ComboFix 09-11-25.03 - SYSTEM 11/26/2009 19:43.6.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2037.950 [GMT -6:00]
Running from: c:\windows\system32\config\systemprofile\Desktop\Trend Micro\ComboFix.exe
Command switches used :: c:\windows\system32\config\systemprofile\Desktop\Trend Micro\CFScript.txt
SP: Windows Defender *disabled* (Outdated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2009-10-27 to 2009-11-27 )))))))))))))))))))))))))))))))
.
2009-11-27 01:54 . 2009-11-27 01:54 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2009-11-27 01:54 . 2009-11-27 01:54 -------- d-----w- c:\users\TEMP\AppData\Local\temp
2009-11-27 01:54 . 2009-11-27 01:54 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-11-27 01:54 . 2009-11-27 01:54 -------- d-----w- c:\users\matt\AppData\Local\temp
2009-11-27 01:54 . 2009-11-27 01:54 -------- d-----w- c:\users\Liz\AppData\Local\temp
2009-11-27 01:54 . 2009-11-27 01:54 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-11-27 01:54 . 2009-11-27 01:54 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2009-11-26 04:44 . 2009-11-03 02:42 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-11-26 04:32 . 2009-11-26 04:32 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Roaming\Malwarebytes
2009-11-26 04:32 . 2009-09-10 20:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-26 04:32 . 2009-11-26 04:32 4096 d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-26 04:32 . 2009-11-26 04:32 -------- d-----w- c:\programdata\Malwarebytes
2009-11-26 04:32 . 2009-09-10 20:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-25 12:12 . 2009-11-25 12:12 -------- d-----w- c:\program files\Windows Portable Devices
2009-11-25 12:11 . 2009-09-10 02:01 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
2009-11-25 12:11 . 2009-09-10 02:00 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2009-11-25 12:11 . 2009-09-10 02:00 92672 ----a-w- c:\windows\system32\UIAnimation.dll
2009-11-25 12:09 . 2009-10-08 21:08 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2009-11-25 12:09 . 2009-10-08 21:08 234496 ----a-w- c:\windows\system32\oleacc.dll
2009-11-25 12:09 . 2009-10-08 21:07 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2009-11-25 05:03 . 2009-11-25 05:07 -------- d-----w- c:\windows\system32\ca-ES
2009-11-25 05:03 . 2009-11-25 05:07 -------- d-----w- c:\windows\system32\eu-ES
2009-11-25 05:03 . 2009-11-25 05:07 -------- d-----w- c:\windows\system32\vi-VN
2009-11-25 04:45 . 2009-11-25 04:45 4096 d-----w- c:\windows\system32\EventProviders
2009-11-25 04:28 . 2009-10-29 09:17 2048 ----a-w- c:\windows\system32\tzres.dll
2009-11-25 03:57 . 2009-09-10 14:58 310784 ----a-w- c:\windows\system32\unregmp2.exe
2009-11-25 03:57 . 2009-09-10 14:59 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-11-25 03:56 . 2009-08-11 16:44 1401856 ----a-w- c:\windows\system32\msxml6.dll
2009-11-25 03:56 . 2009-08-11 16:44 1248768 ----a-w- c:\windows\system32\msxml3.dll
2009-11-25 03:35 . 2009-08-14 13:27 2036736 ----a-w- c:\windows\system32\win32k.sys
2009-11-25 03:35 . 2009-08-10 12:35 355328 ----a-w- c:\windows\system32\WSDApi.dll
2009-11-25 02:39 . 2009-11-25 02:39 4096 d-----w- C:\JustZIPit
2009-11-25 02:39 . 2009-11-25 02:39 386560 ----a-w- c:\windows\System32\config\systemprofile\AppData\Roaming\Free-backup.info\JustZIPit\JustZIPit.exe
2009-11-25 02:39 . 2009-11-25 02:39 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Roaming\Free-backup.info
2009-11-25 00:45 . 2009-11-25 00:45 -------- d-----w- c:\program files\Trend Micro
