ComboFix 09-11-13.04 - Kevin 11/12/2009 19:22.7.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1151.795 [GMT -6:00]
Running from: c:\documents and settings\Kevin\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Kevin\Desktop\CFScript.txt
.
- REDUCED FUNCTIONALITY MODE -
.
((((((((((((((((((((((((( Files Created from 2009-10-13 to 2009-11-13 )))))))))))))))))))))))))))))))
.
2009-11-12 13:18 . 2009-08-01 16:16 6256600 ---ha-w- c:\documents and settings\Kevin\Application Data\mjusbsp\in00000\setup.exe
2009-11-11 17:39 . 2009-11-12 13:24 79488 ----a-w- c:\documents and settings\Kevin\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-11-10 22:25 . 2009-11-10 22:25 -------- d-----w- c:\windows\Sun
2009-11-10 22:25 . 2009-11-10 22:25 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-11-10 22:25 . 2009-11-10 22:25 -------- d-----w- c:\program files\Java
2009-11-10 22:24 . 2009-11-10 22:24 152576 ----a-w- c:\documents and settings\Kevin\Application Data\Sun\Java\jre1.6.0_12\lzma.dll
2009-11-10 22:23 . 2009-11-10 22:23 -------- d-----w- c:\program files\Microsoft ActiveSync
2009-11-10 12:39 . 2009-11-10 12:39 -------- d-----w- C:\$WINDOWS.~BT
2009-11-10 05:03 . 2009-11-10 05:03 -------- d-----w- c:\documents and settings\Kevin\Application Data\Windows Search
2009-11-06 01:16 . 2009-11-06 01:16 -------- d-----w- c:\program files\MSXML 4.0
2009-11-06 01:15 . 2009-08-29 07:36 6067200 -c----w- c:\windows\system32\dllcache\ieframe.dll
2009-11-06 01:15 . 2009-08-29 07:36 52224 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-11-06 01:15 . 2009-08-29 07:36 459264 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2009-11-06 01:15 . 2009-08-29 07:36 268288 -c----w- c:\windows\system32\dllcache\iertutil.dll
2009-11-06 01:15 . 2009-08-29 07:36 63488 -c----w- c:\windows\system32\dllcache\icardie.dll
2009-11-06 01:15 . 2009-08-29 07:36 380928 -c----w- c:\windows\system32\dllcache\ieapfltr.dll
2009-11-06 01:15 . 2009-08-28 10:28 13824 -c----w- c:\windows\system32\dllcache\ieudinit.exe
2009-11-06 01:15 . 2009-06-29 08:33 2452872 -c----w- c:\windows\system32\dllcache\ieapfltr.dat
2009-11-03 01:10 . 2009-11-03 01:10 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2009-11-03 00:10 . 2009-11-03 00:10 128 ----a-w- c:\documents and settings\Kevin\Local Settings\Application Data\fusioncache.dat
2009-11-02 23:50 . 2009-11-02 23:50 344064 ----a-w- c:\windows\system32\msvcr70.dll
2009-11-02 23:49 . 2009-11-02 23:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Macrovision
2009-11-02 23:28 . 2009-11-03 00:10 -------- d-----w- c:\program files\Common Files\BHPS
2009-11-02 23:28 . 2009-11-02 23:51 -------- d-----w- c:\program files\BHPS
2009-11-02 01:59 . 2009-11-02 02:19 -------- d-----w- c:\documents and settings\Kevin\Local Settings\Application Data\Adobe
2009-11-01 23:04 . 2009-11-01 23:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-11-01 23:04 . 2009-11-01 23:06 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-11-01 04:20 . 2000-08-03 01:50 1056768 ----a-w- c:\windows\system32\ROBOEX32.DLL
2009-11-01 04:19 . 2004-12-17 21:14 13952 ------w- c:\windows\system32\drivers\UBHelper.sys
2009-11-01 04:19 . 2009-11-01 04:19 -------- d-----w- c:\program files\Common Files\LightScribe
2009-11-01 04:19 . 2006-12-14 22:53 2819584 ------w- c:\windows\system32\LS_HSI.msi
