ComboFix 11-12-17.03 - Main 12/17/2011 19:08:10.2.4 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3327.2491 [GMT -5:00]
Running from: c:\documents and settings\Main\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Main\Desktop\CFScript.txt
AV: Norton 360 Premier Edition *Disabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton 360 Premier Edition *Disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.
FILE ::
"c:\docume~1\main\locals~1\temp\gtermddo.sys"
"c:\windows\system32\drivers\FixTDSS.sys"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_FIXTDSS
-------\Legacy_GTERMDDO
-------\Service_FixTDSS
-------\Service_gtermddo
.
.
((((((((((((((((((((((((( Files Created from 2011-11-18 to 2011-12-18 )))))))))))))))))))))))))))))))
.
.
2011-12-17 21:35 . 2011-12-17 21:35 -------- d-----w- c:\windows\LastGood.Tmp
2011-12-17 21:35 . 2011-12-17 21:35 -------- d-----w- c:\program files\ESET
2011-12-17 21:14 . 2011-12-17 21:14 -------- d-----w- c:\program files\Common Files\Java
2011-12-17 21:14 . 2011-12-17 21:13 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-12-17 21:14 . 2011-12-17 21:13 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-12-17 21:13 . 2011-12-17 21:13 -------- d-----w- c:\program files\Java
2011-12-15 23:11 . 2011-12-15 23:11 -------- d-----w- C:\TDSSKiller_Quarantine
2011-12-15 17:09 . 2011-12-15 17:09 -------- d-----w- c:\documents and settings\Main\Application Data\Malwarebytes
2011-12-15 17:09 . 2011-12-15 17:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-12-15 17:09 . 2011-12-15 17:09 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-12-15 17:09 . 2011-08-31 22:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-12-14 15:54 . 2011-12-15 02:27 -------- d-----w- c:\documents and settings\Main\Local Settings\Application Data\SanctionedMedia
2011-12-09 01:26 . 2008-05-02 13:25 465920 -c----w- c:\windows\system32\dllcache\imapi2fs.dll
2011-12-09 01:26 . 2008-05-02 13:25 465920 ------w- c:\windows\system32\imapi2fs.dll
2011-12-09 01:26 . 2008-05-02 13:25 317952 -c----w- c:\windows\system32\dllcache\imapi2.dll
2011-12-09 01:26 . 2008-05-02 13:25 317952 ------w- c:\windows\system32\imapi2.dll
2011-12-09 01:26 . 2008-05-02 10:49 62976 -c----w- c:\windows\system32\dllcache\cdrom.sys
2011-12-02 16:44 . 2011-12-02 16:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Playrix Entertainment
2011-11-26 12:44 . 2011-07-07 23:21 876136 ----a-w- c:\windows\system32\nvhdagenco3220102.dll
2011-11-26 12:33 . 2007-06-29 19:47 34304 ----a-w- c:\windows\system32\drivers\AmdLLD.sys
2011-11-26 12:33 . 2011-11-26 12:33 -------- d-----w- c:\program files\AMD
2011-11-26 12:33 . 2011-11-26 12:33 -------- d-----w- c:\documents and settings\Main\Local Settings\Application Data\Downloaded Installations
2011-11-26 12:29 . 2011-11-26 12:30 -------- d-----w- C:\2f285ebdfb9ed59c8a6875e3ff4699e2
2011-11-26 12:18 . 2011-11-26 12:19 -------- d-----w- C:\3a7e93e5a4606a81ac8ad4
2011-11-26 12:18 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2011-11-26 12:18 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2011-11-26 12:18 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2011-11-26 12:18 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2011-11-20 20:42 . 2001-08-18 03:36 5632 ----a-w- c:\windows\system32\ptpusb.dll
2011-11-20 20:42 . 2008-04-14 01:12 159232 ----a-w- c:\windows\system32\ptpusd.dll
2011-11-20 17:04 . 2011-12-11 18:31 -------- d-----w- c:\documents and settings\Main\Local Settings\Application Data\CutePDF Writer
2011-11-20 16:55 . 2011-11-20 16:55 -------- d-----w- c:\program files\GPLGS
2011-11-20 16:55 . 2009-11-05 13:39 87552 ----a-w- c:\windows\system32\cpwmon2k.dll
2011-11-20 16:55 . 2011-11-20 16:55 -------- d-----w- c:\program files\Acro Software
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-16 02:46 . 2004-08-04 12:00 138496 ----a-w- c:\windows\system32\drivers\afd.sys
2011-11-26 12:57 . 2009-08-18 16:30 564632 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\wlidui.dll
2011-11-26 12:57 . 2009-08-18 16:24 18328 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-11-23 13:25 . 2004-08-04 12:00 1859584 ----a-w- c:\windows\system32\win32k.sys
2011-11-04 19:20 . 2004-08-04 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20 . 2004-08-04 12:00 43520 ------w- c:\windows\system32\licmgr10.dll
2011-11-04 19:20 . 2004-08-04 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:23 . 2004-08-04 12:00 385024 ------w- c:\windows\system32\html.iec
