ComboFix 09-07-25.08 - marion willow 27/07/2009 7:11.2.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.735.375 [GMT 10:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
c:\windows\system32\AVSredirect.dll
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-06-26 to 2009-07-26 )))))))))))))))))))))))))))))))
.
2009-07-24 00:52 . 2009-07-26 19:56 ——– d—–w- c:\windows\system32\CatRoot_bak
2009-07-24 00:40 . 2009-02-06 17:22 2136064 -c—-w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-07-24 00:40 . 2009-02-06 17:24 2180480 -c—-w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-07-24 00:40 . 2009-02-06 16:49 2015744 -c—-w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-07-24 00:40 . 2009-02-06 16:49 2057728 -c—-w- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-07-24 00:27 . 2008-10-24 11:10 453632 -c—-w- c:\windows\system32\dllcache\mrxsmb.sys
2009-07-24 00:25 . 2008-06-13 13:10 272128 -c—-w- c:\windows\system32\dllcache\bthport.sys
2009-07-23 21:26 . 2007-05-17 07:30 318976 —-a-w- c:\windows\system32\avisynth.dll
2009-07-23 21:26 . 2004-02-22 00:11 719872 —-a-w- c:\windows\system32\devil.dll
2009-07-23 21:26 . 2004-01-24 14:00 70656 —-a-w- c:\windows\system32\yv12vfw.dll
2009-07-23 21:26 . 2004-01-24 14:00 70656 —-a-w- c:\windows\system32\i420vfw.dll
2009-07-23 21:26 . 2009-07-23 21:26 ——– d—–w- c:\program files\AviSynth 2.5
2009-07-23 20:48 . 2009-06-27 04:35 1008896 —-a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-07-23 04:31 . 2009-07-23 04:31 ——– d—–w- c:\documents and settings\marion willow\Local Settings\Application Data\AVG Security Toolbar
2009-07-23 04:23 . 2009-07-23 04:23 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-07-23 04:23 . 2009-07-23 04:23 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-07-23 04:23 . 2009-07-23 04:23 335752 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-07-23 04:22 . 2009-07-26 20:41 ——– d—–w- c:\windows\system32\drivers\Avg
2009-07-23 04:22 . 2009-07-23 20:48 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-07-23 04:22 . 2009-07-23 04:22 ——– d—–w- c:\program files\AVG
2009-07-23 04:22 . 2009-07-26 20:10 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2009-07-23 01:56 . 2009-07-23 04:23 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-07-23 01:47 . 2004-08-03 14:56 236544 -c–a-w- c:\windows\system32\dllcache\smi2smir.exe
2009-07-23 01:46 . 2004-08-03 14:56 22528 -c–a-w- c:\windows\system32\dllcache\lpdsvc.dll
2009-07-23 01:45 . 2004-08-03 12:31 480256 -c–a-w- c:\windows\system32\dllcache\cintsetp.exe
2009-07-23 01:44 . 2003-03-24 06:52 188480 -c–a-w- c:\windows\system32\dllcache\cfgwiz.exe
2009-07-23 01:44 . 2003-03-24 06:52 20540 -c–a-w- c:\windows\system32\dllcache\author.dll
2009-07-23 01:44 . 2003-03-24 06:52 16439 -c–a-w- c:\windows\system32\dllcache\author.exe
2009-07-23 01:44 . 2003-03-24 06:52 16439 -c–a-w- c:\windows\system32\dllcache\admin.exe
2009-07-23 01:44 . 2003-03-24 06:52 20540 -c–a-w- c:\windows\system32\dllcache\admin.dll
2009-07-23 01:44 . 2004-08-03 14:56 221184 —-a-w- c:\windows\system32\wmpns.dll
