Yes, I had followed the steps concerning Java updates and deleting the cache. And yes, Combofix reported that the report was successfully submitted.
ComboFix 10-01-16.02 - James-Dell8600 01/17/2010 12:44:12.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.781 [GMT -5:00]
Running from: c:\documents and settings\James-Dell8600\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\James-Dell8600\Desktop\CFScript.txt
FILE ::
"c:\documents and settings\James-Dell8600\Application Data\Sun\Java\Deployment\cache\6.0\4\74fa5944-15157d74"
file zipped: C:\efbcmkj.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\James-Dell8600\Application Data\Sun\Java\Deployment\cache\6.0\4\74fa5944-15157d74
C:\efbcmkj.exe
.
((((((((((((((((((((((((( Files Created from 2009-12-17 to 2010-01-17 )))))))))))))))))))))))))))))))
.
2010-01-17 05:51 . 2010-01-17 05:51 152576 ----a-w- c:\documents and settings\James-Dell8600\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-01-17 05:50 . 2010-01-17 05:50 79488 ----a-w- c:\documents and settings\James-Dell8600\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-01-17 04:08 . 2010-01-17 04:08 5115824 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-10 01:56 . 2010-01-10 01:56 -------- d-----w- c:\program files\AC3Filter
2010-01-08 05:11 . 2010-01-08 05:12 34816 ----a-w- c:\windows\system32\drivers\firefox-rore2.com.sys
2010-01-08 04:51 . 2010-01-08 04:51 -------- d-----w- c:\program files\Firefox-g
2010-01-08 02:55 . 2010-01-08 02:55 -------- d-----w- c:\program files\Trend Micro
2010-01-08 02:52 . 2010-01-08 02:52 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-01-08 02:52 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-06 07:03 . 2010-01-06 07:04 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Microsoft
2010-01-06 07:03 . 2010-01-06 07:04 -------- d-----w- c:\documents and settings\Administrator
2010-01-06 06:48 . 2010-01-06 06:48 117760 ----a-w- c:\documents and settings\James-Dell8600\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-01-06 06:48 . 2010-01-06 06:48 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-01-06 06:47 . 2010-01-08 01:29 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-01-06 06:47 . 2010-01-06 06:47 -------- d-----w- c:\documents and settings\James-Dell8600\Application Data\SUPERAntiSpyware.com
2010-01-06 04:24 . 2010-01-06 04:24 -------- d-----w- C:\rsit
2009-12-27 01:04 . 2009-05-18 19:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-12-27 01:04 . 2008-04-17 18:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-12-27 01:03 . 2009-12-27 01:03 -------- d-----w- c:\program files\iPod
2009-12-27 01:02 . 2009-12-27 01:02 -------- d-----w- c:\program files\Bonjour
2009-12-26 19:26 . 2009-12-26 19:26 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-12-25 02:55 . 2009-12-27 01:04 -------- d-----w- c:\program files\iTunes
2009-12-25 02:55 . 2009-12-25 02:56 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-12-25 02:54 . 2009-12-25 02:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-12-25 02:52 . 2009-08-29 00:42 40448 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-12-25 02:52 . 2009-08-29 00:42 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-12-25 02:52 . 2009-12-27 01:03 -------- d-----w- c:\program files\Common Files\Apple
2009-12-24 09:26 . 2010-01-17 01:11 -------- d--h--w- c:\windows\PIF
2009-12-23 01:05 . 2007-10-23 14:27 110592 ----a-w- c:\documents and settings\James-Dell8600\Application Data\U3\temp\cleanup.exe
2009-12-22 22:54 . 2008-05-02 15:41 3493888 ---ha-w- c:\documents and settings\James-Dell8600\Application Data\U3\temp\Launchpad Removal.exe
2009-12-22 22:54 . 2009-12-23 01:05 -------- d-----w- c:\documents and settings\James-Dell8600\Application Data\U3