2011-11-01 16:07 . 2004-08-04 12:00 1288704 ----a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31 . 2004-08-04 12:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:37 . 2004-08-04 12:00 2148864 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52 . 2004-08-03 22:59 2027008 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-24 08:55 . 2011-10-24 08:55 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-18 11:13 . 2004-08-04 12:00 186880 ----a-w- c:\windows\system32\encdec.dll
2011-10-10 14:22 . 2008-12-01 14:48 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-10-08 04:50 . 2011-07-27 17:11 298304 ----a-w- c:\windows\system32\nvsvc32.exe
2011-10-08 04:50 . 2011-07-27 17:11 602432 ----a-w- c:\windows\system32\easyupdatusapiu.dll
2011-10-08 04:50 . 2011-07-27 17:11 54272 ----a-w- c:\windows\system32\nvwddi.dll
2011-10-08 04:50 . 2011-07-27 17:11 220992 ----a-w- c:\windows\system32\nvcolor.exe
2011-10-08 04:50 . 2011-07-27 17:11 203072 ----a-w- c:\windows\system32\nvmctray.dll
2011-10-08 04:50 . 2011-07-27 17:11 16744256 ----a-w- c:\windows\system32\nvcpl.dll
2011-10-08 04:50 . 2010-12-16 19:22 919872 ----a-w- c:\windows\system32\nvdispco32.dll
2011-10-08 04:50 . 2010-12-16 19:22 877376 ----a-w- c:\windows\system32\nvgenco32.dll
2011-10-08 04:50 . 2010-12-16 19:22 65536 ----a-w- c:\windows\system32\OpenCL.dll
2011-10-08 04:50 . 2010-12-16 19:22 5595136 ----a-w- c:\windows\system32\nvcuda.dll
2011-10-08 04:50 . 2010-12-16 19:22 2398016 ----a-w- c:\windows\system32\nvcuvid.dll
2011-10-08 04:50 . 2010-12-16 19:22 2099520 ----a-w- c:\windows\system32\nvcuvenc.dll
2011-10-08 04:50 . 2010-12-16 19:22 17956864 ----a-w- c:\windows\system32\nvoglnt.dll
2011-10-08 04:50 . 2010-12-16 19:22 2449408 ----a-w- c:\windows\system32\nvapi.dll
2011-10-08 04:50 . 2010-12-16 19:22 17240064 ----a-w- c:\windows\system32\nvcompiler.dll
2011-10-08 04:50 . 2004-08-04 07:56 4226688 ----a-w- c:\windows\system32\nv4_disp.dll
2011-10-08 04:50 . 2004-08-04 05:29 12791488 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2011-09-28 22:45 . 2011-09-28 22:45 15453832 ----a-w- c:\windows\system32\xlive.dll
2011-09-28 22:45 . 2011-09-28 22:45 13642888 ----a-w- c:\windows\system32\xlivefnt.dll
2011-09-28 07:06 . 2004-08-04 12:00 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41 . 2010-03-18 14:09 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41 . 2004-08-04 12:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41 . 2004-08-04 12:00 20480 ----a-w- c:\windows\system32\oleaccrc.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-12-16_03.42.35 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-12-18 00:20 . 2011-12-18 00:20 16384 c:\windows\Temp\Perflib_Perfdata_464.dat
+ 2008-07-14 11:09 . 2011-11-08 13:46 46080 c:\windows\system32\tzchange.exe
- 2008-07-14 11:09 . 2011-07-08 13:49 46080 c:\windows\system32\tzchange.exe
- 2004-08-04 12:00 . 2011-08-22 23:48 66560 c:\windows\system32\mshtmled.dll
+ 2004-08-04 12:00 . 2011-11-04 19:20 66560 c:\windows\system32\mshtmled.dll
- 2007-08-13 23:54 . 2011-08-22 23:48 55296 c:\windows\system32\msfeedsbs.dll
+ 2007-08-13 23:54 . 2011-11-04 19:20 55296 c:\windows\system32\msfeedsbs.dll
- 2004-08-04 12:00 . 2011-08-22 23:48 25600 c:\windows\system32\jsproxy.dll
+ 2004-08-04 12:00 . 2011-11-04 19:20 25600 c:\windows\system32\jsproxy.dll
+ 2011-07-25 13:45 . 2011-11-04 19:20 12800 c:\windows\system32\dllcache\xpshims.dll
- 2011-07-25 13:45 . 2011-08-22 23:48 12800 c:\windows\system32\dllcache\xpshims.dll
+ 2011-04-25 14:47 . 2011-11-04 19:20 66560 c:\windows\system32\dllcache\mshtmled.dll
- 2011-04-25 14:47 . 2011-08-22 23:48 66560 c:\windows\system32\dllcache\mshtmled.dll
- 2011-07-25 13:45 . 2011-08-22 23:48 55296 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2011-07-25 13:45 . 2011-11-04 19:20 55296 c:\windows\system32\dllcache\msfeedsbs.dll
- 2009-03-08 08:34 . 2011-08-22 23:48 43520 c:\windows\system32\dllcache\licmgr10.dll
+ 2009-03-08 08:34 . 2011-11-04 19:20 43520 c:\windows\system32\dllcache\licmgr10.dll
- 2009-03-08 08:33 . 2011-08-22 23:48 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2009-03-08 08:33 . 2011-11-04 19:20 25600 c:\windows\system32\dllcache\jsproxy.dll
- 2011-04-26 11:07 . 2011-04-26 11:07 33280 c:\windows\system32\dllcache\csrsrv.dll
+ 2011-04-26 11:07 . 2011-10-28 05:31 33280 c:\windows\system32\dllcache\csrsrv.dll
+ 2009-07-21 14:01 . 2011-12-16 08:59 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut9.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
- 2009-07-21 14:01 . 2009-07-21 14:01 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut9.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
