Combofix log:
ComboFix 11-06-03.02 - QuentinAshleyAli 06/03/2011 5:06.2.1 - x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.895.661 [GMT -5:00]
Running from: c:\documents and settings\QuentinAshleyAli\My Documents\ComboFixfix26.exe
AV: AVG Anti-Virus Free *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\18276132.exe
c:\documents and settings\All Users\Application Data\kqAIrvwyxLeS.exe
c:\documents and settings\All Users\Application Data\Tarma Installer
c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setup.dll
c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\_Setupx.dll
c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.dat
c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.exe
c:\documents and settings\All Users\Application Data\Tarma Installer\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.ico
c:\documents and settings\QuentinAshleyAli\Application Data\Adobe\plugs
c:\documents and settings\QuentinAshleyAli\Application Data\Adobe\plugs\mmc12.exe
c:\documents and settings\QuentinAshleyAli\Application Data\Adobe\plugs\mmc99.exe
c:\documents and settings\QuentinAshleyAli\Application Data\Adobe\shed
c:\documents and settings\QuentinAshleyAli\Application Data\Adobe\shed\thr1.chm
.
.
((((((((((((((((((((((((( Files Created from 2011-05-03 to 2011-06-03 )))))))))))))))))))))))))))))))
.
.
2011-06-03 10:14 . 2011-06-03 10:14 41680 ----a-w- c:\windows\system32\drivers\vwvgafre.sys
2011-06-03 09:55 . 2011-06-03 09:55 -------- d-----w- C:\ComboFixfix26
2011-06-03 09:45 . 2011-06-03 09:45 28752 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{B274C892-B322-42AF-BC78-4B4A78AC5295}\MpKslbf4fc3b3.sys
2011-06-03 09:40 . 2011-06-03 09:40 116224 ----a-w- c:\windows\system32\drivers\136430.sys
2011-06-01 23:42 . 2011-06-01 23:42 28752 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{B274C892-B322-42AF-BC78-4B4A78AC5295}\MpKsl25736a73.sys
2011-06-01 22:48 . 2011-05-09 20:46 6962000 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{B274C892-B322-42AF-BC78-4B4A78AC5295}\mpengine.dll
2011-05-17 19:20 . 2011-05-17 19:20 -------- d-----w- c:\documents and settings\All Users\Application Data\NCH Swift Sound
2011-05-17 19:20 . 2011-06-01 23:46 -------- d-----w- c:\documents and settings\QuentinAshleyAli\Application Data\NCH Swift Sound
2011-05-16 14:02 . 2010-12-20 23:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-16 14:02 . 2010-12-20 23:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-05-05 16:21 . 2011-05-05 21:26 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2011-05-05 16:17 . 2011-05-05 16:18 -------- d-----w- c:\program files\CCleaner
2011-05-05 16:16 . 2011-05-13 15:45 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2011-05-05 16:16 . 2011-05-05 21:21 -------- d-----w- c:\documents and settings\QuentinAshleyAli\Local Settings\Application Data\Temp
2011-05-05 16:16 . 2011-05-05 16:18 -------- d-----w- c:\documents and settings\QuentinAshleyAli\Local Settings\Application Data\Google
2011-05-05 16:14 . 2011-05-05 16:14 388096 ----a-r- c:\documents and settings\QuentinAshleyAli\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-09 20:46 . 2011-02-08 12:11 6962000 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-03-18 18:32 . 2011-02-14 22:05 71072 ----a-w- c:\windows\CouponPrinter.ocx
.
Code:
<pre>
c:\program files\Adobe\Reader 9.0\Reader\Reader_sl .exe
c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM .exe
c:\program files\Common Files\InstallShield\UpdateService\issch .exe
c:\program files\Driver Fetch\2.1.0.0\DriverFetch .exe
c:\program files\Enigma Software Group\SpyHunter\SpyHunter4 .exe
c:\program files\HP\HP Software Update\HPWuSchd2 .exe
c:\program files\Java\jre6\bin\jusched .exe
c:\program files\QuickTime\qttask .exe
c:\program files\Roxio\Drag-to-Disc\DrgToDsc .exe
</pre>
.
((((((((((((((((((((((((((((( SnapShot@2011-02-07_22.37.59 )))))))))))))))))))))))))))))))))))))))))
.