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-17 05:52 . 2008-10-22 03:01 -------- d-----w- c:\program files\Java
2010-01-17 04:08 . 2010-01-08 02:52 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-16 17:59 . 2008-10-09 05:19 47088 ----a-w- c:\windows\system32\nvModes.dat
2010-01-08 02:16 . 2010-01-08 02:16 -------- d-----w- c:\program files\Sophos
2010-01-08 01:29 . 2010-01-08 01:29 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-01-07 21:07 . 2010-01-08 02:52 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-07 15:28 . 2009-02-15 23:47 -------- d-----w- c:\documents and settings\James-Dell8600\Application Data\LimeWire
2010-01-06 16:55 . 2009-02-15 23:46 -------- d-----w- c:\program files\LimeWire
2010-01-06 07:05 . 2010-01-06 07:05 117760 ----a-w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-01-06 07:04 . 2010-01-06 07:04 -------- d-----w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com
2009-12-31 04:31 . 2009-02-28 04:52 722416 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-12-26 19:27 . 2009-04-03 02:09 -------- d-----w- c:\program files\DivX
2009-12-26 15:42 . 2009-04-03 21:29 -------- d-----w- c:\program files\Graboid
2009-12-25 03:05 . 2009-04-29 23:58 -------- d-----w- c:\documents and settings\James-Dell8600\Application Data\Apple Computer
2009-12-25 02:54 . 2009-04-04 23:13 -------- d-----w- c:\program files\QuickTime
2009-12-25 02:53 . 2009-04-04 23:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-12-17 05:14 . 2009-02-07 17:42 -------- d-----w- c:\documents and settings\James-Dell8600\Application Data\Move Networks
2009-12-07 22:41 . 2005-07-04 07:09 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-11-12 22:07 . 2009-11-12 22:07 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-02-24 19:34 . 2009-02-24 19:34 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-01-17_01.13.53 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-01-17 17:42 . 2010-01-17 17:42 16384 c:\windows\Temp\Perflib_Perfdata_6f4.dat
+ 2006-02-28 12:00 . 2010-01-17 17:47 71462 c:\windows\system32\perfc009.dat
- 2006-02-28 12:00 . 2010-01-17 01:04 71462 c:\windows\system32\perfc009.dat
- 2009-10-14 23:43 . 2008-07-08 13:02 26488 c:\windows\SoftwareDistribution\Download\fbdd9f75315c1cf9ff63f37aaca267d3\update\spcustom.dll
- 2009-10-14 23:43 . 2008-07-08 13:02 17272 c:\windows\SoftwareDistribution\Download\fbdd9f75315c1cf9ff63f37aaca267d3\spmsg.dll
- 2009-10-14 23:35 . 2009-05-26 11:40 26488 c:\windows\SoftwareDistribution\Download\e15760431e46367ca5a3dfd40a9d03e3\update\spcustom.dll
- 2009-10-14 23:35 . 2009-05-26 11:40 17272 c:\windows\SoftwareDistribution\Download\e15760431e46367ca5a3dfd40a9d03e3\spmsg.dll
- 2009-10-14 23:43 . 2008-07-08 13:02 26488 c:\windows\SoftwareDistribution\Download\d3767eab8f4479a8d252b47e8ec225c8\update\spcustom.dll
- 2009-10-14 23:43 . 2008-07-08 13:02 17272 c:\windows\SoftwareDistribution\Download\d3767eab8f4479a8d252b47e8ec225c8\spmsg.dll
- 2009-10-14 23:43 . 2009-05-26 11:40 26488 c:\windows\SoftwareDistribution\Download\9868363812bbe4a0a4d814b7943ba906\update\spcustom.dll
- 2009-10-14 23:43 . 2009-05-26 11:40 17272 c:\windows\SoftwareDistribution\Download\9868363812bbe4a0a4d814b7943ba906\spmsg.dll
- 2009-09-04 20:57 . 2009-09-04 20:57 58880 c:\windows\SoftwareDistribution\Download\9868363812bbe4a0a4d814b7943ba906\sp3qfe\msasn1.dll
- 2009-09-04 21:03 . 2009-09-04 21:03 58880 c:\windows\SoftwareDistribution\Download\9868363812bbe4a0a4d814b7943ba906\sp3gdr\msasn1.dll
- 2009-10-14 23:30 . 2009-05-26 11:40 26488 c:\windows\SoftwareDistribution\Download\8fa1ad7968e63408057364ad07aa482c\update\spcustom.dll
