Here is the log from the recent CFScript file:
ComboFix 10-10-30.05 - HY Blair 06/11/2010 9:51.7.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1309 [GMT 0:00]
Running from: c:\documents and settings\WinXP\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\WinXP\Desktop\CFScript.txt
AV: BitDefender Antivirus *On-access scanning disabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: BitDefender Firewall *disabled* {4055920F-2E99-48A8-A270-4243D2B8F242}
.
- REDUCED FUNCTIONALITY MODE -
.
((((((((((((((((((((((((( Files Created from 2010-10-06 to 2010-11-06 )))))))))))))))))))))))))))))))
.
2010-11-05 17:05 . 2010-11-05 18:07 -------- d-----w- C:\MyMusic
2010-11-05 17:04 . 2010-11-05 17:13 -------- d-----w- c:\program files\1-Click YouTube To MP3 Converter
2010-11-05 11:15 . 2010-11-05 11:15 -------- d-----w- C:\bin
2010-11-05 11:13 . 2010-11-05 11:13 -------- d-----w- c:\program files\Common Files\Sonic Shared
2010-11-05 11:04 . 2006-03-03 21:03 69632 ----a-w- c:\windows\system32\HPZipm12.1
2010-11-05 11:04 . 2010-11-05 11:04 -------- d-----w- c:\windows\LastGood
2010-11-03 07:39 . 2010-11-03 07:49 -------- d-----w- c:\documents and settings\WinXP\Application Data\Paltalk
2010-11-03 07:39 . 2010-11-03 07:39 -------- d-----w- c:\windows\PaltalkScene
2010-11-03 07:39 . 2010-11-03 07:39 -------- d-----w- c:\program files\Paltalk Messenger
2010-11-02 14:50 . 2010-11-02 14:49 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-11-02 14:49 . 2010-11-02 14:49 -------- d-----w- c:\program files\Java
2010-10-23 12:00 . 2008-04-14 04:43 40840 -c--a-w- c:\windows\system32\dllcache\termdd.sys
2010-10-23 12:00 . 2008-04-14 04:43 40840 ----a-w- c:\windows\system32\drivers\termdd.sys
2010-10-14 07:52 . 2010-10-14 07:52 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Identities
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-02 14:49 . 2010-06-02 14:37 472808 ----a-w- c:\windows\system32\deployJava1.dll
2006-07-23 08:45 . 2006-07-23 08:45 1923095 -c--a-w- c:\program files\WinRAR Crystal Edition 2006.exe
2006-07-23 08:45 . 2006-07-23 08:45 1107227 -c--a-w- c:\program files\WinRAR 3.51 Corporate Edition.exe
2006-07-23 08:45 . 2006-07-23 08:45 1039753 -c--a-w- c:\program files\Winrar 3.60 Beta 4 Enterprise Edition Oem.exe
2004-03-11 13:27 . 2006-04-25 08:06 40960 -c--a-w- c:\program files\Uninstall_CDS.exe
.
