(Continuation of Combofix Log...)
+ 2009-11-08 09:00 . 2009-08-27 05:22 916480 c:\windows\System32\wininet.dll
+ 2009-11-08 08:59 . 2009-03-08 11:34 208384 c:\windows\System32\WinFXDocObj.exe
- 2008-01-21 02:23 . 2008-01-21 02:23 208384 c:\windows\System32\WinFXDocObj.exe
+ 2009-11-08 08:59 . 2009-03-08 11:34 236544 c:\windows\System32\webcheck.dll
+ 2006-11-02 13:05 . 2009-11-27 20:43 109788 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-11-08 08:59 . 2009-03-08 11:33 420352 c:\windows\System32\vbscript.dll
- 2008-01-21 02:24 . 2008-01-21 02:24 105984 c:\windows\System32\url.dll
+ 2009-11-08 08:59 . 2009-03-08 11:34 105984 c:\windows\System32\url.dll
+ 2009-11-08 08:59 . 2009-03-08 11:33 107008 c:\windows\System32\SetIEInstalledDate.exe
+ 2009-11-08 08:59 . 2009-03-08 11:33 103936 c:\windows\System32\SetDepNx.exe
+ 2009-11-08 08:59 . 2009-03-08 11:33 107520 c:\windows\System32\RegisterIEPKEYs.exe
- 2008-10-06 20:13 . 2008-10-06 20:13 288024 c:\windows\System32\PhysXCplUI.exe
+ 2008-11-25 19:55 . 2008-11-25 19:55 288024 c:\windows\System32\PhysXCplUI.exe
+ 2008-11-24 19:38 . 2008-11-24 19:38 288024 c:\windows\System32\PhysXCompatCplUI.exe
- 2008-10-06 20:13 . 2008-10-06 20:13 288024 c:\windows\System32\PhysXCompatCplUI.exe
- 2006-11-02 10:33 . 2009-11-08 08:15 638346 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-11-27 20:49 638346 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-11-08 08:15 121342 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:33 . 2009-11-27 20:49 121342 c:\windows\System32\perfc009.dat
+ 2009-11-08 08:59 . 2009-03-08 11:33 109568 c:\windows\System32\PDMSetup.exe
+ 2009-11-08 09:00 . 2009-08-27 05:20 206848 c:\windows\System32\occache.dll
+ 2009-11-08 08:59 . 2009-03-08 11:32 611840 c:\windows\System32\mstime.dll
+ 2009-11-08 08:59 . 2009-03-08 11:34 193536 c:\windows\System32\msrating.dll
- 2008-01-21 02:24 . 2008-01-21 02:24 156160 c:\windows\System32\msls31.dll
+ 2009-11-08 08:59 . 2009-03-08 11:22 156160 c:\windows\System32\msls31.dll
+ 2009-11-08 09:00 . 2009-08-27 05:18 594432 c:\windows\System32\msfeeds.dll
+ 2009-11-09 06:21 . 2009-06-06 05:01 726528 c:\windows\System32\jscript.dll
+ 2009-11-25 04:39 . 2009-11-25 04:38 149280 c:\windows\System32\javaws.exe
+ 2009-11-25 04:39 . 2009-11-25 04:38 145184 c:\windows\System32\javaw.exe
+ 2009-11-25 04:39 . 2009-11-25 04:38 145184 c:\windows\System32\java.exe
+ 2009-11-08 08:59 . 2009-03-08 11:32 169472 c:\windows\System32\iexpress.exe
+ 2009-11-08 09:00 . 2009-08-27 03:42 133632 c:\windows\System32\ieUnatt.exe
+ 2009-11-08 09:00 . 2009-08-27 05:17 164352 c:\windows\System32\ieui.dll
+ 2009-11-08 09:00 . 2009-08-27 05:17 109056 c:\windows\System32\iesysprep.dll
+ 2009-11-08 09:00 . 2009-08-27 05:17 184320 c:\windows\System32\iepeers.dll
+ 2009-11-08 09:00 . 2009-08-27 05:17 387584 c:\windows\System32\iedkcs32.dll
+ 2009-11-08 08:59 . 2009-03-08 11:11 445952 c:\windows\System32\ieapfltr.dll
+ 2009-11-08 08:59 . 2009-03-08 11:32 163840 c:\windows\System32\ieakui.dll
+ 2009-11-08 08:59 . 2009-03-08 11:33 229376 c:\windows\System32\ieaksie.dll
+ 2009-11-08 08:59 . 2009-03-08 11:33 125952 c:\windows\System32\ieakeng.dll
+ 2009-11-08 09:00 . 2009-08-27 03:42 173056 c:\windows\System32\ie4uinit.exe
+ 2006-11-02 12:47 . 2009-11-11 19:38 370960 c:\windows\System32\FNTCACHE.DAT
- 2006-11-02 12:47 . 2009-07-15 21:36 370960 c:\windows\System32\FNTCACHE.DAT
+ 2009-11-08 08:59 . 2009-03-08 11:31 216064 c:\windows\System32\dxtrans.dll
