ComboFix 11-11-17.03 - Kay 17/11/2011 19:53:41.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.767.409 [GMT 0:00]
Running from: d:\documents and settings\Kay\Desktop\ComboFix.exe
Command switches used :: d:\documents and settings\Kay\Desktop\CFScript.txt
.
FILE ::
"c:\windows\system32\drivers\OLD63.tmp"
.
.
((((((((((((((((((((((((( Files Created from 2011-10-17 to 2011-11-17 )))))))))))))))))))))))))))))))
.
.
2011-11-17 19:20 . 2011-11-17 19:20 20719 ----a-w- d:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\DIVWRAPPER.JS
2011-11-17 19:20 . 2011-11-17 19:20 23327 ----a-w- d:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\COMBOBOX.JS
2011-11-17 19:20 . 2011-11-17 19:20 7271 ----a-w- d:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\CHECKBOX.JS
2011-11-17 19:20 . 2011-11-17 19:20 8782 ----a-w- d:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\BUTTON.JS
2011-11-15 19:35 . 2008-04-14 00:11 21504 ----a-w- c:\windows\system32\hidserv.dll
2011-11-15 19:35 . 2008-04-14 00:11 21504 ----a-w- c:\windows\system32\dllcache\hidserv.dll
2011-10-30 15:47 . 2011-11-13 16:26 -------- d-----w- c:\program files\Panda Security
2011-10-30 15:01 . 2011-10-30 15:02 -------- d-----w- c:\program files\Unlocker
2011-10-30 13:31 . 2011-10-30 13:31 388096 ----a-r- d:\documents and settings\Kay\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-10-30 13:31 . 2011-10-30 13:31 -------- d-----w- c:\program files\Trend Micro
2011-10-29 12:46 . 2011-10-29 12:46 -------- d-----w- d:\documents and settings\NetworkService\Local Settings\Application Data\PCHealth
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-10 14:22 . 2004-08-10 16:56 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-10-10 09:03 . 2008-05-27 14:41 83360 ----a-w- c:\windows\system32\LMIRfsClientNP.dll
2011-10-10 09:03 . 2008-05-27 14:41 52096 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\LMIproc.dll
2011-10-10 09:02 . 2008-05-27 14:41 30592 ----a-w- c:\windows\system32\LMIport.dll
2011-10-10 09:02 . 2008-05-27 14:41 87424 ----a-w- c:\windows\system32\LMIinit.dll
2011-10-06 09:49 . 2011-10-06 09:49 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-28 07:06 . 2004-08-10 16:37 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 10:41 . 2008-07-29 19:59 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 10:41 . 2004-08-10 16:38 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-26 10:41 . 2004-08-10 16:38 20480 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-06 13:20 . 2004-08-10 16:38 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-08-31 16:00 . 2010-04-17 10:33 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
.
.
((((((((((((((((((((((((((((( SnapShot_2011-11-13_13.26.26 )))))))))))))))))))))))))))))))))))))))))
.
+ 2004-08-10 16:38 . 2011-08-17 21:32 44544 c:\windows\system32\pngfilt.dll
- 2004-08-10 16:38 . 2009-03-08 03:31 48128 c:\windows\system32\mshtmler.dll
+ 2004-08-10 16:38 . 2006-10-17 10:28 48128 c:\windows\system32\mshtmler.dll
- 2004-08-10 16:38 . 2009-03-08 03:31 45568 c:\windows\system32\mshta.exe
+ 2004-08-10 16:38 . 2006-10-17 10:56 45568 c:\windows\system32\mshta.exe
