1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.3.1251.359.1033.18.447.135 [GMT 2:00
]
Running from: c:\documents and settings\Administrator\Desktop\1.exe
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-997
52CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))
)))))))))))))))))))))))))))))
.
.
c:\windows\system32\kbdBF.dll
.
.
((((((((((((((((((((((((( Files Created from 2013-11-15 to 2013-12-15 )))))))
))))))))))))))))))))))))
.
.
2013-12-15 18:27 . 2013-12-15 18:27
-------d-----wC:\Temp
2013-12-15 14:37 . 2013-12-15 14:37
-------d-----rC:\MSOCa
che
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))
)))))))))))))))))))))))))))))))
.
2013-10-28 19:03 . 2013-10-28 17:03
185856 ----a-wc:\windows\syste
m32\upnphost.dll
2013-10-28 19:03 . 2013-10-28 17:03
16896 ----a-wc:\windows\syste
m32\upnpcont.exe
2013-10-28 19:03 . 2013-10-28 17:03
133632 ----a-wc:\windows\syste
m32\upnp.dll
2013-10-28 19:03 . 2013-12-15 13:56
150528 ----a-wc:\windows\pchea
lth\UploadLB\Binaries\UploadM.exe
2013-10-28 19:03 . 2013-10-28 19:03
611328 ----a-wc:\windows\syste
m32\UIAutomationCore.dll
2013-10-28 19:03 . 2013-10-28 17:03
26624 ----a-wc:\windows\syste
m32\udhisapi.dll
2013-10-28 19:03 . 2013-10-28 17:03
279040 ----a-wc:\windows\help\
TSHOOT.dll
2013-10-28 19:02 . 2013-10-28 17:02
33280 ----a-wc:\windows\help\
sstub.dll
2013-10-28 19:02 . 2013-12-15 13:56
726078 ----a-wc:\windows\srcha
sst\srchui.dll
2013-10-28 19:02 . 2013-12-15 13:56
58434 ----a-wc:\windows\srcha
sst\srchctls.dll
2013-10-28 19:02 . 2013-10-28 17:02
71680 ----a-wc:\windows\syste
m32\ssdpsrv.dll
2013-10-28 19:02 . 2013-10-28 17:02
34816 ----a-wc:\windows\syste
m32\ssdpapi.dll
2013-10-28 19:02 . 2013-10-28 17:02
34816 ----a-wc:\windows\help\
sniffpol.dll
2013-10-28 19:01 . 2013-12-15 13:56
38400 ----a-wc:\windows\pchea
lth\helpctr\binaries\pchsvc.dll
2013-10-28 19:01 . 2013-12-15 13:56
102912 ----a-wc:\windows\pchea
lth\helpctr\binaries\pchshell.dll
2013-10-28 19:01 . 2013-12-15 13:56
35328 ----a-wc:\windows\pchea
lth\helpctr\binaries\notiflag.exe
376832 ----a-w-
c:\windows\pchea
3166208 ----a-w-
c:\windows\srcha
169984 ----a-w-
c:\windows\pchea
18432
----a-w-
c:\windows\pchea
99840
----a-w-
c:\windows\pchea
6656
----a-w-
c:\windows\pchea
769024 ----a-w-
c:\windows\pchea
744448 ----a-w-
c:\windows\pchea
21504
----a-w-
c:\windows\pchea
152576 ----a-w-
c:\windows\help\
12824
----a-w-
c:\windows\syste
3330
----a-w-
c:\windows\syste
28672
----a-w-
c:\windows\syste
338432 ----a-w-
c:\windows\syste
5120
----a-w-
c:\windows\syste
2897920 ----a-w-
c:\windows\syste
438784 ----a-w-
c:\windows\syste
187392 ----a-w-
c:\windows\syste
50176
----a-w-
c:\windows\syste
129024 ----a-w-
c:\windows\syste
91648
----a-w-
c:\windows\syste
30720
----a-w-
c:\windows\syste
174200 ----a-w-
c:\windows\syste
91904
----a-w-
c:\windows\syste
64512
----a-w-
c:\windows\syste
567808 ----a-w-
c:\windows\syste
39936
----a-w-
c:\windows\syste
383488 ----a-w-
c:\windows\syste
32256
----a-w-
c:\windows\syste
195584 ----a-w-
c:\windows\syste
17:04
148480 ----a-w-
c:\windows\syste
17:04
132224 ----a-w-
c:\windows\syste
17:04
18432
----a-w-
c:\windows\syste
17:04
90112
----a-w-
c:\windows\syste
17:04
7168
----a-w-
c:\windows\syste
17:04
50688
----a-w-
c:\windows\syste
17:04
41984
----a-w-
c:\windows\syste
17:04
36864
----a-w-
c:\windows\syste
17:04
239616 ----a-w-
c:\windows\syste
17:04
22528
----a-w-
c:\windows\syste
17:04
19456
----a-w-
c:\windows\syste
17:04
164352 ----a-w-
c:\windows\syste
17:04
14336
----a-w-
c:\windows\syste
17:04
135168 ----a-w-
c:\windows\syste
17:04
11776
----a-w-
c:\windows\syste
17:04
11264
----a-w-
c:\windows\syste
17:04
9216
----a-w-
c:\windows\syste
17:04
80896
----a-w-
c:\windows\syste
17:04
