Everything seems to be good, other than those online scanners not working.... Any idea how to fix it? It almost seems like a firewall is keeping them from accessing the internet to download the threat database, but the one I use is off. It's really no big deal if I can't get them to work, as long as I'm virus free I'm happy.
ComboFix 11-05-26.02 - Administrator 05/27/2011 0:22.8.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.660 [GMT -6:00]
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.txt
* Created a new restore point
.
FILE ::
"c:\windows\rfierod.dll"
"c:\windows\system32\null0.8326248260023004.rar/null0.8326248260023004.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\rfierod.dll
.
.
((((((((((((((((((((((((( Files Created from 2011-04-27 to 2011-05-27 )))))))))))))))))))))))))))))))
.
.
2011-05-26 05:25 . 2009-10-22 19:54 37392 ----a-w- c:\windows\system32\drivers\61709312.sys
2011-05-26 05:25 . 2009-10-10 05:31 315408 ----a-w- c:\windows\system32\drivers\6170931.sys
2011-05-26 05:25 . 2009-09-25 23:59 128016 ----a-w- c:\windows\system32\drivers\61709311.sys
2011-05-26 00:52 . 2011-05-26 00:52 -------- d-----w- c:\program files\ESET
2011-05-25 23:29 . 2011-05-25 23:29 -------- d-----w- c:\program files\Common Files\Java
2011-05-25 23:28 . 2011-04-14 11:07 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-05-25 23:23 . 2011-05-25 23:23 -------- d-----w- c:\program files\Foxit Software
2011-05-25 05:20 . 2011-05-25 05:20 -------- d-----w- c:\windows\system32\URTTEMP
2011-05-22 01:14 . 2011-05-22 01:14 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-16 20:34 . 2011-05-16 20:34 -------- d-----w- c:\documents and settings\Administrator\Application Data\.clamwin
2011-05-16 20:33 . 2011-05-16 20:33 -------- d-----w- c:\program files\ClamWin
2011-05-16 20:33 . 2011-05-16 20:33 -------- d-----w- c:\documents and settings\All Users\.clamwin
2011-05-13 03:54 . 2011-05-13 03:54 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Identities
2011-05-09 21:44 . 2011-05-09 21:44 -------- d-----w- C:\Adobe
2011-05-09 19:25 . 2011-05-09 19:25 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2011-05-06 02:06 . 2011-05-06 02:09 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2011-05-03 05:12 . 2011-05-03 05:12 388096 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-05-03 05:12 . 2011-05-03 05:12 -------- d-----w- c:\program files\Trend Micro
2011-05-03 05:05 . 2011-05-03 05:05 -------- d-----w- c:\documents and settings\All Users\Application Data\IObit
2011-05-03 05:02 . 2011-05-03 05:26 -------- d-----w- c:\documents and settings\Administrator\Application Data\IObit
2011-05-03 05:02 . 2011-05-03 05:26 -------- d-----w- c:\program files\IObit
2011-05-02 15:55 . 2011-05-02 15:55 -------- d-----w- C:\!KillBox
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-14 08:40 . 2010-03-20 03:47 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-04-13 22:40 . 2011-04-13 22:40 4284416 ----a-w- c:\windows\system32\GPhotos.scr
2011-04-12 03:35 . 2011-04-12 03:35 5120 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{7EA72399-EE18-40C6-90D5-8629ED6978AF}\IconTmpl.6CB586F0_5D86_454E_A763_2AAC2F44EA18.exe
2011-03-13 03:33 . 2010-03-04 02:54 285480 ----a-w- c:\windows\system32\guard32.dll
2011-03-13 03:33 . 2010-03-04 02:54 94784 ----a-w- c:\windows\system32\drivers\inspect.sys
2011-03-13 03:33 . 2010-03-04 02:54 27576 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2011-03-13 03:33 . 2010-03-04 02:54 239368 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
2011-03-13 03:33 . 2010-03-04 02:54 15592 ----a-w- c:\windows\system32\drivers\cmderd.sys
2011-03-12 22:13 . 2011-03-12 22:13 65536 ----a-w- c:\program files\update_kernel.exe
2011-03-12 21:04 . 2011-03-12 20:42 65536 ----a-w- c:\program files\win64checkKBDK.exe
2011-03-08 03:37 . 2010-10-18 17:07 398760 ----a-r- c:\windows\system32\cpnprt2.cid
2011-04-14 16:26 . 2011-05-09 19:25 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2009-09-14 . A29E1209F925A0E9B330E11DA5FC7BAB . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys
.