+ 2006-10-17 10:58 . 2006-10-17 10:58 12288 c:\windows\system32\msfeedssync.exe
+ 2006-11-07 20:03 . 2011-08-17 21:32 52224 c:\windows\system32\msfeedsbs.dll
+ 2004-08-10 16:37 . 2006-10-17 11:05 40960 c:\windows\system32\licmgr10.dll
+ 2004-08-10 16:37 . 2011-08-17 21:32 27648 c:\windows\system32\jsproxy.dll
+ 2004-08-10 16:37 . 2006-11-07 02:26 92672 c:\windows\system32\inseng.dll
+ 2004-08-10 16:37 . 2006-10-17 10:57 36352 c:\windows\system32\imgutil.dll
+ 2004-08-10 16:37 . 2006-11-07 02:26 55296 c:\windows\system32\iesetup.dll
+ 2004-08-10 16:37 . 2011-08-17 21:32 44544 c:\windows\system32\iernonce.dll
+ 2011-07-17 13:42 . 2011-08-17 21:32 78336 c:\windows\system32\ieencode.dll
+ 2004-08-10 16:37 . 2011-08-17 12:21 70656 c:\windows\system32\ie4uinit.exe
+ 2006-10-17 10:58 . 2011-08-17 21:32 63488 c:\windows\system32\icardie.dll
+ 2006-05-10 05:25 . 2011-08-17 21:32 44544 c:\windows\system32\dllcache\pngfilt.dll
+ 2006-10-17 10:28 . 2006-10-17 10:28 48128 c:\windows\system32\dllcache\mshtmler.dll
- 2006-10-17 10:28 . 2009-03-08 03:31 48128 c:\windows\system32\dllcache\mshtmler.dll
- 2006-10-17 10:56 . 2009-03-08 03:31 45568 c:\windows\system32\dllcache\mshta.exe
+ 2006-10-17 10:56 . 2006-10-17 10:56 45568 c:\windows\system32\dllcache\mshta.exe
+ 2007-05-20 13:12 . 2011-08-17 21:32 52224 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2004-08-10 16:37 . 2006-10-17 11:05 40960 c:\windows\system32\dllcache\licmgr10.dll
+ 2004-08-10 16:37 . 2011-08-17 21:32 27648 c:\windows\system32\dllcache\jsproxy.dll
+ 2004-08-10 16:37 . 2006-11-07 02:26 92672 c:\windows\system32\dllcache\inseng.dll
+ 2006-10-17 10:57 . 2006-10-17 10:57 36352 c:\windows\system32\dllcache\imgutil.dll
- 2007-05-20 13:12 . 2011-04-25 12:00 13824 c:\windows\system32\dllcache\ieudinit.exe
+ 2007-05-20 13:12 . 2011-08-17 12:21 13824 c:\windows\system32\dllcache\ieudinit.exe
+ 2004-08-10 16:37 . 2006-11-07 02:26 55296 c:\windows\system32\dllcache\iesetup.dll
+ 2004-08-10 16:37 . 2011-08-17 21:32 44544 c:\windows\system32\dllcache\iernonce.dll
+ 2011-07-17 13:42 . 2011-08-17 21:32 78336 c:\windows\system32\dllcache\ieencode.dll
+ 2006-11-07 02:26 . 2011-08-17 12:21 70656 c:\windows\system32\dllcache\ie4uinit.exe
+ 2007-08-20 10:04 . 2011-08-17 21:32 63488 c:\windows\system32\dllcache\icardie.dll
+ 2004-08-10 16:56 . 2006-10-17 10:44 60416 c:\windows\system32\dllcache\hmmapi.dll
+ 2009-06-29 16:12 . 2011-08-17 21:32 17408 c:\windows\system32\dllcache\corpol.dll
+ 2004-08-10 16:37 . 2006-11-07 02:26 71680 c:\windows\system32\dllcache\admparse.dll
+ 2004-08-10 16:37 . 2011-08-17 21:32 17408 c:\windows\system32\corpol.dll
+ 2004-08-10 16:37 . 2006-11-07 02:26 71680 c:\windows\system32\admparse.dll
+ 2011-11-15 19:39 . 2011-04-25 15:51 44544 c:\windows\ie7updates\KB2586448-IE7\pngfilt.dll
+ 2011-11-15 19:39 . 2011-04-25 15:51 52224 c:\windows\ie7updates\KB2586448-IE7\msfeedsbs.dll
+ 2011-11-15 19:39 . 2011-04-25 15:51 27648 c:\windows\ie7updates\KB2586448-IE7\jsproxy.dll
+ 2011-11-15 19:39 . 2011-04-25 12:00 13824 c:\windows\ie7updates\KB2586448-IE7\ieudinit.exe
