ComboFix 11-03-21.02 - owner 03/22/2011 1:20.3.2 - x64 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3835.2217 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\owner\Desktop\CFScript.txt AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . FILE :: "c:\users\owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\4604e10c-69294775" . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\owner\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12\4604e10c-69294775 c:\users\owner\AppData\Roaming\Edsa c:\users\owner\AppData\Roaming\Edsa\ufno.igo c:\users\owner\AppData\Roaming\Edsa\ufno.tmp c:\users\owner\AppData\Roaming\Ilxiih . . ((((((((((((((((((((((((( Files Created from 2011-02-22 to 2011-03-22 ))))))))))))))))))))))))))))))) . . 2011-03-22 05:25 . 2011-03-22 05:25 -------- d-----w- c:\users\Default\AppData\Local\temp 2011-03-22 05:25 . 2011-03-22 05:25 -------- d-----w- c:\users\Administrator\AppData\Local\temp 2011-03-21 03:27 . 2011-03-21 03:27 -------- d-----w- c:\users\owner\AppData\Roaming\Foxit Software 2011-03-20 19:36 . 2011-03-20 19:36 -------- d-----w- c:\program files (x86)\ESET 2011-03-20 19:17 . 2011-03-20 19:17 -------- d-----w- c:\program files (x86)\Foxit Software 2011-03-20 18:25 . 2011-03-20 18:25 521448 ----a-w- c:\windows\system32\deployJava1.dll 2011-03-20 18:21 . 2011-03-20 18:25 -------- d-----w- c:\program files\Java 2011-03-20 09:52 . 2011-03-20 09:52 -------- d-----w- c:\users\owner\AppData\Local\PackageAware 2011-03-20 09:42 . 2011-02-23 13:54 22360 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2011-03-20 09:42 . 2011-02-23 13:57 280408 ----a-w- c:\windows\system32\drivers\aswSP.sys 2011-03-20 09:42 . 2011-02-23 13:55 31064 ----a-w- c:\windows\system32\drivers\aswRdr.sys 2011-03-20 09:42 . 2011-02-23 13:55 53592 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2011-03-20 09:42 . 2011-02-23 13:57 505176 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2011-03-20 09:42 . 2011-02-23 14:04 238968 ----a-w- c:\windows\system32\aswBoot.exe 2011-03-20 09:42 . 2011-02-23 13:55 64344 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys 2011-03-20 09:41 . 2011-02-23 14:04 40648 ----a-w- c:\windows\avastSS.scr 2011-03-20 09:41 . 2011-02-23 14:04 190016 ----a-w- c:\windows\SysWow64\aswBoot.exe 2011-03-20 05:21 . 2011-02-23 14:34 7947600 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7D9E9236-850A-426B-BA6A-CFEC24EBA769}\mpengine.dll 2011-03-20 05:21 . 2011-02-02 22:11 270720 ------w- c:\windows\system32\MpSigStub.exe 2011-03-20 05:09 . 2011-03-20 05:10 -------- d-----w- c:\users\owner\AppData\Local\{F339BE28-CD7A-48C1-8959-545CF9276501} 2011-03-20 04:59 . 2011-03-20 04:59 -------- d-----w- c:\users\owner\AppData\Local\{51DE741F-DBF0-423B-A6E1-7A5A35526CA6} 2011-03-17 23:31 . 2011-03-17 23:31 -------- d-----w- c:\users\owner\AppData\Local\{44FC9DB8-CBFE-43C8-A1C7-53B2A1B9CAB2} 2011-03-17 15:26 . 2011-03-17 15:26 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help 2011-03-16 17:18 . 2011-03-16 17:18 -------- d-----w- c:\users\owner\AppData\Local\{1BE13328-3076-47CF-8927-21FF8D10553D} 2011-03-16 03:40 . 2010-12-23 06:07 961024 ----a-w- c:\windows\system32\CPFilters.dll 2011-03-16 03:40 . 2010-12-23 06:07 723968 ----a-w- c:\windows\system32\EncDec.dll 2011-03-16 03:40 . 2010-12-23 05:28 642048 ----a-w- c:\windows\SysWow64\CPFilters.dll 2011-03-16 03:40 . 2010-12-23 05:28 534528 ----a-w- c:\windows\SysWow64\EncDec.dll 2011-03-16 03:40 . 2010-12-23 06:07 1118720 ----a-w- c:\windows\system32\sbe.dll 2011-03-16 03:40 . 2010-12-23 06:02 259072 ----a-w- c:\windows\system32\mpg2splt.ax 2011-03-16 03:40 . 2010-12-23 05:28 850432 ----a-w- c:\windows\SysWow64\sbe.dll 2011-03-16 03:40 . 2010-12-23 05:24 199680 ----a-w- c:\windows\SysWow64\mpg2splt.ax 2011-03-16 03:36 . 2010-12-18 06:12 3138048 ----a-w- c:\windows\system32\mstscax.dll 2011-03-16 03:36 . 2010-12-18 06:08 1097216 ----a-w- c:\windows\system32\mstsc.exe 2011-03-16 03:36 . 2010-12-18 05:30 2690560 ----a-w- c:\windows\SysWow64\mstscax.dll 2011-03-16 03:36 . 2010-12-18 05:26 1034240 ----a-w- c:\windows\SysWow64\mstsc.exe 2011-03-16 01:11 . 2011-03-16 01:12 -------- d-----w- c:\users\owner\AppData\Local\{47636113-E78C-4893-A27F-51EF54D7254F} 2011-03-14 18:47 . 2011-03-14 18:47 -------- d-----w- c:\users\owner\AppData\Local\{1CA49548-73AD-4B1F-9B83-8017D5584405} 2011-03-14 17:22 . 2011-03-14 17:22 -------- d-----w- c:\users\owner\AppData\Local\{E4B7AC7A-648B-4BBD-8D20-77781E620329} 2011-03-14 16:30 . 2011-03-14 16:30 -------- d-----w- c:\users\owner\AppData\Local\{F7404033-7FCD-4D6E-A70A-A65853A5F5C8} 2011-03-14 16:11 . 2011-03-14 16:11 -------- d-----w- c:\users\owner\AppData\Local\ElevatedDiagnostics 2011-03-14 15:36 . 2011-03-14 15:36 -------- d-----w- c:\users\owner\AppData\Roaming\SUPERAntiSpyware.com 2011-03-14 15:36 . 2011-03-14 15:36 -------- d-----w- c:\programdata\SUPERAntiSpyware.com 2011-03-14 15:15 . 2011-03-14 15:15 -------- d-----w- c:\users\owner\AppData\Local\{53B9C53E-9891-4385-96B2-A0DFECA6EEF4} 2011-03-13 05:16 . 2011-03-13 05:16 -------- d-----w- c:\program files (x86)\Common Files\Skype 2011-03-12 16:26 . 2011-03-12 16:26 -------- d-----w- c:\users\owner\AppData\Local\{04E20523-9BB1-47AA-82A8-3E949699C4F0} 2011-03-11 20:58 . 2011-03-11 20:58 -------- d-----w- c:\users\owner\AppData\Local\{22FA4431-DD73-4937-B25D-6B2177778E87} 2011-03-11 00:30 . 2011-03-11 00:31 -------- d-----w- c:\users\owner\AppData\Local\{51B30190-5E90-4B6E-B577-74830DA6F852} 2011-03-07 23:39 . 2011-03-07 23:39 -------- d-----w- c:\users\owner\AppData\Local\{3197B8B4-7814-40A5-8BC7-69598DB519E1} 2011-03-07 08:32 . 2011-03-07 08:32 -------- d-----w- c:\users\owner\AppData\Local\{423BDB21-3FC6-4EC8-82AA-42877B39BDE5} 2011-03-06 03:39 . 2011-03-06 03:39 -------- d-----w- c:\programdata\AVAST Software 2011-03-06 03:39 . 2011-03-06 03:39 -------- d-----w- c:\program files\AVAST Software 2011-03-05 11:52 . 2011-03-05 11:52 -------- d-----w- c:\users\owner\AppData\Local\{0A20BECB-A2F3-48C2-8F9F-5231A0C002BF} 2011-02-27 16:25 . 2011-02-27 16:25 -------- d-----w- c:\users\owner\AppData\Local\{8D2DB7A5-D855-4E2E-953D-142A17980B08} 2011-02-27 06:12 . 2011-02-27 06:12 -------- d-----w- c:\users\owner\AppData\Local\{1F698C1B-697F-47CE-A7BD-B9171C78B6AF} 2011-02-27 02:04 . 2011-02-27 02:04 -------- d-----w- c:\programdata\Hewlett-Packard 2011-02-27 02:04 . 2009-07-14 01:41 230400 ----a-w- c:\windows\system32\Spool\prtprocs\x64\hpzppw71.dll 2011-02-24 00:35 . 2010-09-14 06:45 367104 ----a-w- c:\windows\system32\wcncsvc.dll 2011-02-24 00:35 . 2010-09-14 06:07 276992 ----a-w- c:\windows\SysWow64\wcncsvc.dll 2011-02-23 02:52 . 2011-02-23 02:52 -------- d-----w- c:\users\owner\AppData\Roaming\Rockwell Software 2011-02-23 02:52 . 2011-02-23 02:52 -------- d-----w- c:\programdata\Rockwell Automation 2011-02-23 02:51 . 