ComboFix 09-06-14.02 - Administrator 06/14/2009 19:54.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1678 [GMT -7:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\gxvxccount
c:\windows\system32\grpconv.exe . . . is missing!!
.
((((((((((((((((((((((((( Files Created from 2009-05-15 to 2009-06-15 )))))))))))))))))))))))))))))))
.
2009-06-21 11:38 . 2002-01-01 11:15 81984 ----a-w- c:\windows\system32\bdod.bin
2009-06-21 11:12 . 2009-06-21 11:12 -------- d-----w- c:\program files\Trend Micro
2009-06-21 10:24 . 2009-03-09 18:34 971776 ----a-w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ajfzlr43.default\ext ensions\moveplayer@movenetworks.com\platform\WINNT _x86-msvc\plugins\npmnqmp071303000006.dll
2009-06-21 10:15 . 2009-06-02 06:35 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\ApplicationHistory
2009-06-21 10:14 . 2009-06-21 10:14 -------- d-----w- c:\program files\MSXML 4.0
2009-06-21 08:45 . 2002-01-01 11:00 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Meebo
2009-06-20 09:31 . 2009-06-20 09:31 -------- d-----w- c:\program files\TightVNC
2009-06-20 09:10 . 2009-06-20 09:10 -------- d-----w- c:\windows\system32\logs
2009-06-20 09:10 . 2009-06-20 09:10 -------- d-----w- C:\Binaries
2009-06-20 09:10 . 2009-06-20 09:10 -------- d-----w- c:\program files\BitDefender
2009-06-20 09:08 . 2009-06-20 09:08 -------- d-----w- c:\windows\system32\URTTEMP
2009-06-20 08:45 . 2009-06-14 14:36 -------- d-----w- c:\documents and settings\Administrator\Application Data\BitTorrent
2009-06-20 08:45 . 2009-06-20 08:45 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\DNA
2009-06-20 08:45 . 2009-06-20 09:13 -------- d-----w- c:\program files\DNA
2009-06-20 08:45 . 2009-06-05 02:54 -------- d-----w- c:\documents and settings\Administrator\Application Data\DNA
2009-06-20 08:45 . 2009-06-20 08:45 -------- d-----w- c:\program files\BitTorrent
2009-06-20 08:39 . 2009-06-05 02:04 -------- d-----w- c:\program files\Vuze
2009-06-14 14:00 . 2009-06-14 14:20 -------- d-----w- c:\documents and settings\Administrator\Application Data\FrostWire
2009-06-14 13:59 . 2009-06-14 14:00 -------- d-----w- c:\program files\FrostWire
2009-06-13 10:02 . 2009-06-13 10:02 -------- d-----w- c:\documents and settings\Administrator\Application Data\Macrovision
2009-06-13 09:57 . 2009-06-13 09:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Strands
2009-06-13 09:57 . 2009-06-13 09:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Macrovision
2009-06-13 09:39 . 2008-03-21 20:57 14640 ------w- c:\windows\system32\spmsgXP_2k3.dll
2009-06-13 09:38 . 2009-06-13 09:38 -------- d-----w- c:\documents and settings\Administrator\Application Data\Nokia
2009-06-13 09:38 . 2009-06-13 09:40 -------- d-----w- c:\documents and settings\Administrator\Application Data\PC Suite
2009-06-13 09:38 . 2009-06-13 09:39 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite
2009-06-13 09:35 . 2009-06-13 09:29 33731296 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Nokia_PC_Suite_7_1_26_0_eng_us_web.e xe
2009-06-13 09:34 . 2009-06-13 09:34 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\Uninst CCD.exe
2009-06-13 09:34 . 2009-06-13 09:34 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\Uninst PCSFEMsi.exe
2009-06-13 09:34 . 2009-06-13 09:34 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\Uninst PCS.exe
2009-06-13 09:34 . 2009-06-13 09:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2009-06-13 09:29 . 2009-06-13 09:29 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\MyStrands_Winamp
2009-06-13 09:29 . 2009-06-14 14:05 -------- d-----w- c:\program files\MyStrands
2009-06-12 00:17 . 2009-06-12 00:17 -------- d-----w- c:\program files\CCleaner
2009-06-05 03:39 . 2009-06-05 03:39 -------- d-----w- c:\program files\Engelmann Media
