running combofix got me on the internet again...we'll see if it lasts. here's the log.
ComboFix 11-02-22.01 - Chris 02/22/2011 16:29:12.7.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.592 [GMT -6:00]
Running from: c:\documents and settings\Chris\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
((((((((((((((((((((((((( Files Created from 2011-01-22 to 2011-02-22 )))))))))))))))))))))))))))))))
.
2011-02-19 22:48 . 2011-02-19 22:48 -------- d-----w- c:\documents and settings\Chris\Local Settings\Application Data\ESET
2011-02-19 22:21 . 2011-02-19 22:21 -------- d-----w- c:\program files\ESET
2011-02-19 22:21 . 2011-02-19 22:21 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
2011-02-15 03:24 . 2011-02-15 03:24 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2011-02-15 03:20 . 2011-02-15 03:20 -------- d-----w- c:\documents and settings\Chris\Local Settings\Application Data\Mozilla
2011-02-15 03:15 . 2011-02-15 03:15 388096 ----a-r- c:\documents and settings\Chris\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2011-02-15 02:11 . 2011-02-15 02:11 -------- d-----w- c:\program files\TrendMicro
2011-02-11 01:49 . 2010-12-21 00:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-02-11 01:49 . 2010-12-21 00:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-02-11 01:42 . 2011-02-11 01:42 -------- d-----w- c:\program files\CCleaner
2011-01-30 15:45 . 2011-01-30 15:45 135568 ----a-w- c:\program files\Internet Explorer\PLUGINS\nppdf32.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-20 20:49 . 2006-04-05 15:42 10240 ----a-w- c:\windows\system32\drivers\compbatt.sys
2011-02-19 02:11 . 2007-09-15 15:26 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-02-19 02:11 . 2010-07-17 01:46 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-01-21 14:44 . 2004-08-11 22:00 439296 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-07 14:09 . 2004-08-11 22:00 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 13:10 . 2004-08-11 22:00 1854976 ----a-w- c:\windows\system32\win32k.sys
2010-12-22 12:34 . 2004-08-11 22:00 301568 ----a-w- c:\windows\system32\kerberos.dll
2010-12-21 21:04 . 2010-12-21 21:04 141264 ----a-w- c:\windows\system32\drivers\eamon.sys
2010-12-21 21:04 . 2010-12-21 21:04 115008 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2010-12-21 19:47 . 2010-12-21 19:47 94872 ----a-w- c:\windows\system32\drivers\epfwtdir.sys
2010-12-20 23:59 . 2004-08-11 22:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-12-20 23:59 . 2004-08-11 22:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-12-20 23:59 . 2004-08-11 22:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-12-20 17:26 . 2004-08-11 22:00 730112 ----a-w- c:\windows\system32\lsasrv.dll
2010-12-20 12:55 . 2004-08-11 22:00 385024 ----a-w- c:\windows\system32\html.iec
2010-12-09 15:15 . 2004-08-11 22:00 718336 ----a-w- c:\windows\system32\ntdll.dll
2010-12-09 14:30 . 2004-08-11 22:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2010-12-09 13:42 . 2004-08-11 22:00 2148864 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-12-09 13:07 . 2004-08-04 03:59 2027008 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-11-29 23:38 . 2010-11-29 23:38 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-11-29 23:38 . 2010-11-29 23:38 69632 ----a-w- c:\windows\system32\QuickTime.qts
.
