ComboFix 09-06-16.05 - Admin 06/17/2009 15:34.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.673 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\skit.exe
AV: AVG Anti-Virus *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\_id.dat
c:\windows\system32\drivers\UACddtpqmdvkaiddxc.sys
c:\windows\system32\UACawuxjwylyoawhpx.dll
c:\windows\system32\UACbjkluiyougcwwmx.dll
c:\windows\system32\UACdlwowjwobpnkhdh.log
c:\windows\system32\uacinit.dll
c:\windows\system32\UACiocjrqljtmoyvpa.dll
c:\windows\system32\UACmiubdooysveoxnd.dat
c:\windows\system32\UACnlguhylabefnmtp.dll
c:\windows\system32\UACnuodlytrmqydqvk.dll
c:\windows\system32\UACqppvrbkaksdfgjc.log
c:\windows\system32\UACsrpxtetdrxhlxud.dll
c:\windows\system32\uactmp.db
c:\windows\system32\UACxahrnqjumcvbphq.log
c:\windows\system32\UACyxebfdwvjlekvjn.db
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_UACd.sys
((((((((((((((((((((((((( Files Created from 2009-05-17 to 2009-06-17 )))))))))))))))))))))))))))))))
.
2009-06-17 03:27 . 2009-06-17 03:29 ——– d—–w- C:\!KillBox
2009-06-16 12:07 . 2009-05-18 21:07 2052376 —-a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-06-16 12:07 . 2009-06-11 12:32 3298072 —-a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\setup.exe
2009-06-16 12:07 . 2009-06-11 12:32 1261344 —-a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgwd.dll
2009-06-16 12:07 . 2009-06-11 12:32 829208 —-a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcfgx.dll
2009-06-15 20:39 . 2009-06-15 20:42 ——– d—–w- c:\program files\Windows Live Safety Center
2009-06-15 20:20 . 2009-05-19 05:36 2884832 ——w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\vwpt.exe
2009-06-15 20:20 . 2009-05-19 05:36 28 ——w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\unregister.bat
2009-06-15 20:20 . 2009-05-19 05:36 30512 ——w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\Uninstaller.exe
2009-06-15 20:20 . 2009-05-19 05:35 376568 ——w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\unagi3.exe
2009-06-15 20:20 . 2009-05-19 05:36 1484856 ——w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\toolbar.exe
2009-06-15 20:20 . 2009-05-19 05:35 11568 ——w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\tbinst.dll
2009-06-15 20:20 . 2009-05-19 05:35 383128 ——w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\tbsetup.exe
2009-06-15 20:20 . 2009-05-19 05:35 172840 ——w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\setup.exe
2009-06-11 12:32 . 2009-06-11 12:32 1452312 —-a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.dll
2009-05-21 00:53 . 2009-05-21 00:53 ——– d—–w- c:\program files\ESET
2009-05-19 18:17 . 2009-05-19 18:17 ——– d—–w- C:\rsit
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-17 03:29 . 2009-05-11 22:15 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-06-17 03:27 . 2009-02-23 02:05 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-06-16 12:06 . 2009-02-08 22:17 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-15 18:19 . 2009-02-08 22:17 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2009-06-15 17:19 . 2009-02-09 21:30 ——– d—–w- c:\documents and settings\Admin\Application Data\Azureus
2009-06-11 12:32 . 2009-02-08 22:17 327688 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-05-26 17:20 . 2009-05-11 22:15 40160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-26 17:19 . 2009-05-11 22:15 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-05-23 14:34 . 2009-02-16 20:54 ——– d—–w- c:\documents and settings\Admin\Application Data\LimeWire
2009-05-22 20:40 . 2007-05-01 19:59 56 –sh–r- c:\windows\system32\C34AC63E24.sys
2009-05-22 20:40 . 2007-05-01 19:59 4288 –sha-w- c:\windows\system32\KGyGaAvL.sys
2009-05-19 05:36 . 2009-06-15 20:19 25 ——w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\register.bat
2009-05-19 05:36 . 2009-06-15 20:19 97072 ——w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\bsetutil.exe
2009-05-19 05:36 . 2009-06-15 20:19 142040 ——w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\alsetup.exe
2009-05-19 05:36 . 2009-06-15 20:19 111920 ——w- c:\documents and settings\All Users\Application Data\AOL OCP\AIM\Storage\All Users\SUDS_BBC2683C\CACHE\4426.0.4\AOLSearch.dll
2009-05-11 22:15 . 2009-05-11 22:15 ——– d—–w- c:\documents and settings\Admin\Application Data\Malwarebytes
2009-05-11 22:15 . 2009-05-11 22:15 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-09 16:27 . 2009-05-09 16:27 ——– d—–w- c:\program files\Trend Micro
2009-05-07 15:32 . 2004-08-10 18:51 345600 —-a-w- c:\windows\system32\localspl.dll
2009-04-29 23:47 . 2009-04-29 23:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-04-29 22:23 . 2009-02-08 22:17 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-04-29 22:22 . 2009-02-08 22:17 12552 —-a-w- c:\windows\system32\drivers\avgrkx86.sys
2009-04-29 22:22 . 2009-02-08 22:17 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-04-29 04:56 . 2004-08-10 18:51 827392 —-a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2004-08-10 18:51 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-04-25 18:37 . 2009-02-23 00:55 ——– d—–w- c:\documents and settings\Admin\Application Data\GetRightToGo
2009-04-25 17:59 . 2009-02-09 21:35 7114736 —-a-w- c:\documents and settings\Admin\Application Data\Azureus\plugins\azemp\azmplay.exe
2009-04-19 10:49 . 2009-04-19 10:49 64512 —-a-w- c:\documents and settings\iris\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u4\HTML\item_templ\coach\RunGdp.exe
2009-04-19 10:47 . 2009-04-19 10:47 698511 —-a-w- c:\documents and settings\iris\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u2\HTML\AutoMaintenance\AutoMaintenance.dll
2009-04-19 10:47 . 2009-04-19 10:47 225280 —-a-w- c:\documents and settings\iris\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u2\HTML\AutoMaintenance\Images.dll
2009-04-19 10:46 . 2009-04-13 01:30 ——– d—–w- c:\program files\Microsoft ActiveSync
2009-04-19 10:46 . 2009-03-16 16:56 ——– d—–w- c:\documents and settings\iris\Application Data\GTek
2009-04-19 10:46 . 2009-04-19 10:46 1896448 —-a-w- c:\documents and settings\iris\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\dplugins\2.0.1.571\DiagPlugin.dll
2009-04-19 10:46 . 2009-04-19 10:46 123138 —-a-w- c:\documents and settings\iris\Application Data\GTek\GTUpdate\AUpdate\Channels\ch_u1\HTML\MakeDesktopShortcut.EXE
2009-04-17 12:26 . 2004-08-10 18:51 1847168 —-a-w- c:\windows\system32\win32k.sys
2009-04-16 01:37 . 2009-04-16 01:37 81920 —-a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
2009-04-16 01:37 . 2009-04-16 01:37 98304 —-a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\nxgameus.dll
2009-04-16 01:37 . 2009-04-16 01:37 258352 —-a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\unicows.dll
2009-04-16 01:37 . 2009-04-16 01:37 520192 —-a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\NGMDll.dll
2009-04-16 01:37 . 2009-04-16 01:37 335872 —-a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\NGMResource.dll
2009-04-16 01:37 . 2009-04-16 01:37 167936 —-a-w- c:\documents and settings\All Users\Application Data\NexonUS\NGM\NGM.exe
2009-04-15 14:51 . 2004-08-10 18:51 585216 —-a-w- c:\windows\system32\rpcrt4.dll
2009-03-27 18:41 . 2009-03-27 18:41 152576 —-a-w- c:\documents and settings\Admin\Application Data\Sun\Java\jre1.6.0_11\lzma.dll
2007-08-04 00:31 . 2007-05-03 19:50 88 –sh–r- c:\windows\system32\243EC64AC3.sys
.
