Here is the log:
ComboFix 09-04-25.A3 - Artur 04/26/2009 1:54.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2039.1326 [GMT -4:00]
Running from: c:\documents and settings\Artur\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090425-0] *On-access scanning disabled* (Updated)
.
((((((((((((((((((((((((( Files Created from 2009-05-26 to 2009-4-26 )))))))))))))))))))))))))))))))
.
2009-04-26 05:44 . 2009-04-26 05:44 118 ----a-w c:\windows\system32\MRT.INI
2009-04-23 20:32 . 2008-10-28 22:03 31280 ----a-r c:\windows\system32\drivers\vmusb.sys
2009-04-23 17:13 . 2009-03-06 14:22 284160 ------w c:\windows\system32\dllcache\pdh.dll
2009-04-23 17:13 . 2009-02-06 10:39 35328 ------w c:\windows\system32\dllcache\sc.exe
2009-04-23 17:13 . 2009-02-09 12:10 401408 ------w c:\windows\system32\dllcache\rpcss.dll
2009-04-23 17:13 . 2009-02-06 11:11 110592 ------w c:\windows\system32\dllcache\services.exe
2009-04-23 17:13 . 2009-02-09 12:10 473600 ------w c:\windows\system32\dllcache\fastprox.dll
2009-04-23 17:13 . 2009-02-06 10:10 227840 ------w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-23 17:13 . 2009-02-09 12:10 453120 ------w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-23 17:13 . 2009-02-09 12:10 729088 ------w c:\windows\system32\dllcache\lsasrv.dll
2009-04-23 17:13 . 2009-02-09 12:10 617472 ------w c:\windows\system32\dllcache\advapi32.dll
2009-04-23 17:13 . 2009-02-09 12:10 714752 ------w c:\windows\system32\dllcache\ntdll.dll
2009-04-23 17:09 . 2008-05-03 11:55 2560 ------w c:\windows\system32\xpsp4res.dll
2009-04-23 17:09 . 2009-03-27 06:58 1203922 ------w c:\windows\system32\dllcache\sysmain.sdb
2009-04-23 17:09 . 2008-04-21 12:08 215552 ------w c:\windows\system32\dllcache\wordpad.exe
2009-04-22 06:03 . 2009-04-22 06:03 -------- d-----w c:\program files\Alwil Software
2009-04-20 22:39 . 2009-04-20 22:39 -------- d-----w c:\documents and settings\Artur\Application Data\Malwarebytes
2009-04-20 22:39 . 2009-04-06 19:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-04-20 22:39 . 2009-04-06 19:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-20 22:39 . 2009-04-20 22:39 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-04-20 22:39 . 2009-04-20 22:39 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-20 01:58 . 2009-04-20 01:58 -------- d-----w c:\program files\Trend Micro
2009-04-10 22:44 . 2009-04-10 22:44 -------- d-----w c:\documents and settings\Artur\Application Data\OfficeUpdate12
2009-04-09 00:37 . 2009-04-09 00:37 -------- d-----w c:\documents and settings\Artur\Local Settings\Application Data\Intuit
2009-04-09 00:36 . 2009-04-09 00:36 -------- d-----w c:\documents and settings\Artur\Application Data\Intuit
2009-04-09 00:36 . 2009-04-09 00:36 -------- d-----w c:\program files\Common Files\AnswerWorks 5.0
2009-04-09 00:32 . 2009-04-09 00:32 -------- d-----w c:\program files\TurboTax
2009-04-03 07:03 . 2009-04-03 07:03 -------- d-sh--w c:\documents and settings\Artur\IECompatCache
2009-04-03 07:02 . 2009-04-03 07:02 -------- d-sh--w c:\documents and settings\Artur\PrivacIE
2009-04-03 07:00 . 2009-04-03 07:00 -------- d-sh--w c:\documents and settings\LocalService\IETldCache
2009-04-03 06:59 . 2009-04-03 06:59 -------- d-sh--w c:\documents and settings\NetworkService\IETldCache
2009-04-03 06:59 . 2009-04-03 06:59 -------- d-sh--w c:\documents and settings\Artur\IETldCache
2009-04-03 06:54 . 2009-04-15 13:07 -------- d-----w c:\windows\ie8updates
2009-04-03 06:47 . 2009-02-20 18:09 78336 ----a-w c:\windows\system32\ieencode.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2009-04-26 05:50 . 2008-09-11 14:43 -------- d-----w c:\documents and settings\Artur\Application Data\Delicious IE Extension
2009-04-26 05:50 . 2008-02-01 19:35 -------- d-----w c:\documents and settings\Artur\Application Data\Skype
2009-04-26 05:49 . 2008-02-01 19:37 -------- d-----w c:\documents and settings\Artur\Application Data\skypePM
2009-04-26 05:48 . 2008-07-26 02:42 22528 ----a-w c:\windows\system32\drivers\nhcDriver.sys
2009-04-26 05:47 . 2008-02-08 19:01 -------- d-----w c:\documents and settings\All Users\Application Data\VMware
2009-04-26 05:47 . 2008-02-08 19:05 -------- d-----w c:\documents and settings\LocalService\Application Data\VMware
2009-04-26 04:56 . 2009-04-26 04:56 17729 ----a-w C:\ComboFix1.txt
2009-04-24 16:03 . 2008-02-08 22:03 -------- d-----w c:\documents and settings\Artur\Application Data\VMware
2009-04-22 05:55 . 2008-02-10 05:49 -------- d-----w c:\program files\Common Files\Symantec Shared
2009-04-22 05:55 . 2007-07-26 05:58 -------- d-----w c:\program files\Symantec
2009-04-22 05:55 . 2007-07-26 05:58 -------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2009-04-22 05:55 . 2008-02-10 05:49 -------- d-----w c:\program files\Symantec AntiVirus