((((((((((((((((((((((((((((( SnapShot@2011-02-16_06.44.24 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-02-22 22:19 . 2011-02-22 22:19 16384 c:\windows\temp\Perflib_Perfdata_5cc.dat
+ 2004-08-11 22:00 . 2011-02-22 22:23 73052 c:\windows\system32\perfc009.dat
- 2004-08-11 22:00 . 2011-02-16 06:29 73052 c:\windows\system32\perfc009.dat
- 2004-08-11 22:00 . 2010-11-06 00:26 66560 c:\windows\system32\mshtmled.dll
+ 2004-08-11 22:00 . 2010-12-20 23:59 66560 c:\windows\system32\mshtmled.dll
- 2006-11-08 02:03 . 2010-11-06 00:26 55296 c:\windows\system32\msfeedsbs.dll
+ 2006-11-08 02:03 . 2010-12-20 23:59 55296 c:\windows\system32\msfeedsbs.dll
+ 2004-08-11 22:00 . 2010-12-20 23:59 25600 c:\windows\system32\jsproxy.dll
- 2004-08-11 22:00 . 2010-11-06 00:26 25600 c:\windows\system32\jsproxy.dll
- 2010-01-06 02:23 . 2010-11-06 00:26 12800 c:\windows\system32\dllcache\xpshims.dll
+ 2010-01-06 02:23 . 2010-12-20 23:59 12800 c:\windows\system32\dllcache\xpshims.dll
+ 2006-06-23 11:25 . 2010-12-20 23:59 66560 c:\windows\system32\dllcache\mshtmled.dll
- 2006-06-23 11:25 . 2010-11-06 00:26 66560 c:\windows\system32\dllcache\mshtmled.dll
- 2007-06-27 14:34 . 2010-11-06 00:26 55296 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2007-06-27 14:34 . 2010-12-20 23:59 55296 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2006-10-17 17:05 . 2010-12-20 23:59 43520 c:\windows\system32\dllcache\licmgr10.dll
- 2006-10-17 17:05 . 2010-11-06 00:26 43520 c:\windows\system32\dllcache\licmgr10.dll
+ 2006-06-23 11:25 . 2010-12-20 23:59 25600 c:\windows\system32\dllcache\jsproxy.dll
- 2006-06-23 11:25 . 2010-11-06 00:26 25600 c:\windows\system32\dllcache\jsproxy.dll
- 2009-12-14 07:08 . 2009-12-14 07:08 33280 c:\windows\system32\dllcache\csrsrv.dll
+ 2009-12-14 07:08 . 2010-12-09 14:30 33280 c:\windows\system32\dllcache\csrsrv.dll
+ 2011-02-19 22:22 . 2011-02-19 22:22 10134 c:\windows\Installer\{A66242A1-9101-425D-9BE5-D19A50E1D0D8}\callmsi.exe
+ 2010-11-10 18:49 . 2010-11-10 18:49 17304 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\ViewerPS.dll
+ 2010-11-10 18:49 . 2010-11-10 18:49 35736 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\reader_sl.exe
+ 2010-11-10 18:49 . 2010-11-10 18:49 84896 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\PDFPrevHndlr.dll
+ 2010-11-10 18:49 . 2010-11-10 18:49 94608 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\eula.exe
+ 2010-11-10 18:49 . 2010-11-10 18:49 49064 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\acrotextextractor.exe
+ 2010-11-10 18:49 . 2010-11-10 18:49 17824 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\AcroRd32Info.exe
+ 2010-11-10 18:49 . 2010-11-10 18:49 62376 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\acroiehelpershim.dll
+ 2010-11-10 18:49 . 2010-11-10 18:49 64928 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\AcroIEHelper.dll
+ 2010-11-10 18:49 . 2010-11-10 18:49 63384 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\Acrofx32.dll
+ 2011-02-21 17:46 . 2010-11-06 00:26 12800 c:\windows\ie8updates\KB2482017-IE8\xpshims.dll
+ 2011-02-21 17:46 . 2010-11-06 00:26 66560 c:\windows\ie8updates\KB2482017-IE8\mshtmled.dll
+ 2011-02-21 17:46 . 2010-11-06 00:26 55296 c:\windows\ie8updates\KB2482017-IE8\msfeedsbs.dll
+ 2011-02-21 17:46 . 2010-11-06 00:26 43520 c:\windows\ie8updates\KB2482017-IE8\licmgr10.dll
+ 2011-02-21 17:46 . 2010-11-06 00:26 25600 c:\windows\ie8updates\KB2482017-IE8\jsproxy.dll
- 2004-08-11 22:00 . 2011-02-16 06:29 443914 c:\windows\system32\perfh009.dat
+ 2004-08-11 22:00 . 2011-02-22 22:23 443914 c:\windows\system32\perfh009.dat
