+ 2009-11-05 16:16 . 2009-11-05 16:16 537600 c:\windows\Installer\726c21.msi
+ 2009-01-22 00:39 . 2009-11-11 18:41 888080 c:\windows\Installer\{91120000-0013-0000-0000-0000000FF1CE}\wordicon.exe
- 2009-01-22 00:39 . 2009-10-30 17:54 888080 c:\windows\Installer\{91120000-0013-0000-0000-0000000FF1CE}\wordicon.exe
+ 2009-01-22 00:39 . 2009-11-11 18:41 845584 c:\windows\Installer\{91120000-0013-0000-0000-0000000FF1CE}\outicon.exe
- 2009-01-22 00:39 . 2009-10-30 17:54 845584 c:\windows\Installer\{91120000-0013-0000-0000-0000000FF1CE}\outicon.exe
+ 2009-01-22 00:39 . 2009-11-11 18:41 217864 c:\windows\Installer\{91120000-0013-0000-0000-0000000FF1CE}\misc.exe
- 2009-01-22 00:39 . 2009-10-30 17:54 217864 c:\windows\Installer\{91120000-0013-0000-0000-0000000FF1CE}\misc.exe
+ 2009-11-05 19:03 . 2008-07-08 13:02 382840 c:\windows\ie8updates\KB976749-IE8\spuninst\updspapi.dll
+ 2009-11-05 19:03 . 2008-07-08 13:02 231288 c:\windows\ie8updates\KB976749-IE8\spuninst\spuninst.exe
+ 2009-11-05 19:03 . 2008-07-08 13:02 382840 c:\windows\ie8updates\KB971961-IE8\spuninst\updspapi.dll
+ 2009-11-05 19:03 . 2008-07-08 13:02 231288 c:\windows\ie8updates\KB971961-IE8\spuninst\spuninst.exe
+ 2009-11-05 19:03 . 2009-03-08 09:33 726528 c:\windows\ie8updates\KB971961-IE8\jscript.dll
+ 2004-08-04 10:00 . 2009-08-14 13:21 1850624 c:\windows\system32\win32k.sys
+ 2006-03-23 17:32 . 2009-10-22 09:19 5939712 c:\windows\system32\mshtml.dll
+ 2009-01-22 08:07 . 2009-08-14 13:21 1850624 c:\windows\system32\dllcache\win32k.sys
+ 2006-03-23 17:32 . 2009-10-22 09:19 5939712 c:\windows\system32\dllcache\mshtml.dll
+ 2009-10-16 12:03 . 2009-10-16 12:03 5003776 c:\windows\Installer\fb3fc2.msp
+ 2009-08-18 17:58 . 2009-08-18 17:58 8301056 c:\windows\Installer\fb3fb2.msp
+ 2009-08-18 17:57 . 2009-08-18 17:57 9122304 c:\windows\Installer\fb3fa2.msp
- 2009-01-22 00:39 . 2009-10-30 17:54 1172240 c:\windows\Installer\{91120000-0013-0000-0000-0000000FF1CE}\xlicons.exe
+ 2009-01-22 00:39 . 2009-11-11 18:41 1172240 c:\windows\Installer\{91120000-0013-0000-0000-0000000FF1CE}\xlicons.exe
+ 2009-11-05 19:03 . 2009-08-29 08:08 5940224 c:\windows\ie8updates\KB976749-IE8\mshtml.dll
+ 2009-01-23 16:15 . 2009-11-05 17:36 26768832 c:\windows\system32\MRT.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-02 68856]
"OM2_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" [2008-05-15 95536]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-27 4351216]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-03-24 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-03-24 118784]
"CTSVolFE"="c:\program files\Creative\Mixer\CTSVolFE.exe" [2005-02-23 57344]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-09-01 282624]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"ToolBoxFX"="c:\program files\HP\ToolBoxFX\bin\HPTLBXFX.exe" [2005-11-21 45056]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-09-24 49152]
"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 483328]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-11-05 149280]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2009-10-20 25214]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Best\\90cs\\MAS90\\HOME\\PVXWIN32.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1224:UDP"= 1224:UDP:Windows Media Format SDK (iexplore.exe)
"1225:UDP"= 1225:UDP:Windows Media Format SDK (iexplore.exe)
"1226:UDP"= 1226:UDP:Windows Media Format SDK (iexplore.exe)
"1358:UDP"= 1358:UDP:Windows Media Format SDK (iexplore.exe)
"1359:UDP"= 1359:UDP:Windows Media Format SDK (iexplore.exe)
"1360:UDP"= 1360:UDP:Windows Media Format SDK (iexplore.exe)
"2152:UDP"= 2152:UDP:Windows Media Format SDK (iexplore.exe)
"2155:UDP"= 2155:UDP:Windows Media Format SDK (iexplore.exe)
"2154:UDP"= 2154:UDP:Windows Media Format SDK (iexplore.exe)
"1204:UDP"= 1204:UDP:Windows Media Format SDK (iexplore.exe)
"1205:UDP"= 1205:UDP:Windows Media Format SDK (iexplore.exe)
"1206:UDP"= 1206:UDP:Windows Media Format SDK (iexplore.exe)
"1256:UDP"= 1256:UDP:Windows Media Format SDK (iexplore.exe)
"1257:UDP"= 1257:UDP:Windows Media Format SDK (iexplore.exe)
"1258:UDP"= 1258:UDP:Windows Media Format SDK (iexplore.exe)
"1621:UDP"= 1621:UDP:Windows Media Format SDK (iexplore.exe)
"1624:UDP"= 1624:UDP:Windows Media Format SDK (iexplore.exe)
"1625:UDP"= 1625:UDP:Windows Media Format SDK (iexplore.exe)
"1361:UDP"= 1361:UDP:Windows Media Format SDK (iexplore.exe)
"1362:UDP"= 1362:UDP:Windows Media Format SDK (iexplore.exe)
"1340:UDP"= 1340:UDP:Windows Media Format SDK (iexplore.exe)
"1341:UDP"= 1341:UDP:Windows Media Format SDK (iexplore.exe)
"1342:UDP"= 1342:UDP:Windows Media Format SDK (iexplore.exe)
R2 NitroDriverReadSpool;NitroPDFDriverCreatorReadSpool;c:\program files\Nitro PDF\Professional\NitroPDFDriverService.exe [9/15/2009 9:20 AM 188736]
--- Other Services/Drivers In Memory ---
*Deregistered* - mbr
.
Contents of the 'Scheduled Tasks' folder
2009-10-14 c:\windows\Tasks\Norton Security Scan for Johnlin.job
- c:\program files\Norton Security Scan\Norton Security Scan\Engine\2.3.0.44\Nss.exe [2009-07-22 23:58]
2009-11-17 c:\windows\Tasks\User_Feed_Synchronization-{17BD2D1D-81CB-43B0-8EA7-AEF1A5EF0512}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 09:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*
http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*
http://www.yahoo.com
IE: &Search
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-11-17 13:53
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3176)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll