ComboFix 10-01-04.01 - Nemesis 05.01.2010 12:01:39.4.1 - x86
Systém Microsoft Windows XP Home Edition 5.1.2600.3.1250.421.1033.18.767.489 [GMT 1:00]
Running from: c:\documents and settings\Nemesis\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Nemesis\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1368 [VPS 100105-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FILE ::
"c:\windows\system32\GameMon.des"
"c:\windows\system32\XDva120.sys"
"c:\windows\system32\XDva221.sys"
"c:\windows\system32\XDva297.sys"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\GameMon.des
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_AKAMAI
-------\Legacy_XDVA120
-------\Legacy_XDVA221
-------\Legacy_XDVA281
-------\Legacy_XDVA297
-------\Service_Akamai
-------\Service_npggsvc
-------\Service_npkycryp
-------\Service_XDva120
-------\Service_XDva221
-------\Service_XDva281
-------\Service_XDva297
((((((((((((((((((((((((( Files Created from 2009-12-05 to 2010-01-05 )))))))))))))))))))))))))))))))
.
2010-01-04 16:46 . 2010-01-04 16:52 -------- d-----w- c:\documents and settings\Nemesis\Local Settings\Application Data\ApplicationHistory
2010-01-04 16:46 . 2010-01-04 16:46 130 ----a-w- c:\documents and settings\Nemesis\Local Settings\Application Data\fusioncache.dat
2010-01-04 16:45 . 2010-01-04 16:45 32630 ----a-r- c:\documents and settings\Nemesis\Application Data\Microsoft\Installer\{44966527-AC8E-4C4F-82CE-2E311B68F2C3}\_f3e99.exe
2010-01-04 16:45 . 2010-01-04 16:45 32630 ----a-r- c:\documents and settings\Nemesis\Application Data\Microsoft\Installer\{44966527-AC8E-4C4F-82CE-2E311B68F2C3}\_bb32ea6.exe
2010-01-04 16:45 . 2010-01-04 16:45 32630 ----a-r- c:\documents and settings\Nemesis\Application Data\Microsoft\Installer\{44966527-AC8E-4C4F-82CE-2E311B68F2C3}\_26e91eb.exe
2010-01-04 16:45 . 2010-01-04 16:45 32630 ----a-r- c:\documents and settings\Nemesis\Application Data\Microsoft\Installer\{44966527-AC8E-4C4F-82CE-2E311B68F2C3}\_12db153c.exe
2010-01-04 16:45 . 2010-01-04 16:45 12542 ----a-r- c:\documents and settings\Nemesis\Application Data\Microsoft\Installer\{44966527-AC8E-4C4F-82CE-2E311B68F2C3}\_7e87390c.exe
2010-01-04 16:45 . 2010-01-04 16:45 12542 ----a-r- c:\documents and settings\Nemesis\Application Data\Microsoft\Installer\{44966527-AC8E-4C4F-82CE-2E311B68F2C3}\_440d491c.exe
2010-01-04 16:45 . 2010-01-04 16:45 12542 ----a-r- c:\documents and settings\Nemesis\Application Data\Microsoft\Installer\{44966527-AC8E-4C4F-82CE-2E311B68F2C3}\_124305e.exe
2010-01-04 16:45 . 2010-01-04 16:45 -------- d-----w- c:\program files\GEOMAG SA
2010-01-04 16:43 . 2010-01-04 16:43 -------- d-----w- c:\windows\system32\URTTEMP
2010-01-03 11:35 . 2010-01-03 11:35 -------- d-----w- C:\rsit
2010-01-02 11:01 . 2010-01-02 11:01 -------- d-----w- c:\program files\AhnLab
2010-01-01 21:36 . 2010-01-01 21:36 -------- d-----w- c:\program files\Gravity
2010-01-01 18:38 . 2010-01-01 18:40 -------- d-----w- c:\program files\Aerys Ragnarok Online
2010-01-01 11:48 . 2010-01-01 11:48 -------- d-----w- c:\program files\SmartCell
2009-12-31 13:03 . 2009-12-31 13:03 -------- d-----w- c:\program files\Brain Seal
2009-12-31 11:13 . 2009-12-31 11:13 -------- d-----w- C:\GamesCampus
2009-12-31 11:01 . 2010-01-05 11:10 -------- d-----w- c:\documents and settings\Nemesis\Local Settings\Application Data\PMB Files
2009-12-31 11:01 . 2009-12-31 11:04 -------- d-----w- c:\documents and settings\All Users\Application Data\PMB Files
2009-12-31 11:01 . 2009-12-31 11:01 -------- d-----w- c:\program files\Pando Networks
2009-12-23 18:33 . 2009-12-23 18:37 -------- d-----w- c:\documents and settings\Nemesis\Local Settings\Application Data\Painkiller Overdose
2009-12-23 13:25 . 2009-12-23 13:25 -------- d-----w- c:\program files\OpenAL
2009-12-22 19:51 . 2009-12-22 19:51 -------- d-----w- c:\windows\desktop
2009-12-22 19:04 . 2009-12-22 19:08 -------- d-----w- c:\documents and settings\Nemesis\Local Settings\Application Data\NFS Underground 2
2009-12-22 13:29 . 2009-12-22 13:29 65144 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-12-21 15:58 . 2009-12-21 16:07 -------- d-----w- c:\documents and settings\Nemesis\Local Settings\Application Data\Painkiller Resurrection
2009-12-20 08:08 . 2009-09-23 08:41 26176 ---ha-w- c:\windows\system32\hamachi.sys
2009-12-20 08:08 . 2009-12-20 08:08 -------- d-----w- c:\program files\LogMeIn Hamachi
