ComboFix 10-08-18.04 - Administrator 08/19/2010 21:01:38.6.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2048.1573 [GMT -4:00]
Running from: c:\documents and settings\Administrator\My Documents\Downloads\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((( Files Created from 2010-07-20 to 2010-08-20 )))))))))))))))))))))))))))))))
.
2010-08-19 01:13 . 2010-08-19 01:13 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee Security Scan
2010-08-19 01:13 . 2010-08-19 15:49 -------- d-----w- c:\program files\McAfee Security Scan
2010-08-16 05:28 . 2010-08-16 05:28 -------- d-----w- C:\636f054e8a09ffd597518c54
2010-08-13 20:29 . 2010-08-13 20:29 -------- d-----w- c:\program files\ESET
2010-08-13 20:23 . 2010-08-13 20:23 -------- d-----w- c:\program files\VS Revo Group
2010-08-13 05:11 . 2010-08-13 05:11 -------- d-----w- C:\3c338c4143b3e209eef585dc3e
2010-08-10 19:35 . 2010-06-28 20:37 165456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-08-10 19:35 . 2010-06-28 20:32 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-08-10 19:35 . 2010-06-28 20:33 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-08-10 19:35 . 2010-06-28 20:37 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-08-10 19:35 . 2010-06-28 20:32 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-08-10 19:35 . 2010-06-28 20:32 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-08-10 19:35 . 2010-06-28 20:32 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-08-10 19:35 . 2010-06-28 20:57 38848 ----a-w- c:\windows\avastSS.scr
2010-08-10 19:35 . 2010-06-28 20:57 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-08-10 19:28 . 2010-08-10 19:35 -------- d-----w- c:\program files\Alwil Software
2010-08-10 19:28 . 2010-08-10 19:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-07-31 18:44 . 2010-08-04 16:11 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-07-30 13:24 . 2010-07-31 18:34 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\AskToolbar
2010-07-27 00:15 . 2010-08-06 17:34 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-07-25 20:44 . 2010-07-25 20:44 452104 ----a-w- c:\documents and settings\Administrator\Application Data\Real\Update\setup3.12\setup.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-13 20:52 . 2009-09-15 19:48 -------- d-----w- c:\program files\Eusing Free Registry Cleaner
2010-08-12 16:32 . 2008-11-04 04:48 -------- d-----w- c:\program files\QuickTime
2010-08-10 19:37 . 2008-11-04 04:49 -------- d-----w- c:\documents and settings\Administrator\Application Data\Apple Computer
2010-08-10 19:16 . 2009-11-10 19:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-08-06 08:41 . 2010-01-13 15:39 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-08-05 20:54 . 2010-01-28 12:10 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-08-05 20:45 . 2010-04-08 19:05 0 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\prvlcl.dat
2010-08-02 05:25 . 2010-06-03 22:21 -------- d-----w- c:\documents and settings\All Users\Application Data\DivX
2010-07-20 16:53 . 2010-03-18 16:56 117760 ----a-w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-06-30 12:31 . 2002-08-29 10:41 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-24 12:15 . 2002-08-29 10:41 832512 ----a-w- c:\windows\system32\wininet.dll
2010-06-24 12:15 . 2004-08-04 07:56 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-06-24 12:15 . 2001-08-18 05:36 17408 ------w- c:\windows\system32\corpol.dll
2010-06-23 13:44 . 2002-08-29 09:14 1851904 ----a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27 . 2001-08-18 05:24 354304 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-17 14:03 . 2001-08-18 05:36 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-14 14:31 . 2002-08-29 10:41 744448 ----a-w- c:\windows\PCHealth\HelpCtr\Binaries\helpsvc.exe
2010-06-14 07:41 . 2002-08-29 10:41 1172480 ----a-w- c:\windows\system32\msxml3.dll
2010-06-04 19:53 . 2010-06-03 22:37 57344 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-06-04 19:51 . 2010-06-04 19:52 1062184 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\Resource.dll
2010-06-04 19:51 . 2010-06-04 19:52 895256 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe
2010-06-04 19:49 . 2010-06-04 19:49 54101 ----a-w- c:\documents and settings\All Users\Application Data\DivX\MPEG2Plugin\Uninstaller.exe
2010-06-04 19:48 . 2010-06-04 19:48 56969 ----a-w- c:\documents and settings\All Users\Application Data\DivX\ASPEncoder\Uninstaller.exe
.