2009-04-21 03:39 . 2008-09-07 00:48 -------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-04-21 03:39 . 2008-09-07 00:47 -------- d-----w c:\program files\SpywareBlaster
2009-04-19 06:48 . 2008-01-31 02:34 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-04-19 06:14 . 2008-01-31 02:34 -------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-04-19 05:36 . 2008-02-04 22:20 -------- d-----w c:\documents and settings\Artur\Application Data\Free Download Manager
2009-04-09 00:36 . 2007-07-26 05:35 68728 ----a-w c:\documents and settings\Artur\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-09 00:34 . 2006-01-03 21:49 -------- d-----w c:\documents and settings\All Users\Application Data\Intuit
2009-04-09 00:34 . 2006-01-03 21:49 -------- d-----w c:\program files\Common Files\Intuit
2009-03-21 14:06 . 2009-03-21 14:06 989696 ------w c:\windows\system32\dllcache\kernel32.dll
2009-03-21 05:28 . 2009-03-21 03:59 -------- d-----w c:\program files\Mikroelektronika
2009-03-21 03:47 . 2009-03-21 03:47 -------- d-----w c:\program files\DIFX
2009-03-16 22:42 . 2009-03-16 22:42 524288 ----a-w c:\windows\opuc.dll
2009-03-11 02:47 . 2009-03-11 02:47 -------- d-----w c:\program files\Microsoft Silverlight
2009-03-06 14:22 . 2004-08-11 23:00 284160 ----a-w c:\windows\system32\pdh.dll
2009-03-06 14:18 . 2009-03-06 14:18 -------- d-----w c:\documents and settings\Artur\Application Data\Apple Computer
2009-03-03 00:18 . 2007-10-11 05:57 826368 ----a-w c:\windows\system32\dllcache\wininet.dll
2009-03-03 00:18 . 2004-08-11 23:00 826368 ----a-w c:\windows\system32\wininet.dll
2009-02-28 04:54 . 2007-08-13 23:43 636072 ----a-w c:\windows\system32\dllcache\iexplore.exe
2009-02-20 10:20 . 2008-01-31 00:16 13824 ------w c:\windows\system32\dllcache\ieudinit.exe
2009-02-20 10:20 . 2007-08-13 23:39 70656 ----a-w c:\windows\system32\dllcache\ie4uinit.exe
2009-02-20 05:14 . 2007-08-13 22:56 161792 ----a-w c:\windows\system32\dllcache\ieakui.dll
2009-02-09 12:10 . 2004-08-11 23:00 729088 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2004-08-11 23:00 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 12:10 . 2004-08-11 23:00 714752 ----a-w c:\windows\system32\ntdll.dll
2009-02-09 12:10 . 2004-08-11 23:00 617472 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 11:13 . 2009-01-25 06:47 1846784 ------w c:\windows\system32\dllcache\win32k.sys
2009-02-09 11:13 . 2004-08-11 23:00 1846784 ----a-w c:\windows\system32\win32k.sys
2009-02-07 23:02 . 2009-01-25 06:46 2066048 ------w c:\windows\system32\dllcache\ntkrnlpa.exe
2009-02-07 23:02 . 2004-08-04 04:59 2066048 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-06 11:11 . 2004-08-11 23:00 110592 ----a-w c:\windows\system32\services.exe
2009-02-06 11:08 . 2009-01-25 06:46 2189056 ------w c:\windows\system32\dllcache\ntoskrnl.exe
2009-02-06 11:08 . 2004-08-11 23:00 2189056 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 11:06 . 2009-01-25 06:46 2145280 ------w c:\windows\system32\dllcache\ntkrnlmp.exe
2009-02-06 10:39 . 2004-08-11 23:00 35328 ----a-w c:\windows\system32\sc.exe
2009-02-06 10:32 . 2009-01-25 06:46 2023936 ------w c:\windows\system32\dllcache\ntkrpamp.exe
2009-02-03 19:59 . 2009-02-03 19:59 56832 ------w c:\windows\system32\dllcache\secur32.dll
2009-02-03 19:59 . 2004-08-11 23:00 56832 ----a-w c:\windows\system32\secur32.dll
2009-01-28 01:42 . 2008-02-08 19:03 1024 ----a-w C:\.rnd
2009-01-16 03:11 . 2009-01-16 03:11 2311 ----a-w c:\documents and settings\All Users\Application Data\xml2A0.tmp
2009-01-16 03:11 . 2009-01-16 03:11 13054 ----a-w c:\documents and settings\All Users\Application Data\xml29F.tmp
2009-01-16 03:11 . 2009-01-16 03:11 16854 ----a-w c:\documents and settings\All Users\Application Data\xml29E.tmp
2008-11-06 03:23 . 2008-11-06 03:23 548047 ----a-w c:\program files\lame3.98-final.zip
2008-02-14 04:37 . 2008-02-14 04:37 128 ----a-w c:\documents and settings\Artur\Local Settings\Application Data\fusioncache.dat
2008-02-01 19:37 . 2008-02-01 19:37 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2008-01-31 01:34 . 2008-01-31 01:34 114856 ----a-w c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-01-06 03:2008-01-31 02:02 16:50 . c:\program files\mozilla firefox\components\jar50.dll
2009-01-06 03:2008-01-31 02:02 16:50 . c:\program files\mozilla firefox\components\jsd3250.dll
2009-01-06 03:2008-01-31 02:02 16:50 . c:\program files\mozilla firefox\components\myspell.dll
2009-01-06 03:2008-01-31 02:02 16:50 . c:\program files\mozilla firefox\components\spellchk.dll
2009-01-06 03:2008-01-31 02:02 16:50 . c:\program files\mozilla firefox\components\xpinstal.dll
2008-07-25 19:33 . 2008-07-25 19:33 32768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008072520080 726\index.dat
.