((((((((((((((((((((((((((((( SnapShot@2010-10-23_12.20.50 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-11-05 11:07 . 2010-11-05 11:07 82432 c:\windows\WinSxS\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\msxml4r.dll
- 2006-12-18 10:52 . 2006-12-18 10:52 82432 c:\windows\WinSxS\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.0.0_x-ww_29c3ad6a\msxml4r.dll
+ 2010-11-05 10:44 . 2010-11-05 10:44 16384 c:\windows\temp\Perflib_Perfdata_688.dat
+ 2005-10-05 12:12 . 2009-08-06 18:24 35552 c:\windows\system32\wups.dll
+ 2005-10-05 12:12 . 2009-08-06 18:24 53472 c:\windows\system32\wuauclt.exe
- 2004-08-04 12:00 . 2010-06-01 13:10 86526 c:\windows\system32\perfc009.dat
+ 2004-08-04 12:00 . 2010-10-31 13:26 86526 c:\windows\system32\perfc009.dat
+ 2006-09-07 15:21 . 2010-11-05 11:27 38200 c:\windows\system32\GDIPFONTCACHEV1.DAT
+ 2005-10-05 12:12 . 2009-08-06 18:24 35552 c:\windows\system32\dllcache\wups.dll
+ 2005-10-05 12:12 . 2009-08-06 18:24 53472 c:\windows\system32\dllcache\wuauclt.exe
+ 2004-08-04 12:00 . 2009-08-06 18:24 96480 c:\windows\system32\dllcache\cdm.dll
+ 2010-05-31 21:24 . 2010-11-05 11:05 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2010-05-31 21:24 . 2010-06-03 09:14 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2005-10-05 12:22 . 2010-11-05 11:05 49152 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2005-10-05 12:22 . 2010-06-03 09:14 49152 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2010-11-05 11:05 . 2010-11-05 11:05 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2004-08-04 12:00 . 2009-08-06 18:24 96480 c:\windows\system32\cdm.dll
+ 2006-12-18 10:53 . 2010-11-05 11:09 65536 c:\windows\Installer\{DBC20735-34E6-4E97-A9E5-2066B66B243D}\NewShortcut1.A6CC6977_F7B4_4C0B_9510_BCD847D4BDB2.exe
- 2006-12-18 10:53 . 2006-12-18 10:53 65536 c:\windows\Installer\{DBC20735-34E6-4E97-A9E5-2066B66B243D}\NewShortcut1.A6CC6977_F7B4_4C0B_9510_BCD847D4BDB2.exe
+ 2010-11-05 11:08 . 2010-11-05 11:08 65536 c:\windows\Installer\{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}\ARPPRODUCTICON.exe
- 2006-12-18 10:53 . 2006-12-18 10:53 65536 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut27.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
+ 2006-12-18 10:53 . 2010-11-05 11:09 65536 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut27.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
- 2006-12-18 10:53 . 2006-12-18 10:53 65536 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut25.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
+ 2006-12-18 10:53 . 2010-11-05 11:09 65536 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut25.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
- 2006-11-02 16:44 . 2006-12-18 10:53 65536 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut15_1.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
+ 2006-11-02 16:44 . 2010-11-05 11:09 65536 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut15_1.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
+ 2006-02-19 03:28 . 2006-02-19 03:28 12288 c:\windows\Fonts\RandFont.dll
+ 2005-08-19 03:00 . 2005-08-19 03:00 2560 c:\windows\system32\drivers\cdralw2k.sys
+ 2005-08-19 03:00 . 2005-08-19 03:00 2432 c:\windows\system32\drivers\cdr4_xp.sys
- 2006-12-18 10:54 . 2006-12-18 10:54 4286 c:\windows\Installer\{B6286A44-7505-471A-A72B-04EC2DB2F442}\Shortcut_start.9FAB98ED_2143_4534_9750_7CD4ECEB9596.exe
+ 2006-12-18 10:54 . 2010-11-05 11:11 4286 c:\windows\Installer\{B6286A44-7505-471A-A72B-04EC2DB2F442}\Shortcut_start.9FAB98ED_2143_4534_9750_7CD4ECEB9596.exe
+ 2005-10-05 12:12 . 2009-08-06 18:24 209632 c:\windows\system32\wuweb.dll
+ 2005-10-05 12:12 . 2009-08-06 18:24 327896 c:\windows\system32\wucltui.dll
+ 2005-10-05 12:12 . 2009-08-06 18:23 575704 c:\windows\system32\wuapi.dll
+ 2005-09-29 15:05 . 2005-09-29 15:05 151552 c:\windows\system32\pxwma.dll