((((((((((((((((((((((((((((( SnapShot@2009-05-10_15.26.03 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-02-19 21:59 . 2007-11-30 12:39 17272 c:\windows\system32\spmsg.dll
+ 2009-02-19 21:59 . 2008-07-09 07:38 17272 c:\windows\system32\spmsg.dll
+ 2004-08-10 18:51 . 2009-04-29 04:56 44544 c:\windows\system32\pngfilt.dll
- 2004-08-10 18:51 . 2009-02-20 18:09 44544 c:\windows\system32\pngfilt.dll
- 2004-08-10 18:51 . 2009-05-10 15:01 63016 c:\windows\system32\perfc009.dat
+ 2004-08-10 18:51 . 2009-06-17 19:38 63016 c:\windows\system32\perfc009.dat
- 2007-08-13 22:54 . 2009-02-20 18:09 52224 c:\windows\system32\msfeedsbs.dll
+ 2007-08-13 22:54 . 2009-04-29 04:55 52224 c:\windows\system32\msfeedsbs.dll
- 2009-02-06 22:48 . 2009-03-09 19:58 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2009-02-06 22:48 . 2009-06-10 22:08 84661 c:\windows\system32\Macromed\Flash\uninstall_plugin.exe
+ 2004-08-10 18:51 . 2009-04-29 04:55 27648 c:\windows\system32\jsproxy.dll
- 2004-08-10 18:51 . 2009-02-20 18:09 27648 c:\windows\system32\jsproxy.dll
- 2007-08-13 22:39 . 2009-02-20 10:20 13824 c:\windows\system32\ieudinit.exe
+ 2007-08-13 22:39 . 2009-04-28 09:05 13824 c:\windows\system32\ieudinit.exe
- 2004-08-10 18:51 . 2009-02-20 18:09 44544 c:\windows\system32\iernonce.dll
+ 2004-08-10 18:51 . 2009-04-29 04:55 44544 c:\windows\system32\iernonce.dll
- 2004-08-10 18:51 . 2009-02-20 10:20 70656 c:\windows\system32\ie4uinit.exe
+ 2004-08-10 18:51 . 2009-04-28 09:05 70656 c:\windows\system32\ie4uinit.exe
+ 2007-08-13 22:36 . 2009-04-29 04:55 63488 c:\windows\system32\icardie.dll
- 2007-08-13 22:36 . 2009-02-20 18:09 63488 c:\windows\system32\icardie.dll
- 2006-06-23 11:25 . 2009-02-20 18:09 44544 c:\windows\system32\dllcache\pngfilt.dll
+ 2006-06-23 11:25 . 2009-04-29 04:56 44544 c:\windows\system32\dllcache\pngfilt.dll
- 2008-10-18 22:44 . 2009-02-20 18:09 52224 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2008-10-18 22:44 . 2009-04-29 04:55 52224 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2006-06-23 11:25 . 2009-04-29 04:55 27648 c:\windows\system32\dllcache\jsproxy.dll
- 2006-06-23 11:25 . 2009-02-20 18:09 27648 c:\windows\system32\dllcache\jsproxy.dll
+ 2008-10-18 22:44 . 2009-04-28 09:05 13824 c:\windows\system32\dllcache\ieudinit.exe
- 2008-10-18 22:44 . 2009-02-20 10:20 13824 c:\windows\system32\dllcache\ieudinit.exe
+ 2007-08-13 22:39 . 2009-04-29 04:55 44544 c:\windows\system32\dllcache\iernonce.dll
- 2007-08-13 22:39 . 2009-02-20 18:09 44544 c:\windows\system32\dllcache\iernonce.dll
+ 2009-02-20 18:09 . 2009-04-29 04:55 78336 c:\windows\system32\dllcache\ieencode.dll
- 2009-02-20 18:09 . 2009-02-20 18:09 78336 c:\windows\system32\dllcache\ieencode.dll
- 2007-08-13 22:39 . 2009-02-20 10:20 70656 c:\windows\system32\dllcache\ie4uinit.exe
+ 2007-08-13 22:39 . 2009-04-28 09:05 70656 c:\windows\system32\dllcache\ie4uinit.exe
+ 2008-10-18 22:44 . 2009-04-29 04:55 63488 c:\windows\system32\dllcache\icardie.dll
- 2008-10-18 22:44 . 2009-02-20 18:09 63488 c:\windows\system32\dllcache\icardie.dll