2009-12-20 08:08 . 2010-01-05 11:08 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\LogMeIn Hamachi
2009-12-20 08:08 . 2009-12-22 16:04 -------- d-----w- c:\documents and settings\Nemesis\Local Settings\Application Data\LogMeIn Hamachi
2009-12-19 15:52 . 2003-03-15 22:15 90112 ----a-w- c:\windows\unvise32.exe
2009-12-15 19:15 . 2009-12-15 19:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Blizzard
2009-12-13 15:20 . 2009-11-24 14:27 53616 ----a-w- c:\windows\system32\CMStarter_Eng.dll
2009-12-13 15:20 . 2009-11-24 14:27 53616 ----a-w- c:\windows\system32\CMStarter_Kor.dll
2009-12-13 15:20 . 2009-11-24 14:27 364912 ----a-w- c:\windows\system32\CMStarterCore.exe
2009-12-13 09:55 . 2009-08-06 18:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2009-12-13 09:55 . 2009-08-06 18:23 215920 ----a-w- c:\windows\system32\muweb.dll
2009-12-12 16:55 . 2009-12-12 16:55 12862 ----a-r- c:\documents and settings\Nemesis\Application Data\Microsoft\Installer\{0E2B767B-EA6A-489B-BF83-8083FE1DB661}\_1EEFFF72773535163E4216.exe
2009-12-12 11:08 . 2009-12-12 11:08 -------- d-----w- c:\program files\Microsoft Silverlight
2009-12-11 22:05 . 2009-12-11 22:05 573440 ----a-w- c:\documents and settings\All Users\Application Data\Nanovor\Utils\ConsoleDeviceInterface.exe
2009-12-11 22:02 . 2009-12-11 22:02 5940880 ----a-w- c:\documents and settings\All Users\Application Data\Nanovor\evolver.exe
2009-12-11 21:50 . 2009-12-11 22:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Nanovor
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-05 10:48 . 2009-03-29 18:04 -------- d-----w- c:\documents and settings\Nemesis\Application Data\Skype
2010-01-05 10:19 . 2009-03-29 18:06 -------- d-----w- c:\documents and settings\Nemesis\Application Data\skypePM
2010-01-04 23:31 . 2008-08-03 15:43 -------- d-----w- c:\documents and settings\Nemesis\Application Data\uTorrent
2010-01-04 21:47 . 2009-04-08 13:35 -------- d-----w- c:\program files\Garena
2010-01-04 12:10 . 2008-05-19 16:25 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-03 11:31 . 2009-06-02 17:55 3766 --sha-w- c:\windows\system32\KGyGaAvL.sys
2010-01-03 11:31 . 2009-06-02 18:18 88 --sh--r- c:\windows\system32\45695CAEBB.sys
2009-12-30 09:52 . 2009-08-06 19:28 -------- d-----w- c:\program files\ICQ6.5
2009-12-28 12:14 . 2009-02-21 06:17 65536 ----a-w- c:\windows\IFinst27.exe
2009-12-23 18:31 . 2008-05-26 17:48 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-12-23 13:26 . 2008-10-04 15:02 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-12-23 13:26 . 2008-10-04 15:03 -------- d-----w- c:\program files\AGEIA Technologies
2009-12-23 13:25 . 2008-09-28 10:58 444952 ----a-w- c:\windows\system32\wrap_oal.dll
2009-12-23 13:25 . 2008-09-28 10:58 109080 ----a-w- c:\windows\system32\OpenAL32.dll
2009-12-14 20:51 . 2009-01-17 08:10 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2009-12-14 15:58 . 2009-06-29 17:44 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-11 22:05 . 2009-09-08 16:33 11284648 ----a-w- c:\documents and settings\All Users\Application Data\Nanovor\Nanovor.exe
2009-12-11 22:05 . 2009-08-14 11:48 108 ----a-w- c:\documents and settings\All Users\Application Data\Nanovor\Nanovor.bat
2009-12-04 17:24 . 2008-08-15 19:18 -------- d-----w- c:\documents and settings\Nemesis\Application Data\Hamachi
2009-12-02 12:10 . 2009-12-02 12:10 66680 ----a-w- c:\windows\system32\rakion.sys
2009-11-29 10:47 . 2009-11-29 10:47 -------- d-----w- c:\program files\Conduit
2009-11-28 17:26 . 2009-11-28 17:26 -------- d-----w- c:\documents and settings\Nemesis\Application Data\Atari
2009-11-28 17:08 . 2009-11-28 17:08 -------- d-----w- c:\documents and settings\Nemesis\Application Data\Leadertech
2009-11-28 15:49 . 2009-11-28 15:49 0 ----a-w- c:\windows\PowerReg.dat
2009-11-26 07:01 . 2009-11-26 07:01 -------- d-----w- c:\program files\MSXML 4.0
2009-11-24 23:54 . 2009-03-01 08:51 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:51 . 2009-03-01 08:51 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-11-24 23:50 . 2009-03-01 08:51 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-11-24 23:50 . 2009-03-01 08:51 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-24 23:50 . 2009-03-01 08:51 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-24 23:49 . 2009-03-01 08:51 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2009-03-01 08:51 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2009-03-01 08:51 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-11-24 23:47 . 2009-03-01 08:51 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-11-22 16:38 . 2008-05-19 17:51 13880 ----a-w- c:\documents and settings\Nemesis\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-22 10:39 . 2008-05-27 15:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-11-22 10:24 . 2009-10-28 09:37 -------- d-----w- c:\program files\Java
