fleadhfan
First, here's the mbam log (in blue) I told you about from last night. As you can see i let it clean the items in restore, but unchecked the combo-fix.sys thinking it might be a false positive. Following the mbam log is the new combofix log (in brown) from this evening. A note on the combofix log: it reports avg and comodo enabled for the run; the avg you know about, and i exited the comodo firewall before doing the combofix run.
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4442
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13
8/17/2010 10:00:36 PM
mbam-log-2010-08-17 (22-00-36).txt
Scan type: Full scan (C:\|)
Objects scanned: 175378
Time elapsed: 31 minute(s), 40 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 5
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\ComboFix\Combo-Fix.sys (Trojan.Agent.Gen) -> Not selected for removal.
C:\System Volume Information\_restore{2293CDFF-D6F8-4FBC-9BD3-AFEDFFD0A6EF}\RP227\A0023862.sys (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2293CDFF-D6F8-4FBC-9BD3-AFEDFFD0A6EF}\RP229\A0024099.sys (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2293CDFF-D6F8-4FBC-9BD3-AFEDFFD0A6EF}\RP229\A0024150.sys (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2293CDFF-D6F8-4FBC-9BD3-AFEDFFD0A6EF}\RP229\A0024248.sys (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
ComboFix 10-08-17.04 - Tom Spencer 08/18/2010 18:17:09.7.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.685 [GMT -4:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
c:\documents and settings\All Users\Application Data\SMBIRMCAV
c:\documents and settings\All Users\Application Data\SMBIRMCAV\SMYPAV.cfg
.
((((((((((((((((((((((((( Files Created from 2010-07-18 to 2010-08-18 )))))))))))))))))))))))))))))))
.
2010-08-16 23:30 . 2010-08-16 23:30 ——– d—–w- c:\program files\Java
2010-08-15 19:54 . 2010-08-15 19:54 ——– d—–w- c:\program files\Common Files\Java
2010-08-09 19:00 . 2010-08-09 19:00 61440 —-a-w- c:\documents and settings\Coby\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-44d523b0-n\decora-sse.dll
2010-08-09 19:00 . 2010-08-09 19:00 503808 —-a-w- c:\documents and settings\Coby\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-583aa9bc-n\msvcp71.dll
2010-08-09 19:00 . 2010-08-09 19:00 499712 —-a-w- c:\documents and settings\Coby\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-583aa9bc-n\jmc.dll
2010-08-09 19:00 . 2010-08-09 19:00 348160 —-a-w- c:\documents and settings\Coby\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-583aa9bc-n\msvcr71.dll
2010-08-08 22:44 . 2010-08-08 22:44 ——– d—–w- c:\documents and settings\Coby
2010-08-08 22:44 . 2010-04-07 22:59 ——– d—–w- c:\documents and settings\Coby\Local Settings\Application Data\Google
2010-08-08 22:35 . 2010-08-18 00:50 0 —-a-w- c:\documents and settings\Tom Spencer\Local Settings\Application Data\prvlcl.dat
2010-08-08 17:23 . 2010-08-08 17:23 388096 —-a-r- c:\documents and settings\Tom Spencer\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-08-08 15:30 . 2010-08-08 15:30 ——– d—–w- c:\documents and settings\All Users\Application Data\COMODO
2010-08-08 15:29 . 2010-08-08 15:29 ——– d—–w- c:\program files\COMODO
2010-08-08 15:27 . 2010-08-08 15:28 ——– d—–w- c:\documents and settings\All Users\Application Data\Comodo Downloader
2010-08-08 14:40 . 2010-08-18 22:16 ——– d—–w- c:\program files\Everything
2010-08-08 14:16 . 2008-04-14 00:11 21504 —-a-w- c:\windows\system32\drivers\hidserv.dll
2010-08-08 01:09 . 2010-08-16 22:37 63488 —-a-w- c:\documents and settings\Tom Spencer\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-08-08 01:09 . 2010-08-08 01:09 52224 —-a-w- c:\documents and settings\Tom Spencer\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-08-07 22:08 . 2010-04-29 19:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-07 22:08 . 2010-08-07 23:00 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-08-07 22:08 . 2010-04-29 19:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-08-07 22:02 . 2008-04-14 00:11 21504 -c–a-w- c:\windows\system32\dllcache\hidserv.dll
2010-08-07 22:02 . 2008-04-14 00:11 21504 —-a-w- c:\windows\system32\hidserv.dll
2010-08-07 21:59 . 2010-08-07 21:59 ——– d—–w- c:\windows\system32\wbem\Repository
2010-08-02 21:35 . 2010-08-02 21:35 61440 —-a-w- c:\documents and settings\Tom Spencer\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-13a0aad3-n\decora-sse.dll
2010-08-02 21:35 . 2010-08-02 21:35 503808 —-a-w- c:\documents and settings\Tom Spencer\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-740df2f0-n\msvcp71.dll
2010-08-02 21:35 . 2010-08-02 21:35 499712 —-a-w- c:\documents and settings\Tom Spencer\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-740df2f0-n\jmc.dll
2010-08-02 21:35 . 2010-08-02 21:35 348160 —-a-w- c:\documents and settings\Tom Spencer\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-740df2f0-n\msvcr71.dll
2010-08-02 21:35 . 2010-08-02 21:35 12800 —-a-w- c:\documents and settings\Tom Spencer\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-13a0aad3-n\decora-d3d.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-16 23:30 . 2010-06-13 20:51 423656 —-a-w- c:\windows\system32\deployJava1.dll
2010-08-16 22:37 . 2009-10-29 23:32 117760 —-a-w- c:\documents and settings\Tom Spencer\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-08-09 19:00 . 2010-08-09 19:00 12800 —-a-w- c:\documents and settings\Coby\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-44d523b0-n\decora-d3d.dll
2010-08-08 14:16 . 2010-08-08 14:16 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2010-08-08 14:16 . 2010-08-08 14:16 0 —ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2010-08-08 14:04 . 2008-12-10 19:40 ——– d—–w- c:\program files\Trend Micro
2010-08-08 03:26 . 2008-11-25 15:40 ——– d—–w- c:\program files\Defraggler
2010-08-08 00:23 . 2008-11-25 15:38 ——– d—–w- c:\program files\CCleaner
2010-07-27 23:15 . 2008-11-25 16:02 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-06-30 12:31 . 2004-08-04 10:00 149504 —-a-w- c:\windows\system32\schannel.dll
2010-06-24 12:15 . 2006-03-04 03:33 832512 —-a-w- c:\windows\system32\wininet.dll
2010-06-24 12:15 . 2004-08-04 10:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-06-24 12:15 . 2004-08-04 10:00 17408 —-a-w- c:\windows\system32\corpol.dll
2010-06-23 13:44 . 2004-08-04 10:00 1851904 —-a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27 . 2004-08-04 10:00 354304 —-a-w- c:\windows\system32\drivers\srv.sys
2010-06-17 14:03 . 2004-08-04 10:00 80384 —-a-w- c:\windows\system32\iccvid.dll
2010-06-14 14:31 . 2008-08-02 18:19 744448 —-a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-14 07:41 . 2004-08-04 10:00 1172480 —-a-w- c:\windows\system32\msxml3.dll
2010-06-14 00:48 . 2008-08-02 18:57 13104 —-a-w- c:\documents and settings\Tom Spencer\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-04 15:55 . 2010-06-04 15:55 229312 —-a-w- c:\windows\system32\drivers\cmdGuard.sys
2010-06-01 23:00 . 2010-06-01 23:00 278288 —-a-w- c:\windows\system32\guard32.dll
2010-06-01 23:00 . 2010-06-01 23:00 87824 —-a-w- c:\windows\system32\drivers\inspect.sys
2010-06-01 23:00 . 2010-06-01 23:00 25240 —-a-w- c:\windows\system32\drivers\cmdhlp.sys
2010-06-01 23:00 . 2010-06-01 23:00 15464 —-a-w- c:\windows\system32\drivers\cmderd.sys
2010-05-26 22:18 . 2010-05-26 22:18 503808 —-a-w- c:\documents and settings\Tom Spencer\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-426a6f5d-n\msvcp71.dll
2010-05-26 22:18 . 2010-05-26 22:18 499712 —-a-w- c:\documents and settings\Tom Spencer\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-426a6f5d-n\jmc.dll
2010-05-26 22:18 . 2010-05-26 22:18 348160 —-a-w- c:\documents and settings\Tom Spencer\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-426a6f5d-n\msvcr71.dll
2010-05-26 22:18 . 2010-05-26 22:18 61440 —-a-w- c:\documents and settings\Tom Spencer\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-2579a0a2-n\decora-sse.dll
2010-05-26 22:18 . 2010-05-26 22:18 12800 —-a-w- c:\documents and settings\Tom Spencer\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-2579a0a2-n\decora-d3d.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-08-15_16.53.35 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-08-18 22:05 . 2010-08-18 22:05 16384 c:\windows\temp\Perflib_Perfdata_7dc.dat
+ 2004-08-04 10:00 . 2008-04-14 00:12 30749 c:\windows\system32\dllcache\vbajet32.dll
