http://www.bleepingcomputer.com/forums/t/215492/infected-with-a-trojandns/
here are all the things i was asked for.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:07, on 2008-12-22
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Microsoft Windows OneCare Live\WinSSNotifyE.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Jennifer\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Jennifer.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com?o=1607
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\Windows\system32\PSIService.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 5753 bytes
ComboFix 09-04-04.01 - Jennifer 2009-04-05 20:22:52.3 - NTFSx86
Running from: c:\users\Jennifer\Desktop\ComboFix.exe
AV: AVG *On-access scanning disabled* (Outdated)
.
((((((((((((((((((((((((( Files Created from 2009-03-06 to 2009-04-06 )))))))))))))))))))))))))))))))
.
2009-04-05 20:17 . 2006-03-03 00:42 73,728 --a--c--- C:\pv.exe
2009-03-26 00:43 . 2009-03-26 00:43
2009-03-26 00:42 . 2009-03-26 00:45
2009-03-26 00:42 . 2009-03-26 00:45
2009-03-26 00:42 . 2009-03-29 18:44
2009-03-06 16:00 . 2009-03-06 16:00
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-06 00:11 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-04-05 07:45 --------- d-----w c:\users\Jennifer\AppData\Roaming\FrostWire
2009-04-01 15:56 --------- d-----w c:\users\Jennifer\AppData\Roaming\uTorrent
2009-03-26 20:49 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-26 20:49 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-03-07 08:12 --------- d-----w c:\programdata\CyberLink
2009-02-27 05:14 --------- d-----w c:\programdata\Viewpoint
2009-02-27 05:05 --------- d-----w c:\program files\Common Files\AOL
2009-02-27 02:10 --------- d-----w c:\program files\Common Files\Software Update Utility
2009-02-18 02:54 --------- d-----w c:\users\Jennifer\AppData\Roaming\Aim
2009-02-18 02:54 --------- d-----w c:\program files\AOD
2009-02-18 02:54 --------- d-----w c:\program files\AIM
2009-02-18 02:42 --------- d-----w c:\programdata\Kaspersky Lab
2009-02-18 01:41 --------- d-----w c:\program files\PhotoScape
2009-02-16 22:08 --------- d-----w c:\program files\Windows Live Safety Center
2009-02-16 03:10 --------- d-----w c:\users\Jennifer\AppData\Roaming\acccore
2009-02-16 03:06 --------- d-----w c:\programdata\acccore
2009-02-15 21:59 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-02-15 21:56 --------- d-----w c:\program files\Verizon
2009-02-15 21:52 --------- d-----w c:\programdata\Spybot - Search & Destroy
2009-02-15 21:39 --------- d-----w c:\programdata\Lavasoft
2009-02-10 21:37 --------- d-----w c:\program files\verizon_broad
2009-02-10 21:19 --------- d-----w c:\program files\InstallShield Installation Information
2009-02-10 21:06 --------- d-----w c:\users\Jennifer\AppData\Roaming\Verizon
2009-02-10 21:06 --------- d-----w c:\programdata\Verizon
2009-02-09 20:54 --------- d-----w c:\program files\Real
2009-02-09 20:54 --------- d-----w c:\program files\Common Files\Real
2009-02-09 19:52 --------- d-----w c:\users\Jennifer\AppData\Roaming\Apple Computer
2009-02-06 19:03 --------- d-----w c:\users\Jennifer\AppData\Roaming\Media Player Classic
2009-02-06 18:59 --------- d-----w c:\program files\Window Gadgets
2009-02-06 18:42 --------- d-----w c:\users\Jennifer\AppData\Roaming\iScreensaver
2009-02-06 18:30 --------- d-----w c:\programdata\HP
2009-02-06 18:30 --------- d-----w c:\program files\HP
2009-02-06 18:28 --------- d-----w c:\users\Jennifer\AppData\Roaming\SUPERAntiSpyware.com
2009-02-06 18:23 --------- d-----w c:\program files\Common Files\Roxio Shared
2009-02-06 01:36 --------- d-----w c:\program files\Microsoft Windows OneCare Live
2008-08-29 17:33 47,360 ----a-w c:\users\Jennifer\AppData\Roaming\pcouffin.sys
2008-07-02 17:04 174 --sha-w c:\program files\desktop.ini
2007-09-05 09:52 476,752 ----a-w c:\users\All Users\pswi_preloaded.exe
2007-09-05 09:52 476,752 ----a-w c:\programdata\pswi_preloaded.exe
2008-11-04 07:57 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-11-04 07:57 32,768 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-11-04 07:57 16,384 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
2008-07-21 09:49 168 --sh--r c:\windows\System32\DEE8856056.sys
2008-07-21 09:49 5,018 --sha-w c:\windows\System32\KGyGaAvL.sys
2008-12-14 07:52 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008120120081208\index.dat
2008-12-18 14:38 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008120820081215\index.dat
2008-12-18 14:38 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008121820081219\index.dat
2008-12-20 17:34 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008122020081221\index.dat
.
