|
Re: Vista Antivirus 2008???
ComboFix 08-07-17.4 - Karen 2008-07-18 19:45:20.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.920 [GMT -4:00]
Running from: C:\Documents and Settings\Karen\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Karen\err.log
C:\WINDOWS\system32\avica.dll
C:\WINDOWS\system32\avwrvqvu.dll
C:\WINDOWS\system32\drivers\fad.sys
C:\WINDOWS\system32\eoeravla.ini
C:\WINDOWS\system32\exbuinfs.ini
C:\WINDOWS\system32\fjjttv.dll
C:\WINDOWS\system32\hofjchgw.dll
C:\WINDOWS\system32\ikmjvy.dll
C:\WINDOWS\system32\ixtatf.dll
C:\WINDOWS\system32\lnqeqdmt.ini
C:\WINDOWS\system32\lstepcyi.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\MWyIlUtv.ini
C:\WINDOWS\system32\MWyIlUtv.ini2
C:\WINDOWS\system32\mxbcgfvd.ini
C:\WINDOWS\system32\npkimtri.dll
C:\WINDOWS\system32\sbnvjada.dll
C:\WINDOWS\system32\slvwgu.dll
C:\WINDOWS\system32\tsvqndmj.dll
C:\WINDOWS\system32\winsrc.dll.tmp
C:\WINDOWS\system32\wrjtduhm.dll
C:\WINDOWS\system32\xsnvwm.dll
.
((((((((((((((((((((((((( Files Created from 2008-06-18 to 2008-07-18 )))))))))))))))))))))))))))))))
.
2008-07-18 17:21 . 2008-07-18 17:21 <DIR> d-------- C:\Deckard
2008-07-18 12:30 . 2008-07-18 12:30 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-18 12:30 . 2008-07-18 12:30 <DIR> d-------- C:\Documents and Settings\Karen\Application Data\Malwarebytes
2008-07-18 12:30 . 2008-07-18 12:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-18 12:30 . 2008-07-07 17:35 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-07-18 12:30 . 2008-07-07 17:35 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-07-18 12:25 . 2008-07-18 17:23 <DIR> d-------- C:\Temp\HighJackThis
2008-07-18 11:50 . 2008-07-18 11:50 <DIR> d-------- C:\Program Files\Google
2008-07-18 11:18 . 2008-07-18 11:18 110,952 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-07-18 11:18 . 2008-07-18 11:18 48,768 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-07-18 11:18 . 2008-07-18 11:18 8,014 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-07-18 11:18 . 2008-07-18 11:18 805 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-07-18 11:17 . 2008-07-18 11:48 <DIR> d-------- C:\Program Files\Symantec
2008-07-18 11:06 . 2008-07-18 11:06 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-07-18 11:06 . 2008-07-18 11:06 1,409 --a------ C:\WINDOWS\QTFont.for
2008-07-18 11:04 . 2008-07-18 11:08 <DIR> d-------- C:\Documents and Settings\Karen\Application Data\Morpheus
2008-07-18 11:02 . 2008-07-18 11:08 <DIR> d-------- C:\Program Files\Morpheus
2008-07-18 10:16 . 2008-07-18 11:26 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-07-18 10:11 . 2008-07-18 10:11 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-07-18 10:11 . 2008-07-18 10:11 1,152 --a------ C:\WINDOWS\system32\windrv.sys
2008-07-18 10:04 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-07-17 20:51 . 2008-07-17 21:37 <DIR> d-------- C:\WINDOWS\SxsCaPendDel
2008-07-17 17:19 . 2008-07-17 17:19 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-17 16:10 . 2008-07-17 16:15 <DIR> d-------- C:\f33f171db22688ce5536b501
2008-07-17 15:50 . 2001-08-17 13:48 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2008-07-17 14:18 . 2008-07-17 17:33 <DIR> d-------- C:\Program Files\Lavasoft
2008-07-17 14:18 . 2008-07-17 16:55 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-17 13:56 . 2008-07-17 13:56 0 --a------ C:\WINDOWS\vpc32.INI
2008-07-17 13:42 . 2008-07-18 11:53 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-17 13:20 . 2008-07-17 13:21 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-07-17 13:20 . 2008-07-17 13:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-17 13:14 . 2008-07-17 14:02 <DIR> d-------- C:\Program Files\RegCleaner
2008-07-17 13:13 . 2008-07-17 13:44 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-07-17 13:13 . 2008-07-17 13:13 <DIR> d-------- C:\Program Files\CleanUp!