((((((((((((((((((((((((((((( SnapShot_2010-08-10_21.23.32 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-08-19 15:44 . 2010-08-19 15:44 16384 c:\windows\Temp\Perflib_Perfdata_2f0.dat
- 2002-08-29 10:41 . 2010-05-04 17:20 44544 c:\windows\system32\pngfilt.dll
+ 2002-08-29 10:41 . 2010-06-24 12:15 44544 c:\windows\system32\pngfilt.dll
+ 2007-08-13 23:54 . 2010-06-24 12:15 52224 c:\windows\system32\msfeedsbs.dll
- 2007-08-13 23:54 . 2010-05-04 17:20 52224 c:\windows\system32\msfeedsbs.dll
+ 2001-08-18 05:36 . 2010-06-24 12:15 27648 c:\windows\system32\jsproxy.dll
- 2001-08-18 05:36 . 2010-05-04 17:20 27648 c:\windows\system32\jsproxy.dll
- 2007-08-13 23:39 . 2010-05-04 12:39 13824 c:\windows\system32\ieudinit.exe
+ 2007-08-13 23:39 . 2010-06-23 12:06 13824 c:\windows\system32\ieudinit.exe
+ 2001-08-18 05:36 . 2010-06-24 12:15 44544 c:\windows\system32\iernonce.dll
- 2001-08-18 05:36 . 2010-05-04 17:20 44544 c:\windows\system32\iernonce.dll
+ 2002-08-29 10:41 . 2010-06-23 12:06 70656 c:\windows\system32\ie4uinit.exe
- 2002-08-29 10:41 . 2010-05-04 12:39 70656 c:\windows\system32\ie4uinit.exe
- 2007-08-13 23:36 . 2010-05-04 17:20 63488 c:\windows\system32\icardie.dll
+ 2007-08-13 23:36 . 2010-06-24 12:15 63488 c:\windows\system32\icardie.dll
+ 2007-08-13 23:36 . 2010-06-24 12:15 44544 c:\windows\system32\dllcache\pngfilt.dll
- 2007-08-13 23:36 . 2010-05-04 17:20 44544 c:\windows\system32\dllcache\pngfilt.dll
+ 2008-08-26 07:24 . 2010-06-24 12:15 52224 c:\windows\system32\dllcache\msfeedsbs.dll
- 2008-08-26 07:24 . 2010-05-04 17:20 52224 c:\windows\system32\dllcache\msfeedsbs.dll
- 2001-08-18 05:36 . 2010-05-04 17:20 27648 c:\windows\system32\dllcache\jsproxy.dll
+ 2001-08-18 05:36 . 2010-06-24 12:15 27648 c:\windows\system32\dllcache\jsproxy.dll
- 2008-08-25 08:38 . 2010-05-04 12:39 13824 c:\windows\system32\dllcache\ieudinit.exe
+ 2008-08-25 08:38 . 2010-06-23 12:06 13824 c:\windows\system32\dllcache\ieudinit.exe
+ 2001-08-18 05:36 . 2010-06-24 12:15 44544 c:\windows\system32\dllcache\iernonce.dll
- 2001-08-18 05:36 . 2010-05-04 17:20 44544 c:\windows\system32\dllcache\iernonce.dll
+ 2009-02-20 18:09 . 2010-06-24 12:15 78336 c:\windows\system32\dllcache\ieencode.dll
- 2009-02-20 18:09 . 2010-05-04 17:20 78336 c:\windows\system32\dllcache\ieencode.dll
- 2007-08-13 23:39 . 2010-05-04 12:39 70656 c:\windows\system32\dllcache\ie4uinit.exe
+ 2007-08-13 23:39 . 2010-06-23 12:06 70656 c:\windows\system32\dllcache\ie4uinit.exe
+ 2008-08-26 07:24 . 2010-06-24 12:15 63488 c:\windows\system32\dllcache\icardie.dll
- 2008-08-26 07:24 . 2010-05-04 17:20 63488 c:\windows\system32\dllcache\icardie.dll
+ 2009-06-29 16:12 . 2010-06-24 12:15 17408 c:\windows\system32\dllcache\corpol.dll
- 2009-06-29 16:12 . 2010-05-04 17:20 17408 c:\windows\system32\dllcache\corpol.dll
+ 2010-08-12 02:07 . 2010-08-12 02:07 38240 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
