Okay, I tried doing the things you said, but ran into some problems. I ran the Hijack this scan and got rid of those 6 things. Next when I copied the text and put it into Combo Fix, it started to run and was removing all the stuff but after that, it just stopped and I was just left with my background image, since Combo Fix closed Explorer in order to run, so I restarted and ran Combo Fix on the restart and got the log. Also on that note, on start up, ComboFix asked me if I wanted to upgrade. I said no, just to get the scan. But if its okay to upgrade then I can do that too. Now the Kaspersky scan keeps freezing at 13%. It doesnt freeze up, it just doesnt seem to go past that point. Also it wont generate that report either. When I clicked the button to generate it, it will go to the screen but not show anything. There is a yellow triangle with an exclaimation point at the bottom left of the internet screen, like an error on page, dont know what is going on there. Since I was going to go to bed, I thought I would just give you the new ComboFix and Hijack this report and see what you can tell me about it.
ComboFix 08-09-26.06 - Sean 2008-09-27 18:47:54.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.147 [GMT -7:00]
Running from: H:\Documents and Settings\[removed]\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
H:\WINDOWS\BM9fe4da89.txt
H:\WINDOWS\BM9fe4da89.xml
H:\WINDOWS\pskt.ini
.
((((((((((((((((((((((((( Files Created from 2008-08-28 to 2008-09-28 )))))))))))))))))))))))))))))))
.
2008-09-27 10:34 . 2008-09-27 18:28 d——– H:\WINDOWS\system32\CatRoot_bak
2008-09-27 10:33 . 2008-06-13 06:10 272,128 ——— H:\WINDOWS\system32\drivers\bthport.sys
2008-09-27 10:33 . 2008-06-13 06:10 272,128 —–c— H:\WINDOWS\system32\dllcache\bthport.sys
2008-09-27 10:10 . 2008-09-27 10:10 d——– H:\Program Files\Avira
2008-09-27 10:10 . 2008-09-27 10:10 d——– H:\Documents and Settings\All Users\Application Data\Avira
2008-09-26 20:20 . 2008-09-26 20:20 d——– H:\Program Files\ERUNT
2008-09-26 20:11 . 2008-09-26 20:11 988,531 –ahs—- H:\WINDOWS\system32\dupqcqam.ini
2008-09-26 20:11 . 2008-09-26 20:11 73,216 –a—— H:\WINDOWS\system32\maqcqpud.dll
2008-09-26 20:09 . 2008-09-26 20:09 115,200 –a—— H:\WINDOWS\system32\hdvwlegb.dll
2008-09-26 20:09 . 2008-09-26 20:09 115,200 –a—— H:\WINDOWS\system32\cjxjzy.dll
2008-09-26 20:07 . 2008-09-26 20:07 105,984 –a—— H:\WINDOWS\system32\slshvewf.dll
2008-09-25 20:53 . 2008-09-25 20:52 410,976 –a—— H:\WINDOWS\system32\deploytk.dll
2008-09-25 20:53 . 2008-09-25 20:52 73,728 –a—— H:\WINDOWS\system32\javacpl.cpl
2008-09-25 20:01 . 2008-09-26 20:11 988,531 –ahs—- H:\WINDOWS\system32\uxmosndk.ini
2008-09-25 20:01 . 2008-09-25 20:01 115,200 –a—— H:\WINDOWS\system32\zzuazh.dll
2008-09-25 20:01 . 2008-09-25 20:01 115,200 –a—— H:\WINDOWS\system32\jlxyqvdb.dll
2008-09-25 19:58 . 2008-09-25 19:58 105,472 –a—— H:\WINDOWS\system32\tsovvqlf.dll
2008-09-24 20:22 . 2008-09-25 20:57 d——– H:\WINDOWS\BDOSCAN8
2008-09-24 20:08 . 2008-09-24 20:08 d——– H:\VundoFix Backups
2008-09-24 19:59 . 2008-09-24 20:00 914,829 –ahs—- H:\WINDOWS\system32\qjfqwovw.ini
2008-09-24 19:59 . 2008-09-24 19:59 84,992 –a—— H:\WINDOWS\system32\wvowqfjq.dll
2008-09-24 19:56 . 2008-09-24 19:56 115,200 –a—— H:\WINDOWS\system32\fessvr.dll
2008-09-24 19:56 . 2008-09-24 19:56 115,200 –a—— H:\WINDOWS\system32\dngxkfkf.dll
2008-09-24 18:59 . 2008-09-24 18:59 115,200 –a—— H:\WINDOWS\system32\jgpcdfvs.dll
2008-09-23 18:07 . 2008-09-23 18:07 115,200 –a—— H:\WINDOWS\system32\itntwwos.dll
2008-09-23 18:04 . 2008-09-24 19:24 898,333 –ahs—- H:\WINDOWS\system32\xoyredqh.ini
2008-09-23 16:57 . 2008-09-23 16:57 d——– H:\Documents and Settings\Administrator\Application Data\PC Tools
2008-09-23 16:55 . 2008-09-23 21:58 d——– H:\Documents and Settings\Administrator
2008-09-22 17:02 . 2008-09-22 17:03 879,273 –ahs—- H:\WINDOWS\system32\sqedqumh.ini
2008-09-22 17:02 . 2008-09-22 17:02 85,504 –a—— H:\WINDOWS\system32\hmuqdeqs.dll
2008-09-22 16:59 . 2008-09-22 16:59 115,200 –a—— H:\WINDOWS\system32\huwuysxc.dll
2008-09-22 16:59 . 2008-09-22 16:59 115,200 –a—— H:\WINDOWS\system32\aeiwuv.dll
2008-09-22 16:57 . 2008-09-22 16:57 95,232 –a—— H:\WINDOWS\system32\tmwkxuma.dll
2008-09-18 21:47 . 2008-09-18 21:47 115,200 –a—— H:\WINDOWS\system32\fykltryw.dll
2008-09-18 21:44 . 2008-09-22 16:58 1,059,857 –ahs—- H:\WINDOWS\system32\OoUFgfii.ini
2008-09-18 21:44 . 2008-09-18 21:44 221,184 –a—— H:\WINDOWS\system32\ibapmyid.dll
2008-09-18 21:44 . 2008-09-18 21:44 108,544 –a—— H:\WINDOWS\system32\geBqNeFX.dll
2008-09-18 21:41 . 2008-09-18 21:41 95,744 –a—— H:\WINDOWS\system32\jeraqmkd.dll
2008-09-18 17:44 . 2008-09-18 21:44 1,001,024 –ahs—- H:\WINDOWS\system32\FMTAKRqr.ini
2008-09-18 17:44 . 2008-09-18 17:44 221,184 –a—— H:\WINDOWS\system32\vmhdprty.dll
2008-09-18 17:44 . 2008-09-18 17:44 115,200 –a—— H:\WINDOWS\system32\vaqaiweh.dll
