Hijackthis, Mbam, Combofix.

Status
Not open for further replies.
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [9/6/2009 3:04 PM 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [9/6/2009 3:04 PM 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [9/6/2009 3:04 PM 108552]
R1 SSHDRV85;SSHDRV85;c:\windows\system32\drivers\SSHDRV85.sys [8/22/2009 5:06 PM 78848]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [9/6/2009 3:04 PM 297752]
R3 HCWBT8XX;Hauppauge WinTV 848/9 WDM Video Driver;c:\windows\system32\drivers\HCWBT8xx.sys [8/15/2008 5:58 PM 472644]
S2 BT848;WinFast TV2000 XP WDM Video Capture;c:\windows\system32\drivers\wf2kvcap.sys [6/1/2005 3:00 PM 76325]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-09-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-492894223-839522115-1004Core.job
- c:\documents and settings\mikey\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-15 08:28]

2009-09-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-492894223-839522115-1004UA.job
- c:\documents and settings\mikey\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-15 08:28]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = localhost;*.local
IE: &Download FLV by WinAVI... - c:\program files\WinAVI FLV Converter\flv_link.htm
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\mikey\Application Data\Mozilla\Firefox\Profiles\nmqqiwva.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?source=gghp
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\mikey\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover
Rootkit scan 2009-09-09 14:28
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLBTCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG10.00.00.01WORKSTATION"="2419F1EF15EF5577CC503FA81D791F06EF1868F77F7133C7E193A7B8EFFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A2D97226D213B555FEBC9E127BECC74CC038D530D6EB3452488F85555B05B435FE9EF0B48FD2E0E6DF469B4E709BF6E0AF57B89031C0C166ADFB0906C24B2B3045B64D101DF711737AFCFC3360576472BFDED77148F9A02083B742326B3314D09E7AEDBE4B63EDFD8A86584EB459A498EB8D191CEE3EACEBE6897B16C0177E0E4FC26C96BCD062E4166B372C62DE9F391E3E1076116C6B564A3BF592C316AA3DEB6BD50F27BF0F69F9B6917E7669739F98CD440DADA593D5729C63A98795111E61D2AA46D2F447B065FA551D8C3D6FFA709EAF8D57D015407A7F6E843539DC4FEC5DE07C1D7892C45C4B667FD86419DA8D15C1C9361811CFCE3BB26F096FE95422736016F7172D91374198C5A0AC27B7AC9CDD3B0769DC26B1AA3E5853E5CC97E7FE061DE7DF8469207837303EA587ECDE22DA7B16F702C5B92B17D5F78E4B64F8F1A33E8728BD03181380A5A0A5DBB50A960349C7B7BD16CE21351E6FA2E06BE23E7EC9030831F4F2B526AFC84475B76470168794E4826231F0038CC61DBAC08A5B4FB41B59E73F58874DFA4DE0DFF67DA847BD067CF3D9708762A29CBB3C5D25464398A63F2341443510DBD99AD6DFB4BDBD16BD416D90F353A583A602FA1EBDFDFA318D9C57C185F17E47ABD749BF3E3014DF6CB8FCFD744517772DB8434133068BE04E99296A40EE995615425DC7A307D80EDAAD627C7F54F0698A6812EC38657D2CF8227647ECE7D5C7FB456B9042CA9038E2AD93CBF87CE26A31631A2954A94FBA33E6CDCA57181FFCDB9300144A0AB097F58BB990143C12ADA53AC2E26161F05A375BF34A9E3FD2FBC1A05BAFC056258B955D3450DB15960BFD44A5690E1F47FCD038DE7E3623C2EED0A7F1A6FCC4CC98D9FC9278AD0FFB7E671E12725EFBAC3562793A05670D35A4BD24EB9EAE6FF963ED881BD53C33C2A9A3A60A9527926C3EE05FE55FCC48648CD4582723D3F2F43911E1C79E0C91DD4D067F444E160448F2D4EEF5F256A5FE3E73C733A141F2F7061630C5E878BC3654F5912BFEA67376565D6EB189C67BA4F38BBD556D2292B1DF655D752F2D4AA8C77086DDEAAD871E0C2A6B155038A06D8AA44704BBF1FD45FBF896ED52AD55825A064FADBAD1ECDCDC80354D5994F1E305D7B36E2701E14B35E0CD7895CEFD8A5DD91D22FA8D524335BAE0C0189CD08387D399F3AF74EE4D8AC0BA129F3A6477CA2668749BAFECD7A7C5450668E321C0DD5AD028B5455CCA1F4ED66D7C6F3176BD356C95F05A739368A100678552CC0075C27855014062B6B9D6DFEE1BBD8D26756827A5B305A1E1CFE5F06692A3BE1D"