+ 2007-04-02 16:36 . 2007-04-02 16:36 16384 c:\windows\system32\dllcache\tcptsat.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 32827 c:\windows\system32\dllcache\tcptest.exe
+ 2004-08-04 10:00 . 2008-04-14 00:12 25088 c:\windows\system32\dllcache\slayerxp.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 16437 c:\windows\system32\dllcache\shtml.exe
+ 2008-04-14 00:12 . 2008-04-14 00:12 20536 c:\windows\system32\dllcache\shtml.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 65024 c:\windows\system32\dllcache\shimeng.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 77312 c:\windows\system32\dllcache\sdbinst.exe
+ 2004-08-04 10:00 . 2008-04-14 00:12 64000 c:\windows\system32\dllcache\samlib.dll
+ 2010-08-18 03:02 . 2001-08-17 18:56 66048 c:\windows\system32\dllcache\s3legacy.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 84992 c:\windows\system32\dllcache\olepro32.dll
+ 2008-08-02 18:19 . 2008-04-14 00:12 65536 c:\windows\system32\dllcache\oledb32r.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 20511 c:\windows\system32\dllcache\odtext32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 20510 c:\windows\system32\dllcache\odpdx32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 20510 c:\windows\system32\dllcache\odfox32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 20510 c:\windows\system32\dllcache\odexl32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 20511 c:\windows\system32\dllcache\oddbse32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:10 53279 c:\windows\system32\dllcache\odbcji32.dll
+ 2004-08-04 10:00 . 2008-04-13 17:26 94208 c:\windows\system32\dllcache\odbcint.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 65536 c:\windows\system32\dllcache\odbccu32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 65536 c:\windows\system32\dllcache\odbccr32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 69632 c:\windows\system32\dllcache\odbcconf.exe
+ 2004-08-04 10:00 . 2008-04-14 00:12 32768 c:\windows\system32\dllcache\odbcad32.exe
+ 2004-08-04 10:00 . 2008-04-14 00:12 16384 c:\windows\system32\dllcache\odbc32gt.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 67584 c:\windows\system32\dllcache\ocmanage.dll
+ 2004-08-04 10:00 . 2008-04-13 19:20 91520 c:\windows\system32\dllcache\ndiswan.sys
+ 2008-08-02 18:18 . 2008-04-14 00:12 24576 c:\windows\system32\dllcache\msxactps.dll
+ 2004-08-04 10:00 . 2008-04-13 18:30 61440 c:\windows\system32\dllcache\msvcrt40.dll
+ 2004-08-04 10:00 . 2007-04-02 12:49 60192 c:\windows\system32\dllcache\msjter40.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 36864 c:\windows\system32\dllcache\msdfmap.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 20480 c:\windows\system32\dllcache\msdatt.dll
+ 2008-08-02 18:18 . 2008-04-13 17:26 16384 c:\windows\system32\dllcache\msdasqlr.dll
+ 2008-08-02 18:18 . 2008-04-13 17:25 16384 c:\windows\system32\dllcache\msdaremr.dll
+ 2008-08-02 18:18 . 2008-04-13 17:25 16384 c:\windows\system32\dllcache\msdaprsr.dll
+ 2008-08-02 18:19 . 2008-04-14 00:11 77824 c:\windows\system32\dllcache\msdaosp.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 36864 c:\windows\system32\dllcache\mscpxl32.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 57344 c:\windows\system32\dllcache\msadrh15.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 57344 c:\windows\system32\dllcache\msador15.dll
+ 2008-08-02 18:18 . 2008-04-13 17:26 24576 c:\windows\system32\dllcache\msader15.dll
+ 2008-08-02 18:18 . 2008-04-13 17:25 24576 c:\windows\system32\dllcache\msaddsr.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 53248 c:\windows\system32\dllcache\msadcs.dll
+ 2008-08-02 18:18 . 2008-04-13 17:25 16384 c:\windows\system32\dllcache\msadcor.dll
+ 2008-08-02 18:18 . 2008-04-13 17:25 16384 c:\windows\system32\dllcache\msadcfr.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 61440 c:\windows\system32\dllcache\msadcf.dll
+ 2008-08-02 18:18 . 2008-04-13 17:25 20480 c:\windows\system32\dllcache\msadcer.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 22528 c:\windows\system32\dllcache\mfcsubs.dll
+ 2004-08-04 10:00 . 2010-06-24 12:15 27648 c:\windows\system32\dllcache\jsproxy.dll
- 2007-08-13 22:54 . 2010-06-24 12:15 27648 c:\windows\system32\dllcache\jsproxy.dll
+ 2004-08-04 10:00 . 2008-04-13 19:19 75264 c:\windows\system32\dllcache\ipsec.sys
+ 2004-08-04 10:00 . 2008-04-14 00:11 36921 c:\windows\system32\dllcache\imeshare.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 20538 c:\windows\system32\dllcache\fpremadm.exe
+ 2008-04-14 00:11 . 2008-04-14 00:11 20541 c:\windows\system32\dllcache\fpexedll.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 15120 c:\windows\system32\dllcache\fp98sadm.exe
+ 2008-04-14 00:11 . 2008-04-14 00:11 49212 c:\windows\system32\dllcache\fp4awebs.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 32826 c:\windows\system32\dllcache\fp4avss.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 41020 c:\windows\system32\dllcache\fp4avnb.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 49210 c:\windows\system32\dllcache\fp4areg.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 82035 c:\windows\system32\dllcache\fp4anscp.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 16384 c:\windows\system32\dllcache\ds32gt.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 32768 c:\windows\system32\dllcache\dispex.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 39936 c:\windows\system32\dllcache\dimsroam.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 19456 c:\windows\system32\dllcache\dimsntfy.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 62464 c:\windows\system32\dllcache\cryptsvc.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 64512 c:\windows\system32\dllcache\cryptnet.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 53760 c:\windows\system32\dllcache\cryptext.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 33280 c:\windows\system32\dllcache\cryptdll.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 74752 c:\windows\system32\dllcache\cryptdlg.dll
+ 2004-08-04 10:00 . 2008-04-14 00:09 16896 c:\windows\system32\dllcache\cfgmgr32.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 16439 c:\windows\system32\dllcache\author.exe
+ 2008-04-14 00:11 . 2008-04-14 00:11 20540 c:\windows\system32\dllcache\author.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 30208 c:\windows\system32\dllcache\atmlib.dll
- 2010-03-05 14:37 . 2010-03-05 14:37 65536 c:\windows\system32\dllcache\asycfilt.dll
+ 2004-08-04 10:00 . 2010-03-05 14:37 65536 c:\windows\system32\dllcache\asycfilt.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 98304 c:\windows\system32\dllcache\ahui.exe
+ 2004-08-04 10:00 . 2008-04-14 00:11 68096 c:\windows\system32\dllcache\adsmsext.dll
+ 2010-08-18 03:02 . 2001-08-17 16:11 46112 c:\windows\system32\dllcache\adptsf50.sys
- 2007-08-13 22:39 . 2007-08-13 22:39 71680 c:\windows\system32\dllcache\admparse.dll
+ 2004-08-04 10:00 . 2007-08-13 22:39 71680 c:\windows\system32\dllcache\admparse.dll
+ 2010-08-18 03:02 . 2004-08-04 02:32 10880 c:\windows\system32\dllcache\admjoy.sys
+ 2008-04-14 00:12 . 2008-04-14 00:12 16439 c:\windows\system32\dllcache\admin.exe
+ 2008-04-14 00:11 . 2008-04-14 00:11 20540 c:\windows\system32\dllcache\admin.dll
+ 2010-08-18 03:02 . 2001-08-17 16:11 20160 c:\windows\system32\dllcache\adm8511.sys
+ 2004-08-04 10:00 . 2008-04-14 00:11 98304 c:\windows\system32\dllcache\actxprxy.dll
+ 2004-08-04 10:00 . 2004-08-04 10:00 11648 c:\windows\system32\dllcache\acpiec.sys
+ 2010-08-18 03:02 . 2001-08-18 02:36 61440 c:\windows\system32\dllcache\acerscad.dll
+ 2010-08-18 03:02 . 2004-08-04 02:32 84480 c:\windows\system32\dllcache\ac97via.sys
+ 2010-08-18 03:02 . 2001-08-17 16:20 96256 c:\windows\system32\dllcache\ac97intc.sys
+ 2010-08-18 03:02 . 2001-08-17 17:52 23552 c:\windows\system32\dllcache\abp480n5.sys
+ 2010-08-18 03:02 . 2001-08-18 02:36 98304 c:\windows\system32\dllcache\a3d.dll
+ 2010-08-18 03:02 . 2001-08-17 18:55 38400 c:\windows\system32\dllcache\8514a.dll
+ 2010-08-18 03:02 . 2008-04-13 18:46 48128 c:\windows\system32\dllcache\61883.sys
+ 2010-08-18 03:02 . 2008-04-13 18:40 12288 c:\windows\system32\dllcache\4mmdat.sys
+ 2010-08-18 03:02 . 2001-08-17 18:06 11264 c:\windows\system32\dllcache\1394vdbg.sys
+ 2010-08-18 03:02 . 2008-04-13 18:46 53376 c:\windows\system32\dllcache\1394bus.sys