+ 2009-11-08 08:59 . 2009-03-08 11:31 348160 c:\windows\System32\dxtmsft.dll
+ 2009-11-08 09:27 . 2009-11-26 04:40 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-11-08 08:59 . 2009-03-08 11:32 128512 c:\windows\System32\advpack.dll
+ 2009-11-25 04:38 . 2009-11-25 04:38 537600 c:\windows\Installer\ef4fc.msi
+ 2009-11-25 08:33 . 2009-11-25 08:33 429568 c:\windows\Installer\e558b3.msi
+ 2009-11-20 07:44 . 2009-11-20 07:44 847872 c:\windows\Installer\9308ef.msi
+ 2009-11-20 07:44 . 2009-11-20 07:44 752128 c:\windows\Installer\9308e1.msi
- 2009-02-10 08:41 . 2009-10-14 19:21 888080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
+ 2009-02-10 08:41 . 2009-11-11 19:22 888080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
+ 2009-02-10 08:41 . 2009-11-11 19:22 272648 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
- 2009-02-10 08:41 . 2009-10-14 19:21 272648 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
+ 2009-02-10 08:41 . 2009-11-11 19:22 922384 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
- 2009-02-10 08:41 . 2009-10-14 19:21 922384 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
+ 2009-02-10 08:41 . 2009-11-11 19:22 845584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
- 2009-02-10 08:41 . 2009-10-14 19:21 845584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
- 2009-02-10 08:41 . 2009-10-14 19:21 217864 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
+ 2009-02-10 08:41 . 2009-11-11 19:22 217864 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
+ 2009-02-10 08:41 . 2009-11-11 19:22 184080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
- 2009-02-10 08:41 . 2009-10-14 19:21 184080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
+ 2009-02-10 08:41 . 2009-11-11 19:22 159504 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
- 2009-02-10 08:41 . 2009-10-14 19:21 159504 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
+ 2009-11-11 06:56 . 2009-11-11 06:56 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
- 2009-07-12 09:21 . 2009-07-12 09:21 223232 c:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
- 2009-07-12 09:21 . 2009-07-12 09:21 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2009-11-11 06:57 . 2009-11-11 06:57 178176 c:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
- 2009-07-12 09:21 . 2009-07-12 09:21 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
+ 2009-11-11 06:57 . 2009-11-11 06:57 364544 c:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
- 2009-07-12 09:21 . 2009-07-12 09:21 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2009-11-11 06:57 . 2009-11-11 06:57 159232 c:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
- 2009-07-12 09:21 . 2009-07-12 09:21 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2009-11-11 06:57 . 2009-11-11 06:57 145920 c:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2009-11-11 06:57 . 2009-11-11 06:57 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-07-12 09:21 . 2009-07-12 09:21 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-07-12 09:21 . 2009-07-12 09:21 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-11-11 06:56 . 2009-11-11 06:56 578560 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-11-11 06:56 . 2009-11-11 06:56 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-07-12 09:21 . 2009-07-12 09:21 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-11-11 06:56 . 2009-11-11 06:56 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-07-12 09:21 . 