- 2009-07-21 14:01 . 2009-07-21 14:01 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut8.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
+ 2009-07-21 14:01 . 2011-12-16 08:59 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut8.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
- 2009-07-21 14:01 . 2009-07-21 14:01 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut7.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
+ 2009-07-21 14:01 . 2011-12-16 08:59 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut7.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
- 2009-07-21 14:01 . 2009-07-21 14:01 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut6.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
+ 2009-07-21 14:01 . 2011-12-16 08:59 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut6.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
- 2009-07-21 14:01 . 2009-07-21 14:01 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut5.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
+ 2009-07-21 14:01 . 2011-12-16 08:59 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut5.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
- 2009-07-21 14:01 . 2009-07-21 14:01 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut28.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
+ 2009-07-21 14:01 . 2011-12-16 08:59 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut28.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
- 2009-07-21 14:01 . 2009-07-21 14:01 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut27.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
+ 2009-07-21 14:01 . 2011-12-16 08:59 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut27.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
- 2009-07-21 14:01 . 2009-07-21 14:01 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut26.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
+ 2009-07-21 14:01 . 2011-12-16 08:59 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut26.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
+ 2009-07-21 14:01 . 2011-12-16 08:59 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut25.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
- 2009-07-21 14:01 . 2009-07-21 14:01 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut25.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
+ 2009-07-21 14:01 . 2011-12-16 08:59 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut24.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
- 2009-07-21 14:01 . 2009-07-21 14:01 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut24.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
+ 2009-07-21 14:01 . 2011-12-16 08:59 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut23.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
- 2009-07-21 14:01 . 2009-07-21 14:01 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut23.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
- 2009-07-21 14:01 . 2009-07-21 14:01 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut22.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
+ 2009-07-21 14:01 . 2011-12-16 08:59 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut22.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
+ 2009-07-21 14:01 . 2011-12-16 08:59 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut21.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
- 2009-07-21 14:01 . 2009-07-21 14:01 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut21.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
+ 2009-07-21 14:01 . 2011-12-16 08:59 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut20.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
- 2009-07-21 14:01 . 2009-07-21 14:01 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut20.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
- 2009-07-21 14:01 . 2009-07-21 14:01 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut2_1.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
+ 2009-07-21 14:01 . 2011-12-16 08:59 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut2_1.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
- 2009-07-21 14:01 . 2009-07-21 14:01 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut19.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
+ 2009-07-21 14:01 . 2011-12-16 08:59 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut19.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
- 2009-07-21 14:01 . 2009-07-21 14:01 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut18.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