2008-09-18 17:44 . 2008-09-18 17:44 108,544 –a—— H:\WINDOWS\system32\wvUnLFVM.dll
2008-09-18 17:43 . 2008-09-27 10:21 1,166 –ahs—- H:\WINDOWS\system32\kQAayccf.ini2
2008-09-18 17:43 . 2008-09-27 10:21 1,166 –ahs—- H:\WINDOWS\system32\kQAayccf.ini
2008-09-18 17:41 . 2008-09-18 17:41 147,456 –a—— H:\WINDOWS\system32\vbzip10.dll
2008-09-18 17:38 . 2008-09-18 22:53 d——– H:\WINDOWS\system32\mC02
2008-09-06 22:49 . 2008-09-06 22:49 d——– H:\Program Files\NETGEAR
2008-09-06 22:49 . 2008-09-06 22:49 d——– H:\Documents and Settings\Sean\Application Data\InstallShield
2008-09-06 22:49 . 2005-07-20 04:53 966,765 –a—— H:\WINDOWS\system32\acAuth.dll
2008-09-06 22:49 . 2007-12-25 11:24 344,064 –a—— H:\WINDOWS\system32\SCMLib.dll
2008-09-06 22:49 . 2007-12-26 10:47 272,128 –a—— H:\WINDOWS\system32\drivers\wg111v2.sys
2008-09-06 22:49 . 2005-01-25 14:30 143,360 –a—— H:\WINDOWS\system32\IpLib.dll
2008-09-06 22:32 . 2007-04-27 06:00 1,069,056 –a—— H:\WINDOWS\system32\libeay32.dll
2008-09-06 22:32 . 2007-12-18 15:46 266,240 –a—— H:\WINDOWS\system32\WG1v2lib.dll
2008-09-06 22:32 . 2006-07-27 14:26 36,864 –a—— H:\WINDOWS\system32\RtlGina2.dll
2008-09-06 22:32 . 2008-09-06 22:32 21,035 –a—— H:\WINDOWS\system32\drivers\AegisP.sys
2008-08-31 13:16 . 2008-08-31 13:16 d——– H:\Program Files\Bethesda Softworks
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-28 01:44 ——— d—a-w H:\Documents and Settings\All Users\Application Data\TEMP
2008-09-28 01:35 ——— d—–w H:\Program Files\PokerStars.NET
2008-09-27 17:17 ——— d—–w H:\Program Files\Spyware Doctor
2008-09-26 03:52 ——— d—–w H:\Program Files\Java
2008-09-26 02:48 ——— d—–w H:\Documents and Settings\All Users\Application Data\Viewpoint
2008-09-19 01:09 ——— d—–w H:\Documents and Settings\Sean\Application Data\LimeWire
2008-07-28 00:25 ——— d—–w H:\Program Files\DOSBox-0.71
2008-07-19 05:10 94,920 —-a-w H:\WINDOWS\system32\cdm.dll
2008-07-19 05:10 53,448 —-a-w H:\WINDOWS\system32\wuauclt.exe
2008-07-19 05:10 45,768 —-a-w H:\WINDOWS\system32\wups2.dll
2008-07-19 05:10 36,552 —-a-w H:\WINDOWS\system32\wups.dll
2008-07-19 05:09 563,912 —-a-w H:\WINDOWS\system32\wuapi.dll
2008-07-19 05:09 325,832 —-a-w H:\WINDOWS\system32\wucltui.dll
2008-07-19 05:09 205,000 —-a-w H:\WINDOWS\system32\wuweb.dll
2008-07-19 05:09 1,811,656 —-a-w H:\WINDOWS\system32\wuaueng.dll
2008-07-19 05:07 270,880 —-a-w H:\WINDOWS\system32\mucltui.dll
2008-07-19 05:07 210,976 —-a-w H:\WINDOWS\system32\muweb.dll
2008-07-07 20:32 253,952 —-a-w H:\WINDOWS\system32\es.dll
.
((((((((((((((((((((((((((((( snapshot@2008-09-27_10.33.11.01 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-06-13 13:10:50 272,128 ——w H:\WINDOWS\Driver Cache\i386\bthport.sys
+ 2007-03-06 01:22:41 213,216 -c—-w H:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w H:\WINDOWS\ie7updates\KB938127-IE7\spuninst\updspapi.dll
+ 2007-08-14 02:54:10 765,952 -c—-w H:\WINDOWS\ie7updates\KB938127-IE7\vgx.dll
+ 2007-03-06 01:22:39 213,216 -c—-w H:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:47 371,424 -c—-w H:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\updspapi.dll
+ 2007-07-12 23:31:54 765,952 -c—-w H:\WINDOWS\ie7updates\KB938127-v2-IE7\vgx.dll
+ 2007-12-07 02:21:45 124,928 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\advpack.dll
+ 2007-12-19 23:01:06 347,136 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\dxtmsft.dll
+ 2007-12-07 02:21:45 214,528 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\dxtrans.dll
+ 2007-12-07 02:21:45 133,120 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\extmgr.dll
+ 2007-12-07 02:21:45 63,488 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\icardie.dll
+ 2007-12-06 11:00:57 70,656 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\ie4uinit.exe
+ 2007-12-07 02:21:45 153,088 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\ieakeng.dll
+ 2007-12-07 02:21:45 230,400 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\ieaksie.dll
+ 2007-12-06 04:59:51 161,792 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\ieakui.dll
+ 2007-12-07 02:21:45 383,488 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\ieapfltr.dll
+ 2007-12-07 02:21:45 384,512 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\iedkcs32.dll
+ 2007-12-07 02:21:46 6,066,176 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\ieframe.dll
+ 2007-12-07 02:21:46 44,544 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\iernonce.dll
+ 2007-12-07 02:21:46 267,776 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\iertutil.dll
+ 2007-12-06 11:00:58 13,824 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\ieudinit.exe
+ 2007-12-06 11:01:25 625,664 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\iexplore.exe
+ 2007-12-07 02:21:47 27,648 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\jsproxy.dll
+ 2007-12-07 02:21:47 459,264 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\msfeeds.dll