- 2010-06-12 05:53 . 2010-06-12 05:53 38240 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
+ 2010-08-17 18:10 . 2010-05-04 17:20 44544 c:\windows\ie7updates\KB2183461-IE7\pngfilt.dll
+ 2010-08-17 18:10 . 2010-05-04 17:20 52224 c:\windows\ie7updates\KB2183461-IE7\msfeedsbs.dll
+ 2010-08-17 18:10 . 2010-05-04 17:20 27648 c:\windows\ie7updates\KB2183461-IE7\jsproxy.dll
+ 2010-08-17 18:10 . 2010-05-04 12:39 13824 c:\windows\ie7updates\KB2183461-IE7\ieudinit.exe
+ 2010-08-17 18:10 . 2010-05-04 17:20 44544 c:\windows\ie7updates\KB2183461-IE7\iernonce.dll
+ 2010-08-17 18:10 . 2010-05-04 17:20 78336 c:\windows\ie7updates\KB2183461-IE7\ieencode.dll
+ 2010-08-17 18:10 . 2010-05-04 12:39 70656 c:\windows\ie7updates\KB2183461-IE7\ie4uinit.exe
+ 2010-08-17 18:10 . 2010-05-04 17:20 63488 c:\windows\ie7updates\KB2183461-IE7\icardie.dll
+ 2010-08-17 18:10 . 2010-05-04 17:20 17408 c:\windows\ie7updates\KB2183461-IE7\corpol.dll
- 2002-08-29 10:41 . 2010-05-04 17:20 233472 c:\windows\system32\webcheck.dll
+ 2002-08-29 10:41 . 2010-06-24 12:15 233472 c:\windows\system32\webcheck.dll
- 2002-08-29 10:41 . 2010-05-04 17:20 105984 c:\windows\system32\url.dll
+ 2002-08-29 10:41 . 2010-06-24 12:15 105984 c:\windows\system32\url.dll
- 2001-08-18 05:36 . 2010-05-04 17:20 102912 c:\windows\system32\occache.dll
+ 2001-08-18 05:36 . 2010-06-24 12:15 102912 c:\windows\system32\occache.dll
+ 2002-08-29 10:41 . 2010-06-24 12:15 671232 c:\windows\system32\mstime.dll
- 2002-08-29 10:41 . 2010-05-04 17:20 671232 c:\windows\system32\mstime.dll
- 2002-08-29 10:41 . 2010-05-04 17:20 193024 c:\windows\system32\msrating.dll
+ 2002-08-29 10:41 . 2010-06-24 12:15 193024 c:\windows\system32\msrating.dll
+ 2002-08-29 10:41 . 2010-06-24 12:15 477696 c:\windows\system32\mshtmled.dll
- 2002-08-29 10:41 . 2010-05-04 17:20 477696 c:\windows\system32\mshtmled.dll
+ 2007-08-13 23:54 . 2010-06-24 12:15 459264 c:\windows\system32\msfeeds.dll
- 2007-08-13 23:54 . 2010-05-04 17:20 459264 c:\windows\system32\msfeeds.dll
+ 2010-08-19 01:13 . 2010-08-19 01:13 232912 c:\windows\system32\Macromed\Flash\FlashUtil10i_ActiveX.exe
+ 2010-08-19 01:13 . 2010-08-19 01:13 311760 c:\windows\system32\Macromed\Flash\FlashUtil10i_ActiveX.dll
+ 2007-08-13 23:34 . 2010-06-24 12:15 268288 c:\windows\system32\iertutil.dll
- 2007-08-13 23:34 . 2010-05-04 17:20 268288 c:\windows\system32\iertutil.dll
+ 2002-08-29 10:40 . 2010-06-24 12:15 192512 c:\windows\system32\iepeers.dll
- 2002-08-29 10:40 . 2010-05-04 17:20 192512 c:\windows\system32\iepeers.dll
+ 2002-08-29 10:40 . 2010-06-24 12:15 385024 c:\windows\system32\iedkcs32.dll
- 2002-08-29 10:40 . 2010-05-04 17:20 385024 c:\windows\system32\iedkcs32.dll
- 2007-07-11 17:27 . 2010-05-04 17:20 380928 c:\windows\system32\ieapfltr.dll
+ 2007-07-11 17:27 . 2010-06-24 12:15 380928 c:\windows\system32\ieapfltr.dll
+ 2001-08-18 05:34 . 2010-06-17 15:11 161792 c:\windows\system32\ieakui.dll