+ 2004-08-04 10:00 . 2011-05-29 02:10 40836 c:\windows\system32\perfc009.dat
+ 2011-02-23 11:44 . 2011-03-18 11:11 44576 c:\windows\system32\mlfcache.dat
+ 2010-10-07 18:23 . 2010-10-07 18:23 75040 c:\windows\system32\jdns_sd.dll
+ 2009-12-03 23:15 . 2006-02-21 03:01 23040 c:\windows\system32\fltmc.exe
- 2009-12-03 23:15 . 2004-08-04 10:00 16896 c:\windows\system32\fltlib.dll
+ 2009-12-03 23:15 . 2006-02-21 06:57 16896 c:\windows\system32\fltlib.dll
+ 2011-03-14 21:05 . 2003-01-10 21:13 33588 c:\windows\system32\drivers\wanatw4.sys
- 2009-12-04 20:42 . 2003-01-10 21:13 33588 c:\windows\system32\drivers\wanatw4.sys
+ 2010-10-07 18:23 . 2010-10-07 18:23 91424 c:\windows\system32\dnssd.dll
+ 2009-12-03 23:15 . 2006-02-21 03:01 23040 c:\windows\system32\dllcache\fltmc.exe
- 2009-12-03 23:15 . 2004-08-04 10:00 16896 c:\windows\system32\dllcache\fltlib.dll
+ 2009-12-03 23:15 . 2006-02-21 06:57 16896 c:\windows\system32\dllcache\fltlib.dll
+ 2011-06-01 03:26 . 2011-06-01 03:26 21504 c:\windows\Installer\b53c1c8.msi
+ 2011-05-12 08:00 . 2011-05-12 08:00 34632 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
+ 2009-12-04 20:00 . 2011-05-12 08:01 23040 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2009-12-04 20:00 . 2011-02-06 19:05 23040 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2009-12-04 20:00 . 2011-05-12 08:01 61440 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2009-12-04 20:00 . 2011-02-06 19:05 61440 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2009-12-04 20:00 . 2011-02-06 19:05 27136 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2009-12-04 20:00 . 2011-05-12 08:01 27136 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2009-12-04 20:00 . 2011-05-12 08:01 11264 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2009-12-04 20:00 . 2011-02-06 19:05 11264 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2009-12-04 20:00 . 2011-02-06 19:05 86016 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2009-12-04 20:00 . 2011-05-12 08:01 86016 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2009-12-04 20:00 . 2011-02-06 19:05 12288 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2009-12-04 20:00 . 2011-05-12 08:01 12288 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2009-12-04 16:26 . 2009-12-04 16:26 17534 c:\windows\Installer\{6D52C408-B09A-4520-9B18-475B81D393F1}\gtngstrtd.exe
+ 2009-12-04 16:26 . 2011-02-10 09:03 17534 c:\windows\Installer\{6D52C408-B09A-4520-9B18-475B81D393F1}\gtngstrtd.exe
- 2009-12-04 16:26 . 2009-12-04 16:26 65536 c:\windows\Installer\{6D52C408-B09A-4520-9B18-475B81D393F1}\_B8B1511D9331_467C_9B1B_E8204012E95B.exe
+ 2009-12-04 16:26 . 2011-02-10 09:03 65536 c:\windows\Installer\{6D52C408-B09A-4520-9B18-475B81D393F1}\_B8B1511D9331_467C_9B1B_E8204012E95B.exe
- 2009-12-04 16:26 . 2009-12-04 16:26 65536 c:\windows\Installer\{6D52C408-B09A-4520-9B18-475B81D393F1}\_630CEEA9B210_4765_A2B1_FC24596048D7.exe
+ 2009-12-04 16:26 . 2011-02-10 09:03 65536 c:\windows\Installer\{6D52C408-B09A-4520-9B18-475B81D393F1}\_630CEEA9B210_4765_A2B1_FC24596048D7.exe
- 2009-12-04 16:26 . 2009-12-04 16:26 65536 c:\windows\Installer\{6D52C408-B09A-4520-9B18-475B81D393F1}\_4E403E143BE9_4CD1_B8DF_8012EBBE9E82.exe
+ 2009-12-04 16:26 . 2011-02-10 09:03 65536 c:\windows\Installer\{6D52C408-B09A-4520-9B18-475B81D393F1}\_4E403E143BE9_4CD1_B8DF_8012EBBE9E82.exe
+ 2007-03-23 01:07 . 2007-03-23 01:07 78168 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\RM.DLL
+ 2007-03-23 01:07 . 2007-03-23 01:07 41824 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\RECALL.DLL
+ 2007-03-23 01:05 . 2007-03-23 01:05 97632 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\PP7X32.DLL
+ 2007-04-19 19:53 . 2007-04-19 19:53 69984 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\OUTLRPC.DLL
+ 2007-03-23 01:07 . 2007-03-23 01:07 80224 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\DLGSETP.DLL
+ 2007-03-23 01:07 . 2007-03-23 01:07 91488 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\ADDRPARS.DLL
+ 2011-02-08 12:03 . 2004-08-04 10:00 22528 c:\windows\$NtUninstallKB914882$\fltmc.exe
