ComboFix 12-08-16.01 - Steve 08/16/2012 18:43:22.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.275 [GMT -5:00]
Running from: c:\documents and settings\Steve\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Steve\Local Settings\Application Data\Vid-Saver
c:\documents and settings\Steve\Local Settings\Application Data\Vid-Saver\Chrome\Vid-Saver.crx
c:\program files\Vid-Saver
c:\program files\Vid-Saver\Uninstall.exe
c:\program files\Vid-Saver\Vid-Saver.exe
c:\program files\Vid-Saver\Vid-Saver.ico
c:\program files\Vid-Saver\Vid-Saver.ini
c:\program files\Vid-Saver\Vid-SaverGui.exe
c:\program files\Vid-Saver\Vid-SaverInstaller.log
.
.
((((((((((((((((((((((((( Files Created from 2012-07-16 to 2012-08-16 )))))))))))))))))))))))))))))))
.
.
2012-08-14 00:47 . 2012-08-14 00:47 -------- d-----w- C:\TDSSKiller_Quarantine
2012-08-14 00:11 . 2012-08-14 00:11 664 ----a-w- c:\documents and settings\NetworkService\Local Settings\Application Data\d3d9caps.tmp
2012-08-10 02:39 . 2012-08-10 02:41 -------- d-----w- c:\windows\2C7D909F99544F67AC816F6D9D054A08.TMP
2012-08-10 01:58 . 2012-08-10 01:58 -------- d-----w- c:\program files\Enigma Software Group
2012-08-10 01:57 . 2012-08-10 01:57 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2012-08-07 00:59 . 2011-03-09 21:15 33568 ----a-w- c:\windows\system32\drivers\sct_skmscan.sys
2012-08-07 00:57 . 2012-08-07 00:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Sophos
2012-08-02 16:02 . 2012-08-02 16:05 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2012-07-31 09:31 . 2012-07-31 09:31 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2012-07-31 07:15 . 2012-07-31 07:34 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-15 03:14 . 2012-06-04 17:15 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-15 03:14 . 2011-09-23 05:58 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-16 19:25 . 2012-04-20 01:09 17320 ----a-w- c:\windows\system32\roboot.exe
2012-07-06 13:58 . 2004-08-04 05:56 78336 ----a-w- c:\windows\system32\browser.dll
2012-07-04 14:05 . 2007-02-09 03:34 139784 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-07-03 13:40 . 2004-08-04 04:17 1866112 ----a-w- c:\windows\system32\win32k.sys
2012-07-02 17:49 . 2004-08-04 05:56 916992 ----a-w- c:\windows\system32\wininet.dll
2012-07-02 17:49 . 2004-08-04 05:56 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-07-02 17:49 . 2004-08-04 05:56 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-07-02 12:05 . 2004-08-04 03:59 385024 ----a-w- c:\windows\system32\html.iec
2012-06-05 15:50 . 2008-04-14 00:12 1372672 ------w- c:\windows\system32\msxml6.dll
2012-06-05 15:50 . 2004-08-04 05:56 1172480 ----a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32 . 2004-08-04 05:56 152576 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 20:19 . 2007-06-25 05:59 22040 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 20:19 . 2007-06-25 05:59 15384 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 20:19 . 2007-02-09 03:37 329240 ----a-w- c:\windows\system32\wucltui.dll
2012-06-02 20:19 . 2007-02-09 03:37 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 20:19 . 2007-02-09 03:37 210968 ----a-w- c:\windows\system32\wuweb.dll
2012-06-02 20:19 . 2007-06-25 05:59 15384 ----a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 20:19 . 2007-02-09 03:37 53784 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 20:19 . 2007-02-09 03:37 35864 ----a-w- c:\windows\system32\wups.dll
2012-06-02 20:19 . 2005-05-26 10:16 45080 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 20:19 . 2004-08-04 05:56 97304 ----a-w- c:\windows\system32\cdm.dll
2012-06-02 20:19 . 2007-06-25 05:59 17944 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 20:19 . 2007-02-09 03:37 577048 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 20:19 . 2007-02-09 03:37 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 20:18 . 2007-06-25 11:05 17136 ----a-w- c:\windows\system32\mucltui.dll.mui