"OOCC06.00.00.01WSSV"="B9398204046D65564D2E89E88310EAE09DB3578CD5AB94715C762E731CBD27DD850F8E2CF032BD578E7FCE187A9F7AC4DF3F77534E9A10A5A1D4F61A271C1E8CDA7E9D4C6AF055225AEE717978BBF1BDF4185181D489050A93825D421CF389BE0BB93F54C150D2634E48B75C2E77BEA7E7C17E689794C1CB4659715DC3083F12D8929AF600DCB0497CF67AD5FE469F6437E1AC1EF6B66C1CC75A56A29B80E829FC0366ACDC07BE89678B27BD0283A858D3C020F906D5FCB114A7C20DD46803AAA326EDAFC8239DDA8B3BBDB083E9C1EA24CEAC9A8E35C0C4210881D8D52FE0426CBA927E65FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A2D97226D213B555A6A0AC4980AC7933A9C6AECB7A5D14077BA9F00DFCCDF309742D6E20C31D2A464C032C12979CE6F82BDBAA3FD3615CB3F2498D25BE5A072FE0D955C1F109F190400320BD549802FAAD5509E8A3BB5376E787850991DCAE25B6CE63F26D9E7E43D589C7FA5D2CE303FE314E2E295A53A9F829A9E0169B4206BA57D90A4FB6E5BA1B0575EEE4E206CA192300A1CD9F520129C74FCD0D6B5A261A0D01D3533E848507B981B1BDDEA33C59332749208110E55D4FD063DE39558AE266220F5834F8E36F3DC7D1E255BDF7013ECE9ED18A0CF461010B261502D76A8AA68CF1E2AEA54F92F92750EE8E985135728911B7578B7E64F16013E0DB4536E56792231CD333F010AF8420256A3B4F8053E900CC1C1887F50AB61A136C480EB2178CBE4D610BA6EBF0C52C6957F2AE4E3A0AC3AF9E00C68E06F51B226FCFC70FF75255E8A75D048F25D7D044DB4FDC71D18526A039522B09780E6F2BB30EECFE1F446A808A1ECE4706A9DF6291247F209A7EE30659E554A1C36F61EB9DF7BA69F645F54E8182034323AF9D95250AEDF0E719306A8352957D22103147A348A399BBBAE42D9A864D17DD60C2D2D75D3164E17DB0FA4BF5792020699044D0FECABF0190169C7469113CED39FC32003E0C59845800895C71BB769DF8268DC4DA8C6EAB35DDBF442F648FDEB86DF10590F0971E5AAB0DF42ACBCC50C08D72B2E4751EF59A84E0519D13CF8E622871E57B854753B7359E674A4FD7C146D66662E5C6A8ED37466AF9419AA1303E38B532EDA7759D2B937C98BC9EAC4D93837EAEEBF54E7386D2EC2C67AC8EC9D797689115661345EE2F0805334745A3B50B7606C92C333E874F1B6DA43203B6BE3AD6BA6705776DC4E84839250801CABD59AEED95C8DC57BBD14FD550C3CDA58604EFFD9BFADA88F08F65D8C8D5219BC24CA77B29DA399DAA6782128430A51A47CC4BB9AD735ADD3DEBAE999D594DC0DD388ADA23A91541DD8F55E1A1FAA0E99CE31FE35ECDF809F4361546E2EF0F3DACE19FCB642EA5C9E5"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(748)
c:\windows\system32\Ati2evxx.dll
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll
.
Completion time: 2009-09-09 14:33
ComboFix-quarantined-files.txt 2009-09-09 19:32

Pre-Run: 35,132,518,400 bytes free
Post-Run: 35,091,484,672 bytes free

279 --- E O F --- 2009-09-01 21:00
 
ok and one more time, combofix. I seen that it deleted another nasty file, this is good. The run malwarebytes as well
 
Oh man, the MBAM takes over three hours. I'll get it done tho.

May I ask? How the **** you know what to look for?...lol
 
Cuz I've done it a million times :D
Just let her run, hopefully it will find something that needs to be removed. I ran it on my server 3 days ago, took 16 hours so a few hours wont hurt ya ;)
 
****, 16 hours. OK, well here's the combo fix log.

ComboFix 09-09-09.01 - mikey 09/09/2009 20:37.3.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.629 [GMT -5:00]
Running from: c:\documents and settings\mikey\Desktop\ComboFix.exe
AV: AVG Anti-Virus *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
/wow section - STAGE 32A


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

O:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2009-08-10 to 2009-09-10 )))))))))))))))))))))))))))))))
.