+ 2011-02-08 12:03 . 2004-08-04 10:00 16896 c:\windows\$NtUninstallKB914882$\fltlib.dll
+ 2011-02-08 12:03 . 2005-10-12 23:12 22752 c:\windows\$hf_mig$\KB914882\update\spcustom.dll
+ 2011-02-08 12:03 . 2005-10-12 23:12 14048 c:\windows\$hf_mig$\KB914882\spmsg.dll
+ 2011-02-08 12:02 . 2006-02-21 03:37 23040 c:\windows\$hf_mig$\KB914882\SP2QFE\fltmc.exe
+ 2011-02-08 12:02 . 2006-02-21 07:20 16896 c:\windows\$hf_mig$\KB914882\SP2QFE\fltlib.dll
- 2009-12-04 20:00 . 2011-02-06 19:05 4096 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2009-12-04 20:00 . 2011-05-12 08:01 4096 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2009-12-04 16:26 . 2009-12-04 16:26 4710 c:\windows\Installer\{6D52C408-B09A-4520-9B18-475B81D393F1}\WSBico.exe
+ 2009-12-04 16:26 . 2011-02-10 09:03 4710 c:\windows\Installer\{6D52C408-B09A-4520-9B18-475B81D393F1}\WSBico.exe
+ 2009-12-04 16:26 . 2011-02-10 09:03 4710 c:\windows\Installer\{6D52C408-B09A-4520-9B18-475B81D393F1}\Win2Kico.exe
- 2009-12-04 16:26 . 2009-12-04 16:26 4710 c:\windows\Installer\{6D52C408-B09A-4520-9B18-475B81D393F1}\Win2Kico.exe
- 2007-11-07 07:19 . 2007-11-07 07:19 655872 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375\msvcr90.dll
+ 2007-11-07 06:19 . 2007-11-07 06:19 655872 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375\msvcr90.dll
- 2007-11-07 07:19 . 2007-11-07 07:19 568832 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375\msvcp90.dll
+ 2007-11-07 06:19 . 2007-11-07 06:19 568832 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375\msvcp90.dll
- 2007-11-07 02:23 . 2007-11-07 02:23 224768 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375\msvcm90.dll
+ 2007-11-07 01:23 . 2007-11-07 01:23 224768 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_d08d0375\msvcm90.dll
+ 2005-09-23 04:48 . 2005-09-23 04:48 626688 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcr80.dll
+ 2005-09-23 04:48 . 2005-09-23 04:48 548864 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcp80.dll
+ 2005-09-23 04:48 . 2005-09-23 04:48 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcm80.dll
+ 2004-08-04 10:00 . 2011-05-29 02:10 314508 c:\windows\system32\perfh009.dat
+ 2004-01-27 12:13 . 2004-01-27 12:13 421888 c:\windows\system32\OpenQuicktimeLib_dec.dll
+ 2011-02-08 20:09 . 2009-08-07 01:23 215920 c:\windows\system32\muweb.dll
+ 2011-02-08 20:09 . 2009-08-07 01:23 274288 c:\windows\system32\mucltui.dll
+ 2011-02-08 12:11 . 2010-10-19 20:51 222080 c:\windows\system32\MpSigStub.exe
+ 2011-03-10 14:07 . 2011-03-10 14:07 234656 c:\windows\system32\Macromed\Flash\FlashUtil10n_ActiveX.exe
+ 2011-03-10 14:07 . 2011-03-10 14:07 311456 c:\windows\system32\Macromed\Flash\FlashUtil10n_ActiveX.dll
+ 2011-02-07 23:16 . 2010-11-13 00:53 157472 c:\windows\system32\javaws.exe
+ 2011-02-07 23:16 . 2010-11-13 00:53 145184 c:\windows\system32\javaw.exe
- 2009-12-13 00:58 . 2009-12-13 00:58 145184 c:\windows\system32\javaw.exe
- 2009-12-13 00:58 . 2009-12-13 00:58 145184 c:\windows\system32\java.exe
+ 2011-02-07 23:16 . 2010-11-13 00:53 145184 c:\windows\system32\java.exe
+ 2009-12-03 08:09 . 2011-03-27 18:52 221632 c:\windows\system32\FNTCACHE.DAT
+ 2010-10-25 03:25 . 2010-10-25 03:25 165264 c:\windows\system32\drivers\MpFilter.sys
+ 2009-12-03 23:15 . 2006-02-21 03:01 128896 c:\windows\system32\drivers\fltmgr.sys
+ 2010-10-07 18:23 . 2010-10-07 18:23 197920 c:\windows\system32\dnssdX.dll
+ 2010-10-07 18:23 . 2010-10-07 18:23 107808 c:\windows\system32\dns-sd.exe
+ 2009-12-03 23:15 . 2006-02-21 03:01 128896 c:\windows\system32\dllcache\fltmgr.sys
+ 2011-02-07 23:16 . 2010-11-13 00:53 472808 c:\windows\system32\deployJava1.dll
- 2010-05-02 02:13 . 2010-05-02 02:13 262144 c:\windows\system32\config\systemprofile\ntuser.dat
+ 2010-05-02 02:13 . 2011-05-05 16:18 262144 c:\windows\system32\config\systemprofile\ntuser.dat
+ 2004-01-27 13:35 . 2004-01-27 13:35 270336 c:\windows\system32\3ivxVfWCodec_dec.dll
+ 2004-01-27 13:35 . 2004-01-27 13:35 958464 c:\windows\system32\3ivx_dec.dll
+ 2009-09-09 21:40 . 2009-09-09 21:40 632320 c:\windows\Installer\c892f27.msp