- 2006-03-13 22:43 . 2009-05-06 23:52 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2006-03-13 22:43 . 2009-06-16 19:31 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2006-03-13 22:43 . 2009-06-16 19:31 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2006-03-13 22:43 . 2009-05-06 23:52 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2006-03-13 22:43 . 2009-06-16 19:31 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2006-03-13 22:43 . 2009-05-06 23:52 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-02-23 02:09 . 2009-04-25 18:42 35088 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
+ 2009-02-23 02:09 . 2009-06-12 07:06 35088 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
+ 2009-02-23 02:09 . 2009-06-12 07:06 18704 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
- 2009-02-23 02:09 . 2009-04-25 18:42 18704 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
- 2009-02-23 02:09 . 2009-04-25 18:42 20240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
+ 2009-02-23 02:09 . 2009-06-12 07:06 20240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
+ 2009-06-12 07:01 . 2009-02-20 18:09 44544 c:\windows\ie7updates\KB969897-IE7\pngfilt.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 52224 c:\windows\ie7updates\KB969897-IE7\msfeedsbs.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 27648 c:\windows\ie7updates\KB969897-IE7\jsproxy.dll
+ 2009-06-12 07:01 . 2009-02-20 10:20 13824 c:\windows\ie7updates\KB969897-IE7\ieudinit.exe
+ 2009-06-12 07:01 . 2009-02-20 18:09 44544 c:\windows\ie7updates\KB969897-IE7\iernonce.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 78336 c:\windows\ie7updates\KB969897-IE7\ieencode.dll
+ 2009-06-12 07:01 . 2009-02-20 10:20 70656 c:\windows\ie7updates\KB969897-IE7\ie4uinit.exe
+ 2009-06-12 07:01 . 2009-02-20 18:09 63488 c:\windows\ie7updates\KB969897-IE7\icardie.dll
- 2004-08-10 18:51 . 2009-02-20 18:09 233472 c:\windows\system32\webcheck.dll
+ 2004-08-10 18:51 . 2009-04-29 04:56 233472 c:\windows\system32\webcheck.dll
- 2004-08-10 18:51 . 2009-02-20 18:09 105984 c:\windows\system32\url.dll
+ 2004-08-10 18:51 . 2009-04-29 04:56 105984 c:\windows\system32\url.dll
- 2004-08-10 18:51 . 2009-05-10 15:01 402406 c:\windows\system32\perfh009.dat
+ 2004-08-10 18:51 . 2009-06-17 19:38 402406 c:\windows\system32\perfh009.dat
- 2004-08-10 18:51 . 2009-02-20 18:09 102912 c:\windows\system32\occache.dll
+ 2004-08-10 18:51 . 2009-04-29 04:56 102912 c:\windows\system32\occache.dll
- 2004-08-10 18:51 . 2009-02-20 18:09 671232 c:\windows\system32\mstime.dll
+ 2004-08-10 18:51 . 2009-04-29 04:56 671232 c:\windows\system32\mstime.dll
+ 2004-08-10 18:51 . 2009-04-29 04:56 193024 c:\windows\system32\msrating.dll
- 2004-08-10 18:51 . 2009-02-20 18:09 193024 c:\windows\system32\msrating.dll
- 2004-08-10 18:51 . 2009-02-20 18:09 477696 c:\windows\system32\mshtmled.dll
+ 2004-08-10 18:51 . 2009-04-29 04:56 477696 c:\windows\system32\mshtmled.dll
- 2007-08-13 22:54 . 2009-02-20 18:09 459264 c:\windows\system32\msfeeds.dll
+ 2007-08-13 22:54 . 2009-04-29 04:55 459264 c:\windows\system32\msfeeds.dll
+ 2007-08-13 22:34 . 2009-04-29 04:55 268288 c:\windows\system32\iertutil.dll
- 2007-08-13 22:34 . 2009-02-20 18:09 268288 c:\windows\system32\iertutil.dll
+ 2004-08-10 18:51 . 2009-04-29 04:55 385024 c:\windows\system32\iedkcs32.dll