2009-11-22 10:23 . 2009-11-22 10:23 152576 ----a-w- c:\documents and settings\Nemesis\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-22 10:23 . 2009-11-22 10:23 79488 ----a-w- c:\documents and settings\Nemesis\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-11-16 20:08 . 2009-11-16 20:08 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Xfire
2009-11-14 18:26 . 2009-11-14 18:26 -------- d-----w- c:\program files\Common Files\Skype
2009-11-14 18:26 . 2009-11-14 18:26 -------- d-----r- c:\program files\Skype
2009-11-14 18:26 . 2009-03-29 18:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-11-12 14:44 . 2009-11-12 14:44 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-11-07 18:13 . 2008-05-21 15:26 -------- d-----w- c:\documents and settings\Nemesis\Application Data\ICQ
2009-11-04 17:35 . 2009-11-04 17:35 271360 ----a-w- c:\windows\system32\drivers\atksgt.sys
2009-11-04 17:35 . 2009-11-04 17:35 18048 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2009-10-29 05:38 . 2006-03-04 03:33 667136 ------w- c:\windows\system32\wininet.dll
2009-10-28 09:37 . 2009-10-28 09:37 152576 ----a-w- c:\documents and settings\Nemesis\Application Data\Sun\Java\jre1.6.0_16\lzma.dll
2009-10-21 05:38 . 2004-08-04 10:00 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-04 10:00 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 10:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2004-08-04 10:00 270336 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2004-08-04 10:00 149504 ----a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2004-08-04 10:00 79872 ----a-w- c:\windows\system32\raschap.dll
2009-10-11 03:17 . 2009-10-28 09:38 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-07 13:00 . 2008-07-08 14:37 21840 -c--atw- c:\windows\system32\SIntfNT.dll
2009-10-07 13:00 . 2008-07-08 14:37 17212 -c--atw- c:\windows\system32\SIntf32.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-01-04_10.47.39 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-01-05 11:08 . 2010-01-05 11:08 16384 c:\windows\Temp\Perflib_Perfdata_70c.dat
+ 2010-01-05 10:56 . 2010-01-05 10:56 16384 c:\windows\Temp\Perflib_Perfdata_6f4.dat
+ 2003-02-21 04:16 . 2003-02-21 04:16 49152 c:\windows\system32\URTTEMP\regtlib.exe
+ 2006-02-28 12:00 . 2010-01-04 16:44 71002 c:\windows\system32\perfc009.dat
+ 2003-02-20 19:10 . 2003-02-20 19:10 31744 c:\windows\Microsoft.NET\Framework\v1.1.4322\WMINet_Utils.dll
+ 2003-02-21 06:24 . 2003-02-21 06:24 57344 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.RegularExpressions.dll
+ 2003-02-21 06:26 . 2003-02-21 06:26 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Security.dll
+ 2003-02-20 18:09 . 2003-02-20 18:09 64000 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.EnterpriseServices.Thunk.dll
+ 2003-02-21 06:26 . 2003-02-21 06:26 65536 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Drawing.Design.dll
+ 2003-02-21 06:26 . 2003-02-21 06:26 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.DirectoryServices.dll
+ 2003-02-21 06:26 . 2003-02-21 06:26 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Configuration.Install.dll
+ 2003-02-21 06:25 . 2003-02-21 06:25 12288 c:\windows\Microsoft.NET\Framework\v1.1.4322\RegSvcs.exe
+ 2003-02-21 06:26 . 2003-02-21 06:26 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\RegCode.dll
+ 2003-02-21 06:25 . 2003-02-21 06:25 28672 c:\windows\Microsoft.NET\Framework\v1.1.4322\RegAsm.exe
+ 2003-02-20 18:09 . 2003-02-20 18:09 90112 c:\windows\Microsoft.NET\Framework\v1.1.4322\PerfCounter.dll
+ 2003-02-20 18:09 . 2003-02-20 18:09 73728 c:\windows\Microsoft.NET\Framework\v1.1.4322\ngen.exe
+ 2003-02-20 17:43 . 2003-02-20 17:43 22528 c:\windows\Microsoft.NET\Framework\v1.1.4322\MUI\0409\mscorsecr.dll
+ 2003-02-20 18:18 . 2003-02-20 18:18 20480 c:\windows\Microsoft.NET\Framework\v1.1.4322\mtxoci8.dll