2009-11-24 03:16 . 2009-11-24 03:16 10752 ----a-w- c:\windows\DCEBoot.exe
2009-11-24 00:53 . 2009-11-24 00:53 -------- d-----w- c:\programdata\WindowsSearch
2009-11-23 03:15 . 2009-11-23 03:15 -------- d-----w- c:\program files\AVG
2009-11-23 03:15 . 2009-11-26 01:01 4096 d-----w- c:\programdata\avg9
2009-11-22 19:06 . 2009-11-25 03:28 4096 d-----w- c:\program files\TrojanHunter 5.2
2009-11-22 18:30 . 2009-11-22 18:30 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Roaming\McAfee
2009-11-22 17:54 . 2009-11-22 17:54 -------- d-sh--w- c:\windows\system32\%APPDATA%
2009-11-22 15:32 . 2009-11-22 15:32 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Roaming\TrojanHunter
2009-11-22 06:17 . 2009-11-22 06:17 -------- d-----w- c:\program files\CCleaner
2009-11-22 06:11 . 2009-11-22 06:11 4096 d-----w- c:\program files\TrojanHunter 5.0
2009-11-22 05:50 . 2009-11-26 13:10 8192 d-----w- c:\programdata\PCPitstop
2009-11-22 05:50 . 2009-11-22 05:50 -------- d-----w- c:\program files\PCPitstop
2009-11-22 02:59 . 2009-11-04 22:53 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys
2009-11-22 02:59 . 2009-11-04 22:54 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-11-22 02:59 . 2009-11-04 22:54 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-11-22 02:59 . 2009-11-04 22:54 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-11-22 02:59 . 2009-11-04 22:54 214664 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-11-22 02:59 . 2009-07-16 18:32 130424 ----a-w- c:\windows\system32\drivers\Mpfp.sys
2009-11-22 02:58 . 2009-11-22 02:59 -------- d-----w- c:\program files\McAfee.com
2009-11-22 02:58 . 2009-11-22 02:59 4096 d-----w- c:\program files\Common Files\McAfee
2009-11-22 02:58 . 2009-11-22 02:58 -------- d-----w- c:\users\TEMP\AppData\Local\Mozilla
2009-11-22 02:58 . 2009-11-26 13:09 4096 d-----w- c:\program files\McAfee
2009-11-22 02:46 . 2009-11-26 02:20 4096 d-----w- c:\programdata\McAfee
2009-11-22 02:38 . 2009-08-07 02:24 44768 ----a-w- c:\windows\system32\wups2.dll
2009-11-22 02:38 . 2009-08-07 02:24 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-11-22 02:38 . 2009-08-07 02:23 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-11-22 02:38 . 2009-08-07 01:45 2421760 ----a-w- c:\windows\system32\wucltux.dll
2009-11-22 02:36 . 2009-08-07 02:24 35552 ----a-w- c:\windows\system32\wups.dll
2009-11-22 02:36 . 2009-08-07 02:23 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-11-22 02:36 . 2009-08-07 01:44 87552 ----a-w- c:\windows\system32\wudriver.dll
2009-11-22 02:36 . 2009-08-07 01:23 171608 ----a-w- c:\windows\system32\wuwebv.dll
2009-11-22 02:36 . 2009-08-07 00:44 33792 ----a-w- c:\windows\system32\wuapp.exe
2009-11-22 02:08 . 2009-11-22 02:08 0 ----a-w- c:\windows\nsreg.dat
2009-11-22 02:07 . 2009-11-22 02:07 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\Mozilla
2009-10-31 15:51 . 2009-05-18 19:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-10-31 15:51 . 2008-04-17 18:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-10-31 15:50 . 2009-10-31 15:51 -------- d-----w- c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-10-31 15:47 . 2009-10-31 15:48 4096 d-----w- c:\program files\QuickTime
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-26 02:54 . 2007-10-07 06:53 4096 d-----w- c:\program files\Yahoo!
2009-11-26 02:54 . 2007-10-08 01:00 4096 d-----w- c:\programdata\Yahoo!
2009-11-26 02:54 . 2008-11-11 02:11 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Roaming\Yahoo!