- 2004-08-10 18:51 . 2009-02-20 18:09 385024 c:\windows\system32\iedkcs32.dll
- 2007-07-11 16:27 . 2009-02-20 18:09 383488 c:\windows\system32\ieapfltr.dll
+ 2007-07-11 16:27 . 2009-04-29 04:55 383488 c:\windows\system32\ieapfltr.dll
+ 2004-08-10 18:51 . 2009-04-25 05:26 161792 c:\windows\system32\ieakui.dll
- 2004-08-10 18:51 . 2009-02-20 05:14 161792 c:\windows\system32\ieakui.dll
+ 2004-08-10 18:51 . 2009-04-29 04:55 230400 c:\windows\system32\ieaksie.dll
- 2004-08-10 18:51 . 2009-02-20 18:09 230400 c:\windows\system32\ieaksie.dll
+ 2004-08-10 18:51 . 2009-04-29 04:55 153088 c:\windows\system32\ieakeng.dll
- 2004-08-10 18:51 . 2009-02-20 18:09 153088 c:\windows\system32\ieakeng.dll
+ 2004-08-10 18:57 . 2009-06-12 07:12 233576 c:\windows\system32\FNTCACHE.DAT
- 2004-08-10 18:57 . 2009-03-11 07:07 233576 c:\windows\system32\FNTCACHE.DAT
- 2004-08-10 18:51 . 2009-02-20 18:09 133120 c:\windows\system32\extmgr.dll
+ 2004-08-10 18:51 . 2009-04-29 04:55 133120 c:\windows\system32\extmgr.dll
- 2004-08-10 18:51 . 2009-02-20 18:09 214528 c:\windows\system32\dxtrans.dll
+ 2004-08-10 18:51 . 2009-04-29 04:55 214528 c:\windows\system32\dxtrans.dll
- 2004-08-10 18:51 . 2009-02-20 18:09 347136 c:\windows\system32\dxtmsft.dll
+ 2004-08-10 18:51 . 2009-04-29 04:55 347136 c:\windows\system32\dxtmsft.dll
+ 2006-06-23 11:25 . 2009-04-29 04:56 827392 c:\windows\system32\dllcache\wininet.dll
+ 2007-08-13 22:54 . 2009-04-29 04:56 233472 c:\windows\system32\dllcache\webcheck.dll
- 2007-08-13 22:54 . 2009-02-20 18:09 233472 c:\windows\system32\dllcache\webcheck.dll
+ 2007-08-13 22:44 . 2009-04-29 04:56 105984 c:\windows\system32\dllcache\url.dll
- 2007-08-13 22:44 . 2009-02-20 18:09 105984 c:\windows\system32\dllcache\url.dll
+ 2009-04-15 14:51 . 2009-04-15 14:51 585216 c:\windows\system32\dllcache\rpcrt4.dll
+ 2007-08-13 22:44 . 2009-04-29 04:56 102912 c:\windows\system32\dllcache\occache.dll
- 2007-08-13 22:44 . 2009-02-20 18:09 102912 c:\windows\system32\dllcache\occache.dll
- 2006-06-23 11:25 . 2009-02-20 18:09 671232 c:\windows\system32\dllcache\mstime.dll
+ 2006-06-23 11:25 . 2009-04-29 04:56 671232 c:\windows\system32\dllcache\mstime.dll
+ 2006-06-23 11:25 . 2009-04-29 04:56 193024 c:\windows\system32\dllcache\msrating.dll
- 2006-06-23 11:25 . 2009-02-20 18:09 193024 c:\windows\system32\dllcache\msrating.dll
- 2006-06-23 11:25 . 2009-02-20 18:09 477696 c:\windows\system32\dllcache\mshtmled.dll
+ 2006-06-23 11:25 . 2009-04-29 04:56 477696 c:\windows\system32\dllcache\mshtmled.dll
- 2008-10-18 22:44 . 2009-02-20 18:09 459264 c:\windows\system32\dllcache\msfeeds.dll
+ 2008-10-18 22:44 . 2009-04-29 04:55 459264 c:\windows\system32\dllcache\msfeeds.dll
+ 2009-05-07 15:32 . 2009-05-07 15:32 345600 c:\windows\system32\dllcache\localspl.dll
+ 2007-08-13 22:43 . 2009-04-25 05:27 636088 c:\windows\system32\dllcache\iexplore.exe
+ 2008-10-18 22:44 . 2009-04-29 04:55 268288 c:\windows\system32\dllcache\iertutil.dll
- 2008-10-18 22:44 . 2009-02-20 18:09 268288 c:\windows\system32\dllcache\iertutil.dll
- 2007-08-13 22:39 . 2009-02-20 18:09 385024 c:\windows\system32\dllcache\iedkcs32.dll
+ 2007-08-13 22:39 . 2009-04-29 04:55 385024 c:\windows\system32\dllcache\iedkcs32.dll