2009-11-01 04:18 . 2009-11-01 04:18 1024 ---h--r- c:\windows\system32\NTIMP3.dll
2009-11-01 04:18 . 2009-11-01 04:18 1024 ---h--r- c:\windows\system32\NTIJCMK5.dll
2009-11-01 04:12 . 2009-11-01 04:12 1024 ---h--r- c:\windows\system32\NTIDBD32.dll
2009-11-01 04:10 . 2009-11-01 04:20 1024 ---h--r- c:\windows\system32\NTIBUN4.dll
2009-11-01 04:08 . 2009-11-01 04:20 -------- d-----w- c:\program files\Common Files\NewTech Infosystems
2009-11-01 04:07 . 2009-11-01 04:18 1024 ---h--r- c:\windows\system32\NTIFCD3.dll
2009-11-01 04:06 . 2009-11-01 04:06 -------- d-----w- c:\program files\Elaborate Bytes
2009-10-30 05:01 . 2009-11-06 01:09 -------- d-----w- c:\documents and settings\Kevin\Local Settings\Application Data\ApplicationHistory
2009-10-30 04:53 . 2009-10-30 04:53 -------- d-----w- c:\documents and settings\Kevin\Local Settings\Application Data\Identities
2009-10-30 04:53 . 2009-10-30 04:53 -------- d-----w- c:\documents and settings\Kevin\Application Data\Windows Desktop Search
2009-10-30 04:53 . 2009-11-01 04:22 -------- d-----w- c:\program files\Windows Desktop Search
2009-10-30 04:53 . 2009-10-30 04:53 -------- d-----w- c:\windows\system32\GroupPolicy
2009-10-30 04:53 . 2008-03-07 17:02 98304 -c----w- c:\windows\system32\dllcache\nlhtml.dll
2009-10-30 04:53 . 2008-03-07 17:02 29696 -c----w- c:\windows\system32\dllcache\mimefilt.dll
2009-10-30 04:53 . 2008-03-07 17:02 192000 -c----w- c:\windows\system32\dllcache\offfilt.dll
2009-10-30 04:48 . 2009-06-21 21:44 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2009-10-30 04:45 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2009-10-30 04:39 . 2008-12-11 10:57 333952 -c----w- c:\windows\system32\dllcache\srv.sys
2009-10-30 04:37 . 2008-10-24 11:21 455296 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2009-10-30 04:37 . 2008-09-04 17:15 1106944 -c----w- c:\windows\system32\dllcache\msxml3.dll
2009-10-30 04:37 . 2008-10-15 16:34 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2009-10-30 04:37 . 2008-05-01 14:33 331776 -c----w- c:\windows\system32\dllcache\msadce.dll
2009-10-30 04:36 . 2008-04-11 19:04 691712 -c----w- c:\windows\system32\dllcache\inetcomm.dll
2009-10-30 04:34 . 2008-06-13 11:05 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2009-10-30 04:34 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2009-10-30 01:38 . 2009-10-30 01:38 -------- d-----w- c:\documents and settings\Kevin\Application Data\Malwarebytes
2009-10-30 01:38 . 2009-09-10 20:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-30 01:38 . 2009-10-30 01:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-10-30 01:38 . 2009-09-10 20:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-28 04:50 . 2009-10-28 04:50 -------- d-----w- c:\windows\system32\XPSViewer
2009-10-28 04:50 . 2009-10-28 04:50 -------- d-----w- c:\program files\MSBuild
2009-10-28 04:50 . 2009-10-28 04:50 -------- d-----w- c:\program files\Reference Assemblies
2009-10-28 04:49 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-10-28 04:49 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-10-28 04:49 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-10-28 04:49 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-10-28 04:49 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-10-28 04:49 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2009-10-28 04:49 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-10-28 03:15 . 2009-10-28 03:15 -------- d-----w- c:\windows\system32\scripting