+ 2009-07-21 14:01 . 2011-12-16 08:59 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut18.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
- 2009-07-21 14:01 . 2009-07-21 14:01 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut17.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
+ 2009-07-21 14:01 . 2011-12-16 08:59 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut17.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
- 2009-07-21 14:01 . 2009-07-21 14:01 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut16.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
+ 2009-07-21 14:01 . 2011-12-16 08:59 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut16.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
- 2009-07-21 14:01 . 2009-07-21 14:01 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut15.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
+ 2009-07-21 14:01 . 2011-12-16 08:59 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut15.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
+ 2009-07-21 14:01 . 2011-12-16 08:59 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut14.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
- 2009-07-21 14:01 . 2009-07-21 14:01 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut14.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
- 2009-07-21 14:01 . 2009-07-21 14:01 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut13.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
+ 2009-07-21 14:01 . 2011-12-16 08:59 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut13.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
- 2009-07-21 14:01 . 2009-07-21 14:01 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut12.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
+ 2009-07-21 14:01 . 2011-12-16 08:59 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut12.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
- 2009-07-21 14:01 . 2009-07-21 14:01 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut11.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
+ 2009-07-21 14:01 . 2011-12-16 08:59 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut11.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
- 2009-07-21 14:01 . 2009-07-21 14:01 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut10.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
+ 2009-07-21 14:01 . 2011-12-16 08:59 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\NewShortcut10.BCCDD171_C13C_4D41_ACA3_0E088E5E60A9.exe
+ 2009-07-21 14:01 . 2011-12-16 08:59 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\ARPPRODUCTICON.exe
- 2009-07-21 14:01 . 2009-07-21 14:01 25214 c:\windows\Installer\{D74CFE48-087F-46E1-80E6-E2950E1A8DCE}\ARPPRODUCTICON.exe
+ 2011-12-16 08:03 . 2011-08-22 23:48 12800 c:\windows\ie8updates\KB2618444-IE8\xpshims.dll
+ 2011-12-16 08:03 . 2011-08-22 23:48 66560 c:\windows\ie8updates\KB2618444-IE8\mshtmled.dll
+ 2011-12-16 08:03 . 2011-08-22 23:48 55296 c:\windows\ie8updates\KB2618444-IE8\msfeedsbs.dll
+ 2011-12-16 08:03 . 2011-08-22 23:48 43520 c:\windows\ie8updates\KB2618444-IE8\licmgr10.dll
+ 2011-12-16 08:03 . 2011-08-22 23:48 25600 c:\windows\ie8updates\KB2618444-IE8\jsproxy.dll
- 2004-08-04 12:00 . 2011-08-22 23:48 105984 c:\windows\system32\url.dll
+ 2004-08-04 12:00 . 2011-11-04 19:20 105984 c:\windows\system32\url.dll
- 2004-08-04 12:00 . 2011-08-22 23:48 206848 c:\windows\system32\occache.dll
+ 2004-08-04 12:00 . 2011-11-04 19:20 206848 c:\windows\system32\occache.dll
+ 2004-08-04 12:00 . 2011-11-04 19:20 611840 c:\windows\system32\mstime.dll
- 2004-08-04 12:00 . 2011-08-22 23:48 611840 c:\windows\system32\mstime.dll
+ 2007-08-13 23:54 . 2011-11-04 19:20 602112 c:\windows\system32\msfeeds.dll
- 2007-08-13 23:54 . 2011-08-22 23:48 602112 c:\windows\system32\msfeeds.dll
+ 2011-12-17 21:14 . 2011-12-17 21:13 157472 c:\windows\system32\javaws.exe
+ 2011-12-17 21:14 . 2011-12-17 21:13 149280 c:\windows\system32\javaw.exe
+ 2011-12-17 21:14 . 2011-12-17 21:13 149280 c:\windows\system32\java.exe
- 2004-08-04 12:00 . 2011-08-22 23:48 184320 c:\windows\system32\iepeers.dll
+ 2004-08-04 12:00 . 2011-11-04 19:20 184320 c:\windows\system32\iepeers.dll
+ 2004-08-04 12:00 . 2011-11-04 19:20 387584 c:\windows\system32\iedkcs32.dll
- 2004-08-04 12:00 . 2011-08-22 23:48 387584 c:\windows\system32\iedkcs32.dll
- 2004-08-04 12:00 . 2011-08-22 11:56 174080 c:\windows\system32\ie4uinit.exe
+ 2004-08-04 12:00 . 2011-11-04 11:24 174080 c:\windows\system32\ie4uinit.exe