+ 2007-12-07 02:21:47 52,224 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\msfeedsbs.dll
+ 2007-12-08 18:51:48 3,592,192 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\mshtml.dll
+ 2007-12-07 02:21:47 478,208 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\mshtmled.dll
+ 2007-12-07 02:21:48 193,024 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\msrating.dll
+ 2007-12-07 02:21:48 671,232 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\mstime.dll
+ 2007-12-07 02:21:48 102,912 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\occache.dll
+ 2008-01-11 05:53:32 44,544 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\pngfilt.dll
+ 2007-03-06 01:22:39 213,216 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\spuninst\updspapi.dll
+ 2007-12-07 02:21:48 105,984 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\url.dll
+ 2007-12-07 02:21:48 1,159,680 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\urlmon.dll
+ 2007-12-07 02:21:48 233,472 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\webcheck.dll
+ 2007-12-07 02:21:48 824,832 -c—-w H:\WINDOWS\ie7updates\KB953838-IE7\wininet.dll
+ 2007-05-31 20:41:06 10,352,472 —-a-r H:\WINDOWS\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\EXCEL.EXE
+ 2007-04-19 21:09:30 167,256 —-a-r H:\WINDOWS\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\IETAG.DLL
+ 2007-06-19 00:16:32 12,259,160 —-a-r H:\WINDOWS\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\MSO.DLL
+ 2007-05-31 20:35:22 6,420,320 —-a-r H:\WINDOWS\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\POWERPNT.EXE
- 2008-06-25 04:35:58 12,288 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2008-09-27 18:49:45 12,288 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2008-06-25 04:35:58 135,168 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2008-09-27 18:49:45 135,168 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2008-06-25 04:35:58 11,264 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2008-09-27 18:49:45 11,264 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2008-06-25 04:35:58 27,136 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2008-09-27 18:49:45 27,136 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2008-06-25 04:35:58 4,096 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2008-09-27 18:49:45 4,096 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2008-06-25 04:35:58 794,624 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2008-09-27 18:49:45 794,624 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2008-06-25 04:35:58 249,856 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2008-09-27 18:49:45 249,856 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2008-06-25 04:35:58 23,040 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2008-09-27 18:49:45 23,040 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2008-06-25 04:35:58 286,720 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2008-09-27 18:49:45 286,720 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2008-06-25 04:35:58 409,600 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2008-09-27 18:49:45 409,600 —-a-r H:\WINDOWS\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2007-12-07 02:21:45 124,928 —-a-w H:\WINDOWS\system32\advpack.dll
+ 2008-06-23 16:57:27 124,928 —-a-w H:\WINDOWS\system32\advpack.dll
- 2007-12-07 02:21:45 124,928 -c—-w H:\WINDOWS\system32\dllcache\advpack.dll
+ 2008-06-23 16:57:27 124,928 -c—-w H:\WINDOWS\system32\dllcache\advpack.dll
- 2004-10-08 12:01:47 138,496 -c–a-w H:\WINDOWS\system32\dllcache\afd.sys
+ 2008-06-20 10:44:38 138,368 -c–a-w H:\WINDOWS\system32\dllcache\afd.sys
- 2004-10-08 12:01:47 561,179 -c–a-w H:\WINDOWS\system32\dllcache\dao360.dll
+ 2008-03-25 04:50:25 554,008 -c–a-w H:\WINDOWS\system32\dllcache\dao360.dll
- 2006-06-26 17:37:10 148,480 -c–a-w H:\WINDOWS\system32\dllcache\dnsapi.dll
+ 2008-06-20 17:41:10 148,992 -c–a-w H:\WINDOWS\system32\dllcache\dnsapi.dll
- 2007-12-19 23:01:06 347,136 -c—-w H:\WINDOWS\system32\dllcache\dxtmsft.dll
+ 2008-06-23 16:57:27 347,136 -c—-w H:\WINDOWS\system32\dllcache\dxtmsft.dll
- 2007-12-07 02:21:45 214,528 -c—-w H:\WINDOWS\system32\dllcache\dxtrans.dll
+ 2008-06-23 16:57:27 214,528 -c—-w H:\WINDOWS\system32\dllcache\dxtrans.dll
- 2005-07-26 04:39:45 243,200 -c–a-w H:\WINDOWS\system32\dllcache\es.dll
+ 2008-07-07 20:32:22 253,952 -c–a-w H:\WINDOWS\system32\dllcache\es.dll
- 2007-12-07 02:21:45 133,120 -c—-w H:\WINDOWS\system32\dllcache\extmgr.dll
+ 2008-06-23 16:57:27 133,120 -c—-w H:\WINDOWS\system32\dllcache\extmgr.dll
- 2007-12-07 02:21:45 63,488 -c—-w H:\WINDOWS\system32\dllcache\icardie.dll
+ 2008-06-23 16:57:28 63,488 -c—-w H:\WINDOWS\system32\dllcache\icardie.dll
- 2007-12-06 11:00:57 70,656 -c—-w H:\WINDOWS\system32\dllcache\ie4uinit.exe