- 2009-10-14 23:30 . 2009-05-26 11:40 17272 c:\windows\SoftwareDistribution\Download\8fa1ad7968e63408057364ad07aa482c\spmsg.dll
- 2009-10-14 23:43 . 2009-05-26 11:40 26488 c:\windows\SoftwareDistribution\Download\85947e1a809663c7f480717673587a59\update\spcustom.dll
- 2009-10-14 23:43 . 2009-05-26 11:40 17272 c:\windows\SoftwareDistribution\Download\85947e1a809663c7f480717673587a59\spmsg.dll
- 2009-10-14 23:29 . 2009-05-26 11:40 26488 c:\windows\SoftwareDistribution\Download\71668abe67b6d77ebac6750f25908a6e\update\spcustom.dll
- 2009-10-14 23:29 . 2009-05-26 11:40 17272 c:\windows\SoftwareDistribution\Download\71668abe67b6d77ebac6750f25908a6e\spmsg.dll
- 2009-10-14 23:43 . 2009-05-26 11:40 26488 c:\windows\SoftwareDistribution\Download\5cfa09586faf6d9470f0c817d855bb6b\update\spcustom.dll
- 2009-10-14 23:43 . 2009-05-26 11:40 17272 c:\windows\SoftwareDistribution\Download\5cfa09586faf6d9470f0c817d855bb6b\spmsg.dll
- 2009-10-15 18:31 . 2008-07-09 07:38 26488 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\update\spcustom.dll
- 2009-10-15 18:31 . 2008-07-09 07:38 26488 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\spupdsvc.exe
- 2009-10-15 18:31 . 2008-07-09 07:38 17272 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\spmsg.dll
- 2009-10-15 18:31 . 2009-02-06 10:36 35328 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3QFE\sc.exe
- 2009-10-15 18:31 . 2009-02-06 10:39 35328 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\sc.exe
- 2009-10-15 18:31 . 2009-02-06 09:54 35328 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\sc.exe
- 2009-10-15 18:31 . 2005-07-26 04:20 60416 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\colbact.dll
- 2009-10-15 18:31 . 2009-02-06 16:54 35328 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\sc.exe
- 2009-10-15 18:31 . 2005-07-26 04:39 60416 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\colbact.dll
- 2006-02-28 12:00 . 2010-01-17 01:04 441692 c:\windows\system32\perfh009.dat
+ 2006-02-28 12:00 . 2010-01-17 17:47 441692 c:\windows\system32\perfh009.dat
+ 2010-01-17 05:52 . 2009-10-11 09:17 149280 c:\windows\system32\javaws.exe
- 2009-10-18 00:42 . 2009-10-18 00:42 149280 c:\windows\system32\javaws.exe
+ 2010-01-17 05:52 . 2009-10-11 09:17 145184 c:\windows\system32\javaw.exe
- 2009-10-18 00:42 . 2009-10-18 00:42 145184 c:\windows\system32\javaw.exe
+ 2010-01-17 05:52 . 2009-10-11 09:17 145184 c:\windows\system32\java.exe
- 2009-10-18 00:42 . 2009-10-18 00:42 145184 c:\windows\system32\java.exe
+ 2008-11-22 22:01 . 2009-10-11 09:17 411368 c:\windows\system32\deploytk.dll
- 2008-11-22 22:01 . 2009-10-18 00:42 411368 c:\windows\system32\deploytk.dll
- 2009-10-14 23:43 . 2009-05-26 11:40 382840 c:\windows\SoftwareDistribution\Download\fbdd9f75315c1cf9ff63f37aaca267d3\update\updspapi.dll
- 2009-10-14 23:43 . 2009-05-26 11:40 755576 c:\windows\SoftwareDistribution\Download\fbdd9f75315c1cf9ff63f37aaca267d3\update\update.exe
- 2009-10-14 23:43 . 2008-07-08 13:02 231288 c:\windows\SoftwareDistribution\Download\fbdd9f75315c1cf9ff63f37aaca267d3\spuninst.exe
- 2009-09-11 14:13 . 2009-09-11 14:13 136704 c:\windows\SoftwareDistribution\Download\fbdd9f75315c1cf9ff63f37aaca267d3\sp3qfe\msv1_0.dll
- 2009-09-11 14:18 . 2009-09-11 14:18 136192 c:\windows\SoftwareDistribution\Download\fbdd9f75315c1cf9ff63f37aaca267d3\sp3gdr\msv1_0.dll
- 2009-10-14 23:35 . 2009-05-26 11:40 382840 c:\windows\SoftwareDistribution\Download\e15760431e46367ca5a3dfd40a9d03e3\update\updspapi.dll
- 2009-10-14 23:35 . 2009-05-26 11:40 755576 c:\windows\SoftwareDistribution\Download\e15760431e46367ca5a3dfd40a9d03e3\update\update.exe
- 2009-10-14 23:35 . 2009-05-26 11:40 231288 c:\windows\SoftwareDistribution\Download\e15760431e46367ca5a3dfd40a9d03e3\spuninst.exe