- 2004-08-04 12:00 . 2010-06-01 13:10 477602 c:\windows\system32\perfh009.dat
+ 2004-08-04 12:00 . 2010-10-31 13:26 477602 c:\windows\system32\perfh009.dat
- 2010-06-02 14:37 . 2010-06-02 14:37 153376 c:\windows\system32\javaws.exe
+ 2010-11-02 14:50 . 2010-11-02 14:49 153376 c:\windows\system32\javaws.exe
- 2010-06-02 14:37 . 2010-06-02 14:37 145184 c:\windows\system32\javaw.exe
+ 2010-11-02 14:50 . 2010-11-02 14:49 145184 c:\windows\system32\javaw.exe
- 2010-06-02 14:37 . 2010-06-02 14:37 145184 c:\windows\system32\java.exe
+ 2010-11-02 14:50 . 2010-11-02 14:49 145184 c:\windows\system32\java.exe
+ 2004-05-27 14:00 . 2004-05-27 14:00 118784 c:\windows\system32\HPODXPAT.DLL
+ 2005-10-05 12:12 . 2009-08-06 18:24 209632 c:\windows\system32\dllcache\wuweb.dll
+ 2005-10-05 12:12 . 2009-08-06 18:24 327896 c:\windows\system32\dllcache\wucltui.dll
+ 2005-10-05 12:12 . 2009-08-06 18:23 575704 c:\windows\system32\dllcache\wuapi.dll
+ 2005-10-05 12:29 . 2002-07-12 10:15 106496 c:\windows\SiSUSBrg.exe
+ 2010-11-03 07:39 . 2010-11-03 07:39 580096 c:\windows\PaltalkScene\uninstall.exe
+ 2010-11-05 11:10 . 2010-11-05 11:10 344064 c:\windows\Installer\edf26.msi
+ 2010-11-05 11:10 . 2010-11-05 11:10 338944 c:\windows\Installer\edf21.msi
+ 2010-11-05 11:10 . 2010-11-05 11:10 557056 c:\windows\Installer\edf1c.msi
+ 2010-11-05 11:10 . 2010-11-05 11:10 325632 c:\windows\Installer\edf16.msi
+ 2010-11-05 11:10 . 2010-11-05 11:10 316416 c:\windows\Installer\edf11.msi
+ 2010-11-05 11:10 . 2010-11-05 11:10 467456 c:\windows\Installer\edf0c.msi
+ 2010-11-05 11:09 . 2010-11-05 11:09 488448 c:\windows\Installer\edefd.msi
+ 2010-11-05 11:09 . 2010-11-05 11:09 537088 c:\windows\Installer\edef7.msi
+ 2010-11-05 11:09 . 2010-11-05 11:09 121344 c:\windows\Installer\edec8.msi
+ 2010-11-05 11:09 . 2010-11-05 11:09 489472 c:\windows\Installer\edec3.msi
+ 2010-11-05 11:09 . 2010-11-05 11:09 667136 c:\windows\Installer\edebd.msi
+ 2010-11-05 11:08 . 2010-11-05 11:08 492032 c:\windows\Installer\ede88.msi
+ 2010-11-05 11:08 . 2010-11-05 11:08 121344 c:\windows\Installer\ede83.msi
+ 2010-11-05 11:08 . 2010-11-05 11:08 183296 c:\windows\Installer\ede7b.msi
+ 2010-11-05 11:07 . 2010-11-05 11:07 437248 c:\windows\Installer\ede73.msi
+ 2010-11-05 11:07 . 2010-11-05 11:07 202240 c:\windows\Installer\ede6b.msi
+ 2010-11-05 11:07 . 2010-11-05 11:07 795136 c:\windows\Installer\ede66.msi
+ 2010-11-05 11:07 . 2010-11-05 11:07 547840 c:\windows\Installer\ede3e.msi
+ 2010-11-05 11:07 . 2010-11-05 11:07 637952 c:\windows\Installer\ede2e.msi
+ 2010-11-05 11:06 . 2010-11-05 11:06 334848 c:\windows\Installer\ede1e.msi
+ 2010-11-05 10:26 . 2010-11-05 10:26 425984 c:\windows\Installer\59f189a.msi
+ 2010-11-02 14:50 . 2010-11-02 14:50 180224 c:\windows\Installer\54277.msi
+ 2010-11-02 14:49 . 2010-11-02 14:49 677376 c:\windows\Installer\54272.msi
+ 2010-11-05 11:17 . 2010-11-05 11:17 244224 c:\windows\Installer\1bf6b0.msi
+ 2010-11-05 11:17 . 2010-11-05 11:17 323072 c:\windows\Installer\1bf6a6.msi
+ 2010-11-05 11:16 . 2010-11-05 11:16 291328 c:\windows\Installer\1bf699.msi
+ 2010-11-05 11:15 . 2010-11-05 11:15 121344 c:\windows\Installer\1bf691.msi
+ 2010-11-05 11:15 . 2010-11-05 11:15 477696 c:\windows\Installer\1bf68c.msi
+ 2010-11-05 11:15 . 2010-11-05 11:15 121344 c:\windows\Installer\1bf684.msi
+ 2010-11-05 11:15 . 2010-11-05 11:15 121344 c:\windows\Installer\1bf67c.msi
+ 2010-11-05 11:13 . 2010-11-05 11:13 609280 c:\windows\Installer\197a4b.msi
+ 2010-11-05 11:13 . 2010-11-05 11:13 304128 c:\windows\Installer\19795e.msi
+ 2010-11-05 11:13 . 2010-11-05 11:13 304128 c:\windows\Installer\197958.msi
+ 2010-11-05 11:13 . 2010-11-05 11:13 310272 c:\windows\Installer\197952.msi
+ 2010-11-05 11:13 . 2010-11-05 11:13 390144 c:\windows\Installer\19794c.msi
+ 2010-11-05 11:13 . 2010-11-05 11:13 314368 c:\windows\Installer\197943.msi
+ 2010-11-05 11:12 . 2010-11-05 11:12 304128 c:\windows\Installer\19793e.msi