+ 2008-07-28 20:59 . 2008-07-28 20:59 180736 c:\windows\Installer\c892e30.msp
+ 2010-11-12 17:08 . 2010-11-12 17:08 889344 c:\windows\Installer\c892e1c.msp
+ 2011-03-15 19:14 . 2011-03-15 19:14 381440 c:\windows\Installer\4c3cbc7.msi
+ 2011-03-27 00:40 . 2011-03-27 00:40 811008 c:\windows\Installer\3e942955.msi
+ 2011-03-14 21:05 . 2011-03-14 21:05 133632 c:\windows\Installer\32e97.msi
+ 2011-02-08 12:08 . 2011-02-08 12:08 786432 c:\windows\Installer\2e7efc4.msi
+ 2011-02-08 12:08 . 2011-02-08 12:08 479744 c:\windows\Installer\2e7efbe.msi
+ 2011-02-08 12:08 . 2011-02-08 12:08 301056 c:\windows\Installer\2e7efb9.msi
+ 2011-02-07 23:16 . 2011-02-07 23:16 180224 c:\windows\Installer\22e6dd.msi
- 2009-12-04 20:00 . 2011-02-06 19:05 409600 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2009-12-04 20:00 . 2011-05-12 08:01 409600 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2009-12-04 20:00 . 2011-02-06 19:05 286720 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2009-12-04 20:00 . 2011-05-12 08:01 286720 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2009-12-04 20:00 . 2011-05-12 08:01 249856 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2009-12-04 20:00 . 2011-02-06 19:05 249856 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2009-12-04 20:00 . 2011-05-12 08:01 794624 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2009-12-04 20:00 . 2011-02-06 19:05 794624 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2009-12-04 20:00 . 2011-02-06 19:05 135168 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2009-12-04 20:00 . 2011-05-12 08:01 135168 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2009-12-04 20:00 . 2011-05-12 08:01 593920 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
- 2009-12-04 20:00 . 2011-02-06 19:05 593920 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
- 2009-12-04 16:26 . 2009-12-04 16:26 184320 c:\windows\Installer\{6D52C408-B09A-4520-9B18-475B81D393F1}\_9FA356B1395F_4530_8CB3_946ED0B3291E.exe
+ 2009-12-04 16:26 . 2011-02-10 09:03 184320 c:\windows\Installer\{6D52C408-B09A-4520-9B18-475B81D393F1}\_9FA356B1395F_4530_8CB3_946ED0B3291E.exe
+ 2011-02-23 11:42 . 2011-02-23 11:42 897024 c:\windows\Installer\{6B9B0C6F-E5FA-4633-A640-AB98A272ECCA}\SafariIco.exe
+ 2007-03-23 01:22 . 2007-03-23 01:22 103264 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\TRANSMGR.DLL
+ 2007-05-10 19:34 . 2007-05-10 19:34 562528 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\PUBCONV.DLL
+ 2007-05-31 19:36 . 2007-05-31 19:36 612184 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\PTXT9.DLL
+ 2007-05-31 19:35 . 2007-05-31 19:35 133976 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\PRTF9.DLL
+ 2007-04-19 19:53 . 2007-04-19 19:53 149856 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\OUTLPH.DLL
+ 2007-05-31 19:42 . 2007-05-31 19:42 200032 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\OUTLOOK.EXE
+ 2007-04-19 19:53 . 2007-04-19 19:53 106336 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\OUTLMIME.DLL
+ 2007-04-19 19:53 . 2007-04-19 19:53 109408 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\OUTLCTL.DLL
+ 2007-04-19 20:01 . 2007-04-19 20:01 238424 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\MSCDM.DLL
+ 2007-01-17 02:32 . 2007-01-17 02:32 136032 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\MSAEXP30.DLL
+ 2007-04-19 19:54 . 2007-04-19 19:54 183136 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\MIMEDIR.DLL
+ 2007-04-19 19:53 . 2007-04-19 19:53 127328 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\IMPMAIL.DLL
+ 2007-04-19 20:09 . 2007-04-19 20:09 167256 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\IETAG.DLL
+ 2007-04-19 19:53 . 2007-04-19 19:53 137568 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\ENVELOPE.DLL
+ 2007-04-19 19:54 . 2007-04-19 19:54 169312 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\ACCWIZ.DLL
+ 2003-07-08 17:48 . 2003-07-08 17:48 115288 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OUTLFLTR.DLL
+ 2003-07-15 09:18 . 2003-07-15 09:18 141360 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\ATP.DLL
