ComboFix 09-05-23.04 - Mega 05/24/2009 13:16.1 - NTFSx86
Running from: c:\documents and settings\Mega\My Documents\Downloads\new\ComboFix.exe
AV: ESET Smart Security 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
E:\desktop.ini
.
((((((((((((((((((((((((( Files Created from 2009-04-24 to 2009-05-24 )))))))))))))))))))))))))))))))
.
2009-05-23 05:59 . 2009-05-23 05:59 -------- d-----w c:\documents and settings\Mega\Application Data\WNR
2009-05-22 14:49 . 2009-05-22 14:49 -------- d-----w c:\documents and settings\Mega\Application Data\Thinstall
2009-05-22 14:27 . 2009-05-22 14:27 -------- d-----w c:\windows\system32\Futuremark
2009-05-22 14:27 . 2009-05-22 14:27 -------- d-----w c:\program files\Common Files\Futuremark Shared
2009-05-22 14:27 . 2008-09-17 12:14 27672 ----a-r c:\windows\system32\drivers\Entech.sys
2009-05-22 11:04 . 2009-05-22 11:04 -------- d-----w C:\youtubevac
2009-05-22 11:04 . 2009-05-22 11:04 -------- d-----w c:\program files\YouTubeVac
2009-05-15 14:48 . 2009-05-15 14:48 57344 ----a-w c:\documents and settings\Mega\Application Data\Sun\Java\Deployment\cache\6.0\50\5b902232-5a6339e7-n\Decora-SSE.dll
2009-05-15 14:48 . 2009-05-15 14:48 24064 ----a-w c:\documents and settings\Mega\Application Data\Sun\Java\Deployment\cache\6.0\15\4e09eacf-6921df1f-n\Decora-D3D.dll
2009-05-15 14:48 . 2009-05-15 14:48 315392 ----a-w c:\documents and settings\Mega\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-58ce169e-n\jogl.dll
2009-05-15 14:48 . 2009-05-15 14:48 20480 ----a-w c:\documents and settings\Mega\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-58ce169e-n\jogl_awt.dll
2009-05-15 14:48 . 2009-05-15 14:48 114688 ----a-w c:\documents and settings\Mega\Application Data\Sun\Java\Deployment\cache\6.0\62\6baea4fe-58ce169e-n\jogl_cg.dll
2009-05-15 14:48 . 2009-05-15 14:48 20480 ----a-w c:\documents and settings\Mega\Application Data\Sun\Java\Deployment\cache\6.0\45\4f710eed-3729417b-n\gluegen-rt.dll
2009-05-15 14:48 . 2009-05-15 14:48 499712 ----a-w c:\documents and settings\Mega\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-28a1919b-n\msvcp71.dll
2009-05-15 14:48 . 2009-05-15 14:48 499712 ----a-w c:\documents and settings\Mega\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-28a1919b-n\jmc.dll
2009-05-15 14:48 . 2009-05-15 14:48 348160 ----a-w c:\documents and settings\Mega\Application Data\Sun\Java\Deployment\cache\6.0\33\258cea61-28a1919b-n\msvcr71.dll
2009-05-14 06:17 . 2009-05-14 06:17 -------- d-----w c:\documents and settings\Mega\Application Data\Red Kawa
2009-05-14 06:13 . 2009-05-14 06:13 -------- d-----w c:\program files\Regensoft
2009-05-14 06:13 . 2009-05-23 15:51 -------- d-----w c:\program files\AviSynth 2.5
2009-05-14 06:13 . 2009-05-14 06:13 -------- d-----w c:\program files\Red Kawa
2009-05-14 01:30 . 2009-05-14 01:30 -------- d-----w c:\documents and settings\Mega\Application Data\ooVoo Details
2009-05-14 01:30 . 2009-05-14 01:30 -------- d-----w c:\program files\ooVoo
2009-05-14 00:12 . 2009-05-23 15:54 -------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-05-14 00:12 . 2007-08-15 10:09 159744 ----a-w c:\windows\system32\wt_menu.dll
2009-05-14 00:12 . 2007-08-15 10:09 40960 ----a-w c:\windows\system32\ssubtmr6.dll
2009-05-14 00:12 . 1999-02-09 18:40 188928 ----a-w c:\windows\system32\vbuzip10.DLL