+ 2010-11-05 11:12 . 2010-11-05 11:12 314368 c:\windows\Installer\197938.msi
+ 2010-11-05 11:12 . 2010-11-05 11:12 303104 c:\windows\Installer\197933.msi
+ 2010-11-05 11:11 . 2010-11-05 11:11 479232 c:\windows\Installer\1978ff.msi
+ 2010-11-05 11:11 . 2010-11-05 11:11 121344 c:\windows\Installer\1978f7.msi
+ 2010-11-05 11:08 . 2010-11-05 11:08 643072 c:\windows\Installer\{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}\HPSUShortcut_BB85ED9CAFC943BDB8DC258C3C7DF72E.exe
- 2006-11-02 16:44 . 2006-12-18 10:53 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut9.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
+ 2006-11-02 16:44 . 2010-11-05 11:09 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut9.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
+ 2006-11-02 16:44 . 2010-11-05 11:09 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut8.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
- 2006-11-02 16:44 . 2006-12-18 10:53 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut8.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
+ 2006-11-02 16:44 . 2010-11-05 11:09 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut7.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
- 2006-11-02 16:44 . 2006-12-18 10:53 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut7.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
- 2006-12-18 10:53 . 2006-12-18 10:53 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut6.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
+ 2006-12-18 10:53 . 2010-11-05 11:09 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut6.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
+ 2006-11-02 16:44 . 2010-11-05 11:09 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut24.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
- 2006-11-02 16:44 . 2006-12-18 10:53 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut24.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
+ 2006-11-02 16:44 . 2010-11-05 11:09 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut23.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
- 2006-11-02 16:44 . 2006-12-18 10:53 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut23.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
+ 2006-11-02 16:44 . 2010-11-05 11:09 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut22.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
- 2006-11-02 16:44 . 2006-12-18 10:53 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut22.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
- 2006-11-02 16:44 . 2006-12-18 10:53 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut21.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
+ 2006-11-02 16:44 . 2010-11-05 11:09 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut21.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
+ 2006-11-02 16:44 . 2010-11-05 11:09 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut20.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
- 2006-11-02 16:44 . 2006-12-18 10:53 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut20.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
- 2006-11-02 16:44 . 2006-12-18 10:53 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut2.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
+ 2006-11-02 16:44 . 2010-11-05 11:09 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut2.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
- 2006-11-02 16:44 . 2006-12-18 10:53 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut19.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
+ 2006-11-02 16:44 . 2010-11-05 11:09 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut19.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
- 2006-11-02 16:44 . 2006-12-18 10:53 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut18.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