2009-10-28 03:15 . 2009-10-28 03:15 -------- d-----w- c:\windows\l2schemas
2009-10-28 03:15 . 2009-10-28 03:15 -------- d-----w- c:\windows\system32\en
2009-10-28 03:01 . 2008-04-14 00:12 276992 ------w- c:\windows\system32\wmphoto.dll
2009-10-28 03:01 . 2008-04-14 00:12 69120 ------w- c:\windows\system32\wlanapi.dll
2009-10-28 03:01 . 2008-04-14 00:12 712704 ------w- c:\windows\system32\windowscodecs.dll
2009-10-28 03:01 . 2008-04-14 00:12 346112 ------w- c:\windows\system32\windowscodecsext.dll
2009-10-28 03:01 . 2008-04-14 00:12 53248 ------w- c:\windows\system32\tsgqec.dll
2009-10-28 03:01 . 2008-04-14 00:12 50688 ------w- c:\windows\system32\tspkg.dll
2009-10-28 03:01 . 2008-04-14 00:12 32768 ------w- c:\windows\system32\setupn.exe
2009-10-28 03:01 . 2008-04-13 18:40 10240 ------w- c:\windows\system32\drivers\sffp_mmc.sys
2009-10-28 02:30 . 2009-10-28 02:30 -------- d-----w- c:\program files\Common Files\muvee Technologies
2009-10-28 02:30 . 2009-11-01 04:20 -------- d-----w- c:\program files\NewTech Infosystems
2009-10-28 02:29 . 2009-11-01 04:18 1024 ---h--r- c:\windows\system32\NTIMPEG2.dll
2009-10-28 02:29 . 2009-11-01 04:18 1024 ---h--r- c:\windows\system32\NTICDMK7.dll
2009-10-28 02:29 . 2009-11-01 04:18 6144 ----a-w- c:\windows\system32\drivers\NTIDrvr.sys
2009-10-27 19:08 . 2009-10-27 19:08 -------- d-----w- c:\documents and settings\Kevin\Application Data\DivX
2009-10-26 20:42 . 2009-11-01 03:45 -------- d-----w- c:\program files\Common Files\Adobe
2009-10-26 20:36 . 2009-10-26 20:36 -------- d-----w- c:\program files\Gtech PASS RR 2.0
2009-10-26 19:33 . 2009-10-26 19:33 -------- d-----w- c:\program files\DIFX
2009-10-26 19:33 . 2009-10-26 19:33 -------- dc----w- c:\windows\system32\DRVSTORE
2009-10-26 19:33 . 2009-10-26 19:33 125670 ----a-w- c:\windows\LogWorks3 Uninstaller.exe
2009-10-26 19:33 . 2009-10-26 19:33 -------- d-----w- c:\program files\LogWorks3
2009-10-26 19:30 . 2000-01-31 11:00 25600 ----a-w- c:\windows\system32\borlndmm.dll
2009-10-26 19:30 . 2000-01-31 11:00 1496064 ----a-w- c:\windows\system32\cc3250mt.dll
2009-10-26 19:30 . 2009-10-26 19:30 -------- d-----w- c:\program files\Haltech
2009-10-26 19:30 . 1999-03-23 15:12 299520 ----a-w- c:\windows\uninst.exe
2009-10-26 19:30 . 2009-10-26 19:30 -------- d-----w- c:\documents and settings\Kevin\WINDOWS
2009-10-26 18:52 . 2009-10-26 18:53 -------- d-----w- c:\windows\ShellNew
2009-10-26 18:52 . 2009-10-26 18:52 -------- d-----w- c:\program files\Common Files\L&H
2009-10-22 00:48 . 2009-11-12 23:22 -------- d-----w- c:\documents and settings\Kevin\Application Data\ProspectorV5
2009-10-22 00:48 . 2009-10-22 00:48 -------- d-----w- c:\documents and settings\Kevin\Local Settings\Application Data\IsolatedStorage
2009-10-22 00:47 . 2009-10-22 00:47 9062 ----a-r- c:\documents and settings\Kevin\Application Data\Microsoft\Installer\{CF3E8BE9-2AD1-42A9-97CD-33AD9826A9E8}\UNINST_Uninstall_P_0EFD655105AD409EA61C7E7C0DD2C138.exe
2009-10-22 00:47 . 2009-10-22 00:47 22486 ----a-r- c:\documents and settings\Kevin\Application Data\Microsoft\Installer\{CF3E8BE9-2AD1-42A9-97CD-33AD9826A9E8}\NewShortcut3_D2FF824E9001418EA3D2B3637212BA28.exe
