Things are running a little faster, but it seems like there are still problems. Here are the latest reports:
HijackThis!
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:00:20 PM, on 5/9/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Live365\Radio365\Radio365TrayAgent.exe
C:\Program Files\FinePixViewerS\QuickDCF2.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\SEC\Natural Color\NaturalColorLoad.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Executive Software\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Radio365Agent] C:\PROGRA~1\Live365\Radio365\Radio365TrayAgent.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: PowerReg SchedulerV2.exe
O4 - Global Startup: Exif Launcher S.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: NaturalColorLoad.lnk = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
–
End of file - 7219 bytes
ComboFix
ComboFix 09-05-08.03 - Administrator 05/09/2009 12:49.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.512.180 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.txt
file zipped: c:\windows\ativpsrm.bin
file zipped: c:\windows\popcinfo.dat
file zipped: c:\windows\system32\babetafu.dll.tmp
file zipped: c:\windows\system32\bajiyise.dll
file zipped: c:\windows\system32\dawuyoha.dll
file zipped: c:\windows\system32\gazeyuha.dll
file zipped: c:\windows\system32\gunowini.dll
file zipped: c:\windows\system32\halojoge.dll
file zipped: c:\windows\system32\joludune.dll.tmp
file zipped: c:\windows\system32\jujijano.exe
file zipped: c:\windows\system32\kapigagi.dll
file zipped: c:\windows\system32\kubidima.exe
file zipped: c:\windows\system32\kubuyula.dll
file zipped: c:\windows\system32\meyobuha.dll
file zipped: c:\windows\system32\mupafeve.exe
file zipped: c:\windows\system32\nenosivu.dll
file zipped: c:\windows\system32\nivedusa.dll
file zipped: c:\windows\system32\nizenopi.exe
file zipped: c:\windows\system32\notabage.dll
file zipped: c:\windows\system32\noweripe.dll
file zipped: c:\windows\system32\nunoruzo.exe
file zipped: c:\windows\system32\nutuhunu.dll
file zipped: c:\windows\system32\petojava.dll
file zipped: c:\windows\system32\piyiliwa.dll.tmp
file zipped: c:\windows\system32\sapahati.dll
file zipped: c:\windows\system32\tefifohi.exe
file zipped: c:\windows\system32\tifunalo.dll
file zipped: c:\windows\system32\timinebe.dll
file zipped: c:\windows\system32\vupesasu.exe
file zipped: c:\windows\system32\wakuribi.dll
file zipped: c:\windows\system32\yahirifi.dll
file zipped: c:\windows\system32\yapufave.dll
file zipped: c:\windows\system32\yonugese.dll.vir
file zipped: c:\windows\system32\ziresula.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\SearchRelevant
c:\windows\ativpsrm.bin
c:\windows\popcinfo.dat
c:\windows\system32\babetafu.dll.tmp
c:\windows\system32\bajiyise.dll
c:\windows\system32\dawuyoha.dll
c:\windows\system32\gazeyuha.dll
c:\windows\system32\gunowini.dll
c:\windows\system32\halojoge.dll
c:\windows\system32\joludune.dll.tmp
c:\windows\system32\jujijano.exe
c:\windows\system32\kapigagi.dll
c:\windows\system32\kubidima.exe
c:\windows\system32\kubuyula.dll
c:\windows\system32\meyobuha.dll
c:\windows\system32\mupafeve.exe
c:\windows\system32\nenosivu.dll
c:\windows\system32\nivedusa.dll
c:\windows\system32\nizenopi.exe
c:\windows\system32\notabage.dll
c:\windows\system32\noweripe.dll
c:\windows\system32\nunoruzo.exe
c:\windows\system32\nutuhunu.dll
c:\windows\system32\petojava.dll
c:\windows\system32\piyiliwa.dll.tmp
c:\windows\system32\sapahati.dll
c:\windows\system32\tefifohi.exe
c:\windows\system32\tifunalo.dll
c:\windows\system32\timinebe.dll
c:\windows\system32\vupesasu.exe
c:\windows\system32\wakuribi.dll
c:\windows\system32\yahirifi.dll
c:\windows\system32\yapufave.dll
c:\windows\system32\yonugese.dll.vir
c:\windows\system32\ziresula.dll
.
((((((((((((((((((((((((( Files Created from 2009-04-09 to 2009-05-09 )))))))))))))))))))))))))))))))
.
