ComboFix 09-06-26.02 - user 07/23/2009 18:29.7 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.966.1033.18.2046.1563 [GMT 3:00]
Running from: f:\documents and settings\user\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
- REDUCED FUNCTIONALITY MODE -
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
E:\Autorun.inf
f:\windows\AhnRpta.exe
f:\windows\system32\e8main0.dll
J:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-06-23 to 2009-07-23 )))))))))))))))))))))))))))))))
.
2009-07-23 07:30 . 2009-07-23 09:22 109631 --sh--r- F:\8dtyjjf.exe
2009-07-23 07:21 . 2009-07-23 07:21 110859 --sh--r- F:\p0ijj.bat
2009-07-17 15:45 . 2009-07-17 15:45 -------- d-----w- f:\documents and settings\user\Application Data\Media Player Classic
2009-07-17 15:44 . 2009-05-29 21:31 881664 ----a-w- f:\windows\system32\xvidcore.dll
2009-07-17 15:44 . 2009-05-29 21:37 205824 ----a-w- f:\windows\system32\xvidvfw.dll
2009-07-17 15:44 . 2009-05-01 21:02 685056 ----a-w- f:\windows\system32\divx.dll
2009-07-17 15:44 . 2009-06-02 16:11 85504 ----a-w- f:\windows\system32\ff_vfw.dll
2009-07-17 15:44 . 2009-01-07 18:14 60273 ----a-w- f:\windows\system32\pthreadGC2.dll
2009-07-17 15:44 . 2009-07-17 15:45 -------- d-----w- f:\program files\K-Lite Codec Pack
2009-07-14 16:28 . 2009-06-28 07:58 106748 --sh--r- F:\uo10sn.cmd
2009-07-12 13:04 . 2009-07-12 13:04 -------- d-----w- f:\program files\DIFX
2009-07-12 08:18 . 2009-07-12 08:18 -------- d-----w- f:\documents and settings\user\Local Settings\Application Data\PunkBuster
2009-07-11 10:12 . 2009-07-11 19:26 -------- d-----w- f:\documents and settings\user\DoctorWeb
2009-07-07 23:55 . 2009-07-07 23:55 41808 ----a-w- f:\windows\system32\xfcodec.dll
2009-06-27 00:05 . 2009-06-27 00:05 -------- d-----w- f:\program files\Trend Micro
2009-06-26 20:29 . 2009-06-26 20:29 -------- dc----w- f:\windows\system32\dllcache\cache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-23 15:32 . 2009-05-09 20:23 433567776 --sha-w- f:\windows\system32\drivers\fidbox.dat
2009-07-23 15:32 . 2008-11-21 12:11 -------- d-----w- f:\documents and settings\user\Application Data\DMCache
2009-07-23 15:29 . 2008-11-10 09:40 -------- d-----w- f:\documents and settings\user\Application Data\uTorrent
2009-07-23 13:08 . 2009-05-09 20:23 5074280 --sha-w- f:\windows\system32\drivers\fidbox.idx
2009-07-22 07:17 . 2008-11-11 19:22 -------- d-----w- f:\program files\Steam
2009-07-22 06:48 . 2009-01-14 11:11 138736 ----a-w- f:\windows\system32\drivers\PnkBstrK.sys
2009-07-22 06:47 . 2009-01-14 11:11 188968 ----a-w- f:\windows\system32\PnkBstrB.exe
2009-07-21 17:34 . 2008-10-23 15:26 -------- d-----w- f:\documents and settings\user\Application Data\Paltalk
2009-07-21 14:15 . 2009-06-20 21:19 -------- d-----w- f:\documents and settings\user\Application Data\vlc
2009-07-20 09:31 . 2009-04-09 15:20 -------- d-----w- f:\documents and settings\user\Application Data\teamspeak2
2009-07-17 15:41 . 2009-01-27 19:19 -------- d-----w- f:\program files\DirectVobSub
2009-07-17 15:41 . 2008-10-23 15:32 -------- d-----w- f:\program files\DivX
2009-07-16 11:41 . 2009-03-21 11:42 256 ----a-w- f:\windows\system32\pool.bin
2009-07-14 12:02 . 2009-01-13 08:28 -------- d-----w- f:\program files\Xfire
2009-07-12 13:22 . 2008-10-23 15:25 -------- d-----w- f:\program files\Messenger Plus! Live
2009-07-12 13:22 . 2008-10-23 15:24 -------- d-----w- f:\program files\MSN Messenger