2009-09-09 21:28 . 2009-09-09 21:28 -------- d-----w- c:\windows\LastGood
2009-09-09 20:00 . 2009-06-21 21:44 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2009-09-09 03:27 . 2005-08-26 06:50 77312 ----a-w- c:\windows\system32\ztvunace26.dll
2009-09-09 03:27 . 2006-06-19 18:01 69632 ----a-w- c:\windows\system32\ztvcabinet.dll
2009-09-09 03:27 . 2006-05-25 20:52 162304 ----a-w- c:\windows\system32\ztvunrar36.dll
2009-09-09 03:27 . 2003-02-03 01:06 153088 ----a-w- c:\windows\system32\UNRAR3.dll
2009-09-09 03:27 . 2002-03-06 06:00 75264 ----a-w- c:\windows\system32\unacev2.dll
2009-09-09 03:27 . 2009-09-09 03:27 -------- d-----w- c:\program files\Trojan Remover
2009-09-09 03:27 . 2009-09-09 03:27 -------- d-----w- c:\documents and settings\mikey\Application Data\Simply Super Software
2009-09-09 03:27 . 2009-09-09 03:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Simply Super Software
2009-09-09 00:03 . 2009-09-09 00:03 -------- d-----w- c:\documents and settings\mikey\Application Data\Malwarebytes
2009-09-09 00:03 . 2009-08-03 18:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-09 00:03 . 2009-09-09 00:03 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-09 00:03 . 2009-09-09 00:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-09 00:03 . 2009-08-03 18:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-08 23:50 . 2009-09-08 23:57 -------- d-----w- c:\documents and settings\mikey\SmitfraudFix
2009-09-08 23:47 . 2009-09-08 23:47 -------- d-----w- c:\program files\Trend Micro
2009-09-08 23:32 . 2009-09-08 23:32 -------- d-sh--w- c:\documents and settings\mikey\IECompatCache
2009-09-08 23:27 . 2009-09-08 23:28 -------- d-----w- c:\program files\CleanUp!
2009-09-08 23:17 . 2009-09-08 23:17 -------- d-----w- c:\program files\MSConfig CleanUp
2009-09-07 21:45 . 2009-09-07 21:45 -------- d-----w- c:\documents and settings\mikey\Local Settings\Application Data\Ascaron Entertainment
2009-09-07 21:35 . 2009-09-07 21:35 -------- d-----w- c:\program files\cdv USA
2009-09-06 20:50 . 2009-09-09 00:08 -------- d-----w- C:\$AVG8.VAULT$
2009-09-06 20:04 . 2009-09-07 20:27 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-09-06 20:04 . 2009-09-06 20:04 12552 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2009-09-06 20:04 . 2009-09-06 20:04 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-09-06 20:04 . 2009-09-07 20:27 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-09-06 20:04 . 2009-09-07 20:27 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-09-06 20:04 . 2009-09-09 21:30 -------- d-----w- c:\windows\system32\drivers\Avg
2009-08-23 22:58 . 2009-08-23 22:59 -------- d-----w- c:\documents and settings\mikey\EurekaLog