+ 2006-11-02 16:44 . 2010-11-05 11:09 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut18.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
- 2006-11-02 16:44 . 2006-12-18 10:53 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut17.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
+ 2006-11-02 16:44 . 2010-11-05 11:09 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut17.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
- 2006-11-02 16:44 . 2006-12-18 10:53 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut16.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
+ 2006-11-02 16:44 . 2010-11-05 11:09 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut16.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
+ 2006-11-02 16:44 . 2010-11-05 11:09 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut14.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
- 2006-11-02 16:44 . 2006-12-18 10:53 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut14.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
+ 2006-11-02 16:44 . 2010-11-05 11:09 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut13.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
- 2006-11-02 16:44 . 2006-12-18 10:53 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut13.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
- 2006-11-02 16:44 . 2006-12-18 10:53 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut12.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
+ 2006-11-02 16:44 . 2010-11-05 11:09 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut12.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
+ 2006-11-02 16:44 . 2010-11-05 11:09 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut11.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
- 2006-11-02 16:44 . 2006-12-18 10:53 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut11.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
+ 2006-11-02 16:44 . 2010-11-05 11:09 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut10.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
- 2006-11-02 16:44 . 2006-12-18 10:53 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut10.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
- 2006-11-02 16:44 . 2006-12-18 10:53 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut1.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
+ 2006-11-02 16:44 . 2010-11-05 11:09 110592 c:\windows\Installer\{8CE4E6E9-9D55-43FB-9DDB-688C976BFC05}\NewShortcut1.DE9B046B_865A_4DEC_B555_7F4B3C92BD42.exe
- 2006-12-18 10:40 . 2006-12-18 11:04 117092 c:\windows\hpoins11.dat
+ 2010-11-05 11:01 . 2010-11-05 11:26 117092 c:\windows\hpoins11.dat
+ 2010-11-05 11:07 . 2010-11-05 11:07 1230336 c:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.1.0.0_x-ww_b319d8da\msxml4.dll
- 2006-12-18 10:52 . 2006-12-18 10:52 1230336 c:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.1.0.0_x-ww_b319d8da\msxml4.dll
+ 2005-10-05 12:12 . 2009-08-06 18:23 1929952 c:\windows\system32\wuaueng.dll
+ 2005-12-09 13:47 . 2005-12-09 13:47 1645320 c:\windows\system32\gdiplus.dll
+ 2005-10-05 12:12 . 2009-08-06 18:23 1929952 c:\windows\system32\dllcache\wuaueng.dll
+ 2010-11-05 11:09 . 2010-11-05 11:09 3155456 c:\windows\Installer\eded2.msi
+ 2010-11-05 11:08 . 2010-11-05 11:08 1241600 c:\windows\Installer\ede7e.msi
+ 2010-11-05 11:16 . 2010-11-05 11:16 1939968 c:\windows\Installer\1bf6a0.msi
+ 2010-11-05 11:15 . 2010-11-05 11:15 1152512 c:\windows\Installer\1bf676.msi
+ 2010-11-05 11:14 . 2010-11-05 11:14 3443712 c:\windows\Installer\1bf5d5.msi
+ 2010-11-05 11:13 . 2010-11-05 11:13 4443648 c:\windows\Installer\197963.msi
+ 2010-11-05 11:12 . 2010-11-05 11:12 1795584 c:\windows\Installer\197926.msi
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiS Windows KeyHook"="c:\windows\system32\keyhook.exe" [2003-12-05 249856]