2009-07-12 13:13 . 2008-11-21 12:11 -------- d-----w- f:\documents and settings\user\Application Data\IDM
2009-07-12 08:20 . 2009-01-14 11:11 75064 ----a-w- f:\windows\system32\PnkBstrA.exe
2009-07-12 07:00 . 2009-01-13 08:28 -------- d-----w- f:\documents and settings\user\Application Data\Xfire
2009-07-11 15:02 . 2008-11-11 10:27 -------- d-----w- f:\program files\Camfrog
2009-06-26 23:43 . 2008-10-23 18:10 1626145 ----a-w- f:\windows\system32\nwiz.exe
2009-06-26 23:33 . 2008-10-23 15:35 -------- d-----w- f:\program files\Real_SC
2009-06-26 23:09 . 2009-06-19 19:15 110124 ----a-w- f:\documents and settings\user\Application Data\BSplayer PRO\AC3 Filter\uninstall.exe
2009-06-26 23:09 . 2008-07-04 10:35 128360 ----a-w- f:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\DifXInstall32.exe
2009-06-26 23:09 . 2008-07-29 16:47 148800 ----a-w- f:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files\Kaspersky Anti-Virus 2009\english\setup.exe
2009-06-26 23:09 . 2008-11-20 11:06 156968 ----a-w- f:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.0.2.20\SetupAdmin.exe
2009-06-26 05:49 . 2009-06-26 21:00 2191110 ----a-w- f:\documents and settings\user\Application Data\IDM\SmitfraudFix\SmitfraudFix.cmd
2009-06-21 16:28 . 2008-10-23 15:27 -------- d-----w- f:\documents and settings\user\Application Data\Skype
2009-06-21 16:17 . 2009-05-15 12:48 -------- d-----w- f:\documents and settings\user\Application Data\skypePM
2009-06-19 21:08 . 2009-06-19 21:08 198064 ----a-w- f:\documents and settings\user\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
2009-06-19 21:08 . 2008-11-21 12:11 -------- d-----w- f:\program files\Internet Download Manager
2009-06-19 19:16 . 2008-10-23 15:31 -------- d-----w- f:\documents and settings\user\Application Data\BSplayer PRO
2009-06-16 08:55 . 2008-10-24 19:39 -------- d-----w- f:\documents and settings\user\Application Data\DivX
2009-06-15 10:09 . 2009-06-15 09:43 -------- d-----w- f:\program files\ManyCam 2.4
2009-06-15 10:09 . 2009-06-15 09:43 -------- d-----w- f:\documents and settings\user\Application Data\ManyCam
2009-06-10 14:21 . 2009-06-10 14:21 -------- d-----w- f:\program files\Subtitles
2009-06-02 08:17 . 2009-06-26 21:00 75776 ----a-w- f:\documents and settings\user\Application Data\IDM\SmitfraudFix\WS2Fix.exe
2009-05-31 20:51 . 2009-05-31 20:51 -------- d-----w- f:\program files\CCleaner
2009-05-22 20:28 . 2009-05-22 20:28 10134 ----a-r- f:\documents and settings\user\Application Data\Microsoft\Installer\{14291118-0C19-45EA-A4FA-5C1C0F5FDE09}\ARPPRODUCTICON.exe
2009-05-15 12:48 . 2009-05-15 12:48 56 ---ha-w- f:\windows\system32\ezsidmv.dat
2009-05-13 13:48 . 2009-03-21 11:40 26694 ----a-r- f:\documents and settings\user\Application Data\Microsoft\Installer\{8659D9D6-1FBE-4A9F-BF64-939022C801B7}\BlackBerry.exe
2009-05-09 19:20 . 2008-11-18 10:26 872080 ----a-w- f:\documents and settings\user\Application Data\cleaner\CSPSeraser.exe
2009-05-09 19:20 . 2008-11-18 10:26 2742416 ----a-w- f:\documents and settings\user\Application Data\cleaner\PrivacySuite.exe
2009-05-09 19:20 . 2008-11-18 10:26 2514064 ----a-w- f:\documents and settings\user\Application Data\cleaner\Scheduler.exe
2009-05-09 19:20 . 2008-11-18 10:26 1845904 ----a-w- f:\documents and settings\user\Application Data\cleaner\Safe.exe