+ 2008-12-01 09:38 . 2011-12-16 08:56 127704 c:\windows\system32\FNTCACHE.DAT
- 2008-12-01 09:38 . 2011-11-26 12:49 127704 c:\windows\system32\FNTCACHE.DAT
+ 2011-04-25 14:47 . 2011-11-04 19:20 916992 c:\windows\system32\dllcache\wininet.dll
- 2009-03-08 08:34 . 2011-08-22 23:48 105984 c:\windows\system32\dllcache\url.dll
+ 2009-03-08 08:34 . 2011-11-04 19:20 105984 c:\windows\system32\dllcache\url.dll
+ 2009-03-08 08:34 . 2011-11-04 19:20 206848 c:\windows\system32\dllcache\occache.dll
- 2009-03-08 08:34 . 2011-08-22 23:48 206848 c:\windows\system32\dllcache\occache.dll
- 2011-04-25 14:47 . 2011-08-22 23:48 611840 c:\windows\system32\dllcache\mstime.dll
+ 2011-04-25 14:47 . 2011-11-04 19:20 611840 c:\windows\system32\dllcache\mstime.dll
- 2011-07-25 13:45 . 2011-08-22 23:48 602112 c:\windows\system32\dllcache\msfeeds.dll
+ 2011-07-25 13:45 . 2011-11-04 19:20 602112 c:\windows\system32\dllcache\msfeeds.dll
+ 2011-07-25 13:45 . 2011-11-04 19:20 247808 c:\windows\system32\dllcache\ieproxy.dll
- 2011-07-25 13:45 . 2011-08-22 23:48 247808 c:\windows\system32\dllcache\ieproxy.dll
+ 2011-04-25 14:47 . 2011-11-04 19:20 184320 c:\windows\system32\dllcache\iepeers.dll
- 2011-04-25 14:47 . 2011-08-22 23:48 184320 c:\windows\system32\dllcache\iepeers.dll
- 2011-07-25 13:45 . 2011-08-22 23:48 743424 c:\windows\system32\dllcache\iedvtool.dll
+ 2011-07-25 13:45 . 2011-11-04 19:20 743424 c:\windows\system32\dllcache\iedvtool.dll
- 2009-03-08 18:09 . 2011-08-22 23:48 387584 c:\windows\system32\dllcache\iedkcs32.dll
+ 2009-03-08 18:09 . 2011-11-04 19:20 387584 c:\windows\system32\dllcache\iedkcs32.dll
+ 2009-03-08 08:32 . 2011-11-04 11:24 174080 c:\windows\system32\dllcache\ie4uinit.exe
- 2009-03-08 08:32 . 2011-08-22 11:56 174080 c:\windows\system32\dllcache\ie4uinit.exe
- 2011-02-09 13:53 . 2011-02-09 13:53 186880 c:\windows\system32\dllcache\encdec.dll
+ 2011-02-09 13:53 . 2011-10-18 11:13 186880 c:\windows\system32\dllcache\encdec.dll
+ 2011-12-17 21:14 . 2011-12-17 21:14 203776 c:\windows\Installer\7c4946e.msi
+ 2011-12-17 21:13 . 2011-12-17 21:13 901120 c:\windows\Installer\7c49467.msi
+ 2011-12-16 08:03 . 2011-08-22 23:48 916480 c:\windows\ie8updates\KB2618444-IE8\wininet.dll
+ 2011-12-16 08:03 . 2011-08-22 23:48 105984 c:\windows\ie8updates\KB2618444-IE8\url.dll
+ 2011-12-16 08:03 . 2010-07-05 13:16 382840 c:\windows\ie8updates\KB2618444-IE8\spuninst\updspapi.dll
+ 2011-12-16 08:03 . 2010-07-05 13:15 231288 c:\windows\ie8updates\KB2618444-IE8\spuninst\spuninst.exe
+ 2011-12-16 08:03 . 2011-08-22 23:48 206848 c:\windows\ie8updates\KB2618444-IE8\occache.dll
+ 2011-12-16 08:03 . 2011-08-22 23:48 611840 c:\windows\ie8updates\KB2618444-IE8\mstime.dll
+ 2011-12-16 08:03 . 2011-08-22 23:48 602112 c:\windows\ie8updates\KB2618444-IE8\msfeeds.dll
+ 2011-12-16 08:03 . 2011-08-22 23:48 247808 c:\windows\ie8updates\KB2618444-IE8\ieproxy.dll
+ 2011-12-16 08:03 . 2011-08-22 23:48 184320 c:\windows\ie8updates\KB2618444-IE8\iepeers.dll
+ 2011-12-16 08:03 . 2011-08-22 23:48 743424 c:\windows\ie8updates\KB2618444-IE8\iedvtool.dll
+ 2011-12-16 08:03 . 2011-08-22 23:48 387584 c:\windows\ie8updates\KB2618444-IE8\iedkcs32.dll
+ 2011-12-16 08:03 . 2011-08-22 11:56 174080 c:\windows\ie8updates\KB2618444-IE8\ie4uinit.exe
+ 2004-08-04 12:00 . 2011-11-04 19:20 1212416 c:\windows\system32\urlmon.dll
- 2004-08-04 12:00 . 2011-08-22 23:48 1212416 c:\windows\system32\urlmon.dll
+ 2004-08-04 12:00 . 2011-11-04 19:20 5978112 c:\windows\system32\mshtml.dll
- 2007-08-13 23:34 . 2011-08-22 23:48 2000384 c:\windows\system32\iertutil.dll
+ 2007-08-13 23:34 . 2011-11-04 19:20 2000384 c:\windows\system32\iertutil.dll
+ 2011-06-02 14:02 . 2011-11-23 13:25 1859584 c:\windows\system32\dllcache\win32k.sys
+ 2011-04-25 14:47 . 2011-11-04 19:20 1212416 c:\windows\system32\dllcache\urlmon.dll
- 2011-04-25 14:47 . 2011-08-22 23:48 1212416 c:\windows\system32\dllcache\urlmon.dll
+ 2010-07-16 12:05 . 2011-11-01 16:07 1288704 c:\windows\system32\dllcache\ole32.dll
+ 2011-07-25 07:04 . 2011-10-25 13:33 2192768 c:\windows\system32\dllcache\ntoskrnl.exe
- 2011-07-25 07:04 . 2010-12-09 13:38 2192768 c:\windows\system32\dllcache\ntoskrnl.exe
- 2011-07-25 07:04 . 2010-12-09 13:07 2027008 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2011-07-25 07:04 . 2011-10-25 12:52 2027008 c:\windows\system32\dllcache\ntkrpamp.exe
- 2011-07-25 07:04 . 2010-12-09 13:07 2069376 c:\windows\system32\dllcache\ntkrnlpa.exe
+ 2011-07-25 07:04 . 2011-10-25 12:52 2069376 c:\windows\system32\dllcache\ntkrnlpa.exe