+ 2008-06-23 09:20:25 70,656 -c—-w H:\WINDOWS\system32\dllcache\ie4uinit.exe
- 2007-12-07 02:21:45 153,088 -c—-w H:\WINDOWS\system32\dllcache\ieakeng.dll
+ 2008-06-23 16:57:29 153,088 -c—-w H:\WINDOWS\system32\dllcache\ieakeng.dll
- 2007-12-07 02:21:45 230,400 -c—-w H:\WINDOWS\system32\dllcache\ieaksie.dll
+ 2008-06-23 16:57:29 230,400 -c—-w H:\WINDOWS\system32\dllcache\ieaksie.dll
- 2007-12-06 04:59:51 161,792 -c—-w H:\WINDOWS\system32\dllcache\ieakui.dll
+ 2008-06-21 05:23:54 161,792 -c—-w H:\WINDOWS\system32\dllcache\ieakui.dll
- 2007-12-07 02:21:45 383,488 -c—-w H:\WINDOWS\system32\dllcache\ieapfltr.dll
+ 2008-06-23 16:57:29 383,488 -c—-w H:\WINDOWS\system32\dllcache\ieapfltr.dll
- 2007-12-07 02:21:45 384,512 -c—-w H:\WINDOWS\system32\dllcache\iedkcs32.dll
+ 2008-06-23 16:57:29 384,512 -c—-w H:\WINDOWS\system32\dllcache\iedkcs32.dll
- 2007-12-07 02:21:46 6,066,176 -c—-w H:\WINDOWS\system32\dllcache\ieframe.dll
+ 2008-06-23 16:57:33 6,066,176 -c—-w H:\WINDOWS\system32\dllcache\ieframe.dll
- 2007-12-07 02:21:46 44,544 -c—-w H:\WINDOWS\system32\dllcache\iernonce.dll
+ 2008-06-23 16:57:33 44,544 -c—-w H:\WINDOWS\system32\dllcache\iernonce.dll
- 2007-12-07 02:21:46 267,776 -c—-w H:\WINDOWS\system32\dllcache\iertutil.dll
+ 2008-06-23 16:57:34 267,776 -c—-w H:\WINDOWS\system32\dllcache\iertutil.dll
- 2007-12-06 11:00:58 13,824 -c—-w H:\WINDOWS\system32\dllcache\ieudinit.exe
+ 2008-06-23 09:20:26 13,824 -c—-w H:\WINDOWS\system32\dllcache\ieudinit.exe
- 2007-12-06 11:01:25 625,664 -c—-w H:\WINDOWS\system32\dllcache\iexplore.exe
+ 2008-06-23 09:20:52 625,664 -c—-w H:\WINDOWS\system32\dllcache\iexplore.exe
- 2007-08-21 06:15:44 683,520 -c–a-w H:\WINDOWS\system32\dllcache\inetcomm.dll
+ 2008-04-11 18:50:43 683,520 -c–a-w H:\WINDOWS\system32\dllcache\inetcomm.dll
- 2007-12-07 02:21:47 27,648 -c—-w H:\WINDOWS\system32\dllcache\jsproxy.dll
+ 2008-06-23 16:57:35 27,648 -c—-w H:\WINDOWS\system32\dllcache\jsproxy.dll
- 2004-10-08 12:01:47 331,776 -c–a-w H:\WINDOWS\system32\dllcache\msadce.dll
+ 2008-05-01 14:30:33 331,776 -c–a-w H:\WINDOWS\system32\dllcache\msadce.dll
- 2005-06-29 01:46:00 74,240 -c–a-w H:\WINDOWS\system32\dllcache\mscms.dll
+ 2008-06-24 16:23:05 74,240 -c–a-w H:\WINDOWS\system32\dllcache\mscms.dll
- 2004-10-08 12:01:47 294,400 -c–a-w H:\WINDOWS\system32\dllcache\msctf.dll
+ 2008-02-26 11:59:50 294,912 -c–a-w H:\WINDOWS\system32\dllcache\msctf.dll
- 2004-10-08 12:01:47 512,029 -c–a-w H:\WINDOWS\system32\dllcache\msexch40.dll
+ 2008-03-25 04:50:28 518,944 -c–a-w H:\WINDOWS\system32\dllcache\msexch40.dll
- 2004-10-08 12:01:47 319,517 -c–a-w H:\WINDOWS\system32\dllcache\msexcl40.dll
+ 2008-03-25 04:50:30 326,432 -c–a-w H:\WINDOWS\system32\dllcache\msexcl40.dll
- 2007-12-07 02:21:47 459,264 -c—-w H:\WINDOWS\system32\dllcache\msfeeds.dll
+ 2008-06-23 16:57:36 459,264 -c—-w H:\WINDOWS\system32\dllcache\msfeeds.dll
- 2007-12-07 02:21:47 52,224 -c—-w H:\WINDOWS\system32\dllcache\msfeedsbs.dll
+ 2008-06-23 16:57:36 52,224 -c—-w H:\WINDOWS\system32\dllcache\msfeedsbs.dll
- 2007-12-08 18:51:48 3,592,192 -c—-w H:\WINDOWS\system32\dllcache\mshtml.dll
+ 2008-06-24 17:57:40 3,592,192 -c—-w H:\WINDOWS\system32\dllcache\mshtml.dll
- 2007-12-07 02:21:47 478,208 -c—-w H:\WINDOWS\system32\dllcache\mshtmled.dll
+ 2008-06-23 16:57:39 477,696 -c—-w H:\WINDOWS\system32\dllcache\mshtmled.dll
- 2004-10-08 12:01:47 1,507,356 -c–a-w H:\WINDOWS\system32\dllcache\msjet40.dll
+ 2008-03-25 04:50:34 1,516,568 -c–a-w H:\WINDOWS\system32\dllcache\msjet40.dll
- 2004-10-08 12:01:47 358,976 -c–a-w H:\WINDOWS\system32\dllcache\msjetol1.dll
+ 2008-03-25 04:50:40 355,112 -c–a-w H:\WINDOWS\system32\dllcache\msjetol1.dll
- 2004-10-08 12:01:47 151,583 -c–a-w H:\WINDOWS\system32\dllcache\msjint40.dll
+ 2008-03-27 08:12:54 151,583 -c–a-w H:\WINDOWS\system32\dllcache\msjint40.dll
- 2004-10-08 12:01:47 53,279 -c–a-w H:\WINDOWS\system32\dllcache\msjter40.dll
+ 2008-03-25 04:50:42 60,192 -c–a-w H:\WINDOWS\system32\dllcache\msjter40.dll
- 2004-10-08 12:01:47 241,693 -c–a-w H:\WINDOWS\system32\dllcache\msjtes40.dll
+ 2008-03-25 04:50:42 248,608 -c–a-w H:\WINDOWS\system32\dllcache\msjtes40.dll
- 2004-10-08 12:01:47 213,023 -c–a-w H:\WINDOWS\system32\dllcache\msltus40.dll
+ 2008-03-25 04:50:44 219,936 -c–a-w H:\WINDOWS\system32\dllcache\msltus40.dll
- 2004-10-08 12:01:47 348,189 -c–a-w H:\WINDOWS\system32\dllcache\mspbde40.dll
+ 2008-03-25 04:50:45 355,104 -c–a-w H:\WINDOWS\system32\dllcache\mspbde40.dll
- 2007-12-07 02:21:48 193,024 -c—-w H:\WINDOWS\system32\dllcache\msrating.dll
+ 2008-06-23 16:57:39 193,024 -c—-w H:\WINDOWS\system32\dllcache\msrating.dll
- 2004-10-08 12:01:47 421,919 -c–a-w H:\WINDOWS\system32\dllcache\msrd2x40.dll
+ 2008-03-25 04:50:47 432,928 -c–a-w H:\WINDOWS\system32\dllcache\msrd2x40.dll
- 2004-10-08 12:01:47 315,423 -c–a-w H:\WINDOWS\system32\dllcache\msrd3x40.dll