+ 2008-10-18 22:44 . 2009-04-29 04:55 383488 c:\windows\system32\dllcache\ieapfltr.dll
- 2008-10-18 22:44 . 2009-02-20 18:09 383488 c:\windows\system32\dllcache\ieapfltr.dll
+ 2007-08-13 21:56 . 2009-04-25 05:26 161792 c:\windows\system32\dllcache\ieakui.dll
- 2007-08-13 21:56 . 2009-02-20 05:14 161792 c:\windows\system32\dllcache\ieakui.dll
+ 2007-08-13 22:39 . 2009-04-29 04:55 230400 c:\windows\system32\dllcache\ieaksie.dll
- 2007-08-13 22:39 . 2009-02-20 18:09 230400 c:\windows\system32\dllcache\ieaksie.dll
- 2007-08-13 22:39 . 2009-02-20 18:09 153088 c:\windows\system32\dllcache\ieakeng.dll
+ 2007-08-13 22:39 . 2009-04-29 04:55 153088 c:\windows\system32\dllcache\ieakeng.dll
+ 2006-06-23 11:25 . 2009-04-29 04:55 133120 c:\windows\system32\dllcache\extmgr.dll
- 2006-06-23 11:25 . 2009-02-20 18:09 133120 c:\windows\system32\dllcache\extmgr.dll
+ 2006-06-23 11:25 . 2009-04-29 04:55 214528 c:\windows\system32\dllcache\dxtrans.dll
- 2006-06-23 11:25 . 2009-02-20 18:09 214528 c:\windows\system32\dllcache\dxtrans.dll
- 2006-06-23 11:25 . 2009-02-20 18:09 347136 c:\windows\system32\dllcache\dxtmsft.dll
+ 2006-06-23 11:25 . 2009-04-29 04:55 347136 c:\windows\system32\dllcache\dxtmsft.dll
+ 2007-08-13 22:39 . 2009-04-29 04:55 124928 c:\windows\system32\dllcache\advpack.dll
- 2007-08-13 22:39 . 2009-02-20 18:09 124928 c:\windows\system32\dllcache\advpack.dll
+ 2004-08-10 18:50 . 2009-04-29 04:55 124928 c:\windows\system32\advpack.dll
- 2004-08-10 18:50 . 2009-02-20 18:09 124928 c:\windows\system32\advpack.dll
- 2009-02-23 02:09 . 2009-04-25 18:42 888080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
+ 2009-02-23 02:09 . 2009-06-12 07:06 888080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
+ 2009-02-23 02:09 . 2009-06-12 07:06 922384 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
- 2009-02-23 02:09 . 2009-04-25 18:42 922384 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
- 2009-02-23 02:09 . 2009-04-25 18:42 217864 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
+ 2009-02-23 02:09 . 2009-06-12 07:06 217864 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
- 2009-02-23 02:09 . 2009-04-25 18:42 184080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
+ 2009-02-23 02:09 . 2009-06-12 07:06 184080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
+ 2009-06-12 07:01 . 2009-03-03 00:18 826368 c:\windows\ie7updates\KB969897-IE7\wininet.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 233472 c:\windows\ie7updates\KB969897-IE7\webcheck.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 105984 c:\windows\ie7updates\KB969897-IE7\url.dll
+ 2009-06-12 07:01 . 2008-07-09 07:38 382840 c:\windows\ie7updates\KB969897-IE7\spuninst\updspapi.dll
+ 2009-06-12 07:01 . 2008-07-09 07:38 231288 c:\windows\ie7updates\KB969897-IE7\spuninst\spuninst.exe
+ 2009-06-12 07:01 . 2009-02-20 18:09 102912 c:\windows\ie7updates\KB969897-IE7\occache.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 671232 c:\windows\ie7updates\KB969897-IE7\mstime.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 193024 c:\windows\ie7updates\KB969897-IE7\msrating.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 477696 c:\windows\ie7updates\KB969897-IE7\mshtmled.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 459264 c:\windows\ie7updates\KB969897-IE7\msfeeds.dll