2009-05-09 19:20 . 2008-11-18 10:26 1777296 ----a-w- f:\documents and settings\user\Application Data\cleaner\CSRiskMon.exe
2009-05-09 19:04 . 2004-08-04 12:00 69120 ----a-w- f:\windows\system32\notepad.exe.tmp
2009-05-09 18:49 . 2004-08-04 12:00 388608 ----a-w- f:\windows\system32\cmd.exe.tmp
2009-05-09 12:31 . 2009-01-27 11:03 720896 ----a-w- f:\windows\iun6002.exe
2009-05-06 16:12 . 2008-10-23 14:59 106080 ----a-w- f:\documents and settings\user\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-01 21:02 . 2008-07-25 08:34 90112 ----a-w- f:\windows\system32\dpl100.dll
2006-05-03 09:06 . 2009-01-12 12:06 163328 --sh--r- f:\windows\system32\flvDX.dll
2007-02-21 10:47 . 2009-01-12 12:06 31232 --sh--r- f:\windows\system32\msfDX.dll
2008-03-16 12:30 . 2009-01-12 12:06 216064 --sh--r- f:\windows\system32\nbDX.dll
.
(((((((((((((((((((((((((((((
SnapShot@2009-06-26_20.26.12 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-23 13:09 . 2009-07-23 13:09 16384 f:\windows\temp\Perflib_Perfdata_688.dat
+ 2009-07-20 10:04 . 2007-04-04 15:53 81768 f:\windows\system32\xinput1_3.dll
+ 2009-07-20 10:04 . 2006-07-28 06:30 62744 f:\windows\system32\xinput1_2.dll
+ 2009-07-20 10:04 . 2006-03-31 09:39 62672 f:\windows\system32\xinput1_1.dll
+ 2009-07-20 10:04 . 2009-03-16 11:18 69448 f:\windows\system32\XAPOFX1_3.dll
+ 2009-07-20 10:04 . 2008-10-15 04:03 70992 f:\windows\system32\XAPOFX1_2.dll
+ 2009-07-20 10:04 . 2008-07-30 03:20 68616 f:\windows\system32\XAPOFX1_1.dll
+ 2009-07-20 10:04 . 2008-05-30 11:17 65032 f:\windows\system32\XAPOFX1_0.dll
+ 2009-07-20 10:04 . 2009-03-16 11:18 22360 f:\windows\system32\X3DAudio1_6.dll
+ 2009-07-20 10:04 . 2008-10-15 04:03 23376 f:\windows\system32\X3DAudio1_5.dll
+ 2009-07-20 10:04 . 2008-05-30 11:17 25608 f:\windows\system32\X3DAudio1_4.dll
+ 2009-07-20 10:04 . 2008-03-05 13:00 25608 f:\windows\system32\X3DAudio1_3.dll
+ 2009-07-20 10:04 . 2007-10-22 00:37 17928 f:\windows\system32\X3DAudio1_2.dll
+ 2009-07-20 10:04 . 2007-03-05 09:42 15128 f:\windows\system32\x3daudio1_1.dll
+ 2009-06-26 20:29 . 2008-10-16 11:09 51224 f:\windows\system32\dllcache\cache\wuauclt.exe
+ 2009-06-26 20:29 . 2004-08-04 12:00 82944 f:\windows\system32\dllcache\cache\ws2_32.dll
+ 2009-06-26 20:29 . 2004-08-04 12:00 24576 f:\windows\system32\dllcache\cache\userinit.exe
+ 2009-06-26 20:29 . 2004-08-04 12:00 14336 f:\windows\system32\dllcache\cache\svchost.exe
+ 2009-06-26 20:29 . 2004-08-04 12:00 57856 f:\windows\system32\dllcache\cache\spoolsv.exe
+ 2009-06-26 20:29 . 2004-08-04 12:00 17408 f:\windows\system32\dllcache\cache\powrprof.dll
+ 2009-06-26 20:29 . 2004-08-04 12:00 13312 f:\windows\system32\dllcache\cache\lsass.exe
+ 2009-06-26 20:29 . 2004-08-04 12:00 24576 f:\windows\system32\dllcache\cache\kbdclass.sys
+ 2009-06-26 20:29 . 2004-08-04 12:00 29056 f:\windows\system32\dllcache\cache\ip6fw.sys
+ 2009-06-26 20:29 . 2004-08-04 12:00 15360 f:\windows\system32\dllcache\cache\ctfmon.exe
+ 2009-07-20 10:04 . 2005-03-18 13:23 12800 f:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Diagnostics.dll
+ 2009-07-20 10:04 . 2005-03-18 13:23 53248 f:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2009-07-12 13:16 . 2009-07-12 13:16 29926 f:\windows\Installer\{571700F0-DB9D-4B3A-B03D-35A14BB5939F}\MsblIco.Exe
+ 2009-07-20 10:04 . 2009-07-20 10:04 12800 f:\windows\assembly\GAC\Microsoft.DirectX.Diagnostics\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Diagnostics.dll