- 2009-10-14 23:43 . 2009-05-26 11:40 382840 c:\windows\SoftwareDistribution\Download\d3767eab8f4479a8d252b47e8ec225c8\update\updspapi.dll
- 2009-10-14 23:43 . 2009-05-26 11:40 755576 c:\windows\SoftwareDistribution\Download\d3767eab8f4479a8d252b47e8ec225c8\update\update.exe
- 2009-10-14 23:43 . 2008-07-08 13:02 231288 c:\windows\SoftwareDistribution\Download\d3767eab8f4479a8d252b47e8ec225c8\spuninst.exe
- 2009-10-14 23:43 . 2009-05-26 11:40 382840 c:\windows\SoftwareDistribution\Download\9868363812bbe4a0a4d814b7943ba906\update\updspapi.dll
- 2009-10-14 23:43 . 2009-05-26 11:40 755576 c:\windows\SoftwareDistribution\Download\9868363812bbe4a0a4d814b7943ba906\update\update.exe
- 2009-10-14 23:43 . 2009-05-26 11:40 231288 c:\windows\SoftwareDistribution\Download\9868363812bbe4a0a4d814b7943ba906\spuninst.exe
- 2009-10-14 23:30 . 2009-05-26 11:40 382840 c:\windows\SoftwareDistribution\Download\8fa1ad7968e63408057364ad07aa482c\update\updspapi.dll
- 2009-10-14 23:30 . 2009-05-26 11:40 755576 c:\windows\SoftwareDistribution\Download\8fa1ad7968e63408057364ad07aa482c\update\update.exe
- 2009-10-14 23:30 . 2009-05-26 11:40 231288 c:\windows\SoftwareDistribution\Download\8fa1ad7968e63408057364ad07aa482c\spuninst.exe
- 2009-10-14 23:43 . 2009-05-26 11:40 382840 c:\windows\SoftwareDistribution\Download\85947e1a809663c7f480717673587a59\update\updspapi.dll
- 2009-10-14 23:43 . 2009-05-26 11:40 755576 c:\windows\SoftwareDistribution\Download\85947e1a809663c7f480717673587a59\update\update.exe
- 2009-10-14 23:43 . 2009-05-26 11:40 231288 c:\windows\SoftwareDistribution\Download\85947e1a809663c7f480717673587a59\spuninst.exe
- 2009-08-26 08:03 . 2009-08-26 08:03 247326 c:\windows\SoftwareDistribution\Download\85947e1a809663c7f480717673587a59\sp3qfe\strmdll.dll
- 2009-08-26 08:00 . 2009-08-26 08:00 247326 c:\windows\SoftwareDistribution\Download\85947e1a809663c7f480717673587a59\sp3gdr\strmdll.dll
- 2009-10-14 23:29 . 2009-05-26 11:40 382840 c:\windows\SoftwareDistribution\Download\71668abe67b6d77ebac6750f25908a6e\update\updspapi.dll
- 2009-10-14 23:29 . 2009-05-26 11:40 755576 c:\windows\SoftwareDistribution\Download\71668abe67b6d77ebac6750f25908a6e\update\update.exe
- 2009-10-14 23:29 . 2009-05-26 11:40 231288 c:\windows\SoftwareDistribution\Download\71668abe67b6d77ebac6750f25908a6e\spuninst.exe
- 2009-10-14 23:43 . 2009-05-26 11:40 382840 c:\windows\SoftwareDistribution\Download\5cfa09586faf6d9470f0c817d855bb6b\update\updspapi.dll
- 2009-10-14 23:43 . 2009-05-26 11:40 755576 c:\windows\SoftwareDistribution\Download\5cfa09586faf6d9470f0c817d855bb6b\update\update.exe
- 2009-10-14 23:43 . 2009-05-26 11:40 231288 c:\windows\SoftwareDistribution\Download\5cfa09586faf6d9470f0c817d855bb6b\spuninst.exe
- 2009-10-15 18:31 . 2008-07-09 07:38 382840 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\update\updspapi.dll
- 2009-10-15 18:31 . 2008-07-09 07:38 755576 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\update\update.exe
- 2009-10-15 18:31 . 2008-07-09 07:38 231288 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\spuninst.exe
- 2009-10-15 18:31 . 2009-02-06 10:15 227840 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3QFE\wmiprvse.exe
- 2009-10-15 18:31 . 2009-02-09 10:56 453120 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3QFE\wmiprvsd.dll
- 2009-10-15 18:31 . 2009-02-06 11:06 110592 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3QFE\services.exe
- 2009-10-15 18:31 . 2009-02-09 10:56 401408 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3QFE\rpcss.dll
- 2009-10-15 18:31 . 2009-03-06 13:49 284160 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3QFE\pdh.dll
- 2009-10-15 18:31 . 2009-02-09 10:56 715264 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3QFE\ntdll.dll