+ 2009-06-12 07:01 . 2009-02-28 04:54 636072 c:\windows\ie7updates\KB969897-IE7\iexplore.exe
+ 2009-06-12 07:01 . 2009-02-20 18:09 268288 c:\windows\ie7updates\KB969897-IE7\iertutil.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 385024 c:\windows\ie7updates\KB969897-IE7\iedkcs32.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 383488 c:\windows\ie7updates\KB969897-IE7\ieapfltr.dll
+ 2009-06-12 07:01 . 2009-02-20 05:14 161792 c:\windows\ie7updates\KB969897-IE7\ieakui.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 230400 c:\windows\ie7updates\KB969897-IE7\ieaksie.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 153088 c:\windows\ie7updates\KB969897-IE7\ieakeng.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 133120 c:\windows\ie7updates\KB969897-IE7\extmgr.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 214528 c:\windows\ie7updates\KB969897-IE7\dxtrans.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 347136 c:\windows\ie7updates\KB969897-IE7\dxtmsft.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 124928 c:\windows\ie7updates\KB969897-IE7\advpack.dll
+ 2009-06-11 20:02 . 2009-06-11 20:02 452496 c:\windows\Downloaded Program Files\wlscBase.dll
+ 2009-05-16 16:10 . 2009-05-16 16:10 350064 c:\windows\assembly\GAC\Microsoft.Office.Interop.PowerPoint\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.PowerPoint.dll
+ 2004-08-10 18:51 . 2009-04-29 04:56 1159680 c:\windows\system32\urlmon.dll
+ 2004-08-10 18:51 . 2009-04-29 04:56 3596288 c:\windows\system32\mshtml.dll
+ 2007-08-13 22:54 . 2009-04-29 04:55 6066176 c:\windows\system32\ieframe.dll
- 2007-08-13 22:54 . 2009-02-20 18:09 6066176 c:\windows\system32\ieframe.dll
+ 2008-10-18 19:12 . 2009-04-17 12:26 1847168 c:\windows\system32\dllcache\win32k.sys
+ 2006-07-25 20:42 . 2009-04-29 04:56 1159680 c:\windows\system32\dllcache\urlmon.dll
+ 2006-07-28 11:30 . 2009-04-29 04:56 3596288 c:\windows\system32\dllcache\mshtml.dll
- 2008-10-18 22:44 . 2009-02-20 18:09 6066176 c:\windows\system32\dllcache\ieframe.dll
+ 2008-10-18 22:44 . 2009-04-29 04:55 6066176 c:\windows\system32\dllcache\ieframe.dll
+ 2009-02-23 02:09 . 2009-06-12 07:06 1172240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
- 2009-02-23 02:09 . 2009-04-25 18:41 1172240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
+ 2009-06-12 07:01 . 2009-02-20 18:09 1160192 c:\windows\ie7updates\KB969897-IE7\urlmon.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 3595264 c:\windows\ie7updates\KB969897-IE7\mshtml.dll
+ 2009-06-12 07:01 . 2009-02-20 18:09 6066176 c:\windows\ie7updates\KB969897-IE7\ieframe.dll
+ 2009-06-12 07:01 . 2008-07-09 14:25 2455488 c:\windows\ie7updates\KB969897-IE7\ieapfltr.dat
+ 2009-05-16 16:06 . 2009-06-01 16:51 23635392 c:\windows\system32\MRT.exe
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\Wcescomm.exe" [2006-11-13 1289000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-15 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-15 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-15 114688]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2006-02-22 26112]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"MMTray"="c:\progra~1\MUSICM~1\MUSICM~3\mm_tray.exe" [2005-09-09 110592]