((((((((((((((((((((((((((((( snapshot@2009-01-08_15.21.41.25 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-12-01 18:02:54 59,668,072 ----a-w c:\windows\bin\setup.exe
- 2008-10-02 18:18:36 38,428 ----a-w c:\windows\Downloaded Program Files\unagiuninst.exe
+ 2009-02-27 02:09:04 38,428 ----a-w c:\windows\Downloaded Program Files\unagiuninst.exe
+ 2008-10-28 21:25:00 453,512 ----a-w c:\windows\Downloaded Program Files\wlscBase.dll
- 2005-10-21 01:02:28 163,328 ----a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
+ 2005-10-21 00:02:28 163,328 ----a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
- 2008-12-30 18:41:50 51,200 ----a-w c:\windows\inf\infpub.dat
+ 2009-02-16 06:17:40 51,200 ----a-w c:\windows\inf\infpub.dat
- 2008-12-29 02:39:12 86,016 ----a-w c:\windows\inf\infstor.dat
+ 2009-02-16 06:17:40 86,016 ----a-w c:\windows\inf\infstor.dat
- 2008-12-30 18:41:50 143,360 ----a-w c:\windows\inf\infstrng.dat
+ 2009-02-16 06:17:39 143,360 ----a-w c:\windows\inf\infstrng.dat
+ 2009-02-05 04:09:57 10,134 ----a-r c:\windows\Installer\{011A2240-08DF-45BB-AA4E-1A78637CCF80}\ARPPRODUCTICON.exe
- 2007-04-23 20:06:55 25,214 ----a-r c:\windows\Installer\{938B1CD7-7C60-491E-AA90-1F1888168240}\CineMagicShortcut_8E832933A07340209FB8DBADC480B69B.exe
+ 2009-01-13 22:50:38 25,214 ----a-r c:\windows\Installer\{938B1CD7-7C60-491E-AA90-1F1888168240}\CineMagicShortcut_8E832933A07340209FB8DBADC480B69B.exe
- 2007-04-23 20:06:55 25,214 ----a-r c:\windows\Installer\{938B1CD7-7C60-491E-AA90-1F1888168240}\NewShortcut13_8E832933A07340209FB8DBADC480B69B.exe
+ 2009-01-13 22:50:38 25,214 ----a-r c:\windows\Installer\{938B1CD7-7C60-491E-AA90-1F1888168240}\NewShortcut13_8E832933A07340209FB8DBADC480B69B.exe
- 2007-04-23 20:06:55 25,214 ----a-r c:\windows\Installer\{938B1CD7-7C60-491E-AA90-1F1888168240}\NewShortcut15_8E832933A07340209FB8DBADC480B69B.exe
+ 2009-01-13 22:50:38 25,214 ----a-r c:\windows\Installer\{938B1CD7-7C60-491E-AA90-1F1888168240}\NewShortcut15_8E832933A07340209FB8DBADC480B69B.exe
- 2007-04-23 20:06:55 25,214 ----a-r c:\windows\Installer\{938B1CD7-7C60-491E-AA90-1F1888168240}\NewShortcut16_8E832933A07340209FB8DBADC480B69B.exe
+ 2009-01-13 22:50:38 25,214 ----a-r c:\windows\Installer\{938B1CD7-7C60-491E-AA90-1F1888168240}\NewShortcut16_8E832933A07340209FB8DBADC480B69B.exe
- 2007-04-23 20:06:55 25,214 ----a-r c:\windows\Installer\{938B1CD7-7C60-491E-AA90-1F1888168240}\NewShortcut32_8E832933A07340209FB8DBADC480B69B.exe
+ 2009-01-13 22:50:38 25,214 ----a-r c:\windows\Installer\{938B1CD7-7C60-491E-AA90-1F1888168240}\NewShortcut32_8E832933A07340209FB8DBADC480B69B.exe
- 2007-04-23 20:06:55 3,638 ----a-r c:\windows\Installer\{938B1CD7-7C60-491E-AA90-1F1888168240}\NewShortcut38_8E832933A07340209FB8DBADC480B69B.exe
+ 2009-01-13 22:50:38 3,638 ----a-r c:\windows\Installer\{938B1CD7-7C60-491E-AA90-1F1888168240}\NewShortcut38_8E832933A07340209FB8DBADC480B69B.exe
- 2000-08-31 13:00:00 28,672 ----a-w c:\windows\NIRCMD.exe
+ 2000-08-31 12:00:00 29,696 ----a-w c:\windows\NIRCMD.exe
- 2009-01-06 00:44:19 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-03-31 04:57:38 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-01-06 00:44:19 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-03-31 04:57:38 2,048 --sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2008-06-04 07:02:24 262,144 ----a-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\UsrClass.dat