2009-10-22 00:47 . 2009-10-22 00:47 22486 ----a-r- c:\documents and settings\Kevin\Application Data\Microsoft\Installer\{CF3E8BE9-2AD1-42A9-97CD-33AD9826A9E8}\NewShortcut2_41A2A34BEFF14C1C9CC9CA3E462D2AD1.exe
2009-10-22 00:47 . 2009-10-22 00:47 22486 ----a-r- c:\documents and settings\Kevin\Application Data\Microsoft\Installer\{CF3E8BE9-2AD1-42A9-97CD-33AD9826A9E8}\ARPPRODUCTICON.exe
2009-10-22 00:47 . 2009-10-22 00:47 -------- d-----w- c:\program files\MoxieProxy
2009-10-21 23:20 . 2009-10-21 23:20 -------- d-----w- c:\windows\Downloaded Installations
2009-10-21 23:13 . 2009-11-01 13:40 20328 ----a-w- c:\documents and settings\Kevin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-21 23:12 . 2009-10-30 04:55 -------- d-----w- c:\windows\system32\wbem\AutoRecover
2009-10-21 22:31 . 2009-10-21 22:31 -------- d-----w- c:\windows\provisioning
2009-10-21 12:57 . 2008-04-14 11:42 11264 ------w- c:\windows\system32\spnpinst.exe
2009-10-21 12:57 . 2004-08-02 19:20 4569 ------w- c:\windows\system32\secupd.dat
2009-10-21 12:23 . 2009-10-21 12:23 -------- d-----w- c:\documents and settings\Kevin\Local Settings\Application Data\tjnet
2009-10-21 05:00 . 2009-08-01 16:16 6256600 ---ha-w- c:\documents and settings\Kevin\Application Data\mjusbsp\Upgrade\setup1.exe
2009-10-21 05:00 . 2009-08-01 16:12 728600 ---ha-w- c:\documents and settings\Kevin\Application Data\mjusbsp\Upgrade\install1.exe
2009-10-21 04:59 . 2009-11-13 01:24 -------- d-----w- c:\documents and settings\Kevin\Application Data\mjusbsp
2009-10-21 04:58 . 2008-04-14 00:11 4096 ----a-w- c:\windows\system32\ksuser.dll
2009-10-21 04:58 . 2008-04-13 19:16 141056 ----a-w- c:\windows\system32\drivers\ks.sys
2009-10-21 04:58 . 2008-04-13 18:45 60160 ----a-w- c:\windows\system32\drivers\drmk.sys
2009-10-21 04:58 . 2008-04-13 18:45 60032 ----a-w- c:\windows\system32\drivers\usbaudio.sys
2009-10-21 04:58 . 2008-04-13 19:19 146048 ----a-w- c:\windows\system32\drivers\portcls.sys
2009-10-21 04:58 . 2008-04-13 18:45 49408 ----a-w- c:\windows\system32\drivers\stream.sys
2009-10-21 04:49 . 2008-04-14 00:11 40960 ----a-w- c:\windows\system32\mf3216.dll
2009-10-21 04:49 . 2008-04-14 00:11 45056 ----a-w- c:\windows\system32\wbem\cmdevtgprov.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-01 04:20 . 2009-10-21 02:02 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-28 03:19 . 2009-10-21 01:42 86327 ----a-w- c:\windows\PCHEALTH\HELPCTR\OfflineCache\index.dat
2009-10-28 02:30 . 2009-10-21 02:02 -------- d-----w- c:\program files\Common Files\InstallShield
2009-10-21 02:02 . 2009-10-21 02:02 -------- d-----w- c:\program files\WUSB11 WLAN Monitor
2009-10-21 01:43 . 2009-10-21 01:43 -------- d-----w- c:\program files\microsoft frontpage
2009-10-21 01:33 . 2009-10-21 01:33 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2009-10-08 20:57 . 2008-07-30 01:59 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
2009-10-08 20:57 . 2001-08-23 15:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2009-10-08 20:56 . 2001-08-23 15:00 20480 ----a-w- c:\windows\system32\oleaccrc.dll
2009-09-25 16:41 . 2009-09-25 16:41 90112 ----a-w- c:\windows\system32\dpl100.dll