.
.
c:\windows\System32\wscntfy.exe ... is missing !!
c:\windows\System32\regsvc.dll ... is missing !!
.
((((((((((((((((((((((((((((( SnapShot_2011-04-01_06.33.29 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-05-27 06:04 . 2011-05-27 06:04 16384 c:\windows\temp\Perflib_Perfdata_6f0.dat
+ 2001-08-22 21:59 . 2001-08-22 21:59 27136 c:\windows\system32\WinNTDlls\CTL3D32.DLL
+ 2001-08-22 21:59 . 2001-08-22 21:59 45056 c:\windows\system32\Win98Dlls\ctl3d32.dll
+ 2003-02-21 11:16 . 2003-02-21 11:16 49152 c:\windows\system32\URTTEMP\regtlib.exe
+ 2011-04-25 04:06 . 2008-04-14 16:42 23552 c:\windows\system32\ReinstallBackups\0000\DriverFiles\i386\wdmaud.drv
+ 2011-04-25 04:06 . 2008-04-14 11:15 49408 c:\windows\system32\ReinstallBackups\0000\DriverFiles\i386\stream.sys
+ 2011-04-25 04:06 . 2008-04-14 11:15 60160 c:\windows\system32\ReinstallBackups\0000\DriverFiles\i386\drmk.sys
+ 2011-04-25 04:06 . 2001-10-15 20:15 53248 c:\windows\system32\ReinstallBackups\0000\DriverFiles\FTdll32.dll
+ 2001-08-23 12:00 . 2011-05-25 05:21 69732 c:\windows\system32\perfc009.dat
+ 2002-03-27 21:29 . 2002-03-27 21:29 24576 c:\windows\system32\msxml3a.dll
- 2010-03-16 09:19 . 2004-09-29 19:09 57344 c:\windows\system32\HPZisn12.dll
+ 2010-03-16 09:19 . 2004-09-29 18:09 57344 c:\windows\system32\HPZisn12.dll
- 2010-03-16 09:19 . 2004-09-29 19:09 94208 c:\windows\system32\HPZipt12.dll
+ 2010-03-16 09:19 . 2004-09-29 18:09 94208 c:\windows\system32\HPZipt12.dll
- 2010-03-16 09:19 . 2004-09-29 19:14 69632 c:\windows\system32\HPZipm12.exe
+ 2010-03-16 09:19 . 2004-09-29 18:14 69632 c:\windows\system32\HPZipm12.exe
- 2010-03-16 09:19 . 2004-09-29 19:08 61440 c:\windows\system32\HPZinw12.exe
+ 2010-03-16 09:19 . 2004-09-29 18:08 61440 c:\windows\system32\HPZinw12.exe
- 2010-03-22 02:04 . 2010-04-29 21:39 38224 c:\windows\system32\drivers\mbamswissarmy.sys
+ 2010-03-22 02:04 . 2010-12-21 00:09 38224 c:\windows\system32\drivers\mbamswissarmy.sys
- 2010-03-22 02:04 . 2010-04-29 21:39 20952 c:\windows\system32\drivers\mbam.sys
+ 2010-03-22 02:04 . 2010-12-21 00:08 20952 c:\windows\system32\drivers\mbam.sys
+ 2010-05-31 04:34 . 2011-05-02 05:23 40208 c:\windows\system32\config\systemprofile\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
+ 2003-02-21 02:10 . 2003-02-21 02:10 31744 c:\windows\Microsoft.NET\Framework\v1.1.4322\WMINet_Utils.dll
+ 2003-02-21 13:24 . 2003-02-21 13:24 57344 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.RegularExpressions.dll
+ 2003-02-21 13:26 . 2003-02-21 13:26 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
+ 2003-02-21 01:09 . 2003-02-21 01:09 64000 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.EnterpriseServices.Thunk.dll
+ 2003-02-21 13:26 . 2003-02-21 13:26 65536 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Drawing.Design.dll
+ 2003-02-21 13:26 . 2003-02-21 13:26 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.DirectoryServices.dll
+ 2003-02-21 13:26 . 2003-02-21 13:26 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Configuration.Install.dll
+ 2003-02-21 13:25 . 2003-02-21 13:25 12288 c:\windows\Microsoft.NET\Framework\v1.1.4322\RegSvcs.exe
+ 2003-02-21 13:26 . 2003-02-21 13:26 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\RegCode.dll
+ 2003-02-21 13:25 . 2003-02-21 13:25 28672 c:\windows\Microsoft.NET\Framework\v1.1.4322\RegAsm.exe
+ 2003-02-21 01:09 . 2003-02-21 01:09 90112 c:\windows\Microsoft.NET\Framework\v1.1.4322\PerfCounter.dll
+ 2003-02-21 01:09 . 2003-02-21 01:09 73728 c:\windows\Microsoft.NET\Framework\v1.1.4322\ngen.exe
+ 2003-02-21 00:43 . 2003-02-21 00:43 22528 c:\windows\Microsoft.NET\Framework\v1.1.4322\MUI\0409\mscorsecr.dll
+ 2003-02-21 01:18 . 2003-02-21 01:18 20480 c:\windows\Microsoft.NET\Framework\v1.1.4322\mtxoci8.dll
+ 2003-02-21 01:09 . 2003-02-21 01:09 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