2009-08-23 03:14 . 2009-08-23 03:15 -------- d-----w- c:\documents and settings\mikey\Local Settings\Application Data\Movie Magic Screenwriter
2009-08-23 03:14 . 2009-08-23 03:14 -------- d-----w- c:\program files\Write Brothers, Inc
2009-08-23 03:13 . 2009-08-23 03:13 -------- d-----w- c:\windows\Downloaded Installations
2009-08-22 22:06 . 2009-08-22 22:06 78848 ----a-w- c:\windows\system32\drivers\SSHDRV85.sys
2009-08-21 04:44 . 2009-08-21 04:46 -------- d-----w- C:\DeusEx
2009-08-21 03:32 . 2009-08-21 03:32 -------- d-----w- c:\documents and settings\mikey\Application Data\GetRightToGo
2009-08-21 01:54 . 2009-08-21 01:57 -------- d-----w- c:\program files\Attack on Pearl Harbor
2009-08-20 20:16 . 2009-08-20 20:16 -------- d-----w- c:\program files\Ascaron Entertainment
2009-08-20 05:01 . 2009-08-20 05:02 -------- d-----w- c:\windows\Logs
2009-08-20 05:01 . 2009-09-07 21:38 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2009-08-20 05:01 . 2009-09-07 21:38 110592 ----a-w- c:\windows\system32\OpenAL32.dll
2009-08-18 02:17 . 2009-08-18 02:17 -------- d-----w- c:\program files\Ubisoft
2009-08-17 21:18 . 2009-08-17 21:18 451072 ----a-w- c:\windows\uninstall\Ultima7.exe
2009-08-17 21:18 . 2009-08-17 21:18 451072 ----a-w- c:\windows\uninstall\Ultima6.exe
2009-08-17 21:17 . 2009-08-17 21:17 451072 ----a-w- c:\windows\uninstall\Ultima5.exe
2009-08-17 21:17 . 2009-08-17 21:17 451072 ----a-w- c:\windows\uninstall\Ultima4.exe
2009-08-17 21:16 . 2009-08-17 21:16 451072 ----a-w- c:\windows\uninstall\Ultima3.exe
2009-08-17 21:16 . 2009-08-17 21:16 451072 ----a-w- c:\windows\uninstall\Ultima2.exe
2009-08-17 21:16 . 2009-08-17 21:16 451072 ----a-w- c:\windows\uninstall\Ultima1.exe
2009-08-17 21:15 . 2009-08-17 21:18 -------- d-----w- c:\windows\Uninstall
2009-08-17 21:15 . 2009-08-17 21:18 -------- d-----w- c:\program files\Origin Systems
2009-08-17 21:15 . 2009-08-17 21:15 451072 ----a-w- c:\windows\uninstall\Akalabeth.exe
2009-08-12 23:05 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2009-08-12 20:31 . 2009-08-12 20:31 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE
2009-08-12 20:30 . 2009-08-12 20:30 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2009-08-12 06:20 . 2009-08-12 22:02 -------- d-----w- c:\program files\FS2ATC
2009-08-12 04:32 . 2009-08-12 06:30 353 ----a-w- C:\temp.reg
2009-08-12 04:29 . 2009-08-12 06:20 249856 ------w- c:\windows\Setup1.exe
2009-08-12 04:29 . 2009-08-12 04:29 73216 ------w- c:\windows\ST6UNST.EXE
2009-08-12 04:29 . 2008-04-14 00:12 343040 ----a-w- c:\windows\system32\msvcrt.dll
2009-08-12 04:28 . 2008-04-14 00:12 57344 ----a-w- c:\windows\system32\msvcirt.dll
2009-08-12 04:28 . 2001-11-05 19:35 565760 ----a-w- c:\windows\system32\msvcp50.dll
2009-08-12 04:28 . 2009-08-12 04:28 -------- d-----w- c:\windows\lhsp