2011-02-23 02:51 -------- d-----w- c:\programdata\Rockwell Software 2011-02-23 02:50 . 2011-02-23 02:50 -------- d-----w- c:\program files (x86)\Common Files\Crystal Decisions 2011-02-23 02:50 . 2011-02-23 02:50 -------- d-----w- c:\program files (x86)\Rockwell Software 2011-02-23 01:10 . 2011-01-07 07:31 442880 ----a-w- c:\windows\SysWow64\XpsPrint.dll 2011-02-23 01:10 . 2011-01-07 08:07 662528 ----a-w- c:\windows\system32\XpsPrint.dll 2011-02-23 01:10 . 2011-01-07 08:07 475648 ----a-w- c:\windows\system32\XpsGdiConverter.dll 2011-02-23 01:10 . 2011-01-07 07:31 288256 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-03-11 20:57 . 2010-06-24 16:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2011-01-27 20:16 . 2011-01-27 20:16 254528 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys 2011-01-26 06:53 . 2011-02-08 23:37 982912 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys 2011-01-26 06:53 . 2011-02-08 23:37 265088 ----a-w- c:\windows\system32\drivers\dxgmms1.sys 2011-01-26 06:31 . 2011-02-08 23:37 144384 ----a-w- c:\windows\system32\cdd.dll 2011-01-07 08:06 . 2011-02-08 23:37 46080 ----a-w- c:\windows\system32\atmlib.dll 2011-01-07 07:27 . 2011-02-08 23:37 34304 ----a-w- c:\windows\SysWow64\atmlib.dll 2011-01-07 05:49 . 2011-02-08 23:37 366080 ----a-w- c:\windows\system32\atmfd.dll 2011-01-07 05:33 . 2011-02-08 23:37 294400 ----a-w- c:\windows\SysWow64\atmfd.dll 2011-01-05 06:20 . 2011-02-08 23:37 612352 ----a-w- c:\windows\system32\vbscript.dll 2011-01-05 05:37 . 2011-02-08 23:37 428032 ----a-w- c:\windows\SysWow64\vbscript.dll 2011-01-05 04:00 . 2011-02-08 23:37 3127808 ----a-w- c:\windows\system32\win32k.sys . . ((((((((((((((((((((((((((((( SnapShot@2011-03-20_08.57.07 ))))))))))))))))))))))))))))))))))))))))) . + 2009-07-14 04:54 . 2011-03-22 02:38 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2009-07-14 04:54 . 2011-02-20 16:35 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2009-07-14 04:54 . 2011-03-22 02:38 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-07-14 04:54 . 2011-02-20 16:35 32768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2009-07-14 04:54 . 2011-02-20 16:35 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 04:54 . 2011-03-22 02:38 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2009-07-14 05:10 . 2011-03-20 18:03 40932 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin + 2011-01-26 22:01 . 2011-03-20 18:02 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2011-01-26 22:01 . 2011-03-20 05:26 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2009-07-14 04:46 . 2011-03-20 18:09 78720 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat - 2011-01-26 22:01 . 2011-03-20 05:26 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2011-01-26 22:01 . 2011-03-20 18:02 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2011-01-26 22:01 . 2011-03-20 18:02 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2011-01-26 22:01 . 2011-03-20 05:26 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2011-01-26 15:57 . 2011-03-21 00:21 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2011-01-26 15:57 . 2011-03-20 06:04 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2011-01-26 15:57 . 2011-03-21 00:21 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2011-01-26 15:57 . 2011-03-20 06:04 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2011-03-20 07:01 . 