2012-06-02 20:18 . 2007-02-10 00:59 275696 ----a-w- c:\windows\system32\mucltui.dll
2012-06-02 20:18 . 2005-05-26 10:19 214256 ----a-w- c:\windows\system32\muweb.dll
2012-05-31 13:22 . 2004-08-04 05:56 599040 ----a-w- c:\windows\system32\crypt32.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2012-08-13_01.49.40 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-08-16 08:26 . 2012-08-16 08:26 16384 c:\windows\Temp\Perflib_Perfdata_758.dat
- 2004-08-04 05:56 . 2012-05-11 14:42 67072 c:\windows\system32\mshtmled.dll
+ 2004-08-04 05:56 . 2012-07-02 17:49 67072 c:\windows\system32\mshtmled.dll
- 2006-10-17 19:33 . 2012-05-11 14:42 55296 c:\windows\system32\msfeedsbs.dll
+ 2006-10-17 19:33 . 2012-07-02 17:49 55296 c:\windows\system32\msfeedsbs.dll
- 2004-08-04 05:56 . 2012-05-11 14:42 25600 c:\windows\system32\jsproxy.dll
+ 2004-08-04 05:56 . 2012-07-02 17:49 25600 c:\windows\system32\jsproxy.dll
+ 2009-07-08 18:23 . 2012-07-02 17:49 12800 c:\windows\system32\dllcache\xpshims.dll
- 2009-07-08 18:23 . 2012-05-11 14:42 12800 c:\windows\system32\dllcache\xpshims.dll
- 2004-08-04 05:56 . 2012-05-11 14:42 67072 c:\windows\system32\dllcache\mshtmled.dll
+ 2004-08-04 05:56 . 2012-07-02 17:49 67072 c:\windows\system32\dllcache\mshtmled.dll
- 2007-04-25 08:41 . 2012-05-11 14:42 55296 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2007-04-25 08:41 . 2012-07-02 17:49 55296 c:\windows\system32\dllcache\msfeedsbs.dll
- 2004-08-04 05:56 . 2012-05-11 14:42 43520 c:\windows\system32\dllcache\licmgr10.dll
+ 2004-08-04 05:56 . 2012-07-02 17:49 43520 c:\windows\system32\dllcache\licmgr10.dll
- 2004-08-04 05:56 . 2012-05-11 14:42 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2004-08-04 05:56 . 2012-07-02 17:49 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2012-07-06 13:58 . 2012-07-06 13:58 78336 c:\windows\system32\dllcache\browser.dll
+ 2007-02-09 04:34 . 2012-08-16 08:06 23040 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2007-02-09 04:34 . 2012-07-12 08:01 23040 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2007-02-09 04:34 . 2012-07-12 08:01 61440 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2007-02-09 04:34 . 2012-08-16 08:06 61440 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2007-02-09 04:34 . 2012-08-16 08:06 27136 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2007-02-09 04:34 . 2012-07-12 08:01 27136 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2007-02-09 04:34 . 2012-07-12 08:01 11264 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2007-02-09 04:34 . 2012-08-16 08:06 11264 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2007-02-09 04:34 . 2012-07-12 08:01 86016 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2007-02-09 04:34 . 2012-08-16 08:06 86016 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2007-02-09 04:34 . 2012-07-12 08:01 12288 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2007-02-09 04:34 . 2012-08-16 08:06 12288 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2012-08-16 08:02 . 2012-05-11 14:42 12800 c:\windows\ie8updates\KB2722913-IE8\xpshims.dll
+ 2012-08-16 08:02 . 2012-05-11 14:42 67072 c:\windows\ie8updates\KB2722913-IE8\mshtmled.dll
+ 2012-08-16 08:02 . 2012-05-11 14:42 55296 c:\windows\ie8updates\KB2722913-IE8\msfeedsbs.dll
+ 2012-08-16 08:02 . 2012-05-11 14:42 43520 c:\windows\ie8updates\KB2722913-IE8\licmgr10.dll
+ 2012-08-16 08:02 . 2012-05-11 14:42 25600 c:\windows\ie8updates\KB2722913-IE8\jsproxy.dll
- 2007-02-09 04:34 . 2012-07-12 08:01 4096 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2007-02-09 04:34 . 2012-08-16 08:06 4096 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2004-08-04 05:56 . 2012-05-11 14:42 105984 c:\windows\system32\url.dll