((((((((((((((((((((((((((((( SnapShot@2009-04-26_04.54.17 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-26 05:47 . 2009-04-26 05:47 16384 c:\windows\Temp\Perflib_Perfdata_bc8.dat
+ 2009-04-26 05:47 . 2009-04-26 05:47 16384 c:\windows\Temp\Perflib_Perfdata_2d8.dat
+ 2004-08-11 23:00 . 2009-02-20 18:09 44544 c:\windows\system32\pngfilt.dll
- 2004-08-11 23:00 . 2008-10-16 20:38 44544 c:\windows\system32\pngfilt.dll
- 2004-08-11 23:11 . 2008-04-14 09:42 91648 c:\windows\system32\mtxoci.dll
+ 2004-08-11 23:11 . 2008-06-12 14:23 91648 c:\windows\system32\mtxoci.dll
- 2004-08-11 23:00 . 2008-04-14 09:42 66560 c:\windows\system32\mtxclu.dll
+ 2004-08-11 23:00 . 2008-06-12 14:23 66560 c:\windows\system32\mtxclu.dll
- 2007-08-13 23:54 . 2008-10-16 20:38 52224 c:\windows\system32\msfeedsbs.dll
+ 2007-08-13 23:54 . 2009-02-20 18:09 52224 c:\windows\system32\msfeedsbs.dll
- 2004-08-11 23:11 . 2008-04-14 09:42 58880 c:\windows\system32\msdtclog.dll
+ 2004-08-11 23:11 . 2008-06-12 14:23 58880 c:\windows\system32\msdtclog.dll
- 2004-08-11 23:00 . 2008-10-16 20:38 27648 c:\windows\system32\jsproxy.dll
+ 2004-08-11 23:00 . 2009-02-20 18:09 27648 c:\windows\system32\jsproxy.dll
- 2004-08-11 23:00 . 2008-10-16 20:38 44544 c:\windows\system32\iernonce.dll
+ 2004-08-11 23:00 . 2009-02-20 18:09 44544 c:\windows\system32\iernonce.dll
+ 2004-08-11 23:00 . 2009-02-20 10:20 70656 c:\windows\system32\ie4uinit.exe
- 2004-08-11 23:00 . 2008-10-16 13:11 70656 c:\windows\system32\ie4uinit.exe
+ 2007-08-13 23:36 . 2009-02-20 18:09 63488 c:\windows\system32\icardie.dll
- 2007-08-13 23:36 . 2008-10-16 20:38 63488 c:\windows\system32\icardie.dll
+ 2007-10-11 05:57 . 2009-02-20 18:09 44544 c:\windows\system32\dllcache\pngfilt.dll
- 2007-10-11 05:57 . 2008-10-16 20:38 44544 c:\windows\system32\dllcache\pngfilt.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 91648 c:\windows\system32\dllcache\mtxoci.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 66560 c:\windows\system32\dllcache\mtxclu.dll
- 2008-01-31 00:16 . 2008-10-16 20:38 52224 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2008-01-31 00:16 . 2009-02-20 18:09 52224 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 58880 c:\windows\system32\dllcache\msdtclog.dll
+ 2007-10-11 05:57 . 2009-02-20 18:09 27648 c:\windows\system32\dllcache\jsproxy.dll
- 2007-10-11 05:57 . 2008-10-16 20:38 27648 c:\windows\system32\dllcache\jsproxy.dll
- 2007-08-13 23:39 . 2008-10-16 20:38 44544 c:\windows\system32\dllcache\iernonce.dll
+ 2007-08-13 23:39 . 2009-02-20 18:09 44544 c:\windows\system32\dllcache\iernonce.dll
+ 2009-02-20 18:09 . 2009-02-20 18:09 78336 c:\windows\system32\dllcache\ieencode.dll
+ 2008-01-31 00:16 . 2009-02-20 18:09 63488 c:\windows\system32\dllcache\icardie.dll
- 2008-01-31 00:16 . 2008-10-16 20:38 63488 c:\windows\system32\dllcache\icardie.dll
- 2007-07-26 05:15 . 2009-04-25 03:38 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-07-26 05:15 . 2009-04-26 05:46 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2007-07-26 05:15 . 2009-04-25 03:38 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-07-26 05:15 . 2009-04-26 05:46 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-07-26 05:15 . 2009-04-25 03:38 16384 c:\windows\system32\config\systemprofile\Cookies\i ndex.dat
+ 2007-07-26 05:15 . 2009-04-26 05:46 16384 c:\windows\system32\config\systemprofile\Cookies\i ndex.dat
+ 2007-07-26 05:14 . 2009-04-26 05:45 23040 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2007-07-26 05:14 . 2009-01-25 07:10 23040 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2007-07-26 05:14 . 2009-04-26 05:45 61440 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2007-07-26 05:14 . 2009-01-25 07:10 61440 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2007-07-26 05:14 . 2009-04-26 05:45 27136 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2007-07-26 05:14 . 2009-01-25 07:10 27136 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2007-07-26 05:14 . 2009-01-25 07:10 11264 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2007-07-26 05:14 . 2009-04-26 05:45 11264 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2007-07-26 05:14 . 2009-04-26 05:45 86016 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2007-07-26 05:14 . 2009-01-25 07:10 86016 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2007-07-26 05:14 . 2009-01-25 07:10 12288 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2007-07-26 05:14 . 2009-04-26 05:45 12288 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2009-04-26 05:44 . 2008-10-16 20:38 44544 c:\windows\ie7updates\KB963027-IE7\pngfilt.dll