- 2001-08-18 05:34 . 2010-04-16 11:43 161792 c:\windows\system32\ieakui.dll
+ 2002-08-29 10:40 . 2010-06-24 12:15 230400 c:\windows\system32\ieaksie.dll
- 2002-08-29 10:40 . 2010-05-04 17:20 230400 c:\windows\system32\ieaksie.dll
- 2002-08-29 10:40 . 2010-05-04 17:20 153088 c:\windows\system32\ieakeng.dll
+ 2002-08-29 10:40 . 2010-06-24 12:15 153088 c:\windows\system32\ieakeng.dll
+ 2004-08-04 07:56 . 2010-06-24 12:15 133120 c:\windows\system32\extmgr.dll
- 2004-08-04 07:56 . 2010-05-04 17:20 133120 c:\windows\system32\extmgr.dll
+ 2002-08-29 10:40 . 2010-06-24 12:15 214528 c:\windows\system32\dxtrans.dll
- 2002-08-29 10:40 . 2010-05-04 17:20 214528 c:\windows\system32\dxtrans.dll
- 2002-08-29 10:40 . 2010-05-04 17:20 347136 c:\windows\system32\dxtmsft.dll
+ 2002-08-29 10:40 . 2010-06-24 12:15 347136 c:\windows\system32\dxtmsft.dll
- 2007-08-13 23:54 . 2010-05-04 17:20 832512 c:\windows\system32\dllcache\wininet.dll
+ 2007-08-13 23:54 . 2010-06-24 12:15 832512 c:\windows\system32\dllcache\wininet.dll
+ 2007-08-13 23:54 . 2010-06-24 12:15 233472 c:\windows\system32\dllcache\webcheck.dll
- 2007-08-13 23:54 . 2010-05-04 17:20 233472 c:\windows\system32\dllcache\webcheck.dll
- 2007-08-13 23:44 . 2010-05-04 17:20 105984 c:\windows\system32\dllcache\url.dll
+ 2007-08-13 23:44 . 2010-06-24 12:15 105984 c:\windows\system32\dllcache\url.dll
+ 2008-10-29 20:57 . 2010-06-21 15:27 354304 c:\windows\system32\dllcache\srv.sys
+ 2008-12-05 06:54 . 2010-06-30 12:31 149504 c:\windows\system32\dllcache\schannel.dll
+ 2007-08-13 23:44 . 2010-06-24 12:15 102912 c:\windows\system32\dllcache\occache.dll
- 2007-08-13 23:44 . 2010-05-04 17:20 102912 c:\windows\system32\dllcache\occache.dll
+ 2002-08-29 10:41 . 2010-06-24 12:15 671232 c:\windows\system32\dllcache\mstime.dll
- 2002-08-29 10:41 . 2010-05-04 17:20 671232 c:\windows\system32\dllcache\mstime.dll
- 2007-08-13 23:44 . 2010-05-04 17:20 193024 c:\windows\system32\dllcache\msrating.dll
+ 2007-08-13 23:44 . 2010-06-24 12:15 193024 c:\windows\system32\dllcache\msrating.dll
- 2007-08-13 23:54 . 2010-05-04 17:20 477696 c:\windows\system32\dllcache\mshtmled.dll
+ 2007-08-13 23:54 . 2010-06-24 12:15 477696 c:\windows\system32\dllcache\mshtmled.dll
+ 2008-08-26 07:24 . 2010-06-24 12:15 459264 c:\windows\system32\dllcache\msfeeds.dll
- 2008-08-26 07:24 . 2010-05-04 17:20 459264 c:\windows\system32\dllcache\msfeeds.dll
- 2007-08-13 23:43 . 2010-04-16 11:43 634656 c:\windows\system32\dllcache\iexplore.exe
+ 2007-08-13 23:43 . 2010-06-17 15:12 634656 c:\windows\system32\dllcache\iexplore.exe
- 2008-08-26 07:24 . 2010-05-04 17:20 268288 c:\windows\system32\dllcache\iertutil.dll
+ 2008-08-26 07:24 . 2010-06-24 12:15 268288 c:\windows\system32\dllcache\iertutil.dll
- 2007-08-13 23:54 . 2010-05-04 17:20 192512 c:\windows\system32\dllcache\iepeers.dll
+ 2007-08-13 23:54 . 2010-06-24 12:15 192512 c:\windows\system32\dllcache\iepeers.dll