+ 2008-03-25 04:50:49 322,336 -c–a-w H:\WINDOWS\system32\dllcache\msrd3x40.dll
- 2004-10-08 12:01:47 552,989 -c–a-w H:\WINDOWS\system32\dllcache\msrepl40.dll
+ 2008-03-25 04:50:52 559,904 -c–a-w H:\WINDOWS\system32\dllcache\msrepl40.dll
- 2004-10-08 12:01:47 258,077 -c–a-w H:\WINDOWS\system32\dllcache\mstext40.dll
+ 2008-03-25 04:50:55 264,992 -c–a-w H:\WINDOWS\system32\dllcache\mstext40.dll
- 2007-12-07 02:21:48 671,232 -c—-w H:\WINDOWS\system32\dllcache\mstime.dll
+ 2008-06-23 16:57:40 671,232 -c—-w H:\WINDOWS\system32\dllcache\mstime.dll
- 2004-10-08 12:01:47 831,519 -c–a-w H:\WINDOWS\system32\dllcache\mswdat10.dll
+ 2008-03-25 04:50:57 838,432 -c–a-w H:\WINDOWS\system32\dllcache\mswdat10.dll
- 2004-10-08 12:01:47 245,248 -c–a-w H:\WINDOWS\system32\dllcache\mswsock.dll
+ 2008-06-20 17:41:10 245,248 -c–a-w H:\WINDOWS\system32\dllcache\mswsock.dll
- 2004-10-08 12:01:47 614,429 -c–a-w H:\WINDOWS\system32\dllcache\mswstr10.dll
+ 2008-03-25 04:50:58 621,344 -c–a-w H:\WINDOWS\system32\dllcache\mswstr10.dll
- 2004-10-08 12:01:47 348,189 -c–a-w H:\WINDOWS\system32\dllcache\msxbde40.dll
+ 2008-03-25 04:50:58 355,104 -c–a-w H:\WINDOWS\system32\dllcache\msxbde40.dll
- 2007-12-07 02:21:48 102,912 -c—-w H:\WINDOWS\system32\dllcache\occache.dll
+ 2008-06-23 16:57:40 102,912 -c—-w H:\WINDOWS\system32\dllcache\occache.dll
- 2008-01-11 05:53:32 44,544 -c—-w H:\WINDOWS\system32\dllcache\pngfilt.dll
+ 2008-06-23 16:57:40 44,544 -c—-w H:\WINDOWS\system32\dllcache\pngfilt.dll
- 2007-10-29 22:43:03 1,287,680 -c–a-w H:\WINDOWS\system32\dllcache\quartz.dll
+ 2008-05-07 05:18:48 1,287,680 -c–a-w H:\WINDOWS\system32\dllcache\quartz.dll
- 2006-07-13 08:48:58 202,240 -c–a-w H:\WINDOWS\system32\dllcache\rmcast.sys
+ 2008-05-08 12:28:49 202,752 -c–a-w H:\WINDOWS\system32\dllcache\rmcast.sys
- 2007-10-30 17:20:55 360,064 -c–a-w H:\WINDOWS\system32\dllcache\tcpip.sys
+ 2008-06-20 10:45:13 360,320 -c–a-w H:\WINDOWS\system32\dllcache\tcpip.sys
- 2006-08-16 09:37:30 225,664 -c–a-w H:\WINDOWS\system32\dllcache\tcpip6.sys
+ 2008-06-20 09:52:06 225,920 -c–a-w H:\WINDOWS\system32\dllcache\tcpip6.sys
- 2007-12-07 02:21:48 105,984 -c—-w H:\WINDOWS\system32\dllcache\url.dll
+ 2008-06-23 16:57:40 105,984 -c—-w H:\WINDOWS\system32\dllcache\url.dll
- 2007-12-07 02:21:48 1,159,680 -c—-w H:\WINDOWS\system32\dllcache\urlmon.dll
+ 2008-06-23 16:57:40 1,159,680 -c—-w H:\WINDOWS\system32\dllcache\urlmon.dll
- 2007-08-14 02:54:10 765,952 -c–a-w H:\WINDOWS\system32\dllcache\VGX.dll
+ 2008-05-27 17:23:58 765,952 -c–a-w H:\WINDOWS\system32\dllcache\vgx.dll
- 2007-12-07 02:21:48 233,472 -c—-w H:\WINDOWS\system32\dllcache\webcheck.dll
+ 2008-06-23 16:57:41 233,472 -c—-w H:\WINDOWS\system32\dllcache\webcheck.dll
- 2007-12-07 02:21:48 824,832 -c—-w H:\WINDOWS\system32\dllcache\wininet.dll
+ 2008-06-23 16:57:41 826,368 -c—-w H:\WINDOWS\system32\dllcache\wininet.dll
- 2006-06-26 17:37:10 148,480 —-a-w H:\WINDOWS\system32\dnsapi.dll
+ 2008-06-20 17:41:10 148,992 —-a-w H:\WINDOWS\system32\dnsapi.dll
- 2004-10-08 12:01:47 138,496 —-a-w H:\WINDOWS\system32\drivers\afd.sys
+ 2008-06-20 10:44:38 138,368 —-a-w H:\WINDOWS\system32\drivers\afd.sys
- 2006-07-13 08:48:58 202,240 —-a-w H:\WINDOWS\system32\drivers\rmcast.sys
+ 2008-05-08 12:28:49 202,752 —-a-w H:\WINDOWS\system32\drivers\rmcast.sys
- 2007-10-30 17:20:55 360,064 —-a-w H:\WINDOWS\system32\drivers\tcpip.sys
+ 2008-06-20 10:45:13 360,320 —-a-w H:\WINDOWS\system32\drivers\tcpip.sys
- 2006-08-16 09:37:30 225,664 —-a-w H:\WINDOWS\system32\drivers\tcpip6.sys
+ 2008-06-20 09:52:06 225,920 —-a-w H:\WINDOWS\system32\drivers\tcpip6.sys
- 2007-12-19 23:01:06 347,136 —-a-w H:\WINDOWS\system32\dxtmsft.dll
+ 2008-06-23 16:57:27 347,136 —-a-w H:\WINDOWS\system32\dxtmsft.dll
- 2007-12-07 02:21:45 214,528 —-a-w H:\WINDOWS\system32\dxtrans.dll
+ 2008-06-23 16:57:27 214,528 —-a-w H:\WINDOWS\system32\dxtrans.dll
- 2007-12-07 02:21:45 133,120 —-a-w H:\WINDOWS\system32\extmgr.dll
+ 2008-06-23 16:57:27 133,120 —-a-w H:\WINDOWS\system32\extmgr.dll
- 2007-12-07 02:21:45 63,488 —-a-w H:\WINDOWS\system32\icardie.dll
+ 2008-06-23 16:57:28 63,488 —-a-w H:\WINDOWS\system32\icardie.dll
- 2007-12-06 11:00:57 70,656 —-a-w H:\WINDOWS\system32\ie4uinit.exe
+ 2008-06-23 09:20:25 70,656 —-a-w H:\WINDOWS\system32\ie4uinit.exe
- 2007-12-07 02:21:45 153,088 —-a-w H:\WINDOWS\system32\ieakeng.dll
+ 2008-06-23 16:57:29 153,088 —-a-w H:\WINDOWS\system32\ieakeng.dll
- 2007-12-07 02:21:45 230,400 —-a-w H:\WINDOWS\system32\ieaksie.dll
+ 2008-06-23 16:57:29 230,400 —-a-w H:\WINDOWS\system32\ieaksie.dll
- 2007-12-06 04:59:51 161,792 —-a-w H:\WINDOWS\system32\ieakui.dll
+ 2008-06-21 05:23:54 161,792 —-a-w H:\WINDOWS\system32\ieakui.dll
- 2007-12-07 02:21:45 383,488 —-a-w H:\WINDOWS\system32\ieapfltr.dll
+ 2008-06-23 16:57:29 383,488 —-a-w H:\WINDOWS\system32\ieapfltr.dll
- 2007-12-07 02:21:45 384,512 —-a-w H:\WINDOWS\system32\iedkcs32.dll