+ 2004-08-04 10:00 . 2008-04-14 00:12 5120 c:\windows\system32\dllcache\sfc.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 4096 c:\windows\system32\dllcache\msdaurl.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 4096 c:\windows\system32\dllcache\msdasc.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 4096 c:\windows\system32\dllcache\msdaer.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 4096 c:\windows\system32\dllcache\msdaenum.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 4096 c:\windows\system32\dllcache\msdadc.dll
+ 2008-04-14 00:09 . 2008-04-14 00:09 6144 c:\windows\system32\dllcache\kbdpash.dll
+ 2008-04-14 00:09 . 2008-04-14 00:09 6144 c:\windows\system32\dllcache\kbdnepr.dll
+ 2008-04-14 00:09 . 2008-04-14 00:09 6144 c:\windows\system32\dllcache\kbdiultn.dll
+ 2008-04-14 00:09 . 2008-04-14 00:09 6144 c:\windows\system32\dllcache\kbdbhc.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 7168 c:\windows\system32\dllcache\bitsprx4.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 3775 c:\windows\system32\dllcache\adv11nt5.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 3711 c:\windows\system32\dllcache\adv09nt5.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 3135 c:\windows\system32\dllcache\adv08nt5.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 3647 c:\windows\system32\dllcache\adv07nt5.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 3615 c:\windows\system32\dllcache\adv05nt5.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 3967 c:\windows\system32\dllcache\adv02nt5.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 4255 c:\windows\system32\dllcache\adv01nt5.dll
+ 2010-08-18 03:02 . 2001-08-17 17:53 7424 c:\windows\system32\dllcache\adicvls.sys
+ 2004-08-04 10:00 . 2008-04-14 00:12 4096 c:\windows\system32\dllcache\actmovie.exe
- 2010-06-13 20:51 . 2010-04-12 21:29 153376 c:\windows\system32\javaws.exe
+ 2010-08-16 23:30 . 2010-08-16 23:30 153376 c:\windows\system32\javaws.exe
- 2010-06-13 20:51 . 2010-04-12 21:29 145184 c:\windows\system32\javaw.exe
+ 2010-08-16 23:30 . 2010-08-16 23:30 145184 c:\windows\system32\javaw.exe
+ 2010-08-16 23:30 . 2010-08-16 23:30 145184 c:\windows\system32\java.exe
- 2010-06-13 20:51 . 2010-04-12 21:29 145184 c:\windows\system32\java.exe
+ 2004-08-04 10:00 . 2009-12-24 06:59 177664 c:\windows\system32\dllcache\wintrust.dll
- 2009-12-24 06:59 . 2009-12-24 06:59 177664 c:\windows\system32\dllcache\wintrust.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 507904 c:\windows\system32\dllcache\winlogon.exe
+ 2006-03-04 03:33 . 2010-06-24 12:15 832512 c:\windows\system32\dllcache\wininet.dll
- 2007-08-13 22:54 . 2010-06-24 12:15 832512 c:\windows\system32\dllcache\wininet.dll
- 2007-08-13 22:54 . 2010-03-09 11:09 430080 c:\windows\system32\dllcache\vbscript.dll
+ 2004-08-04 10:00 . 2010-03-09 11:09 430080 c:\windows\system32\dllcache\vbscript.dll
- 2007-08-13 22:44 . 2010-06-24 12:15 105984 c:\windows\system32\dllcache\url.dll
+ 2004-08-04 10:00 . 2010-06-24 12:15 105984 c:\windows\system32\dllcache\url.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 123392 c:\windows\system32\dllcache\umpnpmgr.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 106496 c:\windows\system32\dllcache\sysocmgr.exe
+ 2004-08-04 10:00 . 2008-04-14 09:42 985088 c:\windows\system32\dllcache\setupapi.dll
+ 2004-08-04 10:00 . 2008-05-09 10:53 172032 c:\windows\system32\dllcache\scrrun.dll
- 2008-05-09 10:53 . 2008-05-09 10:53 172032 c:\windows\system32\dllcache\scrrun.dll
+ 2004-08-04 10:00 . 2008-05-09 10:53 180224 c:\windows\system32\dllcache\scrobj.dll
- 2008-05-09 10:53 . 2008-05-09 10:53 180224 c:\windows\system32\dllcache\scrobj.dll
+ 2004-08-04 10:00 . 2010-06-30 12:31 149504 c:\windows\system32\dllcache\schannel.dll
- 2008-12-05 06:54 . 2010-06-30 12:31 149504 c:\windows\system32\dllcache\schannel.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 415744 c:\windows\system32\dllcache\samsrv.dll
+ 2004-08-04 10:00 . 2008-04-13 17:37 208384 c:\windows\system32\dllcache\rsaenh.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 433664 c:\windows\system32\dllcache\riched20.dll
+ 2008-08-02 18:19 . 2008-04-14 00:12 487424 c:\windows\system32\dllcache\oledb32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 551936 c:\windows\system32\dllcache\oleaut32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 147456 c:\windows\system32\dllcache\odbctrac.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 278559 c:\windows\system32\dllcache\odbcjt32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 106496 c:\windows\system32\dllcache\odbccp32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 135168 c:\windows\system32\dllcache\odbcconf.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 249856 c:\windows\system32\dllcache\odbc32.dll
+ 2004-08-04 10:00 . 2008-04-13 19:15 574976 c:\windows\system32\dllcache\ntfs.sys
- 2009-04-14 19:32 . 2009-02-09 12:10 714752 c:\windows\system32\dllcache\ntdll.dll
+ 2004-08-04 10:00 . 2009-02-09 12:10 714752 c:\windows\system32\dllcache\ntdll.dll
+ 2004-08-04 10:00 . 2008-10-15 16:34 337408 c:\windows\system32\dllcache\netapi32.dll
- 2008-10-23 22:32 . 2008-10-15 16:34 337408 c:\windows\system32\dllcache\netapi32.dll
+ 2004-08-04 10:00 . 2007-04-02 12:52 355104 c:\windows\system32\dllcache\msxbde40.dll
+ 2004-08-04 10:00 . 2007-04-02 12:51 621344 c:\windows\system32\dllcache\mswstr10.dll
+ 2004-08-04 10:00 . 2007-04-02 12:51 838432 c:\windows\system32\dllcache\mswdat10.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 343040 c:\windows\system32\dllcache\msvcrt.dll
+ 2004-08-04 10:00 . 2007-04-02 12:51 264992 c:\windows\system32\dllcache\mstext40.dll
+ 2004-08-04 10:00 . 2007-04-02 12:51 559904 c:\windows\system32\dllcache\msrepl40.dll
+ 2004-08-04 10:00 . 2007-04-02 12:50 322336 c:\windows\system32\dllcache\msrd3x40.dll
+ 2004-08-04 10:00 . 2007-04-02 12:50 432928 c:\windows\system32\dllcache\msrd2x40.dll
+ 2004-08-04 10:00 . 2007-04-02 12:50 355104 c:\windows\system32\dllcache\mspbde40.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 143360 c:\windows\system32\dllcache\msorcl32.dll
+ 2004-08-04 10:00 . 2007-04-02 12:49 219936 c:\windows\system32\dllcache\msltus40.dll
+ 2004-08-04 10:00 . 2007-04-02 12:49 248608 c:\windows\system32\dllcache\msjtes40.dll
+ 2008-08-02 18:18 . 2008-04-14 00:12 102400 c:\windows\system32\dllcache\msjro.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 151583 c:\windows\system32\dllcache\msjint40.dll
+ 2004-08-04 10:00 . 2007-04-02 12:47 326432 c:\windows\system32\dllcache\msexcl40.dll
+ 2004-08-04 10:00 . 2007-04-02 12:47 518944 c:\windows\system32\dllcache\msexch40.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 315392 c:\windows\system32\dllcache\msdasql.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 118784 c:\windows\system32\dllcache\msdarem.dll
+ 2008-08-02 18:19 . 2008-04-14 00:11 204800 c:\windows\system32\dllcache\msdaps.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 200704 c:\windows\system32\dllcache\msdaprst.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 233472 c:\windows\system32\dllcache\msdaora.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 200704 c:\windows\system32\dllcache\msadox.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 180224 c:\windows\system32\dllcache\msadomd.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 536576 c:\windows\system32\dllcache\msado15.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 155648 c:\windows\system32\dllcache\msadds.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 143360 c:\windows\system32\dllcache\msadco.dll
- 2008-08-30 23:00 . 2008-05-01 14:33 331776 c:\windows\system32\dllcache\msadce.dll
+ 2008-08-02 18:18 . 2008-05-01 14:33 331776 c:\windows\system32\dllcache\msadce.dll
+ 2004-08-04 10:00 . 2007-04-03 03:14 981760 c:\windows\system32\dllcache\mfc42u.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 927504 c:\windows\system32\dllcache\mfc40u.dll
- 2009-04-14 19:32 . 2009-06-25 08:25 730112 c:\windows\system32\dllcache\lsasrv.dll
+ 2004-08-04 10:00 . 2009-06-25 08:25 730112 c:\windows\system32\dllcache\lsasrv.dll
- 2009-03-21 14:06 . 2009-03-21 14:06 989696 c:\windows\system32\dllcache\kernel32.dll
+ 2004-08-04 10:00 . 2009-03-21 14:06 989696 c:\windows\system32\dllcache\kernel32.dll
+ 2004-08-04 10:00 . 2009-08-13 15:16 512000 c:\windows\system32\dllcache\jscript.dll