+ 2009-02-10 21:10:55 262,144 ----a-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\UsrClass.dat
- 2009-01-08 20:19:39 1,310,720 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2009-03-31 04:59:44 1,310,720 --sha-w c:\windows\ServiceProfiles\LocalService\NTUSER.DAT
- 2008-06-04 07:03:58 262,144 ----a-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\UsrClass.dat
+ 2009-02-10 21:10:55 262,144 ----a-w c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\UsrClass.dat
- 2009-01-08 20:19:32 1,310,720 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2009-03-31 04:59:38 1,310,720 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
- 2000-08-31 13:00:00 161,792 ----a-w c:\windows\SWREG.exe
+ 2000-08-31 12:00:00 161,792 ----a-w c:\windows\SWREG.exe
- 2007-01-05 14:04:10 466,944 ----a-w c:\windows\System32\capicom.dll
+ 2006-06-15 15:39:18 516,832 ----a-w c:\windows\System32\CapiCom.dll
- 2009-01-06 00:45:16 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-03-06 20:07:17 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-01-06 00:46:07 131,072 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-03-06 20:07:17 229,376 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2007-08-23 09:08:12 262,144 ----a-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\usrclass.dat
+ 2009-02-10 21:10:55 262,144 ----a-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\usrclass.dat
+ 2009-02-10 21:10:55 262,144 ---ha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\usrclass.dat.LOG1
- 2009-01-06 00:45:16 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-03-06 20:07:17 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-01-08 20:13:12 262,144 ----a-w c:\windows\System32\config\systemprofile\ntuser.dat
+ 2009-04-06 00:22:27 262,144 ----a-w c:\windows\System32\config\systemprofile\ntuser.dat
- 2007-02-02 08:00:00 9,464 ----a-w c:\windows\System32\drivers\cdralw2k.sys
+ 2006-10-18 08:00:00 2,560 ----a-w c:\windows\System32\drivers\cdralw2k.sys
+ 2007-04-19 16:36:50 48,384 ----a-w c:\windows\System32\DriverStore\FileRepository\rp_pkt32_mf.inf_5a314f80\rp_pkt32.sys
+ 2007-04-19 16:36:50 48,384 ----a-w c:\windows\System32\DriverStore\FileRepository\rp_pkt32_pf.inf_6e35963d\rp_pkt32.sys
+ 2008-04-24 19:02:36 53,192 ----a-w c:\windows\System32\DriverStore\FileRepository\rp_skt32.inf_fa13ae56\rp_skt32.sys
- 2008-12-12 17:40:11 1,653,440 ----a-w c:\windows\System32\FNTCACHE.DAT
+ 2009-02-02 20:22:53 1,653,440 ----a-w c:\windows\System32\FNTCACHE.DAT
+ 2009-02-03 02:07:18 240,544 ----a-r c:\windows\System32\Macromed\Flash\FlashUtil10b.exe
- 2007-11-21 00:52:38 2,884,992 ----a-w c:\windows\System32\Macromed\Flash\NPSWF32.dll
+ 2009-02-03 02:15:28 3,771,296 ----a-w c:\windows\System32\Macromed\Flash\NPSWF32.dll
- 2007-11-21 00:52:40 218,496 ----a-w c:\windows\System32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2009-02-03 02:15:30 240,544 ----a-w c:\windows\System32\Macromed\Flash\NPSWF32_FlashUtil.exe
+ 2009-03-26 04:44:29 88,590 ----a-w c:\windows\System32\Macromed\Flash\uninstall_activeX.exe
- 2008-02-14 14:24:01 70,264 ----a-w c:\windows\System32\Macromed\Flash\uninstall_plugin.exe
+ 2009-03-03 06:56:12 84,661 ----a-w c:\windows\System32\Macromed\Flash\uninstall_plugin.exe
- 2009-01-07 23:35:08 113,466 ----a-w c:\windows\System32\perfc009.dat
+ 2009-04-01 05:01:26 113,466 ----a-w c:\windows\System32\perfc009.dat