2009-05-06 00:00 . 2009-05-06 00:00 ——– d—–w c:\windows\LastGood
2009-05-05 22:17 . 2009-05-05 22:17 ——– d—–w c:\program files\Common Files\eSellerate
2009-05-05 22:14 . 2009-05-05 22:14 ——– d—–w c:\program files\Senuti iPod Rip
2009-05-05 22:02 . 2009-05-05 22:02 ——– d—–w c:\documents and settings\Administrator\Application Data\CopyTrans
2009-05-05 22:01 . 2009-05-05 22:01 ——– d—–w c:\program files\WindSolutions
2009-05-05 22:01 . 2009-05-05 22:01 ——– d—–w c:\documents and settings\All Users\Application Data\CopyTransControlCenter
2009-05-05 21:47 . 2009-03-06 14:44 283648 -c—-w c:\windows\system32\dllcache\pdh.dll
2009-05-05 21:47 . 2005-07-26 04:39 60416 -c—-w c:\windows\system32\dllcache\colbact.dll
2009-05-05 21:47 . 2009-02-09 10:20 399360 -c—-w c:\windows\system32\dllcache\rpcss.dll
2009-05-05 21:47 . 2009-02-06 17:14 110592 -c—-w c:\windows\system32\dllcache\services.exe
2009-05-05 21:47 . 2009-02-09 10:20 473088 -c—-w c:\windows\system32\dllcache\fastprox.dll
2009-05-05 21:47 . 2009-02-06 16:39 227840 -c—-w c:\windows\system32\dllcache\wmiprvse.exe
2009-05-05 21:47 . 2009-02-09 10:20 453120 -c—-w c:\windows\system32\dllcache\wmiprvsd.dll
2009-05-05 21:47 . 2009-02-09 10:20 616960 -c—-w c:\windows\system32\dllcache\advapi32.dll
2009-05-05 21:47 . 2009-02-09 10:20 714752 -c—-w c:\windows\system32\dllcache\ntdll.dll
2009-05-05 15:37 . 2009-05-05 15:37 ——– d—–w c:\program files\ERUNT
2009-05-05 14:36 . 2009-05-05 14:36 ——– d—–w c:\program files\Trend Micro
2009-05-05 07:06 . 2009-05-05 07:06 ——– d—–w c:\documents and settings\Administrator\Application Data\CopyTransControlCenter
2009-05-05 06:57 . 2009-05-05 06:58 ——– d—–w c:\program files\MusicBrainz Picard
2009-05-05 05:46 . 2009-05-05 05:46 ——– d—–w c:\program files\iPod
2009-05-05 05:45 . 2009-05-05 05:46 ——– d—–w c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-05 05:45 . 2009-05-05 05:46 ——– d—–w c:\program files\iTunes
2009-05-05 05:12 . 2009-05-05 05:12 ——– d—–w c:\documents and settings\Administrator\dwhelper
2009-04-21 21:05 . 2009-04-21 21:05 ——– d—–w c:\documents and settings\LocalService\Local Settings\Application Data\ESET
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-05 14:49 . 2005-01-13 09:49 ——– d—–w c:\program files\Java
2009-05-05 05:46 . 2009-04-04 20:37 ——– d—–w c:\program files\Common Files\Apple
2009-04-04 20:39 . 2009-04-04 20:39 ——– d—–w c:\program files\Bonjour
2009-04-03 02:28 . 2009-04-01 02:39 ——– d—–w c:\program files\HP
2009-04-03 02:28 . 2009-04-01 03:25 ——– d—–w c:\program files\Hewlett-Packard
2009-04-01 03:28 . 2009-04-01 03:28 ——– d—–w c:\program files\Common Files\HP
2009-04-01 03:23 . 2009-04-01 03:23 ——– d—–w c:\program files\Common Files\Hewlett-Packard
2009-03-24 23:04 . 2005-06-21 00:55 ——– d—–w c:\program files\Warcraft III
2009-03-24 20:20 . 2005-06-21 00:58 116036 -c–a-w c:\windows\War3Unin.dat
2009-03-23 18:25 . 2009-03-23 18:25 ——– d—–w c:\program files\ESET
2009-03-23 02:08 . 2009-03-19 21:36 ——– d—–w c:\program files\Common Files\Symantec Shared
2009-03-19 20:32 . 2008-01-29 16:01 23400 —-a-w c:\windows\system32\drivers\GEARAspiWDM.sys
2009-03-18 23:06 . 2006-07-08 13:19 ——– d—–w c:\program files\Lavasoft
2009-03-18 21:49 . 2009-03-18 21:49 ——– d—–w c:\program files\Common Files\Blizzard Entertainment
2009-03-09 19:06 . 2009-03-19 02:08 15688 —-a-w c:\windows\system32\lsdelete.exe
2009-03-09 19:06 . 2009-03-18 23:07 64160 —-a-w c:\windows\system32\drivers\Lbd.sys
2009-03-09 09:19 . 2009-01-27 00:36 410984 —-a-w c:\windows\system32\deploytk.dll
2009-03-06 14:44 . 2003-03-31 12:00 283648 —-a-w c:\windows\system32\pdh.dll
2009-03-06 03:59 . 2009-04-04 20:38 36864 —-a-w c:\windows\system32\drivers\usbaapl.sys
2009-03-06 03:59 . 2009-04-04 20:38 1900544 —-a-w c:\windows\system32\usbaaplrc.dll
2009-03-03 00:18 . 2003-03-31 12:00 826368 —-a-w c:\windows\system32\wininet.dll
2009-02-20 18:09 . 2004-10-12 12:48 78336 —-a-w c:\windows\system32\ieencode.dll
2009-02-19 23:43 . 2009-01-12 06:25 1257256 —-a-w c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-02-19 23:42 . 2009-02-19 23:42 716272 —-a-w c:\windows\system32\drivers\sptd.sys
2009-02-09 18:56 . 2009-02-17 23:53 67584 —-a-w c:\windows\system32\ff_vfw.dll
2009-02-09 10:20 . 2008-12-09 19:12 723456 —-a-w c:\windows\system32\lsasrv.dll
2009-02-09 10:20 . 2003-03-31 12:00 399360 —-a-w c:\windows\system32\rpcss.dll
2009-02-09 10:20 . 2008-12-09 19:12 616960 —-a-w c:\windows\system32\advapi32.dll
2009-02-09 10:20 . 2008-12-09 19:12 714752 —-a-w c:\windows\system32\ntdll.dll
2009-02-09 10:19 . 2008-12-09 19:12 1846272 —-a-w c:\windows\system32\win32k.sys
2008-01-12 23:17 . 2008-01-12 23:17 0 -csh–w c:\windows\SF6385B5B.tmp
2005-04-26 19:55 . 2005-04-26 19:55 56 –sh–r c:\windows\system32\3D15C80603.sys
.
