ComboFix 11-11-30.01 - loaner 11/30/2011 9:26.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.895.203 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\schrauber.exe
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
FW: McAfee Firewall *Enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
.
((((((((((((((((((((((((( Files Created from 2011-10-28 to 2011-11-30 )))))))))))))))))))))))))))))))
.
.
2011-11-30 01:05 . 2011-11-30 01:05 ——– d—–w- c:\program files\CCleaner
2011-11-29 22:05 . 2011-11-30 13:18 56200 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BCB87F85-8D07-4F99-AA74-4DE542336C64}\offreg.dll
2011-11-29 15:54 . 2011-10-07 00:48 6668624 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BCB87F85-8D07-4F99-AA74-4DE542336C64}\mpengine.dll
2011-11-28 13:18 . 2011-11-29 12:27 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-11-15 12:25 . 2011-11-15 12:25 ——– d—–w- c:\documents and settings\loaner\Local Settings\Application Data\PCHealth
2011-11-14 04:13 . 2011-11-17 16:37 ——– d—–w- C:\CMRC
2011-11-08 00:20 . 2011-11-28 15:16 ——– d—–w- C:\MS Torrent
2011-11-07 19:51 . 2011-11-07 19:51 ——– d—–w- c:\documents and settings\loaner\Application Data\Malwarebytes
2011-11-07 19:50 . 2011-11-07 19:50 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-11-07 19:50 . 2011-08-31 21:00 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-11-07 19:50 . 2011-11-07 19:50 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-11-03 18:06 . 2011-11-03 18:06 ——– d—–w- c:\documents and settings\Default User\Local Settings\Application Data\Microsoft Help
2011-11-02 23:35 . 2011-10-07 00:48 6668624 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-11-02 14:05 . 2008-11-10 15:41 32656 —-a-w- c:\windows\system32\msonpmon.dll
2011-11-02 14:05 . 2006-10-26 23:56 33104 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\msonpppr.dll
2011-11-02 09:32 . 2011-11-02 09:32 ——– d—–w- C:\backup
2011-11-02 09:09 . 2009-08-06 23:23 215904 —-a-w- c:\windows\system32\muweb.dll
2011-11-02 09:09 . 2009-08-06 23:23 274288 —-a-w- c:\windows\system32\mucltui.dll
2011-11-02 03:10 . 2011-11-04 20:24 ——– d—–w- c:\windows\system32\NtmsData
2011-11-02 01:39 . 2011-11-02 01:39 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\PCHealth
2011-11-01 20:00 . 2010-10-19 20:51 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-11-01 19:48 . 2011-11-01 19:50 ——– d—–w- c:\program files\Microsoft Security Client
2011-11-01 17:10 . 2011-11-25 02:20 ——– d—–w- C:\dvd convert
2011-11-01 13:08 . 2010-04-14 00:10 54776 —-a-w- c:\windows\system32\drivers\MOBK.sys
2011-11-01 13:06 . 2011-11-01 13:08 ——– d—–w- c:\program files\McAfee Online Backup
2011-11-01 13:02 . 2011-10-15 17:16 9608 —-a-w- c:\windows\system32\drivers\mfeclnk.sys
2011-11-01 13:02 . 2011-10-15 17:16 89792 —-a-w- c:\windows\system32\drivers\mfetdi2k.sys
2011-11-01 13:02 . 2011-10-15 17:16 87656 —-a-w- c:\windows\system32\drivers\mferkdet.sys
2011-11-01 13:02 . 2011-10-15 17:16 83856 —-a-w- c:\windows\system32\drivers\mfendisk.sys
2011-11-01 13:02 . 2011-10-15 17:16 59456 —-a-w- c:\windows\system32\drivers\mfebopk.sys
2011-11-01 13:02 . 2011-10-15 17:16 57600 —-a-w- c:\windows\system32\drivers\cfwids.sys
2011-11-01 13:02 . 2011-10-15 17:16 338176 —-a-w- c:\windows\system32\drivers\mfefirek.sys
2011-11-01 13:02 . 2011-10-15 17:16 180816 —-a-w- c:\windows\system32\drivers\mfeavfk.sys
2011-11-01 13:02 . 2011-11-01 13:04 ——– d—–w- c:\program files\Common Files\Mcafee
2011-11-01 13:01 . 2011-11-10 15:45 ——– d—–w- c:\program files\McAfee
2011-11-01 12:25 . 2011-10-18 18:32 150856 —-a-w- c:\windows\system32\mfevtps.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-25 19:15 . 2011-10-25 19:15 30576 —-a-w- c:\windows\_SETUPD_.EXE