+ 2003-02-20 18:09 . 2003-02-20 18:09 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsn.dll
+ 2003-02-20 18:09 . 2003-02-20 18:09 81920 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsec.dll
+ 2003-02-20 18:06 . 2003-02-20 18:06 65536 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorpe.dll
+ 2003-02-20 18:09 . 2003-02-20 18:09 98304 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
+ 2003-02-20 18:09 . 2003-02-20 18:09 86016 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorie.dll
+ 2003-02-20 18:09 . 2003-02-20 18:09 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscordbc.dll
+ 2003-02-21 06:25 . 2003-02-21 06:25 49152 c:\windows\Microsoft.NET\Framework\v1.1.4322\MigPolWin.exe
+ 2003-02-21 06:25 . 2003-02-21 06:25 49152 c:\windows\Microsoft.NET\Framework\v1.1.4322\MigPol.exe
+ 2003-02-21 06:25 . 2003-02-21 06:25 11264 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2003-02-21 06:24 . 2003-02-21 06:24 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.Vsa.dll
+ 2003-02-21 06:24 . 2003-02-21 06:24 28672 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.VisualBasic.Vsa.dll
+ 2003-02-21 06:24 . 2003-02-21 06:24 40960 c:\windows\Microsoft.NET\Framework\v1.1.4322\jsc.exe
+ 2003-02-21 06:24 . 2003-02-21 06:24 26112 c:\windows\Microsoft.NET\Framework\v1.1.4322\ISymWrapper.dll
+ 2003-02-20 18:22 . 2003-02-20 18:22 40960 c:\windows\Microsoft.NET\Framework\v1.1.4322\InstallUtilLib.dll
+ 2003-02-21 06:24 . 2003-02-21 06:24 15872 c:\windows\Microsoft.NET\Framework\v1.1.4322\InstallUtil.exe
+ 2003-02-21 06:24 . 2003-02-21 06:24 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\IEHost.dll
+ 2003-02-21 03:12 . 2003-02-21 03:12 28672 c:\windows\Microsoft.NET\Framework\v1.1.4322\cvtres.exe
+ 2003-02-21 06:24 . 2003-02-21 06:24 33792 c:\windows\Microsoft.NET\Framework\v1.1.4322\CustomMarshalers.dll
+ 2003-02-21 06:24 . 2003-02-21 06:24 12288 c:\windows\Microsoft.NET\Framework\v1.1.4322\cscompmgd.dll
+ 2003-02-21 09:20 . 2003-02-21 09:20 49152 c:\windows\Microsoft.NET\Framework\v1.1.4322\csc.exe
+ 2003-02-20 18:09 . 2003-02-20 18:09 77824 c:\windows\Microsoft.NET\Framework\v1.1.4322\CORPerfMonExt.dll
+ 2003-02-21 06:24 . 2003-02-21 06:24 49152 c:\windows\Microsoft.NET\Framework\v1.1.4322\ConfigWizards.exe
+ 2003-02-21 06:24 . 2003-02-21 06:24 94208 c:\windows\Microsoft.NET\Framework\v1.1.4322\CasPol.exe
+ 2003-02-20 18:19 . 2003-02-20 18:19 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe
+ 2003-02-20 18:19 . 2003-02-20 18:19 32768 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe
+ 2003-02-20 18:19 . 2003-02-20 18:19 20480 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_regiis.exe
+ 2003-02-20 18:19 . 2003-02-20 18:19 40960 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_rc.dll
+ 2003-02-20 18:19 . 2003-02-20 18:19 24576 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_filter.dll
+ 2003-02-21 04:00 . 2003-02-21 04:00 98304 c:\windows\Microsoft.NET\Framework\v1.1.4322\alink.dll
+ 2003-02-21 02:55 . 2003-02-21 02:55 94208 c:\windows\Microsoft.NET\Framework\v1.1.4322\1033\cscompui.dll
+ 2003-02-21 01:59 . 2003-02-21 01:59 16896 c:\windows\Microsoft.NET\Framework\v1.1.4322\1033\alinkui.dll
+ 2010-01-04 16:44 . 2010-01-04 16:44 90112 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a_1d53a4aa\System.Drawing.Design.dll
+ 2010-01-04 16:44 . 2010-01-04 16:44 61440 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a_725fbe0b\CustomMarshalers.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 57344 c:\windows\assembly\GAC\System.Web.RegularExpressions\1.0.5000.0__b03f5f7f11d50a3a\System.Web.RegularExpressions.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 77824 c:\windows\assembly\GAC\System.Security\1.0.5000.0__b03f5f7f11d50a3a\System.Security.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 64000 c:\windows\assembly\GAC\System.EnterpriseServices\1.0.5000.0__b03f5f7f11d50a3a\System.EnterpriseServices.Thunk.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 65536 c:\windows\assembly\GAC\System.Drawing.Design\1.0.5000.0__b03f5f7f11d50a3a\System.Drawing.Design.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 86016 c:\windows\assembly\GAC\System.DirectoryServices\1.0.5000.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 77824 c:\windows\assembly\GAC\System.Configuration.Install\1.0.5000.0__b03f5f7f11d50a3a\System.Configuration.Install.