2009-05-14 00:12 . 2009-05-14 00:14 -------- d-----w c:\program files\Smarty Uninstaller Pro
2009-05-14 00:11 . 2009-05-14 00:11 -------- d-----w C:\Documents and Cettings
2009-05-13 10:50 . 2008-03-29 20:01 126976 ----a-w c:\windows\system32\USBcillin.exe
2009-05-13 01:32 . 2009-05-13 01:32 -------- d-----w c:\documents and settings\Mega\ErrorLogs
2009-05-13 01:25 . 2009-05-14 02:05 910632 ----a-w c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-05-12 12:39 . 2009-05-12 12:39 -------- d-----w c:\documents and settings\Mega\Application Data\uniblue
2009-05-12 12:22 . 2009-05-12 12:22 -------- d-----w c:\windows\system32\ar-SA
2009-05-12 12:19 . 2009-05-12 12:19 -------- d-----w C:\f72cb9575c8fc1ebf413cf604f390d67
2009-05-12 12:19 . 2009-05-12 12:34 -------- d-----w c:\windows\SxsCaPendDel
2009-05-12 12:04 . 2009-05-12 12:04 -------- d--h--r C:\AHCache
2009-05-09 10:05 . 2009-05-09 10:05 -------- d-----w c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2009-05-08 22:32 . 2008-04-14 12:00 221184 ----a-w c:\windows\system32\wmpns.dll
2009-05-08 22:32 . 2009-05-08 22:32 -------- d-----w C:\7eeb38b214610f077a91408ebdfe0f
2009-05-08 22:31 . 2009-05-08 22:32 -------- d-----w c:\windows\system32\drivers\umdf
2009-05-08 15:29 . 2009-05-08 22:32 -------- d-----w c:\windows\system32\LogFiles
2009-05-07 23:54 . 2009-05-21 12:53 -------- d-----w c:\documents and settings\Mega\Application Data\VMware
2009-05-07 23:50 . 2009-05-23 15:46 -------- d-----w c:\documents and settings\LocalService\Application Data\VMware
2009-05-07 23:48 . 2009-03-26 14:31 55856 ----a-r c:\windows\system32\vnetinst.dll
2009-05-07 23:48 . 2009-03-26 14:31 16560 ----a-r c:\windows\system32\drivers\vmnetadapter.sys
2009-05-07 23:48 . 2009-03-26 20:04 326192 ----a-w c:\windows\system32\vmnetdhcp.exe
2009-05-07 23:48 . 2009-03-26 20:05 26288 ----a-w c:\windows\system32\drivers\vmnetuserif.sys
2009-05-07 23:48 . 2009-03-26 20:04 399920 ----a-w c:\windows\system32\vmnat.exe
2009-05-07 23:48 . 2009-03-26 14:31 50736 ----a-r c:\windows\system32\vmnetbridge.dll
2009-05-07 23:48 . 2009-03-26 14:31 31280 ----a-r c:\windows\system32\drivers\vmnetbridge.sys
2009-05-07 23:48 . 2009-03-26 14:31 18736 ----a-r c:\windows\system32\drivers\vmnet.sys
2009-05-07 23:48 . 2009-03-26 20:04 723504 ----a-w c:\windows\system32\vnetlib.dll
2009-05-07 23:47 . 2009-03-26 20:05 23216 ----a-w c:\windows\system32\drivers\VMkbd.sys
2009-05-07 23:45 . 2009-05-23 15:46 -------- d-----w c:\documents and settings\All Users\Application Data\VMware
2009-05-07 23:45 . 2009-05-07 23:45 -------- d-----w c:\program files\VMware
2009-05-07 14:46 . 2009-05-07 14:46 -------- d-----w c:\documents and settings\Mega\Local Settings\Application Data\Identities
2009-05-07 14:43 . 2009-05-07 14:46 -------- d-----w c:\documents and settings\Mega\Local Settings\Application Data\Google
2009-05-07 12:44 . 2009-05-07 12:44 -------- d-----w c:\program files\Reemo
2009-05-07 07:42 . 2009-03-26 15:35 210352 ----a-w c:\windows\system32\idmmbc.dll
2009-05-06 15:32 . 2009-05-06 15:32 -------- d-----w c:\program files\iPhone Tunnel Suite
2009-05-05 15:55 . 2009-05-05 15:56 -------- d-----w c:\program files\Neighbours From Hell 5
2009-05-05 12:02 . 2009-05-05 12:02 -------- d-----w c:\documents and settings\Mega\Library