2009-09-25 16:41 . 2009-09-25 16:41 856064 ----a-w- c:\windows\system32\divx_xx0c.dll
2009-09-25 16:41 . 2009-09-25 16:41 856064 ----a-w- c:\windows\system32\divx_xx07.dll
2009-09-25 16:41 . 2009-09-25 16:41 847872 ----a-w- c:\windows\system32\divx_xx0a.dll
2009-09-25 16:41 . 2009-09-25 16:41 843776 ----a-w- c:\windows\system32\divx_xx16.dll
2009-09-25 16:41 . 2009-09-25 16:41 839680 ----a-w- c:\windows\system32\divx_xx11.dll
2009-09-25 16:41 . 2009-09-25 16:41 696320 ----a-w- c:\windows\system32\DivX.dll
2009-09-11 14:18 . 2001-08-23 15:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:03 . 2001-08-23 15:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 07:36 . 2006-06-23 16:33 832512 ------w- c:\windows\system32\wininet.dll
2009-08-29 07:36 . 2004-08-04 07:56 78336 ------w- c:\windows\system32\ieencode.dll
2009-08-29 07:36 . 2001-08-23 15:00 17408 ----a-w- c:\windows\system32\corpol.dll
2009-08-26 08:00 . 2009-10-21 03:10 247326 ----a-w- c:\windows\system32\strmdll.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-11-10_21.54.12 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-11-13 01:24 . 2009-11-13 01:24 16384 c:\windows\temp\Perflib_Perfdata_5fc.dat
+ 2001-08-23 15:00 . 2009-11-13 01:28 78114 c:\windows\system32\perfc009.dat
- 2001-08-23 15:00 . 2009-11-10 11:58 78114 c:\windows\system32\perfc009.dat
+ 2009-10-26 18:54 . 2009-11-10 22:23 90112 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\xlicons.exe
- 2009-10-26 18:54 . 2009-10-26 18:54 90112 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\xlicons.exe
+ 2009-10-26 18:54 . 2009-11-10 22:23 45056 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\wordicon.exe
- 2009-10-26 18:54 . 2009-10-26 18:54 45056 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\wordicon.exe
+ 2009-10-26 18:54 . 2009-11-10 22:23 22528 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\unbndico.exe
- 2009-10-26 18:54 . 2009-10-26 18:54 22528 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\unbndico.exe
- 2009-10-26 18:54 . 2009-10-26 18:54 30720 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\pptico.exe
+ 2009-10-26 18:54 . 2009-11-10 22:23 30720 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\pptico.exe
- 2009-10-26 18:54 . 2009-10-26 18:54 16384 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\PEicons.exe
+ 2009-10-26 18:54 . 2009-11-10 22:23 16384 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\PEicons.exe
- 2009-10-26 18:54 . 2009-10-26 18:54 34304 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\misc.exe
+ 2009-10-26 18:54 . 2009-11-10 22:23 34304 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\misc.exe
+ 2009-10-26 18:54 . 2009-11-10 22:23 81920 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\fpicon.exe
- 2009-10-26 18:54 . 2009-10-26 18:54 81920 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\fpicon.exe
- 2009-10-26 18:54 . 2009-10-26 18:54 3584 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\opwicon.exe
+ 2009-10-26 18:54 . 2009-11-10 22:23 3584 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\opwicon.exe
+ 2009-10-26 18:54 . 2009-11-10 22:23 8192 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\mspicons.exe
- 2009-10-26 18:54 . 2009-10-26 18:54 8192 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\mspicons.exe