- 2009-10-15 18:31 . 2009-02-09 10:56 729088 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3QFE\lsasrv.dll
- 2009-10-15 18:31 . 2009-02-09 10:56 473600 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3QFE\fastprox.dll
- 2009-02-10 23:26 . 2009-02-10 23:26 617472 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3QFE\advapi32.dll
- 2009-10-15 18:31 . 2009-02-06 10:10 227840 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\wmiprvse.exe
- 2009-10-15 18:31 . 2009-02-09 12:10 453120 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\wmiprvsd.dll
- 2009-10-15 18:31 . 2009-02-06 11:11 110592 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\services.exe
- 2009-10-15 18:31 . 2009-02-09 12:10 401408 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\rpcss.dll
- 2009-10-15 18:31 . 2009-03-06 14:22 284160 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\pdh.dll
- 2009-10-15 18:31 . 2009-02-09 12:10 714752 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\ntdll.dll
- 2009-10-15 18:31 . 2009-02-09 12:10 729088 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\lsasrv.dll
- 2009-10-15 18:31 . 2009-02-09 12:10 473600 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\fastprox.dll
- 2009-10-15 18:31 . 2009-02-09 12:10 617472 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\advapi32.dll
- 2009-10-15 18:31 . 2009-02-06 09:41 227840 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\wmiprvse.exe
- 2009-02-10 22:31 . 2009-02-10 22:31 453120 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\wmiprvsd.dll
- 2009-10-15 18:31 . 2009-02-06 10:22 110592 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\services.exe
- 2009-10-15 18:31 . 2009-02-09 10:01 401408 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\rpcss.dll
- 2009-10-15 18:31 . 2009-03-06 14:00 284160 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\pdh.dll
- 2009-10-15 18:31 . 2009-02-09 10:01 715264 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\ntdll.dll
- 2009-10-15 18:31 . 2009-02-09 10:01 728576 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\lsasrv.dll
- 2009-10-15 18:31 . 2009-02-09 10:01 473088 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\fastprox.dll
- 2009-10-15 18:31 . 2009-02-09 10:01 617984 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\advapi32.dll
- 2009-10-15 18:31 . 2009-02-06 16:39 227840 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\wmiprvse.exe
- 2009-10-15 18:31 . 2009-02-09 10:20 453120 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\wmiprvsd.dll
- 2009-10-15 18:31 . 2009-02-06 17:14 110592 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\services.exe
- 2009-10-15 18:31 . 2009-02-09 10:20 399360 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\rpcss.dll
- 2009-10-15 18:31 . 2009-03-06 14:44 283648 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\pdh.dll
- 2009-10-15 18:31 . 2009-02-09 10:20 714752 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\ntdll.dll
- 2009-10-15 18:31 . 2009-02-09 10:20 723456 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\lsasrv.dll
- 2009-10-15 18:31 . 2009-02-09 10:20 473088 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\fastprox.dll
- 2009-10-15 18:31 . 2009-02-09 10:20 616960 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\advapi32.dll
- 2009-10-14 23:35 . 2009-08-13 13:55 1748992 c:\windows\SoftwareDistribution\Download\e15760431e46367ca5a3dfd40a9d03e3\SP3QFE\asms\10\msft\windows\gdiplus\gdiplus.dll
- 2009-07-17 16:01 . 2009-07-17 16:01 1435648 c:\windows\SoftwareDistribution\Download\d3767eab8f4479a8d252b47e8ec225c8\sp3qfe\query.dll