- 2009-01-07 23:35:09 634,344 ----a-w c:\windows\System32\perfh009.dat
+ 2009-04-01 05:01:26 634,344 ----a-w c:\windows\System32\perfh009.dat
- 2008-12-20 07:35:38 6,291,456 ----a-w c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2009-02-15 21:58:04 6,291,456 ----a-w c:\windows\System32\SMI\Store\Machine\schema.dat
- 2009-01-06 00:49:08 13,546 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1513765705-769051305-1750566984-1000_UserData.bin
+ 2009-03-31 04:59:56 15,694 ----a-w c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1513765705-769051305-1750566984-1000_UserData.bin
- 2009-01-06 00:49:07 64,176 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-03-31 04:59:56 67,358 ----a-w c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-01-06 00:48:47 51,238 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-03-31 04:59:52 55,312 ----a-w c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
- 2008-07-05 20:51:45 51,056 ----a-w c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2009-01-09 02:26:41 75,528 ----a-w c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
- 2008-12-20 07:39:34 136,124,782 ----a-w c:\windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
+ 2009-02-10 23:04:24 136,148,654 ----a-w c:\windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
+ 2009-02-10 23:03:46 161,784 ----a-w c:\windows\winsxs\x86_microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_none_e29d1181971ae11e\ATL90.dll
+ 2009-02-10 23:03:57 225,280 ----a-w c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada\msvcm90.dll
+ 2009-02-10 23:03:57 572,928 ----a-w c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada\msvcp90.dll
+ 2009-02-10 23:03:57 655,872 ----a-w c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada\msvcr90.dll
+ 2009-02-10 23:04:14 312,832 ----a-w c:\windows\winsxs\x86_microsoft.vc90.debugcrt_1fc8b3b9a1e18e3b_9.0.30729.1_none_bb1f6aa1308c35eb\msvcm90d.dll
+ 2009-02-10 23:04:14 875,520 ----a-w c:\windows\winsxs\x86_microsoft.vc90.debugcrt_1fc8b3b9a1e18e3b_9.0.30729.1_none_bb1f6aa1308c35eb\msvcp90d.dll
+ 2009-02-10 23:04:14 1,180,672 ----a-w c:\windows\winsxs\x86_microsoft.vc90.debugcrt_1fc8b3b9a1e18e3b_9.0.30729.1_none_bb1f6aa1308c35eb\msvcr90d.dll
+ 2009-02-10 23:04:19 5,937,144 ----a-w c:\windows\winsxs\x86_microsoft.vc90.debugmfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_bfff6c932d60651e\mfc90d.dll
+ 2009-02-10 23:04:19 5,982,720 ----a-w c:\windows\winsxs\x86_microsoft.vc90.debugmfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_bfff6c932d60651e\mfc90ud.dll
+ 2009-02-10 23:04:19 80,896 ----a-w c:\windows\winsxs\x86_microsoft.vc90.debugmfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_bfff6c932d60651e\mfcm90d.dll
+ 2009-02-10 23:04:19 80,896 ----a-w c:\windows\winsxs\x86_microsoft.vc90.debugmfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_bfff6c932d60651e\mfcm90ud.dll
+ 2009-02-10 23:04:02 3,768,312 ----a-w c:\windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf\mfc90.dll
+ 2009-02-10 23:04:01 3,783,672 ----a-w c:\windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf\mfc90u.dll
+ 2009-02-10 23:04:01 59,904 ----a-w c:\windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf\mfcm90.dll
+ 2009-02-10 23:04:02 59,904 ----a-w c:\windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf\mfcm90u.dll
+ 2009-02-10 23:04:08 38,912 ----a-w c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90CHS.DLL