2009-06-05 03:12 . 2009-06-05 03:12 -------- d-----w- c:\documents and settings\Administrator\ErrorLogs
2009-06-05 03:01 . 2008-10-26 04:55 2567159 -c--a-w- c:\documents and settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}\Uniblue RegistryBooster.exe
2009-06-05 03:00 . 2008-08-26 16:48 497496 -c--a-w- c:\documents and settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}\registrybooster2\AF01B0B\6383BC9B\Xc eedZip.dll
2009-06-05 03:00 . 2008-08-26 16:48 413696 -c--a-w- c:\documents and settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}\registrybooster2\52CD59C9\6383BC9B\u pdate.dll
2009-06-05 03:00 . 2008-08-26 16:48 99624 -c--a-w- c:\documents and settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}\registrybooster2\7390E4F0\6383BC9B\S tartRegistryBooster.exe
2009-06-05 03:00 . 2008-08-26 16:48 757760 -c--a-w- c:\documents and settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}\registrybooster2\2B86F085\6383BC9B\U BVarRB.dll
2009-06-05 03:00 . 2008-08-26 16:48 6676480 -c--a-w- c:\documents and settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}\registrybooster2\4E45A1A4\6383BC9B\R egistryBooster.dll
2009-06-05 03:00 . 2008-08-26 16:48 2019624 -c--a-w- c:\documents and settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}\registrybooster2\7CE1607E\6383BC9B\R egistryBooster.exe
2009-06-05 03:00 . 2008-08-26 16:48 111912 -c--a-w- c:\documents and settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}\registrybooster2\65B92A91\6383BC9B\K illRBProcess.exe
2009-06-05 03:00 . 2009-06-05 03:01 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2009-06-05 02:41 . 2009-06-05 03:03 -------- d-----w- c:\documents and settings\Administrator\Application Data\uniblue
2009-06-05 02:37 . 2009-06-05 03:01 -------- d-----w- c:\program files\Uniblue
2009-06-05 01:10 . 2009-06-05 01:10 -------- d-----w- c:\windows\system32\xircom
2009-06-05 01:10 . 2009-06-05 01:10 -------- d-----w- c:\windows\system32\wbem\snmp
2009-06-05 01:10 . 2009-06-05 01:10 -------- d-----w- c:\windows\system32\oobe
2009-06-05 01:10 . 2009-06-05 01:10 -------- d-----w- c:\windows\srchasst
2009-06-05 01:10 . 2009-06-05 01:10 -------- d-----w- c:\windows\msagent
2009-06-05 01:10 . 2009-06-05 01:10 -------- d-----w- c:\program files\microsoft frontpage
2009-06-04 13:17 . 2009-01-13 01:07 2633728 ----a-w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ajfzlr43.default\ext ensions\LogMeInClient@logmein.com\plugins\npRACtrl .dll
2009-06-04 13:17 . 2007-08-06 19:07 8784 ----a-w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ajfzlr43.default\ext ensions\LogMeInClient@logmein.com\plugins\ractrlke yhook.dll
2009-06-04 13:17 . 2007-08-06 19:07 71248 ----a-w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ajfzlr43.default\ext ensions\LogMeInClient@logmein.com\plugins\LMIProxy Helper.exe
2009-06-04 13:17 . 2007-07-18 21:54 245408 ----a-w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ajfzlr43.default\ext ensions\LogMeInClient@logmein.com\plugins\unicows. dll
2009-06-04 12:52 . 2009-06-04 12:53 -------- d-----w- c:\program files\CrossLoop
2009-06-04 06:38 . 2009-03-24 23:08 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-06-04 06:35 . 2009-06-04 06:35 -------- d-----w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-04 06:33 . 2005-08-26 02:18 118784 ----a-w- c:\windows\system32\MSSTDFMT.DLL
2009-06-04 06:13 . 2009-06-04 06:43 -------- d-----w- c:\program files\Sunbelt Software
2009-06-04 03:43 . 2008-10-16 21:06 268648 ----a-w- c:\windows\system32\mucltui.dll
2009-06-02 13:22 . 2009-06-02 13:22 -------- d-----w- c:\documents and settings\Administrator\Application Data\IObit
2009-06-02 13:22 . 2009-06-02 13:22 -------- d-----w- c:\program files\IObit
2009-06-02 09:05 . 2009-06-02 09:05 4846 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{4FD3EFE2-C856-4C55-AF0F-B29C1E2D6A24}\_4ae13d6c.exe