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
 
2009-09-10 01:32 . 2008-01-05 03:47 -------- d-----w- c:\documents and settings\mikey\Application Data\uTorrent
2009-09-09 21:31 . 2008-02-02 01:49 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-09 03:38 . 2008-02-25 01:33 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-08 23:34 . 2008-01-06 04:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-09-08 23:08 . 2008-01-04 22:03 69464 -c--a-w- c:\documents and settings\mikey\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-07 21:32 . 2008-01-07 02:25 -------- d-----w- c:\program files\AGEIA Technologies
2009-09-06 20:04 . 2009-05-28 09:13 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-09-06 19:49 . 2008-01-05 00:17 -------- d-----w- c:\program files\RegVac Registry Cleaner
2009-08-22 19:28 . 2008-01-18 03:12 -------- d-----w- c:\program files\Microsoft Games
2009-08-20 04:53 . 2008-01-04 23:09 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-08-19 19:49 . 2008-01-13 18:40 -------- d-----w- c:\documents and settings\mikey\Application Data\dvdcss
2009-08-17 22:04 . 2009-05-30 07:10 -------- d-----w- c:\program files\Return to Castle Wolfenstein
2009-08-12 20:49 . 2009-06-05 04:59 -------- d-----w- c:\documents and settings\mikey\Application Data\Lavasoft
2009-08-10 02:02 . 2008-01-06 04:30 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-08 22:15 . 2009-08-08 22:15 -------- d-----w- c:\program files\MSBuild
2009-08-08 22:14 . 2009-08-08 22:14 -------- d-----w- c:\program files\Reference Assemblies
2009-08-05 09:01 . 2008-01-04 21:32 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-02 20:24 . 2009-08-02 20:24 -------- d-----w- c:\program files\Test My Hardware
2009-08-02 07:57 . 2009-08-02 07:57 -------- d-----w- c:\documents and settings\All Users\Application Data\InstallShield
2009-08-02 07:56 . 2009-08-02 07:56 -------- d-----w- c:\documents and settings\mikey\Application Data\Nuance
2009-08-02 07:49 . 2009-08-02 07:49 -------- d-----w- c:\program files\Common Files\ScanSoft Shared
2009-08-02 07:49 . 2009-08-02 07:49 -------- d-----w- c:\documents and settings\All Users\Application Data\ScanSoft
2009-08-02 07:49 . 2008-01-04 21:05 -------- d-----w- c:\program files\Common Files\InstallShield
2009-08-02 07:49 . 2009-08-02 07:49 -------- d-----w- c:\program files\Common Files\Nuance
2009-08-02 07:48 . 2009-08-02 07:48 -------- d-----w- c:\program files\Nuance
2009-08-02 07:48 . 2009-08-02 07:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Nuance
2009-08-02 00:42 . 2009-08-02 00:42 -------- d-----w- c:\program files\The Adventure Company
2009-07-31 23:19 . 2009-05-17 22:31 -------- d-----w- c:\program files\Mafia
2009-07-31 23:18 . 2009-02-05 01:08 -------- d-----w- c:\program files\Diablo II
2009-07-31 23:16 . 2008-01-04 21:05 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-29 02:33 . 2009-07-29 02:24 -------- d-----w- c:\program files\Pocket Tanks Deluxe
2009-07-28 00:49 . 2008-01-04 22:57 -------- d-----w- c:\documents and settings\mikey\Application Data\U3
2009-07-27 23:57 . 2009-07-27 23:56 -------- d-----w- c:\program files\Escape Rosecliff Island
2009-07-27 18:16 . 2009-07-27 18:16 -------- d-----w- c:\program files\Activision Value
2009-07-26 01:47 . 2008-01-29 04:47 -------- d-----w- c:\documents and settings\mikey\Application Data\LimeWire
2009-07-25 00:26 . 2008-01-08 17:08 -------- d-----w- c:\program files\SystemRequirementsLab
2009-07-25 00:20 . 2008-01-08 17:08 -------- d-----w- c:\documents and settings\mikey\Application Data\SystemRequirementsLab
2009-07-17 19:01 . 2001-11-05 19:33 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 04:43 . 2004-08-04 07:56 286208 ------w- c:\windows\system32\wmpdxm.dll
2009-07-12 09:46 . 2009-07-12 09:46 25 ----a-w- c:\windows\popcinfot.dat
2009-07-12 09:06 . 2009-07-12 09:06 -------- d-----w- c:\documents and settings\All Users\Application Data\PopCap Games
2009-07-12 08:10 . 2009-07-12 08:10 -------- d-----w- c:\program files\PopCap Games
2009-07-03 17:09 . 2001-11-05 19:35 915456 ------w- c:\windows\system32\wininet.dll
2009-06-21 05:40 . 2009-06-21 05:40 166097 ----a-w- c:\windows\Video Cleaner Pro Uninstaller.exe
2009-06-16 14:36 . 2001-11-05 19:35 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2001-11-05 19:34 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-12 12:31 . 2001-11-05 19:35 80896 ----a-w- c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2001-11-05 19:35 76288 ----a-w- c:\windows\system32\telnet.exe
.