- 2004-08-11 22:00 . 2010-11-06 00:26 206848 c:\windows\system32\occache.dll
+ 2004-08-11 22:00 . 2010-12-20 23:59 206848 c:\windows\system32\occache.dll
- 2004-08-11 22:00 . 2010-11-06 00:26 611840 c:\windows\system32\mstime.dll
+ 2004-08-11 22:00 . 2010-12-20 23:59 611840 c:\windows\system32\mstime.dll
+ 2006-11-08 02:03 . 2010-12-20 23:59 602112 c:\windows\system32\msfeeds.dll
- 2006-11-08 02:03 . 2010-11-06 00:26 602112 c:\windows\system32\msfeeds.dll
+ 2011-02-19 02:11 . 2011-02-19 02:11 157472 c:\windows\system32\javaws.exe
+ 2011-02-19 02:11 . 2011-02-19 02:11 145184 c:\windows\system32\javaw.exe
- 2010-11-02 12:44 . 2010-09-15 09:50 145184 c:\windows\system32\javaw.exe
- 2010-11-02 12:44 . 2010-09-15 09:50 145184 c:\windows\system32\java.exe
+ 2011-02-19 02:11 . 2011-02-19 02:11 145184 c:\windows\system32\java.exe
- 2004-08-11 22:00 . 2010-11-06 00:26 184320 c:\windows\system32\iepeers.dll
+ 2004-08-11 22:00 . 2010-12-20 23:59 184320 c:\windows\system32\iepeers.dll
- 2004-08-11 22:00 . 2010-11-06 00:26 387584 c:\windows\system32\iedkcs32.dll
+ 2004-08-11 22:00 . 2010-12-20 23:59 387584 c:\windows\system32\iedkcs32.dll
- 2004-08-11 22:00 . 2010-11-03 12:26 173568 c:\windows\system32\ie4uinit.exe
+ 2004-08-11 22:00 . 2010-12-20 12:55 173568 c:\windows\system32\ie4uinit.exe
+ 2004-08-11 22:06 . 2011-02-16 11:34 138056 c:\windows\system32\FNTCACHE.DAT
- 2004-08-11 22:06 . 2010-12-16 19:12 138056 c:\windows\system32\FNTCACHE.DAT
- 2008-01-18 04:43 . 2008-01-18 10:43 716272 c:\windows\system32\drivers\sptd.sys
+ 2008-01-18 04:43 . 2008-01-18 16:43 716272 c:\windows\system32\drivers\sptd.sys
+ 2006-06-23 11:25 . 2010-12-20 23:59 916480 c:\windows\system32\dllcache\wininet.dll
- 2006-06-23 11:25 . 2010-11-06 00:26 916480 c:\windows\system32\dllcache\wininet.dll
+ 2011-01-21 14:44 . 2011-01-21 14:44 439296 c:\windows\system32\dllcache\shimgvw.dll
+ 2004-08-11 22:00 . 2004-08-04 10:00 146432 c:\windows\system32\dllcache\regedit.exe
+ 2006-10-17 17:04 . 2010-12-20 23:59 206848 c:\windows\system32\dllcache\occache.dll
- 2006-10-17 17:04 . 2010-11-06 00:26 206848 c:\windows\system32\dllcache\occache.dll
+ 2009-04-18 04:29 . 2010-12-09 15:15 718336 c:\windows\system32\dllcache\ntdll.dll
- 2006-06-23 11:25 . 2010-11-06 00:26 611840 c:\windows\system32\dllcache\mstime.dll
+ 2006-06-23 11:25 . 2010-12-20 23:59 611840 c:\windows\system32\dllcache\mstime.dll
- 2007-06-27 14:34 . 2010-11-06 00:26 602112 c:\windows\system32\dllcache\msfeeds.dll
+ 2007-06-27 14:34 . 2010-12-20 23:59 602112 c:\windows\system32\dllcache\msfeeds.dll
- 2009-04-18 04:29 . 2009-06-25 08:25 730112 c:\windows\system32\dllcache\lsasrv.dll
+ 2009-04-18 04:29 . 2010-12-20 17:26 730112 c:\windows\system32\dllcache\lsasrv.dll
- 2009-06-25 08:25 . 2009-06-25 08:25 301568 c:\windows\system32\dllcache\kerberos.dll
+ 2009-06-25 08:25 . 2010-12-22 12:34 301568 c:\windows\system32\dllcache\kerberos.dll
- 2010-01-06 02:23 . 2010-11-06 00:26 247808 c:\windows\system32\dllcache\ieproxy.dll
+ 2010-01-06 02:23 . 2010-12-20 23:59 247808 c:\windows\system32\dllcache\ieproxy.dll
+ 2006-06-23 11:25 . 2010-12-20 23:59 184320 c:\windows\system32\dllcache\iepeers.dll
- 2006-06-23 11:25 . 2010-11-06 00:26 184320 c:\windows\system32\dllcache\iepeers.dll
+ 2010-06-10 00:50 . 2010-12-20 23:59 743424 c:\windows\system32\dllcache\iedvtool.dll
- 2010-06-10 00:50 . 2010-11-06 00:26 743424 c:\windows\system32\dllcache\iedvtool.dll
+ 2006-11-07 08:27 . 2010-12-20 23:59 387584 c:\windows\system32\dllcache\iedkcs32.dll
- 2006-11-07 08:27 . 2010-11-06 00:26 387584 c:\windows\system32\dllcache\iedkcs32.dll