"CTSysVol"="c:\program files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe" [2003-09-17 57344]
"Adobe_ID0ENQBO"="c:\progra~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" [2008-08-15 378224]
"BDAgent"="c:\program files\BitDefender\BitDefender 2010\bdagent.exe" [2010-03-18 1123360]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2010\IEShow.exe" [2009-10-19 71152]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-17 421888]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-11 640376]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2006-2-10 73728]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MaxRecentDocs"= 99 (0x63)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0sasnative32
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 6:25 PM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 6:41 PM 67656]
R2 ASO3DiskOptimizer;ASO3DiskOptimizer;c:\program files\Advanced System Optimizer 3\ASO3DefragSrv.exe [5/26/2010 4:02 PM 199400]
R2 BDVEDISK;BDVEDISK;c:\program files\BitDefender\BitDefender 2010\bdvedisk.sys [1/19/2010 6:32 PM 85128]
R2 PfDetNT;PfDetNT;c:\windows\system32\drivers\pfmodnt.sys [3/5/2003 7:07 AM 15840]
R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [2/3/2010 12:57 PM 153448]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [1/4/2010 6:41 PM 111312]
S3 ADASPROT;SYSTWEAKASO;c:\program files\Advanced System Optimizer 3\adasprot32.sys [5/26/2010 4:02 PM 6656]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [8/15/2008 4:46 AM 284016]
S3 Arrakis3;BitDefender Arrakis Server;c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe [10/19/2009 4:06 PM 183880]
S3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\System32\svchost.exe -k nosGetPlusHelper [8/4/2004 12:00 PM 14336]
S3 S3G700;S3G700;c:\windows\system32\DRIVERS\S3G700m.sys --> c:\windows\system32\DRIVERS\S3G700m.sys [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - 12BEB740
*NewlyCreated* - HP_PORT_RESOLVER
*NewlyCreated* - HP_STATUS_SERVER
*NewlyCreated* - PML_DRIVER_HPZ12
*Deregistered* - 12beb740
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2010-11-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 10:50]
2010-11-05 c:\windows\Tasks\Disk Cleanup.job
- c:\windows\system32\cleanmgr.exe [2004-08-04 04:42]
2010-11-05 c:\windows\Tasks\Disk Defragmenter.job
- c:\windows\system32\dfrg.msc [2004-08-04 12:00]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.optionsxpress.com/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/ymj/*http://www.yahoo.com
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: pandasoftware.com\acs
Trusted Zone: pandasoftware.com\activescan
Trusted Zone: pandasoftware.com\www
Trusted Zone: pandasoftware.es\www
FF - ProfilePath - c:\documents and settings\WinXP\Application Data\Mozilla\Firefox\Profiles\gexs7lyq.Daz\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT329536&SearchSource=3&q=
FF - prefs.js: browser.search.selectedEngine - Google.co.uk
FF - prefs.js: browser.startup.homepage - hxxp://www.elliottwave.com
FF - plugin: c:\documents and settings\WinXP\Application Data\Mozilla\Firefox\Profiles\gexs7lyq.Daz\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npitunes.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Veetle\Player\npvlc.dll
FF - plugin: c:\program files\Veetle\plugins\npVeetle.dll
FF - plugin: c:\program files\Veetle\VLCBroadcast\npvbp.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-11-06 09:53
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(716)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2010-11-06 09:55:17
ComboFix-quarantined-files.txt 2010-11-06 09:55
ComboFix2.txt 2010-11-03 13:53
ComboFix3.txt 2010-11-02 14:26
ComboFix4.txt 2010-11-01 18:35
ComboFix5.txt 2010-11-06 09:44
Pre-Run: 86,800,850,944 bytes free
Post-Run: 86,785,007,616 bytes free
- - End Of File - - F463650FF2E2F388DA11E68E45D23B9B