+ 2009-10-26 18:54 . 2009-11-10 22:23 2560 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\cagicon.exe
- 2009-10-26 18:54 . 2009-10-26 18:54 2560 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\cagicon.exe
- 2001-08-23 15:00 . 2009-11-10 11:58 462168 c:\windows\system32\perfh009.dat
+ 2001-08-23 15:00 . 2009-11-13 01:28 462168 c:\windows\system32\perfh009.dat
+ 2009-11-10 22:25 . 2009-11-10 22:25 148888 c:\windows\system32\javaws.exe
+ 2009-11-10 22:25 . 2009-11-10 22:25 144792 c:\windows\system32\javaw.exe
+ 2009-11-10 22:25 . 2009-11-10 22:25 144792 c:\windows\system32\java.exe
+ 2009-11-10 22:25 . 2009-11-10 22:25 598016 c:\windows\Installer\23a3bcb.msi
+ 2009-10-26 18:54 . 2009-11-10 22:23 114688 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\outicon.exe
- 2009-10-26 18:54 . 2009-10-26 18:54 114688 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\outicon.exe
- 2009-10-26 18:54 . 2009-10-26 18:54 167936 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\accicons.exe
+ 2009-10-26 18:54 . 2009-11-10 22:23 167936 c:\windows\Installer\{90280409-6000-11D3-8CFE-0050048383C9}\accicons.exe
+ 2009-11-10 22:23 . 2009-11-10 22:23 120592 c:\windows\Downloaded Program Files\LiveSound.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cdloader"="c:\documents and settings\Kevin\Application Data\mjusbsp\cdloader2.exe" [2009-08-01 50520]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-10-21 198160]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-05-26 85160]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-11-10 148888]
"Malwarebytes Anti-Malware (reboot)"="c:\documents and settings\Kevin\Desktop\hijackthis\New Folder\New Folder\1\mbam.exe" [2009-09-10 1312080]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WgaLogon]
[BU]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^office.exe]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\office.exe
backup=c:\windows\pss\office.exeCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\Kevin\\Application Data\\mjusbsp\\magicJack.exe"=
R2 ProQuest Product License Manager;ProQuest Product License Manager;c:\progra~1\BHPS\lic\bin\lmgrd.exe [11/2/2009 5:49 PM 630272]
--- Other Services/Drivers In Memory ---
*Deregistered* - mbr
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uInternet Connection Wizard,ShellNext = iexplore
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-11-12 19:25
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3896)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\windows\System32\nvsvc32.exe
c:\windows\System32\wdfmgr.exe
c:\windows\system32\SearchIndexer.exe
c:\progra~1\BHPS\lic\bin\bhepcls.exe
c:\windows\system32\wscntfy.exe
c:\documents and settings\Kevin\Application Data\mjusbsp\st00000\mjsetup.exe
c:\documents and settings\Kevin\Application Data\mjusbsp\magicJack.exe
c:\program files\Java\jre6\bin\jucheck.exe
.
**************************************************************************
.
Completion time: 2009-11-12 19:30 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-13 01:30
ComboFix2.txt 2009-11-13 00:58
ComboFix3.txt 2009-11-12 23:37
ComboFix4.txt 2009-11-12 03:18
ComboFix5.txt 2009-11-13 01:20
Pre-Run: 29,779,804,160 bytes free
Post-Run: 29,719,728,128 bytes free
- - End Of File - - 2954E9E4660FFE85AF39F0895B652DDE