+ 2003-02-21 01:09 . 2003-02-21 01:09 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsec.dll
+ 2003-02-21 01:06 . 2003-02-21 01:06 65536 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorpe.dll
+ 2003-02-21 01:09 . 2003-02-21 01:09 98304 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
+ 2003-02-21 01:09 . 2003-02-21 01:09 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
+ 2003-02-21 01:09 . 2003-02-21 01:09 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscordbc.dll
+ 2003-02-21 13:25 . 2003-02-21 13:25 49152 c:\windows\Microsoft.NET\Framework\v1.1.4322\MigPolWin.exe
+ 2003-02-21 13:25 . 2003-02-21 13:25 49152 c:\windows\Microsoft.NET\Framework\v1.1.4322\MigPol.exe
+ 2003-02-21 13:25 . 2003-02-21 13:25 11264 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2003-02-21 13:24 . 2003-02-21 13:24 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.Vsa.dll
+ 2003-02-21 13:24 . 2003-02-21 13:24 28672 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.VisualBasic.Vsa.dll
+ 2003-02-21 13:24 . 2003-02-21 13:24 40960 c:\windows\Microsoft.NET\Framework\v1.1.4322\jsc.exe
+ 2003-02-21 13:24 . 2003-02-21 13:24 26112 c:\windows\Microsoft.NET\Framework\v1.1.4322\ISymWrapper.dll
+ 2003-02-21 01:22 . 2003-02-21 01:22 40960 c:\windows\Microsoft.NET\Framework\v1.1.4322\InstallUtilLib.dll
+ 2003-02-21 13:24 . 2003-02-21 13:24 15872 c:\windows\Microsoft.NET\Framework\v1.1.4322\InstallUtil.exe
+ 2003-02-21 13:24 . 2003-02-21 13:24 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\IEHost.dll
+ 2003-02-21 10:12 . 2003-02-21 10:12 28672 c:\windows\Microsoft.NET\Framework\v1.1.4322\cvtres.exe
+ 2003-02-21 13:24 . 2003-02-21 13:24 33792 c:\windows\Microsoft.NET\Framework\v1.1.4322\CustomMarshalers.dll
+ 2003-02-21 13:24 . 2003-02-21 13:24 12288 c:\windows\Microsoft.NET\Framework\v1.1.4322\cscompmgd.dll
+ 2003-02-21 16:20 . 2003-02-21 16:20 49152 c:\windows\Microsoft.NET\Framework\v1.1.4322\csc.exe
+ 2003-02-21 01:09 . 2003-02-21 01:09 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
+ 2003-02-21 13:24 . 2003-02-21 13:24 49152 c:\windows\Microsoft.NET\Framework\v1.1.4322\ConfigWizards.exe
+ 2003-02-21 13:24 . 2003-02-21 13:24 94208 c:\windows\Microsoft.NET\Framework\v1.1.4322\CasPol.exe
+ 2003-02-21 01:19 . 2003-02-21 01:19 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
+ 2003-02-21 01:19 . 2003-02-21 01:19 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe
+ 2003-02-21 01:19 . 2003-02-21 01:19 20480 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_regiis.exe
+ 2003-02-21 01:19 . 2003-02-21 01:19 40960 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_rc.dll
+ 2003-02-21 01:19 . 2003-02-21 01:19 24576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
+ 2003-02-21 11:00 . 2003-02-21 11:00 98304 c:\windows\Microsoft.NET\Framework\v1.1.4322\alink.dll
+ 2003-02-21 09:55 . 2003-02-21 09:55 94208 c:\windows\Microsoft.NET\Framework\v1.1.4322\1033\cscompui.dll
+ 2003-02-21 08:59 . 2003-02-21 08:59 16896 c:\windows\Microsoft.NET\Framework\v1.1.4322\1033\alinkui.dll
+ 2011-05-25 05:22 . 2011-05-25 05:22 49152 c:\windows\Installer\{17293791-C82E-476C-9997-9A0FF234A19B}\NewShortcut1_17293791C82E476C99979A0FF234A19B.exe
+ 2011-05-25 05:21 . 2011-05-25 05:21 90112 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_6894ca77\System.Drawing.Design.dll