2011-10-15 17:16 . 2011-03-13 15:20 464176 —-a-w- c:\windows\system32\drivers\mfehidk.sys
2011-10-15 17:16 . 2011-03-13 15:20 121256 —-a-w- c:\windows\system32\drivers\mfeapfk.sys
2011-10-10 14:22 . 2011-01-26 14:17 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-10-08 09:47 . 2011-05-17 07:23 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-03 09:06 . 2011-02-23 12:17 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-10-03 06:37 . 2011-02-23 12:17 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-09-28 07:06 . 2006-02-28 12:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41 . 2008-07-29 23:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41 . 2006-02-28 12:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41 . 2006-02-28 12:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-09-06 13:20 . 2006-02-28 12:00 1858944 —-a-w- c:\windows\system32\win32k.sys
.
.
((((((((((((((((((((((((((((( SnapShot@2011-11-29_15.42.16 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-11-30 13:19 . 2011-11-30 13:19 16384 c:\windows\Temp\Perflib_Perfdata_924.dat
+ 2011-11-30 13:19 . 2011-11-30 13:19 16384 c:\windows\Temp\Perflib_Perfdata_890.dat
+ 2011-11-30 13:19 . 2011-11-30 13:19 16384 c:\windows\Temp\Perflib_Perfdata_580.dat
- 2011-01-26 14:25 . 2011-11-29 13:26 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2011-01-26 14:25 . 2011-11-29 22:44 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2011-01-26 14:25 . 2011-11-29 22:44 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2011-01-26 14:25 . 2011-11-29 13:26 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2011-01-26 14:25 . 2011-11-29 13:26 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2011-11-29 22:42 . 2011-11-29 22:44 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2006-07-24 14:50 . 2006-07-24 14:50 47920 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\VBAME.DLL
+ 2009-02-26 19:24 . 2009-02-26 19:24 71536 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\ONFILTER.DLL
+ 2009-02-26 19:24 . 2009-02-26 19:24 97680 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\ONENOTEM.EXE
+ 2006-07-24 14:50 . 2006-07-24 14:50 92976 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\MSADDNDR.DLL
+ 2011-02-15 03:02 . 2011-02-15 03:02 35648 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\OLCTLPIA.DLL
+ 2006-10-27 00:13 . 2006-10-27 00:13 56192 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACECNFLT.EXE
+ 2011-11-30 13:06 . 2011-11-30 13:06 63336 c:\windows\assembly\tmp\JZ5BO8MO\Microsoft.Vbe.Interop.dll
+ 2011-11-30 13:08 . 2011-11-30 13:08 11144 c:\windows\assembly\tmp\DAIAEPWL\Policy.11.0.Microsoft.Office.Interop.Word.dll
+ 2011-11-30 13:08 . 2011-11-30 13:08 34696 c:\windows\assembly\tmp\6EXJ2RD9\Microsoft.Office.Interop.OutlookViewCtl.dll
- 2011-11-15 12:01 . 2011-11-15 12:01 217864 c:\windows\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
+ 2011-11-30 12:05 . 2011-11-30 12:05 217864 c:\windows\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
+ 2007-06-07 23:51 . 2007-06-07 23:51 125320 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\SSGEN.DLL
+ 2007-06-07 23:51 . 2007-06-07 23:51 465800 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\OUTLFLTR.DLL
+ 2008-03-19 10:27 . 2008-03-19 10:27 661536 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\OGALEGIT.DLL
+ 2006-07-24 14:50 . 2006-07-24 14:50 125744 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\MSSTDFMT.DLL
+ 2008-10-25 10:18 . 2008-10-25 10:18 172880 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\IEAWSDC.DLL
+ 2006-10-27 19:35 . 2006-10-27 19:35 436512 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\UMOUTLOOKADDIN.DLL