+ 2007-08-13 23:39 . 2010-06-24 12:15 385024 c:\windows\system32\dllcache\iedkcs32.dll
- 2007-08-13 23:39 . 2010-05-04 17:20 385024 c:\windows\system32\dllcache\iedkcs32.dll
- 2008-08-26 07:24 . 2010-05-04 17:20 380928 c:\windows\system32\dllcache\ieapfltr.dll
+ 2008-08-26 07:24 . 2010-06-24 12:15 380928 c:\windows\system32\dllcache\ieapfltr.dll
+ 2001-08-18 05:34 . 2010-06-17 15:11 161792 c:\windows\system32\dllcache\ieakui.dll
- 2001-08-18 05:34 . 2010-04-16 11:43 161792 c:\windows\system32\dllcache\ieakui.dll
+ 2002-08-29 10:40 . 2010-06-24 12:15 230400 c:\windows\system32\dllcache\ieaksie.dll
- 2002-08-29 10:40 . 2010-05-04 17:20 230400 c:\windows\system32\dllcache\ieaksie.dll
+ 2002-08-29 10:40 . 2010-06-24 12:15 153088 c:\windows\system32\dllcache\ieakeng.dll
- 2002-08-29 10:40 . 2010-05-04 17:20 153088 c:\windows\system32\dllcache\ieakeng.dll
- 2007-08-13 23:54 . 2010-05-04 17:20 133120 c:\windows\system32\dllcache\extmgr.dll
+ 2007-08-13 23:54 . 2010-06-24 12:15 133120 c:\windows\system32\dllcache\extmgr.dll
- 2007-08-13 23:35 . 2010-05-04 17:20 214528 c:\windows\system32\dllcache\dxtrans.dll
+ 2007-08-13 23:35 . 2010-06-24 12:15 214528 c:\windows\system32\dllcache\dxtrans.dll
- 2007-08-13 23:35 . 2010-05-04 17:20 347136 c:\windows\system32\dllcache\dxtmsft.dll
+ 2007-08-13 23:35 . 2010-06-24 12:15 347136 c:\windows\system32\dllcache\dxtmsft.dll
+ 2007-08-13 23:39 . 2010-06-24 12:15 124928 c:\windows\system32\dllcache\advpack.dll
- 2007-08-13 23:39 . 2010-05-04 17:20 124928 c:\windows\system32\dllcache\advpack.dll
- 2002-08-29 10:40 . 2010-05-04 17:20 124928 c:\windows\system32\advpack.dll
+ 2002-08-29 10:40 . 2010-06-24 12:15 124928 c:\windows\system32\advpack.dll
+ 2010-08-17 18:10 . 2010-05-04 17:20 832512 c:\windows\ie7updates\KB2183461-IE7\wininet.dll
+ 2010-08-17 18:10 . 2010-05-04 17:20 233472 c:\windows\ie7updates\KB2183461-IE7\webcheck.dll
+ 2010-08-17 18:10 . 2010-05-04 17:20 105984 c:\windows\ie7updates\KB2183461-IE7\url.dll
+ 2010-08-17 18:10 . 2010-02-22 14:23 382840 c:\windows\ie7updates\KB2183461-IE7\spuninst\updspapi.dll
+ 2010-08-17 18:10 . 2010-02-22 14:23 231288 c:\windows\ie7updates\KB2183461-IE7\spuninst\spuninst.exe
+ 2010-08-17 18:10 . 2010-05-04 17:20 102912 c:\windows\ie7updates\KB2183461-IE7\occache.dll
+ 2010-08-17 18:10 . 2010-05-04 17:20 671232 c:\windows\ie7updates\KB2183461-IE7\mstime.dll
+ 2010-08-17 18:10 . 2010-05-04 17:20 193024 c:\windows\ie7updates\KB2183461-IE7\msrating.dll
+ 2010-08-17 18:10 . 2010-05-04 17:20 477696 c:\windows\ie7updates\KB2183461-IE7\mshtmled.dll
+ 2010-08-17 18:10 . 2010-05-04 17:20 459264 c:\windows\ie7updates\KB2183461-IE7\msfeeds.dll
+ 2010-08-17 18:10 . 2010-04-16 11:43 634656 c:\windows\ie7updates\KB2183461-IE7\iexplore.exe
+ 2010-08-17 18:10 . 2010-05-04 17:20 268288 c:\windows\ie7updates\KB2183461-IE7\iertutil.dll
+ 2010-08-17 18:10 . 2010-05-04 17:20 192512 c:\windows\ie7updates\KB2183461-IE7\iepeers.dll