+ 2011-05-25 05:21 . 2011-05-25 05:21 61440 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_a9754b55\CustomMarshalers.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 57344 c:\windows\assembly\GAC\System.Web.RegularExpressions\1.0.5000.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 77824 c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 64000 c:\windows\assembly\GAC\System.EnterpriseServices\1.0.5000.0__b03f5f7f11d50a3a\System.EnterpriseServices.Thunk.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 65536 c:\windows\assembly\GAC\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 86016 c:\windows\assembly\GAC\System.DirectoryServices\1.0.5000.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 77824 c:\windows\assembly\GAC\System.Configuration.Install\1.0.5000.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 32768 c:\windows\assembly\GAC\Regcode\1.0.5000.0__b03f5f7f11d50a3a\RegCode.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 32768 c:\windows\assembly\GAC\Microsoft.Vsa\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 11264 c:\windows\assembly\GAC\Microsoft.Vsa.Vb.CodeDOMProcessor\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 28672 c:\windows\assembly\GAC\Microsoft.VisualBasic.Vsa\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 26112 c:\windows\assembly\GAC\ISymWrapper\1.0.5000.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 32768 c:\windows\assembly\GAC\IEHost\1.0.5000.0__b03f5f7f11d50a3a\IEHost.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 33792 c:\windows\assembly\GAC\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 12288 c:\windows\assembly\GAC\cscompmgd\7.0.5000.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2011-04-25 04:06 . 2008-04-14 16:41 4096 c:\windows\system32\ReinstallBackups\0000\DriverFiles\i386\ksuser.dll
+ 2003-02-21 00:43 . 2003-02-21 00:43 4096 c:\windows\system32\mui\0409\mscoreer.dll
+ 2003-02-21 01:09 . 2003-02-21 01:09 9216 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscortim.dll
+ 2003-02-21 13:25 . 2003-02-21 13:25 6656 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft_VsaVb.dll
+ 2003-02-21 13:25 . 2003-02-21 13:25 6144 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.VisualC.Dll
+ 2003-02-21 13:24 . 2003-02-21 13:24 4608 c:\windows\Microsoft.NET\Framework\v1.1.4322\IIEHost.dll
+ 2003-02-21 13:24 . 2003-02-21 13:24 7168 c:\windows\Microsoft.NET\Framework\v1.1.4322\IEExecRemote.dll
+ 2003-02-21 13:24 . 2003-02-21 13:24 7680 c:\windows\Microsoft.NET\Framework\v1.1.4322\IEExec.exe
+ 2003-02-21 13:24 . 2003-02-21 13:24 7680 c:\windows\Microsoft.NET\Framework\v1.1.4322\Accessibility.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 6656 c:\windows\assembly\GAC\Microsoft_VsaVb\7.0.5000.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 6144 c:\windows\assembly\GAC\Microsoft.VisualC\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.VisualC.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 4608 c:\windows\assembly\GAC\IIEHost\1.0.5000.0__b03f5f7f11d50a3a\IIEHost.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 7168 c:\windows\assembly\GAC\IEExecRemote\1.0.5000.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 7680 c:\windows\assembly\GAC\Accessibility\1.0.5000.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2010-05-30 05:51 . 2011-04-17 17:56 999496 c:\windows\system32\Restore\rstrlog.dat
+ 2011-04-25 04:06 . 2008-04-14 11:49 146048 c:\windows\system32\ReinstallBackups\0000\DriverFiles\i386\portcls.sys
+ 2011-04-25 04:06 . 2008-04-14 11:46 141056 c:\windows\system32\ReinstallBackups\0000\DriverFiles\i386\ks.sys
+ 2011-04-25 04:06 . 2001-08-21 03:47 270336 c:\windows\system32\ReinstallBackups\0000\DriverFiles\fmctrl.exe
+ 2011-04-25 04:06 . 2001-11-02 20:33 328320 c:\windows\system32\ReinstallBackups\0000\DriverFiles\fm801.sys
+ 2001-08-23 12:00 . 2011-05-25 05:21 438174 c:\windows\system32\perfh009.dat
+ 2006-05-09 17:22 . 2006-05-09 17:22 196608 c:\windows\system32\MUPTestPrinter.exe
+ 2011-05-22 01:14 . 2011-05-22 01:14 239776 c:\windows\system32\Macromed\Flash\FlashUtil10q_Plugin.exe
+ 2007-05-04 21:33 . 2007-05-04 21:33 851968 c:\windows\system32\LocalAT.dll
+ 2011-05-25 23:28 . 2011-04-14 11:08 157472 c:\windows\system32\javaws.exe