+ 2008-06-23 16:57:29 384,512 —-a-w H:\WINDOWS\system32\iedkcs32.dll
- 2007-12-07 02:21:46 6,066,176 —-a-w H:\WINDOWS\system32\ieframe.dll
+ 2008-06-23 16:57:33 6,066,176 —-a-w H:\WINDOWS\system32\ieframe.dll
- 2007-12-07 02:21:46 44,544 —-a-w H:\WINDOWS\system32\iernonce.dll
+ 2008-06-23 16:57:33 44,544 —-a-w H:\WINDOWS\system32\iernonce.dll
- 2007-12-07 02:21:46 267,776 —-a-w H:\WINDOWS\system32\iertutil.dll
+ 2008-06-23 16:57:34 267,776 —-a-w H:\WINDOWS\system32\iertutil.dll
- 2007-12-06 11:00:58 13,824 —-a-w H:\WINDOWS\system32\ieudinit.exe
+ 2008-06-23 09:20:26 13,824 —-a-w H:\WINDOWS\system32\ieudinit.exe
- 2007-08-21 06:15:44 683,520 —-a-w H:\WINDOWS\system32\inetcomm.dll
+ 2008-04-11 18:50:43 683,520 —-a-w H:\WINDOWS\system32\inetcomm.dll
- 2007-12-07 02:21:47 27,648 —-a-w H:\WINDOWS\system32\jsproxy.dll
+ 2008-06-23 16:57:35 27,648 —-a-w H:\WINDOWS\system32\jsproxy.dll
- 2008-02-04 23:09:48 18,214,008 —-a-w H:\WINDOWS\system32\MRT.exe
+ 2008-08-26 20:28:14 16,208,504 —-a-w H:\WINDOWS\system32\MRT.exe
- 2005-06-29 01:46:00 74,240 —-a-w H:\WINDOWS\system32\mscms.dll
+ 2008-06-24 16:23:05 74,240 —-a-w H:\WINDOWS\system32\mscms.dll
- 2004-10-08 12:01:47 294,400 —-a-w H:\WINDOWS\system32\MSCTF.dll
+ 2008-02-26 11:59:50 294,912 —-a-w H:\WINDOWS\system32\msctf.dll
- 2004-10-08 12:01:47 512,029 —-a-w H:\WINDOWS\system32\msexch40.dll
+ 2008-03-25 04:50:28 518,944 —-a-w H:\WINDOWS\system32\msexch40.dll
- 2004-10-08 12:01:47 319,517 —-a-w H:\WINDOWS\system32\msexcl40.dll
+ 2008-03-25 04:50:30 326,432 —-a-w H:\WINDOWS\system32\msexcl40.dll
- 2007-12-07 02:21:47 459,264 —-a-w H:\WINDOWS\system32\msfeeds.dll
+ 2008-06-23 16:57:36 459,264 —-a-w H:\WINDOWS\system32\msfeeds.dll
- 2007-12-07 02:21:47 52,224 —-a-w H:\WINDOWS\system32\msfeedsbs.dll
+ 2008-06-23 16:57:36 52,224 —-a-w H:\WINDOWS\system32\msfeedsbs.dll
- 2007-12-08 18:51:48 3,592,192 —-a-w H:\WINDOWS\system32\mshtml.dll
+ 2008-06-24 17:57:40 3,592,192 —-a-w H:\WINDOWS\system32\mshtml.dll
- 2007-12-07 02:21:47 478,208 —-a-w H:\WINDOWS\system32\mshtmled.dll
+ 2008-06-23 16:57:39 477,696 —-a-w H:\WINDOWS\system32\mshtmled.dll
- 2004-10-08 12:01:47 1,507,356 —-a-w H:\WINDOWS\system32\msjet40.dll
+ 2008-03-25 04:50:34 1,516,568 —-a-w H:\WINDOWS\system32\msjet40.dll
- 2004-10-08 12:01:47 358,976 —-a-w H:\WINDOWS\system32\msjetoledb40.dll
+ 2008-03-25 04:50:40 355,112 —-a-w H:\WINDOWS\system32\msjetoledb40.dll
- 2004-10-08 12:01:47 151,583 —-a-w H:\WINDOWS\system32\msjint40.dll
+ 2008-03-27 08:12:54 151,583 —-a-w H:\WINDOWS\system32\msjint40.dll
- 2004-10-08 12:01:47 53,279 —-a-w H:\WINDOWS\system32\msjter40.dll
+ 2008-03-25 04:50:42 60,192 —-a-w H:\WINDOWS\system32\msjter40.dll
- 2004-10-08 12:01:47 241,693 —-a-w H:\WINDOWS\system32\msjtes40.dll
+ 2008-03-25 04:50:42 248,608 —-a-w H:\WINDOWS\system32\msjtes40.dll
- 2004-10-08 12:01:47 213,023 —-a-w H:\WINDOWS\system32\msltus40.dll
+ 2008-03-25 04:50:44 219,936 —-a-w H:\WINDOWS\system32\msltus40.dll
- 2004-10-08 12:01:47 348,189 —-a-w H:\WINDOWS\system32\mspbde40.dll
+ 2008-03-25 04:50:45 355,104 —-a-w H:\WINDOWS\system32\mspbde40.dll
- 2007-12-07 02:21:48 193,024 —-a-w H:\WINDOWS\system32\msrating.dll
+ 2008-06-23 16:57:39 193,024 —-a-w H:\WINDOWS\system32\msrating.dll
- 2004-10-08 12:01:47 421,919 —-a-w H:\WINDOWS\system32\msrd2x40.dll
+ 2008-03-25 04:50:47 432,928 —-a-w H:\WINDOWS\system32\msrd2x40.dll
- 2004-10-08 12:01:47 315,423 —-a-w H:\WINDOWS\system32\msrd3x40.dll
+ 2008-03-25 04:50:49 322,336 —-a-w H:\WINDOWS\system32\msrd3x40.dll
- 2004-10-08 12:01:47 552,989 —-a-w H:\WINDOWS\system32\msrepl40.dll
+ 2008-03-25 04:50:52 559,904 —-a-w H:\WINDOWS\system32\msrepl40.dll
- 2004-10-08 12:01:47 258,077 —-a-w H:\WINDOWS\system32\mstext40.dll
+ 2008-03-25 04:50:55 264,992 —-a-w H:\WINDOWS\system32\mstext40.dll
- 2007-12-07 02:21:48 671,232 —-a-w H:\WINDOWS\system32\mstime.dll
+ 2008-06-23 16:57:40 671,232 —-a-w H:\WINDOWS\system32\mstime.dll
- 2004-10-08 12:01:47 831,519 —-a-w H:\WINDOWS\system32\mswdat10.dll
+ 2008-03-25 04:50:57 838,432 —-a-w H:\WINDOWS\system32\mswdat10.dll
- 2004-10-08 12:01:47 245,248 —-a-w H:\WINDOWS\system32\mswsock.dll
+ 2008-06-20 17:41:10 245,248 —-a-w H:\WINDOWS\system32\mswsock.dll
- 2004-10-08 12:01:47 614,429 —-a-w H:\WINDOWS\system32\mswstr10.dll
+ 2008-03-25 04:50:58 621,344 —-a-w H:\WINDOWS\system32\mswstr10.dll
- 2004-10-08 12:01:47 348,189 —-a-w H:\WINDOWS\system32\msxbde40.dll
+ 2008-03-25 04:50:58 355,104 —-a-w H:\WINDOWS\system32\msxbde40.dll
- 2007-12-07 02:21:48 102,912 —-a-w H:\WINDOWS\system32\occache.dll
+ 2008-06-23 16:57:40 102,912 —-a-w H:\WINDOWS\system32\occache.dll
- 2008-01-11 05:53:32 44,544 —-a-w H:\WINDOWS\system32\pngfilt.dll
+ 2008-06-23 16:57:40 44,544 —-a-w H:\WINDOWS\system32\pngfilt.dll
- 2007-10-29 22:43:03 1,287,680 —-a-w H:\WINDOWS\system32\quartz.dll
+ 2008-05-07 05:18:48 1,287,680 —-a-w H:\WINDOWS\system32\quartz.dll