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 32768 c:\windows\assembly\GAC\Regcode\1.0.5000.0__b03f5f7f11d50a3a\RegCode.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 32768 c:\windows\assembly\GAC\Microsoft.Vsa\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.Vsa.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 11264 c:\windows\assembly\GAC\Microsoft.Vsa.Vb.CodeDOMProcessor\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.Vsa.Vb.CodeDOMProcessor.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 28672 c:\windows\assembly\GAC\Microsoft.VisualBasic.Vsa\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Vsa.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 26112 c:\windows\assembly\GAC\ISymWrapper\1.0.5000.0__b03f5f7f11d50a3a\ISymWrapper.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 32768 c:\windows\assembly\GAC\IEHost\1.0.5000.0__b03f5f7f11d50a3a\IEHost.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 33792 c:\windows\assembly\GAC\CustomMarshalers\1.0.5000.0__b03f5f7f11d50a3a\CustomMarshalers.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 12288 c:\windows\assembly\GAC\cscompmgd\7.0.5000.0__b03f5f7f11d50a3a\cscompmgd.dll
+ 2003-02-20 17:43 . 2003-02-20 17:43 4096 c:\windows\system32\mui\0409\mscoreer.dll
+ 2003-02-20 18:09 . 2003-02-20 18:09 9216 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscortim.dll
+ 2003-02-21 06:25 . 2003-02-21 06:25 6656 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft_VsaVb.dll
+ 2003-02-21 06:25 . 2003-02-21 06:25 6144 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.VisualC.Dll
+ 2003-02-21 06:24 . 2003-02-21 06:24 4608 c:\windows\Microsoft.NET\Framework\v1.1.4322\IIEHost.dll
+ 2003-02-21 06:24 . 2003-02-21 06:24 7168 c:\windows\Microsoft.NET\Framework\v1.1.4322\IEExecRemote.dll
+ 2003-02-21 06:24 . 2003-02-21 06:24 7680 c:\windows\Microsoft.NET\Framework\v1.1.4322\IEExec.exe
+ 2003-02-21 06:24 . 2003-02-21 06:24 7680 c:\windows\Microsoft.NET\Framework\v1.1.4322\Accessibility.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 6656 c:\windows\assembly\GAC\Microsoft_VsaVb\7.0.5000.0__b03f5f7f11d50a3a\Microsoft_VsaVb.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 6144 c:\windows\assembly\GAC\Microsoft.VisualC\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.VisualC.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 4608 c:\windows\assembly\GAC\IIEHost\1.0.5000.0__b03f5f7f11d50a3a\IIEHost.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 7168 c:\windows\assembly\GAC\IEExecRemote\1.0.5000.0__b03f5f7f11d50a3a\IEExecRemote.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 7680 c:\windows\assembly\GAC\Accessibility\1.0.5000.0__b03f5f7f11d50a3a\Accessibility.dll
+ 2006-02-28 12:00 . 2010-01-04 16:44 440684 c:\windows\system32\perfh009.dat
+ 2003-02-21 09:20 . 2003-02-21 09:20 737280 c:\windows\Microsoft.NET\Framework\v1.1.4322\vbc.exe
+ 2003-02-21 06:27 . 2003-02-21 06:27 569344 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.Services.dll
+ 2003-02-21 06:27 . 2003-02-21 06:27 819200 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.Mobile.dll
+ 2003-02-21 06:27 . 2003-02-21 06:27 126976 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.ServiceProcess.dll
+ 2003-02-21 06:26 . 2003-02-21 06:26 131072 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Runtime.Serialization.Formatters.Soap.dll
+ 2003-02-21 06:26 . 2003-02-21 06:26 323584 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Runtime.Remoting.dll
+ 2003-02-21 06:26 . 2003-02-21 06:26 241664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Messaging.dll
+ 2003-02-21 06:26 . 2003-02-21 06:26 368640 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Management.dll
+ 2003-02-21 06:26 . 2003-02-21 06:26 241664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.EnterpriseServices.dll
+ 2003-02-21 06:26 . 2003-02-21 06:26 466944 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Drawing.dll
+ 2003-02-21 06:25 . 2003-02-21 06:25 299008 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Data.OracleClient.dll
+ 2003-02-20 18:09 . 2003-02-20 18:09 319488 c:\windows\Microsoft.NET\Framework\v1.1.4322\SOS.dll
+ 2003-02-20 18:09 . 2003-02-20 18:09 122880 c:\windows\Microsoft.NET\Framework\v1.1.4322\shfusres.dll
+ 2003-02-20 18:09 . 2003-02-20 18:09 253952 c:\windows\Microsoft.NET\Framework\v1.1.4322\shfusion.dll