2009-11-26 02:51 . 2007-12-25 17:43 -------- d-----w- c:\program files\Common Files\Apple
2009-11-25 12:12 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-11-25 12:12 . 2009-11-25 12:12 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2009-11-25 12:12 . 2009-11-25 12:12 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-25 05:08 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2009-11-25 05:08 . 2006-11-02 11:18 4096 d-----w- c:\program files\Windows Mail
2009-11-25 05:08 . 2006-11-02 12:37 4096 d-----w- c:\program files\Windows Sidebar
2009-11-25 05:08 . 2006-11-02 12:37 4096 d-----w- c:\program files\Windows Journal
2009-11-25 05:08 . 2006-11-02 12:37 4096 d-----w- c:\program files\Windows Collaboration
2009-11-25 05:08 . 2006-11-02 12:37 4096 d-----w- c:\program files\Windows Photo Gallery
2009-11-25 05:08 . 2006-11-02 12:37 4096 d-----w- c:\program files\Windows Defender
2009-11-25 05:01 . 2009-11-25 05:01 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-11-25 04:28 . 2007-10-06 20:20 8192 d-----w- c:\programdata\Microsoft Help
2009-11-22 06:03 . 2007-04-10 09:04 8192 d--h--w- c:\program files\InstallShield Installation Information
2009-10-31 15:53 . 2008-11-24 01:32 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Roaming\Apple Computer
2009-10-19 02:33 . 2009-10-19 02:33 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Roaming\ooVoo Details
2009-10-17 13:02 . 2007-10-07 06:48 58896 ----a-w- c:\windows\system32\config\systemprofile\AppData\Local\GDIPFONTCACHEV1.DAT
2009-10-11 00:36 . 2009-10-11 00:28 -------- d-----w- c:\program files\PlaySushi
2009-10-01 01:02 . 2009-11-25 12:10 2537472 ----a-w- c:\windows\system32\wpdshext.dll
2009-10-01 01:02 . 2009-11-25 12:10 30208 ----a-w- c:\windows\system32\WPDShextAutoplay.exe
2009-10-01 01:02 . 2009-11-25 12:10 334848 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2009-10-01 01:02 . 2009-11-25 12:10 87552 ----a-w- c:\windows\system32\WPDShServiceObj.dll
2009-10-01 01:02 . 2009-11-25 12:10 31232 ----a-w- c:\windows\system32\BthMtpContextHandler.dll
2009-10-01 01:01 . 2009-11-25 12:10 546816 ----a-w- c:\windows\system32\wpd_ci.dll
2009-10-01 01:01 . 2009-11-25 12:10 160256 ----a-w- c:\windows\system32\PortableDeviceTypes.dll
2009-10-01 01:01 . 2009-11-25 12:10 60928 ----a-w- c:\windows\system32\PortableDeviceConnectApi.dll
2009-10-01 01:01 . 2009-11-25 12:10 350208 ----a-w- c:\windows\system32\WPDSp.dll
2009-10-01 01:01 . 2009-11-25 12:10 196608 ----a-w- c:\windows\system32\PortableDeviceWMDRM.dll
2009-10-01 01:01 . 2009-11-25 12:10 100864 ----a-w- c:\windows\system32\PortableDeviceClassExtension.dll
2009-10-01 01:01 . 2009-11-25 12:10 81920 ----a-w- c:\windows\system32\wpdbusenum.dll
2009-10-01 01:01 . 2009-11-25 12:10 40448 ----a-w- c:\windows\system32\drivers\WpdUsb.sys
2009-10-01 01:01 . 2009-11-25 12:10 226816 ----a-w- c:\windows\system32\WpdMtp.dll
2009-10-01 01:01 . 2009-11-25 12:10 61952 ----a-w- c:\windows\system32\WpdMtpUS.dll
2009-10-01 01:01 . 2009-11-25 12:10 33280 ----a-w- c:\windows\system32\WpdConns.dll
2009-09-30 01:34 . 2007-11-25 15:41 58896 ----a-w- c:\users\matt\AppData\Local\GDIPFONTCACHEV1.DAT
2009-09-25 02:10 . 2009-11-25 12:10 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll
2009-09-25 02:07 . 2009-11-25 12:10 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll
2009-09-25 02:04 . 2009-11-25 12:10 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll
2009-09-25 01:49 . 2009-11-25 12:10 1554432 ----a-w- c:\windows\system32\xpsservices.dll
2009-09-25 01:48 . 2009-11-25 12:10 351232 ----a-w- c:\windows\system32\XpsPrint.dll
2009-09-25 01:38 . 2009-11-25 12:10 847360 ----a-w- c:\windows\system32\OpcServices.dll
2009-09-25 01:36 . 2009-11-25 12:10 280064 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2009-09-25 01:35 . 2009-11-25 12:10 135680 ----a-w- c:\windows\system32\XpsRasterService.dll
2009-09-25 01:33 . 2009-11-25 12:10 195584 ----a-w- c:\windows\system32\dxdiagn.dll
2009-09-25 01:33 . 2009-11-25 12:10 829440 ----a-w- c:\windows\system32\d3d10warp.dll
2009-09-25 01:33 . 2009-11-25 12:10 369664 ----a-w- c:\windows\system32\WMPhoto.dll
2009-09-25 01:32 . 2009-11-25 12:10 252928 ----a-w- c:\windows\system32\dxdiag.exe
2009-09-25 01:31 . 2009-11-25 12:10 519680 ----a-w- c:\windows\system32\d3d11.dll
2009-09-25 01:31 . 2009-11-25 12:10 486912 ----a-w- c:\windows\system32\d3d10level9.dll