+ 2009-07-20 10:04 . 2009-07-20 10:04 53248 f:\windows\assembly\GAC\Microsoft.DirectX.AudioVideoPlayback\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.AudioVideoPlayback.dll
+ 2009-01-12 12:06 . 2004-01-25 16:18 217088 f:\windows\system32\yv12vfw.dll
+ 2009-07-20 10:04 . 2009-03-16 11:18 517448 f:\windows\system32\XAudio2_4.dll
+ 2009-07-20 10:04 . 2008-10-15 04:03 514384 f:\windows\system32\XAudio2_3.dll
+ 2009-07-20 10:04 . 2008-07-30 03:20 509448 f:\windows\system32\XAudio2_2.dll
+ 2009-07-20 10:04 . 2008-05-30 11:19 507400 f:\windows\system32\XAudio2_1.dll
+ 2009-07-20 10:04 . 2008-03-05 13:03 479752 f:\windows\system32\XAudio2_0.dll
+ 2009-07-20 10:04 . 2009-03-16 11:18 235352 f:\windows\system32\xactengine3_4.dll
+ 2009-07-20 10:04 . 2008-10-15 04:03 235856 f:\windows\system32\xactengine3_3.dll
+ 2009-07-20 10:04 . 2008-07-30 03:20 238088 f:\windows\system32\xactengine3_2.dll
+ 2009-07-20 10:04 . 2008-05-30 11:18 238088 f:\windows\system32\xactengine3_1.dll
+ 2009-07-20 10:04 . 2008-03-05 13:03 238088 f:\windows\system32\xactengine3_0.dll
+ 2009-07-20 10:04 . 2007-07-19 21:57 267112 f:\windows\system32\xactengine2_9.dll
+ 2009-07-20 10:04 . 2007-06-20 17:46 266088 f:\windows\system32\xactengine2_8.dll
+ 2009-07-20 10:04 . 2007-04-04 15:55 261480 f:\windows\system32\xactengine2_7.dll
+ 2009-07-20 10:04 . 2007-01-24 12:27 255848 f:\windows\system32\xactengine2_6.dll
+ 2009-07-20 10:04 . 2006-12-08 09:02 251672 f:\windows\system32\xactengine2_5.dll
+ 2009-07-20 10:04 . 2006-09-28 13:05 237848 f:\windows\system32\xactengine2_4.dll
+ 2009-07-20 10:04 . 2006-07-28 06:30 236824 f:\windows\system32\xactengine2_3.dll
+ 2009-07-20 10:04 . 2006-05-31 04:24 230168 f:\windows\system32\xactengine2_2.dll
+ 2009-07-20 10:04 . 2007-10-22 00:39 267272 f:\windows\system32\xactengine2_10.dll
+ 2009-07-20 10:04 . 2006-03-31 09:39 229584 f:\windows\system32\xactengine2_1.dll
+ 2008-10-23 15:42 . 2008-09-10 18:56 185920 f:\windows\system32\rmoc3260.dll
+ 2009-06-26 20:29 . 2004-08-04 12:00 502272 f:\windows\system32\dllcache\cache\winlogon.exe
+ 2009-06-26 20:29 . 2004-08-04 12:00 656384 f:\windows\system32\dllcache\cache\wininet.dll
+ 2009-06-26 20:29 . 2004-08-04 12:00 577024 f:\windows\system32\dllcache\cache\user32.dll
+ 2009-06-26 20:29 . 2004-08-04 12:00 295424 f:\windows\system32\dllcache\cache\termsrv.dll
+ 2009-06-26 20:29 . 2004-08-04 12:00 359040 f:\windows\system32\dllcache\cache\tcpip.sys
+ 2009-06-26 20:29 . 2004-08-04 12:00 108032 f:\windows\system32\dllcache\cache\services.exe
+ 2009-06-26 20:29 . 2004-08-04 12:00 182912 f:\windows\system32\dllcache\cache\ndis.sys
+ 2009-06-26 20:29 . 2004-08-04 12:00 983552 f:\windows\system32\dllcache\cache\kernel32.dll
+ 2009-06-26 20:29 . 2004-08-04 12:00 110080 f:\windows\system32\dllcache\cache\imm32.dll
+ 2009-06-26 20:29 . 2004-08-04 12:00 167936 f:\windows\system32\dllcache\cache\appmgmts.dll
+ 2009-07-20 10:04 . 2009-03-09 12:27 453456 f:\windows\system32\d3dx10_41.dll
+ 2009-07-20 10:04 . 2008-10-15 03:22 452440 f:\windows\system32\d3dx10_40.dll
+ 2009-07-20 10:04 . 2008-07-10 08:01 467984 f:\windows\system32\d3dx10_39.dll
+ 2009-07-20 10:04 . 2008-05-30 11:11 467984 f:\windows\system32\d3dx10_38.dll
+ 2009-07-20 10:04 . 2008-02-05 20:07 462864 f:\windows\system32\d3dx10_37.dll
+ 2009-07-20 10:04 . 2007-10-02 06:56 444776 f:\windows\system32\d3dx10_36.dll