2009-07-23 01:44 . 2009-07-23 01:44 ——– d—–w- c:\documents and settings\Default User\Local Settings\Application Data\Microsoft
2009-07-23 01:42 . 2003-03-31 12:00 16384 -c–a-w- c:\windows\system32\dllcache\isignup.exe
2009-07-23 01:29 . 2003-03-31 12:00 24661 -c–a-w- c:\windows\system32\dllcache\spxcoins.dll
2009-07-23 01:29 . 2003-03-31 12:00 24661 —-a-w- c:\windows\system32\spxcoins.dll
2009-07-23 01:29 . 2003-03-31 12:00 13312 -c–a-w- c:\windows\system32\dllcache\irclass.dll
2009-07-23 01:29 . 2003-03-31 12:00 13312 —-a-w- c:\windows\system32\irclass.dll
2009-07-23 00:47 . 2009-07-23 00:47 ——– d—–w- c:\documents and settings\marion willow\Application Data\AVG8
2009-07-19 04:47 . 2009-07-19 04:47 ——– d—–w- c:\documents and settings\marion willow\Application Data\DriveHQHOOK
2009-07-18 00:50 . 2009-07-18 00:55 ——– d—–w- c:\documents and settings\All Users\Application Data\MyHeritage
2009-07-18 00:50 . 2009-07-18 00:50 ——– d—–w- c:\documents and settings\marion willow\Application Data\MyHeritage
2009-07-17 05:00 . 2009-07-17 05:00 ——– d—–w- c:\program files\MSXML 4.0
2009-07-16 20:06 . 2009-07-16 20:06 ——– d—–w- c:\documents and settings\marion willow\Local Settings\Application Data\Scansoft
2009-07-16 20:02 . 2009-07-16 20:02 50 —-a-w- c:\windows\system32\bridf07a.dat
2009-07-16 20:00 . 2009-07-16 20:00 ——– d—–w- C:\Brother
2009-07-16 20:00 . 2003-11-28 08:57 0 —-a-w- c:\windows\brdfxspd.dat
2009-07-16 20:00 . 2006-01-16 15:03 126976 —-a-w- c:\windows\system32\BrfxD05a.dll
2009-07-16 20:00 . 2007-04-27 07:13 61440 —-a-w- c:\windows\system32\BrMfNt.dll
2009-07-16 20:00 . 2007-01-18 03:51 163840 —-a-w- c:\windows\system32\NSSearch.dll
2009-07-16 20:00 . 2006-07-07 02:40 73728 —-a-w- c:\windows\system32\BRCrypt.dll
2009-07-16 20:00 . 2002-11-26 03:43 106496 —-a-w- c:\windows\system32\BrMuSNMP.dll
2009-07-16 20:00 . 2007-02-15 03:54 131072 —-a-w- c:\windows\brunin03.dll
2009-07-16 19:59 . 2009-07-16 19:59 ——– d—–w- c:\documents and settings\marion willow\Application Data\InstallShield
2009-07-16 19:58 . 2009-07-16 19:58 ——– d—–w- c:\program files\Nuance
2009-07-16 19:57 . 2009-07-16 19:57 ——– d—–w- c:\documents and settings\All Users\Application Data\InstallShield
2009-07-16 19:57 . 2009-07-16 19:57 ——– d—–w- c:\program files\Common Files\ScanSoft Shared
2009-07-16 19:56 . 2009-07-16 19:57 ——– d—–w- c:\documents and settings\All Users\Application Data\ScanSoft
2009-07-16 19:56 . 2009-07-16 19:56 ——– d—–w- c:\program files\ScanSoft
2009-07-16 19:54 . 2009-07-16 19:54 ——– d—–w- c:\documents and settings\All Users\Application Data\Brother
2009-07-16 19:48 . 2009-07-16 20:01 ——– d—–w- c:\program files\Brother
2009-07-16 01:43 . 2009-07-16 01:43 ——– d—–w- c:\documents and settings\marion willow\Application Data\Malwarebytes
2009-07-16 01:43 . 2009-07-13 03:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-16 01:43 . 2009-07-16 01:43 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-07-16 01:43 . 2009-07-16 01:43 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-16 01:43 . 2009-07-13 03:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-07-16 01:17 . 2009-07-16 01:17 ——– d—–w- c:\program files\HP