+ 2003-02-21 03:42 . 2003-02-21 03:42 348160 c:\windows\Microsoft.NET\Framework\v1.1.4322\msvcr71.dll
+ 2003-02-20 18:09 . 2003-02-20 18:09 143360 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorrc.dll
+ 2003-02-20 17:43 . 2003-02-20 17:43 131072 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscormmc.dll
+ 2003-02-20 18:06 . 2003-02-20 18:06 311296 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
+ 2003-02-20 18:09 . 2003-02-20 18:09 233472 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscordbi.dll
+ 2003-02-21 06:26 . 2003-02-21 06:26 299008 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.VisualBasic.dll
+ 2003-02-21 06:26 . 2003-02-21 06:26 716800 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.JScript.dll
+ 2003-02-20 18:09 . 2003-02-20 18:09 196608 c:\windows\Microsoft.NET\Framework\v1.1.4322\ilasm.exe
+ 2003-02-20 18:06 . 2003-02-20 18:06 282624 c:\windows\Microsoft.NET\Framework\v1.1.4322\fusion.dll
+ 2003-02-20 18:16 . 2003-02-20 18:16 798720 c:\windows\Microsoft.NET\Framework\v1.1.4322\EventLogMessages.dll
+ 2003-02-21 09:21 . 2003-02-21 09:21 524288 c:\windows\Microsoft.NET\Framework\v1.1.4322\diasymreader.dll
+ 2003-02-21 09:21 . 2003-02-21 09:21 626688 c:\windows\Microsoft.NET\Framework\v1.1.4322\cscomp.dll
+ 2002-07-29 10:11 . 2002-07-29 10:11 219136 c:\windows\Microsoft.NET\Framework\v1.1.4322\c_g18030.dll
+ 2003-02-20 18:19 . 2003-02-20 18:19 253952 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2003-02-21 04:04 . 2003-02-21 04:04 155648 c:\windows\Microsoft.NET\Framework\v1.1.4322\1033\Vsavb7rtUI.dll
+ 2003-02-21 02:02 . 2003-02-21 02:02 131072 c:\windows\Microsoft.NET\Framework\v1.1.4322\1033\vbc7ui.dll
+ 2010-01-04 16:45 . 2010-01-04 16:45 525824 c:\windows\Installer\2d92a3.msi
+ 2010-01-04 16:44 . 2010-01-04 16:44 835584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a_09c54d60\System.Drawing.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 569344 c:\windows\assembly\GAC\System.Web.Services\1.0.5000.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 819200 c:\windows\assembly\GAC\System.Web.Mobile\1.0.5000.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 126976 c:\windows\assembly\GAC\System.ServiceProcess\1.0.5000.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 131072 c:\windows\assembly\GAC\System.Runtime.Serialization.Formatters.Soap\1.0.5000.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 323584 c:\windows\assembly\GAC\System.Runtime.Remoting\1.0.5000.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 241664 c:\windows\assembly\GAC\System.Messaging\1.0.5000.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 368640 c:\windows\assembly\GAC\System.Management\1.0.5000.0__b03f5f7f11d50a3a\System.Management.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 241664 c:\windows\assembly\GAC\System.EnterpriseServices\1.0.5000.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 466944 c:\windows\assembly\GAC\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 299008 c:\windows\assembly\GAC\System.Data.OracleClient\1.0.5000.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 299008 c:\windows\assembly\GAC\Microsoft.VisualBasic\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 716800 c:\windows\assembly\GAC\Microsoft.JScript\7.0.5000.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2003-02-21 04:04 . 2003-02-21 04:04 1032192 c:\windows\Microsoft.NET\Framework\v1.1.4322\VsaVb7rt.dll
+ 2003-02-21 06:27 . 2003-02-21 06:27 1335296 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.XML.dll
+ 2003-02-21 06:27 . 2003-02-21 06:27 2039808 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Windows.Forms.dll
+ 2003-02-21 06:27 . 2003-02-21 06:27 1245184 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
+ 2003-02-21 06:26 . 2003-02-21 06:26 1216512 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
+ 2003-02-21 06:26 . 2003-02-21 06:26 1699840 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Design.dll
+ 2003-02-21 06:26 . 2003-02-21 06:26 1290240 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Data.dll
+ 2003-02-20 18:08 . 2003-02-20 18:08 2482176 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
+ 2003-02-20 18:07 . 2003-02-20 18:07 2494464 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
+ 2003-02-21 06:26 . 2003-02-21 06:26 2088960 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