+ 2006-10-27 00:13 . 2006-10-27 00:13 764800 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\ACECNF.DLL
+ 2011-11-30 13:08 . 2011-11-30 13:08 870256 c:\windows\assembly\tmp\N9SC5APO\Microsoft.Office.Interop.Word.dll
+ 2011-11-30 13:08 . 2011-11-30 13:08 608136 c:\windows\assembly\tmp\ARO3279Y\Microsoft.Office.Infopath.Client.Internal.Host.dll
+ 2011-11-30 13:08 . 2011-11-30 13:08 117160 c:\windows\assembly\tmp\ADSGSQZ0\Microsoft.Office.Infopath.Client.Internal.Host.Interop.dll
+ 2011-11-30 13:09 . 2011-11-30 13:09 350080 c:\windows\assembly\tmp\687YNIEZ\Microsoft.Office.Interop.PowerPoint.dll
+ 2011-11-30 13:06 . 2011-11-30 13:06 149368 c:\windows\assembly\tmp\46WB6A5B\Microsoft.Office.Interop.Graph.dll
+ 2011-07-07 06:28 . 2011-07-07 06:28 1193320 c:\windows\system32\FM20.DLL
+ 2011-09-15 22:35 . 2011-09-15 22:35 1411072 c:\windows\Installer\9f6a2.msp
+ 2009-10-10 03:10 . 2009-10-10 03:10 2594632 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.6612\VBE6.DLL
+ 2006-10-27 00:25 . 2006-10-27 00:25 2172688 c:\windows\Installer\$PatchCache$\Managed\00002109030000000000000000F01FEC\12.0.4518\PSRCHFEA.DLL
+ 2011-11-30 13:08 . 2011-11-30 13:08 1279864 c:\windows\assembly\tmp\4E0I6596\Microsoft.Office.Interop.Excel.dll
+ 2011-09-15 22:37 . 2011-09-15 22:37 16691712 c:\windows\Installer\9f6bd.msp
+ 2011-09-15 22:37 . 2011-09-15 22:37 34428416 c:\windows\Installer\9f6a3.msp
+ 2011-09-15 22:34 . 2011-09-15 22:34 428804608 c:\windows\Installer\ab63f.msp
+ 2011-11-30 12:28 . 2011-11-30 12:28 409672484 c:\windows\Installer\854ff.msp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\MOBK]
@="{3c3f3c1a-9153-7c05-f938-622e7003894d}"
[HKEY_CLASSES_ROOT\CLSID\{3c3f3c1a-9153-7c05-f938-622e7003894d}]
2010-04-14 00:11 2872120 —-a-w- c:\program files\McAfee Online Backup\MOBKshell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\MOBK2]
@="{e6ea1d7d-144e-b977-98c4-84c53c1a69d0}"
[HKEY_CLASSES_ROOT\CLSID\{e6ea1d7d-144e-b977-98c4-84c53c1a69d0}]
2010-04-14 00:11 2872120 —-a-w- c:\program files\McAfee Online Backup\MOBKshell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\MOBK3]
@="{b4caf489-1eec-c617-49ad-8d7088598c06}"
[HKEY_CLASSES_ROOT\CLSID\{b4caf489-1eec-c617-49ad-8d7088598c06}]
2010-04-14 00:11 2872120 —-a-w- c:\program files\McAfee Online Backup\MOBKshell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2011-03-30 399736]
"cdloader"="c:\documents and settings\loaner\Application Data\mjusbsp\cdloader2.exe" [2011-08-23 50592]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2011-07-05 421888]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2011-08-07 273544]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2011-07-27 434080]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\FinalTorrent\\FinalTorrent.EXE"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\FileZilla FTP Client\\filezilla.exe"=
"c:\\Program Files\\Research In Motion\\BlackBerry Desktop\\Rim.Desktop.exe"=
"c:\\Program Files\\Microsoft Office\\OFFICE11\\FRONTPG.EXE"=
"c:\\Program Files\\Real\\Helix Server\\Bin\\rmserver.exe"=
"c:\\Documents and Settings\\loaner\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\FinalMediaPlayer\\FMPCheckForUpdates.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Common Files\\Mcafee\\McSvcHost\\McSvHost.exe"=
"c:\\Documents and Settings\\loaner\\Application Data\\mjusbsp\\magicJack.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [11/1/2011 9:02 AM 89792]
R1 MOBKFilter;MOBKFilter;c:\windows\system32\drivers\MOBK.sys [11/1/2011 9:08 AM 54776]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\Firebird\Firebird_2_1\bin\fbguard.exe -s DefaultInstance –> c:\program files\Firebird\Firebird_2_1\bin\fbguard.exe -s DefaultInstance [?]