- 2011-07-25 07:04 . 2010-12-09 13:42 2148864 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2011-07-25 07:04 . 2011-10-25 13:37 2148864 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2011-04-25 14:47 . 2011-11-04 19:20 5978112 c:\windows\system32\dllcache\mshtml.dll
- 2011-07-25 13:45 . 2011-08-22 23:48 2000384 c:\windows\system32\dllcache\iertutil.dll
+ 2011-07-25 13:45 . 2011-11-04 19:20 2000384 c:\windows\system32\dllcache\iertutil.dll
+ 2011-12-16 08:03 . 2011-08-22 23:48 1212416 c:\windows\ie8updates\KB2618444-IE8\urlmon.dll
+ 2011-12-16 08:03 . 2011-10-03 08:35 5971456 c:\windows\ie8updates\KB2618444-IE8\mshtml.dll
+ 2011-12-16 08:03 . 2011-08-22 23:48 2000384 c:\windows\ie8updates\KB2618444-IE8\iertutil.dll
- 2011-07-25 07:04 . 2010-12-09 13:38 2192768 c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2011-07-25 07:04 . 2011-10-25 13:33 2192768 c:\windows\Driver Cache\i386\ntoskrnl.exe
- 2011-07-25 07:04 . 2010-12-09 13:07 2027008 c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2011-07-25 07:04 . 2011-10-25 12:52 2027008 c:\windows\Driver Cache\i386\ntkrpamp.exe
- 2011-07-25 07:04 . 2010-12-09 13:07 2069376 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2011-07-25 07:04 . 2011-10-25 12:52 2069376 c:\windows\Driver Cache\i386\ntkrnlpa.exe
- 2011-07-25 07:04 . 2010-12-09 13:42 2148864 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2011-07-25 07:04 . 2011-10-25 13:37 2148864 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2008-12-01 16:35 . 2011-12-16 08:01 52988224 c:\windows\system32\MRT.exe
+ 2007-08-13 23:54 . 2011-11-04 19:20 11081728 c:\windows\system32\ieframe.dll
- 2007-08-13 23:54 . 2011-08-23 21:48 11081728 c:\windows\system32\ieframe.dll
+ 2011-07-25 13:45 . 2011-11-04 19:20 11081728 c:\windows\system32\dllcache\ieframe.dll
- 2011-07-25 13:45 . 2011-08-23 21:48 11081728 c:\windows\system32\dllcache\ieframe.dll
+ 2011-12-16 08:03 . 2011-08-23 21:48 11081728 c:\windows\ie8updates\KB2618444-IE8\ieframe.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SansaDispatch"="c:\documents and settings\Main\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe" [2010-12-15 79872]
"igndlm.exe"="c:\program files\Download Manager\DLM.exe" [2009-10-27 1103216]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2008-03-26 49152]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2009-09-30 718688]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-04 44032]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2008-07-22 77824]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-10-08 16744256]
"NvMediaCenter"="NvMCTray.dll" [2011-10-08 203072]
"nwiz"="c:\program files\NVIDIA Corporation\nview\nwiz.exe" [2011-10-08 1632360]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-03-13 81920]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2010-08-26 15:24 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"c:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpsapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqcopy2.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqpse.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqsudi.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\alien swarm\\srcds.exe"=
"c:\\Riot Games\\League of Legends\\lol.launcher.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\deus ex\\System\\DeusEx.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\chantelise\\chantelise.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\chantelise\\custom.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\tidalis\\Tidalis.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\plants vs zombies\\PlantsVsZombies.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\dreddvsdeath\\Dredd.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\titan quest\\Titan Quest.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\titan quest\\help.htm"=
"c:\\Program Files\\Steam\\SteamApps\\common\\ghost master\\ghost.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\thief deadly shadows\\System\\runme.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\bioshock\\Builds\\Release\\Bioshock.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\star raiders\\StarRaiders.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\the undergarden\\TheUndergarden.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\ghostbusters sanctum of slime\\Game\\GhostBustersSOS.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\universe at war earth assault\\LaunchUAW.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\space siege\\Space Siege\\SpaceSiege.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\aaaaaaaaaaaaaaaaaaaaaaaaa!!!\\main.