- 2009-07-17 16:22 . 2009-07-17 16:22 1435648 c:\windows\SoftwareDistribution\Download\d3767eab8f4479a8d252b47e8ec225c8\sp3gdr\query.dll
- 2009-10-14 23:30 . 2009-08-04 13:56 2189312 c:\windows\SoftwareDistribution\Download\8fa1ad7968e63408057364ad07aa482c\SP3QFE\ntoskrnl.exe
- 2009-10-14 23:30 . 2009-08-04 13:17 2023936 c:\windows\SoftwareDistribution\Download\8fa1ad7968e63408057364ad07aa482c\SP3QFE\ntkrpamp.exe
- 2009-08-04 22:47 . 2009-08-04 22:47 2066176 c:\windows\SoftwareDistribution\Download\8fa1ad7968e63408057364ad07aa482c\SP3QFE\ntkrnlpa.exe
- 2009-10-14 23:30 . 2009-08-04 13:54 2145280 c:\windows\SoftwareDistribution\Download\8fa1ad7968e63408057364ad07aa482c\SP3QFE\ntkrnlmp.exe
- 2009-08-05 00:44 . 2009-08-05 00:44 2189184 c:\windows\SoftwareDistribution\Download\8fa1ad7968e63408057364ad07aa482c\SP3GDR\ntoskrnl.exe
- 2009-10-14 23:30 . 2009-08-04 14:20 2023936 c:\windows\SoftwareDistribution\Download\8fa1ad7968e63408057364ad07aa482c\SP3GDR\ntkrpamp.exe
- 2009-10-14 23:29 . 2009-08-04 14:20 2066048 c:\windows\SoftwareDistribution\Download\8fa1ad7968e63408057364ad07aa482c\SP3GDR\ntkrnlpa.exe
- 2009-10-14 23:30 . 2009-08-04 15:13 2145280 c:\windows\SoftwareDistribution\Download\8fa1ad7968e63408057364ad07aa482c\SP3GDR\ntkrnlmp.exe
- 2009-10-14 23:30 . 2009-08-04 12:51 2185984 c:\windows\SoftwareDistribution\Download\8fa1ad7968e63408057364ad07aa482c\SP2QFE\ntoskrnl.exe
- 2009-10-14 23:30 . 2009-08-04 12:02 2020864 c:\windows\SoftwareDistribution\Download\8fa1ad7968e63408057364ad07aa482c\SP2QFE\ntkrpamp.exe
- 2009-10-14 23:29 . 2009-08-04 12:02 2062976 c:\windows\SoftwareDistribution\Download\8fa1ad7968e63408057364ad07aa482c\SP2QFE\ntkrnlpa.exe
- 2009-10-14 23:30 . 2009-08-04 12:49 2142720 c:\windows\SoftwareDistribution\Download\8fa1ad7968e63408057364ad07aa482c\SP2QFE\ntkrnlmp.exe
- 2009-10-14 23:30 . 2009-08-04 14:00 2180352 c:\windows\SoftwareDistribution\Download\8fa1ad7968e63408057364ad07aa482c\SP2GDR\ntoskrnl.exe
- 2009-10-14 23:30 . 2009-08-04 13:13 2015744 c:\windows\SoftwareDistribution\Download\8fa1ad7968e63408057364ad07aa482c\SP2GDR\ntkrpamp.exe
- 2009-10-14 23:29 . 2009-08-04 13:13 2057728 c:\windows\SoftwareDistribution\Download\8fa1ad7968e63408057364ad07aa482c\SP2GDR\ntkrnlpa.exe
- 2009-10-14 23:30 . 2009-08-04 13:58 2136064 c:\windows\SoftwareDistribution\Download\8fa1ad7968e63408057364ad07aa482c\SP2GDR\ntkrnlmp.exe
- 2009-02-07 23:35 . 2009-02-07 23:35 2189184 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3QFE\ntoskrnl.exe
- 2009-10-15 18:31 . 2009-02-06 10:30 2023936 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3QFE\ntkrpamp.exe
- 2009-10-15 18:31 . 2009-02-06 10:30 2066176 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3QFE\ntkrnlpa.exe
- 2009-10-15 18:31 . 2009-02-06 11:03 2145280 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3QFE\ntkrnlmp.exe
- 2009-10-15 18:31 . 2009-02-06 11:08 2189056 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\ntoskrnl.exe
- 2009-10-15 18:31 . 2009-02-06 10:32 2023936 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\ntkrpamp.exe
- 2009-02-07 23:02 . 2009-02-07 23:02 2066048 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\ntkrnlpa.exe
- 2009-10-15 18:31 . 2009-02-06 11:06 2145280 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP3GDR\ntkrnlmp.exe
- 2009-10-15 18:31 . 2009-02-06 10:32 2186112 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\ntoskrnl.exe
- 2009-10-15 18:31 . 2009-02-06 09:49 2020864 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\ntkrpamp.exe
- 2009-10-15 18:31 . 2009-02-06 09:49 2062976 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\ntkrnlpa.exe
- 2009-10-15 18:31 . 2009-02-06 10:29 2142720 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2QFE\ntkrnlmp.exe