R2 Helix Mobile Server;Helix Mobile Server;c:\program files\Real\Helix Server\Bin\rmserver.exe [5/19/2011 2:41 AM 3300352]
R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [11/1/2011 9:02 AM 214904]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [11/1/2011 9:02 AM 214904]
R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\Mcafee\SystemCore\mfefire.exe [11/1/2011 9:03 AM 160608]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [11/1/2011 8:25 AM 150856]
R2 MOBKbackup;McAfee Online Backup;c:\program files\McAfee Online Backup\MOBKbackup.exe [4/13/2010 8:11 PM 229688]
R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [11/1/2011 9:02 AM 57600]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\Firebird\Firebird_2_1\bin\fbserver.exe -s DefaultInstance –> c:\program files\Firebird\Firebird_2_1\bin\fbserver.exe -s DefaultInstance [?]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [7/23/2008 11:31 AM 44800]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [11/1/2011 9:02 AM 338176]
R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [11/1/2011 9:02 AM 83856]
S1 MpKsl01286304;MpKsl01286304;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2BCB7C5D-2FD6-4393-BD35-F5A8231AB41C}\MpKsl01286304.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2BCB7C5D-2FD6-4393-BD35-F5A8231AB41C}\MpKsl01286304.sys [?]
S1 MpKsl0529931f;MpKsl0529931f;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2BCB7C5D-2FD6-4393-BD35-F5A8231AB41C}\MpKsl0529931f.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2BCB7C5D-2FD6-4393-BD35-F5A8231AB41C}\MpKsl0529931f.sys [?]
S1 MpKsl091f7d70;MpKsl091f7d70;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5F5125E5-3149-44CC-8B7A-82910FE8D38C}\MpKsl091f7d70.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5F5125E5-3149-44CC-8B7A-82910FE8D38C}\MpKsl091f7d70.sys [?]
S1 MpKsl206b40cc;MpKsl206b40cc;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D1ED1EE8-0E83-4EBA-964D-2BF0302EF1FF}\MpKsl206b40cc.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D1ED1EE8-0E83-4EBA-964D-2BF0302EF1FF}\MpKsl206b40cc.sys [?]
S1 MpKsl25af1a14;MpKsl25af1a14;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D1ED1EE8-0E83-4EBA-964D-2BF0302EF1FF}\MpKsl25af1a14.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D1ED1EE8-0E83-4EBA-964D-2BF0302EF1FF}\MpKsl25af1a14.sys [?]
S1 MpKsl2821f94a;MpKsl2821f94a;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F479E07D-18F7-46A0-A408-31FD6FD35E40}\MpKsl2821f94a.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F479E07D-18F7-46A0-A408-31FD6FD35E40}\MpKsl2821f94a.sys [?]
S1 MpKsl293256e5;MpKsl293256e5;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7F90D040-6F6D-4E6A-9B3E-914C2FF4FA03}\MpKsl293256e5.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7F90D040-6F6D-4E6A-9B3E-914C2FF4FA03}\MpKsl293256e5.sys [?]
S1 MpKsl2aa17a02;MpKsl2aa17a02;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{52949CDD-56E9-4543-936A-6994D6EE663E}\MpKsl2aa17a02.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{52949CDD-56E9-4543-936A-6994D6EE663E}\MpKsl2aa17a02.sys [?]
S1 MpKsl3128ccf5;MpKsl3128ccf5;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{48F1EC8F-911F-4533-AEC0-3A1E1350092F}\MpKsl3128ccf5.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{48F1EC8F-911F-4533-AEC0-3A1E1350092F}\MpKsl3128ccf5.sys [?]