2009-06-02 09:05 . 2009-06-02 09:05 25214 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{4FD3EFE2-C856-4C55-AF0F-B29C1E2D6A24}\_2cd672ae.exe
2009-06-02 09:05 . 2009-06-02 09:05 25214 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{4FD3EFE2-C856-4C55-AF0F-B29C1E2D6A24}\_18be6784.exe
2009-06-02 09:05 . 2009-06-02 09:05 23558 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{4FD3EFE2-C856-4C55-AF0F-B29C1E2D6A24}\_69525f90.exe
2009-06-02 09:05 . 2009-06-02 09:05 23558 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{4FD3EFE2-C856-4C55-AF0F-B29C1E2D6A24}\_294823.exe
2009-06-02 08:45 . 2009-06-02 08:45 -------- d-----w- c:\program files\AdventNet
2009-06-01 06:38 . 2009-06-01 06:53 -------- d-----w- c:\program files\Hero Designer
2009-06-01 00:29 . 2009-06-01 00:32 -------- d-----w- C:\DeusEx
2009-05-29 11:09 . 2009-06-12 00:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-05-28 23:38 . 2009-05-28 23:59 -------- d-----w- C:\OUTPUT.tmp
2009-05-25 00:26 . 2009-05-26 12:59 -------- d-----w- C:\DOS
2009-05-24 00:11 . 2009-05-24 00:11 -------- d-----w- C:\MBAUTIL
2009-05-23 22:14 . 2009-05-23 22:14 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-05-23 21:58 . 2009-05-23 21:58 -------- d-----w- c:\windows\ie8updates
2009-05-23 21:57 . 2009-05-23 21:57 -------- d-----w- c:\program files\Microsoft Silverlight
2009-05-23 21:57 . 2009-05-23 21:57 -------- d-----w- c:\program files\Windows Desktop Search
2009-05-23 21:56 . 2008-03-07 17:02 98304 ------w- c:\windows\system32\dllcache\nlhtml.dll
2009-05-23 21:56 . 2008-03-07 17:02 29696 ------w- c:\windows\system32\dllcache\mimefilt.dll
2009-05-23 21:56 . 2008-03-07 17:02 192000 ------w- c:\windows\system32\dllcache\offfilt.dll
2009-05-23 21:56 . 2009-04-25 05:30 102400 ------w- c:\windows\system32\dllcache\iecompat.dll
2009-05-23 10:40 . 2009-05-23 10:40 766 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{D48511FA-71C5-4059-88D0-B99AA08AA798}\NewIcon1.exe
2009-05-23 10:40 . 2009-05-23 10:40 65536 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{D48511FA-71C5-4059-88D0-B99AA08AA798}\NewIcon2.exe
2009-05-23 10:40 . 2009-05-23 10:40 25214 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{D48511FA-71C5-4059-88D0-B99AA08AA798}\NewIcon.exe
2009-05-23 10:40 . 2009-05-23 10:40 -------- d-----w- c:\program files\DVD_Generator
2009-05-23 08:30 . 2009-05-23 08:30 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-05-23 08:30 . 2009-05-23 08:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-22 06:55 . 2009-05-22 06:55 -------- d--h--w- c:\windows\system32\GroupPolicy
2009-05-22 06:00 . 2009-05-22 06:00 167376 ----a-w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ajfzlr43.default\Fla shGot.exe
2009-05-22 00:32 . 2005-10-16 15:00 12928 ----a-w- c:\windows\system32\drivers\filedisk.sys
2009-05-22 00:31 . 2009-05-22 00:31 -------- d-----w- c:\program files\WinImage
2009-05-21 22:44 . 2009-05-21 22:44 136 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\fusioncache.dat
2009-05-18 04:18 . 2009-06-21 10:27 -------- d-----w- c:\program files\Unlocker
2009-05-18 04:18 . 2009-05-18 04:18 -------- d-----w- c:\documents and settings\Administrator\Application Data\Desktopicon
2009-05-16 16:38 . 2009-05-16 16:38 -------- d-----w- c:\program files\7-Zip
2009-05-16 14:05 . 2009-05-16 14:05 118784 ----a-w- c:\windows\system32\sgcncaj0e373.dll
2009-05-16 14:05 . 2009-05-16 14:05 33280 ----a-w- c:\windows\system32\emsbqij.exe
2009-05-16 12:39 . 2009-05-16 12:39 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\AOL OCP
2009-05-16 12:39 . 2009-05-16 12:39 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\AOL
