Thomas
Full Member
  

Gender: 
Posts: 233
|
 |
Re: do i need these files
« Reply #2 on: Mar 10th, 2009, 5:59am » |
Quote Modify
|
---------c:\windows\system32\dllcache\ieudinit.exe 2009-03-08 09:32 . 2009-03-08 12:401,355--a------c:\windows\imsins.BAK 2009-03-08 09:21 . 2008-04-11 15:04691,712---------c:\windows\system32\dllcache\inetcomm.dll 2009-03-08 09:21 . 2008-05-08 10:02203,136---------c:\windows\system32\dllcache\rmcast.sys 2009-03-08 09:20 . 2008-08-14 06:112,189,184---------c:\windows\system32\dllcache\ntoskrnl.exe 2009-03-08 09:20 . 2008-08-14 06:092,145,280---------c:\windows\system32\dllcache\ntkrnlmp.exe 2009-03-08 09:20 . 2008-08-14 05:332,066,048---------c:\windows\system32\dllcache\ntkrnlpa.exe 2009-03-08 09:20 . 2008-08-14 05:332,023,936---------c:\windows\system32\dllcache\ntkrpamp.exe 2009-03-08 09:20 . 2008-09-15 08:121,846,400---------c:\windows\system32\dllcache\win32k.sys 2009-03-08 09:20 . 2008-12-11 06:57333,952---------c:\windows\system32\dllcache\srv.sys 2009-03-08 09:20 . 2008-06-13 07:05272,128---------c:\windows\system32\drivers\bthport.sys 2009-03-08 09:20 . 2008-06-13 07:05272,128---------c:\windows\system32\dllcache\bthport.sys 2009-03-08 09:19 . 2008-10-24 07:21455,296---------c:\windows\system32\dllcache\mrxsmb.sys 2009-03-08 09:16 . 2008-10-15 12:34337,408---------c:\windows\system32\dllcache\netapi32.dll 2009-03-08 09:07 . 2009-03-08 09:07<DIR>d--hs----c:\documents and settings\Compaq_Owner\UserData 2009-03-08 08:35 . 2009-03-08 08:35<DIR>d--------c:\program files\iTunes 2009-03-08 08:35 . 2009-03-08 08:35<DIR>d--------c:\program files\iPod 2009-03-08 08:35 . 2009-03-08 08:35<DIR>d--------c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6} 2009-03-08 08:34 . 2009-03-08 08:34<DIR>d--------c:\program files\QuickTime 2009-03-08 08:34 . 2009-03-08 08:34<DIR>d--------c:\program files\Bonjour 2009-03-08 08:33 . 2009-03-08 16:09<DIR>d----c---c:\windows\system32\DRVSTORE 2009-03-08 08:33 . 2009-03-08 08:35<DIR>d--------c:\program files\Common Files\Apple 2009-03-08 08:33 . 2009-03-08 08:33<DIR>d--------c:\documents and settings\All Users\Application Data\Apple 2009-03-08 08:05 . 2009-03-10 07:23410,984--a------c:\windows\system32\deploytk.dll 2009-03-08 07:57 . 2008-04-13 14:4685,248--a------c:\windows\system32\drivers\nabtsfec.sys 2009-03-08 07:57 . 2008-04-13 14:4619,200--a------c:\windows\system32\drivers\wstcodec.sys 2009-03-08 07:57 . 2008-04-13 14:4617,024--a------c:\windows\system32\drivers\ccdecode.sys 2009-03-08 07:57 . 2008-04-13 20:1216,384--a------c:\windows\system32\ipsink.ax 2009-03-08 07:57 . 2008-04-13 14:4615,232--a------c:\windows\system32\drivers\streamip.sys 2009-03-08 07:57 . 2008-04-13 14:4611,136--a------c:\windows\system32\drivers\slip.sys 2009-03-08 07:57 . 2008-04-13 14:4610,880--a------c:\windows\system32\drivers\ndisip.sys 2009-03-08 07:57 . 2008-04-13 14:395,504--a------c:\windows\system32\drivers\mstee.sys 2009-03-08 07:56 . 2008-04-13 20:1291,136--a------c:\windows\system32\kswdmcap.ax 2009-03-08 07:56 . 2008-04-13 20:1261,952--a------c:\windows\system32\kstvtune.ax 2009-03-08 07:56 . 2008-04-13 20:1253,760--a------c:\windows\system32\vfwwdm32.dll 2009-03-08 07:56 . 2008-04-13 20:1243,008--a------c:\windows\system32\ksxbar.ax 2009-03-08 07:56 . 