2009-05-05 12:02 . 2009-05-05 12:02 -------- d-----w c:\documents and settings\Mega\Application Data\com.adobe.ExMan
2009-05-05 11:54 . 2009-05-05 11:54 -------- d-----w c:\documents and settings\All Users\Application Data\FLEXnet
2009-05-05 11:48 . 2009-05-05 11:48 -------- d-----w c:\documents and settings\All Users\Application Data\ALM
2009-05-05 01:35 . 2009-05-05 01:57 -------- d-----w C:\Dady
2009-05-04 21:17 . 2009-05-04 21:17 -------- d-----w c:\program files\Common Files\Macrovision Shared
2009-05-04 21:05 . 2009-05-04 21:05 -------- d-----w c:\program files\Avramovic Web Solutions
2009-05-04 20:06 . 2009-05-14 00:28 -------- d-sh--w C:\found.001
2009-05-03 21:22 . 2009-05-03 21:22 -------- d-----w c:\documents and settings\LocalService\Local Settings\Application Data\ESET
2009-05-03 07:57 . 2009-05-14 00:28 -------- d-sh--w C:\found.000
2009-05-03 06:02 . 2009-05-03 06:03 -------- d-----w c:\program files\Error Repair Professional
2009-05-03 05:52 . 2009-05-03 05:52 0 ----a-w c:\windows\system32\cd.dat
2009-05-02 23:53 . 2009-05-02 23:53 -------- d-----w c:\documents and settings\Mega\Application Data\Media Player Classic
2009-05-02 23:51 . 2004-01-11 22:00 348160 ----a-w c:\windows\system32\msvcr71.dll
2009-05-02 23:51 . 2003-03-19 03:14 499712 ----a-w c:\windows\system32\msvcp71.dll
2009-05-02 21:25 . 2009-05-02 21:25 -------- d-----w c:\windows\Sun
2009-05-02 21:25 . 2009-05-02 21:25 410984 ----a-w c:\windows\system32\deploytk.dll
2009-05-02 21:25 . 2009-05-02 21:25 -------- d-----w c:\program files\Java
2009-05-02 21:24 . 2009-05-02 21:24 152576 ----a-w c:\documents and settings\Mega\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-05-02 13:24 . 2009-05-02 13:24 -------- d-----w c:\windows\system32\Adobe
2009-05-02 13:24 . 2001-10-26 21:16 16384 ----a-w c:\windows\system32\FileOps.exe
2009-05-02 13:22 . 2009-05-02 13:22 -------- d-----w c:\windows\Adobe Illustrator CS
2009-05-02 12:15 . 2009-05-23 11:23 -------- d-----w c:\documents and settings\Mega\Local Settings\Application Data\Adobe
2009-05-02 12:08 . 2008-10-16 11:06 268648 ----a-w c:\windows\system32\mucltui.dll
2009-05-02 12:08 . 2008-10-16 11:06 208744 ----a-w c:\windows\system32\muweb.dll
2009-05-02 01:04 . 2009-05-02 01:04 -------- d-----w c:\windows\KingoOo
2009-05-01 21:16 . 2009-05-01 21:16 -------- d-----w c:\documents and settings\All Users\Application Data\Adobe Systems
2009-05-01 21:16 . 2009-05-01 21:16 -------- d-----w c:\program files\Common Files\Adobe Systems Shared
2009-05-01 21:15 . 2009-05-23 11:24 -------- d-----w c:\program files\Common Files\Adobe
2009-05-01 18:17 . 2009-05-01 18:17 -------- d-----w c:\program files\iPod
2009-05-01 18:17 . 2009-05-01 18:17 -------- d-----w c:\program files\iTunes
2009-05-01 18:17 . 2009-05-01 18:17 -------- d-----w c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-01 18:13 . 2009-05-01 18:13 75048 ----a-w c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
2009-05-01 17:39 . 2001-08-17 19:36 5632 ----a-w c:\windows\system32\ptpusb.dll
2009-05-01 17:39 . 2008-04-14 02:42 159232 ----a-w c:\windows\system32\ptpusd.dll
2009-05-01 17:39 . 2008-04-13 21:15 15104 -c--a-w c:\windows\system32\dllcache\usbscan.sys
2009-05-01 17:39 . 2008-04-13 21:15 15104 ----a-w c:\windows\system32\drivers\usbscan.sys