2009-07-16 01:17 . 2007-11-22 02:13 1191520 —-a-w- c:\windows\system32\XWheel.dll
2009-07-16 01:17 . 2007-11-22 02:11 151136 —-a-w- c:\windows\system32\Hook.dll
2009-07-16 01:17 . 2007-11-22 02:05 983040 —-a-w- c:\windows\system32\MousePage.dll
2009-07-16 01:17 . 2006-02-06 06:26 30848 —-a-w- c:\windows\system32\drivers\HidMouse.sys
2009-07-16 01:12 . 2009-07-16 01:12 ——– d—–w- c:\documents and settings\Administrator
2009-07-16 00:16 . 2009-07-16 00:16 ——– d—–w- c:\windows\SxsCaPendDel
2009-07-15 22:27 . 2009-07-16 00:50 ——– d—–w- c:\documents and settings\marion willow\Local Settings\Application Data\LastPass
2009-07-15 10:54 . 2009-07-15 10:54 ——– d—–w- c:\program files\ERUNT
2009-07-11 22:49 . 2006-09-21 13:01 499712 —-a-w- c:\windows\system32\msvcp71.dll
2009-07-11 22:49 . 2009-07-14 04:50 ——– d—–w- c:\program files\WinMerge
2009-07-09 00:49 . 2001-08-17 12:36 5632 —-a-w- c:\windows\system32\ptpusb.dll
2009-07-09 00:49 . 2008-04-13 19:42 159232 —-a-w- c:\windows\system32\ptpusd.dll
2009-07-09 00:49 . 2004-08-03 12:58 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2009-07-08 01:59 . 2009-07-23 22:39 ——– d—–w- c:\documents and settings\marion willow\Application Data\FileZilla
2009-07-07 11:37 . 2009-07-07 11:37 25440 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\savapibridge.dll
2009-07-07 11:36 . 2009-07-07 11:36 1630560 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2009-07-07 11:36 . 2009-07-07 11:36 2353480 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-07-05 23:33 . 2009-07-19 04:47 ——– d—–w- c:\documents and settings\marion willow\Application Data\DriveHQ
2009-07-05 23:32 . 2009-07-05 23:32 ——– d—–w- c:\program files\DriveHQ
2009-07-05 01:23 . 2009-07-05 01:23 58 —-a-w- c:\windows\system32\DonationCoder_ScreenshotCaptor_InstallInfo.dat
2009-07-05 01:23 . 2009-07-05 01:23 58 —-a-w- c:\documents and settings\marion willow\Local Settings\Application Data\DonationCoder_ScreenshotCaptor_InstallInfo.dat
2009-07-05 01:23 . 2009-07-05 01:23 ——– d—–w- c:\documents and settings\marion willow\Application Data\DonationCoder
2009-07-05 01:22 . 2009-07-23 11:54 ——– d—–w- c:\program files\ScreenshotCaptor
2009-07-05 01:22 . 2009-07-05 01:22 ——– d—–w- c:\documents and settings\All Users\Application Data\DonationCoder
2009-07-04 04:47 . 2009-07-04 04:47 ——– d–h–w- c:\windows\PIF
2009-07-04 03:44 . 2009-07-04 03:44 ——– d—–w- c:\program files\Lame for Audacity
2009-07-04 02:51 . 2009-07-19 06:32 ——– d—–w- c:\documents and settings\marion willow\.thinupload
2009-07-03 10:57 . 2009-07-03 10:57 314712 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-07-03 10:57 . 2009-07-03 10:57 15688 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-07-03 10:57 . 2009-07-03 10:57 169312 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-07-03 10:56 . 2009-07-03 10:56 348496 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
2009-07-03 10:56 . 2009-07-03 10:56 298336 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2009-07-03 10:56 . 2009-07-03 10:56 84832 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-07-03 10:54 . 2009-07-03 10:54 246128 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-07-03 10:54 . 2009-07-03 10:54 40288 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-07-03 10:54 . 2009-07-03 10:54 64160 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