+ 2005-08-22 19:16 . 2005-08-22 19:16 929792 c:\windows\Installer\$PatchCache$\Managed\804C25D6A90B0254B98174B5183D391F\8.5.818\F20987_wkwpqd.dll
+ 2005-08-22 19:18 . 2005-08-22 19:18 147456 c:\windows\Installer\$PatchCache$\Managed\804C25D6A90B0254B98174B5183D391F\8.5.818\F20985_wkwpqrtf.dll
+ 2005-08-18 11:11 . 2005-08-18 11:11 225280 c:\windows\Installer\$PatchCache$\Managed\804C25D6A90B0254B98174B5183D391F\8.5.818\F20963_wkssole.dll
+ 2011-02-08 12:03 . 2006-01-19 19:29 371424 c:\windows\$NtUninstallKB914882$\spuninst\updspapi.dll
+ 2011-02-08 12:03 . 2005-10-12 23:12 213216 c:\windows\$NtUninstallKB914882$\spuninst\spuninst.exe
+ 2011-02-08 12:03 . 2004-08-04 10:00 124800 c:\windows\$NtUninstallKB914882$\fltmgr.sys
+ 2011-02-08 12:03 . 2006-01-19 19:29 371424 c:\windows\$hf_mig$\KB914882\update\updspapi.dll
+ 2011-02-08 12:03 . 2005-10-12 23:12 716000 c:\windows\$hf_mig$\KB914882\update\update.exe
+ 2011-02-08 12:03 . 2005-10-12 23:12 213216 c:\windows\$hf_mig$\KB914882\spuninst.exe
+ 2011-02-08 12:02 . 2006-02-21 03:37 128768 c:\windows\$hf_mig$\KB914882\SP2QFE\fltmgr.sys
+ 2008-09-05 08:09 . 2008-09-05 08:09 1376528 c:\windows\system32\msvbvm60.dll
+ 2009-08-05 01:52 . 2009-08-05 01:52 1193832 c:\windows\system32\FM20.DLL
+ 2010-08-05 16:57 . 2010-08-05 16:57 4066304 c:\windows\Installer\c892fbf.msp
+ 2009-10-17 00:07 . 2009-10-17 00:07 6115328 c:\windows\Installer\c892f9b.msp
+ 2005-10-26 20:59 . 2005-10-26 20:59 2883072 c:\windows\Installer\c892f71.msp
+ 2010-10-22 21:45 . 2010-10-22 21:45 8444928 c:\windows\Installer\c892f5c.msp
+ 2011-01-17 22:06 . 2011-01-17 22:06 5518848 c:\windows\Installer\c892f3d.msp
+ 2009-08-20 11:02 . 2009-08-20 11:02 5204992 c:\windows\Installer\c892f13.msp
+ 2010-06-11 23:55 . 2010-06-11 23:55 1827328 c:\windows\Installer\c892efd.msp
+ 2009-07-01 19:21 . 2009-07-01 19:21 8891904 c:\windows\Installer\c892ee4.msp
+ 2010-08-23 23:09 . 2010-08-23 23:09 7673344 c:\windows\Installer\c892ecc.msp
+ 2008-01-14 22:53 . 2008-01-14 22:53 5213696 c:\windows\Installer\c892eb7.msp
+ 2010-10-01 23:42 . 2010-10-01 23:42 5054464 c:\windows\Installer\c892ea3.msp
+ 2009-12-17 04:58 . 2009-12-17 04:58 5382144 c:\windows\Installer\c892e8c.msp
+ 2008-10-25 15:15 . 2008-10-25 15:15 6227456 c:\windows\Installer\c892e74.msp
+ 2009-11-18 00:29 . 2009-11-18 00:29 4870656 c:\windows\Installer\c892e60.msp
+ 2009-09-29 15:08 . 2009-09-29 15:08 6747648 c:\windows\Installer\c892e45.msp
+ 2010-08-25 23:06 . 2010-08-25 23:06 6479360 c:\windows\Installer\c892e03.msp
+ 2010-10-02 03:53 . 2010-10-02 03:53 4147712 c:\windows\Installer\c892dee.msp
+ 2010-08-24 15:49 . 2010-08-24 15:49 6825472 c:\windows\Installer\c892dd6.msp
+ 2010-03-30 18:34 . 2010-03-30 18:34 3826688 c:\windows\Installer\c892dc1.msp
+ 2010-09-17 11:04 . 2010-09-17 11:04 9401856 c:\windows\Installer\7813ecc.msp
+ 2010-08-13 22:59 . 2010-08-13 22:59 8182272 c:\windows\Installer\7813ec4.msp
+ 2010-08-13 23:02 . 2010-08-13 23:02 2545664 c:\windows\Installer\7813ebc.msp
+ 2010-08-04 20:12 . 2010-08-04 20:12 1004544 c:\windows\Installer\7813eb4.msp
+ 2011-02-23 11:42 . 2011-02-23 11:42 3140608 c:\windows\Installer\500c883c.msi
+ 2011-02-23 11:41 . 2011-02-23 11:41 1984000 c:\windows\Installer\500c8838.msi
+ 2011-04-27 16:14 . 2011-04-27 16:14 5520384 c:\windows\Installer\40698227.msp
+ 2011-04-29 18:04 . 2011-04-29 18:04 5053440 c:\windows\Installer\40698212.msp
+ 2011-04-29 17:30 . 2011-04-29 17:30 1197056 c:\windows\Installer\406981fd.msp
+ 2011-03-27 00:41 . 2011-03-27 00:41 9472000 c:\windows\Installer\3e9429e4.msi
+ 2011-01-27 19:49 . 2011-01-27 19:49 6825472 c:\windows\Installer\213a8099.msp
+ 2011-04-05 17:52 . 2011-04-05 17:52 5519872 c:\windows\Installer\213a806f.msp
+ 2010-11-21 04:34 . 2010-11-21 04:34 1198080 c:\windows\Installer\213a805a.msp
+ 2011-03-18 01:01 . 2011-03-18 01:01 9563648 c:\windows\Installer\213a8052.msp
+ 2011-03-03 16:25 . 2011-03-03 16:25 5051904 c:\windows\Installer\213a804a.msp
+ 2011-01-11 22:50 . 2011-01-11 22:50 8177152 c:\windows\Installer\213a8035.msp
+ 2011-02-22 16:32 . 2011-02-22 16:32 5520384 c:\windows\Installer\1f81efb6.msp