+ 2009-04-26 05:44 . 2008-10-16 20:38 52224 c:\windows\ie7updates\KB963027-IE7\msfeedsbs.dll
+ 2009-04-26 05:44 . 2008-10-16 20:38 27648 c:\windows\ie7updates\KB963027-IE7\jsproxy.dll
+ 2009-04-26 05:44 . 2008-10-16 13:11 13824 c:\windows\ie7updates\KB963027-IE7\ieudinit.exe
+ 2009-04-26 05:44 . 2008-10-16 20:38 44544 c:\windows\ie7updates\KB963027-IE7\iernonce.dll
+ 2009-04-26 05:44 . 2008-04-14 09:41 81920 c:\windows\ie7updates\KB963027-IE7\ieencode.dll
+ 2009-04-26 05:44 . 2008-10-16 13:11 70656 c:\windows\ie7updates\KB963027-IE7\ie4uinit.exe
+ 2009-04-26 05:44 . 2008-10-16 20:38 63488 c:\windows\ie7updates\KB963027-IE7\icardie.dll
+ 2009-04-25 14:46 . 2009-04-26 05:45 9668 c:\windows\SoftwareDistribution\EventCache\{37051B 2F-DED5-4325-BFC9-EE38E569CD68}.bin
+ 2007-07-26 05:14 . 2009-04-26 05:45 4096 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2007-07-26 05:14 . 2009-01-25 07:10 4096 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2004-08-11 23:00 . 2008-12-16 12:30 354304 c:\windows\system32\winhttp.dll
- 2004-08-11 23:00 . 2008-04-14 09:42 354304 c:\windows\system32\winhttp.dll
- 2004-08-11 23:00 . 2008-10-16 20:38 233472 c:\windows\system32\webcheck.dll
+ 2004-08-11 23:00 . 2009-02-20 18:09 233472 c:\windows\system32\webcheck.dll
+ 2004-08-11 23:11 . 2009-02-06 10:10 227840 c:\windows\system32\wbem\wmiprvse.exe
+ 2004-08-11 23:11 . 2009-02-09 12:10 453120 c:\windows\system32\wbem\wmiprvsd.dll
+ 2004-08-11 23:11 . 2009-02-09 12:10 473600 c:\windows\system32\wbem\fastprox.dll
- 2004-08-11 23:00 . 2008-10-16 20:38 105984 c:\windows\system32\url.dll
+ 2004-08-11 23:00 . 2009-02-20 18:09 105984 c:\windows\system32\url.dll
+ 2004-08-11 23:00 . 2008-12-05 06:54 144896 c:\windows\system32\schannel.dll
+ 2004-08-11 23:00 . 2009-04-26 05:52 576510 c:\windows\system32\perfh009.dat
- 2004-08-11 23:00 . 2009-04-03 07:01 576510 c:\windows\system32\perfh009.dat
+ 2004-08-11 23:00 . 2009-04-26 05:52 116502 c:\windows\system32\perfc009.dat
- 2004-08-11 23:00 . 2009-04-03 07:01 116502 c:\windows\system32\perfc009.dat
+ 2004-08-11 23:00 . 2009-02-20 18:09 102912 c:\windows\system32\occache.dll
- 2004-08-11 23:00 . 2008-10-16 20:38 102912 c:\windows\system32\occache.dll
- 2004-08-11 23:00 . 2008-10-16 20:38 671232 c:\windows\system32\mstime.dll
+ 2004-08-11 23:00 . 2009-02-20 18:09 671232 c:\windows\system32\mstime.dll
- 2004-08-11 23:00 . 2008-10-16 20:38 193024 c:\windows\system32\msrating.dll
+ 2004-08-11 23:00 . 2009-02-20 18:09 193024 c:\windows\system32\msrating.dll
+ 2004-08-11 23:00 . 2009-02-20 18:09 477696 c:\windows\system32\mshtmled.dll
- 2004-08-11 23:00 . 2008-10-16 20:38 477696 c:\windows\system32\mshtmled.dll
+ 2007-08-13 23:54 . 2009-02-20 18:09 459264 c:\windows\system32\msfeeds.dll
- 2007-08-13 23:54 . 2008-10-16 20:38 459264 c:\windows\system32\msfeeds.dll
- 2004-08-11 23:11 . 2008-04-14 09:42 161792 c:\windows\system32\msdtcuiu.dll
+ 2004-08-11 23:11 . 2008-06-12 14:23 161792 c:\windows\system32\msdtcuiu.dll
+ 2004-08-11 23:11 . 2008-06-12 14:23 956928 c:\windows\system32\msdtctm.dll
- 2004-08-11 23:11 . 2008-04-14 09:42 956928 c:\windows\system32\msdtctm.dll
+ 2004-08-11 23:11 . 2008-06-12 14:23 428032 c:\windows\system32\msdtcprx.dll
+ 2004-08-11 23:00 . 2009-03-21 14:06 989696 c:\windows\system32\kernel32.dll
- 2004-08-11 23:00 . 2008-04-14 09:41 989696 c:\windows\system32\kernel32.dll
+ 2008-01-31 21:59 . 2009-04-26 05:47 247856 c:\windows\system32\inetsrv\MetaBase.bin
+ 2007-08-13 23:34 . 2009-02-20 18:09 268288 c:\windows\system32\iertutil.dll
+ 2004-08-11 23:00 . 2009-02-20 18:09 385024 c:\windows\system32\iedkcs32.dll
+ 2007-07-11 17:27 . 2009-02-20 18:09 383488 c:\windows\system32\ieapfltr.dll
- 2007-07-11 17:27 . 2008-10-16 20:38 383488 c:\windows\system32\ieapfltr.dll
+ 2004-08-11 23:00 . 2009-02-20 05:14 161792 c:\windows\system32\ieakui.dll
- 2004-08-11 23:00 . 2008-10-15 07:04 161792 c:\windows\system32\ieakui.dll