2009-05-01 16:11 . 2008-04-14 12:00 36864 -c--a-w c:\windows\system32\dllcache\hanjadic.dll
2009-05-01 16:08 . 2001-08-17 13:59 3072 ----a-w c:\windows\system32\drivers\audstub.sys
2009-05-01 16:07 . 2008-04-14 05:41 21504 ----a-w c:\windows\system32\hidserv.dll
2009-05-01 16:07 . 2008-04-14 00:10 57600 ----a-w c:\windows\system32\drivers\redbook.sys
2009-05-01 16:06 . 2008-04-14 05:42 74240 ----a-w c:\windows\system32\usbui.dll
2009-05-01 16:03 . 2009-05-24 10:16 -------- d-----w c:\windows\system32\CatRoot2
2009-05-01 16:03 . 2009-05-12 21:26 -------- d-----w c:\windows\system32\CatRoot
2009-05-01 16:03 . 2009-05-01 13:26 -------- d-----w C:\Documents and Settings
2009-05-01 16:03 . 2009-05-01 13:21 -------- d--h--w c:\documents and settings\Default User
2009-05-01 16:03 . 2009-05-01 13:20 -------- d-----w c:\documents and settings\All Users
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-24 10:17 . 2009-05-01 13:55 -------- d-----w c:\documents and settings\Mega\Application Data\uTorrent
2009-05-24 10:17 . 2009-05-01 14:47 -------- d-----w c:\documents and settings\Mega\Application Data\DMCache
2009-05-22 14:47 . 2009-05-01 14:47 -------- d-----w c:\program files\Internet Download Manager
2009-05-22 14:27 . 2009-05-01 13:46 -------- d--h--w c:\program files\InstallShield Installation Information
2009-05-22 07:33 . 2009-05-01 15:05 -------- d-----w c:\program files\The KMPlayer
2009-05-16 22:55 . 2009-05-01 14:47 198064 ----a-w c:\documents and settings\Mega\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
2009-05-16 22:52 . 2009-05-01 14:56 2916816 ----a-w c:\documents and settings\Mega\Application Data\IDM\idmupdt.exe
2009-05-16 22:52 . 2009-05-01 14:47 -------- d-----w c:\documents and settings\Mega\Application Data\IDM
2009-05-15 17:06 . 2009-05-01 14:20 -------- d-----w c:\program files\Messenger Plus! Live
2009-05-12 12:36 . 2009-05-12 12:35 -------- dc-h--w c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}
2009-05-12 12:36 . 2009-05-12 12:36 -------- d-----w c:\program files\Uniblue
2009-05-12 12:35 . 2009-05-01 13:31 145296 ----a-w c:\documents and settings\Mega\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-07 15:27 . 2009-05-01 18:08 -------- d-----w c:\documents and settings\Mega\Application Data\Apple Computer
2009-05-07 14:41 . 2009-05-07 14:41 -------- d-----w c:\program files\K-Lite Codec Pack
2009-05-07 12:54 . 2009-05-01 14:44 -------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-05-04 08:46 . 2009-05-12 12:36 2835656 -c--a-w c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}\speedupmypc2009.exe
2009-05-03 07:55 . 2009-05-02 12:07 90112 ----a-w c:\windows\DUMP419c.tmp
2009-05-02 15:03 . 2009-05-01 13:20 86327 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-05-01 18:17 . 2009-05-01 18:06 -------- d-----w c:\program files\Common Files\Apple
2009-05-01 18:07 . 2009-05-01 18:07 -------- d-----w c:\documents and settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
2009-05-01 18:07 . 2009-05-01 18:07 -------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2009-05-01 18:07 . 2009-05-01 18:07 -------- d-----w c:\program files\QuickTime
2009-05-01 18:06 . 2009-05-01 18:06 -------- d-----w c:\program files\Apple Software Update