- 2006-09-26 00:58:48 14,640 —-a-w H:\WINDOWS\system32\spmsg.dll
+ 2007-11-30 11:18:51 17,272 ——w H:\WINDOWS\system32\spmsg.dll
- 2007-11-13 11:31:11 60,416 —-a-w H:\WINDOWS\system32\tzchange.exe
+ 2008-07-14 11:09:18 62,976 —-a-w H:\WINDOWS\system32\tzchange.exe
- 2007-12-07 02:21:48 105,984 —-a-w H:\WINDOWS\system32\url.dll
+ 2008-06-23 16:57:40 105,984 —-a-w H:\WINDOWS\system32\url.dll
- 2007-12-07 02:21:48 1,159,680 —-a-w H:\WINDOWS\system32\urlmon.dll
+ 2008-06-23 16:57:40 1,159,680 —-a-w H:\WINDOWS\system32\urlmon.dll
- 2007-12-07 02:21:48 233,472 —-a-w H:\WINDOWS\system32\webcheck.dll
+ 2008-06-23 16:57:41 233,472 —-a-w H:\WINDOWS\system32\webcheck.dll
- 2007-12-07 02:21:48 824,832 —-a-w H:\WINDOWS\system32\wininet.dll
+ 2008-06-23 16:57:41 826,368 —-a-w H:\WINDOWS\system32\wininet.dll
- 2006-10-19 04:47:20 295,936 —-a-w H:\WINDOWS\system32\wmpeffects.dll
+ 2008-06-25 01:12:58 295,936 —-a-w H:\WINDOWS\system32\wmpeffects.dll
+ 2008-09-28 01:43:30 16,384 —-atw H:\WINDOWS\temp\Perflib_Perfdata_61c.dat
+ 2008-04-15 17:54:19 1,724,416 —-a-w H:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.3352_x-ww_81af8e88\GdiPlus.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="H:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"ctfmon.exe"="H:\WINDOWS\system32\ctfmon.exe" [2004-10-08 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="H:\WINDOWS\system32\NvCpl.dll" [2007-12-05 8523776]
"NvMediaCenter"="H:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 81920]
"TkBellExe"="H:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-07-13 180269]
"QuickTime Task"="H:\Program Files\QuickTime\qttask.exe" [2008-05-27 413696]
"SunJavaUpdateSched"="H:\Program Files\Java\jre6\bin\jusched.exe" [2008-09-25 140696]
"avgnt"="H:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"BM9fe4da89"="H:\WINDOWS\system32\slshvewf.dll" [2008-09-26 105984]
"nwiz"="nwiz.exe" [2007-12-05 H:\WINDOWS\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Spyware Doctor"="H:\Program Files\Spyware Doctor\swdoctor.exe" [2006-12-15 2115728]
H:\Documents and Settings\All Users\Start Menu\Programs\Startup\
NETGEAR WG111v2 Smart Wizard.lnk - H:\Program Files\NETGEAR\WG111v2\WG111v2.exe [2008-09-06 1261568]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
[HKLM\~\startupfolder\H:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=H:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=H:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\H:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
path=H:\Documents and Settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
backup=H:\WINDOWS\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
–a—— 2006-03-21 18:30 1191936 H:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
–a—— 2007-01-19 13:54 5674352 H:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
–a—— 2007-12-05 01:41 8523776 H:\WINDOWS\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVIDIA nTune]
–a—— 2005-01-18 13:32 532480 H:\Program Files\NVIDIA Corporation\nTune\nTune.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
–a—— 2007-12-05 01:41 81920 H:\WINDOWS\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVRaidService]
-ra—— 2005-02-25 14:27 83968 H:\WINDOWS\system32\nvraidservice.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-05-27 10:50 413696 H:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyware Doctor]
–a—— 2006-12-15 12:16 2115728 H:\PROGRA~1\SPYWAR~1\swdoctor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2006-07-13 10:53 180269 H:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vptray]
–a—— 2003-05-21 01:21 90112 H:\PROGRA~1\SYMANT~1\SYMANT~1\VPTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
–a—— 2007-12-05 01:41 1626112 H:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
–a—— 2005-02-25 14:26 67584 H:\WINDOWS\SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"usnjsvc"=3 (0x3)
"SDhelper"=2 (0x2)
"ose"=3 (0x3)
"NVSvc"=2 (0x2)
"Norton AntiVirus Server"=2 (0x2)
"IDriverT"=3 (0x3)
"DefWatch"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"H:\\Program Files\\Messenger\\msmsgs.exe"=
"H:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"H:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"H:\\Program Files\\MSN Messenger\\livecall.exe"=
"H:\\Program Files\\World of Warcraft\\WoW-1.12.0-enUS-downloader.exe"=
"H:\\Program Files\\World of Warcraft\\WoW-1.12.x-to-2.0.1-enUS-patch-downloader.exe"=
"H:\\Program Files\\World of Warcraft\\Launcher.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader
"6112:TCP"= 6112:TCP:Blizzard Downloader
R2 JavaQuickStarterService;Java Quick Starter;H:\Program Files\Java\jre6\bin\jqs.exe [2008-09-25 152984]
R3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;H:\WINDOWS\system32\DRIVERS\wg111v2.sys [2007-12-26 272128]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\AutoRunMorrowind.exe