2009-07-12 09:21 577536 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-07-12 09:21 . 2009-07-12 09:21 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-11-11 06:56 . 2009-11-11 06:56 577024 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-11-11 06:56 . 2009-11-11 06:56 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-07-12 09:21 . 2009-07-12 09:21 576000 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-07-12 09:21 . 2009-07-12 09:21 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-11-11 06:56 . 2009-11-11 06:56 567296 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-07-12 09:21 . 2009-07-12 09:21 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-11-11 06:56 . 2009-11-11 06:56 563712 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-07-12 09:21 . 2009-07-12 09:21 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2009-11-11 06:56 . 2009-11-11 06:56 473600 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2009-11-25 08:33 . 2009-11-25 08:33 1348432 c:\windows\winsxs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9876.0_none_b7e610287b2b4ea5\msxml4.dll
+ 2009-11-11 01:29 . 2009-08-14 13:29 2045440 c:\windows\winsxs\x86_microsoft-windows-win32k_31bf3856ad364e35_6.0.6002.22200_none_bb639005b0cab34a\win32k.sys
+ 2009-11-11 01:29 . 2009-08-14 13:27 2036736 c:\windows\winsxs\x86_microsoft-windows-win32k_31bf3856ad364e35_6.0.6002.18091_none_ba79a25297f52b29\win32k.sys
+ 2009-11-11 01:29 . 2009-08-14 13:46 2036224 c:\windows\winsxs\x86_microsoft-windows-win32k_31bf3856ad364e35_6.0.6001.22497_none_b922cef1b3e70dd9\win32k.sys
+ 2009-11-11 01:29 . 2009-08-14 13:53 2035712 c:\windows\winsxs\x86_microsoft-windows-win32k_31bf3856ad364e35_6.0.6001.18311_none_b8e9afca9a8df67d\win32k.sys
+ 2009-11-11 01:29 . 2009-08-15 21:08 2032128 c:\windows\winsxs\x86_microsoft-windows-win32k_31bf3856ad364e35_6.0.6000.21108_none_b79eb803b676ce08\win32k.sys
+ 2009-11-11 01:29 . 2009-08-14 14:01 2031104 c:\windows\winsxs\x86_microsoft-windows-win32k_31bf3856ad364e35_6.0.6000.16908_none_b71543169d58fafc\win32k.sys
+ 2009-11-11 01:29 . 2009-10-16 08:39 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6002.22247_none_f4d3f2c581d85dd6\OESpamFilter.dat
+ 2009-11-11 01:29 . 2009-10-16 08:36 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6002.18124_none_f45cf4f468ad3a25\OESpamFilter.dat
+ 2009-11-11 01:29 . 2009-10-16 08:38 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.22544_none_f2ea7fff84b4bcad\OESpamFilter.dat
+ 2009-11-11 01:29 . 2009-10-16 08:39 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.18344_none_f260e14e6b971fbc\OESpamFilter.dat
+ 2009-11-11 01:29 . 2009-10-16 08:40 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.21142_none_f102170187902f29\OESpamFilter.dat
+ 2009-11-11 01:29 . 2009-10-16 08:41 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.16939_none_f08a74066e63f18d\OESpamFilter.dat
+ 2009-11-24 21:35 . 2009-08-11 16:58 1401856 c:\windows\winsxs\x86_microsoft-windows-msxml60_31bf3856ad364e35_6.0.6002.22196_none_8a82c317ad5def05\msxml6.dll
+ 2009-11-24 21:35 . 2009-08-11 16:44 1401856 c:\windows\winsxs\x86_microsoft-windows-msxml60_31bf3856ad364e35_6.0.6002.18087_none_8a04f68294374ca1\msxml6.dll
+ 2009-11-24 21:35 . 2009-08-11 15:26 1401344 c:\windows\winsxs\x86_microsoft-windows-msxml60_31bf3856ad364e35_6.0.6001.22492_none_88985007b03b3485\msxml6.dll