+ 2010-08-17 18:10 . 2010-05-04 17:20 385024 c:\windows\ie7updates\KB2183461-IE7\iedkcs32.dll
+ 2010-08-17 18:10 . 2010-05-04 17:20 380928 c:\windows\ie7updates\KB2183461-IE7\ieapfltr.dll
+ 2010-08-17 18:10 . 2010-04-16 11:43 161792 c:\windows\ie7updates\KB2183461-IE7\ieakui.dll
+ 2010-08-17 18:10 . 2010-05-04 17:20 230400 c:\windows\ie7updates\KB2183461-IE7\ieaksie.dll
+ 2010-08-17 18:10 . 2010-05-04 17:20 153088 c:\windows\ie7updates\KB2183461-IE7\ieakeng.dll
+ 2010-08-17 18:10 . 2010-05-04 17:20 133120 c:\windows\ie7updates\KB2183461-IE7\extmgr.dll
+ 2010-08-17 18:10 . 2010-05-04 17:20 214528 c:\windows\ie7updates\KB2183461-IE7\dxtrans.dll
+ 2010-08-17 18:10 . 2010-05-04 17:20 347136 c:\windows\ie7updates\KB2183461-IE7\dxtmsft.dll
+ 2010-08-17 18:10 . 2010-05-04 17:20 124928 c:\windows\ie7updates\KB2183461-IE7\advpack.dll
- 2003-10-18 03:15 . 2010-05-04 17:20 1168384 c:\windows\system32\urlmon.dll
+ 2003-10-18 03:15 . 2010-06-24 12:15 1168384 c:\windows\system32\urlmon.dll
+ 2002-08-29 09:03 . 2010-04-28 02:25 2189952 c:\windows\system32\ntoskrnl.exe
- 2002-08-29 09:03 . 2010-02-17 13:10 2189952 c:\windows\system32\ntoskrnl.exe
- 2003-03-31 09:00 . 2010-02-16 13:25 2066816 c:\windows\system32\ntkrnlpa.exe
+ 2003-03-31 09:00 . 2010-04-27 13:05 2066816 c:\windows\system32\ntkrnlpa.exe
+ 2003-10-16 21:34 . 2010-06-24 12:15 3600896 c:\windows\system32\mshtml.dll
+ 2007-08-13 23:54 . 2010-06-24 12:15 6067200 c:\windows\system32\ieframe.dll
- 2007-08-13 23:54 . 2010-05-04 17:20 6067200 c:\windows\system32\ieframe.dll
- 2003-05-19 20:27 . 2010-06-12 14:49 1542320 c:\windows\system32\FNTCACHE.DAT
+ 2003-05-19 20:27 . 2010-08-12 14:44 1542320 c:\windows\system32\FNTCACHE.DAT
+ 2008-10-29 20:57 . 2010-06-23 13:44 1851904 c:\windows\system32\dllcache\win32k.sys
- 2007-08-13 23:54 . 2010-05-04 17:20 1168384 c:\windows\system32\dllcache\urlmon.dll
+ 2007-08-13 23:54 . 2010-06-24 12:15 1168384 c:\windows\system32\dllcache\urlmon.dll
- 2008-10-29 20:57 . 2010-02-17 13:10 2189952 c:\windows\system32\dllcache\ntoskrnl.exe
+ 2008-10-29 20:57 . 2010-04-28 02:25 2189952 c:\windows\system32\dllcache\ntoskrnl.exe
- 2008-10-29 20:57 . 2010-02-16 13:25 2024448 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2008-10-29 20:57 . 2010-04-27 13:05 2024448 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2008-10-29 20:57 . 2010-04-27 13:05 2066816 c:\windows\system32\dllcache\ntkrnlpa.exe
- 2008-10-29 20:57 . 2010-02-16 13:25 2066816 c:\windows\system32\dllcache\ntkrnlpa.exe
+ 2008-10-29 20:57 . 2010-04-27 13:59 2146304 c:\windows\system32\dllcache\ntkrnlmp.exe
- 2008-10-29 20:57 . 2010-02-16 14:08 2146304 c:\windows\system32\dllcache\ntkrnlmp.exe
- 2008-11-12 20:22 . 2009-07-31 04:35 1172480 c:\windows\system32\dllcache\msxml3.dll
+ 2008-11-12 20:22 . 2010-06-14 07:41 1172480 c:\windows\system32\dllcache\msxml3.dll
+ 2007-08-13 23:54 . 2010-06-24 12:15 3600896 c:\windows\system32\dllcache\mshtml.dll