+ 2011-11-15 19:39 . 2011-04-25 15:51 44544 c:\windows\ie7updates\KB2586448-IE7\iernonce.dll
+ 2011-11-15 19:39 . 2011-04-25 15:51 78336 c:\windows\ie7updates\KB2586448-IE7\ieencode.dll
+ 2011-11-15 19:39 . 2011-04-25 12:00 70656 c:\windows\ie7updates\KB2586448-IE7\ie4uinit.exe
+ 2011-11-15 19:39 . 2011-04-25 15:51 63488 c:\windows\ie7updates\KB2586448-IE7\icardie.dll
+ 2011-11-15 19:39 . 2011-04-25 15:51 17408 c:\windows\ie7updates\KB2586448-IE7\corpol.dll
+ 2004-08-10 16:38 . 2011-08-17 21:32 832512 c:\windows\system32\wininet.dll
+ 2006-10-17 11:05 . 2006-10-17 11:05 206336 c:\windows\system32\winfxdocobj.exe
+ 2004-08-10 16:38 . 2011-08-17 21:32 233472 c:\windows\system32\webcheck.dll
+ 2004-08-10 16:38 . 2011-03-04 06:45 434176 c:\windows\system32\vbscript.dll
+ 2004-08-10 16:38 . 2011-08-17 21:32 106496 c:\windows\system32\url.dll
+ 2004-08-10 16:38 . 2011-08-17 21:32 102912 c:\windows\system32\occache.dll
+ 2004-08-10 16:38 . 2011-08-17 21:32 671232 c:\windows\system32\mstime.dll
+ 2004-08-10 16:38 . 2011-08-17 21:32 193024 c:\windows\system32\msrating.dll
- 2004-08-10 16:38 . 2009-03-08 03:22 156160 c:\windows\system32\msls31.dll
+ 2004-08-10 16:38 . 2006-11-07 20:03 156160 c:\windows\system32\msls31.dll
+ 2004-08-10 16:38 . 2011-08-17 21:32 478720 c:\windows\system32\mshtmled.dll
+ 2006-11-07 20:03 . 2011-08-17 21:32 468480 c:\windows\system32\msfeeds.dll
+ 2004-08-10 16:37 . 2011-03-04 06:45 512000 c:\windows\system32\jscript.dll
+ 2006-11-07 20:03 . 2006-11-07 20:03 180736 c:\windows\system32\ieui.dll
+ 2006-10-17 10:57 . 2011-08-17 21:32 268288 c:\windows\system32\iertutil.dll
+ 2004-08-10 16:37 . 2011-08-17 21:32 192512 c:\windows\system32\iepeers.dll
+ 2004-08-10 16:37 . 2011-08-17 21:32 384512 c:\windows\system32\iedkcs32.dll
+ 2006-10-17 10:27 . 2011-08-17 21:32 380928 c:\windows\system32\ieapfltr.dll
+ 2004-08-10 16:37 . 2011-08-17 11:00 161792 c:\windows\system32\ieakui.dll
+ 2004-08-10 16:37 . 2011-08-17 21:32 230400 c:\windows\system32\ieaksie.dll
+ 2004-08-10 16:37 . 2011-08-17 21:32 153088 c:\windows\system32\ieakeng.dll
+ 2004-08-10 16:37 . 2011-08-17 21:32 133120 c:\windows\system32\extmgr.dll
- 2004-08-10 16:37 . 2011-04-25 15:51 133120 c:\windows\system32\extmgr.dll
+ 2004-08-10 16:37 . 2011-08-17 21:32 214528 c:\windows\system32\dxtrans.dll
+ 2004-08-10 16:37 . 2011-08-17 21:32 347136 c:\windows\system32\dxtmsft.dll
+ 2006-05-10 05:25 . 2011-08-17 21:32 832512 c:\windows\system32\dllcache\wininet.dll
+ 2006-11-07 20:03 . 2011-08-17 21:32 233472 c:\windows\system32\dllcache\webcheck.dll
+ 2004-08-10 16:56 . 2011-04-30 08:50 766464 c:\windows\system32\dllcache\vgx.dll
+ 2008-05-09 10:53 . 2011-03-04 06:45 434176 c:\windows\system32\dllcache\vbscript.dll
+ 2006-10-17 11:05 . 2011-08-17 21:32 106496 c:\windows\system32\dllcache\url.dll
+ 2006-10-17 11:04 . 2011-08-17 21:32 102912 c:\windows\system32\dllcache\occache.dll
+ 2004-08-10 16:38 . 2011-08-17 21:32 671232 c:\windows\system32\dllcache\mstime.dll
+ 2006-05-10 05:25 . 2011-08-17 21:32 193024 c:\windows\system32\dllcache\msrating.dll
+ 2006-11-07 20:03 . 2006-11-07 20:03 156160 c:\windows\system32\dllcache\msls31.dll