- 2007-08-13 22:38 . 2009-08-13 15:16 512000 c:\windows\system32\dllcache\jscript.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 138240 c:\windows\system32\dllcache\itss.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 155136 c:\windows\system32\dllcache\itircl.dll
+ 2007-04-02 16:36 . 2007-04-02 16:36 208896 c:\windows\system32\dllcache\fpmmcsat.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 598071 c:\windows\system32\dllcache\fpmmc.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 188494 c:\windows\system32\dllcache\fpcount.exe
+ 2008-04-14 00:12 . 2008-04-14 00:12 109840 c:\windows\system32\dllcache\fp98swin.exe
+ 2008-04-14 00:11 . 2008-04-14 00:11 876653 c:\windows\system32\dllcache\fp4awel.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 102509 c:\windows\system32\dllcache\fp4atxt.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 147513 c:\windows\system32\dllcache\fp4apws.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 184435 c:\windows\system32\dllcache\fp4amsft.dll
+ 2004-08-04 10:00 . 2008-04-13 19:14 143744 c:\windows\system32\dllcache\fastfat.sys
+ 2004-08-04 10:00 . 2008-04-14 00:11 380445 c:\windows\system32\dllcache\expsrv.dll
+ 2004-08-04 10:00 . 2008-04-13 17:37 138752 c:\windows\system32\dllcache\dssenh.dll
+ 2008-08-02 18:19 . 2008-01-19 11:04 554008 c:\windows\system32\dllcache\dao360.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 512512 c:\windows\system32\dllcache\cryptui.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 599040 c:\windows\system32\dllcache\crypt32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 252928 c:\windows\system32\dllcache\compatui.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 276992 c:\windows\system32\dllcache\comdlg32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 617472 c:\windows\system32\dllcache\comctl32.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 188480 c:\windows\system32\dllcache\cfgwiz.exe
+ 2008-04-14 00:11 . 2008-04-14 00:11 233472 c:\windows\system32\dllcache\azroles.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 125952 c:\windows\system32\dllcache\apphelp.dll
+ 2004-08-04 10:00 . 2008-08-14 10:04 138496 c:\windows\system32\dllcache\afd.sys
- 2008-06-20 11:40 . 2008-08-14 10:04 138496 c:\windows\system32\dllcache\afd.sys
+ 2008-08-02 18:51 . 2008-04-13 16:39 142592 c:\windows\system32\dllcache\aec.sys
+ 2004-08-04 10:00 . 2010-06-24 12:15 124928 c:\windows\system32\dllcache\advpack.dll
- 2007-08-13 22:39 . 2010-06-24 12:15 124928 c:\windows\system32\dllcache\advpack.dll
+ 2004-08-04 10:00 . 2009-02-09 12:10 617472 c:\windows\system32\dllcache\advapi32.dll
- 2009-04-14 19:32 . 2009-02-09 12:10 617472 c:\windows\system32\dllcache\advapi32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 263680 c:\windows\system32\dllcache\adsnt.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 143360 c:\windows\system32\dllcache\adsldpc.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 175616 c:\windows\system32\dllcache\adsldp.dll
+ 2010-08-18 03:02 . 2001-08-17 18:07 101888 c:\windows\system32\dllcache\adpu160m.sys
+ 2010-08-18 03:02 . 2001-08-17 16:19 747392 c:\windows\system32\dllcache\adm8830.sys
+ 2010-08-18 03:02 . 2001-08-17 16:19 553984 c:\windows\system32\dllcache\adm8820.sys
+ 2010-08-18 03:02 . 2001-08-17 16:19 584448 c:\windows\system32\dllcache\adm8810.sys
+ 2004-08-04 10:00 . 2008-04-14 00:11 116224 c:\windows\system32\dllcache\acxtrnal.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 193536 c:\windows\system32\dllcache\activeds.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 245248 c:\windows\system32\dllcache\acspecfc.dll
+ 2004-08-04 10:00 . 2008-04-13 18:36 187776 c:\windows\system32\dllcache\acpi.sys
+ 2004-08-04 10:00 . 2008-04-14 00:11 115712 c:\windows\system32\dllcache\aclui.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 141312 c:\windows\system32\dllcache\aclua.dll
- 2010-01-12 20:28 . 2009-11-21 15:51 471552 c:\windows\system32\dllcache\aclayers.dll
+ 2004-08-04 10:00 . 2009-11-21 15:51 471552 c:\windows\system32\dllcache\aclayers.dll
+ 2008-08-02 18:17 . 2008-04-14 00:12 184320 c:\windows\system32\dllcache\accwiz.exe
+ 2010-08-18 03:02 . 2001-08-17 16:20 297728 c:\windows\system32\dllcache\ac97sis.sys
+ 2010-08-18 03:02 . 2004-08-04 02:32 231552 c:\windows\system32\dllcache\ac97ali.sys
+ 2008-04-14 00:11 . 2008-04-14 00:11 136192 c:\windows\system32\dllcache\aaclient.dll
+ 2010-08-18 03:02 . 2001-08-18 02:36 462848 c:\windows\system32\dllcache\a3dapi.dll
- 2010-02-12 04:33 . 2010-02-12 04:33 100864 c:\windows\system32\dllcache\6to4svc.dll
+ 2004-08-04 10:00 . 2010-02-12 04:33 100864 c:\windows\system32\dllcache\6to4svc.dll
+ 2010-08-18 03:02 . 2001-08-17 16:48 148352 c:\windows\system32\dllcache\3dfxvsm.sys
+ 2010-08-18 03:02 . 2001-08-17 18:55 689216 c:\windows\system32\dllcache\3dfxvs.dll
+ 2010-08-18 03:02 . 2001-08-17 17:28 762780 c:\windows\system32\dllcache\3cwmcru.sys
+ 2010-08-15 19:54 . 2010-08-15 19:54 180224 c:\windows\Installer\afe9a.msi
+ 2010-08-16 23:30 . 2010-08-16 23:30 676352 c:\windows\Installer\360fe4.msi
+ 2006-03-18 11:09 . 2010-06-24 12:15 1168384 c:\windows\system32\dllcache\urlmon.dll
- 2007-08-13 22:54 . 2010-06-24 12:15 1168384 c:\windows\system32\dllcache\urlmon.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 1614848 c:\windows\system32\dllcache\sfcfiles.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 1287168 c:\windows\system32\dllcache\ole32.dll
- 2008-10-14 21:38 . 2010-04-28 02:25 2189952 c:\windows\system32\dllcache\ntoskrnl.exe
+ 2005-03-30 01:23 . 2010-04-28 02:25 2189952 c:\windows\system32\dllcache\ntoskrnl.exe
+ 2004-08-04 10:00 . 2007-10-22 09:30 1516568 c:\windows\system32\dllcache\msjet40.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 1028096 c:\windows\system32\dllcache\mfc42.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 1852928 c:\windows\system32\dllcache\acgenral.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-07-27 2403568]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-06-06 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-06-06 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-06-06 118784]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2010-06-01 2039240]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-05 00:09 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]
2007-02-21 15:17 970752 —-a-w- c:\program files\Intel\Wireless\Bin\iFrmewrk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelZeroConfig]
2007-02-21 15:19 819200 —-a-w- c:\program files\Intel\Wireless\Bin\ZCfgSvc.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [6/4/2010 11:55 AM 229312]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [6/1/2010 7:00 PM 25240]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [11/17/2008 4:11 PM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [11/17/2008 4:11 PM 67656]
S2 gupdate1c9cccb13c57a8a;Google Update Service (gupdate1c9cccb13c57a8a);c:\program files\Google\Update\GoogleUpdate.exe [5/4/2009 11:14 AM 133104]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [11/17/2008 4:11 PM 12872]
.
Contents of the 'Scheduled Tasks' folder
2010-08-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-04 15:14]
2010-08-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-04 15:14]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
FF - ProfilePath - c:\documents and settings\Tom Spencer\Application Data\Mozilla\Firefox\Profiles\8m02ir7m.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=VI2TDF&PC=VI2TDF&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=VI2TDF&PC=VI2TDF&q=
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-18 18:21
Windows 5.1.2600 Service Pack 3 NTFS
detected NTDLL code modification:
ZwClose, ZwOpenFile
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(832)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(1280)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-08-18 18:23:20
ComboFix-quarantined-files.txt 2010-08-18 22:23
ComboFix2.txt 2010-08-15 16:55
Pre-Run: 48,212,836,352 bytes free
Post-Run: 48,334,557,184 bytes free
- - End Of File - - 00286502314FF1BDF2BA0C8236BCD23D
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4442
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13
8/17/2010 10:00:36 PM
mbam-log-2010-08-17 (22-00-36).txt
Scan type: Full scan (C:\|)
Objects scanned: 175378
Time elapsed: 31 minute(s), 40 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 5
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\ComboFix\Combo-Fix.sys (Trojan.Agent.Gen) -> Not selected for removal.