2009-07-03 10:54 . 2009-07-03 10:54 85352 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\AAWDriverTool.exe
2009-07-03 10:54 . 2009-07-03 10:54 664424 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-07-03 10:54 . 2009-07-03 10:54 563064 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-07-03 10:54 . 2009-07-03 10:54 566632 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-07-03 10:53 . 2009-07-03 10:53 629072 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWWSC.exe
2009-07-03 10:53 . 2009-07-03 10:53 520024 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-07-03 10:53 . 2009-07-03 10:53 1029456 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-07-02 03:24 . 2009-03-09 19:06 15688 —-a-w- c:\windows\system32\lsdelete.exe
2009-07-02 02:45 . 2009-07-26 20:06 ——– d—–w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\Microsoft
2009-07-02 00:51 . 2009-07-02 00:51 ——– d—–w- c:\windows\Sun
2009-07-01 23:37 . 2009-07-01 23:38 ——– d—–w- c:\program files\DVD Decrypter
2009-07-01 09:08 . 2009-07-01 09:08 ——– d—–w- c:\program files\Bibliopolis
2009-07-01 09:05 . 2009-07-01 09:05 ——– d—–w- c:\documents and settings\marion willow\Local Settings\Application Data\FileMaker
2009-07-01 08:12 . 2009-07-01 08:12 ——– d—–w- C:\New Folder
2009-07-01 05:18 . 2009-07-01 05:18 ——– d—–w- c:\documents and settings\marion willow\Local Settings\Application Data\Identities
2009-07-01 05:17 . 2009-07-26 19:47 ——– d—–w- c:\documents and settings\marion willow\Application Data\MailWasherFree
2009-07-01 05:17 . 2009-07-01 05:17 ——– d—–w- c:\program files\FireTrust
2009-07-01 01:32 . 2009-07-01 01:33 ——– d—–w- c:\documents and settings\marion willow\Application Data\vlc
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-26 21:08 . 2009-06-30 09:12 ——– d—–w- c:\documents and settings\marion willow\Application Data\uTorrent
2009-07-23 21:27 . 2009-06-30 08:57 ——– d—–w- c:\program files\SUPER
2009-07-23 15:13 . 2009-06-30 05:39 76487 —-a-w- c:\windows\PCHealth\HelpCtr\OfflineCache\index.dat
2009-07-23 01:41 . 2009-06-30 05:36 22720 —-a-w- c:\windows\system32\emptyregdb.dat
2009-07-20 22:21 . 2009-06-30 11:30 ——– d—–w- c:\program files\FileZilla FTP Client
2009-07-18 13:55 . 2009-06-30 09:22 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-07-18 00:52 . 2009-06-30 08:54 ——– d—–w- c:\program files\MyHeritage
2009-07-16 21:46 . 2009-06-30 15:34 1 —-a-w- c:\documents and settings\marion willow\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-07-16 20:07 . 2009-06-30 06:59 17744 —-a-w- c:\documents and settings\marion willow\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-16 20:03 . 2009-06-30 11:47 34 —-a-w- c:\windows\system32\FD203A.DAT
2009-07-16 20:00 . 2009-06-30 11:45 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-07-16 19:57 . 2009-06-30 07:05 ——– d—–w- c:\program files\Common Files\InstallShield
2009-07-16 00:42 . 2009-06-30 09:03 ——– d—–w- c:\program files\Yahoo!