2008-07-14 21:05 . 2008-07-14 21:05 1,879,563 --ahs---- C:\WINDOWS\system32\mxbcgfvd.tmp
2008-07-05 22:58 . 2008-07-05 22:58 <DIR> d-------- C:\WINDOWS\system32\modtrux01
2008-07-05 22:58 . 2008-07-18 13:05 <DIR> d-------- C:\Temp
2008-07-01 00:10 . 2008-07-18 14:10 <DIR> d-------- C:\Documents and Settings\Karen\Application Data\MSN6
2008-07-01 00:10 . 2008-07-01 00:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MSN6
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-18 18:25 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-07-18 18:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-07-18 14:10 --------- d-----w C:\Program Files\Java
2008-07-18 13:58 --------- d-----w C:\Program Files\MUSICMATCH
2008-07-18 13:57 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-18 01:07 --------- d-----w C:\Program Files\Real
2008-07-17 20:05 --------- d-----w C:\Program Files\Dell
2008-07-11 04:11 --------- d-----w C:\Program Files\Viewpoint
2008-07-11 04:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-07-02 22:05 --------- d-----w C:\Program Files\Apple Software Update
2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-05-16 15:58 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
.
------- Sigcheck -------
2003-07-16 12:41 12800 0f7d9c87b0ce1fa520473119752c6f79 C:\WINDOWS\$NtServicePackUninstall$\svchost.exe
2004-08-04 01:56 14336 8f078ae4ed187aaabc0a305146de6716 C:\WINDOWS\ServicePackFiles\i386\svchost.exe
2004-08-04 01:56 14336 8f078ae4ed187aaabc0a305146de6716 C:\WINDOWS\system32\svchost.exe
2005-03-02 14:19 577024 1800f293bccc8ede8a70e12b88d80036 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
2007-03-08 11:48 578048 7aa4f6c00405dfc4b70ed4214e7d687b C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
2003-07-16 12:43 560128 dd9269230c21ee8fb7fd3fccc3b1cfcb C:\WINDOWS\$NtServicePackUninstall$\user32.dll
2004-08-04 01:56 577024 c72661f8552ace7c5c85e16a3cf505c4 C:\WINDOWS\$NtUninstallKB890859$\user32.dll
2005-03-02 14:09 577024 de2db164bbb35db061af0997e4499054 C:\WINDOWS\$NtUninstallKB925902$\user32.dll
2004-08-04 01:56 577024 c72661f8552ace7c5c85e16a3cf505c4 C:\WINDOWS\ServicePackFiles\i386\user32.dll
2007-03-08 11:36 577536 b409909f6e2e8a7067076ed748abf1e7 C:\WINDOWS\system32\user32.dll
2007-03-08 11:36 577536 b409909f6e2e8a7067076ed748abf1e7 C:\WINDOWS\system32\dllcache\user32.dll
2003-07-16 12:46 75264 8529c295df59b564d37a73b5629162b1 C:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll
2004-08-04 01:56 82944 2ed0b7f12a60f90092081c50fa0ec2b2 C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll
2004-08-04 01:56 82944 2ed0b7f12a60f90092081c50fa0ec2b2 C:\WINDOWS\system32\ws2_32.dll
2008-04-23 00:16 826368 f6589be784647cfdbc22ea51ccb1a57a C:\WINDOWS\system32\wininet.dll
2008-04-23 00:16 826368 f6589be784647cfdbc22ea51ccb1a57a C:\WINDOWS\system32\dllcache\wininet.dll
2006-04-20 08:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2007-10-30 12:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2003-07-16 12:41 332928 244a2f9816bc9b593957281ef577d976 C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
2004-08-04 00:14 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
2006-04-20 07:51 359808 1dbf125862891817f374f407626967f4 C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
2004-08-04 00:14 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\ServicePackFiles\i386\tcpip.sys