+ 2011-05-05 16:14 . 2011-05-05 16:14 1094656 c:\windows\Installer\1e211def.msi
+ 2007-05-09 23:19 . 2007-05-09 23:19 2585936 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\VBE6.DLL
+ 2007-04-19 19:49 . 2007-04-19 19:49 1661280 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\PPTVIEW.EXE
+ 2007-05-31 19:35 . 2007-05-31 19:35 6420320 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\POWERPNT.EXE
+ 2007-05-10 19:45 . 2007-05-10 19:45 8069464 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\OWC11.DLL
+ 2007-03-14 19:10 . 2007-03-14 19:10 7255384 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\OWC10.DLL
+ 2007-05-31 19:43 . 2007-05-31 19:43 7613280 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\OUTLLIB.DLL
+ 2007-05-10 19:35 . 2007-05-10 19:35 6747480 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\MSPUB.EXE
+ 2007-05-10 19:43 . 2007-05-10 19:43 6688096 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\MSACCESS.EXE
+ 2007-04-30 20:57 . 2007-04-30 20:57 7084384 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\INFOPATH.EXE
+ 2007-06-06 16:53 . 2007-06-06 16:53 1195888 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\FM20.DLL
+ 2003-07-07 19:36 . 2003-07-07 19:36 2058343 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OUTLFLTR.DAT
+ 2005-08-18 11:36 . 2005-08-18 11:36 2023424 c:\windows\Installer\$PatchCache$\Managed\804C25D6A90B0254B98174B5183D391F\8.5.818\F22194_wksssdb.dll
+ 2004-08-04 08:57 . 2004-08-04 08:57 1712128 c:\windows\Installer\$PatchCache$\Managed\804C25D6A90B0254B98174B5183D391F\8.5.818\F20954_gdiplus.dll
+ 2009-08-19 23:04 . 2009-08-19 23:04 4542296 c:\windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6514\WRD12CNV.DLL
+ 2009-08-17 20:32 . 2009-08-17 20:32 1787728 c:\windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6514\PPCNV.DLL
+ 2011-02-08 12:02 . 2006-02-21 04:01 2180992 c:\windows\$hf_mig$\KB914882\SP2QFE\ntoskrnl.exe
+ 2011-02-08 12:02 . 2006-02-21 03:36 2015744 c:\windows\$hf_mig$\KB914882\SP2QFE\ntkrpamp.exe
+ 2011-02-08 12:02 . 2006-02-21 03:36 2057984 c:\windows\$hf_mig$\KB914882\SP2QFE\ntkrnlpa.exe
+ 2011-02-08 12:02 . 2006-02-21 03:59 2136576 c:\windows\$hf_mig$\KB914882\SP2QFE\ntkrnlmp.exe
+ 2010-10-14 22:57 . 2010-10-14 22:57 11189248 c:\windows\Installer\c892f86.msp
+ 2010-06-11 23:52 . 2010-06-11 23:52 45542912 c:\windows\Installer\c892efe.msp
+ 2009-07-01 19:19 . 2009-07-01 19:19 10607104 c:\windows\Installer\c892ee5.msp
+ 2011-02-24 14:38 . 2011-02-24 14:38 10984448 c:\windows\Installer\213a8084.msp
+ 2007-05-31 19:37 . 2007-05-31 19:37 12310368 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\WINWORD.EXE
+ 2007-06-18 23:16 . 2007-06-18 23:16 12259160 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\MSO.DLL
+ 2007-05-31 19:41 . 2007-05-31 19:41 10352472 c:\windows\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.8173\EXCEL.EXE
+ 2009-08-17 22:39 . 2009-08-17 22:39 15119720 c:\windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6514\XL12CNV.EXE
+ 2009-08-17 21:40 . 2009-08-17 21:40 17309040 c:\windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6514\MSO.DLL
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AOL Fast Start"="c:\program files\AOL 9.5\AOL.EXE" [2009-10-28 50536]
"kqAIrvwyxLeS"="c:\documents and settings\All Users\Application Data\kqAIrvwyxLeS.exe" [N/A]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-09-27 16844800]
"SkyTel"="SkyTel.EXE" [2007-08-03 1826816]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
"HostManager"="c:\program files\Common Files\AOL\1300136716\ee\AOLSoftware.exe" [2009-07-20 41264]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Common Files\\aol\\acs\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\aol\\acs\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\aol\\1300136716\\ee\\aolsoftware.exe"=
"c:\\Program Files\\AOL 9.5\\waol.exe"=
"c:\\Program Files\\Common Files\\aol\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\Common Files\\aol\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\aol\\System Information\\sinf.exe"=
.