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\oddworld abes oddysee\\AbeWin.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\oddworld abes exoddus\\Exoddus.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\on the rain-slick precipice of darkness - episode one\\RainSlickEp1.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\penny arcade adventures on the rain-slick precipice of darkness episode 2\\RainSlickEp2.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\puzzle chronicles\\PuzzleChronicles.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\mrrobot\\MrRobot.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\shatter\\ShatterSettingsEditor.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\project aftermath\\ProjectAftermath.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\spectromancer\\Spectromancer.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\droplitz\\Cascade.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\the last remnant\\Binaries\\TLR.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\poker night at the inventory\\CelebrityPoker.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\zombie driver\\Release\\ZombieDriver.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\light of altair\\Altair.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\avencast\\Avencast.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\grotesque tactics\\GrotesqueTactics.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\armada 2526\\bin\\Armada2526.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\command and conquer 4 tiberian twilight\\CNC4.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\command and conquer 4 tiberian twilight\\Support\\EA Help\\Electronic_Arts_Technical_Support.htm"=
"c:\\Program Files\\Steam\\SteamApps\\common\\age of wonders\\Launcher.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\age of wonders\\AoWSetup.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\age of wonders\\Readme.txt"=
"c:\\Program Files\\Steam\\SteamApps\\common\\age of wonders\\QuickStart.pdf"=
"c:\\Program Files\\Steam\\SteamApps\\common\\age of wonders\\AoWEd.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\recettear\\recettear.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\recettear\\custom.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\ares\\ARES.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\spiral knights\\java_vm\\bin\\javaw.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\breath of death vii\\BoDVIIPC.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\cthulhu saves the world\\CSTW.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\alien swarm\\swarm.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\team fortress 2 meet the medic\\smp.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\post apocalyptic mayhem\\PAMMainGame.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\sid meier's civilization v\\Launcher.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\portal 2\\portal2.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\titan quest immortal throne\\Tqit.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\titan quest immortal throne\\help.htm"=
"c:\\Program Files\\Steam\\SteamApps\\common\\deus ex - human revolution\\dxhr.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\sanctum\\Binaries\\Win32\\SanctumGame-Win32-Shipping.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\back to the future ep 2\\BackToTheFuture102.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\tomb raider anniversary\\tra.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\bejeweled 3\\Bejeweled3.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\magicka\\Magicka.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\4 elements\\4 Elements.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\batman2\\Binaries\\Win32\\BatmanAC.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\batman2\\RunLauncher.bat"=
"c:\\Program Files\\Steam\\SteamApps\\common\\dungeon defenders\\Binaries\\Win32\\DungeonDefenders.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\defensegridtheawakening\\DefenseGrid.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"135:TCP"= 135:TCP:TCP Port 135
"5000:TCP"= 5000:TCP:TCP Port 5000
"5001:TCP"= 5001:TCP:TCP Port 5001
"5002:TCP"= 5002:TCP:TCP Port 5002
"5003:TCP"= 5003:TCP:TCP Port 5003
"5004:TCP"= 5004:TCP:TCP Port 5004
"5005:TCP"= 5005:TCP:TCP Port 5005
"5006:TCP"= 5006:TCP:TCP Port 5006
"5007:TCP"= 5007:TCP:TCP Port 5007
"5008:TCP"= 5008:TCP:TCP Port 5008
"5009:TCP"= 5009:TCP:TCP Port 5009