+ 2009-02-10 23:04:08 39,936 ----a-w c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90CHT.DLL
+ 2009-02-10 23:04:08 66,560 ----a-w c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90DEU.DLL
+ 2009-02-10 23:04:08 56,832 ----a-w c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90ENU.DLL
+ 2009-02-10 23:04:08 65,024 ----a-w c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90ESN.DLL
+ 2009-02-10 23:04:08 65,024 ----a-w c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90ESP.DLL
+ 2009-02-10 23:04:08 66,048 ----a-w c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90FRA.DLL
+ 2009-02-10 23:04:08 64,512 ----a-w c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90ITA.DLL
+ 2009-02-10 23:04:08 46,592 ----a-w c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90JPN.DLL
+ 2009-02-10 23:04:09 46,080 ----a-w c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90KOR.DLL
+ 2009-02-10 23:04:09 62,976 ----a-w c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90RUS.DLL
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-03-26 1277584]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.i420"= i420vfw.dll
"vidc.MJPG"= m3jpeg32.dll
"vidc.dmb1"= m3jpeg32.dll
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2008-05-22 15:49 13539872 c:\windows\System32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2008-05-22 15:49 92704 c:\windows\System32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvSvc]
--a------ 2008-05-22 15:49 526880 c:\windows\System32\nvsvc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-11-10 06:43 136600 c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
--a------ 2008-01-15 11:26 4874240 c:\windows\RtHDVCpl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{A2BA7BB0-0A5D-4AD1-A567-9CDB56C66DA4}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{B7CFD448-8992-4C98-A715-056437C829ED}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{883B765C-92CD-4879-8402-E0FC1F059436}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{4FA0E868-3BCF-4380-A754-A522F3EC9FE5}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{B1A873B2-04D8-4433-9227-4B0E81AA9A49}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{3B844328-D30C-4F0D-B0E2-4A50DC50570D}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{8C61405D-C85F-4BBE-A6A5-5A1BD6819583}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{4378B205-0E33-461A-B353-842AAF0C3B03}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{7363932D-9202-413D-9C62-BEAA3D7D3B3E}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{088FADAB-A564-43D2-8A74-7D715182C659}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{97216739-CC2B-4D26-B138-0E1E3FC68355}"= UDP:c:\program files\Morpheus\Morpheus.exe:Morpheus
"{94006A0A-5DE5-46E1-8CEB-BC99F853A35E}"= TCP:c:\program files\Morpheus\Morpheus.exe:Morpheus
"{808F4B56-9285-4394-B34C-6F115E757E83}"= UDP:c:\program files\Lavasoft\Ad-Aware 2007\Ad-Aware2007.exe:Ad-Aware 2007
"{026ED870-B1D7-441E-B6A0-2472B900C617}"= TCP:c:\program files\Lavasoft\Ad-Aware 2007\Ad-Aware2007.exe:Ad-Aware 2007
"{4821D79F-52A3-442B-9C47-6957C70510DE}"= UDP:c:\program files\AOL\RC\regclient.exe:AOL
"{C8949732-4A6C-435D-9A9F-A6F151D9A25C}"= TCP:c:\program files\AOL\RC\regclient.exe:AOL
"{ECE8BBFE-0066-4801-92E8-0858A9421EA1}"= UDP:c:\program files\Common Files\AOL\ACS\AOLDial.exe:AOL Connectivity Service Dialer