S1 MpKsl25736a73;MpKsl25736a73;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{B274C892-B322-42AF-BC78-4B4A78AC5295}\MpKsl25736a73.sys [6/1/2011 6:42 PM 28752]
S1 MpKsl3671b97e;MpKsl3671b97e;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0ACC8150-C52F-40C0-B11E-5422323D812C}\MpKsl3671b97e.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0ACC8150-C52F-40C0-B11E-5422323D812C}\MpKsl3671b97e.sys [?]
S1 MpKsl4a9e1d01;MpKsl4a9e1d01;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EA6F2495-9A0C-4E11-AD47-C4E84256E3BB}\MpKsl4a9e1d01.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{EA6F2495-9A0C-4E11-AD47-C4E84256E3BB}\MpKsl4a9e1d01.sys [?]
S1 MpKsl4e5f59ff;MpKsl4e5f59ff;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{16B70A1F-E9B8-4D67-BDC7-A90E63E179D0}\MpKsl4e5f59ff.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{16B70A1F-E9B8-4D67-BDC7-A90E63E179D0}\MpKsl4e5f59ff.sys [?]
S1 MpKsl676b6e26;MpKsl676b6e26;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E76A253C-76EB-43A8-A038-458BD269B0E5}\MpKsl676b6e26.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E76A253C-76EB-43A8-A038-458BD269B0E5}\MpKsl676b6e26.sys [?]
S1 MpKsl6e7306ee;MpKsl6e7306ee;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D9CEFB25-30AC-4DFA-9A90-EBF37D0B28A8}\MpKsl6e7306ee.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D9CEFB25-30AC-4DFA-9A90-EBF37D0B28A8}\MpKsl6e7306ee.sys [?]
S1 MpKsl7ed93d1e;MpKsl7ed93d1e;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D9CEFB25-30AC-4DFA-9A90-EBF37D0B28A8}\MpKsl7ed93d1e.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D9CEFB25-30AC-4DFA-9A90-EBF37D0B28A8}\MpKsl7ed93d1e.sys [?]
S1 MpKsl82a78a7b;MpKsl82a78a7b;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CC40FAB4-008D-4F2D-A368-0428B1C412F8}\MpKsl82a78a7b.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{CC40FAB4-008D-4F2D-A368-0428B1C412F8}\MpKsl82a78a7b.sys [?]
S1 MpKslb8c6a8bc;MpKslb8c6a8bc;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{955D3C13-2394-4F7B-A781-9775921CE499}\MpKslb8c6a8bc.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{955D3C13-2394-4F7B-A781-9775921CE499}\MpKslb8c6a8bc.sys [?]
S1 MpKslbf4fc3b3;MpKslbf4fc3b3;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{B274C892-B322-42AF-BC78-4B4A78AC5295}\MpKslbf4fc3b3.sys [6/3/2011 4:45 AM 28752]
S1 MpKsld035d297;MpKsld035d297;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0ACC8150-C52F-40C0-B11E-5422323D812C}\MpKsld035d297.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0ACC8150-C52F-40C0-B11E-5422323D812C}\MpKsld035d297.sys [?]
S1 MpKsld94df21a;MpKsld94df21a;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{54D9EB97-A98F-44BB-ADCA-A23C4B81A4C5}\MpKsld94df21a.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{54D9EB97-A98F-44BB-ADCA-A23C4B81A4C5}\MpKsld94df21a.sys [?]
S1 MpKslda4f5b63;MpKslda4f5b63;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{60D80D41-DAFE-45C6-B01A-266C35C0A10F}\MpKslda4f5b63.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{60D80D41-DAFE-45C6-B01A-266C35C0A10F}\MpKslda4f5b63.sys [?]