+ 2009-07-20 10:04 . 2007-07-19 15:14 444776 f:\windows\system32\d3dx10_35.dll
+ 2009-07-20 10:04 . 2007-05-16 13:45 443752 f:\windows\system32\d3dx10_34.dll
+ 2009-07-20 10:04 . 2007-03-15 13:57 443752 f:\windows\system32\d3dx10_33.dll
+ 2009-07-20 10:04 . 2006-03-31 08:27 578560 f:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2911.0\Microsoft.DirectX.Direct3DX.dll
+ 2009-07-20 10:04 . 2006-02-03 04:40 578560 f:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2910.0\Microsoft.DirectX.Direct3DX.dll
+ 2009-07-20 10:04 . 2005-12-05 14:20 577536 f:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2909.0\Microsoft.DirectX.Direct3DX.dll
+ 2009-07-20 10:04 . 2005-09-28 11:11 577536 f:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2908.0\Microsoft.DirectX.Direct3DX.dll
+ 2009-07-20 10:04 . 2005-07-22 14:21 577024 f:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2907.0\Microsoft.DirectX.Direct3DX.dll
+ 2009-07-20 10:04 . 2005-05-26 12:15 576000 f:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2906.0\Microsoft.DirectX.Direct3DX.dll
+ 2009-07-20 10:04 . 2005-03-18 14:23 567296 f:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2905.0\Microsoft.DirectX.Direct3DX.dll
+ 2009-07-20 10:04 . 2005-02-05 16:32 563712 f:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2904.0\Microsoft.DirectX.Direct3DX.dll
+ 2009-07-20 10:04 . 2005-03-18 13:23 223232 f:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.dll
+ 2009-07-20 10:04 . 2005-03-18 13:23 178176 f:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectSound.dll
+ 2009-07-20 10:04 . 2005-03-18 13:23 364544 f:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectPlay.dll
+ 2009-07-20 10:04 . 2005-03-18 13:23 159232 f:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectInput.dll
+ 2009-07-20 10:04 . 2005-03-18 13:23 145920 f:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.DirectDraw.dll
+ 2009-07-20 10:04 . 2005-03-18 13:23 473600 f:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Direct3D.dll
+ 2009-07-20 10:04 . 2009-07-20 10:04 223232 f:\windows\assembly\GAC\Microsoft.DirectX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.dll
+ 2009-07-20 10:04 . 2009-07-20 10:04 178176 f:\windows\assembly\GAC\Microsoft.DirectX.DirectSound\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectSound.dll
+ 2009-07-20 10:04 . 2009-07-20 10:04 364544 f:\windows\assembly\GAC\Microsoft.DirectX.DirectPlay\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectPlay.dll
+ 2009-07-20 10:04 . 2009-07-20 10:04 159232 f:\windows\assembly\GAC\Microsoft.DirectX.DirectInput\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectInput.dll
+ 2009-07-20 10:04 . 2009-07-20 10:04 145920 f:\windows\assembly\GAC\Microsoft.DirectX.DirectDraw\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.DirectDraw.dll
+ 2009-07-20 10:04 . 2009-07-20 10:04 578560 f:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2911.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-07-20 10:04 . 2009-07-20 10:04 578560 f:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-07-20 10:04 . 2009-07-20 10:04 577536 f:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-07-20 10:04 . 2009-07-20 10:04 577536 f:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-07-20 10:04 . 2009-07-20 10:04 577024 f:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-07-20 10:04 . 