2009-07-04 22:27 . 2009-06-30 09:33 ——– d—–w- c:\program files\Foxit Software
2009-07-03 10:54 . 2009-06-30 11:35 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys
2009-07-02 00:05 . 2009-06-30 11:46 ——– d—–w- c:\program files\Brownie
2009-07-01 05:31 . 2009-06-30 10:21 ——– d—–w- c:\documents and settings\marion willow\Application Data\Ahead
2009-07-01 01:32 . 2009-06-30 10:00 ——– d—–w- c:\program files\VLC player
2009-06-30 15:33 . 2009-06-30 15:33 ——– d—–w- c:\documents and settings\marion willow\Application Data\OpenOffice.org
2009-06-30 12:06 . 2009-06-30 09:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-30 11:49 . 2009-06-30 11:49 ——– d—–r- c:\documents and settings\marion willow\Application Data\FX
2009-06-30 11:45 . 2009-06-30 11:45 ——– d—–w- c:\program files\Fuji Xerox
2009-06-30 11:36 . 2009-06-30 11:31 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-06-30 11:34 . 2009-06-30 11:34 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-06-30 11:34 . 2009-06-30 11:34 ——– d—–w- c:\program files\QuickTime Alternative
2009-06-30 11:31 . 2009-06-30 11:31 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-30 11:31 . 2009-06-30 11:31 ——– d—–w- c:\program files\Lavasoft
2009-06-30 11:08 . 2009-06-30 11:08 ——– d—–w- c:\program files\Any Video Converter
2009-06-30 11:08 . 2009-06-30 11:08 ——– d—–w- c:\documents and settings\marion willow\Application Data\Any Video Converter
2009-06-30 10:54 . 2009-06-30 10:54 ——– d—–w- c:\program files\Audacity
2009-06-30 10:39 . 2009-06-30 10:39 ——– d—–w- c:\documents and settings\All Users\Application Data\DVD Shrink
2009-06-30 10:39 . 2009-06-30 10:39 ——– d—–w- c:\program files\DVD Shrink
2009-06-30 10:30 . 2009-06-30 10:30 ——– d—–w- c:\program files\Recuva
2009-06-30 10:23 . 2009-06-30 10:23 ——– d—–w- c:\program files\7-Zip
2009-06-30 10:22 . 2009-06-30 10:18 ——– d—–w- c:\program files\Common Files\Ahead
2009-06-30 10:18 . 2009-06-30 10:18 ——– d—–w- c:\documents and settings\All Users\Application Data\Nero
2009-06-30 10:18 . 2009-06-30 10:18 ——– d—–w- c:\program files\Nero
2009-06-30 10:12 . 2009-06-30 10:12 ——– d—–w- c:\program files\Chami
2009-06-30 10:08 . 2009-06-30 09:38 ——– d—–w- c:\program files\NetVisualize
2009-06-30 09:52 . 2009-06-30 09:52 ——– d—–w- c:\program files\C-Media 3D Audio
2009-06-30 09:42 . 2009-06-30 09:42 ——– d—–w- c:\program files\ReNamer
2009-06-30 09:13 . 2009-06-30 09:13 ——– d—–w- c:\program files\uTorrent
2009-06-30 09:07 . 2009-06-30 09:07 ——– d—–w- c:\documents and settings\marion willow\Application Data\The Complete Genealogy Reporter - FTB
2009-06-30 09:03 . 2009-06-30 09:02 ——– d—–w- c:\program files\CCleaner
2009-06-30 08:56 . 2009-06-30 08:35 ——– d—–w- c:\program files\OpenOffice.org 3
2009-06-30 08:35 . 2009-06-30 08:35 ——– d—–w- c:\program files\JRE
2009-06-30 08:34 . 2009-06-30 08:34 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-06-30 08:34 . 2009-06-30 08:34 ——– d—–w- c:\program files\Java
2009-06-30 07:38 . 2009-06-30 07:37 ——– d—–w- c:\program files\SpywareBlaster
2009-06-30 07:38 . 2009-06-30 07:38 ——– d—–w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-30 07:34 . 2009-06-30 07:34 0 —-a-w- c:\windows\nsreg.dat
2009-06-30 07:07 . 2009-06-30 07:07 ——– d—–w- c:\program files\SiSVGA
2009-06-30 07:06 . 2009-06-30 07:06 ——– d—–w- c:\program files\SiS Compatible VGA V2.18
2009-06-30 05:40 . 2009-06-30 05:40 ——– d—–w- c:\program files\microsoft frontpage
2009-06-16 14:55 . 2004-08-03 14:56 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:55 . 2003-03-31 12:00 82432 —-a-w- c:\windows\system32\fontsub.dll