+ 2009-11-24 21:35 . 2009-08-10 11:01 1399296 c:\windows\winsxs\x86_microsoft-windows-msxml60_31bf3856ad364e35_6.0.6001.18306_none_887403b096d0fe9e\msxml6.dll
+ 2009-11-24 21:35 . 2009-08-10 12:51 1409536 c:\windows\winsxs\x86_microsoft-windows-msxml60_31bf3856ad364e35_6.0.6000.21103_none_87143919b2caf4b4\msxml6.dll
+ 2009-11-24 21:35 . 2009-08-10 13:05 1406464 c:\windows\winsxs\x86_microsoft-windows-msxml60_31bf3856ad364e35_6.0.6000.16903_none_868ac42c99ad21a8\msxml6.dll
+ 2009-11-24 21:35 . 2009-08-11 16:58 1248768 c:\windows\winsxs\x86_microsoft-windows-msxml30_31bf3856ad364e35_6.0.6002.22196_none_8a83076fad5da222\msxml3.dll
+ 2009-11-24 21:35 . 2009-08-11 16:44 1248768 c:\windows\winsxs\x86_microsoft-windows-msxml30_31bf3856ad364e35_6.0.6002.18087_none_8a053ada9436ffbe\msxml3.dll
+ 2009-11-24 21:35 . 2009-08-11 15:25 1257472 c:\windows\winsxs\x86_microsoft-windows-msxml30_31bf3856ad364e35_6.0.6001.22492_none_8898945fb03ae7a2\msxml3.dll
+ 2009-11-24 21:35 . 2009-08-10 11:00 1257472 c:\windows\winsxs\x86_microsoft-windows-msxml30_31bf3856ad364e35_6.0.6001.18306_none_8874480896d0b1bb\msxml3.dll
+ 2009-11-24 21:35 . 2009-08-10 12:51 1260032 c:\windows\winsxs\x86_microsoft-windows-msxml30_31bf3856ad364e35_6.0.6000.21103_none_87147d71b2caa7d1\msxml3.dll
+ 2009-11-24 21:35 . 2009-08-10 13:05 1260032 c:\windows\winsxs\x86_microsoft-windows-msxml30_31bf3856ad364e35_6.0.6000.16903_none_868b088499acd4c5\msxml3.dll
+ 2009-11-08 09:00 . 2009-08-27 13:21 1986048 c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_8.0.6001.22918_none_2b139d34bb6ff18c\iertutil.dll
+ 2009-11-08 09:00 . 2009-08-27 05:17 1985536 c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_8.0.6001.18828_none_2a7f307da25a6db3\iertutil.dll
+ 2009-11-08 08:59 . 2009-03-08 11:32 1985024 c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_8.0.6001.18702_none_2a8eccb3a24fa0a0\iertutil.dll
+ 2009-11-09 06:22 . 2009-10-21 19:26 5943296 c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_8.0.6001.22942_none_f68c93f75132f82e\mshtml.dll
+ 2009-11-08 09:00 . 2009-08-27 13:22 5942272 c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_8.0.6001.22918_none_f6b3057751153c65\mshtml.dll
+ 2009-11-09 06:22 . 2009-10-21 10:40 5939712 c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_8.0.6001.18852_none_f5f82740381d7455\mshtml.dll
+ 2009-11-08 09:00 . 2009-08-27 05:18 5940224 c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_8.0.6001.18828_none_f61e98c037ffb88c\mshtml.dll
+ 2009-11-08 08:59 . 2009-03-08 11:41 5937152 c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_8.0.6001.18702_none_f62e34f637f4eb79\mshtml.dll
+ 2009-11-08 08:59 . 2009-02-07 04:07 3698584 c:\windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_8.0.6001.18702_none_de7d38b18189fc96\ieapfltr.dat
+ 2009-11-08 09:00 . 2009-08-27 13:29 1209344 c:\windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_8.0.6001.22918_none_98530ab705b5ac9c\urlmon.dll
+ 2009-11-08 09:00 . 2009-08-27 05:22 1208832 c:\windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_8.0.6001.18828_none_97be9dffeca028c3\urlmon.dll
+ 2009-11-08 08:59 . 2009-03-08 11:34 1206784 c:\windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_8.0.6001.18702_none_97ce3a35ec955bb0\urlmon.dll
+ 2009-11-08 09:00 . 2009-08-27 05:22 1208832 c:\windows\System32\urlmon.dll
- 2006-11-02 10:22 . 2009-11-04 20:49 6291456 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2006-11-02 10:22 . 2009-11-25 13:25 6291456 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-07-20 11:05 . 2009-07-20 11:05 1348432 c:\windows\System32\msxml4.dll