2009-05-16 12:39 . 2009-05-18 05:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-05-16 12:39 . 2009-05-16 12:39 -------- d-----w- c:\documents and settings\All Users\Application Data\acccore
2009-05-16 12:38 . 2009-05-16 12:40 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL OCP
2009-05-16 12:38 . 2009-05-16 12:38 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL
2009-05-16 12:36 . 2009-05-16 12:36 -------- d-----w- c:\program files\Common Files\AOL
2009-05-16 12:35 . 2009-05-16 12:39 -------- d-----w- c:\program files\AIM6
2009-05-16 12:27 . 2009-05-16 12:39 -------- d-----w- c:\documents and settings\Administrator\Application Data\acccore
2009-05-16 12:26 . 2009-05-16 12:27 -------- d-----w- c:\documents and settings\Administrator\Application Data\LAIM
2009-05-16 12:26 . 2009-05-16 12:26 -------- d-----w- c:\program files\AIM Lite
2009-05-16 12:13 . 2009-05-16 12:13 15086 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{D21B65C4-F7ED-4805-8781-BB835AC85D14}\_AF6EF1E1D61E94F138937B.exe
2009-05-16 12:13 . 2009-05-16 12:13 15086 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{D21B65C4-F7ED-4805-8781-BB835AC85D14}\_AC451EB93647F071F44C3B.exe
2009-05-16 12:13 . 2009-05-16 12:13 -------- d-----w- c:\program files\Thoosje
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2009-06-21 13:00 . 2009-05-14 07:35 -------- d-----w- c:\documents and settings\Administrator\Application Data\Move Networks
2009-06-21 10:58 . 2008-04-24 01:34 192512 ----a-w- c:\windows\system32\txmlutil.dll
2009-06-14 13:56 . 2009-05-05 09:32 -------- d-----w- c:\documents and settings\Administrator\Application Data\LimeWire
2009-06-14 02:46 . 2009-04-30 03:36 -------- d-----w- c:\program files\City of Heroes
2009-06-13 10:19 . 2009-05-09 06:42 -------- d-----w- c:\documents and settings\Administrator\Application Data\Free Download Manager
2009-06-13 09:42 . 2009-05-09 10:10 -------- d-----w- c:\documents and settings\Administrator\Application Data\Systweak
2009-06-13 09:39 . 2009-06-13 09:39 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_010 07.Wdf
2009-06-13 09:39 . 2009-06-13 09:39 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_C oinstaller_Critical.Wdf
2009-06-13 09:37 . 2009-06-13 09:37 -------- d-----w- c:\program files\Common Files\PCSuite
2009-06-13 09:37 . 2009-06-13 09:37 -------- d-----w- c:\program files\Common Files\Nokia
2009-06-13 09:37 . 2009-06-13 09:36 -------- d-----w- c:\program files\Nokia
2009-06-13 09:36 . 2009-06-13 09:36 -------- d-----w- c:\program files\DIFX
2009-06-13 09:36 . 2009-06-13 09:36 -------- d-----w- c:\program files\PC Connectivity Solution
2009-06-12 00:43 . 2009-05-02 11:48 -------- d-----w- c:\program files\Steam
2009-06-05 02:51 . 2009-06-05 02:49 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}
2009-06-02 08:45 . 2009-04-29 23:45 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-28 09:41 . 2009-05-05 06:34 -------- d-----w- c:\documents and settings\Administrator\Application Data\Azureus
2009-05-26 04:53 . 2009-04-29 23:21 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-05-23 10:31 . 2009-04-29 23:02 8224 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-18 05:23 . 2009-04-29 23:02 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-05-15 10:22 . 2009-05-15 10:22 -------- d-----w- c:\program files\Tftpd32
2009-05-14 12:55 . 2009-05-14 12:53 4506256 ----a-w- c:\documents and settings\Administrator\Application Data\LimeWire\.NetworkShare\LimeWireWin4.16.6.exe
2009-05-12 21:51 . 2009-05-12 21:51 -------- d-----w- c:\documents and settings\Administrator\Application Data\Media Player Classic
2009-05-12 21:51 . 2009-05-12 21:51 -------- d-----w- c:\documents and settings\Administrator\Application Data\DivX
2009-05-12 00:46 . 2009-05-12 00:46 -------- d-----w- c:\documents and settings\Administrator\Application Data\vlc