- 2006-11-07 20:03 . 2009-03-08 03:22 156160 c:\windows\system32\dllcache\msls31.dll
+ 2006-05-10 05:25 . 2011-08-17 21:32 478720 c:\windows\system32\dllcache\mshtmled.dll
+ 2007-05-20 13:12 . 2011-08-17 21:32 468480 c:\windows\system32\dllcache\msfeeds.dll
+ 2008-05-09 10:53 . 2011-03-04 06:45 512000 c:\windows\system32\dllcache\jscript.dll
+ 2008-08-15 08:01 . 2011-10-10 14:22 692736 c:\windows\system32\dllcache\inetcomm.dll
- 2008-08-15 08:01 . 2011-05-02 15:31 692736 c:\windows\system32\dllcache\inetcomm.dll
+ 2006-10-17 11:04 . 2011-08-17 11:01 634632 c:\windows\system32\dllcache\iexplore.exe
+ 2007-05-20 13:12 . 2011-08-17 21:32 268288 c:\windows\system32\dllcache\iertutil.dll
+ 2006-05-10 05:25 . 2011-08-17 21:32 192512 c:\windows\system32\dllcache\iepeers.dll
+ 2006-11-07 02:27 . 2011-08-17 21:32 384512 c:\windows\system32\dllcache\iedkcs32.dll
+ 2007-05-20 13:12 . 2011-08-17 21:32 380928 c:\windows\system32\dllcache\ieapfltr.dll
+ 2004-08-10 16:37 . 2011-08-17 11:00 161792 c:\windows\system32\dllcache\ieakui.dll
+ 2004-08-10 16:37 . 2011-08-17 21:32 230400 c:\windows\system32\dllcache\ieaksie.dll
+ 2004-08-10 16:37 . 2011-08-17 21:32 153088 c:\windows\system32\dllcache\ieakeng.dll
- 2004-08-10 16:37 . 2011-04-25 15:51 133120 c:\windows\system32\dllcache\extmgr.dll
+ 2004-08-10 16:37 . 2011-08-17 21:32 133120 c:\windows\system32\dllcache\extmgr.dll
+ 2006-05-10 05:25 . 2011-08-17 21:32 214528 c:\windows\system32\dllcache\dxtrans.dll
+ 2006-05-10 05:25 . 2011-08-17 21:32 347136 c:\windows\system32\dllcache\dxtmsft.dll
- 2011-09-03 10:17 . 2011-09-09 09:12 599040 c:\windows\system32\dllcache\crypt32.dll
+ 2011-09-03 10:17 . 2011-09-28 07:06 599040 c:\windows\system32\dllcache\crypt32.dll
+ 2006-11-07 02:26 . 2011-08-17 21:32 124928 c:\windows\system32\dllcache\advpack.dll
+ 2004-08-10 16:37 . 2011-08-17 21:32 124928 c:\windows\system32\advpack.dll
+ 2011-11-15 19:39 . 2011-04-25 15:51 832512 c:\windows\ie7updates\KB2586448-IE7\wininet.dll
+ 2011-11-15 19:39 . 2011-04-25 15:51 233472 c:\windows\ie7updates\KB2586448-IE7\webcheck.dll
+ 2011-11-15 19:39 . 2011-04-25 15:51 105984 c:\windows\ie7updates\KB2586448-IE7\url.dll
+ 2011-11-15 19:39 . 2010-07-05 13:16 382840 c:\windows\ie7updates\KB2586448-IE7\spuninst\updspapi.dll
+ 2011-11-15 19:39 . 2010-07-05 13:15 231288 c:\windows\ie7updates\KB2586448-IE7\spuninst\spuninst.exe
+ 2011-11-15 19:39 . 2011-04-25 15:51 102912 c:\windows\ie7updates\KB2586448-IE7\occache.dll
+ 2011-11-15 19:39 . 2011-04-25 15:51 671232 c:\windows\ie7updates\KB2586448-IE7\mstime.dll
+ 2011-11-15 19:39 . 2011-04-25 15:51 193024 c:\windows\ie7updates\KB2586448-IE7\msrating.dll
+ 2011-11-15 19:39 . 2011-04-25 15:51 478208 c:\windows\ie7updates\KB2586448-IE7\mshtmled.dll
+ 2011-11-15 19:39 . 2011-04-25 15:51 468480 c:\windows\ie7updates\KB2586448-IE7\msfeeds.dll
+ 2011-11-15 19:39 . 2011-04-21 10:58 634648 c:\windows\ie7updates\KB2586448-IE7\iexplore.exe
+ 2011-11-15 19:39 . 2011-04-25 15:51 268288 c:\windows\ie7updates\KB2586448-IE7\iertutil.dll
+ 2011-11-15 19:39 . 2011-04-25 15:51 192512 c:\windows\ie7updates\KB2586448-IE7\iepeers.dll