2009-07-20 10:04 576000 f:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-07-20 10:04 . 2009-07-20 10:04 567296 f:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2905.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-07-20 10:04 . 2009-07-20 10:04 563712 f:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2904.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-07-20 10:04 . 2009-07-20 10:04 473600 f:\windows\assembly\GAC\Microsoft.DirectX.Direct3D\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3D.dll
+ 2008-07-23 16:50 . 2008-11-06 16:37 3596288 f:\windows\system32\qt-dx331.dll
- 2008-07-23 16:50 . 2008-07-23 16:50 3596288 f:\windows\system32\qt-dx331.dll
+ 2009-06-26 20:29 . 2004-08-04 12:00 1580544 f:\windows\system32\dllcache\cache\sfcfiles.dll
+ 2009-06-26 20:29 . 2004-08-04 12:00 2148352 f:\windows\system32\dllcache\cache\ntoskrnl.exe
+ 2009-06-26 20:29 . 2004-08-04 12:00 2015232 f:\windows\system32\dllcache\cache\ntkrnlpa.exe
+ 2009-06-26 20:29 . 2004-08-04 12:00 1032192 f:\windows\system32\dllcache\cache\explorer.exe
+ 2009-07-20 10:04 . 2009-03-09 12:27 4178264 f:\windows\system32\D3DX9_41.dll
+ 2009-07-20 10:04 . 2008-10-15 03:22 4379984 f:\windows\system32\D3DX9_40.dll
+ 2009-07-20 10:04 . 2008-07-10 08:00 3851784 f:\windows\system32\D3DX9_39.dll
+ 2009-07-20 10:04 . 2008-05-30 11:11 3850760 f:\windows\system32\D3DX9_38.dll
+ 2009-07-20 10:04 . 2008-03-05 12:56 3786760 f:\windows\system32\D3DX9_37.dll
+ 2009-07-20 10:04 . 2007-10-12 12:14 3734536 f:\windows\system32\d3dx9_36.dll
+ 2009-07-20 10:04 . 2007-07-19 15:14 3727720 f:\windows\system32\d3dx9_35.dll
+ 2009-07-20 10:04 . 2007-05-16 13:45 3497832 f:\windows\system32\d3dx9_34.dll
+ 2009-07-20 10:04 . 2007-03-12 13:42 3495784 f:\windows\system32\d3dx9_33.dll
+ 2009-07-20 10:04 . 2006-11-29 10:06 3426072 f:\windows\system32\d3dx9_32.dll
+ 2009-07-20 10:04 . 2006-09-28 13:05 2414360 f:\windows\system32\d3dx9_31.dll
+ 2009-07-20 10:04 . 2009-03-09 12:27 1846632 f:\windows\system32\D3DCompiler_41.dll
+ 2009-07-20 10:04 . 2008-10-15 03:22 2036576 f:\windows\system32\D3DCompiler_40.dll
+ 2009-07-20 10:04 . 2008-07-10 08:00 1493528 f:\windows\system32\D3DCompiler_39.dll
+ 2009-07-20 10:04 . 2008-05-30 11:11 1491992 f:\windows\system32\D3DCompiler_38.dll
+ 2009-07-20 10:04 . 2008-03-05 12:56 1420824 f:\windows\system32\D3DCompiler_37.dll
+ 2009-07-20 10:04 . 2007-10-12 12:14 1374232 f:\windows\system32\D3DCompiler_36.dll
+ 2009-07-20 10:04 . 2007-07-19 15:14 1358192 f:\windows\system32\D3DCompiler_35.dll
+ 2009-07-20 10:04 . 2007-05-16 13:45 1124720 f:\windows\system32\D3DCompiler_34.dll
+ 2009-07-20 10:04 . 2007-03-12 13:42 1123696 f:\windows\system32\D3DCompiler_33.dll
+ 2009-07-20 10:04 . 2004-12-01 12:53 2846720 f:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2903.0\Microsoft.DirectX.Direct3DX.dll
+ 2009-07-20 10:04 . 2004-09-29 09:38 2676224 f:\windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\Microsoft.DirectX.Direct3DX.dll
+ 2009-07-20 10:04 . 2009-07-20 10:04 2846720 f:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2903.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
+ 2009-07-20 10:04 . 2009-07-20 10:04 2676224 f:\windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2902.0__31bf3856ad364e35\Microsoft.DirectX.Direct3DX.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="f:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"MSMSGS"="f:\program files\Messenger\msmsgs.exe" [2009-06-26 1671715]