- 2004-08-11 23:00 . 2008-10-16 20:38 230400 c:\windows\system32\ieaksie.dll
+ 2004-08-11 23:00 . 2009-02-20 18:09 230400 c:\windows\system32\ieaksie.dll
+ 2004-08-11 23:00 . 2009-02-20 18:09 153088 c:\windows\system32\ieakeng.dll
- 2004-08-11 23:00 . 2008-10-16 20:38 153088 c:\windows\system32\ieakeng.dll
- 2004-08-11 23:06 . 2009-04-12 22:57 255864 c:\windows\system32\FNTCACHE.DAT
+ 2004-08-11 23:06 . 2009-04-26 05:46 255864 c:\windows\system32\FNTCACHE.DAT
+ 2004-08-11 23:00 . 2009-02-20 18:09 133120 c:\windows\system32\extmgr.dll
- 2004-08-11 23:00 . 2008-10-16 20:38 133120 c:\windows\system32\extmgr.dll
+ 2004-08-11 23:00 . 2009-02-20 18:09 214528 c:\windows\system32\dxtrans.dll
- 2004-08-11 23:00 . 2008-10-16 20:38 214528 c:\windows\system32\dxtrans.dll
- 2004-08-11 23:00 . 2008-10-16 20:38 347136 c:\windows\system32\dxtmsft.dll
+ 2004-08-11 23:00 . 2009-02-20 18:09 347136 c:\windows\system32\dxtmsft.dll
+ 2008-12-16 12:30 . 2008-12-16 12:30 354304 c:\windows\system32\dllcache\winhttp.dll
+ 2007-08-13 23:54 . 2009-02-20 18:09 233472 c:\windows\system32\dllcache\webcheck.dll
- 2007-08-13 23:54 . 2008-10-16 20:38 233472 c:\windows\system32\dllcache\webcheck.dll
+ 2007-08-13 23:44 . 2009-02-20 18:09 105984 c:\windows\system32\dllcache\url.dll
- 2007-08-13 23:44 . 2008-10-16 20:38 105984 c:\windows\system32\dllcache\url.dll
+ 2008-12-05 06:54 . 2008-12-05 06:54 144896 c:\windows\system32\dllcache\schannel.dll
+ 2007-08-13 23:44 . 2009-02-20 18:09 102912 c:\windows\system32\dllcache\occache.dll
- 2007-08-13 23:44 . 2008-10-16 20:38 102912 c:\windows\system32\dllcache\occache.dll
+ 2007-10-11 05:57 . 2009-02-20 18:09 671232 c:\windows\system32\dllcache\mstime.dll
- 2007-10-11 05:57 . 2008-10-16 20:38 671232 c:\windows\system32\dllcache\mstime.dll
- 2007-10-11 05:57 . 2008-10-16 20:38 193024 c:\windows\system32\dllcache\msrating.dll
+ 2007-10-11 05:57 . 2009-02-20 18:09 193024 c:\windows\system32\dllcache\msrating.dll
- 2007-10-11 05:57 . 2008-10-16 20:38 477696 c:\windows\system32\dllcache\mshtmled.dll
+ 2007-10-11 05:57 . 2009-02-20 18:09 477696 c:\windows\system32\dllcache\mshtmled.dll
- 2008-01-31 00:16 . 2008-10-16 20:38 459264 c:\windows\system32\dllcache\msfeeds.dll
+ 2008-01-31 00:16 . 2009-02-20 18:09 459264 c:\windows\system32\dllcache\msfeeds.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 161792 c:\windows\system32\dllcache\msdtcuiu.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 956928 c:\windows\system32\dllcache\msdtctm.dll
+ 2008-06-12 14:23 . 2008-06-12 14:23 428032 c:\windows\system32\dllcache\msdtcprx.dll
+ 2008-01-31 00:16 . 2009-02-20 18:09 268288 c:\windows\system32\dllcache\iertutil.dll
+ 2007-08-13 23:39 . 2009-02-20 18:09 385024 c:\windows\system32\dllcache\iedkcs32.dll
- 2008-01-31 00:16 . 2008-10-16 20:38 383488 c:\windows\system32\dllcache\ieapfltr.dll
+ 2008-01-31 00:16 . 2009-02-20 18:09 383488 c:\windows\system32\dllcache\ieapfltr.dll
+ 2007-08-13 23:39 . 2009-02-20 18:09 230400 c:\windows\system32\dllcache\ieaksie.dll
- 2007-08-13 23:39 . 2008-10-16 20:38 230400 c:\windows\system32\dllcache\ieaksie.dll
- 2007-08-13 23:39 . 2008-10-16 20:38 153088 c:\windows\system32\dllcache\ieakeng.dll
+ 2007-08-13 23:39 . 2009-02-20 18:09 153088 c:\windows\system32\dllcache\ieakeng.dll
+ 2007-10-11 05:57 . 2009-02-20 18:09 133120 c:\windows\system32\dllcache\extmgr.dll
- 2007-10-11 05:57 . 2008-10-16 20:38 133120 c:\windows\system32\dllcache\extmgr.dll
+ 2007-10-11 05:57 . 2009-02-20 18:09 214528 c:\windows\system32\dllcache\dxtrans.dll
- 2007-10-11 05:57 . 2008-10-16 20:38 214528 c:\windows\system32\dllcache\dxtrans.dll
+ 2007-10-11 05:57 . 2009-02-20 18:09 347136 c:\windows\system32\dllcache\dxtmsft.dll
- 2007-10-11 05:57 . 2008-10-16 20:38 347136 c:\windows\system32\dllcache\dxtmsft.dll
+ 2007-08-13 23:39 . 2009-02-20 18:09 124928 c:\windows\system32\dllcache\advpack.dll
- 2007-08-13 23:39 . 2008-10-16 20:38 124928 c:\windows\system32\dllcache\advpack.dll
+ 2004-08-11 23:00 . 2009-02-20 18:09 124928 c:\windows\system32\advpack.dll
- 2004-08-11 23:00 . 2008-10-16 20:38 124928 c:\windows\system32\advpack.dll