((((((((((((((((((((((((((((( SnapShot@2009-05-05_20.46.41 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-05-09 15:39 . 2009-05-09 15:39 16384 c:\windows\Temp\Perflib_Perfdata_6ac.dat
+ 2009-05-09 15:39 . 2009-05-09 15:39 16384 c:\windows\Temp\Perflib_Perfdata_4fc.dat
+ 2004-10-12 12:43 . 2008-07-09 07:38 26488 c:\windows\system32\spupdsvc.exe
- 2004-10-12 12:43 . 2007-11-30 11:18 26488 c:\windows\system32\spupdsvc.exe
- 2004-10-12 12:44 . 2007-11-30 11:18 17272 c:\windows\system32\spmsg.dll
+ 2004-10-12 12:44 . 2007-11-30 12:39 17272 c:\windows\system32\spmsg.dll
- 2003-03-31 12:00 . 2004-08-04 04:56 55808 c:\windows\system32\secur32.dll
+ 2003-03-31 12:00 . 2009-02-03 20:08 55808 c:\windows\system32\secur32.dll
+ 2003-03-31 12:00 . 2009-02-06 16:54 35328 c:\windows\system32\sc.exe
+ 2003-03-31 12:00 . 2009-02-20 18:09 44544 c:\windows\system32\pngfilt.dll
- 2003-03-31 12:00 . 2008-12-20 23:15 44544 c:\windows\system32\pngfilt.dll
- 2003-03-31 12:00 . 2009-03-08 23:02 67312 c:\windows\system32\perfc009.dat
+ 2003-03-31 12:00 . 2009-05-09 15:40 67312 c:\windows\system32\perfc009.dat
+ 2004-10-12 12:20 . 2008-06-12 14:16 91648 c:\windows\system32\mtxoci.dll
+ 2003-03-31 12:00 . 2008-06-12 14:16 66560 c:\windows\system32\mtxclu.dll
- 2003-03-31 12:00 . 2006-03-01 19:42 66560 c:\windows\system32\mtxclu.dll
- 2006-11-08 02:03 . 2008-12-20 23:15 52224 c:\windows\system32\msfeedsbs.dll
+ 2006-11-08 02:03 . 2009-02-20 18:09 52224 c:\windows\system32\msfeedsbs.dll
+ 2004-10-12 12:20 . 2008-06-12 14:16 58880 c:\windows\system32\msdtclog.dll
- 2004-10-12 12:20 . 2004-08-04 04:56 58880 c:\windows\system32\msdtclog.dll
- 2003-03-31 12:00 . 2008-12-20 23:15 27648 c:\windows\system32\jsproxy.dll
+ 2003-03-31 12:00 . 2009-02-20 18:09 27648 c:\windows\system32\jsproxy.dll
- 2006-11-07 08:26 . 2008-12-19 09:10 13824 c:\windows\system32\ieudinit.exe
+ 2006-11-07 08:26 . 2009-02-20 10:20 13824 c:\windows\system32\ieudinit.exe
+ 2003-03-31 12:00 . 2009-02-20 18:09 44544 c:\windows\system32\iernonce.dll
- 2003-03-31 12:00 . 2008-12-20 23:15 44544 c:\windows\system32\iernonce.dll
- 2003-03-31 12:00 . 2008-12-19 09:10 70656 c:\windows\system32\ie4uinit.exe
+ 2003-03-31 12:00 . 2009-02-20 10:20 70656 c:\windows\system32\ie4uinit.exe
- 2006-10-17 16:58 . 2008-12-20 23:15 63488 c:\windows\system32\icardie.dll
+ 2006-10-17 16:58 . 2009-02-20 18:09 63488 c:\windows\system32\icardie.dll
+ 2009-02-03 20:08 . 2009-02-03 20:08 55808 c:\windows\system32\dllcache\secur32.dll
+ 2003-03-31 12:00 . 2009-02-06 16:54 35328 c:\windows\system32\dllcache\sc.exe
- 2006-05-10 05:23 . 2008-12-20 23:15 44544 c:\windows\system32\dllcache\pngfilt.dll
+ 2006-05-10 05:23 . 2009-02-20 18:09 44544 c:\windows\system32\dllcache\pngfilt.dll
+ 2008-06-12 14:16 . 2008-06-12 14:16 91648 c:\windows\system32\dllcache\mtxoci.dll
+ 2008-06-12 14:16 . 2008-06-12 14:16 66560 c:\windows\system32\dllcache\mtxclu.dll
- 2007-05-10 00:14 . 2008-12-20 23:15 52224 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2007-05-10 00:14 . 2009-02-20 18:09 52224 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2008-06-12 14:16 . 2008-06-12 14:16 58880 c:\windows\system32\dllcache\msdtclog.dll
- 2006-05-10 05:22 . 2008-12-20 23:15 27648 c:\windows\system32\dllcache\jsproxy.dll
+ 2006-05-10 05:22 . 2009-02-20 18:09 27648 c:\windows\system32\dllcache\jsproxy.dll
- 2007-05-10 00:14 . 2008-12-19 09:10 13824 c:\windows\system32\dllcache\ieudinit.exe
+ 2007-05-10 00:14 . 2009-02-20 10:20 13824 c:\windows\system32\dllcache\ieudinit.exe
+ 2006-11-07 08:26 . 2009-02-20 18:09 44544 c:\windows\system32\dllcache\iernonce.dll
- 2006-11-07 08:26 . 2008-12-20 23:15 44544 c:\windows\system32\dllcache\iernonce.dll
+ 2008-12-09 19:15 . 2009-02-20 18:09 78336 c:\windows\system32\dllcache\ieencode.dll
- 2008-12-09 19:15 . 2006-10-17 17:06 78336 c:\windows\system32\dllcache\ieencode.dll
- 2006-11-07 08:26 . 2008-12-19 09:10 70656 c:\windows\system32\dllcache\ie4uinit.exe
+ 2006-11-07 08:26 . 2009-02-20 10:20 70656 c:\windows\system32\dllcache\ie4uinit.exe