+ 2003-02-21 06:25 . 2003-02-21 06:25 1564672 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorcfg.dll
+ 2010-01-04 16:44 . 2010-01-04 16:44 3443712 c:\windows\Installer\2bdf87.msi
+ 2010-01-04 16:44 . 2010-01-04 16:44 1929216 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934e089_2f7dfd6f\System.dll
+ 2010-01-04 16:44 . 2010-01-04 16:44 2076672 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c561934e089_a71f9d65\System.Xml.dll
+ 2010-01-04 16:44 . 2010-01-04 16:44 2994176 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0__b77a5c561934e089_a9c6fca9\System.Windows.Forms.dll
+ 2010-01-04 16:44 . 2010-01-04 16:44 1462272 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5f7f11d50a3a_27b81981\System.Design.dll
+ 2010-01-04 16:44 . 2010-01-04 16:44 3289088 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_1048f2ea\mscorlib.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 1216512 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 1335296 c:\windows\assembly\GAC\System.Xml\1.0.5000.0__b77a5c561934e089\System.Xml.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 2039808 c:\windows\assembly\GAC\System.Windows.Forms\1.0.5000.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 1245184 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 1699840 c:\windows\assembly\GAC\System.Design\1.0.5000.0__b03f5f7f11d50a3a\System.Design.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 1290240 c:\windows\assembly\GAC\System.Data\1.0.5000.0__b77a5c561934e089\System.Data.dll
+ 2010-01-04 16:43 . 2010-01-04 16:43 1564672 c:\windows\assembly\GAC\mscorcfg\1.0.5000.0__b03f5f7f11d50a3a\mscorcfg.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\documents and settings\Nemesis\Desktop\DAEMON Tools Lite\daemon.exe" [2008-07-04 486856]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-09-25 94208]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2006-09-10 218032]
"Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2009-12-31 2935480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-03-30 5898240]
"nwiz"="nwiz.exe" [2005-03-30 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-03-30 86016]
"SoundMan"="SOUNDMAN.EXE" [2005-06-14 77824]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2005-09-25 155648]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 10:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0sprestrt
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"\\\\PONOZKA\\ZdieľanéDoku\\NarutoLF2 2.0\\Naruto.exe"=
"c:\\Program Files\\Garena\\Garena.exe"=
"c:\\Documents and Settings\\All Users\\Documents\\LieroX v0.56 Pack 1.9\\LieroX.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"d:\\W III\\Warcraft III.exe"=
"d:\\Wowko\\Kópia (2) – Kópia – Kópia – Counter-Strike 1.6\\hl.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Documents and Settings\\Nemesis\\Desktop\\Nový priečinok\\theduel.exe"=
"d:\\Program Files\\DreamCatcher\\Painkiller\\Painkiller Overdose\\Bin\\Overdose.exe"=
"d:\\Program Files\\DreamCatcher\\Painkiller\\Painkiller Overdose\\Bin\\OverdoseEditor.exe"=
"d:\\Program Files\\DreamCatcher\\Painkiller\\Painkiller Overdose\\Bin\\OverdoseServer.exe"=
"d:\\Wowko\\Kópia (2) – Kópia – Kópia – Counter-Strike 1.6\\hlds.exe"=
"d:\\Program Files\\Codemasters\\Overlord\\Overlord.exe"=
"d:\\Program Files\\Postal2\\System\\System\\Postal2MP.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\globallyopenports\list]
"57714:TCP"= 57714:TCP:Pando Media Booster
"57714:UDP"= 57714:UDP:Pando Media Booster
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [26.5.2008 18:29 717296]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [1.3.2009 9:51 114768]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [17.2.2009 11:43 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [17.2.2009 11:43 55024]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [1.3.2009 9:51 20560]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [29.10.2009 12:27 1074568]
R2 ICQ Service;ICQ Service;c:\program files\ICQ6Toolbar\ICQ Service.exe [6.8.2009 20:31 222968]
S3 alcan5ln;Alcatel SpeedTouch(tm) USB ADSL RFC1483 Networking Driver (NDIS);c:\windows\system32\drivers\alcan5ln.sys [19.5.2008 19:55 36048]
S3 GarenaPEngine;GarenaPEngine;\??\c:\docume~1\Nemesis\LOCALS~1\Temp\NEI81.tmp --> c:\docume~1\Nemesis\LOCALS~1\Temp\NEI81.tmp [?]