S1 MpKsle0642e50;MpKsle0642e50;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0ACC8150-C52F-40C0-B11E-5422323D812C}\MpKsle0642e50.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{0ACC8150-C52F-40C0-B11E-5422323D812C}\MpKsle0642e50.sys [?]
S1 MpKslfe1ba7f0;MpKslfe1ba7f0;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{310FC98A-34D4-4C98-AE6E-3A2768A1A811}\MpKslfe1ba7f0.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{310FC98A-34D4-4C98-AE6E-3A2768A1A811}\MpKslfe1ba7f0.sys [?]
S1 vwvgafre;vwvgafre;c:\windows\system32\drivers\vwvgafre.sys [6/3/2011 5:14 AM 41680]
S1 xvtebljv;xvtebljv;\??\c:\windows\system32\drivers\xvtebljv.sys --> c:\windows\system32\drivers\xvtebljv.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [5/5/2011 11:16 AM 136176]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [5/5/2011 11:16 AM 136176]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WUAUSERV
.
Contents of the 'Scheduled Tasks' folder
.
2011-06-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]
.
2011-06-02 c:\windows\Tasks\At1.job
- c:\program files\HP\HP Deskjet 1000 J110 series\Bin\HPCustPartic.exe [2010-06-14 22:07]
.
2011-06-03 c:\windows\Tasks\At2.job
- c:\program files\HP\HP Deskjet 1000 J110 series\Bin\HPCustPartic.exe [2010-06-14 22:07]
.
2011-06-03 c:\windows\Tasks\At3.job
- c:\program files\HP\HP Deskjet 1000 J110 series\Bin\HPCustPartic.exe [2010-06-14 22:07]
.
2011-06-02 c:\windows\Tasks\At4.job
- c:\program files\HP\HP Deskjet 1000 J110 series\Bin\HPCustPartic.exe [2010-06-14 22:07]
.
2011-06-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-05-05 16:16]
.
2011-06-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-05-05 16:16]
.
2011-06-02 c:\windows\Tasks\hpwebreg_CN0AF22KXT05D2.job
- c:\program files\HP\HP Deskjet 1000 J110 series\Bin\hpwebreg.exe [2010-06-14 22:10]
.
2011-06-03 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2010-11-11 18:26]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 76.85.229.110 76.85.229.111
FF - ProfilePath - c:\documents and settings\QuentinAshleyAli\Application Data\Mozilla\Firefox\Profiles\bdg8hvb6.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.aol.com/aolcom/search?invocationType=tb50ffTB50CL-chromesbox-en-us&query=
FF - prefs.js: browser.search.selectedEngine - AOL Search
FF - prefs.js: browser.startup.homepage - hxxp://search.bearshare.com/
FF - prefs.js: keyword.URL - hxxp://search.bearshare.com/web?src=ffb&systemid=2&q=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter:
[email protected] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - user.js: protocol-handler.warn-external.dnUpdate - false
FF - user.js: browser.sessionstore.resume_from_crash - false
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-10 - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-06-03 05:14
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer,
http://www.gmer.net
Windows 5.1.2600 Disk: WDC_WD1600AAJS-22WAA0 rev.58.01D58 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-e
.
device: opened successfully
user: MBR read successfully
error: Read A device attached to the system is not functioning.
kernel: MBR read successfully
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x850DA31B
user & kernel MBR OK
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(552)
c:\windows\system32\WININET.dll
.
- - - - - - - > 'lsass.exe'(620)
c:\windows\system32\WININET.dll
.
Completion time: 2011-06-03 05:17:30
ComboFix-quarantined-files.txt 2011-06-03 10:17
ComboFix2.txt 2011-02-07 22:39
.
Pre-Run: 144,385,298,432 bytes free
Post-Run: 144,581,394,432 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - A3C3CB1226D0817B2BEFBE77E7C8D4EE
HIjack this log:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:18:53 AM, on 6/3/2011
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode with network support
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - !{ba00b7b1-0351-477a-b948-23e3ee5a73d4} - (no file)
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1300136716\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.5\AOL.EXE" -b
O4 - HKCU\..\Run: [kqAIrvwyxLeS] C:\Documents and Settings\All Users\Application Data\kqAIrvwyxLeS.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Unknown owner - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (file missing)
--
End of file - 3488 bytes
malware bytes:
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6733
Windows 5.1.2600 Service Pack 2 (Safe Mode)
Internet Explorer 8.0.6001.18702
6/3/2011 5:20:40 AM
mbam-log-2011-06-03 (05-20-40).txt
Scan type: Quick scan
Objects scanned: 135603
Time elapsed: 1 minute(s), 16 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\WINDOWS\system32\drivers\136430.sys (Rootkit.TDSS) -> Quarantined and deleted successfully.