+ 2007-08-20 10:04 . 2009-02-20 18:09 63488 c:\windows\system32\dllcache\icardie.dll
- 2007-08-20 10:04 . 2008-12-20 23:15 63488 c:\windows\system32\dllcache\icardie.dll
+ 2009-05-06 00:03 . 2008-12-20 23:15 44544 c:\windows\ie7updates\KB963027-IE7\pngfilt.dll
+ 2009-05-06 00:03 . 2008-12-20 23:15 52224 c:\windows\ie7updates\KB963027-IE7\msfeedsbs.dll
+ 2009-05-06 00:03 . 2008-12-20 23:15 27648 c:\windows\ie7updates\KB963027-IE7\jsproxy.dll
+ 2009-05-06 00:03 . 2008-12-19 09:10 13824 c:\windows\ie7updates\KB963027-IE7\ieudinit.exe
+ 2009-05-06 00:03 . 2008-12-20 23:15 44544 c:\windows\ie7updates\KB963027-IE7\iernonce.dll
+ 2009-05-06 00:03 . 2006-10-17 17:06 78336 c:\windows\ie7updates\KB963027-IE7\ieencode.dll
+ 2009-05-06 00:03 . 2008-12-19 09:10 70656 c:\windows\ie7updates\KB963027-IE7\ie4uinit.exe
+ 2009-05-06 00:03 . 2008-12-20 23:15 63488 c:\windows\ie7updates\KB963027-IE7\icardie.dll
+ 2003-03-31 12:00 . 2008-12-16 12:47 351232 c:\windows\system32\winhttp.dll
- 2003-03-31 12:00 . 2004-08-04 04:56 351232 c:\windows\system32\winhttp.dll
- 2003-03-31 12:00 . 2008-12-20 23:15 233472 c:\windows\system32\webcheck.dll
+ 2003-03-31 12:00 . 2009-02-20 18:09 233472 c:\windows\system32\webcheck.dll
+ 2004-10-12 12:20 . 2009-02-06 16:39 227840 c:\windows\system32\wbem\wmiprvse.exe
+ 2004-10-12 12:20 . 2009-02-09 10:20 453120 c:\windows\system32\wbem\wmiprvsd.dll
+ 2004-10-12 12:20 . 2009-02-09 10:20 473088 c:\windows\system32\wbem\fastprox.dll
- 2003-03-31 12:00 . 2008-12-20 23:15 105984 c:\windows\system32\url.dll
+ 2003-03-31 12:00 . 2009-02-20 18:09 105984 c:\windows\system32\url.dll
+ 2008-12-09 19:12 . 2009-02-06 17:14 110592 c:\windows\system32\services.exe
+ 2003-03-31 12:00 . 2009-05-09 15:40 432356 c:\windows\system32\perfh009.dat
- 2003-03-31 12:00 . 2009-03-08 23:02 432356 c:\windows\system32\perfh009.dat
- 2003-03-31 12:00 . 2008-12-20 23:15 102912 c:\windows\system32\occache.dll
+ 2003-03-31 12:00 . 2009-02-20 18:09 102912 c:\windows\system32\occache.dll
- 2003-03-31 12:00 . 2008-12-20 23:15 671232 c:\windows\system32\mstime.dll
+ 2003-03-31 12:00 . 2009-02-20 18:09 671232 c:\windows\system32\mstime.dll
- 2003-03-31 12:00 . 2008-12-20 23:15 193024 c:\windows\system32\msrating.dll
+ 2003-03-31 12:00 . 2009-02-20 18:09 193024 c:\windows\system32\msrating.dll
+ 2003-03-31 12:00 . 2009-02-20 18:09 477696 c:\windows\system32\mshtmled.dll
- 2003-03-31 12:00 . 2008-12-20 23:15 477696 c:\windows\system32\mshtmled.dll
+ 2006-11-08 02:03 . 2009-02-20 18:09 459264 c:\windows\system32\msfeeds.dll
- 2006-11-08 02:03 . 2008-12-20 23:15 459264 c:\windows\system32\msfeeds.dll
+ 2004-10-12 12:20 . 2008-06-12 14:16 161792 c:\windows\system32\msdtcuiu.dll
+ 2004-10-12 12:20 . 2008-06-12 14:16 956928 c:\windows\system32\msdtctm.dll
+ 2004-10-12 12:20 . 2008-06-12 14:16 428032 c:\windows\system32\msdtcprx.dll
+ 2008-12-09 19:12 . 2009-03-21 14:18 986112 c:\windows\system32\kernel32.dll
+ 2006-10-17 16:57 . 2009-02-20 18:09 268288 c:\windows\system32\iertutil.dll
+ 2003-03-31 12:00 . 2009-02-20 18:09 385024 c:\windows\system32\iedkcs32.dll
- 2006-10-17 16:27 . 2008-12-20 23:15 383488 c:\windows\system32\ieapfltr.dll
+ 2006-10-17 16:27 . 2009-02-20 18:09 383488 c:\windows\system32\ieapfltr.dll
- 2003-03-31 12:00 . 2008-12-19 05:23 161792 c:\windows\system32\ieakui.dll
+ 2003-03-31 12:00 . 2009-02-20 05:14 161792 c:\windows\system32\ieakui.dll
+ 2003-03-31 12:00 . 2009-02-20 18:09 230400 c:\windows\system32\ieaksie.dll
- 2003-03-31 12:00 . 2008-12-20 23:15 230400 c:\windows\system32\ieaksie.dll
- 2003-03-31 12:00 . 2008-12-20 23:15 153088 c:\windows\system32\ieakeng.dll
+ 2003-03-31 12:00 . 2009-02-20 18:09 153088 c:\windows\system32\ieakeng.dll
- 2004-10-12 12:48 . 2008-12-20 23:15 133120 c:\windows\system32\extmgr.dll
+ 2004-10-12 12:48 . 2009-02-20 18:09 133120 c:\windows\system32\extmgr.dll
- 2003-03-31 12:00 . 2008-12-20 23:15 214528 c:\windows\system32\dxtrans.dll
+ 2003-03-31 12:00 . 2009-02-20 18:09 214528 c:\windows\system32\dxtrans.dll
+ 2003-03-31 12:00 . 2009-02-20 18:09 347136 c:\windows\system32\dxtmsft.dll
- 2003-03-31 12:00 . 2008-12-20 23:15 347136 c:\windows\system32\dxtmsft.dll