2009-05-12 00:41 . 2009-05-12 00:41 -------- d-----w- c:\documents and settings\Administrator\Application Data\Apple Computer
2009-05-12 00:41 . 2009-05-12 00:41 -------- d-----w- c:\program files\iTunes
2009-05-12 00:41 . 2009-05-12 00:41 -------- d-----w- c:\documents and settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
2009-05-12 00:41 . 2009-05-12 00:41 -------- d-----w- c:\program files\iPod
2009-05-12 00:41 . 2009-05-12 00:41 -------- d-----w- c:\program files\Bonjour
2009-05-12 00:41 . 2009-05-12 00:41 -------- d-----w- c:\program files\Common Files\Apple
2009-05-12 00:39 . 2009-04-29 23:23 -------- d-----w- c:\program files\QuickTime
2009-05-12 00:39 . 2009-05-01 15:27 -------- d-----w- c:\program files\DivX
2009-05-12 00:38 . 2009-05-01 15:27 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-05-12 00:37 . 2009-05-01 15:31 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-05-12 00:32 . 2009-05-12 00:32 -------- d-----w- c:\program files\Secunia
2009-05-09 10:10 . 2008-04-14 04:42 146432 ----a-w- c:\windows\regedit.exe
2009-05-09 06:52 . 2009-04-29 23:16 -------- d-----w- c:\program files\MultiRes
2009-05-09 06:51 . 2009-05-09 06:51 -------- d-----w- c:\program files\Radeon Omega Drivers
2009-05-09 06:42 . 2009-05-09 06:42 -------- d-----w- c:\program files\Free Download Manager
2009-05-09 06:42 . 2009-05-09 06:42 -------- d-----w- c:\documents and settings\All Users\Application Data\FreeDownloadManager.ORG
2009-05-09 06:39 . 2009-04-30 01:26 -------- d-----w- c:\documents and settings\Administrator\Application Data\GetRight
2009-05-09 04:35 . 2009-05-09 04:35 0 ----a-w- c:\windows\ativpsrm.bin
2009-05-09 03:53 . 2009-04-29 23:01 1887 ----a-w- c:\documents and settings\All Users\Application Data\xml2C.tmp
2009-05-09 03:53 . 2009-04-29 23:01 13375 ----a-w- c:\documents and settings\All Users\Application Data\xml2B.tmp
2009-05-09 03:53 . 2009-04-29 23:01 7972 ----a-w- c:\documents and settings\All Users\Application Data\xml2A.tmp
2009-05-08 08:13 . 2009-05-08 08:13 -------- d-----w- c:\documents and settings\All Users\Application Data\TrackMania
2009-05-05 09:03 . 2009-05-05 09:03 -------- d-----w- c:\program files\Windows Media Connect 2
2009-05-05 06:34 . 2009-05-05 06:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Azureus
2009-05-04 08:46 . 2009-06-05 02:51 2835656 -c--a-w- c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}\speedupmypc2009.exe
2009-05-03 16:58 . 2009-04-29 22:56 -------- d-----w- c:\program files\Firefox Downloads
2009-05-03 04:02 . 2009-05-03 03:59 102262 ----a-w- c:\windows\hpoins05.dat
2009-05-03 04:01 . 2009-05-03 04:01 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2009-05-03 04:00 . 2009-05-03 04:00 -------- d-----w- c:\program files\HP
2009-05-01 23:48 . 2009-05-01 23:48 98304 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-05-01 23:37 . 2009-04-29 23:17 -------- d-----w- c:\program files\Common Files\InstallShield
2009-05-01 15:51 . 2009-04-29 23:27 -------- d-----w- c:\program files\NOS
2009-05-01 15:51 . 2009-04-29 23:27 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-05-01 15:39 . 2009-05-01 15:39 -------- d-----w- c:\program files\MSBuild
2009-05-01 15:38 . 2009-05-01 15:38 -------- d-----w- c:\program files\Reference Assemblies
2009-05-01 15:31 . 2009-05-01 15:31 -------- d-----w- c:\program files\Common Files\Adobe
2009-05-01 15:29 . 2009-05-01 15:27 -------- d-----w- c:\program files\Google
2009-05-01 12:54 . 2009-05-01 12:54 -------- d-----w- c:\program files\Realtek
2009-04-30 07:21 . 2009-04-30 07:21 -------- d-----w- c:\program files\Microsoft
2009-04-30 07:21 . 2009-04-30 07:21 -------- d-----w- c:\program files\Windows Live
2009-04-30 07:21 . 2009-04-30 07:21 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-04-30 07:17 . 2009-04-30 07:17 -------- d-----w- c:\program files\Common Files\Windows Live