S1 MpKsl3279af08;MpKsl3279af08;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2BCB7C5D-2FD6-4393-BD35-F5A8231AB41C}\MpKsl3279af08.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2BCB7C5D-2FD6-4393-BD35-F5A8231AB41C}\MpKsl3279af08.sys [?]
S1 MpKsl42f5af95;MpKsl42f5af95;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2BCB7C5D-2FD6-4393-BD35-F5A8231AB41C}\MpKsl42f5af95.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2BCB7C5D-2FD6-4393-BD35-F5A8231AB41C}\MpKsl42f5af95.sys [?]
S1 MpKsl4c7304df;MpKsl4c7304df;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2A8A12F5-BC45-485F-9FE3-91C37D65C482}\MpKsl4c7304df.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2A8A12F5-BC45-485F-9FE3-91C37D65C482}\MpKsl4c7304df.sys [?]
S1 MpKsl5c0bca57;MpKsl5c0bca57;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5F5125E5-3149-44CC-8B7A-82910FE8D38C}\MpKsl5c0bca57.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5F5125E5-3149-44CC-8B7A-82910FE8D38C}\MpKsl5c0bca57.sys [?]
S1 MpKsl5dcef7bc;MpKsl5dcef7bc;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C5A37D36-0467-44D7-A859-D5F147FE924F}\MpKsl5dcef7bc.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C5A37D36-0467-44D7-A859-D5F147FE924F}\MpKsl5dcef7bc.sys [?]
S1 MpKsl64380ef5;MpKsl64380ef5;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{26B504E5-E9CB-4005-8A3F-CACA0DE425FC}\MpKsl64380ef5.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{26B504E5-E9CB-4005-8A3F-CACA0DE425FC}\MpKsl64380ef5.sys [?]
S1 MpKsl691cbe5b;MpKsl691cbe5b;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F479E07D-18F7-46A0-A408-31FD6FD35E40}\MpKsl691cbe5b.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F479E07D-18F7-46A0-A408-31FD6FD35E40}\MpKsl691cbe5b.sys [?]
S1 MpKsl714f566e;MpKsl714f566e;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C5A37D36-0467-44D7-A859-D5F147FE924F}\MpKsl714f566e.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C5A37D36-0467-44D7-A859-D5F147FE924F}\MpKsl714f566e.sys [?]
S1 MpKsl74381e05;MpKsl74381e05;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C5A37D36-0467-44D7-A859-D5F147FE924F}\MpKsl74381e05.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C5A37D36-0467-44D7-A859-D5F147FE924F}\MpKsl74381e05.sys [?]
S1 MpKsl8366c0e0;MpKsl8366c0e0;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2A8A12F5-BC45-485F-9FE3-91C37D65C482}\MpKsl8366c0e0.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2A8A12F5-BC45-485F-9FE3-91C37D65C482}\MpKsl8366c0e0.sys [?]
S1 MpKsl83d78b4a;MpKsl83d78b4a;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2A8A12F5-BC45-485F-9FE3-91C37D65C482}\MpKsl83d78b4a.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{2A8A12F5-BC45-485F-9FE3-91C37D65C482}\MpKsl83d78b4a.sys [?]
S1 MpKsl8612a10f;MpKsl8612a10f;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CA18D9B1-5860-4FEB-8DDB-0541ADEB5B63}\MpKsl8612a10f.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CA18D9B1-5860-4FEB-8DDB-0541ADEB5B63}\MpKsl8612a10f.sys [?]
S1 MpKsla364b468;MpKsla364b468;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{52949CDD-56E9-4543-936A-6994D6EE663E}\MpKsla364b468.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{52949CDD-56E9-4543-936A-6994D6EE663E}\MpKsla364b468.sys [?]
S1 MpKslae95932b;MpKslae95932b;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{52949CDD-56E9-4543-936A-6994D6EE663E}\MpKslae95932b.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{52949CDD-56E9-4543-936A-6994D6EE663E}\MpKslae95932b.sys [?]