- 2006-05-10 05:23 . 2008-12-20 23:15 826368 c:\windows\system32\dllcache\wininet.dll
+ 2006-05-10 05:23 . 2009-03-03 00:18 826368 c:\windows\system32\dllcache\wininet.dll
+ 2008-12-16 12:47 . 2008-12-16 12:47 351232 c:\windows\system32\dllcache\winhttp.dll
+ 2006-11-08 02:03 . 2009-02-20 18:09 233472 c:\windows\system32\dllcache\webcheck.dll
- 2006-11-08 02:03 . 2008-12-20 23:15 233472 c:\windows\system32\dllcache\webcheck.dll
+ 2006-10-17 17:05 . 2009-02-20 18:09 105984 c:\windows\system32\dllcache\url.dll
- 2006-10-17 17:05 . 2008-12-20 23:15 105984 c:\windows\system32\dllcache\url.dll
+ 2006-10-17 17:04 . 2009-02-20 18:09 102912 c:\windows\system32\dllcache\occache.dll
- 2006-10-17 17:04 . 2008-12-20 23:15 102912 c:\windows\system32\dllcache\occache.dll
- 2006-05-10 05:23 . 2008-12-20 23:15 671232 c:\windows\system32\dllcache\mstime.dll
+ 2006-05-10 05:23 . 2009-02-20 18:09 671232 c:\windows\system32\dllcache\mstime.dll
- 2006-05-10 05:23 . 2008-12-20 23:15 193024 c:\windows\system32\dllcache\msrating.dll
+ 2006-05-10 05:23 . 2009-02-20 18:09 193024 c:\windows\system32\dllcache\msrating.dll
- 2006-05-10 05:23 . 2008-12-20 23:15 477696 c:\windows\system32\dllcache\mshtmled.dll
+ 2006-05-10 05:23 . 2009-02-20 18:09 477696 c:\windows\system32\dllcache\mshtmled.dll
- 2007-05-10 00:14 . 2008-12-20 23:15 459264 c:\windows\system32\dllcache\msfeeds.dll
+ 2007-05-10 00:14 . 2009-02-20 18:09 459264 c:\windows\system32\dllcache\msfeeds.dll
+ 2008-06-12 14:16 . 2008-06-12 14:16 161792 c:\windows\system32\dllcache\msdtcuiu.dll
+ 2008-06-12 14:16 . 2008-06-12 14:16 956928 c:\windows\system32\dllcache\msdtctm.dll
+ 2008-06-12 14:16 . 2008-06-12 14:16 428032 c:\windows\system32\dllcache\msdtcprx.dll
+ 2008-12-09 19:12 . 2009-02-09 10:20 723456 c:\windows\system32\dllcache\lsasrv.dll
+ 2008-12-09 19:12 . 2009-03-21 14:18 986112 c:\windows\system32\dllcache\kernel32.dll
+ 2006-10-17 17:04 . 2009-02-28 04:54 636072 c:\windows\system32\dllcache\iexplore.exe
+ 2007-05-10 00:14 . 2009-02-20 18:09 268288 c:\windows\system32\dllcache\iertutil.dll
+ 2006-11-07 08:27 . 2009-02-20 18:09 385024 c:\windows\system32\dllcache\iedkcs32.dll
- 2007-05-10 00:14 . 2008-12-20 23:15 383488 c:\windows\system32\dllcache\ieapfltr.dll
+ 2007-05-10 00:14 . 2009-02-20 18:09 383488 c:\windows\system32\dllcache\ieapfltr.dll
- 2003-03-31 12:00 . 2008-12-19 05:23 161792 c:\windows\system32\dllcache\ieakui.dll
+ 2003-03-31 12:00 . 2009-02-20 05:14 161792 c:\windows\system32\dllcache\ieakui.dll
+ 2006-11-07 08:27 . 2009-02-20 18:09 230400 c:\windows\system32\dllcache\ieaksie.dll
- 2006-11-07 08:27 . 2008-12-20 23:15 230400 c:\windows\system32\dllcache\ieaksie.dll
+ 2006-11-07 08:26 . 2009-02-20 18:09 153088 c:\windows\system32\dllcache\ieakeng.dll
- 2006-11-07 08:26 . 2008-12-20 23:15 153088 c:\windows\system32\dllcache\ieakeng.dll
+ 2006-05-10 05:22 . 2009-02-20 18:09 133120 c:\windows\system32\dllcache\extmgr.dll
- 2006-05-10 05:22 . 2008-12-20 23:15 133120 c:\windows\system32\dllcache\extmgr.dll
+ 2006-05-10 05:22 . 2009-02-20 18:09 214528 c:\windows\system32\dllcache\dxtrans.dll
- 2006-05-10 05:22 . 2008-12-20 23:15 214528 c:\windows\system32\dllcache\dxtrans.dll
- 2006-05-10 05:22 . 2008-12-20 23:15 347136 c:\windows\system32\dllcache\dxtmsft.dll
+ 2006-05-10 05:22 . 2009-02-20 18:09 347136 c:\windows\system32\dllcache\dxtmsft.dll
- 2006-11-07 08:26 . 2008-12-20 23:15 124928 c:\windows\system32\dllcache\advpack.dll
+ 2006-11-07 08:26 . 2009-02-20 18:09 124928 c:\windows\system32\dllcache\advpack.dll
- 2003-03-31 12:00 . 2008-12-20 23:15 124928 c:\windows\system32\advpack.dll
+ 2003-03-31 12:00 . 2009-02-20 18:09 124928 c:\windows\system32\advpack.dll
+ 2009-05-06 00:03 . 2008-12-20 23:15 826368 c:\windows\ie7updates\KB963027-IE7\wininet.dll
+ 2009-05-06 00:03 . 2008-12-20 23:15 233472 c:\windows\ie7updates\KB963027-IE7\webcheck.dll
+ 2009-05-06 00:03 . 2008-12-20 23:15 105984 c:\windows\ie7updates\KB963027-IE7\url.dll
+ 2009-05-06 00:03 . 2008-07-09 07:38 382840 c:\windows\ie7updates\KB963027-IE7\spuninst\updspapi.dll