604160 ----a-w-
c:\windows\syste
17:04
155648 ----a-w-
c:\windows\syste
17:04
148480 ----a-w-
c:\windows\syste
17:04
13824
----a-w-
c:\windows\syste
17:04
108032 ----a-w-
c:\windows\syste
17:04
82432
----a-w-
c:\windows\syste
17:04
38528
----a-w-
c:\windows\syste
17:04
356352 ----a-w-
c:\windows\syste
17:04
19968
----a-w-
c:\windows\syste
17:04
133632 ----a-w-
c:\windows\syste
17:04
12032
----a-w-
c:\windows\syste
17:04
11264
----a-w-
c:\windows\syste
. . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))
)))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2006-09-14 53248]
"VTTrayp"="VTtrayp.exe" [2007-04-25 176128]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 99740
8]
"Bonus.SSR.FR11"="c:\program files\ABBYY FineReader 11\Bonus.ScreenshotReader.ex
e" [2013-06-27 1364496]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2013-10-28 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-03
435096]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" [2013-10-28 128512]
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer
]
"NoSMHelp"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe AR
M]
2013-04-04 21:06
958576 ----a-wc:\program files\Common Files\Ad
obe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Re
ader Speed Launcher]
2013-05-08 21:20
41056 ----a-wc:\program files\Adobe\Reader 9.
0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Bonus.SS
R.FR11]
2013-06-27 23:51
1364496 ----a-wc:\program files\ABBYY FineReade
r 11\Bonus.ScreenshotReader.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.E
XE]
2013-10-28 16:58
15360 ----a-wc:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DWPersis
tentQueuedReporting]
2008-11-03 23:44
435096 ----a-wc:\program files\Common Files\Mi
crosoft Shared\DW\DWTRIG20.EXE
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Authoriz
edApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\WINDOWS\\System32\\hasplms.exe"=
"c:\\Program Files\\Winamp\\winamp.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Samsung\\Samsung Universal Print Driver 2\\PrinterSelector\\
SUPDApp.exe"=
"c:\\Program Files\\Samsung\\Samsung Universal Print Driver 2 PCL6\\PrinterSelec
tor\\SUPDApp.exe"=
"c:\\Program Files\\Samsung\\Samsung Universal Scan Driver\\ICCUpdater.exe"=
"c:\\Program Files\\Samsung\\Samsung Universal Scan Driver\\ScanCDLM.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSett
ings]
"AllowInboundEchoRequest"= 1 (0x1)
.
R0 mv61xxmm;mv61xxmm;c:\windows\system32\drivers\mv61xxmm.sys [28.10.2013 . 19:01
14184]
R0 mv64xxmm;mv64xxmm;c:\windows\system32\drivers\mv64xxmm.sys [28.10.2013 . 19:01
5632]
R0 mvxxmm;mvxxmm;c:\windows\system32\drivers\mvxxmm.sys [28.10.2013 . 19:01 14184
]
R1 eusk2par;EUTRON SmartKey Parallel Driver;c:\windows\system32\drivers\eusk2par
.sys [15.12.2013 . 17:20 30656]
R2 hasplms;Sentinel HASP License Manager;c:\windows\system32\hasplms.exe -run -> c:\windows\system32\hasplms.exe -run [?]
S2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [19.4.20
13 . 15:14 161384]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D3
45-D564-463c-AFF1-A69D9E530F96}]
2013-12-15 14:58
1210320 ----a-wc:\program files\Google\Chrome\A
pplication\31.0.1650.63\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-12-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-12-15 14:57]
.
2013-12-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-12-15 14:57]
.
2013-12-15 c:\windows\Tasks\MpIdleTask.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2010-11-1
1 10:26]
.
2013-12-15 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2010-11-1
1 10:26]
.
.
------- Supplementary Scan ------.
uStart Page = www.google.bg
IE: & Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000