+ 2011-05-25 23:28 . 2011-04-14 11:08 145184 c:\windows\system32\javaw.exe
- 2010-03-20 03:47 . 2010-03-20 03:47 145184 c:\windows\system32\javaw.exe
- 2010-03-20 03:47 . 2010-03-20 03:47 145184 c:\windows\system32\java.exe
+ 2011-05-25 23:28 . 2011-04-14 11:08 145184 c:\windows\system32\java.exe
+ 2010-03-16 09:19 . 2004-09-29 18:15 204800 c:\windows\system32\HPZipr12.dll
- 2010-03-16 09:19 . 2004-09-29 19:15 204800 c:\windows\system32\HPZipr12.dll
+ 2010-03-16 09:19 . 2004-09-29 18:12 278584 c:\windows\system32\HPZidr12.dll
- 2010-03-16 09:19 . 2004-09-29 19:12 278584 c:\windows\system32\HPZidr12.dll
+ 2010-03-16 23:43 . 2011-04-17 16:26 181040 c:\windows\system32\FNTCACHE.DAT
+ 2003-02-21 16:20 . 2003-02-21 16:20 737280 c:\windows\Microsoft.NET\Framework\v1.1.4322\vbc.exe
+ 2003-02-21 13:27 . 2003-02-21 13:27 569344 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.Services.dll
+ 2003-02-21 13:27 . 2003-02-21 13:27 819200 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.Mobile.dll
+ 2003-02-21 13:27 . 2003-02-21 13:27 126976 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.ServiceProcess.dll
+ 2003-02-21 13:26 . 2003-02-21 13:26 131072 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Runtime.Serialization.Formatters.Soap.dll
+ 2003-02-21 13:26 . 2003-02-21 13:26 323584 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Runtime.Remoting.dll
+ 2003-02-21 13:26 . 2003-02-21 13:26 241664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Messaging.dll
+ 2003-02-21 13:26 . 2003-02-21 13:26 368640 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Management.dll
+ 2003-02-21 13:26 . 2003-02-21 13:26 241664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.EnterpriseServices.dll
+ 2003-02-21 13:26 . 2003-02-21 13:26 466944 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Drawing.dll
+ 2003-02-21 13:25 . 2003-02-21 13:25 299008 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Data.OracleClient.dll
+ 2003-02-21 01:09 . 2003-02-21 01:09 319488 c:\windows\Microsoft.NET\Framework\v1.1.4322\SOS.dll
+ 2003-02-21 01:09 . 2003-02-21 01:09 122880 c:\windows\Microsoft.NET\Framework\v1.1.4322\shfusres.dll
+ 2003-02-21 01:09 . 2003-02-21 01:09 253952 c:\windows\Microsoft.NET\Framework\v1.1.4322\shfusion.dll
+ 2003-02-21 10:42 . 2003-02-21 10:42 348160 c:\windows\Microsoft.NET\Framework\v1.1.4322\msvcr71.dll
+ 2003-02-21 01:09 . 2003-02-21 01:09 143360 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorrc.dll
+ 2003-02-21 00:43 . 2003-02-21 00:43 131072 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscormmc.dll
+ 2003-02-21 01:06 . 2003-02-21 01:06 311296 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
+ 2003-02-21 01:09 . 2003-02-21 01:09 233472 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscordbi.dll
+ 2003-02-21 13:26 . 2003-02-21 13:26 299008 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.VisualBasic.dll
+ 2003-02-21 13:26 . 2003-02-21 13:26 716800 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.JScript.dll
+ 2003-02-21 01:09 . 2003-02-21 01:09 196608 c:\windows\Microsoft.NET\Framework\v1.1.4322\ilasm.exe
+ 2003-02-21 01:06 . 2003-02-21 01:06 282624 c:\windows\Microsoft.NET\Framework\v1.1.4322\fusion.dll
+ 2003-02-21 01:16 . 2003-02-21 01:16 798720 c:\windows\Microsoft.NET\Framework\v1.1.4322\EventLogMessages.dll
+ 2003-02-21 16:21 . 2003-02-21 16:21 524288 c:\windows\Microsoft.NET\Framework\v1.1.4322\diasymreader.dll
+ 2003-02-21 16:21 . 2003-02-21 16:21 626688 c:\windows\Microsoft.NET\Framework\v1.1.4322\cscomp.dll
+ 2002-07-29 17:11 . 2002-07-29 17:11 219136 c:\windows\Microsoft.NET\Framework\v1.1.4322\c_g18030.dll
+ 2003-02-21 01:19 . 2003-02-21 01:19 253952 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2003-02-21 11:04 . 2003-02-21 11:04 155648 c:\windows\Microsoft.NET\Framework\v1.1.4322\1033\Vsavb7rtUI.dll