((((((((((((((((((((((((((((( SnapShot@2009-09-09_04.23.01 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-09-09 21:23 . 2009-09-09 21:23 16384 c:\windows\Temp\Perflib_Perfdata_2b8.dat
- 2008-01-05 01:44 . 2009-08-13 21:31 23040 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2008-01-05 01:44 . 2009-09-09 21:32 23040 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2008-01-05 01:44 . 2009-09-09 21:32 61440 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2008-01-05 01:44 . 2009-08-13 21:31 61440 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2008-01-05 01:44 . 2009-09-09 21:32 27136 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2008-01-05 01:44 . 2009-08-13 21:31 27136 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2008-01-05 01:44 . 2009-08-13 21:31 11264 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2008-01-05 01:44 . 2009-09-09 21:32 11264 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2008-01-05 01:44 . 2009-08-13 21:31 86016 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2008-01-05 01:44 . 2009-09-09 21:32 86016 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2008-01-05 01:44 . 2009-08-13 21:31 12288 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2008-01-05 01:44 . 2009-09-09 21:32 12288 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2008-01-05 01:44 . 2009-09-09 21:32 4096 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2008-01-05 01:44 . 2009-08-13 21:31 4096 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2003-01-13 19:57 . 2009-06-22 06:44 726528 c:\windows\system32\jscript.dll
- 2003-01-13 19:57 . 2009-03-08 09:33 726528 c:\windows\system32\jscript.dll
- 2008-05-09 10:53 . 2009-03-08 09:33 726528 c:\windows\system32\dllcache\jscript.dll
+ 2008-05-09 10:53 . 2009-06-22 06:44 726528 c:\windows\system32\dllcache\jscript.dll
- 2008-01-05 01:44 . 2009-08-13 21:31 409600 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2008-01-05 01:44 . 2009-09-09 21:32 409600 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2008-01-05 01:44 . 2009-09-09 21:32 286720 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2008-01-05 01:44 . 2009-08-13 21:31 286720 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2008-01-05 01:44 . 2009-08-13 21:31 249856 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2008-01-05 01:44 . 2009-09-09 21:32 249856 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2008-01-05 01:44 . 2009-09-09 21:32 794624 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2008-01-05 01:44 . 2009-08-13 21:31 794624 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2008-01-05 01:44 . 2009-09-09 21:32 135168 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2008-01-05 01:44 . 2009-08-13 21:31 135168 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2008-01-05 01:44 . 2009-08-13 21:31 593920 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2008-01-05 01:44 . 2009-09-09 21:32 593920 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2009-09-09 21:30 . 2008-07-08 13:02 382840 c:\windows\ie8updates\KB971961-IE8\spuninst\updspapi.dll
+ 2009-09-09 21:30 . 2008-07-08 13:02 231288 c:\windows\ie8updates\KB971961-IE8\spuninst\spuninst.exe
+ 2009-09-09 21:30 . 2009-03-08 09:33 726528 c:\windows\ie8updates\KB971961-IE8\jscript.dll
- 2001-11-05 19:36 . 2008-06-18 10:03 2458112 c:\windows\system32\WMVCore.dll
+ 2001-11-05 19:36 . 2009-05-20 09:56 2458112 c:\windows\system32\WMVCore.dll
+ 2001-11-05 19:36 . 2009-05-20 09:56 2458112 c:\windows\system32\dllcache\WMVCore.dll
- 2001-11-05 19:36 . 2008-06-18 10:03 2458112 c:\windows\system32\dllcache\WMVCore.dll
+ 2009-08-25 19:57 . 2009-08-25 19:57 5518336 c:\windows\Installer\7e76c.msp
+ 2008-01-04 21:39 . 2009-08-28 21:38 24689600 c:\windows\system32\MRT.exe
+ 2009-09-09 21:30 . 2009-09-09 21:30 15709696 c:\windows\Installer\7e757.msp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
 
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DLBTCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll" [2004-11-09 69632]
"DNS7reminder"="c:\program files\Nuance\NaturallySpeaking10\Ereg\Ereg.exe" [2007-04-16 259624]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-09-07 2007832]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 07:42 72208 ----a-w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-09-07 20:27 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck lsdelete\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS\0autocheck OODBS

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\dlbtcoms.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\DLBTPSWX.EXE"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
"c:\\Program Files\\EA Sports\\MVP Baseball 2005\\mvp2005.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\IEPro\\MiniDM.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\River Past\\Video Cleaner Pro\\VideoCleanerPro.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\cdv USA\\Sacred 2 - Demo\\system\\s2gs.exe"=
"c:\\Program Files\\cdv USA\\Sacred 2 - Demo\\system\\sacred2.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26212:TCP"= 26212:TCP:BitComet 26212 TCP
"26212:UDP"= 26212:UDP:BitComet 26212 UDP
"135:TCP"= 135:TCP:TCP Port 135
"5000:TCP"= 5000:TCP:TCP Port 5000
"5001:TCP"= 5001:TCP:TCP Port 5001
"5002:TCP"= 5002:TCP:TCP Port 5002
"5003:TCP"= 5003:TCP:TCP Port 5003
"5004:TCP"= 5004:TCP:TCP Port 5004
"5005:TCP"= 5005:TCP:TCP Port 5005
"5006:TCP"= 5006:TCP:TCP Port 5006
"5007:TCP"= 5007:TCP:TCP Port 5007
"5008:TCP"= 5008:TCP:TCP Port 5008
"5009:TCP"= 5009:TCP:TCP Port 5009
"5010:TCP"= 5010:TCP:TCP Port 5010
"5011:TCP"= 5011:TCP:TCP Port 5011
"5012:TCP"= 5012:TCP:TCP Port 5012
"5013:TCP"= 5013:TCP:TCP Port 5013
"5014:TCP"= 5014:TCP:TCP Port 5014
"5015:TCP"= 5015:TCP:TCP Port 5015
"5016:TCP"= 5016:TCP:TCP Port 5016
"5017:TCP"= 5017:TCP:TCP Port 5017
"5018:TCP"= 5018:TCP:TCP Port 5018
"5019:TCP"= 5019:TCP:TCP Port 5019
"5020:TCP"= 5020:TCP:TCP Port 5020