+ 2006-11-07 08:26 . 2010-12-20 12:55 173568 c:\windows\system32\dllcache\ie4uinit.exe
- 2006-11-07 08:26 . 2010-11-03 12:26 173568 c:\windows\system32\dllcache\ie4uinit.exe
+ 2010-04-20 05:30 . 2011-01-07 14:09 290048 c:\windows\system32\dllcache\atmfd.dll
- 2010-04-20 05:30 . 2010-10-28 13:13 290048 c:\windows\system32\dllcache\atmfd.dll
+ 2004-08-11 22:00 . 2004-08-04 10:00 146432 c:\windows\regedit.exe
- 2004-08-11 22:00 . 2008-04-14 00:12 146432 c:\windows\regedit.exe
+ 2011-02-19 02:12 . 2011-02-19 02:12 180224 c:\windows\Installer\a9c0f.msi
+ 2011-02-19 02:11 . 2011-02-19 02:11 677376 c:\windows\Installer\a9c01.msi
+ 2011-02-19 22:22 . 2011-02-19 22:22 967680 c:\windows\Installer\46d5f.msi
+ 2011-02-19 22:22 . 2011-02-19 22:22 101504 c:\windows\Installer\{A66242A1-9101-425D-9BE5-D19A50E1D0D8}\egui.exe
+ 2010-11-10 18:49 . 2010-11-10 18:49 390552 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\pdfshell.dll
+ 2010-11-10 18:49 . 2010-11-10 18:49 101288 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\PDFPrevHndlrShim.exe
+ 2010-11-10 18:49 . 2010-11-10 18:49 135568 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\nppdf32.dll
+ 2010-11-10 18:49 . 2010-11-10 18:49 681872 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\JP2KLib.dll
+ 2010-11-10 18:49 . 2010-11-10 18:49 104344 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\AiodLite.dll
+ 2010-11-10 18:49 . 2010-11-10 18:49 702352 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\AcroPDF.dll
+ 2010-11-10 18:49 . 2010-11-10 18:49 294808 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\acrobroker.exe
+ 2010-11-10 18:49 . 2010-11-10 18:49 205720 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\a3dutils.dll
+ 2011-02-21 17:46 . 2010-11-06 00:26 916480 c:\windows\ie8updates\KB2482017-IE8\wininet.dll
+ 2011-02-21 17:46 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2482017-IE8\spuninst\updspapi.dll
+ 2011-02-21 17:46 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2482017-IE8\spuninst\spuninst.exe
+ 2011-02-21 17:46 . 2010-11-06 00:26 206848 c:\windows\ie8updates\KB2482017-IE8\occache.dll
+ 2011-02-21 17:46 . 2010-11-06 00:26 611840 c:\windows\ie8updates\KB2482017-IE8\mstime.dll
+ 2011-02-21 17:46 . 2010-11-06 00:26 602112 c:\windows\ie8updates\KB2482017-IE8\msfeeds.dll
+ 2011-02-21 17:46 . 2010-11-06 00:26 247808 c:\windows\ie8updates\KB2482017-IE8\ieproxy.dll
+ 2011-02-21 17:46 . 2010-11-06 00:26 184320 c:\windows\ie8updates\KB2482017-IE8\iepeers.dll
+ 2011-02-21 17:46 . 2010-11-06 00:26 743424 c:\windows\ie8updates\KB2482017-IE8\iedvtool.dll
+ 2011-02-21 17:46 . 2010-11-06 00:26 387584 c:\windows\ie8updates\KB2482017-IE8\iedkcs32.dll
+ 2011-02-21 17:46 . 2010-11-03 12:26 173568 c:\windows\ie8updates\KB2482017-IE8\ie4uinit.exe
- 2004-08-11 22:00 . 2010-11-06 00:26 1210880 c:\windows\system32\urlmon.dll
+ 2004-08-11 22:00 . 2010-12-20 23:59 1210880 c:\windows\system32\urlmon.dll
- 2004-08-11 22:00 . 2010-07-27 06:30 8462336 c:\windows\system32\shell32.dll
+ 2004-08-11 22:00 . 2011-01-21 14:44 8462336 c:\windows\system32\shell32.dll
+ 2004-08-11 22:00 . 2010-12-20 23:59 5961216 c:\windows\system32\mshtml.dll
+ 2006-10-17 16:57 . 2010-12-20 23:59 1991680 c:\windows\system32\iertutil.dll
- 2006-10-17 16:57 . 2010-11-06 00:26 1991680 c:\windows\system32\iertutil.dll
+ 2008-10-16 20:33 . 2010-12-31 13:10 1854976 c:\windows\system32\dllcache\win32k.sys
- 2006-07-25 20:42 . 2010-11-06 00:26 1210880 c:\windows\system32\dllcache\urlmon.dll
+ 2006-07-25 20:42 . 2010-12-20 23:59 1210880 c:\windows\system32\dllcache\urlmon.dll
+ 2008-06-17 19:02 . 2011-01-21 14:44 8462336 c:\windows\system32\dllcache\shell32.dll