+ 2004-08-04 05:56 . 2012-07-02 17:49 105984 c:\windows\system32\url.dll
- 2004-08-04 05:56 . 2012-05-11 14:42 206848 c:\windows\system32\occache.dll
+ 2004-08-04 05:56 . 2012-07-02 17:49 206848 c:\windows\system32\occache.dll
+ 2004-08-04 05:56 . 2012-07-06 13:58 337920 c:\windows\system32\netapi32.dll
+ 2004-08-04 05:56 . 2012-07-02 17:49 611840 c:\windows\system32\mstime.dll
- 2004-08-04 05:56 . 2012-05-11 14:42 611840 c:\windows\system32\mstime.dll
+ 2006-10-17 19:33 . 2012-07-02 17:49 629760 c:\windows\system32\msfeeds.dll
- 2006-10-17 19:33 . 2012-05-11 14:42 629760 c:\windows\system32\msfeeds.dll
+ 2012-08-15 03:14 . 2012-08-15 03:14 686792 c:\windows\system32\Macromed\Flash\FlashUtil32_11_3_300_271_ActiveX.exe
+ 2012-08-15 03:14 . 2012-08-15 03:14 466632 c:\windows\system32\Macromed\Flash\FlashUtil32_11_3_300_271_ActiveX.dll
- 2012-06-04 17:15 . 2012-08-04 01:17 250056 c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
+ 2012-06-04 17:15 . 2012-08-15 03:15 250056 c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
+ 2004-08-04 05:56 . 2012-05-14 09:22 345600 c:\windows\system32\localspl.dll
- 2004-08-04 05:56 . 2009-05-07 15:32 345600 c:\windows\system32\localspl.dll
- 2004-08-04 05:56 . 2012-05-11 14:42 184320 c:\windows\system32\iepeers.dll
+ 2004-08-04 05:56 . 2012-07-02 17:49 184320 c:\windows\system32\iepeers.dll
- 2004-08-04 05:56 . 2012-05-11 14:42 387584 c:\windows\system32\iedkcs32.dll
+ 2004-08-04 05:56 . 2012-07-02 17:49 387584 c:\windows\system32\iedkcs32.dll
+ 2004-08-04 05:56 . 2012-07-02 12:05 174080 c:\windows\system32\ie4uinit.exe
- 2004-08-04 05:56 . 2012-05-11 11:38 174080 c:\windows\system32\ie4uinit.exe
+ 2007-02-08 21:13 . 2012-08-16 08:26 257456 c:\windows\system32\FNTCACHE.DAT
- 2007-02-08 21:13 . 2012-07-12 08:24 257456 c:\windows\system32\FNTCACHE.DAT
- 2004-08-04 05:56 . 2012-05-16 15:08 916992 c:\windows\system32\dllcache\wininet.dll
+ 2004-08-04 05:56 . 2012-07-02 17:49 916992 c:\windows\system32\dllcache\wininet.dll
- 2004-08-04 05:56 . 2012-05-11 14:42 105984 c:\windows\system32\dllcache\url.dll
+ 2004-08-04 05:56 . 2012-07-02 17:49 105984 c:\windows\system32\dllcache\url.dll
+ 2011-08-09 17:32 . 2012-07-04 14:05 139784 c:\windows\system32\dllcache\rdpwd.sys
+ 2004-08-04 05:56 . 2012-07-02 17:49 206848 c:\windows\system32\dllcache\occache.dll
- 2004-08-04 05:56 . 2012-05-11 14:42 206848 c:\windows\system32\dllcache\occache.dll
+ 2009-07-07 05:28 . 2012-07-06 13:58 337920 c:\windows\system32\dllcache\netapi32.dll
+ 2004-08-04 05:56 . 2012-07-02 17:49 611840 c:\windows\system32\dllcache\mstime.dll
- 2004-08-04 05:56 . 2012-05-11 14:42 611840 c:\windows\system32\dllcache\mstime.dll
+ 2007-04-25 08:41 . 2012-07-02 17:49 629760 c:\windows\system32\dllcache\msfeeds.dll
- 2007-04-25 08:41 . 2012-05-11 14:42 629760 c:\windows\system32\dllcache\msfeeds.dll
+ 2009-05-07 15:32 . 2012-05-14 09:22 345600 c:\windows\system32\dllcache\localspl.dll
- 2009-05-07 15:32 . 2009-05-07 15:32 345600 c:\windows\system32\dllcache\localspl.dll
- 2012-06-13 05:51 . 2012-05-11 14:42 521728 c:\windows\system32\dllcache\jsdbgui.dll
+ 2012-06-13 05:51 . 2012-07-02 17:49 521728 c:\windows\system32\dllcache\jsdbgui.dll
+ 2009-07-08 18:22 . 2012-07-02 17:49 247808 c:\windows\system32\dllcache\ieproxy.dll
- 2009-07-08 18:22 . 2012-05-11 14:42 247808 c:\windows\system32\dllcache\ieproxy.dll
+ 2004-08-04 05:56 . 2012-07-02 17:49 184320 c:\windows\system32\dllcache\iepeers.dll
- 2004-08-04 05:56 . 2012-05-11 14:42 184320 c:\windows\system32\dllcache\iepeers.dll
- 2010-06-11 04:20 . 2012-05-11 14:42 743424 c:\windows\system32\dllcache\iedvtool.dll
+ 2010-06-11 04:20 . 2012-07-02 17:49 743424 c:\windows\system32\dllcache\iedvtool.dll
+ 2004-08-04 05:56 . 2012-07-02 17:49 387584 c:\windows\system32\dllcache\iedkcs32.dll