- 2007-07-26 05:14 . 2009-01-25 07:10 409600 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2007-07-26 05:14 . 2009-04-26 05:45 409600 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2007-07-26 05:14 . 2009-04-26 05:45 286720 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2007-07-26 05:14 . 2009-01-25 07:10 286720 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2007-07-26 05:14 . 2009-04-26 05:45 249856 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2007-07-26 05:14 . 2009-01-25 07:10 249856 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2007-07-26 05:14 . 2009-01-25 07:10 794624 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2007-07-26 05:14 . 2009-04-26 05:45 794624 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2007-07-26 05:14 . 2009-01-25 07:10 135168 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2007-07-26 05:14 . 2009-04-26 05:45 135168 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2007-07-26 05:14 . 2009-01-25 07:10 593920 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2007-07-26 05:14 . 2009-04-26 05:45 593920 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2009-04-26 05:44 . 2008-10-16 20:38 826368 c:\windows\ie7updates\KB963027-IE7\wininet.dll
+ 2009-04-26 05:44 . 2008-10-16 20:38 233472 c:\windows\ie7updates\KB963027-IE7\webcheck.dll
+ 2009-04-26 05:44 . 2008-10-16 20:38 105984 c:\windows\ie7updates\KB963027-IE7\url.dll
+ 2009-04-26 05:44 . 2008-07-09 07:38 382840 c:\windows\ie7updates\KB963027-IE7\spuninst\updspapi.dll
+ 2009-04-26 05:44 . 2008-07-08 13:02 231288 c:\windows\ie7updates\KB963027-IE7\spuninst\spuninst.exe
+ 2009-04-26 05:44 . 2008-10-16 20:38 102912 c:\windows\ie7updates\KB963027-IE7\occache.dll
+ 2009-04-26 05:44 . 2008-10-16 20:38 671232 c:\windows\ie7updates\KB963027-IE7\mstime.dll
+ 2009-04-26 05:44 . 2008-10-16 20:38 193024 c:\windows\ie7updates\KB963027-IE7\msrating.dll
+ 2009-04-26 05:44 . 2008-10-16 20:38 477696 c:\windows\ie7updates\KB963027-IE7\mshtmled.dll
+ 2009-04-26 05:44 . 2008-10-16 20:38 459264 c:\windows\ie7updates\KB963027-IE7\msfeeds.dll
+ 2009-04-26 05:44 . 2008-10-15 07:06 633632 c:\windows\ie7updates\KB963027-IE7\iexplore.exe
+ 2009-04-26 05:44 . 2008-10-16 20:38 267776 c:\windows\ie7updates\KB963027-IE7\iertutil.dll
+ 2009-04-26 05:44 . 2008-10-16 20:38 384512 c:\windows\ie7updates\KB963027-IE7\iedkcs32.dll
+ 2009-04-26 05:44 . 2008-10-16 20:38 383488 c:\windows\ie7updates\KB963027-IE7\ieapfltr.dll
+ 2009-04-26 05:44 . 2008-10-15 07:04 161792 c:\windows\ie7updates\KB963027-IE7\ieakui.dll
+ 2009-04-26 05:44 . 2008-10-16 20:38 230400 c:\windows\ie7updates\KB963027-IE7\ieaksie.dll
+ 2009-04-26 05:44 . 2008-10-16 20:38 153088 c:\windows\ie7updates\KB963027-IE7\ieakeng.dll
+ 2009-04-26 05:44 . 2008-10-16 20:38 133120 c:\windows\ie7updates\KB963027-IE7\extmgr.dll
+ 2009-04-26 05:44 . 2008-10-16 20:38 214528 c:\windows\ie7updates\KB963027-IE7\dxtrans.dll
+ 2009-04-26 05:44 . 2008-10-16 20:38 347136 c:\windows\ie7updates\KB963027-IE7\dxtmsft.dll
+ 2009-04-26 05:44 . 2008-10-16 20:38 124928 c:\windows\ie7updates\KB963027-IE7\advpack.dll
- 2004-08-11 23:00 . 2008-10-16 20:38 1160192 c:\windows\system32\urlmon.dll
+ 2004-08-11 23:00 . 2009-02-20 18:09 1160192 c:\windows\system32\urlmon.dll
+ 2004-08-11 23:00 . 2008-06-17 19:02 8461312 c:\windows\system32\shell32.dll
- 2004-08-11 23:00 . 2008-04-14 09:42 8461312 c:\windows\system32\shell32.dll
+ 2004-08-11 23:00 . 2008-12-20 22:14 1288192 c:\windows\system32\quartz.dll
- 2004-08-11 23:00 . 2008-05-07 05:12 1288192 c:\windows\system32\quartz.dll
+ 2004-08-11 23:00 . 2009-02-20 18:09 3595264 c:\windows\system32\mshtml.dll
- 2007-08-13 23:54 . 2008-10-16 20:38 6066176 c:\windows\system32\ieframe.dll
+ 2007-08-13 23:54 . 2009-02-20 18:09 6066176 c:\windows\system32\ieframe.dll
- 2007-02-12 21:10 . 2007-07-01 03:31 2455488 c:\windows\system32\ieapfltr.dat
+ 2007-02-12 21:10 . 2008-07-09 14:25 2455488 c:\windows\system32\ieapfltr.dat
+ 2007-10-11 05:57 . 2009-02-20 18:09 1160192 c:\windows\system32\dllcache\urlmon.dll
- 2007-10-11 05:57 . 2008-10-16 20:38 1160192 c:\windows\system32\dllcache\urlmon.dll
+ 2008-06-17 19:02 . 2008-06-17 19:02 8461312 c:\windows\system32\dllcache\shell32.dll
+ 2008-05-07 05:12 . 2008-12-20 22:14 1288192 c:\windows\system32\dllcache\quartz.dll
- 2008-05-07 05:12 . 2008-05-07 05:12 1288192 c:\windows\system32\dllcache\quartz.dll