+ 2009-11-09 06:22 . 2009-10-21 10:40 5939712 c:\windows\System32\mshtml.dll
+ 2009-11-08 09:00 . 2009-08-27 05:17 1985536 c:\windows\System32\iertutil.dll
+ 2009-11-08 08:59 . 2009-02-07 04:07 3698584 c:\windows\System32\ieapfltr.dat
+ 2009-11-11 07:14 . 2009-11-11 07:14 1500160 c:\windows\Installer\66eb96.msi
+ 2009-10-15 18:03 . 2009-10-15 18:03 5003776 c:\windows\Installer\46bc6.msp
+ 2009-08-17 23:58 . 2009-08-17 23:58 8301056 c:\windows\Installer\46b99.msp
+ 2009-08-17 23:57 . 2009-08-17 23:57 9122304 c:\windows\Installer\46b83.msp
+ 2009-11-24 11:06 . 2009-11-24 11:06 1583616 c:\windows\Installer\1e9b19.msi
- 2009-02-10 08:41 . 2009-10-14 19:21 1172240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
+ 2009-02-10 08:41 . 2009-11-11 19:22 1172240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
+ 2009-02-10 08:41 . 2009-11-11 19:22 1165584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
- 2009-02-10 08:41 . 2009-10-14 19:21 1165584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
- 2009-07-12 09:21 . 2009-07-12 09:21 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-11-11 06:56 . 2009-11-11 06:56 2846720 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
- 2009-07-12 09:21 . 2009-07-12 09:21 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-11-11 06:56 . 2009-11-11 06:56 2676224 c:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-11-08 09:00 . 2009-08-27 13:21 11069952 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_8.0.6001.22918_none_48125f7add0aca92\ieframe.dll
+ 2009-11-08 09:00 . 2009-08-27 05:17 11069440 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_8.0.6001.18828_none_477df2c3c3f546b9\ieframe.dll
+ 2009-11-08 08:59 . 2009-03-08 11:39 11063808 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_8.0.6001.18702_none_478d8ef9c3ea79a6\ieframe.dll
+ 2006-11-02 10:24 . 2009-11-05 17:36 26768832 c:\windows\System32\mrt.exe
+ 2009-11-08 09:00 . 2009-08-27 05:17 11069440 c:\windows\System32\ieframe.dll
+ 2009-08-18 00:19 . 2009-08-18 00:19 10098688 c:\windows\Installer\46bb0.msp
+ 2009-05-17 02:24 . 2009-11-25 08:33 200597337 c:\windows\winsxs\ManifestCache\6.0.6002.18005_001c11ba_blobs.bin
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-10-15 1115392]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-10-15 23:13 1115392 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-10-15 1115392]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-29 687560]
"Steam"="c:\program files\steam\steam.exe" [2009-10-24 1217808]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2009-09-03 3342336]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2009-10-07 289072]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
"WindowsWelcomeCenter"="oobefldr.dll" - c:\windows\System32\oobefldr.dll [2008-01-21 2153472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BigDog303"="c:\windows\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)" [X]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-11-12 13675040]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-11-12 92704]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-23 33648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-11 34672]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2009-11-12 2020120]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-11-25 149280]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-12 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 01:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