2009-04-30 02:38 . 2009-04-30 02:38 -------- d-----w- c:\program files\Combined Community Codec Pack
2009-04-30 02:19 . 2009-04-30 02:13 -------- d-----w- c:\documents and settings\Administrator\Application Data\Winamp
2009-04-30 01:55 . 2009-04-30 01:55 -------- d-----w- c:\documents and settings\Administrator\Application Data\atitray
2009-04-30 01:37 . 2009-04-30 01:37 -------- d-----w- c:\program files\Intel
2009-04-30 01:26 . 2009-04-30 01:26 -------- d-----w- c:\program files\GetRight
2009-04-29 23:45 . 2009-04-29 23:45 -------- d-----w- c:\program files\Analog Devices
2009-04-29 23:23 . 2009-04-29 23:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-04-29 23:23 . 2009-04-29 23:23 -------- d-----w- c:\program files\Apple Software Update
2009-04-29 23:23 . 2009-04-29 23:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-04-29 23:20 . 2009-04-29 23:20 -------- d-----w- c:\program files\Java
2009-04-29 23:16 . 2009-04-29 23:16 472576 ----a-w- c:\windows\Radeon Omega Drivers v4.8.442 Uninstall.exe
2009-04-29 22:52 . 2009-04-29 22:52 0 ----a-w- c:\windows\nsreg.dat
2009-04-29 22:36 . 2009-04-29 22:36 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2009-04-29 09:45 . 2009-06-05 02:49 845128 -c--a-w- c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}\SpeedUpMyPC2009\58D97068\B74607BA\Sy stem.Data.SQLite.dll
2009-04-29 09:45 . 2009-06-05 02:49 771368 -c--a-w- c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}\SpeedUpMyPC2009\9966075F\B74607BA\UB SysMan.dll
2009-04-29 09:45 . 2009-06-05 02:49 54608 -c--a-w- c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}\SpeedUpMyPC2009\D720648F\B74607BA\In terop.IWshRuntimeLibrary.dll
2009-04-29 09:45 . 2009-06-05 02:49 519168 -c--a-w- c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}\SpeedUpMyPC2009\78B94F67\B74607BA\Is License40.dll
2009-04-29 09:45 . 2009-06-05 02:49 395048 -c--a-w- c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}\SpeedUpMyPC2009\C77843B\B74607BA\SUM PBackend.dll
2009-04-29 09:45 . 2009-06-05 02:49 345008 -c--a-w- c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}\SpeedUpMyPC2009\4BF757A\B74607BA\IsL icense30.dll
2009-04-29 09:45 . 2009-06-05 02:49 236840 -c--a-w- c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}\SpeedUpMyPC2009\683B013A\B74607BA\Po werSuiteBackendUtils.dll
2009-04-29 09:45 . 2009-06-05 02:49 614696 -c--a-w- c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}\SpeedUpMyPC2009\7AEFAE8C\B74607BA\La uncher.exe
2009-04-29 09:45 . 2009-06-05 02:49 474408 -c--a-w- c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}\SpeedUpMyPC2009\62A3297F\B74607BA\Av alonCommon.dll
2009-04-29 09:45 . 2009-06-05 02:49 197968 -c--a-w- c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}\SpeedUpMyPC2009\6A0591D6\B74607BA\IC SharpCode.SharpZipLib.dll
2009-04-29 09:45 . 2009-06-05 02:49 1250600 -c--a-w- c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}\SpeedUpMyPC2009\B430549D\B74607BA\SU MP.exe
2009-04-15 20:25 . 2009-05-01 15:28 120056 ------w- c:\windows\system32\pxcpyi64.exe
2009-04-15 20:25 . 2009-05-01 15:28 118520 ------w- c:\windows\system32\pxinsi64.exe
2009-04-15 20:24 . 2009-04-15 20:24 90112 ----a-w- c:\windows\system32\dpl100.dll
2009-04-15 20:24 . 2009-04-15 20:24 823296 ----a-w- c:\windows\system32\divx_xx0c.dll
2009-04-15 20:24 . 2009-04-15 20:24 823296 ----a-w- c:\windows\system32\divx_xx07.dll
2009-04-15 20:24 . 2009-04-15 20:24 815104 ----a-w- c:\windows\system32\divx_xx0a.dll
2009-04-15 20:24 . 2009-04-15 20:24 802816 ----a-w- c:\windows\system32\divx_xx11.dll
2009-04-15 20:24 . 2009-04-15 20:24 684032 ----a-w- c:\windows\system32\DivX.dll
2009-04-09 11:32 . 2009-04-09 11:32 89088 ----a-w- c:\documents and settings\Administrator\Application Data\Desktopicon\eBayShortcuts.exe
.