- 2004-08-04 05:56 . 2012-05-11 14:42 387584 c:\windows\system32\dllcache\iedkcs32.dll
+ 2004-08-04 05:56 . 2012-07-02 12:05 174080 c:\windows\system32\dllcache\ie4uinit.exe
- 2004-08-04 05:56 . 2012-05-11 11:38 174080 c:\windows\system32\dllcache\ie4uinit.exe
- 2007-02-09 04:34 . 2012-07-12 08:01 409600 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2007-02-09 04:34 . 2012-08-16 08:06 409600 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2007-02-09 04:34 . 2012-07-12 08:01 286720 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2007-02-09 04:34 . 2012-08-16 08:06 286720 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2007-02-09 04:34 . 2012-08-16 08:06 249856 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2007-02-09 04:34 . 2012-07-12 08:01 249856 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2007-02-09 04:34 . 2012-08-16 08:06 794624 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2007-02-09 04:34 . 2012-07-12 08:01 794624 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2007-02-09 04:34 . 2012-07-12 08:01 135168 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2007-02-09 04:34 . 2012-08-16 08:06 135168 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2007-02-09 04:34 . 2012-07-12 08:01 593920 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2007-02-09 04:34 . 2012-08-16 08:06 593920 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2012-08-16 08:02 . 2012-05-16 15:08 916992 c:\windows\ie8updates\KB2722913-IE8\wininet.dll
+ 2012-08-16 08:02 . 2012-05-11 14:42 105984 c:\windows\ie8updates\KB2722913-IE8\url.dll
+ 2012-08-16 08:02 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2722913-IE8\spuninst\updspapi.dll
+ 2012-08-16 08:02 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2722913-IE8\spuninst\spuninst.exe
+ 2012-08-16 08:02 . 2012-05-11 14:42 206848 c:\windows\ie8updates\KB2722913-IE8\occache.dll
+ 2012-08-16 08:02 . 2012-05-11 14:42 611840 c:\windows\ie8updates\KB2722913-IE8\mstime.dll
+ 2012-08-16 08:02 . 2012-05-11 14:42 629760 c:\windows\ie8updates\KB2722913-IE8\msfeeds.dll
+ 2012-08-16 08:02 . 2012-05-11 14:42 521728 c:\windows\ie8updates\KB2722913-IE8\jsdbgui.dll
+ 2012-08-16 08:02 . 2012-05-11 14:42 247808 c:\windows\ie8updates\KB2722913-IE8\ieproxy.dll
+ 2012-08-16 08:02 . 2012-05-11 14:42 184320 c:\windows\ie8updates\KB2722913-IE8\iepeers.dll
+ 2012-08-16 08:02 . 2012-05-11 14:42 743424 c:\windows\ie8updates\KB2722913-IE8\iedvtool.dll
+ 2012-08-16 08:02 . 2012-05-11 14:42 387584 c:\windows\ie8updates\KB2722913-IE8\iedkcs32.dll
+ 2012-08-16 08:02 . 2012-05-11 11:38 174080 c:\windows\ie8updates\KB2722913-IE8\ie4uinit.exe
+ 2004-08-04 05:56 . 2012-07-02 17:49 1212416 c:\windows\system32\urlmon.dll
- 2004-08-04 05:56 . 2012-05-11 14:42 1212416 c:\windows\system32\urlmon.dll
+ 2004-08-04 05:56 . 2012-07-02 17:49 6008320 c:\windows\system32\mshtml.dll
+ 2006-10-17 18:57 . 2012-07-02 17:49 2000384 c:\windows\system32\iertutil.dll
- 2006-10-17 18:57 . 2012-05-11 14:42 2000384 c:\windows\system32\iertutil.dll
+ 2009-04-17 12:26 . 2012-07-03 13:40 1866112 c:\windows\system32\dllcache\win32k.sys
- 2009-04-17 12:26 . 2012-06-13 13:19 1866112 c:\windows\system32\dllcache\win32k.sys
- 2004-08-04 05:56 . 2012-05-11 14:42 1212416 c:\windows\system32\dllcache\urlmon.dll
+ 2004-08-04 05:56 . 2012-07-02 17:49 1212416 c:\windows\system32\dllcache\urlmon.dll
+ 2004-08-04 05:56 . 2012-07-02 17:49 6008320 c:\windows\system32\dllcache\mshtml.dll
- 2007-04-25 08:41 . 2012-05-11 14:42 2000384 c:\windows\system32\dllcache\iertutil.dll
+ 2007-04-25 08:41 . 2012-07-02 17:49 2000384 c:\windows\system32\dllcache\iertutil.dll
+ 2012-07-17 15:11 . 2012-07-17 15:11 6145024 c:\windows\Installer\64f562a.msp
+ 2012-08-02 15:29 . 2012-08-02 15:29 5521920 c:\windows\Installer\64f5614.msp