R0 AvgRkx86;avgrkx86.sys;c:\windows\System32\drivers\avgrkx86.sys [8/11/2009 9:49 p.m. 161800]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [8/11/2009 9:49 p.m. 333192]
R1 AvgTdiX;AVG Network Redirector;c:\windows\System32\drivers\avgtdix.sys [8/11/2009 9:49 p.m. 360584]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [11/11/2009 10:44 a.m. 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [11/11/2009 10:44 a.m. 74480]
R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [8/11/2009 9:48 p.m. 285392]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [30/10/2009 6:23 p.m. 1153368]
R3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\System32\drivers\L1E60x86.sys [15/12/2008 12:04 p.m. 47616]
S0 sptd;sptd;c:\windows\System32\drivers\sptd.sys [5/01/2009 6:26 p.m. 717296]
S2 gupdate1ca4734fee236f0;Google Update Service (gupdate1ca4734fee236f0);c:\program files\Google\Update\GoogleUpdate.exe [7/10/2009 11:00 p.m. 133104]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\Dragon Age\bin_ship\daupdatersvc.service.exe [11/11/2009 8:07 p.m. 25832]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [11/11/2009 10:44 a.m. 7408]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08
.
Contents of the 'Scheduled Tasks' folder
2009-11-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-07 10:00]
2009-11-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-07 10:00]
2009-11-26 c:\windows\Tasks\User_Feed_Synchronization-{653B16E0-257E-4954-9CE2-C2D2468CFFA9}.job
- c:\windows\system32\msfeedssync.exe [2009-11-08 03:41]
.
.
------- Supplementary Scan -------
.
uStart Page =
www.yahoo.comIE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Reden\AppData\Roaming\Mozilla\Firefox\Profiles\rpx6lv48.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://au.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_au&p=
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - ORPHANS REMOVED - - - -
AddRemove-HijackThis - c:\program files\Trend Micro\HijackThis\HijackThis.exe
AddRemove-NVIDIA Drivers - c:\windows\system32\nvuninst.exe UninstallGUI
AddRemove-Sins of a Solar Empire - c:\programdata\{0E8E33D8-193A-414A-A909-0F101A142D26}\setup.exe REMOVE=TRUE MODIFY=FALSE
AddRemove-Steam App 15620 - c:\program files\Steam\steam.exe steam://uninstall/15620
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-11-28 09:51
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
BigDog303 = c:\windows\VM303_STI.EXE VIMICRO USB PC Camera (ZC0301PLH)




@?@?








?
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-904409299-471717701-596354257-1001\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:70,75,1b,4a,1d,d0,30,f4,0d,0e,93,a0,43,a5,6a,b0,0f,34,fe,17,53,e8,1b,
6f,8a,db,c6,87,83,17,1e,7b,ed,b7,1b,d4,ca,e9,4f,9f,0e,dc,0f,5a,db,6b,aa,77,\
"??"=hex:9d,6d,62,c7,7e,94,d3,01,62,72,da,46,cb,d1,2f,38
[HKEY_USERS\S-1-5-21-904409299-471717701-596354257-1001\Software\SecuROM\License information*]
"datasecu"=hex:f3,b2,fd,f8,69,a1,01,19,d1,ca,73,ce,ef,4b,14,cd,00,d0,56,19,f1,
a3,03,bc,fa,70,09,38,35,91,49,b9,36,34,42,4a,02,b1,16,35,fa,17,57,d1,f1,91,\
"rkeysecu"=hex:3f,c4,f9,3c,41,7a,e7,85,6a,2e,79,ff,aa,a2,bf,8d
.
Completion time: 2009-11-28 09:53
ComboFix-quarantined-files.txt 2009-11-27 20:53
ComboFix2.txt 2009-11-08 08:35
Pre-Run: 398,845,313,024 bytes free
Post-Run: 398,807,769,088 bytes free
- - End Of File - - F0C2C5F67548AA82607DBD13799FB976