C:\System Volume Information\_restore{2293CDFF-D6F8-4FBC-9BD3-AFEDFFD0A6EF}\RP227\A0023862.sys (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2293CDFF-D6F8-4FBC-9BD3-AFEDFFD0A6EF}\RP229\A0024099.sys (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2293CDFF-D6F8-4FBC-9BD3-AFEDFFD0A6EF}\RP229\A0024150.sys (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2293CDFF-D6F8-4FBC-9BD3-AFEDFFD0A6EF}\RP229\A0024248.sys (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
ComboFix 10-08-17.04 - Tom Spencer 08/18/2010 18:17:09.7.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.685 [GMT -4:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
c:\documents and settings\All Users\Application Data\SMBIRMCAV
c:\documents and settings\All Users\Application Data\SMBIRMCAV\SMYPAV.cfg
.
((((((((((((((((((((((((( Files Created from 2010-07-18 to 2010-08-18 )))))))))))))))))))))))))))))))
.
2010-08-16 23:30 . 2010-08-16 23:30 ——– d—–w- c:\program files\Java
2010-08-15 19:54 . 2010-08-15 19:54 ——– d—–w- c:\program files\Common Files\Java
2010-08-09 19:00 . 2010-08-09 19:00 61440 —-a-w- c:\documents and settings\Coby\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-44d523b0-n\decora-sse.dll
2010-08-09 19:00 . 2010-08-09 19:00 503808 —-a-w- c:\documents and settings\Coby\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-583aa9bc-n\msvcp71.dll
2010-08-09 19:00 . 2010-08-09 19:00 499712 —-a-w- c:\documents and settings\Coby\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-583aa9bc-n\jmc.dll
2010-08-09 19:00 . 2010-08-09 19:00 348160 —-a-w- c:\documents and settings\Coby\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-583aa9bc-n\msvcr71.dll
2010-08-08 22:44 . 2010-08-08 22:44 ——– d—–w- c:\documents and settings\Coby
2010-08-08 22:44 . 2010-04-07 22:59 ——– d—–w- c:\documents and settings\Coby\Local Settings\Application Data\Google
2010-08-08 22:35 . 2010-08-18 00:50 0 —-a-w- c:\documents and settings\Tom Spencer\Local Settings\Application Data\prvlcl.dat
2010-08-08 17:23 . 2010-08-08 17:23 388096 —-a-r- c:\documents and settings\Tom Spencer\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-08-08 15:30 . 2010-08-08 15:30 ——– d—–w- c:\documents and settings\All Users\Application Data\COMODO
2010-08-08 15:29 . 2010-08-08 15:29 ——– d—–w- c:\program files\COMODO
2010-08-08 15:27 . 2010-08-08 15:28 ——– d—–w- c:\documents and settings\All Users\Application Data\Comodo Downloader
2010-08-08 14:40 . 2010-08-18 22:16 ——– d—–w- c:\program files\Everything
2010-08-08 14:16 . 2008-04-14 00:11 21504 —-a-w- c:\windows\system32\drivers\hidserv.dll
2010-08-08 01:09 . 2010-08-16 22:37 63488 —-a-w- c:\documents and settings\Tom Spencer\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-08-08 01:09 . 2010-08-08 01:09 52224 —-a-w- c:\documents and settings\Tom Spencer\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-08-07 22:08 . 2010-04-29 19:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-07 22:08 . 2010-08-07 23:00 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-08-07 22:08 . 2010-04-29 19:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-08-07 22:02 . 2008-04-14 00:11 21504 -c–a-w- c:\windows\system32\dllcache\hidserv.dll
2010-08-07 22:02 . 2008-04-14 00:11 21504 —-a-w- c:\windows\system32\hidserv.dll
2010-08-07 21:59 . 2010-08-07 21:59 ——– d—–w- c:\windows\system32\wbem\Repository
2010-08-02 21:35 . 2010-08-02 21:35 61440 —-a-w- c:\documents and settings\Tom Spencer\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-13a0aad3-n\decora-sse.dll
2010-08-02 21:35 . 2010-08-02 21:35 503808 —-a-w- c:\documents and settings\Tom Spencer\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-740df2f0-n\msvcp71.dll
2010-08-02 21:35 . 2010-08-02 21:35 499712 —-a-w- c:\documents and settings\Tom Spencer\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-740df2f0-n\jmc.dll
2010-08-02 21:35 . 2010-08-02 21:35 348160 —-a-w- c:\documents and settings\Tom Spencer\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-740df2f0-n\msvcr71.dll
2010-08-02 21:35 . 2010-08-02 21:35 12800 —-a-w- c:\documents and settings\Tom Spencer\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-13a0aad3-n\decora-d3d.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-16 23:30 . 2010-06-13 20:51 423656 —-a-w- c:\windows\system32\deployJava1.dll
2010-08-16 22:37 . 2009-10-29 23:32 117760 —-a-w- c:\documents and settings\Tom Spencer\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-08-09 19:00 . 2010-08-09 19:00 12800 —-a-w- c:\documents and settings\Coby\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-44d523b0-n\decora-d3d.dll
2010-08-08 14:16 . 2010-08-08 14:16 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2010-08-08 14:16 . 2010-08-08 14:16 0 —ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2010-08-08 14:04 . 2008-12-10 19:40 ——– d—–w- c:\program files\Trend Micro
2010-08-08 03:26 . 2008-11-25 15:40 ——– d—–w- c:\program files\Defraggler
2010-08-08 00:23 . 2008-11-25 15:38 ——– d—–w- c:\program files\CCleaner
2010-07-27 23:15 . 2008-11-25 16:02 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-06-30 12:31 . 2004-08-04 10:00 149504 —-a-w- c:\windows\system32\schannel.dll
2010-06-24 12:15 . 2006-03-04 03:33 832512 —-a-w- c:\windows\system32\wininet.dll
2010-06-24 12:15 . 2004-08-04 10:00 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-06-24 12:15 . 2004-08-04 10:00 17408 —-a-w- c:\windows\system32\corpol.dll
2010-06-23 13:44 . 2004-08-04 10:00 1851904 —-a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27 . 2004-08-04 10:00 354304 —-a-w- c:\windows\system32\drivers\srv.sys
2010-06-17 14:03 . 2004-08-04 10:00 80384 —-a-w- c:\windows\system32\iccvid.dll
2010-06-14 14:31 . 2008-08-02 18:19 744448 —-a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-14 07:41 . 2004-08-04 10:00 1172480 —-a-w- c:\windows\system32\msxml3.dll
2010-06-14 00:48 . 2008-08-02 18:57 13104 —-a-w- c:\documents and settings\Tom Spencer\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-04 15:55 . 2010-06-04 15:55 229312 —-a-w- c:\windows\system32\drivers\cmdGuard.sys
2010-06-01 23:00 . 2010-06-01 23:00 278288 —-a-w- c:\windows\system32\guard32.dll
2010-06-01 23:00 . 2010-06-01 23:00 87824 —-a-w- c:\windows\system32\drivers\inspect.sys
2010-06-01 23:00 . 2010-06-01 23:00 25240 —-a-w- c:\windows\system32\drivers\cmdhlp.sys
2010-06-01 23:00 . 2010-06-01 23:00 15464 —-a-w- c:\windows\system32\drivers\cmderd.sys
2010-05-26 22:18 . 2010-05-26 22:18 503808 —-a-w- c:\documents and settings\Tom Spencer\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-426a6f5d-n\msvcp71.dll
2010-05-26 22:18 . 2010-05-26 22:18 499712 —-a-w- c:\documents and settings\Tom Spencer\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-426a6f5d-n\jmc.dll
2010-05-26 22:18 . 2010-05-26 22:18 348160 —-a-w- c:\documents and settings\Tom Spencer\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-426a6f5d-n\msvcr71.dll
2010-05-26 22:18 . 2010-05-26 22:18 61440 —-a-w- c:\documents and settings\Tom Spencer\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-2579a0a2-n\decora-sse.dll
2010-05-26 22:18 . 2010-05-26 22:18 12800 —-a-w- c:\documents and settings\Tom Spencer\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-2579a0a2-n\decora-d3d.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-08-15_16.53.35 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-08-18 22:05 . 2010-08-18 22:05 16384 c:\windows\temp\Perflib_Perfdata_7dc.dat
+ 2004-08-04 10:00 . 2008-04-14 00:12 30749 c:\windows\system32\dllcache\vbajet32.dll
+ 2007-04-02 16:36 . 2007-04-02 16:36 16384 c:\windows\system32\dllcache\tcptsat.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 32827 c:\windows\system32\dllcache\tcptest.exe
+ 2004-08-04 10:00 . 2008-04-14 00:12 25088 c:\windows\system32\dllcache\slayerxp.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 16437 c:\windows\system32\dllcache\shtml.exe
+ 2008-04-14 00:12 . 2008-04-14 00:12 20536 c:\windows\system32\dllcache\shtml.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 65024 c:\windows\system32\dllcache\shimeng.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 77312 c:\windows\system32\dllcache\sdbinst.exe