- 2008-06-17 19:02 . 2010-07-27 06:30 8462336 c:\windows\system32\dllcache\shell32.dll
+ 2008-10-16 20:33 . 2010-12-09 13:38 2192768 c:\windows\system32\dllcache\ntoskrnl.exe
+ 2008-10-16 20:33 . 2010-12-09 13:07 2027008 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2008-10-16 20:33 . 2010-12-09 13:07 2069376 c:\windows\system32\dllcache\ntkrnlpa.exe
+ 2008-10-16 20:33 . 2010-12-09 13:42 2148864 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2006-07-28 11:30 . 2010-12-20 23:59 5961216 c:\windows\system32\dllcache\mshtml.dll
- 2007-06-27 14:34 . 2010-11-06 00:26 1991680 c:\windows\system32\dllcache\iertutil.dll
+ 2007-06-27 14:34 . 2010-12-20 23:59 1991680 c:\windows\system32\dllcache\iertutil.dll
+ 2011-02-19 02:26 . 2011-02-19 02:26 2283008 c:\windows\Installer\a9fb0.msi
+ 2010-11-10 18:49 . 2010-11-10 18:49 2207632 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\rt3d.dll
+ 2010-11-10 18:49 . 2010-11-10 18:49 6222744 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\authplay.dll
+ 2010-11-10 18:49 . 2010-11-10 18:49 5503368 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\AGM.dll
+ 2010-11-10 18:49 . 2010-11-10 18:49 1216416 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\AdobeCollabSync.exe
+ 2010-11-10 18:49 . 2010-11-10 18:49 1289624 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\AcroRd32.exe
+ 2011-02-21 17:46 . 2010-11-06 00:26 1210880 c:\windows\ie8updates\KB2482017-IE8\urlmon.dll
+ 2011-02-21 17:46 . 2010-11-06 00:26 5959168 c:\windows\ie8updates\KB2482017-IE8\mshtml.dll
+ 2011-02-21 17:46 . 2010-11-06 00:26 1991680 c:\windows\ie8updates\KB2482017-IE8\iertutil.dll
+ 2008-10-16 20:33 . 2010-12-09 13:38 2192768 c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2008-10-16 20:33 . 2010-12-09 13:07 2027008 c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2008-10-16 20:33 . 2010-12-09 13:07 2069376 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2008-10-16 20:33 . 2010-12-09 13:42 2148864 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2006-10-05 17:54 . 2011-02-16 09:01 37443528 c:\windows\system32\MRT.exe
+ 2006-11-08 02:03 . 2010-12-21 11:29 11080704 c:\windows\system32\ieframe.dll
- 2006-11-08 02:03 . 2010-11-06 00:26 11080704 c:\windows\system32\ieframe.dll
- 2007-06-27 14:34 . 2010-11-06 00:26 11080704 c:\windows\system32\dllcache\ieframe.dll
+ 2007-06-27 14:34 . 2010-12-21 11:29 11080704 c:\windows\system32\dllcache\ieframe.dll
+ 2011-01-30 20:44 . 2011-01-30 20:44 12425728 c:\windows\Installer\a9fb1.msp
+ 2010-11-10 18:49 . 2010-11-10 18:49 23724952 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0000000010\10.0.0\AcroRd32.dll
+ 2011-02-21 17:46 . 2010-11-06 00:26 11080704 c:\windows\ie8updates\KB2482017-IE8\ieframe.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-01-17 486856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-11-29 761947]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"SigmatelSysTrayApp"="stsystra.exe" [2005-11-17 397312]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 2793304]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-10-18 802816]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-10-18 696320]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-11-19 98304]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-19 118784]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-19 77824]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-10 49152]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-01-27 86016]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"Dell QuickSet"="c:\program files\Dell\QuickSet\Quickset.exe" [2005-12-15 839680]