S3 rak;rak;c:\windows\system32\rakion.sys [2.12.2009 13:10 66680]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [17.2.2009 11:43 7408]
S3 TKFsAc;TKFsAc;c:\windows\system32\TKFsAc2k.sys [2.7.2009 19:46 88864]
S3 TKFsAv;TKFsAv;c:\windows\system32\TKFsAv2k.sys [2.7.2009 19:46 31488]
S3 TKFsFt;TKFsFt;c:\windows\system32\TKFsFt2k.sys [2.7.2009 19:46 80672]
S3 TKRgAc;TKRgAc;c:\windows\system32\TKRgAc2k.sys [2.7.2009 19:46 41984]
S3 TKRgFt;TKRgFt;c:\windows\system32\TKRgFtXp.sys [2.7.2009 19:46 24704]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2090540
mSearch Bar = 687474703a2f2f7777772e676f6f676c652e636f6d2f
mSearchMigratedDefaultURL = 687474703a2f2f7777772e676f6f676c652e636f6d2f
mSearchURL = 687474703a2f2f7777772e676f6f676c652e636f6d2f
IE: &Search
FF - ProfilePath - c:\documents and settings\Nemesis\Application Data\Mozilla\Firefox\Profiles\g2tqtva6.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2090540&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2090540&SearchSource=13
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2090540&SearchSource=2&q=
FF - component: c:\documents and settings\Nemesis\Application Data\Mozilla\Firefox\Profiles\g2tqtva6.default\extensions\{d22f6f66-2f47-4184-8625-fbfa4cbdb7ce}\components\FFExternalAlert.dll
FF - plugin: c:\program files\Java\jre6\bin\npdeploytk.dll
FF - plugin: c:\program files\Java\jre6\bin\npjpi160_17.dll
FF - plugin: c:\program files\Java\jre6\bin\npoji610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPHoldemFireLauncher.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPMFireLauncher.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\defaults\pref\firefox-l10n.js - pref("browser.fixup.alternate.suffix", ".cz");
.
- - - - ORPHANS REMOVED - - - -
AddRemove-gatesofandaron_is1 - d:\program files\Gameforge4D\GatesofAndaron\unins000.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-05 12:09
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys hal.dll ACPI.sys sfsync02.sys nvatabus.sys spxw.sys >>UNKNOWN [0x8318E938]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf75b0f28
\Driver\ACPI -> ACPI.sys @ 0xf731bcb8
\Driver\atapi -> atapi.sys @ 0xf72d6b40
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x80579022
ParseProcedure -> ntkrnlpa.exe @ 0x80577c84
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x80579022
ParseProcedure -> ntkrnlpa.exe @ 0x80577c84
NDIS: NVIDIA nForce Networking Controller -> SendCompleteHandler -> NDIS.sys @ 0xf71cbbb0
PacketIndicateHandler -> NDIS.sys @ 0xf71d8a21
SendHandler -> NDIS.sys @ 0xf71b687b
user & kernel MBR OK
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GarenaPEngine]
"ImagePath"="\??\c:\docume~1\Nemesis\LOCALS~1\Temp\NEI81.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-2052111302-1606980848-1801674531-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:e2,83,c0,cd,59,f3,65,d7,81,54,b3,21,a0,05,23,04,d2,cc,e9,ea,7b,9d,9b,
00,a9,4a,50,a5,35,1a,8b,10,b5,c5,fa,b4,f3,be,59,2c,0f,d3,69,f1,a3,b1,d0,f4,\
"??"=hex:98,8d,b4,1c,7e,f8,57,c3,15,cc,57,96,67,b6,38,56
[HKEY_USERS\S-1-5-21-2052111302-1606980848-1801674531-1004\Software\SecuROM\License information*]
"datasecu"=hex:db,f9,ab,f4,e6,33,bf,3c,48,d6,fb,d6,5a,98,f1,57,28,9c,c4,ca,81,
0f,de,46,1e,37,3f,66,13,b9,1f,fc,08,9d,94,82,3b,ae,04,1c,fe,13,98,4e,79,ee,\
"rkeysecu"=hex:d9,c2,5e,b0,b6,64,0b,36,c5,96,97,69,e3,50,6d,1b
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(720)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\ATKKBService.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PSIService.exe
c:\windows\SOUNDMAN.EXE
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-01-05 12:14:04 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-05 11:14
ComboFix2.txt 2010-01-04 10:52
Pre-Run: 6 620 631 040 bytes free
Post-Run: 6 594 084 864 bytes free
- - End Of File - - 0FAD910F7F14965C6B01478A345128A1