2009-09-25 01:31 . 2009-11-25 12:10 161280 ----a-w- c:\windows\system32\d3d10_1.dll
2009-09-25 01:31 . 2009-11-25 12:10 218112 ----a-w- c:\windows\system32\d3d10_1core.dll
2009-09-25 01:31 . 2009-11-25 12:10 1030144 ----a-w- c:\windows\system32\d3d10.dll
2009-09-25 01:31 . 2009-11-25 12:10 828928 ----a-w- c:\windows\system32\d2d1.dll
2009-09-25 01:30 . 2009-11-25 12:10 481792 ----a-w- c:\windows\system32\dxgi.dll
2009-09-25 01:30 . 2009-11-25 12:10 190464 ----a-w- c:\windows\system32\d3d10core.dll
2009-09-25 01:27 . 2009-11-25 12:10 634880 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2009-09-25 01:27 . 2009-11-25 12:10 37888 ----a-w- c:\windows\system32\cdd.dll
2009-09-25 01:27 . 2009-11-25 12:10 793088 ----a-w- c:\windows\system32\FntCache.dll
2009-09-25 01:27 . 2009-11-25 12:10 1064448 ----a-w- c:\windows\system32\DWrite.dll
2009-09-24 22:54 . 2009-11-25 12:10 258048 ----a-w- c:\windows\system32\winspool.drv
2009-09-24 22:54 . 2009-11-25 12:10 667648 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
2009-09-24 22:54 . 2009-11-25 12:10 26112 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll
2009-09-20 04:39 . 2008-10-29 17:27 58896 ----a-w- c:\users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2009-09-14 09:29 . 2009-10-14 21:29 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2009-09-12 13:00 . 2008-11-11 00:48 58896 ----a-w- c:\users\TEMP\AppData\Local\GDIPFONTCACHEV1.DAT
2009-09-10 16:48 . 2009-10-14 21:32 218624 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 11:41 . 2009-10-14 21:29 60928 ----a-w- c:\windows\system32\msasn1.dll
.
((((((((((((((((((((((((((((( SnapShot_2009-11-26_01.59.22 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-04-10 08:59 . 2009-11-26 13:11 79786 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-11-26 13:11 74564 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-10-29 18:12 . 2009-11-26 01:34 18008 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3771958223-2023274512-727475370-1002_UserData.bin
+ 2008-10-29 18:12 . 2009-11-26 13:11 18008 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3771958223-2023274512-727475370-1002_UserData.bin
- 2008-11-25 04:13 . 2009-11-17 12:16 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\Low\index.dat
+ 2008-11-25 04:13 . 2009-11-26 18:42 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\Low\index.dat
- 2008-11-25 04:13 . 2009-11-17 12:16 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat
+ 2008-11-25 04:13 . 2009-11-26 18:42 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat
+ 2008-11-25 04:13 . 2009-11-26 18:42 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.dat
- 2008-11-25 04:13 . 2009-11-17 12:16 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.dat
+ 2009-11-26 12:50 . 2009-11-26 13:09 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012009112620091127\index.dat
+ 2009-11-26 01:06 . 2009-11-26 04:56 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012009112520091126\index.dat
- 2009-11-26 01:06 . 2009-11-26 01:33 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012009112520091126\index.dat
+ 2009-11-26 19:00 . 2009-11-26 19:00 30208 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Last Active\{EEE5E023-DABD-11DE-8348-001B3821E94F}.dat
+ 2009-11-27 01:36 . 2009-11-27 01:37 19456 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{4EA17C47-DAF5-11DE-8348-001B3821E94F}.dat
+ 2009-10-27 01:01 . 2009-11-26 18:43 27080 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\frameiconcache.dat
- 2008-11-11 00:48 . 2009-11-26 01:41 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Feeds Cache\index.dat
+ 2008-11-11 00:48 . 2009-11-27 01:36 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Feeds Cache\index.dat
+ 2009-11-22 02:09 . 2009-11-26 18:39 8129 c:\windows\System32\config\systemprofile\AppData\Roaming\Mozilla\Firefox\Profiles\pf0onznw.default\pluginreg.dat
+ 2009-11-16 02:23 . 2009-11-26 19:00 4608 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Last Active\RecoveryStore.{F2DC0014-D256-11DE-9797-001B3821E94F}.dat
- 2009-11-16 02:23 . 2009-11-26 01:45 4608 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Last Active\RecoveryStore.{F2DC0014-D256-11DE-9797-001B3821E94F}.dat
+ 2009-11-27 01:36 . 2009-11-27 01:36 3584 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{4EA17C46-DAF5-11DE-8348-001B3821E94F}.dat