+ 2010-03-10 17:49 . 2010-06-18 13:36 3558912 c:\windows\system32\dllcache\moviemk.exe
- 2010-03-10 17:49 . 2009-10-23 15:28 3558912 c:\windows\system32\dllcache\moviemk.exe
- 2008-10-03 17:41 . 2010-05-04 17:20 6067200 c:\windows\system32\dllcache\ieframe.dll
+ 2008-10-03 17:41 . 2010-06-24 12:15 6067200 c:\windows\system32\dllcache\ieframe.dll
+ 2010-06-29 02:53 . 2010-06-29 02:53 6819840 c:\windows\Installer\f1a8.msp
+ 2010-05-03 20:06 . 2010-05-03 20:06 5053952 c:\windows\Installer\f1a5.msp
+ 2010-05-03 20:06 . 2010-05-03 20:06 5053952 c:\windows\Installer\9f025c.msp
+ 2010-05-03 20:06 . 2010-05-03 20:06 5053952 c:\windows\Installer\778ae9b.msp
+ 2010-05-03 20:06 . 2010-05-03 20:06 5053952 c:\windows\Installer\309a6.msp
+ 2010-06-29 02:53 . 2010-06-29 02:53 6819840 c:\windows\Installer\2b79f4f.msp
+ 2010-05-03 20:06 . 2010-05-03 20:06 5053952 c:\windows\Installer\2b79f48.msp
+ 2010-06-29 02:53 . 2010-06-29 02:53 6819840 c:\windows\Installer\2b235e0.msp
+ 2010-05-03 20:06 . 2010-05-03 20:06 5053952 c:\windows\Installer\2b235d9.msp
+ 2010-07-26 21:02 . 2010-07-26 21:02 5519360 c:\windows\Installer\27f031.msp
+ 2010-05-03 20:06 . 2010-05-03 20:06 5053952 c:\windows\Installer\27f02e.msp
+ 2010-05-03 20:06 . 2010-05-03 20:06 5053952 c:\windows\Installer\24137.msp
+ 2009-10-16 22:07 . 2009-10-16 22:07 6115328 c:\windows\Installer\21812eb.msp
+ 2010-06-28 20:01 . 2010-06-28 20:01 7677952 c:\windows\Installer\21812e8.msp
+ 2010-02-04 22:11 . 2010-02-04 22:11 5526528 c:\windows\Installer\21812e5.msp
+ 2010-05-03 20:11 . 2010-05-03 20:11 4149760 c:\windows\Installer\21812e2.msp
+ 2010-06-29 02:53 . 2010-06-29 02:53 6819840 c:\windows\Installer\21812df.msp
+ 2010-07-26 21:02 . 2010-07-26 21:02 5519360 c:\windows\Installer\21812d8.msp
+ 2010-07-11 00:14 . 2010-07-11 00:14 2850816 c:\windows\Installer\21812d6.msp
+ 2010-05-03 20:06 . 2010-05-03 20:06 5053952 c:\windows\Installer\21812cd.msp
+ 2009-10-16 22:07 . 2009-10-16 22:07 6115328 c:\windows\Installer\1a87506.msp
+ 2010-06-28 20:01 . 2010-06-28 20:01 7677952 c:\windows\Installer\1a87503.msp
+ 2010-05-03 20:11 . 2010-05-03 20:11 4149760 c:\windows\Installer\1a87500.msp
+ 2010-06-29 02:53 . 2010-06-29 02:53 6819840 c:\windows\Installer\1a874fd.msp
+ 2010-07-26 21:02 . 2010-07-26 21:02 5519360 c:\windows\Installer\1a874f6.msp
+ 2010-05-03 20:06 . 2010-05-03 20:06 5053952 c:\windows\Installer\1a874f3.msp
+ 2010-08-17 18:10 . 2010-05-04 17:20 1168384 c:\windows\ie7updates\KB2183461-IE7\urlmon.dll
+ 2010-08-17 18:10 . 2010-05-04 17:20 3600384 c:\windows\ie7updates\KB2183461-IE7\mshtml.dll
+ 2010-08-17 18:10 . 2010-05-04 17:20 6067200 c:\windows\ie7updates\KB2183461-IE7\ieframe.dll