+ 2011-11-15 19:39 . 2011-04-25 15:51 384512 c:\windows\ie7updates\KB2586448-IE7\iedkcs32.dll
+ 2011-11-15 19:39 . 2011-04-25 15:51 380928 c:\windows\ie7updates\KB2586448-IE7\ieapfltr.dll
+ 2011-11-15 19:39 . 2011-04-21 10:56 161792 c:\windows\ie7updates\KB2586448-IE7\ieakui.dll
+ 2011-11-15 19:39 . 2011-04-25 15:51 230400 c:\windows\ie7updates\KB2586448-IE7\ieaksie.dll
+ 2011-11-15 19:39 . 2011-04-25 15:51 153088 c:\windows\ie7updates\KB2586448-IE7\ieakeng.dll
+ 2011-11-15 19:39 . 2011-04-25 15:51 133120 c:\windows\ie7updates\KB2586448-IE7\extmgr.dll
+ 2011-11-15 19:39 . 2011-04-25 15:51 214528 c:\windows\ie7updates\KB2586448-IE7\dxtrans.dll
+ 2011-11-15 19:39 . 2011-04-25 15:51 347136 c:\windows\ie7updates\KB2586448-IE7\dxtmsft.dll
+ 2011-11-15 19:39 . 2011-04-25 15:51 124928 c:\windows\ie7updates\KB2586448-IE7\advpack.dll
+ 2011-07-17 13:42 . 2006-09-06 15:43 213216 c:\windows\ie7\spuninst\spuninst.exe
+ 2004-08-10 16:38 . 2011-08-17 21:32 1168896 c:\windows\system32\urlmon.dll
+ 2004-08-10 16:38 . 2011-09-05 07:48 3615744 c:\windows\system32\mshtml.dll
+ 2006-11-07 20:03 . 2011-08-17 21:32 6076416 c:\windows\system32\ieframe.dll
+ 2006-09-05 22:01 . 2009-06-29 08:33 2452872 c:\windows\system32\ieapfltr.dat
+ 2006-05-10 05:25 . 2011-08-17 21:32 1168896 c:\windows\system32\dllcache\urlmon.dll
+ 2006-05-19 15:06 . 2011-09-05 07:48 3615744 c:\windows\system32\dllcache\mshtml.dll
+ 2007-05-20 13:12 . 2011-08-17 21:32 6076416 c:\windows\system32\dllcache\ieframe.dll
+ 2007-05-20 13:12 . 2009-06-29 08:33 2452872 c:\windows\system32\dllcache\ieapfltr.dat
+ 2011-11-15 19:39 . 2011-04-25 15:51 1168896 c:\windows\ie7updates\KB2586448-IE7\urlmon.dll
+ 2011-11-15 19:39 . 2011-04-25 15:51 3608576 c:\windows\ie7updates\KB2586448-IE7\mshtml.dll
+ 2011-11-15 19:39 . 2011-04-25 15:51 6076416 c:\windows\ie7updates\KB2586448-IE7\ieframe.dll
+ 2006-02-04 11:01 . 2011-11-15 19:40 50295240 c:\windows\system32\MRT.exe
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2005-01-20 77824]
"SiSPower"="SiSPower.dll" [2005-01-04 49152]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-02-28 63048]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2010-07-04 17408]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
d:\documents and settings\Tony\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
d:\documents and settings\Kay\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
d:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Utility Tray.lnk - c:\windows\system32\sistray.exe [2005-11-18 331776]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2011-10-10 09:02 87424 ----a-w- c:\windows\system32\LMIinit.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\AOL 9.0\\aol.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\APPS\\skype\\phone\\Skype.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
R1 MpKsl9928b849;MpKsl9928b849;\??\d:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{83DA77B9-C1BA-441D-BC0C-B406A3A3AE72}\MpKsl9928b849.sys --> d:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{83DA77B9-C1BA-441D-BC0C-B406A3A3AE72}\MpKsl9928b849.sys [?]