- 2009-11-26 01:32 . 2009-11-26 01:32 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-11-26 13:09 . 2009-11-26 13:09 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-11-26 13:09 . 2009-11-26 13:09 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-11-26 01:32 . 2009-11-26 01:32 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2006-11-02 10:33 . 2009-11-26 13:14 595684 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-11-26 01:38 595684 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-11-26 13:14 101350 c:\windows\System32\perfc009.dat
- 2006-11-02 10:33 . 2009-11-26 01:38 101350 c:\windows\System32\perfc009.dat
+ 2009-11-25 01:48 . 2009-11-26 16:53 524800 c:\windows\System32\config\systemprofile\Desktop\Trend Micro\dds.pif
- 2009-09-04 12:17 . 2009-11-26 01:33 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-09-04 12:17 . 2009-11-26 13:09 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2007-10-07 06:49 . 2009-11-26 01:58 475136 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2007-10-07 06:49 . 2009-11-27 01:43 475136 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-11-25 03:17 . 2009-11-27 01:43 409600 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2007-10-07 06:50 . 2009-11-26 01:58 966656 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2007-10-07 06:50 . 2009-11-27 01:43 966656 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-09-04 12:17 . 2009-11-26 01:41 12582912 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\PrivacIE\index.dat
+ 2009-09-04 12:17 . 2009-11-27 01:36 12582912 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\PrivacIE\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2009-09-03 3342336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-23 815104]
"AcerOrbicamRibbon"="c:\program files\Acer\OrbiCam10\OrbiCam.exe" [2006-11-29 754712]
"LogitechCommunicationsManager"="c:\program files\Common Files\Logitech\LComMgr\Communications_Helper.exe" [2006-10-31 304664]
"LVCOMSX"="c:\program files\Common Files\Logitech\LComMgr\LVComSX.exe" [2006-11-29 244512]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-03-01 4390912]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Exetender"="c:\program files\Free Ride Games\GPlayer.exe" [2008-11-10 2057216]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Empowering Technology Launcher.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Empowering Technology Launcher.lnk
backup=c:\windows\pss\Empowering Technology Launcher.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^Liz^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\users\Liz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(:56,74,85,70,8e,6d,ca,01
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3771958223-2023274512-727475370-1002]
"EnableNotificationsRef"=dword:00000001
R2 ALaunchService;ALaunch Service;c:\acer\ALaunch\ALaunchSvc.exe [4/10/2007 4:11 AM 50688]
R2 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\PCPitstop\PCPitstopScheduleService.exe [11/21/2009 11:50 PM 90352]
R2 X4HSX32Ex;X4HSX32Ex;c:\program files\Free Ride Games\X4HSX32Ex.sys [12/19/2008 10:02 PM 29856]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [6/24/2008 7:48 PM 21504]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
2009-11-22 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-11-22 18:22]
2009-11-22 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-11-22 18:22]
2009-11-27 c:\windows\Tasks\User_Feed_Synchronization-{63A03D36-4E5F-4208-A186-418FA1F8141A}.job
- c:\windows\system32\msfeedssync.exe [2009-10-14 03:41]
2009-11-27 c:\windows\Tasks\User_Feed_Synchronization-{E63C9BD3-FBDC-4D57-B6E9-3C60F118C076}.job
- c:\windows\system32\msfeedssync.exe [2009-10-14 03:41]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://en.us.acer.yahoo.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: mcafee.com
FF - ProfilePath - c:\windows\System32\config\systemprofile\AppData\Roaming\Mozilla\Firefox\Profiles\pf0onznw.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - plugin: c:\progra~1\SONYON~1\npsoe.dll
FF - plugin: c:\program files\Free Ride Games\npExentCtl.dll
FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-26 19:54
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-11-26 19:57
ComboFix-quarantined-files.txt 2009-11-27 01:57
ComboFix2.txt 2009-11-26 02:04
ComboFix3.txt 2009-11-25 03:53
Pre-Run: 34,353,700,864 bytes free
Post-Run: 34,430,730,240 bytes free
- - End Of File - - 98DA7568E65906884043DB9FCBF795D4