"MimBoot"="c:\progra~1\MUSICM~1\MUSICM~3\mimboot.exe" [2005-09-09 8192]
"Samsung PanelMgr"="c:\windows\Samsung\PanelMgr\ssmmgr.exe" [2006-02-14 507904]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"Broadcom Wireless Manager"="c:\windows\system32\wltray.exe" [2007-03-02 1282048]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2005-08-12 1121792]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-11 1948440]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2008-11-10 157312]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Dynex Wireless Networking Utility.lnk - c:\program files\Dynex G Desktop Card Adapter\DynexWCUI.exe [2009-2-6 1462272]
Keyspan USB Server Task.lnk - c:\program files\Keyspan\USB Server\nhciTask.exe [2008-3-18 102400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-04-29 22:23 11952 —-a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"UPS"=3 (0x3)
"TermService"=3 (0x3)
"TapiSrv"=3 (0x3)
"SCardSvr"=3 (0x3)
"RDSessMgr"=3 (0x3)
"Netlogon"=3 (0x3)
"CiSvc"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Documents and Settings\\Admin\\My Documents\\Azureus downloads\\Azureus\\Azureus.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Documents and Settings\\Admin\\My Documents\\wow\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Documents and Settings\\Admin\\My Documents\\wow\\World of Warcraft\\Launcher.exe"=
"c:\\Documents and Settings\\Admin\\My Documents\\wow\\World of Warcraft\\WoW-3.0.9.9551-to-3.1.0.9767-enUS-downloader.exe"=
"c:\\Documents and Settings\\Admin\\My Documents\\wow\\World of Warcraft\\WoW-3.0.1-to-3.0.2-enUS-Win-Update-downloader.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 2009\\english\\setup.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"57387:TCP"= 57387:TCP:Pando Media Booster
"57387:UDP"= 57387:UDP:Pando Media Booster
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2/8/2009 6:17 PM 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2/8/2009 6:17 PM 327688]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2/8/2009 6:17 PM 108552]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2/8/2009 6:17 PM 906520]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2/8/2009 6:17 PM 298776]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2/19/2009 5:23 PM 24652]
R3 NHCIENUM;NHCIENUM;c:\windows\system32\drivers\nhcienum.sys [3/18/2008 2:33 PM 32000]
S3 NHCI;NHCI;c:\windows\system32\drivers\nhci.sys [3/18/2008 2:34 PM 30080]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://my.att.net/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
Trusted Zone: rexplorer.net
Trusted Zone: musicmatch.com\online
DPF: {0A76211B-A2ED-4A88-A547-0527440E7642} - hxxp://samsungdp.com/Install119.CAB
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-06-17 15:40
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-06-17 15:41
ComboFix-quarantined-files.txt 2009-06-17 19:41
ComboFix2.txt 2009-05-10 15:28
Pre-Run: 24,454,275,072 bytes free
Post-Run: 24,551,051,264 bytes free
387 — E O F — 2009-06-12 07:06