+ 2003-02-21 09:02 . 2003-02-21 09:02 131072 c:\windows\Microsoft.NET\Framework\v1.1.4322\1033\vbc7ui.dll
+ 2008-04-14 03:42 . 2008-04-14 03:42 373248 c:\windows\iwajiwanomoh.dll
+ 2010-03-16 09:19 . 1998-10-29 22:45 306688 c:\windows\IsUninst.exe
- 2010-03-16 09:19 . 1998-10-29 23:45 306688 c:\windows\IsUninst.exe
+ 2011-05-25 05:22 . 2011-05-25 05:22 290304 c:\windows\Installer\e87156.msi
+ 2011-05-25 05:22 . 2011-05-25 05:22 129536 c:\windows\Installer\e87151.msi
+ 2011-05-25 05:22 . 2011-05-25 05:22 342016 c:\windows\Installer\e8714c.msi
+ 2011-05-25 05:22 . 2011-05-25 05:22 287232 c:\windows\Installer\e87146.msi
+ 2011-05-25 05:22 . 2011-05-25 05:22 259584 c:\windows\Installer\e8713c.msi
+ 2011-04-12 00:16 . 2011-04-12 00:16 836096 c:\windows\Installer\de7bc2.msi
+ 2011-05-25 23:29 . 2011-05-25 23:29 180224 c:\windows\Installer\18557a.msi
- 2010-12-31 03:06 . 2010-12-31 03:06 380928 c:\windows\Installer\{881F5DE8-9367-4B81-A325-E91BBC6472F9}\iTunesIco.exe
+ 2010-12-31 03:06 . 2011-04-17 04:58 380928 c:\windows\Installer\{881F5DE8-9367-4B81-A325-E91BBC6472F9}\iTunesIco.exe
+ 2011-05-25 23:24 . 2011-05-25 23:24 102400 c:\windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}\ARPPRODUCTICON.exe
+ 2011-05-25 05:21 . 2011-05-25 05:21 835584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_43d9b6d2\System.Drawing.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 569344 c:\windows\assembly\GAC\System.Web.Services\1.0.5000.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 819200 c:\windows\assembly\GAC\System.Web.Mobile\1.0.5000.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 126976 c:\windows\assembly\GAC\System.ServiceProcess\1.0.5000.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 131072 c:\windows\assembly\GAC\System.Runtime.Serialization.Formatters.Soap\1.0.5000.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 323584 c:\windows\assembly\GAC\System.Runtime.Remoting\1.0.5000.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 241664 c:\windows\assembly\GAC\System.Messaging\1.0.5000.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 368640 c:\windows\assembly\GAC\System.Management\1.0.5000.0__b03f5f7f11d50a3a\System.Management.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 241664 c:\windows\assembly\GAC\System.EnterpriseServices\1.0.5000.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 466944 c:\windows\assembly\GAC\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 299008 c:\windows\assembly\GAC\System.Data.OracleClient\1.0.5000.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 299008 c:\windows\assembly\GAC\Microsoft.VisualBasic\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 716800 c:\windows\assembly\GAC\Microsoft.JScript\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2010-01-27 01:07 . 2011-05-22 01:14 6271136 c:\windows\system32\Macromed\Flash\NPSWF32.dll
+ 2003-02-21 11:04 . 2003-02-21 11:04 1032192 c:\windows\Microsoft.NET\Framework\v1.1.4322\VsaVb7rt.dll
+ 2003-02-21 13:27 . 2003-02-21 13:27 1335296 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.XML.dll
+ 2003-02-21 13:27 . 2003-02-21 13:27 2039808 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Windows.Forms.dll
+ 2003-02-21 13:27 . 2003-02-21 13:27 1245184 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
+ 2003-02-21 13:26 . 2003-02-21 13:26 1216512 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
+ 2003-02-21 13:26 . 2003-02-21 13:26 1699840 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Design.dll
+ 2003-02-21 13:26 . 2003-02-21 13:26 1290240 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Data.dll
+ 2003-02-21 01:08 . 2003-02-21 01:08 2482176 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
+ 2003-02-21 01:07 . 2003-02-21 01:07 2494464 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