+ 2007-10-30 09:55 . 2009-02-20 18:09 3595264 c:\windows\system32\dllcache\mshtml.dll
+ 2008-01-31 00:16 . 2009-02-20 18:09 6066176 c:\windows\system32\dllcache\ieframe.dll
- 2008-01-31 00:16 . 2008-10-16 20:38 6066176 c:\windows\system32\dllcache\ieframe.dll
+ 2008-01-31 00:16 . 2008-07-09 14:25 2455488 c:\windows\system32\dllcache\ieapfltr.dat
- 2008-01-31 00:16 . 2007-07-01 03:31 2455488 c:\windows\system32\dllcache\ieapfltr.dat
+ 2009-04-26 05:44 . 2008-10-16 20:38 1160192 c:\windows\ie7updates\KB963027-IE7\urlmon.dll
+ 2009-04-26 05:44 . 2008-12-13 06:40 3593216 c:\windows\ie7updates\KB963027-IE7\mshtml.dll
+ 2009-04-26 05:44 . 2008-10-16 20:38 6066176 c:\windows\ie7updates\KB963027-IE7\ieframe.dll
+ 2009-04-26 05:44 . 2007-07-01 03:31 2455488 c:\windows\ie7updates\KB963027-IE7\ieapfltr.dat
+ 2009-01-25 06:46 . 2009-02-06 11:08 2189056 c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2009-01-25 06:46 . 2009-02-06 10:32 2023936 c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2009-01-25 06:46 . 2008-08-14 09:33 2023936 c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2009-01-25 06:46 . 2009-02-07 23:02 2066048 c:\windows\Driver Cache\i386\ntkrnlpa.exe
- 2009-01-25 06:46 . 2008-08-14 09:33 2066048 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2009-01-25 06:46 . 2009-02-06 11:06 2145280 c:\windows\Driver Cache\i386\ntkrnlmp.exe
- 2009-01-25 06:46 . 2008-08-14 10:09 2145280 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2008-01-31 00:12 . 2009-04-06 14:57 24921544 c:\windows\system32\MRT.exe
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2008-01-31 144448]
"Communicator"="c:\program files\Microsoft Office Communicator\Communicator.exe" [2007-04-10 3900776]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-07 21633320]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"i8kfangui"="c:\program files\I8kfanGUI\I8kfanGUI.exe" [2007-02-16 856064]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-08-08 490952]
"Windows Live Sync"="c:\program files\Windows Live\Sync\WindowsLiveSync.exe" [2008-12-03 1170256]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2004-09-13 155648]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-07-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-07-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-07-20 114688]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2005-09-01 684032]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-10-08 995328]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-10-08 1101824]
"DMXLauncher"="c:\program files\Roxio\Media Experience\DMXLauncher.exe" [2006-08-14 102400]
"NotebookHardwareControl"="c:\program files\Notebook Hardware Control\nhc.exe" [2007-05-04 2629632]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"VMware hqtray"="c:\program files\VMware\VMware Player\hqtray.exe" [2008-10-29 64048]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp. exe" [2009-02-05 81000]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"Communicator"="c:\program files\Microsoft Office Communicator\Communicator.exe" [2007-04-10 3900776]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1 \DW\dwtrig20.exe" [2007-03-23 39264]
c:\documents and settings\Artur\Start Menu\Programs\Startup\
SQL2005 Service Manager.lnk - c:\documents and settings\Artur\Application Data\Microsoft\Installer\{95083577-9097-4051-A45A-D146C9F21070}\_6196AB78D314038F11DAE1.exe [2008-2-4 318]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-5-24 622653]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\NavLogon]
[BU]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office Communicator\\communicator.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\WINDOWS\\system32\\ftp.exe"=
"c:\\Program Files\\Microsoft Virtual PC\\Virtual PC.exe"=
"c:\\Program Files\\Nortel\\Nortel VPN Client\\Extranet.exe"=
"c:\\Program Files\\Free Download Manager\\fdm.exe"=
"c:\\Program Files\\Tftpd32\\tftpd32.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Delicious Add-on for Internet Explorer\\DeliciousManager.exe"=
"c:\\Program Files\\ASUS\\WL-500W Wireless Router Utilities\\Download.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XII.SP1\\Win32\\RpcDataSrv.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XII.SP1\\RpcSandraSrv.exe"=