+ 2004-08-04 10:00 . 2008-04-14 00:12 64000 c:\windows\system32\dllcache\samlib.dll
+ 2010-08-18 03:02 . 2001-08-17 18:56 66048 c:\windows\system32\dllcache\s3legacy.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 84992 c:\windows\system32\dllcache\olepro32.dll
+ 2008-08-02 18:19 . 2008-04-14 00:12 65536 c:\windows\system32\dllcache\oledb32r.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 20511 c:\windows\system32\dllcache\odtext32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 20510 c:\windows\system32\dllcache\odpdx32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 20510 c:\windows\system32\dllcache\odfox32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 20510 c:\windows\system32\dllcache\odexl32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 20511 c:\windows\system32\dllcache\oddbse32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:10 53279 c:\windows\system32\dllcache\odbcji32.dll
+ 2004-08-04 10:00 . 2008-04-13 17:26 94208 c:\windows\system32\dllcache\odbcint.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 65536 c:\windows\system32\dllcache\odbccu32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 65536 c:\windows\system32\dllcache\odbccr32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 69632 c:\windows\system32\dllcache\odbcconf.exe
+ 2004-08-04 10:00 . 2008-04-14 00:12 32768 c:\windows\system32\dllcache\odbcad32.exe
+ 2004-08-04 10:00 . 2008-04-14 00:12 16384 c:\windows\system32\dllcache\odbc32gt.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 67584 c:\windows\system32\dllcache\ocmanage.dll
+ 2004-08-04 10:00 . 2008-04-13 19:20 91520 c:\windows\system32\dllcache\ndiswan.sys
+ 2008-08-02 18:18 . 2008-04-14 00:12 24576 c:\windows\system32\dllcache\msxactps.dll
+ 2004-08-04 10:00 . 2008-04-13 18:30 61440 c:\windows\system32\dllcache\msvcrt40.dll
+ 2004-08-04 10:00 . 2007-04-02 12:49 60192 c:\windows\system32\dllcache\msjter40.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 36864 c:\windows\system32\dllcache\msdfmap.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 20480 c:\windows\system32\dllcache\msdatt.dll
+ 2008-08-02 18:18 . 2008-04-13 17:26 16384 c:\windows\system32\dllcache\msdasqlr.dll
+ 2008-08-02 18:18 . 2008-04-13 17:25 16384 c:\windows\system32\dllcache\msdaremr.dll
+ 2008-08-02 18:18 . 2008-04-13 17:25 16384 c:\windows\system32\dllcache\msdaprsr.dll
+ 2008-08-02 18:19 . 2008-04-14 00:11 77824 c:\windows\system32\dllcache\msdaosp.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 36864 c:\windows\system32\dllcache\mscpxl32.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 57344 c:\windows\system32\dllcache\msadrh15.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 57344 c:\windows\system32\dllcache\msador15.dll
+ 2008-08-02 18:18 . 2008-04-13 17:26 24576 c:\windows\system32\dllcache\msader15.dll
+ 2008-08-02 18:18 . 2008-04-13 17:25 24576 c:\windows\system32\dllcache\msaddsr.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 53248 c:\windows\system32\dllcache\msadcs.dll
+ 2008-08-02 18:18 . 2008-04-13 17:25 16384 c:\windows\system32\dllcache\msadcor.dll
+ 2008-08-02 18:18 . 2008-04-13 17:25 16384 c:\windows\system32\dllcache\msadcfr.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 61440 c:\windows\system32\dllcache\msadcf.dll
+ 2008-08-02 18:18 . 2008-04-13 17:25 20480 c:\windows\system32\dllcache\msadcer.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 22528 c:\windows\system32\dllcache\mfcsubs.dll
+ 2004-08-04 10:00 . 2010-06-24 12:15 27648 c:\windows\system32\dllcache\jsproxy.dll
- 2007-08-13 22:54 . 2010-06-24 12:15 27648 c:\windows\system32\dllcache\jsproxy.dll
+ 2004-08-04 10:00 . 2008-04-13 19:19 75264 c:\windows\system32\dllcache\ipsec.sys
+ 2004-08-04 10:00 . 2008-04-14 00:11 36921 c:\windows\system32\dllcache\imeshare.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 20538 c:\windows\system32\dllcache\fpremadm.exe
+ 2008-04-14 00:11 . 2008-04-14 00:11 20541 c:\windows\system32\dllcache\fpexedll.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 15120 c:\windows\system32\dllcache\fp98sadm.exe
+ 2008-04-14 00:11 . 2008-04-14 00:11 49212 c:\windows\system32\dllcache\fp4awebs.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 32826 c:\windows\system32\dllcache\fp4avss.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 41020 c:\windows\system32\dllcache\fp4avnb.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 49210 c:\windows\system32\dllcache\fp4areg.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 82035 c:\windows\system32\dllcache\fp4anscp.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 16384 c:\windows\system32\dllcache\ds32gt.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 32768 c:\windows\system32\dllcache\dispex.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 39936 c:\windows\system32\dllcache\dimsroam.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 19456 c:\windows\system32\dllcache\dimsntfy.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 62464 c:\windows\system32\dllcache\cryptsvc.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 64512 c:\windows\system32\dllcache\cryptnet.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 53760 c:\windows\system32\dllcache\cryptext.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 33280 c:\windows\system32\dllcache\cryptdll.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 74752 c:\windows\system32\dllcache\cryptdlg.dll
+ 2004-08-04 10:00 . 2008-04-14 00:09 16896 c:\windows\system32\dllcache\cfgmgr32.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 16439 c:\windows\system32\dllcache\author.exe
+ 2008-04-14 00:11 . 2008-04-14 00:11 20540 c:\windows\system32\dllcache\author.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 30208 c:\windows\system32\dllcache\atmlib.dll
- 2010-03-05 14:37 . 2010-03-05 14:37 65536 c:\windows\system32\dllcache\asycfilt.dll
+ 2004-08-04 10:00 . 2010-03-05 14:37 65536 c:\windows\system32\dllcache\asycfilt.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 98304 c:\windows\system32\dllcache\ahui.exe
+ 2004-08-04 10:00 . 2008-04-14 00:11 68096 c:\windows\system32\dllcache\adsmsext.dll
+ 2010-08-18 03:02 . 2001-08-17 16:11 46112 c:\windows\system32\dllcache\adptsf50.sys
- 2007-08-13 22:39 . 2007-08-13 22:39 71680 c:\windows\system32\dllcache\admparse.dll
+ 2004-08-04 10:00 . 2007-08-13 22:39 71680 c:\windows\system32\dllcache\admparse.dll
+ 2010-08-18 03:02 . 2004-08-04 02:32 10880 c:\windows\system32\dllcache\admjoy.sys
+ 2008-04-14 00:12 . 2008-04-14 00:12 16439 c:\windows\system32\dllcache\admin.exe
+ 2008-04-14 00:11 . 2008-04-14 00:11 20540 c:\windows\system32\dllcache\admin.dll
+ 2010-08-18 03:02 . 2001-08-17 16:11 20160 c:\windows\system32\dllcache\adm8511.sys
+ 2004-08-04 10:00 . 2008-04-14 00:11 98304 c:\windows\system32\dllcache\actxprxy.dll
+ 2004-08-04 10:00 . 2004-08-04 10:00 11648 c:\windows\system32\dllcache\acpiec.sys
+ 2010-08-18 03:02 . 2001-08-18 02:36 61440 c:\windows\system32\dllcache\acerscad.dll
+ 2010-08-18 03:02 . 2004-08-04 02:32 84480 c:\windows\system32\dllcache\ac97via.sys
+ 2010-08-18 03:02 . 2001-08-17 16:20 96256 c:\windows\system32\dllcache\ac97intc.sys
+ 2010-08-18 03:02 . 2001-08-17 17:52 23552 c:\windows\system32\dllcache\abp480n5.sys
+ 2010-08-18 03:02 . 2001-08-18 02:36 98304 c:\windows\system32\dllcache\a3d.dll
+ 2010-08-18 03:02 . 2001-08-17 18:55 38400 c:\windows\system32\dllcache\8514a.dll
+ 2010-08-18 03:02 . 2008-04-13 18:46 48128 c:\windows\system32\dllcache\61883.sys
+ 2010-08-18 03:02 . 2008-04-13 18:40 12288 c:\windows\system32\dllcache\4mmdat.sys
+ 2010-08-18 03:02 . 2001-08-17 18:06 11264 c:\windows\system32\dllcache\1394vdbg.sys
+ 2010-08-18 03:02 . 2008-04-13 18:46 53376 c:\windows\system32\dllcache\1394bus.sys
+ 2004-08-04 10:00 . 2008-04-14 00:12 5120 c:\windows\system32\dllcache\sfc.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 4096 c:\windows\system32\dllcache\msdaurl.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 4096 c:\windows\system32\dllcache\msdasc.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 4096 c:\windows\system32\dllcache\msdaer.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 4096 c:\windows\system32\dllcache\msdaenum.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 4096 c:\windows\system32\dllcache\msdadc.dll