+ 2003-02-21 13:26 . 2003-02-21 13:26 2088960 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
+ 2003-02-21 13:25 . 2003-02-21 13:25 1564672 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorcfg.dll
+ 2011-05-25 05:21 . 2011-05-25 05:21 3443712 c:\windows\Installer\e87137.msi
+ 2011-05-03 05:12 . 2011-05-03 05:12 1094656 c:\windows\Installer\248541.msi
+ 2011-04-12 03:39 . 2011-04-12 03:39 6860800 c:\windows\Installer\198322e.msi
+ 2011-04-12 03:35 . 2011-04-12 03:35 1093632 c:\windows\Installer\194333d.msi
+ 2011-05-25 23:24 . 2011-05-25 23:24 2086912 c:\windows\Installer\185563.msi
+ 2011-05-25 05:21 . 2011-05-25 05:21 1929216 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_4cebc016\System.dll
+ 2011-05-25 05:22 . 2011-05-25 05:22 2076672 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_29b184c0\System.Xml.dll
+ 2011-05-25 05:21 . 2011-05-25 05:21 2994176 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_b5723932\System.Windows.Forms.dll
+ 2011-05-25 05:21 . 2011-05-25 05:21 1462272 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_4e5ab97a\System.Design.dll
+ 2011-05-25 05:21 . 2011-05-25 05:21 3289088 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_1890da0b\mscorlib.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 1216512 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 1335296 c:\windows\assembly\GAC\System.Xml\1.0.5000.0__b77a5c561934e089\System.Xml.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 2039808 c:\windows\assembly\GAC\System.Windows.Forms\1.0.5000.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 1245184 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 1699840 c:\windows\assembly\GAC\System.Design\1.0.5000.0__b03f5f7f11d50a3a\System.Design.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 1290240 c:\windows\assembly\GAC\System.Data\1.0.5000.0__b77a5c561934e089\System.Data.dll
+ 2011-05-25 05:20 . 2011-05-25 05:20 1564672 c:\windows\assembly\GAC\mscorcfg\1.0.5000.0__b03f5f7f11d50a3a\mscorcfg.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 4"="c:\program files\IObit\Advanced SystemCare 4\ASCTray.exe" [2011-04-21 402832]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2011-03-13 2548552]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2010-05-26 323976]
"IObit Security 360"="c:\program files\IObit\IObit Security 360\IS360tray.exe" [2010-06-12 1280344]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
setup_9.0.0.722_26.05.2011_08-18.lnk - c:\documents and settings\Administrator\Desktop\Virus Removal Tool\setup_9.0.0.722_26.05.2011_08-18\startup.exe [2011-5-25 72208]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoSMMyPictures"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoSMMyPictures"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Belkin Wireless Networking Utility.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Belkin Wireless Networking Utility.lnk
backup=c:\windows\pss\Belkin Wireless Networking Utility.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyDVD]
2010-04-03 06:27 499712 ----a-w- c:\program files\SlySoft\AnyDVD\AnyDVD.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FmctrlTray]
2001-08-21 03:47 270336 ----a-w- c:\windows\system32\fmctrl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-12-14 00:16 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Monitor]
2010-11-19 19:38 193880 ----a-w- c:\program files\LeapFrog\LeapFrog Connect\Monitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-01-07 19:12 253672 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemTray]
2001-08-23 12:00 3072 ----a-w- c:\windows\system32\systray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirtualCloneDrive]
2006-04-29 13:21 94208 ----a-w- c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"TapiSrv"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
.