"{FC581E53-2EE5-4E64-80D9-9289A266B86A}"= TCP:c:\program files\Common Files\AOL\ACS\AOLDial.exe:AOL Connectivity Service Dialer
"{066587AD-58B6-4A83-BB37-483380C1379C}"= UDP:c:\program files\Common Files\AOL\ACS\AOLacsd.exe:AOL Connectivity Service
"{15619F1D-E646-4000-B8EC-899B250DBA20}"= TCP:c:\program files\Common Files\AOL\ACS\AOLacsd.exe:AOL Connectivity Service
"TCP Query User{562674CC-DE7B-42BB-8524-59F1340F4142}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{10A792E6-15A5-4B33-ADF0-33A13EE95DCD}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"TCP Query User{BF3CAFC7-DB97-4D29-9BB9-10D7F86E587F}c:\\program files\\java\\jre1.6.0_03\\bin\\javaw.exe"= UDP:c:\program files\java\jre1.6.0_03\bin\javaw.exe:Java Platform SE binary
"UDP Query User{9702843F-D890-4A5E-92E2-8B66AED93B14}c:\\program files\\java\\jre1.6.0_03\\bin\\javaw.exe"= TCP:c:\program files\java\jre1.6.0_03\bin\javaw.exe:Java Platform SE binary
"TCP Query User{D61F5E30-0F44-4723-ACF8-19423F0CB1D2}c:\\program files\\veoh networks\\veoh\\veohclient.exe"= UDP:c:\program files\veoh networks\veoh\veohclient.exe:Veoh Client
"UDP Query User{A2A5D206-78D2-40D7-985C-3446A51667CB}c:\\program files\\veoh networks\\veoh\\veohclient.exe"= TCP:c:\program files\veoh networks\veoh\veohclient.exe:Veoh Client
"TCP Query User{4982591D-4AF0-4D4D-B001-88FF026CFACE}c:\\program files\\java\\jre1.6.0_05\\bin\\javaw.exe"= UDP:c:\program files\java\jre1.6.0_05\bin\javaw.exe:Java Platform SE binary
"UDP Query User{493AF747-84E6-4AD4-B0E7-3DB838BC0F8D}c:\\program files\\java\\jre1.6.0_05\\bin\\javaw.exe"= TCP:c:\program files\java\jre1.6.0_05\bin\javaw.exe:Java Platform SE binary
"TCP Query User{CC33E543-43BA-4889-BADC-96B0B909230E}c:\\program files\\azureus\\azureus.exe"= UDP:c:\program files\azureus\azureus.exe:Azureus
"UDP Query User{26E0974F-B888-4EB5-9324-523F2E245395}c:\\program files\\azureus\\azureus.exe"= TCP:c:\program files\azureus\azureus.exe:Azureus
"{E128AAF2-C17B-4EC8-B0F6-946EF6050461}"= c:\program files\HP\DVDPlay\DVDPlay.exe:DVD Play
"{F68BA7EE-6F2A-4E14-AE06-5F3B35F45F2B}"= c:\program files\HP\DVDPlay\DPService.exe:DVD Play Resident Program
"TCP Query User{A570943C-6C7B-4246-B57D-3B4AF7153747}c:\\program files\\frostwire\\frostwire.exe"= UDP:c:\program files\frostwire\frostwire.exe:FrostWire
"UDP Query User{9739A281-5D94-49D1-8EEF-EC3C8EEDAE13}c:\\program files\\frostwire\\frostwire.exe"= TCP:c:\program files\frostwire\frostwire.exe:FrostWire
"TCP Query User{E5A1B727-1D01-4F52-83A8-72DA7E89C77E}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{0CD605F2-9D58-4052-AAF8-E4DC475D54DF}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"TCP Query User{6EACC334-A68E-484D-A30E-B2556F2C8CB4}c:\\program files\\nero\\nero8\\nero home\\nerohome.exe"= UDP:c:\program files\nero\nero8\nero home\nerohome.exe:Nero Home
"UDP Query User{4DA2CC8D-D02D-48F7-9C02-50FEC1B8930C}c:\\program files\\nero\\nero8\\nero home\\nerohome.exe"= TCP:c:\program files\nero\nero8\nero home\nerohome.exe:Nero Home
"TCP Query User{08E8B9C1-4209-45ED-8870-BBE64E25E8EC}c:\\program files\\vuze\\azureus.exe"= UDP:c:\program files\vuze\azureus.exe:Azureus
"UDP Query User{84B50661-18D4-4EA7-8F21-103627036011}c:\\program files\\vuze\\azureus.exe"= TCP:c:\program files\vuze\azureus.exe:Azureus