S1 MpKslc4d51836;MpKslc4d51836;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1F71F5E5-BEEC-41A8-BC77-33F90E015530}\MpKslc4d51836.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1F71F5E5-BEEC-41A8-BC77-33F90E015530}\MpKslc4d51836.sys [?]
S1 MpKslc70de0e4;MpKslc70de0e4;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F479E07D-18F7-46A0-A408-31FD6FD35E40}\MpKslc70de0e4.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F479E07D-18F7-46A0-A408-31FD6FD35E40}\MpKslc70de0e4.sys [?]
S1 MpKslc9da35db;MpKslc9da35db;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D1ED1EE8-0E83-4EBA-964D-2BF0302EF1FF}\MpKslc9da35db.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D1ED1EE8-0E83-4EBA-964D-2BF0302EF1FF}\MpKslc9da35db.sys [?]
S1 MpKslcb5d34cc;MpKslcb5d34cc;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C9688BD0-E77C-4B5F-94BC-B7EA51A47874}\MpKslcb5d34cc.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{C9688BD0-E77C-4B5F-94BC-B7EA51A47874}\MpKslcb5d34cc.sys [?]
S1 MpKsld1109001;MpKsld1109001;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{26B504E5-E9CB-4005-8A3F-CACA0DE425FC}\MpKsld1109001.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{26B504E5-E9CB-4005-8A3F-CACA0DE425FC}\MpKsld1109001.sys [?]
S1 MpKsld2e59fa1;MpKsld2e59fa1;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1F71F5E5-BEEC-41A8-BC77-33F90E015530}\MpKsld2e59fa1.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{1F71F5E5-BEEC-41A8-BC77-33F90E015530}\MpKsld2e59fa1.sys [?]
S1 MpKsld9bfcea9;MpKsld9bfcea9;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{26B504E5-E9CB-4005-8A3F-CACA0DE425FC}\MpKsld9bfcea9.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{26B504E5-E9CB-4005-8A3F-CACA0DE425FC}\MpKsld9bfcea9.sys [?]
S1 MpKsldb18623e;MpKsldb18623e;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7F90D040-6F6D-4E6A-9B3E-914C2FF4FA03}\MpKsldb18623e.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7F90D040-6F6D-4E6A-9B3E-914C2FF4FA03}\MpKsldb18623e.sys [?]
S1 MpKsle7a962a9;MpKsle7a962a9;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{52949CDD-56E9-4543-936A-6994D6EE663E}\MpKsle7a962a9.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{52949CDD-56E9-4543-936A-6994D6EE663E}\MpKsle7a962a9.sys [?]
S1 MpKsle9507e44;MpKsle9507e44;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{26B504E5-E9CB-4005-8A3F-CACA0DE425FC}\MpKsle9507e44.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{26B504E5-E9CB-4005-8A3F-CACA0DE425FC}\MpKsle9507e44.sys [?]
S1 MpKslee39e17d;MpKslee39e17d;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F46D6FC6-FEF2-4725-BF96-7B1E9B5E2183}\MpKslee39e17d.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F46D6FC6-FEF2-4725-BF96-7B1E9B5E2183}\MpKslee39e17d.sys [?]
S1 MpKslef47bbf7;MpKslef47bbf7;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{40D8BD0F-B3DA-4449-8D4E-DEA05ACEFDB9}\MpKslef47bbf7.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{40D8BD0F-B3DA-4449-8D4E-DEA05ACEFDB9}\MpKslef47bbf7.sys [?]
S1 MpKslfca80051;MpKslfca80051;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7F90D040-6F6D-4E6A-9B3E-914C2FF4FA03}\MpKslfca80051.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7F90D040-6F6D-4E6A-9B3E-914C2FF4FA03}\MpKslfca80051.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S3 CXPLRCAP;Capture Device;c:\windows\system32\drivers\CxPlrCap.sys [8/20/2011 2:47 PM 187776]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [11/1/2011 9:02 AM 83856]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [11/1/2011 9:02 AM 87656]
S3 PPEMSCAN;Protector Plus Email Scan Driver;\??\c:\protector plus\PPEMSCAN.sys –> c:\protector plus\PPEMSCAN.sys [?]