R0 61709312;61709312 Boot Guard Driver;c:\windows\system32\drivers\61709312.sys [5/25/2011 11:25 PM 37392]
R1 61709311;61709311;c:\windows\system32\drivers\61709311.sys [5/25/2011 11:25 PM 128016]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [3/3/2010 8:54 PM 239368]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [3/3/2010 8:54 PM 27576]
R1 setup_9.0.0.722_26.05.2011_08-18drv;setup_9.0.0.722_26.05.2011_08-18drv;c:\windows\system32\drivers\6170931.sys [5/25/2011 11:25 PM 315408]
R2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\IObit\Advanced SystemCare 4\ASCService.exe [5/2/2011 11:02 PM 352656]
R2 CLPSLS;COMODO livePCsupport Service;c:\program files\COMODO\COMODO livePCsupport\CLPSLS.exe [2/12/2010 8:23 PM 148744]
R2 IS360service;IS360service;c:\program files\IObit\IObit Security 360\is360srv.exe [5/2/2011 11:26 PM 312152]
R3 gameport;FM801 PCI Joystick;c:\windows\system32\drivers\fmjoy.sys [9/20/2010 5:11 PM 9728]
R3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8192su.sys [11/15/2010 11:24 PM 584832]
R3 wdm_fm801;FM801 PCI Audio (WDM);c:\windows\system32\drivers\fm801.sys [9/20/2010 5:11 PM 328320]
S4 Belkin Wifi Service;Belkin Wifi Service;c:\program files\Belkin\F5D8053\v6\WifiSvc.exe [11/15/2010 11:24 PM 274432]
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - PROCEXP141
.
Contents of the 'Scheduled Tasks' folder
.
2011-05-27 c:\windows\Tasks\ASC4_PerformanceMonitor.job
- c:\program files\IObit\Advanced SystemCare 4\PMonitor.exe [2011-05-03 22:54]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\9n6pn6yn.default\
FF - prefs.js: browser.startup.homepage - google.com
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\Ask.com\GenericAskToolbar.dll
Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\Ask.com\GenericAskToolbar.dll
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-05-27 00:33
Windows 5.1.2600 Service Pack 3 NTFS
.
detected NTDLL code modification:
ZwClose, ZwOpenFile
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-583907252-1637723038-1644491937-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,18,d6,e8,47,20,2f,00,48,a0,20,fd,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,42,ca,e9,2c,bb,69,9d,42,b6,cf,3b,\
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,18,d6,e8,47,20,2f,00,48,a0,20,fd,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(916)
c:\windows\system32\guard32.dll
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'lsass.exe'(972)
c:\windows\system32\guard32.dll
.
Completion time: 2011-05-27 00:37:57
ComboFix-quarantined-files.txt 2011-05-27 06:37
ComboFix2.txt 2011-05-25 02:23
ComboFix3.txt 2011-05-25 00:28
ComboFix4.txt 2011-05-01 05:09
ComboFix5.txt 2011-05-27 06:19
.
Pre-Run: 179,528,462,336 bytes free
Post-Run: 179,522,789,376 bytes free
.
- - End Of File - - E650EF69C22EAF14CFFF94BFF7B1F8AB