24 05:52 -------- d-----w c:\program files\DeductionPro 2008
2009-03-12 22:01 . 2009-03-12 22:01 125 ----a-w c:\documents and settings\TW\Local Settings\Application Data\fusioncache.dat
2009-03-12 20:41 . 2008-12-04 09:17 -------- d-----w c:\program files\Kyodai
2009-03-12 20:39 . 2008-12-04 08:54 -------- d-----w c:\program files\Eraser
2009-03-12 06:32 . 2009-03-12 06:32 -------- d-----w c:\program files\MSBuild
2009-03-12 06:32 . 2009-03-12 06:32 -------- d-----w c:\program files\Reference Assemblies
2009-03-08 11:34 . 2004-08-04 12:00 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 11:34 . 2004-08-04 12:00 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 11:33 . 2004-08-04 12:00 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 11:33 . 2004-08-04 12:00 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 11:32 . 2004-08-04 12:00 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 11:32 . 2004-08-04 12:00 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 11:31 . 2004-08-04 12:00 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 11:31 . 2004-08-04 12:00 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 11:31 . 2004-08-04 12:00 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 11:22 . 2004-08-04 12:00 156160 ----a-w c:\windows\system32\msls31.dll
2009-03-07 22:20 . 2009-03-07 22:20 -------- d-----w c:\program files\PDF995
2009-03-07 20:34 . 2009-03-05 20:02 -------- d-----w c:\program files\BOWEP
2009-03-06 14:22 . 2004-08-04 12:00 284160 ----a-w c:\windows\system32\pdh.dll
2009-02-09 12:10 . 2004-08-04 12:00 729088 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2004-08-04 12:00 714752 ----a-w c:\windows\system32\ntdll.dll
2009-02-09 12:10 . 2004-08-04 12:00 617472 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 12:10 . 2004-08-04 12:00 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 11:13 . 2004-08-04 12:00 1846784 ----a-w c:\windows\system32\win32k.sys
2009-02-08 02:02 . 2004-08-03 22:59 2066048 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-06 11:11 . 2004-08-04 12:00 110592 ----a-w c:\windows\system32\services.exe
2009-02-06 11:08 . 2004-08-04 12:00 2189056 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2004-08-04 12:00 35328 ----a-w c:\windows\system32\sc.exe
2009-02-03 19:59 . 2004-08-04 12:00 56832 ----a-w c:\windows\system32\secur32.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-04-29_18.58.01 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-12-04 09:17 . 2009-04-29 20:23 88590 c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
+ 2009-04-29 20:31 . 2009-04-29 20:31 78487 c:\windows\system32\Adobe\uninstaller.exe
+ 2009-03-19 15:15 . 2009-03-19 15:15 58736 c:\windows\system32\Adobe\Shockwave 11\SYMCCHECKER.DLL
- 2008-12-11 19:38 . 2008-12-06 06:25 58736 c:\windows\system32\Adobe\Shockwave 11\SYMCCHECKER.DLL
- 2008-12-11 19:38 . 2008-12-06 06:51 94208 c:\windows\system32\Adobe\Shockwave 11\SwMenu.dll
+ 2009-03-19 15:43 . 2009-03-19 15:43 94208 c:\windows\system32\Adobe\Shockwave 11\SwMenu.dll
- 2008-12-11 19:38 . 2008-12-06 06:25 52288 c:\windows\system32\Adobe\Shockwave 11\gtapi.dll
+ 2009-03-19 15:15 . 2009-03-19 15:15 52288 c:\windows\system32\Adobe\Shockwave 11\gtapi.dll
+ 2009-03-19 15:56 . 2009-03-19 15:56 67000 c:\windows\system32\Adobe\Director\SwDnld.exe
- 2008-12-11 19:38 . 2008-12-06 07:01 67000 c:\windows\system32\Adobe\Director\SwDnld.exe
+ 2009-04-30 08:18 . 2009-04-30 08:18 11264 c:\windows\assembly\GAC_MSIL\cli_basetypes\1.0.12.0__ce2cb7e279207b9e\cli_basetypes.dll
+ 2009-04-30 08:18 . 2009-04-30 08:18 64000 c:\windows\assembly\GAC_32\cli_cppuhelper\1.0.15.0__ce2cb7e279207b9e\cli_cppuhelper.dll
- 2008-12-11 19:38 . 2008-12-06 06:53 9216 c:\windows\system32\Adobe\Shockwave 11\DynaPlayer.dll
+ 2009-03-19 15:45 . 2009-03-19 15:45 9216 c:\windows\system32\Adobe\Shockwave 11\DynaPlayer.dll
+ 2009-04-30 08:18 . 2009-04-30 08:18 3072 c:\windows\assembly\GAC_MSIL\policy.1.0.cli_uretypes\1.1.0.0__ce2cb7e279207b9e\policy.1.0.cli_uretypes.dll
+ 2009-04-30 08:18 . 2009-04-30 08:18 3072 c:\windows\assembly\GAC_MSIL\policy.1.0.cli_ure\15.0.0.0__ce2cb7e279207b9e\policy.1.0.cli_ure.dll
+ 2009-04-30 08:19 . 2009-04-30 08:19 3072 c:\windows\assembly\GAC_MSIL\policy.1.0.cli_oootypes\1.1.0.0__ce2cb7e279207b9e\policy.1.0.cli_oootypes.dll