- 2009-10-15 18:31 . 2009-02-06 17:24 2180480 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\ntoskrnl.exe
- 2009-10-15 18:31 . 2009-02-06 16:49 2015744 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\ntkrpamp.exe
- 2009-10-15 18:31 . 2009-02-06 16:49 2057728 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\ntkrnlpa.exe
- 2009-10-15 18:31 . 2009-02-06 17:22 2136064 c:\windows\SoftwareDistribution\Download\51401b498f4675531d9efb941ee01ef3\SP2GDR\ntkrnlmp.exe
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-12-16 2002160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-07-07 7118848]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 49152]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\firefox-rore.com.sys]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\firefox-rore2.com.sys]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk
backup=c:\windows\pss\KODAK Software Updater.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
2005-10-07 19:13 176128 ----a-r- c:\program files\Apoint\Apoint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadcom Wireless Manager UI]
2005-12-19 14:08 1347584 ----a-w- c:\windows\system32\WLTRAY.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ------w- c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ------w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2005-07-07 00:52 7118848 ----a-w- c:\windows\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2005-07-07 00:52 1519616 ----a-w- c:\windows\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-11 04:08 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2003-11-01 00:42 32768 ----a-w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-10-11 09:17 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\backWeb-7288971.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone Version 3\\support\\bin\\win\\RosettaStoneLtdServices.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone Version 3\\RosettaStoneVersion3.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [12/16/2009 4:26 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12/16/2009 4:26 PM 74480]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [2/27/2009 11:52 PM 722416]
S3 firefox-rore.com;firefox-rore.com;\??\c:\windows\system32\drivers\firefox-rore.com.sys --> c:\windows\system32\drivers\firefox-rore.com.sys [?]
S3 firefox-rore2.com;firefox-rore2.com;c:\windows\system32\drivers\firefox-rore2.com.sys [1/8/2010 12:11 AM 34816]
S3 GTICARD;GTICARD;c:\windows\system32\drivers\gticard.sys [10/23/2003 5:04 PM 76160]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [12/16/2009 4:27 PM 7408]
.
Contents of the 'Scheduled Tasks' folder
2010-01-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2010-01-17 c:\windows\Tasks\User_Feed_Synchronization-{2BF28BC1-463F-4864-B919-8C2EC24C84BE}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 08:31]
.
.
------- Supplementary Scan -------
.
mSearch Bar = hxxp://www.mirarsearch.com/?useie5=1&q=
uInternet Settings,ProxyOverride = localhost;*.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
Trusted Zone: cbs.com\www
Trusted Zone: go.com\abc
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-17 12:51
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(644)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\windows\System32\BCMLogon.dll
.
Completion time: 2010-01-17 12:53:57
ComboFix-quarantined-files.txt 2010-01-17 17:53
ComboFix2.txt 2010-01-17 02:01
ComboFix3.txt 2010-01-17 01:19
Pre-Run: 20,678,623,232 bytes free
Post-Run: 20,733,558,784 bytes free
Current=2 Default=2 Failed=4 LastKnownGood=5 Sets=1,2,3,4,5
- - End Of File - - D14974A2CB3EBE1ED0531DCDFCAA76DC
Upload was successful