- 2008-10-29 20:57 . 2010-02-17 13:10 2189952 c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2008-10-29 20:57 . 2010-04-28 02:25 2189952 c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2008-10-29 20:57 . 2010-04-27 13:05 2024448 c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2008-10-29 20:57 . 2010-02-16 13:25 2024448 c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2008-10-29 20:57 . 2010-02-16 13:25 2066816 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2008-10-29 20:57 . 2010-04-27 13:05 2066816 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2008-10-29 20:57 . 2010-04-27 13:59 2146304 c:\windows\Driver Cache\i386\ntkrnlmp.exe
- 2008-10-29 20:57 . 2010-02-16 14:08 2146304 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2008-10-29 21:48 . 2010-08-03 18:09 35962312 c:\windows\system32\MRT.exe
+ 2010-05-19 17:08 . 2010-05-19 17:08 11408896 c:\windows\Installer\9f025f.msp
+ 2010-05-19 17:08 . 2010-05-19 17:08 11408896 c:\windows\Installer\778ae9e.msp
+ 2010-05-19 17:08 . 2010-05-19 17:08 11408896 c:\windows\Installer\2b79f4b.msp
+ 2010-05-19 17:08 . 2010-05-19 17:08 11408896 c:\windows\Installer\2b235dc.msp
+ 2010-05-19 17:08 . 2010-05-19 17:08 11408896 c:\windows\Installer\27f034.msp
+ 2010-05-19 17:08 . 2010-05-19 17:08 11408896 c:\windows\Installer\21812db.msp
+ 2010-05-19 17:08 . 2010-05-19 17:08 11408896 c:\windows\Installer\1a874f9.msp
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask .exe -atboottime" [X]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2004-06-17 4112384]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"Adobe_ID0EYTHM"="c:\progra~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" [2007-03-20 1884160]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-06-28 2837864]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [8/10/2010 3:35 PM 165456]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [8/10/2010 3:35 PM 17744]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2/5/2010 8:10 AM 135664]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-01-24 17:30 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
2010-07-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2010-08-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-05 12:10]
2010-08-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-05 12:10]
2010-08-19 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 19:07]
2010-08-19 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-03-31 02:18]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\nam3sghc.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - plugin: c:\program files\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-08-19 21:10
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(5120)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
.
Completion time: 2010-08-19 21:13:08
ComboFix-quarantined-files.txt 2010-08-20 01:13
ComboFix2.txt 2010-08-12 16:35
ComboFix3.txt 2010-08-10 21:25
ComboFix4.txt 2010-08-09 03:30
ComboFix5.txt 2010-08-20 01:00
Pre-Run: 4,259,840 bytes free
Post-Run: 169,779,200 bytes free
- - End Of File - - 2964065C003B787B03054CC923F509A9