+ 2012-08-16 08:02 . 2012-05-11 14:42 1212416 c:\windows\ie8updates\KB2722913-IE8\urlmon.dll
+ 2012-08-16 08:02 . 2012-05-11 14:42 6007808 c:\windows\ie8updates\KB2722913-IE8\mshtml.dll
+ 2012-08-16 08:02 . 2012-05-11 14:42 2000384 c:\windows\ie8updates\KB2722913-IE8\iertutil.dll
+ 2007-02-09 04:04 . 2012-08-16 08:06 59884088 c:\windows\system32\MRT.exe
+ 2006-10-17 19:33 . 2012-07-03 04:19 11111424 c:\windows\system32\ieframe.dll
- 2006-10-17 19:33 . 2012-05-12 01:12 11111424 c:\windows\system32\ieframe.dll
+ 2007-04-25 08:41 . 2012-07-03 04:19 11111424 c:\windows\system32\dllcache\ieframe.dll
- 2007-04-25 08:41 . 2012-05-12 01:12 11111424 c:\windows\system32\dllcache\ieframe.dll
+ 2012-07-17 15:17 . 2012-07-17 15:17 22363136 c:\windows\Installer\64f5640.msp
+ 2012-08-16 08:02 . 2012-05-12 01:12 11111424 c:\windows\ie8updates\KB2722913-IE8\ieframe.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RoxioEngineUtility"="c:\program files\Common Files\Roxio Shared\System\EngUtil.exe" [2003-01-13 69632]
"RoxioDragToDisc"="c:\program files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe" [2003-01-13 757760]
"RoxioAudioCentral"="c:\program files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe" [2003-01-09 253952]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-08-03 4493312]
"nwiz"="nwiz.exe" [2004-08-03 917504]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-04-27 282624]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-15 49152]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-04-05 2587008]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2011-08-31 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
Wireless USB 2.0 WLAN Card Utility.lnk - c:\program files\Dell Wireless\PRISMCFG.exe [2007-3-26 921704]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PRISMAPI.DLL]
2005-12-23 01:08 450646 ----a-w- c:\windows\system32\PRISMAPI.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
.
R0 AVGIDSHX;AVGIDSHX;c:\windows\system32\drivers\avgidshx.sys [4/19/2012 4:50 AM 24896]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [9/7/2010 4:48 AM 31952]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [12/8/2010 5:12 AM 235216]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [11/12/2010 2:19 PM 301248]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [2/14/2012 4:53 AM 193288]
R2 PRISMSVC;PRISMSVC;c:\windows\system32\PRISMSVC.exe [3/26/2007 9:24 PM 61526]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\avgidsdriverx.sys [12/23/2011 1:32 PM 139856]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\avgidsfilterx.sys [12/23/2011 1:32 PM 24144]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\avgidsshimx.sys [12/23/2011 1:32 PM 17232]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\avgidsagent.exe [7/4/2012 5:25 PM 5160568]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [6/4/2012 12:15 PM 250056]
S3 SCT_SKMScan;SCT_SKMScan;c:\windows\system32\drivers\sct_skmscan.sys [8/6/2012 7:59 PM 33568]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2012-08-16 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-04 03:15]
.
2012-08-16 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 20:07]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://google.com/
TCP: DhcpNameServer = 10.0.0.1
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-08-16 18:51
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(916)
c:\windows\system32\PRISMAPI.DLL
.
Completion time: 2012-08-16 18:55:03
ComboFix-quarantined-files.txt 2012-08-16 23:55
ComboFix2.txt 2012-08-16 03:29
ComboFix3.txt 2012-08-13 01:54
.
Pre-Run: 25,381,191,680 bytes free
Post-Run: 25,361,014,784 bytes free
.
- - End Of File - - 51580CE682B52BC56DFA1FC43E9052CD
Greetings! Here is a copy of the scan from "combo". I think that the puter is running MUCH better than before! What else is needed??