2009-05-01 18:06 . 2009-05-01 18:06 -------- d-----w c:\documents and settings\All Users\Application Data\Apple
2009-05-01 14:48 . 2009-05-01 14:48 -------- d-----w c:\program files\UltraISO
2009-05-01 14:48 . 2009-05-01 14:48 -------- d-----w c:\program files\Common Files\EZB Systems
2009-05-01 14:48 . 2009-05-01 14:46 -------- d-----w c:\program files\Hotspot Shield
2009-05-01 14:20 . 2009-05-01 14:20 -------- d-----w c:\program files\Circl Developement
2009-05-01 14:20 . 2009-05-01 14:16 -------- d-----w c:\program files\Windows Live
2009-05-01 14:18 . 2009-05-01 14:16 -------- dcsh--w c:\program files\Common Files\WindowsLiveInstaller
2009-05-01 14:16 . 2009-05-01 14:16 -------- d-----w c:\documents and settings\All Users\Application Data\WLInstaller
2009-05-01 14:14 . 2009-05-01 14:14 0 ----a-w c:\windows\nsreg.dat
2009-05-01 14:05 . 2009-05-01 14:05 -------- d-----w c:\program files\MSBuild
2009-05-01 14:02 . 2009-05-01 14:02 -------- d-----w c:\program files\Reference Assemblies
2009-05-01 13:56 . 2009-05-01 13:56 -------- d-----w c:\program files\uTorrent
2009-05-01 13:49 . 2009-05-01 13:46 -------- d-----w c:\program files\Realtek
2009-05-01 13:49 . 2009-05-01 13:49 -------- d-----w c:\documents and settings\Mega\Application Data\InstallShield
2009-05-01 13:46 . 2009-05-01 13:46 315392 ----a-w c:\windows\HideWin.exe
2009-05-01 13:33 . 2009-05-01 13:33 -------- d-----w c:\documents and settings\Mega\Application Data\ESET
2009-05-01 13:32 . 2009-05-01 13:32 -------- d-----w c:\program files\ESET
2009-05-01 13:32 . 2009-05-01 13:32 -------- d-----w c:\documents and settings\All Users\Application Data\ESET
2009-05-01 13:28 . 2009-05-01 13:28 -------- d-----w c:\program files\Common Files\InstallShield
2009-05-01 13:21 . 2009-05-01 13:21 -------- d-----w c:\program files\microsoft frontpage
2009-05-01 13:18 . 2009-05-01 13:18 21640 ----a-w c:\windows\system32\emptyregdb.dat
2009-04-29 09:45 . 2009-05-12 12:36 845128 -c--a-w c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}\SpeedUpMyPC2009\58D97068\B74607BA\System.Data.SQLite.dll
2009-04-29 09:45 . 2009-05-12 12:36 771368 -c--a-w c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}\SpeedUpMyPC2009\9966075F\B74607BA\UBSysMan.dll
2009-04-29 09:45 . 2009-05-12 12:36 614696 -c--a-w c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}\SpeedUpMyPC2009\7AEFAE8C\B74607BA\Launcher.exe
2009-04-29 09:45 . 2009-05-12 12:36 54608 -c--a-w c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}\SpeedUpMyPC2009\D720648F\B74607BA\Interop.IWshRuntimeLibrary.dll
2009-04-29 09:45 . 2009-05-12 12:36 519168 -c--a-w c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}\SpeedUpMyPC2009\78B94F67\B74607BA\IsLicense40.dll
2009-04-29 09:45 . 2009-05-12 12:36 474408 -c--a-w c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}\SpeedUpMyPC2009\62A3297F\B74607BA\AvalonCommon.dll
2009-04-29 09:45 . 2009-05-12 12:36 395048 -c--a-w c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}\SpeedUpMyPC2009\C77843B\B74607BA\SUMPBackend.dll
2009-04-29 09:45 . 2009-05-12 12:36 345008 -c--a-w c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}\SpeedUpMyPC2009\4BF757A\B74607BA\IsLicense30.dll
2009-04-29 09:45 . 2009-05-12 12:36 236840 -c--a-w c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}\SpeedUpMyPC2009\683B013A\B74607BA\PowerSuiteBackendUtils.dll