2007-10-30 13:20 360064 90caff4b094573449a0872a0f919b178 C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-30 13:20 360064 90caff4b094573449a0872a0f919b178 C:\WINDOWS\system32\drivers\tcpip.sys
2003-07-16 12:45 516608 2246d8d8f4714a2cedb21ab9b1849abb C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
2004-08-04 01:56 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
2004-08-04 01:56 502272 01c3346c241652f43aed8e2149881bfe C:\WINDOWS\system32\winlogon.exe
2003-03-06 11:30 162432 09b38768036508b51564201afb000950 C:\WINDOWS\$NtServicePackUninstall$\ndis.sys
2004-08-04 00:14 182912 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\ServicePackFiles\i386\ndis.sys
2004-08-04 00:14 182912 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\system32\drivers\ndis.sys
2004-08-04 00:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\ServicePackFiles\i386\ip6fw.sys
2004-08-04 00:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\system32\drivers\ip6fw.sys
2005-03-01 20:36 2056832 d8aba3eab509627e707a3b14f00fbb6b C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
2006-12-19 12:12 2059392 ba4b97c00a437c1cc3da365d93ee1e9d C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntkrnlpa.exe
2007-02-28 05:15 2059392 4d3dbdccbf97f5ba1e74f322b155c3ba C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe
2003-07-16 12:40 1947904 0e8efb15746878a9b256e75267337233 C:\WINDOWS\$NtServicePackUninstall$\ntkrnlpa.exe
2004-08-03 23:59 2056832 947fb1d86d14afcffdb54bf837ec25d0 C:\WINDOWS\$NtUninstallKB890859$\ntkrnlpa.exe
2005-03-01 20:34 2056832 81013f36b21c7f72cf784cc6731e0002 C:\WINDOWS\$NtUninstallKB929338$\ntkrnlpa.exe
2006-12-19 08:55 2057600 1d659bfb788ed2ba45075624b748d249 C:\WINDOWS\$NtUninstallKB931784$\ntkrnlpa.exe
2007-02-28 04:38 2057600 515d30e2c90a3665a2739309334c9283 C:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe
2004-08-03 23:59 2056832 947fb1d86d14afcffdb54bf837ec25d0 C:\WINDOWS\ServicePackFiles\i386\ntkrnlpa.exe
2007-02-28 04:38 2057600 515d30e2c90a3665a2739309334c9283 C:\WINDOWS\system32\ntkrnlpa.exe
2007-02-28 04:38 2057600 515d30e2c90a3665a2739309334c9283 C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2005-03-01 21:04 2179456 28187802b7c368c0d3aef7d4c382aabb C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
2006-12-19 12:51 2182016 cef243f6defd20be4adde26c7ecacb54 C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntoskrnl.exe
2007-02-28 05:55 2182144 5a5c8db4aa962c714c8371fbdf189fc9 C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe
2003-07-16 12:33 2042240 b9080d97dbd631aadf9128f7316958d2 C:\WINDOWS\$NtServicePackUninstall$\ntoskrnl.exe
2004-08-04 00:20 2180992 ce218bc7088681faa06633e218596ca7 C:\WINDOWS\$NtUninstallKB890859$\ntoskrnl.exe
2005-03-01 20:59 2179328 4d4cf2c14550a4b7718e94a6e581856e C:\WINDOWS\$NtUninstallKB929338$\ntoskrnl.exe
2006-12-19 10:17 2180352 8f0deab1f81fb83f9c5995853ce48b9f C:\WINDOWS\$NtUninstallKB931784$\ntoskrnl.exe
2007-02-28 05:10 2180352 582a8dbaa58c3b1f176eb2817daee77c C:\WINDOWS\Driver Cache\i386\ntoskrnl.exe
2004-08-04 00:20 2180992 ce218bc7088681faa06633e218596ca7 C:\WINDOWS\ServicePackFiles\i386\ntoskrnl.exe
2007-02-28 05:10 2180352 582a8dbaa58c3b1f176eb2817daee77c C:\WINDOWS\system32\ntoskrnl.exe
2007-02-28 05:10 2180352 582a8dbaa58c3b1f176eb2817daee77c C:\WINDOWS\system32\dllcache\ntoskrnl.exe
|