"5010:TCP"= 5010:TCP:TCP Port 5010
"5011:TCP"= 5011:TCP:TCP Port 5011
"5012:TCP"= 5012:TCP:TCP Port 5012
"5013:TCP"= 5013:TCP:TCP Port 5013
"5014:TCP"= 5014:TCP:TCP Port 5014
"5015:TCP"= 5015:TCP:TCP Port 5015
"5016:TCP"= 5016:TCP:TCP Port 5016
"5017:TCP"= 5017:TCP:TCP Port 5017
"5018:TCP"= 5018:TCP:TCP Port 5018
"5019:TCP"= 5019:TCP:TCP Port 5019
"5020:TCP"= 5020:TCP:TCP Port 5020
"50942:TCP"= 50942:TCP:CharBuilderFull
"50942:UDP"= 50942:UDP:CharBuilderFull
"19585:TCP"= 19585:TCP:CharBuilderFull
"19585:UDP"= 19585:UDP:CharBuilderFull
"57330:TCP"= 57330:TCP

ando Media Booster
"57330:UDP"= 57330:UDP

ando Media Booster
"8381:TCP"= 8381:TCP:League of Legends Launcher
"8381:UDP"= 8381:UDP:League of Legends Launcher
"8382:TCP"= 8382:TCP:League of Legends Launcher
"8382:UDP"= 8382:UDP:League of Legends Launcher
"8383:TCP"= 8383:TCP:League of Legends Launcher
"8383:UDP"= 8383:UDP:League of Legends Launcher
"8397:TCP"= 8397:TCP:League of Legends Launcher
"8397:UDP"= 8397:UDP:League of Legends Launcher
"6968:TCP"= 6968:TCP:League of Legends Launcher
"6968:UDP"= 6968:UDP:League of Legends Launcher
"8398:TCP"= 8398:TCP:League of Legends Launcher
"8398:UDP"= 8398:UDP:League of Legends Launcher
"8393:TCP"= 8393:TCP:League of Legends Lobby
"8393:UDP"= 8393:UDP:League of Legends Lobby
"8390:TCP"= 8390:TCP:League of Legends Game Client
"8390:UDP"= 8390:UDP:League of Legends Game Client
.
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360\0501000.01D\SymDS.sys [5/18/2011 3:23 PM 340088]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0501000.01D\SymEFA.sys [5/18/2011 3:23 PM 744568]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20111210.003\BHDrvx86.sys [12/14/2011 6:14 PM 819320]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [3/23/2009 1:07 PM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [3/23/2009 1:07 PM 67656]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360\0501000.01D\Ironx86.sys [5/18/2011 3:23 PM 136312]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [12/15/2011 12:09 PM 366152]
R2 N360;Norton 360;c:\program files\Norton 360 Premier Edition\Engine\5.1.0.29\ccSvcHst.exe [5/18/2011 3:22 PM 130008]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [7/27/2011 12:11 PM 2253120]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [12/15/2011 2:08 PM 106104]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20111216.001\IDSXpx86.sys [12/16/2011 7:01 PM 356280]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [12/15/2011 12:09 PM 22216]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [7/27/2011 12:10 PM 119656]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [1/3/2009 10:10 AM 717296]
S2 {09BB444F-B2E2-4009-BAF2-7B727681223E};BuddyVM;\??\c:\mst3k\Titan\SlaveMaker15x5\Hitomi - My Stepsister\Hitomi\VMLaunch\BuddyVM.sys --> c:\mst3k\Titan\SlaveMaker15x5\Hitomi - My Stepsister\Hitomi\VMLaunch\BuddyVM.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 12:16 PM 130384]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [3/23/2009 1:07 PM 12872]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 12:16 PM 753504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.thenorthernempire.com/forum/index.php
TCP: DhcpNameServer = 216.104.96.22 216.104.98.222
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-12-17 19:21
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
SansaDispatch = c:\documents and settings\Main\Application Data\SanDisk\Sansa Updater\SansaDispatch.exe?m%3d%26is-debug%3d%26rom-version%3d%26part-number%3d%26product-n????7?2? ??????????????
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton 360 Premier Edition\Engine\5.1.0.29\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360 Premier Edition\Engine\5.1.0.29\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1844237615-1957994488-839522115-1004\Software\KISS\«0¹0¿0à0á0¤0É03*D*]
"InstallPath"="c:\\MST3K\\mtadfk.com\\custom maid\\ƒJƒXƒ^ƒ€ƒƒCƒh3D"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(732)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
- - - - - - - > 'explorer.exe'(4060)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\RunDLL32.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\wscntfy.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
.
**************************************************************************
.
Completion time: 2011-12-17 19:23:29 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-18 00:23
ComboFix2.txt 2011-12-16 03:46
.
Pre-Run: 68,540,624,896 bytes free
Post-Run: 68,471,656,448 bytes free
.
- - End Of File - - FC35FCA113F097A6D865985978248209