2009-04-29 09:45 . 2009-05-12 12:36 197968 -c--a-w c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}\SpeedUpMyPC2009\6A0591D6\B74607BA\ICSharpCode.SharpZipLib.dll
2009-04-29 09:45 . 2009-05-12 12:36 1250600 -c--a-w c:\documents and settings\All Users\Application Data\{A613CA96-150A-4A1D-90CE-67F81379DF8C}\SpeedUpMyPC2009\B430549D\B74607BA\SUMP.exe
2009-04-03 18:18 . 2009-05-01 14:46 33256 ----a-w c:\windows\system32\drivers\hssdrv.sys
2009-03-26 20:05 . 2009-03-26 20:05 54960 ----a-w c:\windows\system32\drivers\vmci.sys
2009-03-26 20:05 . 2009-03-26 20:05 857520 ----a-w c:\windows\system32\drivers\vmx86.sys
2009-03-26 20:05 . 2009-03-26 20:05 32304 ----a-w c:\windows\system32\drivers\hcmon.sys
2009-03-26 20:04 . 2009-03-26 20:04 14896 ----a-w c:\windows\system32\drivers\vmparport.sys
2009-03-26 16:11 . 2009-03-26 16:11 248368 ----a-w c:\windows\system32\vmnc.dll
2009-03-19 13:32 . 2009-05-01 18:07 23400 ----a-w c:\windows\system32\drivers\GEARAspiWDM.sys
2009-03-19 13:32 . 2009-03-19 13:32 23400 ----a-w c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
2009-03-08 01:34 . 2008-04-14 12:00 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 01:34 . 2008-04-14 12:00 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 01:33 . 2008-04-14 12:00 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 01:33 . 2008-04-14 12:00 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 01:32 . 2008-04-14 12:00 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 01:32 . 2008-04-14 12:00 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 01:31 . 2008-04-14 12:00 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 01:31 . 2008-04-14 12:00 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 01:31 . 2008-04-14 12:00 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 01:22 . 2008-04-14 12:00 156160 ----a-w c:\windows\system32\msls31.dll
2009-03-06 14:22 . 2008-04-14 12:00 284160 ----a-w c:\windows\system32\pdh.dll
2009-03-05 20:59 . 2009-05-01 18:06 36864 ----a-w c:\windows\system32\drivers\usbaapl.sys
2009-03-05 20:59 . 2009-05-01 18:06 1900544 ----a-w c:\windows\system32\usbaaplrc.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
2009-05-01 14:46 204248 ----a-w c:\program files\Hotspot Shield\HssIE\HssIE.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-05-07 2807216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-05-11 8429568]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-05-11 81920]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-02-06 2021400]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-02 148888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2007-05-11 1626112]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-07-05 16380416]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2007-06-15 1826816]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Mega\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 110592]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 110592]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoPrinters"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoPrinters"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\VMware\\VMware Workstation\\vmware-authd.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
"443:TCP"= 443:TCP:*