+ 2009-05-06 00:03 . 2008-07-08 13:02 231288 c:\windows\ie7updates\KB963027-IE7\spuninst\spuninst.exe
+ 2009-05-06 00:03 . 2008-12-20 23:15 102912 c:\windows\ie7updates\KB963027-IE7\occache.dll
+ 2009-05-06 00:03 . 2008-12-20 23:15 671232 c:\windows\ie7updates\KB963027-IE7\mstime.dll
+ 2009-05-06 00:03 . 2008-12-20 23:15 193024 c:\windows\ie7updates\KB963027-IE7\msrating.dll
+ 2009-05-06 00:03 . 2008-12-20 23:15 477696 c:\windows\ie7updates\KB963027-IE7\mshtmled.dll
+ 2009-05-06 00:03 . 2008-12-20 23:15 459264 c:\windows\ie7updates\KB963027-IE7\msfeeds.dll
+ 2009-05-06 00:03 . 2008-12-19 05:25 634024 c:\windows\ie7updates\KB963027-IE7\iexplore.exe
+ 2009-05-06 00:03 . 2008-12-20 23:15 267776 c:\windows\ie7updates\KB963027-IE7\iertutil.dll
+ 2009-05-06 00:03 . 2008-12-20 23:15 384512 c:\windows\ie7updates\KB963027-IE7\iedkcs32.dll
+ 2009-05-06 00:03 . 2008-12-20 23:15 383488 c:\windows\ie7updates\KB963027-IE7\ieapfltr.dll
+ 2009-05-06 00:03 . 2008-12-19 05:23 161792 c:\windows\ie7updates\KB963027-IE7\ieakui.dll
+ 2009-05-06 00:03 . 2008-12-20 23:15 230400 c:\windows\ie7updates\KB963027-IE7\ieaksie.dll
+ 2009-05-06 00:03 . 2008-12-20 23:15 153088 c:\windows\ie7updates\KB963027-IE7\ieakeng.dll
+ 2009-05-06 00:03 . 2008-12-20 23:15 133120 c:\windows\ie7updates\KB963027-IE7\extmgr.dll
+ 2009-05-06 00:03 . 2008-12-20 23:15 214528 c:\windows\ie7updates\KB963027-IE7\dxtrans.dll
+ 2009-05-06 00:03 . 2008-12-20 23:15 347136 c:\windows\ie7updates\KB963027-IE7\dxtmsft.dll
+ 2009-05-06 00:03 . 2008-12-20 23:15 124928 c:\windows\ie7updates\KB963027-IE7\advpack.dll
+ 2009-05-09 15:39 . 2009-05-09 15:39 438272 c:\windows\ERDNT\AutoBackup\5-9-2009\Users\
00000002\UsrClass.dat
+ 2009-05-09 15:39 . 2005-10-20 16:02 163328 c:\windows\ERDNT\AutoBackup\5-9-2009\ERDNT.EXE
+ 2009-05-05 20:47 . 2009-05-05 20:47 438272 c:\windows\ERDNT\AutoBackup\5-5-2009\Users\
00000002\UsrClass.dat
+ 2009-05-05 20:47 . 2005-10-20 16:02 163328 c:\windows\ERDNT\AutoBackup\5-5-2009\ERDNT.EXE
+ 2003-03-31 12:00 . 2009-02-20 18:09 1160192 c:\windows\system32\urlmon.dll
- 2003-03-31 12:00 . 2008-12-20 23:15 1160192 c:\windows\system32\urlmon.dll
+ 2004-10-12 12:31 . 2008-12-20 22:43 1287680 c:\windows\system32\quartz.dll
- 2004-10-12 12:31 . 2008-05-07 05:18 1287680 c:\windows\system32\quartz.dll
+ 2008-12-09 19:12 . 2009-02-06 17:24 2180480 c:\windows\system32\ntoskrnl.exe
- 2008-12-09 19:12 . 2008-08-14 09:22 2057728 c:\windows\system32\ntkrnlpa.exe
+ 2008-12-09 19:12 . 2009-02-06 16:49 2057728 c:\windows\system32\ntkrnlpa.exe
+ 2003-03-31 12:00 . 2009-02-20 18:09 3595264 c:\windows\system32\mshtml.dll
+ 2006-11-08 02:03 . 2009-02-20 18:09 6066176 c:\windows\system32\ieframe.dll
- 2006-09-06 04:01 . 2007-04-17 09:28 2455488 c:\windows\system32\ieapfltr.dat
+ 2006-09-06 04:01 . 2008-07-09 14:25 2455488 c:\windows\system32\ieapfltr.dat
- 2006-05-10 05:23 . 2008-12-20 23:15 1160192 c:\windows\system32\dllcache\urlmon.dll
+ 2006-05-10 05:23 . 2009-02-20 18:09 1160192 c:\windows\system32\dllcache\urlmon.dll
+ 2008-12-09 19:13 . 2008-12-20 22:43 1287680 c:\windows\system32\dllcache\quartz.dll
- 2008-12-09 19:13 . 2008-05-07 05:18 1287680 c:\windows\system32\dllcache\quartz.dll
+ 2008-12-09 19:12 . 2009-02-06 17:24 2180480 c:\windows\system32\dllcache\ntoskrnl.exe
- 2008-12-09 19:14 . 2008-08-14 09:22 2015744 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2008-12-09 19:14 . 2009-02-06 16:49 2015744 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2008-12-09 19:12 . 2009-02-06 16:49 2057728 c:\windows\system32\dllcache\ntkrnlpa.exe
- 2008-12-09 19:12 . 2008-08-14 09:22 2057728 c:\windows\system32\dllcache\ntkrnlpa.exe
- 2008-12-09 19:14 . 2008-08-14 09:58 2136064 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2008-12-09 19:14 . 2009-02-06 17:22 2136064 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2006-05-19 15:08 . 2009-02-20 18:09 3595264 c:\windows\system32\dllcache\mshtml.dll
+ 2007-05-10 00:14 . 2009-02-20 18:09 6066176 c:\windows\system32\dllcache\ieframe.dll
- 2007-05-10 00:14 . 2007-04-17 09:28 2455488 c:\windows\system32\dllcache\ieapfltr.dat