+ 2008-04-14 00:09 . 2008-04-14 00:09 6144 c:\windows\system32\dllcache\kbdpash.dll
+ 2008-04-14 00:09 . 2008-04-14 00:09 6144 c:\windows\system32\dllcache\kbdnepr.dll
+ 2008-04-14 00:09 . 2008-04-14 00:09 6144 c:\windows\system32\dllcache\kbdiultn.dll
+ 2008-04-14 00:09 . 2008-04-14 00:09 6144 c:\windows\system32\dllcache\kbdbhc.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 7168 c:\windows\system32\dllcache\bitsprx4.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 3775 c:\windows\system32\dllcache\adv11nt5.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 3711 c:\windows\system32\dllcache\adv09nt5.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 3135 c:\windows\system32\dllcache\adv08nt5.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 3647 c:\windows\system32\dllcache\adv07nt5.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 3615 c:\windows\system32\dllcache\adv05nt5.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 3967 c:\windows\system32\dllcache\adv02nt5.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 4255 c:\windows\system32\dllcache\adv01nt5.dll
+ 2010-08-18 03:02 . 2001-08-17 17:53 7424 c:\windows\system32\dllcache\adicvls.sys
+ 2004-08-04 10:00 . 2008-04-14 00:12 4096 c:\windows\system32\dllcache\actmovie.exe
- 2010-06-13 20:51 . 2010-04-12 21:29 153376 c:\windows\system32\javaws.exe
+ 2010-08-16 23:30 . 2010-08-16 23:30 153376 c:\windows\system32\javaws.exe
- 2010-06-13 20:51 . 2010-04-12 21:29 145184 c:\windows\system32\javaw.exe
+ 2010-08-16 23:30 . 2010-08-16 23:30 145184 c:\windows\system32\javaw.exe
+ 2010-08-16 23:30 . 2010-08-16 23:30 145184 c:\windows\system32\java.exe
- 2010-06-13 20:51 . 2010-04-12 21:29 145184 c:\windows\system32\java.exe
+ 2004-08-04 10:00 . 2009-12-24 06:59 177664 c:\windows\system32\dllcache\wintrust.dll
- 2009-12-24 06:59 . 2009-12-24 06:59 177664 c:\windows\system32\dllcache\wintrust.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 507904 c:\windows\system32\dllcache\winlogon.exe
+ 2006-03-04 03:33 . 2010-06-24 12:15 832512 c:\windows\system32\dllcache\wininet.dll
- 2007-08-13 22:54 . 2010-06-24 12:15 832512 c:\windows\system32\dllcache\wininet.dll
- 2007-08-13 22:54 . 2010-03-09 11:09 430080 c:\windows\system32\dllcache\vbscript.dll
+ 2004-08-04 10:00 . 2010-03-09 11:09 430080 c:\windows\system32\dllcache\vbscript.dll
- 2007-08-13 22:44 . 2010-06-24 12:15 105984 c:\windows\system32\dllcache\url.dll
+ 2004-08-04 10:00 . 2010-06-24 12:15 105984 c:\windows\system32\dllcache\url.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 123392 c:\windows\system32\dllcache\umpnpmgr.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 106496 c:\windows\system32\dllcache\sysocmgr.exe
+ 2004-08-04 10:00 . 2008-04-14 09:42 985088 c:\windows\system32\dllcache\setupapi.dll
+ 2004-08-04 10:00 . 2008-05-09 10:53 172032 c:\windows\system32\dllcache\scrrun.dll
- 2008-05-09 10:53 . 2008-05-09 10:53 172032 c:\windows\system32\dllcache\scrrun.dll
+ 2004-08-04 10:00 . 2008-05-09 10:53 180224 c:\windows\system32\dllcache\scrobj.dll
- 2008-05-09 10:53 . 2008-05-09 10:53 180224 c:\windows\system32\dllcache\scrobj.dll
+ 2004-08-04 10:00 . 2010-06-30 12:31 149504 c:\windows\system32\dllcache\schannel.dll
- 2008-12-05 06:54 . 2010-06-30 12:31 149504 c:\windows\system32\dllcache\schannel.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 415744 c:\windows\system32\dllcache\samsrv.dll
+ 2004-08-04 10:00 . 2008-04-13 17:37 208384 c:\windows\system32\dllcache\rsaenh.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 433664 c:\windows\system32\dllcache\riched20.dll
+ 2008-08-02 18:19 . 2008-04-14 00:12 487424 c:\windows\system32\dllcache\oledb32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 551936 c:\windows\system32\dllcache\oleaut32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 147456 c:\windows\system32\dllcache\odbctrac.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 278559 c:\windows\system32\dllcache\odbcjt32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 106496 c:\windows\system32\dllcache\odbccp32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 135168 c:\windows\system32\dllcache\odbcconf.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 249856 c:\windows\system32\dllcache\odbc32.dll
+ 2004-08-04 10:00 . 2008-04-13 19:15 574976 c:\windows\system32\dllcache\ntfs.sys
- 2009-04-14 19:32 . 2009-02-09 12:10 714752 c:\windows\system32\dllcache\ntdll.dll
+ 2004-08-04 10:00 . 2009-02-09 12:10 714752 c:\windows\system32\dllcache\ntdll.dll
+ 2004-08-04 10:00 . 2008-10-15 16:34 337408 c:\windows\system32\dllcache\netapi32.dll
- 2008-10-23 22:32 . 2008-10-15 16:34 337408 c:\windows\system32\dllcache\netapi32.dll
+ 2004-08-04 10:00 . 2007-04-02 12:52 355104 c:\windows\system32\dllcache\msxbde40.dll
+ 2004-08-04 10:00 . 2007-04-02 12:51 621344 c:\windows\system32\dllcache\mswstr10.dll
+ 2004-08-04 10:00 . 2007-04-02 12:51 838432 c:\windows\system32\dllcache\mswdat10.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 343040 c:\windows\system32\dllcache\msvcrt.dll
+ 2004-08-04 10:00 . 2007-04-02 12:51 264992 c:\windows\system32\dllcache\mstext40.dll
+ 2004-08-04 10:00 . 2007-04-02 12:51 559904 c:\windows\system32\dllcache\msrepl40.dll
+ 2004-08-04 10:00 . 2007-04-02 12:50 322336 c:\windows\system32\dllcache\msrd3x40.dll
+ 2004-08-04 10:00 . 2007-04-02 12:50 432928 c:\windows\system32\dllcache\msrd2x40.dll
+ 2004-08-04 10:00 . 2007-04-02 12:50 355104 c:\windows\system32\dllcache\mspbde40.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 143360 c:\windows\system32\dllcache\msorcl32.dll
+ 2004-08-04 10:00 . 2007-04-02 12:49 219936 c:\windows\system32\dllcache\msltus40.dll
+ 2004-08-04 10:00 . 2007-04-02 12:49 248608 c:\windows\system32\dllcache\msjtes40.dll
+ 2008-08-02 18:18 . 2008-04-14 00:12 102400 c:\windows\system32\dllcache\msjro.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 151583 c:\windows\system32\dllcache\msjint40.dll
+ 2004-08-04 10:00 . 2007-04-02 12:47 326432 c:\windows\system32\dllcache\msexcl40.dll
+ 2004-08-04 10:00 . 2007-04-02 12:47 518944 c:\windows\system32\dllcache\msexch40.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 315392 c:\windows\system32\dllcache\msdasql.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 118784 c:\windows\system32\dllcache\msdarem.dll
+ 2008-08-02 18:19 . 2008-04-14 00:11 204800 c:\windows\system32\dllcache\msdaps.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 200704 c:\windows\system32\dllcache\msdaprst.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 233472 c:\windows\system32\dllcache\msdaora.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 200704 c:\windows\system32\dllcache\msadox.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 180224 c:\windows\system32\dllcache\msadomd.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 536576 c:\windows\system32\dllcache\msado15.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 155648 c:\windows\system32\dllcache\msadds.dll
+ 2008-08-02 18:18 . 2008-04-14 00:11 143360 c:\windows\system32\dllcache\msadco.dll
- 2008-08-30 23:00 . 2008-05-01 14:33 331776 c:\windows\system32\dllcache\msadce.dll
+ 2008-08-02 18:18 . 2008-05-01 14:33 331776 c:\windows\system32\dllcache\msadce.dll
+ 2004-08-04 10:00 . 2007-04-03 03:14 981760 c:\windows\system32\dllcache\mfc42u.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 927504 c:\windows\system32\dllcache\mfc40u.dll
- 2009-04-14 19:32 . 2009-06-25 08:25 730112 c:\windows\system32\dllcache\lsasrv.dll
+ 2004-08-04 10:00 . 2009-06-25 08:25 730112 c:\windows\system32\dllcache\lsasrv.dll
- 2009-03-21 14:06 . 2009-03-21 14:06 989696 c:\windows\system32\dllcache\kernel32.dll
+ 2004-08-04 10:00 . 2009-03-21 14:06 989696 c:\windows\system32\dllcache\kernel32.dll
+ 2004-08-04 10:00 . 2009-08-13 15:16 512000 c:\windows\system32\dllcache\jscript.dll