+ 2009-04-30 08:18 . 2009-04-30 08:18 3072 c:\windows\assembly\GAC_MSIL\policy.1.0.cli_basetypes\12.0.0.0__ce2cb7e279207b9e\policy.1.0.cli_basetypes.dll
+ 2009-04-30 08:18 . 2009-04-30 08:18 7680 c:\windows\assembly\GAC_MSIL\cli_ure\1.0.15.0__ce2cb7e279207b9e\cli_ure.dll
+ 2009-04-30 08:19 . 2009-04-30 08:19 3072 c:\windows\assembly\GAC_32\policy.1.0.cli_cppuhelper\15.0.0.0__ce2cb7e279207b9e\policy.1.0.cli_cppuhelper.dll
+ 2004-08-04 10:00 . 2009-04-30 08:41 598272 c:\windows\system32\perfh009.dat
- 2004-08-04 10:00 . 2009-04-29 06:40 598272 c:\windows\system32\perfh009.dat
+ 2004-08-04 10:00 . 2009-04-30 08:41 115236 c:\windows\system32\perfc009.dat
- 2004-08-04 10:00 . 2009-04-29 06:40 115236 c:\windows\system32\perfc009.dat
+ 2009-02-03 02:07 . 2009-02-03 02:07 240544 c:\windows\system32\Macromed\Flash\FlashUtil10b.exe
- 2008-12-10 23:36 . 2008-12-10 23:36 148888 c:\windows\system32\javaws.exe
+ 2009-04-30 08:14 . 2009-04-30 08:13 148888 c:\windows\system32\javaws.exe
+ 2009-04-30 08:14 . 2009-04-30 08:13 144792 c:\windows\system32\javaw.exe
- 2008-12-10 23:36 . 2008-12-10 23:36 144792 c:\windows\system32\javaw.exe
- 2008-12-10 23:36 . 2008-12-10 23:36 144792 c:\windows\system32\java.exe
+ 2009-04-30 08:14 . 2009-04-30 08:13 144792 c:\windows\system32\java.exe
+ 2008-12-03 16:26 . 2009-04-30 08:36 121336 c:\windows\system32\FNTCACHE.DAT
+ 2009-03-19 15:43 . 2009-03-19 15:43 114688 c:\windows\system32\Adobe\Shockwave 11\SwInit.exe
- 2008-12-11 19:38 . 2008-12-06 06:51 114688 c:\windows\system32\Adobe\Shockwave 11\SwInit.exe
+ 2009-03-19 15:55 . 2009-03-19 15:55 460216 c:\windows\system32\Adobe\Shockwave 11\SwHelper_1150595.exe
+ 2009-03-19 15:46 . 2009-03-19 15:46 442368 c:\windows\system32\Adobe\Shockwave 11\Proj.dll
+ 2009-03-19 15:44 . 2009-03-19 15:44 376832 c:\windows\system32\Adobe\Shockwave 11\Plugin.dll
+ 2009-03-19 15:15 . 2009-03-19 15:15 704000 c:\windows\system32\Adobe\Shockwave 11\gi.dll
+ 2009-03-19 15:45 . 2009-03-19 15:45 614400 c:\windows\system32\Adobe\Shockwave 11\Control.dll
+ 2009-03-19 15:55 . 2009-03-19 15:55 202168 c:\windows\system32\Adobe\Director\SwDir.dll
- 2008-12-11 19:38 . 2008-12-06 07:01 202168 c:\windows\system32\Adobe\Director\swdir.dll
+ 2009-03-19 15:45 . 2009-03-19 15:45 131072 c:\windows\system32\Adobe\Director\np32dsw.dll
+ 2009-04-30 08:18 . 2009-04-30 08:18 114688 c:\windows\assembly\GAC_MSIL\cli_uretypes\1.0.1.0__ce2cb7e279207b9e\cli_uretypes.dll
+ 2009-04-30 08:18 . 2009-04-30 08:18 823296 c:\windows\assembly\GAC_MSIL\cli_oootypes\1.0.1.0__ce2cb7e279207b9e\cli_oootypes.dll
+ 2009-03-19 15:20 . 2009-03-19 15:20 1011712 c:\windows\system32\Adobe\Shockwave 11\iml32.dll
+ 2009-03-19 15:15 . 2009-03-19 15:15 1145896 c:\windows\system32\Adobe\Shockwave 11\gt.exe
- 2008-12-11 19:38 . 2008-12-06 06:25 1145896 c:\windows\system32\Adobe\Shockwave 11\gt.exe
+ 2009-03-19 15:24 . 2009-03-19 15:24 1798144 c:\windows\system32\Adobe\Shockwave 11\dirapi.dll
- 2008-12-11 19:38 . 2008-12-06 06:33 1798144 c:\windows\system32\Adobe\Shockwave 11\dirapi.dll
+ 2009-04-30 08:19 . 2009-04-30 08:19 7424000 c:\windows\Installer\{92B79901-C57D-409F-8D2F-4E5337383569}\soffice.exe
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2008-12-04 160592]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Cookie Pal"="c:\program files\CPal\CPBrWtch.exe" [2002-07-24 20523]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"EPSON Stylus CX6600 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATI9EA.EXE" [2004-03-01 98304]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-04-27 1932568]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-26 206064]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-30 148888]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-04-27 06:02 10520 ----a-w c:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-04-27 325640]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-04-27 298264]
--- Other Services/Drivers In Memory ---
*Deregistered* - uphcleanhlp
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-04-30 10:51
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(576)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-04-30 10:53
ComboFix-quarantined-files.txt 2009-04-30 17:53
ComboFix2.txt 2009-04-29 19:00
Pre-Run: 8,856,788,992 bytes free
Post-Run: 8,850,718,720 bytes free
216