2009-06-03 19:27 . 2004-08-03 14:56 1290752 —-a-w- c:\windows\system32\quartz.dll
2009-05-07 15:44 . 2004-08-03 14:56 344064 —-a-w- c:\windows\system32\localspl.dll
2009-04-29 04:52 . 2004-08-03 14:56 659456 —-a-w- c:\windows\system32\wininet.dll
2009-04-29 04:52 . 2004-08-03 14:56 81920 —-a-w- c:\windows\system32\ieencode.dll
2009-07-15 21:41 . 2009-06-30 07:33 137208 —-a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
2006-05-03 10:06 . 2009-06-30 08:57 163328 –sha-r- c:\windows\system32\flvDX.dll
2007-02-21 11:47 . 2009-06-30 08:57 31232 –sha-r- c:\windows\system32\msfDX.dll
2008-03-16 13:30 . 2009-06-30 08:57 216064 –sha-r- c:\windows\system32\nbDX.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-07-26_21.05.14 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-26 21:08 . 2009-07-26 21:09 16384 c:\windows\Temp\Perflib_Perfdata_7d0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-27 1008896]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-27 04:35 1008896 —-a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-27 1008896]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-27 1008896]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2009-06-30 288048]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiS KHooker"="c:\windows\system32\khooker.exe" [2003-05-28 294912]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-07-23 1948440]
"Cmaudio"="cmicnfg.cpl" [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-07-23 04:23 11952 —-a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe"
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe"
"PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "c:\documents and settings\All Users\Application Data\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini
"ControlCenter3"=c:\program files\Brother\ControlCenter3\brctrcen.exe /autorun
"BrMfcWnd"=c:\program files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"d:\\DL torrent FULL version\\Foxit.PDF.Editor.v1.5.2722-TE\\Foxit.PDF.Editor.v1.5.2722-TE\\Crack\\PDFEdit.exe"=
"d:\\DL Progs IN USE\\foxit PDF editor v1\\Crack\\PDFEdit.exe"=
"c:\\Program Files\\Foxit Software\\PDF Editor\\PDFEdit.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [30/06/2009 9:35 PM 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [23/07/2009 2:23 PM 335752]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [23/07/2009 2:23 PM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [23/07/2009 2:22 PM 907032]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [23/07/2009 2:22 PM 298776]
R2 DriveHQ FileManagerFun;DriveHQ FileManagerFun;c:\program files\DriveHQ\DriveHQ FileManager\DHQFMSvc.exe [6/07/2009 9:32 AM 45568]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [10/03/2009 5:06 AM 1029456]
.
Contents of the 'Scheduled Tasks' folder
2009-07-21 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 10:54]
.
.
——- Supplementary Scan ——-
.
FF - ProfilePath - c:\documents and settings\marion willow\Application Data\Mozilla\Firefox\Profiles\knxwckl1.default\
FF - prefs.js: browser.startup.homepage - hxxp://worldpeacepoll.com/fabradio/wp-login.php
FF - prefs.js: keyword.URL - hxxp://au.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_au&p=
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-27 07:16
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-07-26 7:19
ComboFix-quarantined-files.txt 2009-07-26 21:19
Pre-Run: 23,678,554,112 bytes free
Post-Run: 23,641,448,448 bytes free
331 — E O F — 2009-07-26 19:13