R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [9/6/2009 3:04 PM 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [9/6/2009 3:04 PM 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [9/6/2009 3:04 PM 108552]
R1 SSHDRV85;SSHDRV85;c:\windows\system32\drivers\SSHDRV85.sys [8/22/2009 5:06 PM 78848]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [9/6/2009 3:04 PM 297752]
R3 HCWBT8XX;Hauppauge WinTV 848/9 WDM Video Driver;c:\windows\system32\drivers\HCWBT8xx.sys [8/15/2008 5:58 PM 472644]
S2 BT848;WinFast TV2000 XP WDM Video Capture;c:\windows\system32\drivers\wf2kvcap.sys [6/1/2005 3:00 PM 76325]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-09-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-492894223-839522115-1004Core.job
- c:\documents and settings\mikey\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-15 08:28]

2009-09-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2052111302-492894223-839522115-1004UA.job
- c:\documents and settings\mikey\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-15 08:28]
.
.
------- Supplementary Scan -------
.
 
uStart Page = about:blank
uInternet Settings,ProxyOverride = localhost;*.local
IE: &Download FLV by WinAVI... - c:\program files\WinAVI FLV Converter\flv_link.htm
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\mikey\Application Data\Mozilla\Firefox\Profiles\nmqqiwva.default\
FF - prefs.js: browser.search.selectedEngine - Amazon.com
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?source=gghp
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\mikey\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover
Rootkit scan 2009-09-09 20:54
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLBTCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG10.00.00.01WORKSTATION"="2419F1EF15EF5577CC503FA81D791F06EF1868F77F7133C7E193A7B8EFFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A2D97226D213B555FEBC9E127BECC74CC038D530D6EB3452488F85555B05B435FE9EF0B48FD2E0E6DF469B4E709BF6E0AF57B89031C0C166ADFB0906C24B2B3045B64D101DF711737AFCFC3360576472BFDED77148F9A02083B742326B3314D09E7AEDBE4B63EDFD8A86584EB459A498EB8D191CEE3EACEBE6897B16C0177E0E4FC26C96BCD062E4166B372C62DE9F391E3E1076116C6B564A3BF592C316AA3DEB6BD50F27BF0F69F9B6917E7669739F98CD440DADA593D5729C63A98795111E61D2AA46D2F447B065FA551D8C3D6FFA709EAF8D57D015407A7F6E843539DC4FEC5DE07C1D7892C45C4B667FD86419DA8D15C1C9361811CFCE3BB26F096FE95422736016F7172D91374198C5A0AC27B7AC9CDD3B0769DC26B1AA3E5853E5CC97E7FE061DE7DF8469207837303EA587ECDE22DA7B16F702C5B92B17D5F78E4B64F8F1A33E8728BD03181380A5A0A5DBB50A960349C7B7BD16CE21351E6FA2E06BE23E7EC9030831F4F2B526AFC84475B76470168794E4826231F0038CC61DBAC08A5B4FB41B59E73F58874DFA4DE0DFF67DA847BD067CF3D9708762A29CBB3C5D25464398A63F2341443510DBD99AD6DFB4BDBD16BD416D90F353A583A602FA1EBDFDFA318D9C57C185F17E47ABD749BF3E3014DF6CB8FCFD744517772DB8434133068BE04E99296A40EE995615425DC7A307D80EDAAD627C7F54F0698A6812EC38657D2CF8227647ECE7D5C7FB456B9042CA9038E2AD93CBF87CE26A31631A2954A94FBA33E6CDCA57181FFCDB9300144A0AB097F58BB990143C12ADA53AC2E26161F05A375BF34A9E3FD2FBC1A05BAFC056258B955D3450DB15960BFD44A5690E1F47FCD038DE7E3623C2EED0A7F1A6FCC4CC98D9FC9278AD0FFB7E671E12725EFBAC3562793A05670D35A4BD24EB9EAE6FF963ED881BD53C33C2A9A3A60A9527926C3