"IDMan"="f:\program files\Internet Download Manager\IDMan.exe" [2009-06-26 2893232]
"MsnMsgr"="f:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="f:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"SysTrayApp"="f:\program files\IDT\WDM\sttray.exe" [2008-05-07 413696]
"SecurDisc"="f:\program files\Nero\Nero 7\InCD\NBHGui.exe" [2009-06-26 1701936]
"RemoteControl"="f:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2009-06-26 34333]
"QuickTime Task"="f:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"LanguageShortcut"="f:\program files\CyberLink\PowerDVD\Language\Language.exe" [2009-06-26 53284]
"InCD"="f:\program files\Nero\Nero 7\InCD\InCD.exe" [2009-06-26 1139248]
"GrooveMonitor"="f:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"nwiz"="nwiz.exe" - f:\windows\system32\nwiz.exe [2009-06-26 1626145]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="f:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
f:\documents and settings\user\Start Menu\Programs\Startup\
Adobe Gamma.lnk - f:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-10-23 117790]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"NoConfigPage"= 0 (0x0)
"NoDevMgrPage"= 0 (0x0)
"NoFileSysPage"= 0 (0x0)
"NoVirtMemPage"= 0 (0x0)
[HKLM\~\startupfolder\F:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=f:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=f:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\F:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=f:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=f:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\F:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=f:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=f:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\F:^Documents and Settings^All Users^Start Menu^Programs^Startup^PalTalk.lnk]
path=f:\documents and settings\All Users\Start Menu\Programs\Startup\PalTalk.lnk
backup=f:\windows\pss\PalTalk.lnkCommon Startup
[HKLM\~\startupfolder\F:^Documents and Settings^All Users^Start Menu^Programs^Startup^SnagIt 9.lnk]
path=f:\documents and settings\All Users\Start Menu\Programs\Startup\SnagIt 9.lnk
backup=f:\windows\pss\SnagIt 9.lnkCommon Startup
[HKLM\~\startupfolder\F:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=f:\documents and settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=f:\windows\pss\WinZip Quick Pick.lnkCommon Startup
[HKLM\~\startupfolder\F:^Documents and Settings^user^Start Menu^Programs^Startup^Xfire.lnk]
path=f:\documents and settings\user\Start Menu\Programs\Startup\Xfire.lnk
backup=f:\windows\pss\Xfire.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"f:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"f:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"f:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"f:\\Program Files\\uTorrent\\uTorrent.exe"=
"f:\\Program Files\\Steam\\SteamApps\\wldabumt3b\\counter-strike source\\hl2.exe"=
"f:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"f:\\Program Files\\iTunes\\iTunes.exe"=
"f:\\Program Files\\Electronic Arts\\Battlefield 2142\\BF2142.exe"=
"f:\\Program Files\\Xfire\\xfire.exe"=
"f:\\Documents and Settings\\user\\Application Data\\Thinstall\\CuteFTP 8 Professional\\4000001d000002i\\ftpte.exe"=