S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8192su.sys [11/25/2010 6:59 AM 606056]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\DRIVERS\wg111v2.sys –> c:\windows\system32\DRIVERS\wg111v2.sys [?]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2/28/2006 8:00 AM 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
.
— Other Services/Drivers In Memory —
.
*Deregistered* - mfeavfk01
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-22 c:\windows\Tasks\AdobeAAMUpdater-1.0-BHPMOTORSPORTS-loaner.job
- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2011-07-14 21:42]
.
2011-11-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 21:57]
.
2011-11-30 c:\windows\Tasks\Final Media Player Update Checker.job
- c:\program files\FinalMediaPlayer\FMPCheckForUpdates.exe [2011-08-18 19:24]
.
2011-11-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1957994488-796845957-725345543-1003Core.job
- c:\documents and settings\loaner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-14 06:28]
.
2011-11-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1957994488-796845957-725345543-1003UA.job
- c:\documents and settings\loaner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-06-14 06:28]
.
2011-11-30 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1957994488-796845957-725345543-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 14:47]
.
2011-11-30 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1957994488-796845957-725345543-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 14:47]
.
2011-11-11 c:\windows\Tasks\SpeedMaxPc Defrag.job
- c:\program files\SpeedMaxPc\SpeedMaxPc\speedmaxpc.exe [2011-10-27 21:14]
.
2011-11-28 c:\windows\Tasks\SpeedMaxPc Registration3.job
- c:\program files\Common Files\SpeedMaxPc\UUS3\UUS3.dll [2010-11-02 18:09]
.
2011-11-22 c:\windows\Tasks\SpeedMaxPc Update3.job
- c:\program files\Common Files\SpeedMaxPc\UUS3\Update3.exe [2010-11-02 18:09]
.
2011-11-20 c:\windows\Tasks\SpeedMaxPc.job
- c:\program files\SpeedMaxPc\SpeedMaxPc\speedmaxpc.exe [2011-10-27 21:14]
.
2011-11-30 c:\windows\Tasks\User_Feed_Synchronization-{F1ACD361-4F07-41D5-B07C-FED2F57481E2}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 08:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/webhp?hl=en
mStart Page = hxxp://search.thechatphone.com
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: {{3B54DEAB-C6D4-48a8-8C32-A70558643400} - c:\program files\FinalVideoDownloader\fvdRunner.html
TCP: DhcpNameServer = 192.168.254.254
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-11-30 09:38
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-1957994488-796845957-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{EC68D8D0-C6CE-DCB9-3409-6509B88ABE66}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iakjloggoobbiggpaa"=hex:6a,61,62,6a,66,62,6c,65,67,65,62,61,68,6a,65,66,6a,6d,
61,61,00,fe
"haajjphdeoaadcbk"=hex:6a,61,67,6b,6d,61,6d,69,70,6f,66,64,6a,6b,66,65,62,6b,
6d,63,00,fe
"iagmfiigainoookjko"=hex:63,61,69,6b,6c,61,00,7c
"dbikmbpehfohcnelmnmnaodjegmcjcokblmfgemg"=hex:68,61,6a,6c,6e,6c,6e,69,62,63,
6f,6e,66,64,69,6a,00,01
"jbikmbpehfohcnelmnmnpmljicnpmbekblpociamacoipfdcagho"=hex:68,61,6a,6c,6e,6c,
6e,69,62,63,6f,6e,66,64,69,6a,00,01
"dbikmbpehfohcnelmnmnjmmjeekfkioaoijgoick"=hex:6c,61,61,68,6b,6b,68,63,63,63,
64,6a,69,64,6c,6f,62,6d,70,66,67,6f,6b,70,00,00
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(1504)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(3840)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
c:\program files\McAfee Online Backup\MOBKshell.dll
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-11-30 09:40:35
ComboFix-quarantined-files.txt 2011-11-30 13:40
ComboFix2.txt 2011-11-29 18:56
ComboFix3.txt 2011-11-29 16:01
.
Pre-Run: 49,175,506,944 bytes free
Post-Run: 49,579,405,312 bytes free
.
- - End Of File - - 4054C5A088BA11B7845C0C70A6B56A80