2008-04-13 20:1228,672--a------c:\windows\system32\vidcap.ax 2009-03-08 07:53 . 2009-03-10 07:40<DIR>d-a------c:\documents and settings\All Users\Application Data\TEMP 2009-03-08 07:51 . 2009-03-08 07:51<DIR>d--------c:\program files\uTorrent 2009-03-08 07:51 . 2009-03-10 04:16<DIR>d--------c:\documents and settings\Compaq_Owner\Application Data\uTorrent 2009-03-08 07:49 . 2009-03-08 07:50<DIR>d--------c:\program files\7-Zip 2009-03-08 07:43 . 2009-03-08 07:45<DIR>d--------c:\program files\CCleaner 2009-03-08 07:40 . 2009-03-08 07:40<DIR>d--------c:\program files\Trend Micro 2009-03-08 07:33 . 2004-08-04 08:00221,184--a------c:\windows\system32\wmpns.dll 2009-03-08 07:33 . 2009-03-08 07:331,857-rahs----c:\windows\system32\drivers\103C_HP_CPC_ED861AA-ABA SR1603WM NA540_YC_0Pres_QCNH542_E54NAheRED2_48_IAmberine M_SASUSTek Computer INC._V1.03_B3.08_T050913_WXH2_L409_M223_J80_7AMD_8Sempron_91.79_#051225_ N10EC8139_Z14F12F20_G10025954.MRK 2009-03-08 07:30 . 2005-08-08 18:50<DIR>d--------c:\documents and settings\Compaq_Owner\WINDOWS 2009-03-08 07:30 . 2005-08-08 18:54<DIR>d--------c:\documents and settings\Compaq_Owner\Application Data\SampleView 2009-03-08 07:30 . 2005-08-08 18:49<DIR>d--------c:\documents and settings\Compaq_Owner\Application Data\Apple Computer 2009-03-08 07:30 . 2009-03-08 16:11<DIR>d--------c:\documents and settings\Compaq_Owner 2009-03-08 07:28 . 2005-08-08 18:50<DIR>d--------c:\windows\system32\config\systemprofile\WINDOWS 2009-03-08 07:28 . 2005-08-08 19:10<DIR>d--------c:\windows\system32\config\systemprofile\Application Data\Symantec 2009-03-08 07:28 . 2005-08-08 18:54<DIR>d--------c:\windows\system32\config\systemprofile\Application Data\SampleView . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-03-08 12:34---------d-----wc:\documents and settings\All Users\Application Data\Apple Computer 2009-03-08 12:24---------d-----wc:\program files\Common Files\InstallShield 2009-03-08 12:22---------d--h--wc:\program files\InstallShield Installation Information 2009-03-08 12:04---------d-----wc:\program files\Java 2009-01-21 11:49118,656----a-wc:\windows\system32\drivers\Rtnicxp.sys . ------- Sigcheck ------- 2005-03-14 04:17 359936 6129e70f3d2f1e60860c930ebeaf92c2c:\windows\$hf_mig$\KB893066\SP2QFE\tcpi p.sys 2008-06-20 06:44 360960 744e57c99232201ae98c49168b918f48c:\windows\$hf_mig$\KB951748\SP2QFE\tcpi p.sys 2008-06-20 07:51 361600 9aefa14bd6b182d61e3119fa5f436d3dc:\windows\$hf_mig$\KB951748\SP3GDR\tcpi p.sys 2008-06-20 07:59 361600 ad978a1b783b5719720cff204b666c8ec:\windows\$hf_mig$\KB951748\SP3QFE\tcpi p.sys 2008-06-20 06:45 360320 2a5554fc5b1e04e131230e3ce035c3f9c:\windows\$NtServicePackUninstall$\tcpi p.sys 2008-04-13 15:20 361344 93ea8d04ec73a85db02eb8805988f733c:\windows\$NtUninstallKB951748$\tcpip.s ys 2005-03-14 03:55 359808 0e66b538096a6529d1ac66e78eb0d5c8c:\windows\$NtUninstallKB951748_0$\tcpip .sys 2008-04-13 15:20 361344 accf5a9a1ffaa490f33dba1c632b95e1c:\windows\ServicePackFiles\i386\tcpip.s ys 2008-06-20 06:45 360320 2a5554fc5b1e04e131230e3ce035c3f9c:\windows\SoftwareDistribution\Download \ad744bdeedce85bf37a096f34577ff3a\sp2gdr\tcpip.sys 2008-06-20 06:44 360960 744e57c99232201ae98c49168b918f48c:\windows\SoftwareDistribution\Download \ad744bdeedce85bf37a096f34577ff3a\sp2qfe\tcpip.sys 2008-06-20 07:51 361600 9aefa14bd6b182d61e3119fa5f436d3dc:\windows\SoftwareDistribution\Download \ad744bdeedce85bf37a096f34577ff3a\sp3gdr\tcpip.sys 2008-06-20 07:59 361600 ad978a1b783b5719720cff204b666c8ec:\windows\SoftwareDistribution\Download \ad744bdeedce85bf37a096f34577ff3a\sp3qfe\tcpip.sys 2008-04-13 15:20 361344 93ea8d04ec73a85db02eb8805988f733c:\windows\SoftwareDistribution\Download \e9500597a78495f397efb821e37bf356\tcpip.sys 2008-06-20 07:51 361600 9425b72f40257b45d45d24773273dad0c:\windows\system32\dllcache\tcpip.sys 2008-06-20 07:51 361600 9425b72f40257b45d45d24773273dad0c:\windows\system32\drivers\tcpip.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RegistryMechanic"="c:\program files\Registry Mechanic\regmech.exe" [2008-07-08 2828184] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-03-08 1830128] "Y!TunnelPro"="c:\program files\Digital Asphyxia\Y!TunnelPro 2.5\YTPro.exe" [2008-09-27 1412608] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "THGuard"="c:\program files\TrojanHunter 5.0\THGuard.exe" [2008-10-24 1056928] "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-02-11 399504] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-10 148888] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-12-12 9555968] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-22 11:05 356352 c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\WINDOWS\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\MSN Messenger\\msnmsgr.exe"= "c:\\Program Files\\MSN Messenger\\livecall.exe"= "c:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "c:\\Program Files\\Digital Asphyxia\\Y!TunnelPro 2.5\\YTPro.exe"= R2 Bonjourwuauserv;Bonjour Service Bonjourwuauserv; [x] R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2009-02-11 179856] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-01-15 8944] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-01-15 55024] S3 DCamUSBVeo532;Veo Stingray/Connect Web Camera;c:\windows\system32\Drivers\ubVeo532.sys [2002-07-01 95232] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2009-02-11 15504] S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-01-15 7408] --- Other Services/Drivers In Memory --- *Deregistered* - AFD *Deregistered* - ALG *Deregistered* - Arp1394 *Deregistered* - Ati HotKey Poller *Deregistered* - AudioSrv *Deregistered* - audstub *Deregistered* - bb-run *Deregistered* - Beep *Deregistered* - Bonjour Service *Deregistered* - Browser *Deregistered* - Cdfs *Deregistered* - CryptSvc *Deregistered* - DcomLaunch *Deregistered* - Dhcp *Deregistered* - Dnscache *Deregistered* - ERSvc *Deregistered* - EventSystem *Deregistered* - Fastfat *Deregistered* - FastUserSwitchingCompatibility *Deregistered* - Fips *Deregistered* - FltMgr *Deregistered* - Ftdisk *Deregistered* - ftsata2 *Deregistered* - Gpc *Deregistered* - helpsvc *Deregistered* - HTTP *Deregistered* - iaStor *Deregistered* - ImapiService *Deregistered* - IntelIde *Deregistered* - IpNat *Deregistered* - IPSec *Deregistered* - JavaQuickStarterService *Deregistered* - KSecDD *Deregistered* - lanmanserver *Deregistered* - lanmanworkstation *Deregistered* - LmHosts *Deregistered* - MBAMProtector *Deregistered* - MBAMService *Deregistered* - MDM *Deregistered* - mdmxsdk *Deregistered* - mnmdd *Deregistered* - MountMgr *Deregistered* - MRxDAV *Deregistered* - MRxSmb *Deregistered* - Msfs *Deregistered* - mssmbios *Deregistered* - Mup *Deregistered* - NDIS *Deregistered* - NdisTapi *Deregistered* - Ndisuio *Deregistered* - NdisWan *Deregistered* - NDProxy *Deregistered* - NetBIOS *Deregistered* - NetBT *Deregistered* - Netman *Deregistered* - Nla *Deregistered* - Npfs *Deregistered* - Ntfs *Deregistered* - Null *Deregistered* - PartMgr *Deregistered* - PolicyAgent *Deregistered* - PptpMiniport *Deregistered* - ProtectedStorage *Deregistered* - PSched *Deregistered* - RasAcd *Deregistered* - Rasl2tp *Deregistered* - RasMan *Deregistered* - RasPppoe *Deregistered* - Raspti *Deregistered* - Rdbss *Deregistered* - RDPCDD *Deregistered* - RpcSs *Deregistered* - SamSs *Deregistered* - SASDIFSV *Deregistered* - SASENUM *Deregistered* - SASKUTIL *Deregistered* - Schedule *Deregistered* - seclogon *Deregistered* - SENS *Deregistered* - SharedAccess *Deregistered* - ShellHWDetection *Deregistered* - Spooler *Deregistered* - sr *Deregistered* - srservice *Deregistered* - Srv *Deregistered* - SSDPSRV *Deregistered* - swenum *Deregistered* - TapiSrv *Deregistered* - Tcpip *Deregistered* - TermDD *Deregistered* - TermService *Deregistered* - Themes *Deregistered* - TrkWks *Deregistered* - Update *Deregistered* - VgaSave *Deregistered* - ViaIde *Deregistered* - VolSnap *Deregistered* - W32Time *Deregistered* - Wanarp *Deregistered* - WebClient *Deregistered* - winmgmt *Deregistered* - wscsvc *Deregistered* - WSearch *Deregistered* - wuauserv *Deregistered* - WZCSVC [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d435b36-e506-11d9-9b78-e6b009352ae7}] \Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480 . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.yahoo.com/ uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_U S&c=Q405 &bd=presario&pf=desktop&parm1=seconduser uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.micros oft:en-US&ie=utf8&oe=utf8 mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_U S&c=Q405 &bd=presario&pf=desktop&parm1=seconduser uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/keyword/%s . . ------- File Associations ------- . . ************************************************************************ ** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-03-10 07:41:07 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************ ** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(672) c:\program files\SUPERAntiSpyware\SASWINLO.dll c:\windows\system32\Ati2evxx.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\ati2evxx.exe c:\windows\system32\ati2evxx.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE c:\windows\system32\searchindexer.exe c:\program files\Windows Desktop Search\WindowsSearch.exe . ************************************************************************ ** . Completion time: 2009-03-10 7:50:45 - machine was rebooted ComboFix-quarantined-files.txt 2009-03-10 11:50:36 Pre-Run: 51,241,656,320 bytes free Post-Run: 51,559,972,864 bytes free 375--- E O F ---2009-03-08 16:29:57
|