R1 MpKsle79e0302;MpKsle79e0302;\??\d:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{83DA77B9-C1BA-441D-BC0C-B406A3A3AE72}\MpKsle79e0302.sys --> d:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{83DA77B9-C1BA-441D-BC0C-B406A3A3AE72}\MpKsle79e0302.sys [?]
R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [31/10/2010 12:06 374152]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [28/02/2008 14:31 12856]
S1 MpKsl0db43414;MpKsl0db43414;\??\d:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E5111222-5AFC-42DA-ACC5-EF9D57C29AE8}\MpKsl0db43414.sys --> d:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E5111222-5AFC-42DA-ACC5-EF9D57C29AE8}\MpKsl0db43414.sys [?]
S1 MpKsl3c55e93d;MpKsl3c55e93d;\??\d:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E5111222-5AFC-42DA-ACC5-EF9D57C29AE8}\MpKsl3c55e93d.sys --> d:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E5111222-5AFC-42DA-ACC5-EF9D57C29AE8}\MpKsl3c55e93d.sys [?]
S1 MpKsl6df984f7;MpKsl6df984f7;\??\d:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{45DF8B7D-B9A1-4ED3-8C72-4BCD511C5E1B}\MpKsl6df984f7.sys --> d:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{45DF8B7D-B9A1-4ED3-8C72-4BCD511C5E1B}\MpKsl6df984f7.sys [?]
S1 MpKsl7829a240;MpKsl7829a240;\??\d:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{AC722EB9-493F-4666-AB71-03FBEF0A77D7}\MpKsl7829a240.sys --> d:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{AC722EB9-493F-4666-AB71-03FBEF0A77D7}\MpKsl7829a240.sys [?]
S1 MpKsl81271b20;MpKsl81271b20;\??\d:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{91EA31B9-7051-4AAC-A1EB-60F54288A577}\MpKsl81271b20.sys --> d:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{91EA31B9-7051-4AAC-A1EB-60F54288A577}\MpKsl81271b20.sys [?]
S1 MpKsld07d0652;MpKsld07d0652;\??\d:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E4A2AB72-C232-4CCE-9742-F7DE315AE33B}\MpKsld07d0652.sys --> d:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E4A2AB72-C232-4CCE-9742-F7DE315AE33B}\MpKsld07d0652.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 12:16 130384]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [10/08/2004 16:38 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 12:16 753504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-16 c:\windows\Tasks\At1.job
- c:\program files\HP\HP Deskjet 2050 J510 series\Bin\HPCustPartic.exe [2010-06-14 15:07]
.
2011-09-22 c:\windows\Tasks\At2.job
- c:\program files\HP\HP Deskjet 2050 J510 series\Bin\HPCustPartic.exe [2010-06-14 15:07]
.
2011-10-27 c:\windows\Tasks\At3.job
- c:\program files\HP\HP Deskjet 2050 J510 series\Bin\HPCustPartic.exe [2010-06-14 15:07]
.
2011-10-30 c:\windows\Tasks\At4.job
- c:\program files\HP\HP Deskjet 2050 J510 series\Bin\HPCustPartic.exe [2010-06-14 15:07]
.
2011-09-21 c:\windows\Tasks\Disk Cleanup.job
- c:\windows\system32\cleanmgr.exe [2004-08-10 00:12]
.
2006-01-01 c:\windows\Tasks\Registration reminder 1.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-08-10 00:12]
.
2006-01-01 c:\windows\Tasks\Registration reminder 2.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-08-10 00:12]
.
2006-01-01 c:\windows\Tasks\Registration reminder 3.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-08-10 00:12]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.uk/
uInternet Connection Wizard,ShellNext = iexplore
TCP: DhcpNameServer = 192.168.0.1
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-11-17 20:00
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1996026722-1646591423-3677921591-1006\RemoteAccess\Profile\x *]
"EnableAutodisconnect"=dword:00000001
"EnableExitDisconnect"=dword:00000001
"DisconnectIdleTime"=dword:00000014
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(640)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
.
- - - - - - - > 'explorer.exe'(2744)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\hnetcfg.dll
c:\windows\system32\LMIRfsClientNP.dll
.
Completion time: 2011-11-17 20:04:31
ComboFix-quarantined-files.txt 2011-11-17 20:04
ComboFix2.txt 2011-11-13 13:29
.
Pre-Run: 7,118,422,016 bytes free
Post-Run: 7,095,623,680 bytes free
.
- - End Of File - - BE00F983B08639F535F297D5A44D8066