"f:\\Program Files\\Internet Download Manager\\IDMan.exe"=
"f:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"f:\\WINDOWS\\system32\\dpvsetup.exe"=
"f:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"f:\\Program Files\\Steam\\Steam.exe"=
"f:\\Program Files\\Skype\\Phone\\Skype.exe"=
"f:\\Program Files\\Nero\\Nero 7\\InCD\\InCD.exe"=
"f:\\Program Files\\Nero\\Nero 7\\InCD\\NBHGui.exe"=
"f:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"f:\\Program Files\\MSN Messenger\\livecall.exe"=
R1 is-KKQ7Kdrv;is-KKQ7Kdrv;f:\windows\system32\drivers\31195849.sys [5/9/2009 11:22 PM 148496]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;f:\windows\system32\drivers\ManyCam.sys [1/14/2008 1:06 PM 21632]
R3 PhTVTune;Philips WDM TV Tuner;f:\windows\system32\drivers\PhTVTune.sys [10/23/2008 10:04 PM 14624]
S3 abp470n5;abp470n5;\??\f:\windows\system32\drivers\mjtgff.sys --> f:\windows\system32\drivers\mjtgff.sys [?]
S3 AVPsys;AVPsys;\??\f:\windows\system32\drivers\cdaudio.sys --> f:\windows\system32\drivers\cdaudio.sys [?]
S3 PAC207;VideoCAM GF112;f:\windows\system32\drivers\PFC027.sys [4/8/2005 10:46 AM 162176]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-TkBellExe - f:\program files\K-Lite Codec Pack\Real\Update_OB\realsched.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = local
IE: Download all links with IDM - f:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - f:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - f:\program files\Internet Download Manager\IEExt.htm
IE: E&xport to Microsoft Excel - f:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java -
DPF: {C171FF59-8C55-4796-A398-4F5D02B4C763} - hxxp://174.36.238.30/saudi1999/talks3n.cab
FF - ProfilePath - f:\documents and settings\user\Application Data\Mozilla\Firefox\Profiles\afzaoj6i.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1959912&SearchSource=3&q=
FF - prefs.js: browser.search.selectedEngine - saleh.alqhtani Customized Web Search
FF - component: f:\documents and settings\user\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
FF - plugin: f:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: f:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: f:\program files\Opera\program\plugins\nppl3260.dll
FF - plugin: f:\program files\Opera\program\plugins\nprpjplug.dll
FF - HiddenExtension: Java Console: No Registry Reference - f:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
.
.
------- File Associations -------
.
txtfile=NOTEPAD %1
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-07-23 18:32
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{49aec333-7c35-4776-a171-c4191373f5d5}]
@Denied: (Full) (Everyone)
"Model"=dword:0000001f
"Therad"=dword:00000011
"MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,98,07,ff,fc,5d,
df,1c,2f,3b,8a,0a,32,11,89,01,b5,ca,af,3f,de,cd,ba,cc,92,e6,c4,b4,85,a7,8b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):c9,d4,b5,10,ec,0d,75,4e,ab,64,5a,a2,df,e5,dd,95,e9,43,74,bc,38,
be,02,d1,8d,6a,d2,2d,c1,e7,df,f4,bd,85,88,1f,26,8b,c0,bc,00,00,00,00,00,00,\
.
Completion time: 2009-07-23 18:34
ComboFix-quarantined-files.txt 2009-07-23 15:34
ComboFix2.txt 2009-07-11 15:08
ComboFix3.txt 2009-06-27 00:23
ComboFix4.txt 2009-06-26 20:31
ComboFix5.txt 2009-07-23 15:29
Pre-Run: 11,344,683,008 bytes free
Post-Run: 11,869,126,656 bytes free
374