isabled

oVoo TCP المنفذ 443
"443:UDP"= 443:UDP:*

isabled

oVoo UDP المنفذ 443
"37674:TCP"= 37674:TCP:*

isabled

oVoo TCP المنفذ 37674
"37674:UDP"= 37674:UDP:*

isabled

oVoo UDP المنفذ 37674
"37675:UDP"= 37675:UDP:*

isabled

oVoo UDP المنفذ 37675
"37676:TCP"= 37676:TCP:*

isabled

oVoo TCP المنفذ 37676
"37676:UDP"= 37676:UDP:*

isabled

oVoo UDP المنفذ 37676
"37677:UDP"= 37677:UDP:*

isabled

oVoo UDP المنفذ 37677
R3 cpuz130;cpuz130;c:\docume~1\Mega\LOCALS~1\Temp\cpuz130\cpuz_x32.sys [x]
R3 HssTrayService;Hotspot Shield Tray Service;c:\program files\Hotspot Shield\bin\HssTrayService.EXE [2009-04-22 34352]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys [2009-02-06 106208]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2009-02-06 727720]
S2 HssSrv;Hotspot Shield Helper Service;c:\program files\Hotspot Shield\HssWPR\hsssrv.exe [2009-04-22 328752]
S2 vmci;VMware vmci;c:\windows\system32\Drivers\vmci.sys [2009-03-26 54960]
S3 HssDrv;Hotspot Shield Helper Miniport;c:\windows\system32\DRIVERS\HssDrv.sys [2009-04-03 33256]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - RSVP
*Deregistered* - AFD
*Deregistered* - ALG
*Deregistered* - Apple Mobile Device
*Deregistered* - AudioSrv
*Deregistered* - audstub
*Deregistered* - Beep
*Deregistered* - BITS
*Deregistered* - Browser
*Deregistered* - Cdfs
*Deregistered* - CryptSvc
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - dmio
*Deregistered* - dmload
*Deregistered* - dmserver
*Deregistered* - Dnscache
*Deregistered* - eamon
*Deregistered* - ehdrv
*Deregistered* - ekrn
*Deregistered* - epfw
*Deregistered* - Epfwndis
*Deregistered* - epfwtdi
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - Fastfat
*Deregistered* - FastUserSwitchingCompatibility
*Deregistered* - Fips
*Deregistered* - FltMgr
*Deregistered* - Ftdisk
*Deregistered* - Gpc
*Deregistered* - hcmon
*Deregistered* - helpsvc
*Deregistered* - HotspotShieldService
*Deregistered* - HssDrv
*Deregistered* - HssSrv
*Deregistered* - ImapiService
*Deregistered* - IpNat
*Deregistered* - IPSec
*Deregistered* - ISODrive
*Deregistered* - KSecDD
*Deregistered* - LanmanServer
*Deregistered* - lanmanworkstation
*Deregistered* - mnmdd
*Deregistered* - Mouclass
*Deregistered* - MountMgr
*Deregistered* - MRxDAV
*Deregistered* - MRxSmb
*Deregistered* - Msfs
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NDIS
*Deregistered* - NdisTapi
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - NVSvc
*Deregistered* - PartMgr
*Deregistered* - ParVdm
*Deregistered* - PptpMiniport
*Deregistered* - ProtectedStorage
*Deregistered* - PSched
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasMan
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - rdpdr
*Deregistered* - RpcSs
*Deregistered* - RSVP
*Deregistered* - SamSs
*Deregistered* - Schedule
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - Spooler
*Deregistered* - sr
*Deregistered* - srservice
*Deregistered* - Srv
*Deregistered* - stisvc
*Deregistered* - swenum
*Deregistered* - TapiSrv
*Deregistered* - tapvpn
*Deregistered* - Tcpip
*Deregistered* - TermDD
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - Update
*Deregistered* - usnjsvc
*Deregistered* - VgaSave
*Deregistered* - VMAuthdService
*Deregistered* - vmci
*Deregistered* - VMnetBridge
*Deregistered* - VMnetDHCP
*Deregistered* - VMnetuserif
*Deregistered* - VMparport
*Deregistered* - VMware NAT Service
*Deregistered* - vmx86
*Deregistered* - VolSnap
*Deregistered* - vstor2-ws60
*Deregistered* - Wanarp
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - WS2IFSL
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-05-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 09:34]
2009-05-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1614895754-1343024091-682003330-1003.job
- c:\documents and settings\Mega\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-07 14:43]
2009-05-24 c:\windows\Tasks\User_Feed_Synchronization-{51555B49-EC3B-401A-BC0D-1A928029C07E}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 01:31]
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-procexp90.Sys
.
------- Supplementary Scan -------
.
uStart Page = about:blank
IE: تحميل الكل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetAll.htm
IE: تحميل بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\program files\Internet Download Manager\IEGetVL.htm
LSP: c:\windows\system32\idmmbc.dll
LSP: c:\program files\VMware\VMware Workstation\vsocklib.dll
FF - ProfilePath - c:\documents and settings\Mega\Application Data\Mozilla\Firefox\Profiles\zb6uzwny.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2195780&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Jawzah Customized Web Search
FF - component: c:\documents and settings\Mega\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
FF - plugin: c:\documents and settings\Mega\Local Settings\Application Data\Google\Update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-05-24 13:17
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{095a743e-8d61-4378-8ffe-c1d671a74238}]
@Denied: (Full) (Everyone)
"Model"=dword:0000008b
"Therad"=dword:00000014
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):45,88,2f,55,90,61,b6,7c,41,15,76,44,59,7b,d9,da,0d,0a,32,42,b8,
86,74,5e,ac,95,ea,cc,43,dd,a6,c1,83,d8,20,45,96,b4,cf,22,00,00,00,00,00,00,\
.
Completion time: 2009-05-24 13:18
ComboFix-quarantined-files.txt 2009-05-24 10:18
Pre-Run: 25,924,202,496 bytes free
Post-Run: 26,116,825,088 bytes free
437 --- E O F --- 2009-05-13 12:58