+ 2007-05-10 00:14 . 2008-07-09 14:25 2455488 c:\windows\system32\dllcache\ieapfltr.dat
+ 2009-05-06 00:03 . 2008-12-20 23:15 1160192 c:\windows\ie7updates\KB963027-IE7\urlmon.dll
+ 2009-05-06 00:03 . 2009-01-17 02:35 3594752 c:\windows\ie7updates\KB963027-IE7\mshtml.dll
+ 2009-05-06 00:03 . 2008-12-20 23:15 6066688 c:\windows\ie7updates\KB963027-IE7\ieframe.dll
+ 2009-05-06 00:03 . 2007-04-17 09:28 2455488 c:\windows\ie7updates\KB963027-IE7\ieapfltr.dat
+ 2009-05-09 15:39 . 2009-05-09 15:39 7270400 c:\windows\ERDNT\AutoBackup\5-9-2009\Users\
00000001\NTUSER.DAT
- 2009-05-05 20:47 . 2009-05-05 20:47 7270400 c:\windows\ERDNT\AutoBackup\5-5-2009\Users\
00000001\NTUSER.DAT
+ 2009-05-05 20:47 . 2009-05-05 20:47 7270400 c:\windows\ERDNT\AutoBackup\5-5-2009\Users\
00000001\NTUSER.DAT
+ 2008-12-09 19:12 . 2009-02-06 17:24 2180480 c:\windows\Driver Cache\i386\ntoskrnl.exe
- 2008-12-09 19:14 . 2008-08-14 09:22 2015744 c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2008-12-09 19:14 . 2009-02-06 16:49 2015744 c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2008-12-09 19:12 . 2008-08-14 09:22 2057728 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2008-12-09 19:12 . 2009-02-06 16:49 2057728 c:\windows\Driver Cache\i386\ntkrnlpa.exe
- 2008-12-09 19:14 . 2008-08-14 09:58 2136064 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2008-12-09 19:14 . 2009-02-06 17:22 2136064 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2009-05-06 00:01 . 2009-04-06 11:57 24921544 c:\windows\system32\MRT.exe
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"Radio365Agent"="c:\progra~1\Live365\Radio365\Radio365TrayAgent.exe" [2005-09-22 303104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RoxioDragToDisc"="c:\program files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe" [2004-06-24 1691648]
"DiskeeperSystray"="c:\program files\Executive Software\Diskeeper\DkIcon.exe" [2004-10-05 176216]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-25 339968]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 2178832]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-09 515416]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"CARPService"="carpserv.exe" - c:\windows\system32\carpserv.exe [2003-06-11 4608]
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
PowerReg SchedulerV2.exe [2004-10-13 256000]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Exif Launcher S.lnk - c:\program files\FinePixViewerS\QuickDCF2.exe [2008-8-18 303104]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-4 258048]
NaturalColorLoad.lnk - c:\program files\SEC\Natural Color\NaturalColorLoad.exe [2004-10-12 155715]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2005-4-3 663552]
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"MIDI1"= SYNCOR11.DLL
"wave1"= serwvdrv.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Documents and Settings\\Administrator\\GypsyPatcher.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\StubInstaller.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\Administrator\\Desktop\\WotC Games\\Rosetta Stone\\support\\bin\\win\\RosettaStoneLtdServices.exe"=
"c:\\Documents and Settings\\Administrator\\Desktop\\WotC Games\\Rosetta Stone\\RosettaStoneVersion3.exe"=
"c:\\Documents and Settings\\Administrator\\Desktop\\WotC Games\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\Executive Software\\Diskeeper\\DkService.exe"=
"c:\\Program Files\\Analog Devices\\SoundMAX\\SMAgent.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\jusched.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\WINDOWS\\system32\\ftp.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Common Files\\Apple\\Mobile Device Support\\bin\\AppleMobileDeviceService.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\iPod\\bin\\iPodService.exe"=
"c:\\Program Files\\MusicBrainz Picard\\picard.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [3/18/2009 7:07 PM 64160]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 3:06 PM 951632]
— Other Services/Drivers In Memory —
*Deregistered* - IPVNMon
.