------- Sigcheck -------
[-] 2009-03-03 00:36 361600 A29E1209F925A0E9B330E11DA5FC7BAB c:\windows\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-03-20 1312256]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\RunOnce]
"_nltide_3"="advpack.dll" - c:\windows\system32\advpack.dll [2009-03-08 128512]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system]
"DisableCAD"= 1 (0x1)
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\explorer]
"NoStrCmpLogical"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoSMMyPictures"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"NoSMBalloonTip"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\cur rentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoSMMyPictures"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\SiSoftware\\SiSoftware Sandra Professional Business 2009.SP2\\RpcAgentSrv.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"d:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\WINDOWS\\system32\\emsbqij.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\trackmania nations forever\\TmForever.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\trackmania nations forever\\TmForeverLauncher.exe"=
"d:\\Program Files\\SiSoftware\\SiSoftware Sandra Professional Business 2009.SP2\\WNt500x86\\RpcSandraSrv.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 atitray;atitray;c:\program files\Radeon Omega Drivers\v4.8.442\ATI Tray Tools\atitray.sys [5/8/2009 11:51 PM 17952]
S3 DbusAudio;DbusAudio;c:\windows\system32\drivers\Db usAudio.sys [5/5/2009 1:52 AM 23096]
S3 DbusVideo;DbusVideo;c:\windows\system32\drivers\Db usVideo.sys [5/5/2009 1:52 AM 3768]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [3/24/2009 4:03 AM 7808]
S3 SandraAgentSrv;SiSoftware Deployment Agent Service;d:\program files\SiSoftware\SiSoftware Sandra Professional Business 2009.SP2\RpcAgentSrv.exe [4/29/2009 4:00 PM 98488]
S3 V0230Vfx;V0230Vfx;c:\windows\system32\drivers\V023 0Vfx.sys [5/4/2009 2:07 AM 6272]
S3 V0230VID;Live! Cam Video IM Pro;c:\windows\system32\drivers\V0230VID.sys [5/4/2009 2:07 AM 500608]
S3 WinDefend;Windows Defender;d:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSe tup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-06-08 c:\windows\Tasks\MP Scheduled Scan.job
- d:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 02:20]
.
.
------- Supplementary Scan -------
.
uStart Page = about
:blank
uInternet Settings,ProxyOverride = *.local
IE: Download all with Free Download Manager - file://c:\program files\Free Download Manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\program files\Free Download Manager\dlselected.htm
IE: Download video with Free Download Manager - file://c:\program files\Free Download Manager\dlfvideo.htm
IE: Download with Free Download Manager - file://c:\program files\Free Download Manager\dllink.htm
IE: Download with GetRight - c:\program files\GetRight\GRdownload.htm
IE: Open with GetRight Browser - c:\program files\GetRight\GRbrowse.htm
FF - ProfilePath -
.
************************************************** ************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
GMER - Rootkit Detector and Remover
Rootkit scan 2009-06-14 19:57
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-602162358-1965331169-1417001333-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:0 1,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,37,7d,d2 ,50,63,2b,af,40,b3,38,16,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:0 1,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,37,7d,d2 ,50,63,2b,af,40,b3,38,16,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(828)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-06-15 20:00
ComboFix-quarantined-files.txt 2009-06-15 03:00
ComboFix2.txt 2009-05-09 10:10
Pre-Run: 72,824,082,432 bytes free
Post-Run: 72,815,034,368 bytes free
347