\Shell\install\command - G:\Setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f4ab9820-05c7-11dd-9991-003018a43a73}]
\Shell\AutoRun\command - I:\setupSNK.exe
.
Contents of the 'Scheduled Tasks' folder
.
.
——- Supplementary Scan ——-
.
R0 -: HKCU-Main,Start Page = hxxp://forums.whatthetech.com/forums.html
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
R0 -: HKLM-Main,Search Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 -: HKCU-SearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
O8 -: E&xport to Microsoft Excel - H:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 -: Easy-WebPrint Add To Print List - H:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 -: Easy-WebPrint High Speed Print - H:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 -: Easy-WebPrint Preview - H:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 -: Easy-WebPrint Print - H:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O16 -: Microsoft XML Parser for Java - file://H:\WINDOWS\Java\classes\xmldso.cab
H:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-09-27 18:50:52
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\H:\DOCUME~1\Sean\LOCALS~1\Temp\mc21.tmp"
.
——————— DLLs Loaded Under Running Processes ———————
PROCESS: H:\WINDOWS\system32\winlogon.exe
-> H:\WINDOWS\system32\NavLogon.dll
.
Completion time: 2008-09-27 18:52:42
ComboFix-quarantined-files.txt 2008-09-28 01:52:39
ComboFix2.txt 2008-09-27 17:33:40
Pre-Run: 12,964,773,888 bytes free
Post-Run: 12,954,935,296 bytes free
521 — E O F — 2008-09-27 18:54:35
Logfile of HijackThis v1.99.1
Scan saved at 10:21:05 PM, on 9/27/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Running processes:
H:\WINDOWS\System32\smss.exe
H:\WINDOWS\system32\csrss.exe
H:\WINDOWS\system32\winlogon.exe
H:\WINDOWS\system32\services.exe
H:\WINDOWS\system32\lsass.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\System32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\svchost.exe
H:\WINDOWS\system32\spoolsv.exe
H:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
H:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
H:\Program Files\Java\jre6\bin\jqs.exe
H:\WINDOWS\system32\nvsvc32.exe
H:\WINDOWS\system32\PnkBstrA.exe
H:\WINDOWS\System32\alg.exe
H:\Program Files\Common Files\Real\Update_OB\realsched.exe
H:\Program Files\QuickTime\qttask.exe
H:\Program Files\Java\jre6\bin\jusched.exe
H:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
H:\WINDOWS\system32\ctfmon.exe
H:\WINDOWS\System32\svchost.exe
H:\PROGRA~1\SPYWAR~1\swdoctor.exe
H:\WINDOWS\system32\wscntfy.exe
H:\WINDOWS\system32\wuauclt.exe
H:\WINDOWS\explorer.exe
H:\Program Files\Internet Explorer\IEXPLORE.EXE
H:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://forums.whatthetech.com/forums.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - H:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - H:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - H:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - H:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - H:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - H:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE H:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE H:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TkBellExe] "H:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "H:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "H:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "H:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [BM9fe4da89] Rundll32.exe "H:\WINDOWS\system32\slshvewf.dll",s
O4 - HKCU\..\Run: [msnmsgr] "H:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] H:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: NETGEAR WG111v2 Smart Wizard.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://H:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://H:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://H:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://H:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://H:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - H:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - H:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - H:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - H:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: NavLogon - H:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - H:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - H:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - H:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - H:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - H:\Program Files\Java\jre6\bin\jqs.exe" -service -config "H:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - H:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - H:\WINDOWS\system32\PnkBstrA.exe