Contents of the 'Scheduled Tasks' folder
2009-03-23 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 19:06]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\4u8gj8de.default\
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin9.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-05-09 12:52
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(696)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-05-09 12:54
ComboFix-quarantined-files.txt 2009-05-09 16:53
ComboFix2.txt 2009-05-05 20:52
Pre-Run: 66,555,170,816 bytes free
Post-Run: 66,538,119,168 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
469 — E O F — 2009-05-06 00:04
Upload was successful
Kapersky
——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0 REPORT
Saturday, May 9, 2009
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Saturday, May 09, 2009 19:04:57
Records in database: 2151722
——————————————————————————–
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
A:\
C:\
D:\
Scan statistics:
Files scanned: 136789
Threat name: 6
Infected objects: 25
Suspicious objects: 0
Duration of the scan: 03:17:24
File name / Threat name / Threats count
C:\Documents and Settings\Administrator\Desktop\WotC Games\ess_nt32_enu.msi Infected: Trojan.Win32.VB.mpj 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\goyinoro.dll.vir Infected: Trojan.Win32.Monder.byqu 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\hobavana.dll.vir Infected: Trojan.Win32.Monder.byqu 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\ketedoti.dll.vir Infected: Trojan.Win32.Stuh.bur 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\ninegozu.exe.vir Infected: Trojan-Downloader.Win32.FraudLoad.vohb 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\zuziberi.exe.vir Infected: Trojan-Downloader.Win32.FraudLoad.vohb 1
C:\Qoobox\Quarantine\[4]-Submit_2009-05-09_12.48.45.zip Infected: Trojan-Downloader.Win32.FraudLoad.vohb 4
C:\Qoobox\Quarantine\[4]-Submit_2009-05-09_12.48.45.zip Infected: Trojan.Win32.Stuh.bur 2
C:\Qoobox\Quarantine\[4]-Submit_2009-05-09_12.48.45.zip Infected: Trojan-Downloader.Win32.FraudLoad.vnjh 1
C:\System Volume Information\_restore{7D0CBF76-301B-49F1-9EC9-36B8B9932C45}\RP1118\A0291603.msi Infected: Trojan.Win32.VB.mpj 1
C:\System Volume Information\_restore{7D0CBF76-301B-49F1-9EC9-36B8B9932C45}\RP1128\A0293357.dll Infected: Trojan.Win32.Stuh.bur 1
C:\System Volume Information\_restore{7D0CBF76-301B-49F1-9EC9-36B8B9932C45}\RP1129\A0293396.dll Infected: Trojan.Win32.Stuh.qf 1
C:\System Volume Information\_restore{7D0CBF76-301B-49F1-9EC9-36B8B9932C45}\RP1129\A0293397.dll Infected: Trojan.Win32.Stuh.qf 1
C:\System Volume Information\_restore{7D0CBF76-301B-49F1-9EC9-36B8B9932C45}\RP1129\A0293398.dll Infected: Trojan.Win32.Stuh.qf 1
C:\System Volume Information\_restore{7D0CBF76-301B-49F1-9EC9-36B8B9932C45}\RP1137\A0295738.rbf Infected: Trojan.Win32.VB.mpj 1
C:\System Volume Information\_restore{7D0CBF76-301B-49F1-9EC9-36B8B9932C45}\RP1137\A0295794.msi Infected: Trojan.Win32.VB.mpj 1
C:\System Volume Information\_restore{7D0CBF76-301B-49F1-9EC9-36B8B9932C45}\RP1137\A0296018.dll Infected: Trojan.Win32.Monder.byqu 1
C:\System Volume Information\_restore{7D0CBF76-301B-49F1-9EC9-36B8B9932C45}\RP1137\A0296019.dll Infected: Trojan.Win32.Monder.byqu 1
C:\System Volume Information\_restore{7D0CBF76-301B-49F1-9EC9-36B8B9932C45}\RP1137\A0296029.dll Infected: Trojan.Win32.Stuh.bur 1
C:\System Volume Information\_restore{7D0CBF76-301B-49F1-9EC9-36B8B9932C45}\RP1137\A0296061.exe Infected: Trojan-Downloader.Win32.FraudLoad.vohb 1
C:\System Volume Information\_restore{7D0CBF76-301B-49F1-9EC9-36B8B9932C45}\RP1137\A0296062.exe Infected: Trojan-Downloader.Win32.FraudLoad.vohb 1
The selected area was scanned.