"ConnectionCenter"="c:\program files\Citrix\ICA Client\concentr.exe" [2009-09-13 103768]
"BellSouthWCC_McciTrayApp"="c:\program files\BellSouthWCC\McciTrayApp.exe" [2005-11-17 543232]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2008-07-04 109056]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-01-12 2219184]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
America Online 9.0 Tray Icon.lnk - c:\program files\America Online 9.0\aoltray.exe [2006-4-5 156784]
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2005-6-16 49152]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-4-5 24576]
dlbcserv.lnk - c:\program files\Dell Photo Printer 720\dlbcserv.exe [2007-3-8 315392]
NkbMonitor.exe.lnk - c:\program files\Nikon\PictureProject\NkbMonitor.exe [2008-3-3 118784]
PHOTOfunSTUDIO.lnk - c:\program files\Panasonic\PHOTOfunSTUDIO\PhAutoRun.exe [2010-1-18 44176]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"GameConsoleService"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Games HQ\\Unreal Tournament\\System\\UnrealTournament.exe"=
"c:\\Program Files\\Games HQ\\Age of Empires II\\age2_x1\\age2_x1.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [1/17/2008 10:43 PM 716272]
R1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\drivers\ctxusbm.sys [9/8/2009 5:13 PM 65584]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [12/21/2010 3:04 PM 115008]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [12/21/2010 1:47 PM 94872]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 12:25 PM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 12:41 PM 67656]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [1/12/2011 4:41 PM 810144]
S0 haqaugev;haqaugev;c:\windows\system32\drivers\jhyedcun.sys --> c:\windows\system32\drivers\jhyedcun.sys [?]
S3 BW2NDIS5;BW2NDIS5;c:\windows\system32\Drivers\BW2NDIS5.sys --> c:\windows\system32\Drivers\BW2NDIS5.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2011-02-12 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
FF - ProfilePath - c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\khnidukr.default\
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Java Quick Starter:
[email protected] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-02-22 16:33
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-763208294-2166686365-2200820826-1006\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{4AE46BEE-309A-D118-EEF6-0B629E101924}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iandjebeamjplkkima"=hex:6a,61,6f,6d,70,67,70,6a,61,6e,6d,62,65,6b,62,6a,67,66,
67,6d,00,f2
"haddpfckmafepble"=hex:6b,61,69,6d,61,6a,63,62,61,63,6c,6a,67,6e,6a,6c,6c,70,
6e,62,69,61,00,00
[HKEY_USERS\S-1-5-21-763208294-2166686365-2200820826-1006\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C4FF9455-D2D0-B2C0-5236-97D1CE5D2B9A}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iaifkpmhmcpabcapeb"=hex:6a,61,6a,6f,63,67,6c,63,66,6b,6a,65,6b,64,68,61,67,68,
6e,6e,00,f1
"hacgbhgnolebgoia"=hex:6a,61,6a,6f,63,67,6c,63,66,6b,6a,65,6b,64,68,61,67,68,
6e,6e,00,00
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(732)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(1000)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-02-22 16:35:42
ComboFix-quarantined-files.txt 2011-02-22 22:35
ComboFix2.txt 2011-02-22 21:56
ComboFix3.txt 2011-02-18 02:02
ComboFix4.txt 2011-02-16 06:53
Pre-Run: 53,639,651,328 bytes free
Post-Run: 53,621,751,808 bytes free
Current=2 Default=2 Failed=1 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 10675F77863A3BE8BC773F10DBBB7087