- 2007-08-13 22:38 . 2009-08-13 15:16 512000 c:\windows\system32\dllcache\jscript.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 138240 c:\windows\system32\dllcache\itss.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 155136 c:\windows\system32\dllcache\itircl.dll
+ 2007-04-02 16:36 . 2007-04-02 16:36 208896 c:\windows\system32\dllcache\fpmmcsat.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 598071 c:\windows\system32\dllcache\fpmmc.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 188494 c:\windows\system32\dllcache\fpcount.exe
+ 2008-04-14 00:12 . 2008-04-14 00:12 109840 c:\windows\system32\dllcache\fp98swin.exe
+ 2008-04-14 00:11 . 2008-04-14 00:11 876653 c:\windows\system32\dllcache\fp4awel.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 102509 c:\windows\system32\dllcache\fp4atxt.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 147513 c:\windows\system32\dllcache\fp4apws.dll
+ 2008-04-14 00:11 . 2008-04-14 00:11 184435 c:\windows\system32\dllcache\fp4amsft.dll
+ 2004-08-04 10:00 . 2008-04-13 19:14 143744 c:\windows\system32\dllcache\fastfat.sys
+ 2004-08-04 10:00 . 2008-04-14 00:11 380445 c:\windows\system32\dllcache\expsrv.dll
+ 2004-08-04 10:00 . 2008-04-13 17:37 138752 c:\windows\system32\dllcache\dssenh.dll
+ 2008-08-02 18:19 . 2008-01-19 11:04 554008 c:\windows\system32\dllcache\dao360.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 512512 c:\windows\system32\dllcache\cryptui.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 599040 c:\windows\system32\dllcache\crypt32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 252928 c:\windows\system32\dllcache\compatui.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 276992 c:\windows\system32\dllcache\comdlg32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 617472 c:\windows\system32\dllcache\comctl32.dll
+ 2008-04-14 00:12 . 2008-04-14 00:12 188480 c:\windows\system32\dllcache\cfgwiz.exe
+ 2008-04-14 00:11 . 2008-04-14 00:11 233472 c:\windows\system32\dllcache\azroles.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 125952 c:\windows\system32\dllcache\apphelp.dll
+ 2004-08-04 10:00 . 2008-08-14 10:04 138496 c:\windows\system32\dllcache\afd.sys
- 2008-06-20 11:40 . 2008-08-14 10:04 138496 c:\windows\system32\dllcache\afd.sys
+ 2008-08-02 18:51 . 2008-04-13 16:39 142592 c:\windows\system32\dllcache\aec.sys
+ 2004-08-04 10:00 . 2010-06-24 12:15 124928 c:\windows\system32\dllcache\advpack.dll
- 2007-08-13 22:39 . 2010-06-24 12:15 124928 c:\windows\system32\dllcache\advpack.dll
+ 2004-08-04 10:00 . 2009-02-09 12:10 617472 c:\windows\system32\dllcache\advapi32.dll
- 2009-04-14 19:32 . 2009-02-09 12:10 617472 c:\windows\system32\dllcache\advapi32.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 263680 c:\windows\system32\dllcache\adsnt.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 143360 c:\windows\system32\dllcache\adsldpc.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 175616 c:\windows\system32\dllcache\adsldp.dll
+ 2010-08-18 03:02 . 2001-08-17 18:07 101888 c:\windows\system32\dllcache\adpu160m.sys
+ 2010-08-18 03:02 . 2001-08-17 16:19 747392 c:\windows\system32\dllcache\adm8830.sys
+ 2010-08-18 03:02 . 2001-08-17 16:19 553984 c:\windows\system32\dllcache\adm8820.sys
+ 2010-08-18 03:02 . 2001-08-17 16:19 584448 c:\windows\system32\dllcache\adm8810.sys
+ 2004-08-04 10:00 . 2008-04-14 00:11 116224 c:\windows\system32\dllcache\acxtrnal.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 193536 c:\windows\system32\dllcache\activeds.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 245248 c:\windows\system32\dllcache\acspecfc.dll
+ 2004-08-04 10:00 . 2008-04-13 18:36 187776 c:\windows\system32\dllcache\acpi.sys
+ 2004-08-04 10:00 . 2008-04-14 00:11 115712 c:\windows\system32\dllcache\aclui.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 141312 c:\windows\system32\dllcache\aclua.dll
- 2010-01-12 20:28 . 2009-11-21 15:51 471552 c:\windows\system32\dllcache\aclayers.dll
+ 2004-08-04 10:00 . 2009-11-21 15:51 471552 c:\windows\system32\dllcache\aclayers.dll
+ 2008-08-02 18:17 . 2008-04-14 00:12 184320 c:\windows\system32\dllcache\accwiz.exe
+ 2010-08-18 03:02 . 2001-08-17 16:20 297728 c:\windows\system32\dllcache\ac97sis.sys
+ 2010-08-18 03:02 . 2004-08-04 02:32 231552 c:\windows\system32\dllcache\ac97ali.sys
+ 2008-04-14 00:11 . 2008-04-14 00:11 136192 c:\windows\system32\dllcache\aaclient.dll
+ 2010-08-18 03:02 . 2001-08-18 02:36 462848 c:\windows\system32\dllcache\a3dapi.dll
- 2010-02-12 04:33 . 2010-02-12 04:33 100864 c:\windows\system32\dllcache\6to4svc.dll
+ 2004-08-04 10:00 . 2010-02-12 04:33 100864 c:\windows\system32\dllcache\6to4svc.dll
+ 2010-08-18 03:02 . 2001-08-17 16:48 148352 c:\windows\system32\dllcache\3dfxvsm.sys
+ 2010-08-18 03:02 . 2001-08-17 18:55 689216 c:\windows\system32\dllcache\3dfxvs.dll
+ 2010-08-18 03:02 . 2001-08-17 17:28 762780 c:\windows\system32\dllcache\3cwmcru.sys
+ 2010-08-15 19:54 . 2010-08-15 19:54 180224 c:\windows\Installer\afe9a.msi
+ 2010-08-16 23:30 . 2010-08-16 23:30 676352 c:\windows\Installer\360fe4.msi
+ 2006-03-18 11:09 . 2010-06-24 12:15 1168384 c:\windows\system32\dllcache\urlmon.dll
- 2007-08-13 22:54 . 2010-06-24 12:15 1168384 c:\windows\system32\dllcache\urlmon.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 1614848 c:\windows\system32\dllcache\sfcfiles.dll
+ 2004-08-04 10:00 . 2008-04-14 00:12 1287168 c:\windows\system32\dllcache\ole32.dll
- 2008-10-14 21:38 . 2010-04-28 02:25 2189952 c:\windows\system32\dllcache\ntoskrnl.exe
+ 2005-03-30 01:23 . 2010-04-28 02:25 2189952 c:\windows\system32\dllcache\ntoskrnl.exe
+ 2004-08-04 10:00 . 2007-10-22 09:30 1516568 c:\windows\system32\dllcache\msjet40.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 1028096 c:\windows\system32\dllcache\mfc42.dll
+ 2004-08-04 10:00 . 2008-04-14 00:11 1852928 c:\windows\system32\dllcache\acgenral.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-07-27 2403568]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-06-06 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-06-06 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-06-06 118784]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2010-06-01 2039240]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-05 00:09 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]
2007-02-21 15:17 970752 —-a-w- c:\program files\Intel\Wireless\Bin\iFrmewrk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelZeroConfig]
2007-02-21 15:19 819200 —-a-w- c:\program files\Intel\Wireless\Bin\ZCfgSvc.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [6/4/2010 11:55 AM 229312]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [6/1/2010 7:00 PM 25240]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [11/17/2008 4:11 PM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [11/17/2008 4:11 PM 67656]
S2 gupdate1c9cccb13c57a8a;Google Update Service (gupdate1c9cccb13c57a8a);c:\program files\Google\Update\GoogleUpdate.exe [5/4/2009 11:14 AM 133104]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [11/17/2008 4:11 PM 12872]
.
Contents of the 'Scheduled Tasks' folder
2010-08-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-04 15:14]
2010-08-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-04 15:14]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
FF - ProfilePath - c:\documents and settings\Tom Spencer\Application Data\Mozilla\Firefox\Profiles\8m02ir7m.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=VI2TDF&PC=VI2TDF&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=VI2TDF&PC=VI2TDF&q=
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-18 18:21
Windows 5.1.2600 Service Pack 3 NTFS
detected NTDLL code modification:
ZwClose, ZwOpenFile
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(832)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(1280)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-08-18 18:23:20
ComboFix-quarantined-files.txt 2010-08-18 22:23
ComboFix2.txt 2010-08-15 16:55
Pre-Run: 48,212,836,352 bytes free
Post-Run: 48,334,557,184 bytes free
- - End Of File - - 00286502314FF1BDF2BA0C8236BCD23D