"{A3F46323-D90F-40CE-88C2-311245A9C554}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{4E1F0F99-CE18-42B8-B6AA-5AB74FB17ECA}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{4FA23331-E858-4BD5-8C2B-C1D65F74747C}"= UDP:c:\program files\AIM6\aim6.exe:AIM
"{2035F4CB-C2D0-4CCA-B316-CC3931831B60}"= TCP:c:\program files\AIM6\aim6.exe:AIM
"{13A4D7E0-ACEF-4E44-9C46-550DC9000365}"= c:\program files\AVG\AVG8\avgemc.exe:avgemc.exe
"{563B6F97-FC8A-4703-BA45-E88D933CFD15}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"TCP Query User{2AD02F10-E8C2-4FAB-8AF7-63801ADE37DC}c:\\program files\\aim6\\aim6.exe"= UDP:c:\program files\aim6\aim6.exe:AIM
"UDP Query User{ABF539AC-5702-474D-955D-92AC4C64720A}c:\\program files\\aim6\\aim6.exe"= TCP:c:\program files\aim6\aim6.exe:AIM
"TCP Query User{ADB9E731-8381-4A2E-83F7-064F3B3BDF16}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:µTorrent
"UDP Query User{11FA901B-6170-4F2D-860E-0F24333E3B03}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:µTorrent
"{DEA35D61-FDB4-4A0F-9586-FB79E5894FE0}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{1F7DF5A4-20B5-4B7C-9539-F3CCF4D047A4}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"TCP Query User{80302A4F-2A52-4C93-A5AA-813773BF0C70}c:\\program files\\frostwire\\frostwire.exe"= UDP:c:\program files\frostwire\frostwire.exe:FrostWire
"UDP Query User{13136431-27AF-43A7-A7CE-5CC34E483BF9}c:\\program files\\frostwire\\frostwire.exe"= TCP:c:\program files\frostwire\frostwire.exe:FrostWire
"{C3632E97-7F8C-498E-8040-F67E99F15B49}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{CBC31017-F303-4487-AD57-F2B64F63D15A}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Configurable\System]
"Rip-Listener-1"= TCP:520|%SystemRoot%\System32\svchost.exe|Svc=iprip:@iprip.dll,-200|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"SNMP-1"= TCP:%SystemRoot%\system32\snmp.exe|Svc=SNMP:@%SystemRoot%\system32\snmp.exe,-5|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= c:\program files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink
R3 AvgWfpX;AVG Free8 Firewall Driver x86;c:\windows\System32\Drivers\avgwfpx.sys [2008-11-15 69128]
R3 Partizan;Partizan;c:\windows\system32\drivers\Partizan.sys [2008-12-17 30946]
R3 s125bus;Sony Ericsson Device 125 driver (WDM);c:\windows\system32\DRIVERS\s125bus.sys [2007-04-24 83336]
R4 avg8emc;AVG Free8 E-mail Scanner; [x]
R4 avg8wd;AVG Free8 WatchDog; [x]
R4 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-08-29 33752]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2008-11-15 97928]
--- Other Services/Drivers In Memory ---
*Deregistered* - AFD
*Deregistered* - AvgLdx86
*Deregistered* - AvgMfx86
*Deregistered* - Beep
*Deregistered* - bowser
*Deregistered* - cdfs
*Deregistered* - CLFS
*Deregistered* - crcdisk
*Deregistered* - DfsC
*Deregistered* - DXGKrnl
*Deregistered* - Ecache
*Deregistered* - fastfat
*Deregistered* - FileInfo
*Deregistered* - FltMgr
*Deregistered* - HTTP
*Deregistered* - IpFilterDriver
*Deregistered* - iScsiPrt
*Deregistered* - KSecDD
*Deregistered* - lltdio
*Deregistered* - luafv
*Deregistered* - MountMgr
*Deregistered* - mpsdrv
*Deregistered* - MRxDAV
*Deregistered* - mrxsmb
*Deregistered* - mrxsmb10
*Deregistered* - mrxsmb20
*Deregistered* - Msfs
*Deregistered* - msisadrv
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NativeWifiP
*Deregistered* - NDIS
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - netbt
*Deregistered* - Npfs
*Deregistered* - nsiproxy
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - PEAUTH