"c:\\Program Files\\VMware\\VMware Player\\vmware-authd.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R3 ICAM3NT5;Intel USB Video Camera III;c:\windows\system32\Drivers\Icam3.sys [2001-08-17 141056]
R3 IPSECEXT;Nortel Extranet Access Protocol;c:\windows\system32\DRIVERS\ipsecw2k.sys [2007-09-13 157648]
R3 USB18PRG;mikroElektronika USB18F Device (x86 Platform);c:\windows\system32\Drivers\USB18PRG.sys [2007-07-16 39424]
R4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2006-12-02 2805000]
S1 aswSP;avast! Self Protection; [x]
S1 fanio;FanIO driver;c:\windows\system32\drivers\fanio.sys [2007-02-16 14464]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswF sBlk.sys [2009-02-05 20560]
S2 IntuitUpdateService;Intuit Update Service;c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [2008-10-10 13088]
S2 vmci;VMware vmci;c:\windows\system32\Drivers\vmci.sys [2008-10-29 54960]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-04 13592]
S3 Eacfilt;Eacfilt Miniport;c:\windows\system32\DRIVERS\eacfilt.sys [2007-09-13 26137]
.
Contents of the 'Scheduled Tasks' folder
2009-04-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2007-07-26 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-08-11 09:42]
2009-04-26 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.micros oft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Spurl! -
http://www.spurl.net/rclick.php
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Download All by ASUS Download - c:\program files\ASUS\WL-500W Wireless Router Utilities\ASDownloadAll.htm
IE: Download all with Free Download Manager - file://c:\program files\Free Download Manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\program files\Free Download Manager\dlselected.htm
IE: Download using ASUS Download - c:\program files\ASUS\WL-500W Wireless Router Utilities\ASDownload.htm
IE: Download video with Free Download Manager - file://c:\program files\Free Download Manager\dlfvideo.htm
IE: Download with Free Download Manager - file://c:\program files\Free Download Manager\dllink.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
LSP: c:\program files\VMware\VMware Player\vsocklib.dll
Trusted Zone: delicious.com
Trusted Zone: delicious.com\secure
FF - ProfilePath - c:\documents and settings\Artur\Application Data\Mozilla\Firefox\Profiles\wtaa1mwp.default\
FF - component: c:\documents and settings\Artur\Application Data\Mozilla\Firefox\Profiles\wtaa1mwp.default\ext ensions\{22119944-ED35-4ab1-910B-E619EA06A115}\components\rfproxy_19.dll
FF - component: c:\program files\Free Download Manager\Firefox\Extension\components\vmsfdmff.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.
************************************************** ************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-04-26 01:57
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\windows\system32\drivers\ovfsthxdhhwsqug.sys 84992 bytes executable
c:\windows\system32\ovfsthxdstyiwlw.dll 19456 bytes executable
c:\windows\system32\ovfsthxfvfskerl.dll 61952 bytes executable
c:\windows\system32\ovfsthxgkhlotoc.dat 43 bytes
c:\windows\system32\ovfsthxltihsyao.dll 19456 bytes executable
c:\windows\system32\ovfsthxnmxdogqu.dat 1013988 bytes
scan completed successfully
hidden files: 6
************************************************** ************************
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\m sftesql]
"ImagePath"="\"c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe\" -s:MSSQL.1 -f:MSSQLSERVER"
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\o vfsthxajelolom]
"imagepath"="\systemroot\system32\drivers\ovfsthxd hhwsqug.sys"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-3652739634-1881219044-1171626444-1005\Software\Microsoft\SystemCertificates\Address Book*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1672)
c:\windows\system32\netprovcredman.dll
- - - - - - - > 'explorer.exe'(4716)
c:\windows\system32\netprovcredman.dll
.
Completion time: 2009-04-26 2:00
ComboFix-quarantined-files.txt 2009-04-26 05:59
Pre-Run: 26,115,457,024 bytes free
Post-Run: 26,094,989,312 bytes free
Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4
477 --- E O F --- 2009-04-26 05:45