EE05FE55FCC48648CD4582723D3F2F43911E1C79E0C91DD4D067F444E160448F2D4EEF5F256A5FE3E73C733A141F2F7061630C5E878BC3654F5912BFEA67376565D6EB189C67BA4F38BBD556D2292B1DF655D752F2D4AA8C77086DDEAAD871E0C2A6B155038A06D8AA44704BBF1FD45FBF896ED52AD55825A064FADBAD1ECDCDC80354D5994F1E305D7B36E2701E14B35E0CD7895CEFD8A5DD91D22FA8D524335BAE0C0189CD08387D399F3AF74EE4D8AC0BA129F3A6477CA2668749BAFECD7A7C5450668E321C0DD5AD028B5455CCA1F4ED66D7C6F3176BD356C95F05A739368A100678552CC0075C27855014062B6B9D6DFEE1BBD8D26756827A5B305A1E1CFE5F06692A3BE1D"
"OOCC06.00.00.01WSSV"="B9398204046D65564D2E89E88310EAE09DB3578CD5AB94715C762E731CBD27DD850F8E2CF032BD578E7FCE187A9F7AC4DF3F77534E9A10A5A1D4F61A271C1E8CDA7E9D4C6AF055225AEE717978BBF1BDF4185181D489050A93825D421CF389BE0BB93F54C150D2634E48B75C2E77BEA7E7C17E689794C1CB4659715DC3083F12D8929AF600DCB0497CF67AD5FE469F6437E1AC1EF6B66C1CC75A56A29B80E829FC0366ACDC07BE89678B27BD0283A858D3C020F906D5FCB114A7C20DD46803AAA326EDAFC8239DDA8B3BBDB083E9C1EA24CEAC9A8E35C0C4210881D8D52FE0426CBA927E65FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A2D97226D213B555A6A0AC4980AC7933A9C6AECB7A5D14077BA9F00DFCCDF309742D6E20C31D2A464C032C12979CE6F82BDBAA3FD3615CB3F2498D25BE5A072FE0D955C1F109F190400320BD549802FAAD5509E8A3BB5376E787850991DCAE25B6CE63F26D9E7E43D589C7FA5D2CE303FE314E2E295A53A9F829A9E0169B4206BA57D90A4FB6E5BA1B0575EEE4E206CA192300A1CD9F520129C74FCD0D6B5A261A0D01D3533E848507B981B1BDDEA33C59332749208110E55D4FD063DE39558AE266220F5834F8E36F3DC7D1E255BDF7013ECE9ED18A0CF461010B261502D76A8AA68CF1E2AEA54F92F92750EE8E985135728911B7578B7E64F16013E0DB4536E56792231CD333F010AF8420256A3B4F8053E900CC1C1887F50AB61A136C480EB2178CBE4D610BA6EBF0C52C6957F2AE4E3A0AC3AF9E00C68E06F51B226FCFC70FF75255E8A75D048F25D7D044DB4FDC71D18526A039522B09780E6F2BB30EECFE1F446A808A1ECE4706A9DF6291247F209A7EE30659E554A1C36F61EB9DF7BA69F645F54E8182034323AF9D95250AEDF0E719306A8352957D22103147A348A399BBBAE42D9A864D17DD60C2D2D75D3164E17DB0FA4BF5792020699044D0FECABF0190169C7469113CED39FC32003E0C59845800895C71BB769DF8268DC4DA8C6EAB35DDBF442F648FDEB86DF10590F0971E5AAB0DF42ACBCC50C08D72B2E4751EF59A84E0519D13CF8E622871E57B854753B7359E674A4FD7C146D66662E5C6A8ED37466AF9419AA1303E38B532EDA7759D2B937C98BC9EAC4D93837EAEEBF54E7386D2EC2C67AC8EC9D797689115661345EE2F0805334745A3B50B7606C92C333E874F1B6DA43203B6BE3AD6BA6705776DC4E84839250801CABD59AEED95C8DC57BBD14FD550C3CDA58604EFFD9BFADA88F08F65D8C8D5219BC24CA77B29DA399DAA6782128430A51A47CC4BB9AD735ADD3DEBAE999D594DC0DD388ADA23A91541DD8F55E1A1FAA0E99CE31FE35ECDF809F4361546E2EF0F3DACE19FCB642EA5C9E5"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(756)
c:\windows\system32\Ati2evxx.dll
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll
.
Completion time: 2009-09-10 20:59
ComboFix-quarantined-files.txt 2009-09-10 01:57
ComboFix2.txt 2009-09-09 19:33

Pre-Run: 34,884,210,688 bytes free
Post-Run: 34,849,406,976 bytes free

310 --- E O F --- 2009-09-09 21:43
 
Would you happen to have system restore on? If so disable it. The autorun entry is back again and it might be coming from system restore.
 
I did turn it off yesterday before I did the scan. I just checked now and it's restored again, don't know how. So, do another scan with it disabled?
 
Status
Not open for further replies.
Back
Top Bottom