*Deregistered* - PptpMiniport
*Deregistered* - PSched
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasPppoe
*Deregistered* - RasSstp
*Deregistered* - rdbss
*Deregistered* - RDPCDD
*Deregistered* - RDPENCDD
*Deregistered* - rspndr
*Deregistered* - secdrv
*Deregistered* - Smb
*Deregistered* - spldr
*Deregistered* - srv
*Deregistered* - srv2
*Deregistered* - srvnet
*Deregistered* - swenum
*Deregistered* - Tcpip
*Deregistered* - tcpipreg
*Deregistered* - tdx
*Deregistered* - TermDD
*Deregistered* - tunmp
*Deregistered* - tunnel
*Deregistered* - udfs
*Deregistered* - umbus
*Deregistered* - VgaSave
*Deregistered* - volmgr
*Deregistered* - volmgrx
*Deregistered* - volsnap
*Deregistered* - Wanarpv6
*Deregistered* - Wdf01000
*Deregistered* - XAudio
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
rsmsvcs REG_MULTI_SZ ntmssvc
ipripsvc REG_MULTI_SZ iprip
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0f213baf-55aa-11dd-b641-00038a000015}]
\shell\AutoRun\command - H:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
2009-03-31 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe []
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-SmartAccess AutoStart - c:\program files\Verizon\DSL\SmartAccess\DSL.exe
MSConfigStartUp-Corel Photo Downloader - c:\program files\Common Files\Corel\Corel PhotoDownloader\Corel PhotoDownloader.exe
MSConfigStartUp-HP Software Update - c:\program files\HP\HP Software Update\HPWuSchd2.exe
MSConfigStartUp-NeroFilterCheck - c:\program files\Common Files\Nero\Lib\NeroCheck.exe
MSConfigStartUp-OneCareUI - c:\program files\Microsoft Windows OneCare Live\winssnotify.exe
MSConfigStartUp-QuickTime Task - c:\program files\QuickTime\QTTask.exe
MSConfigStartUp-SpybotSD TeaTimer - c:\program files\Spybot - Search & Destroy\TeaTimer.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.igoogle.com/
mStart Page = hxxp://www.yahoo.com
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-05 20:31:43
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1536)
c:\windows\system32\avgrsstx.dll
- - - - - - - > 'lsass.exe'(628)
c:\windows\system32\avgrsstx.dll
.
Completion time: 2009-04-05 20:35:05
ComboFix-quarantined-files.txt 2009-04-06 00:35:01
ComboFix2.txt 2009-01-08 20:24:13
Pre-Run: 55,701,966,848 bytes free
Post-Run: 55,772,364,800 bytes free
418 --- E O F --- 2008-10-31 06:21:17
Malwarebytes' Anti-Malware 1.35
Database version: 1904
Windows 6.0.6001 Service Pack 1
2009-04-05 20:31:07
mbam-log-2009-04-05 (20-31-07).txt
Scan type: Quick Scan
Objects scanned: 58826
Time elapsed: 16 minute(s), 39 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 4
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DhcpNameServer (Trojan.DNSChanger) -> Data: 0.255.112.191 85.255.112.181 1.2.3.4 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{da1b2d63-45df-4b40-bd10-3344d82e2f88}\DhcpNameServer (Trojan.DNSChanger) -> Data: 0.255.112.191 85.255.112.181 1.2.3.4 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\DhcpNameServer (Trojan.DNSChanger) -> Data: 0.255.112.191 85.255.112.181 1.2.3.4 -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{da1b2d63-45df-4b40-bd10-3344d82e2f88}\DhcpNameServer (Trojan.DNSChanger) -> Data: 0.255.112.191 85.255.112.181 1.2.3.4 -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)


Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked
Back to top