2011-03-20 07:01 49936 c:\windows\Installer\{95120000-00AF-0409-0000-0000000FF1CE}\ppvwicon.exe + 2011-03-21 13:00 . 2011-03-21 13:00 49936 c:\windows\Installer\{95120000-00AF-0409-0000-0000000FF1CE}\ppvwicon.exe - 2011-03-20 07:00 . 2011-03-20 07:00 35600 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe + 2011-03-21 12:59 . 2011-03-21 12:59 35600 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe + 2009-04-02 18:35 . 2009-04-02 18:35 16712 c:\windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6425\PXBPROXY.DLL + 2009-04-02 18:35 . 2009-04-02 18:35 68496 c:\windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6425\PXBCOM.EXE + 2011-01-26 16:20 . 2011-03-20 18:03 9356 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1341990520-4231836248-1779624025-1000_UserData.bin + 2011-03-20 18:01 . 2011-03-20 18:01 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2011-03-20 05:26 . 2011-03-20 05:26 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2011-03-20 18:01 . 2011-03-20 18:01 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2011-03-20 05:26 . 2011-03-20 05:26 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2011-01-26 17:55 . 2011-03-22 02:18 264488 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin - 2009-07-14 02:36 . 2011-03-20 06:05 624178 c:\windows\system32\perfh009.dat + 2009-07-14 02:36 . 2011-03-22 01:13 624178 c:\windows\system32\perfh009.dat + 2009-07-14 02:36 . 2011-03-22 01:13 106522 c:\windows\system32\perfc009.dat - 2009-07-14 02:36 . 2011-03-20 06:05 106522 c:\windows\system32\perfc009.dat + 2011-03-20 18:25 . 2011-03-20 18:25 189728 c:\windows\system32\javaws.exe + 2011-03-20 18:25 . 2011-03-20 18:25 171808 c:\windows\system32\javaw.exe + 2011-03-20 18:25 . 2011-03-20 18:25 171808 c:\windows\system32\java.exe + 2009-07-14 05:01 . 2011-03-20 10:22 307364 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat - 2009-07-14 05:01 . 2011-03-20 05:25 307364 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat + 2011-01-30 05:04 . 2011-03-20 10:22 615220 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1341990520-4231836248-1779624025-1000-8192.dat - 2011-01-30 05:04 . 2011-03-20 05:25 615220 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1341990520-4231836248-1779624025-1000-8192.dat + 2011-03-20 18:24 . 2011-03-20 18:24 683008 c:\windows\Installer\bf21e.msi + 2011-03-20 18:21 . 2011-03-20 18:21 528384 c:\windows\Installer\bf21a.msi + 2009-04-24 16:31 . 2009-04-24 16:31 1425920 c:\windows\Installer\412e79d.msp + 2009-04-02 18:35 . 2009-04-02 18:35 1787216 c:\windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6425\PPCNV.DLL - 2009-07-14 02:34 . 2011-03-20 07:12 10223616 c:\windows\system32\SMI\Store\Machine\schema.dat + 2009-07-14 02:34 . 2011-03-21 22:56 10223616 c:\windows\system32\SMI\Store\Machine\schema.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}] 2010-12-09 17:51 3911776 ----a-w- c:\program files (x86)\ConduitEngine\ConduitEngine.dll . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}] 2011-01-20 22:59 1487240 ----a-w- c:\program files (x86)\Ask.com\GenericAskToolbar.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files (x86)\ConduitEngine\ConduitEngine.dll" [2010-12-09 3911776] "{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files (x86)\Ask.com\GenericAskToolbar.dll" [2011-01-20 1487240] . [HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}] . [HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1] [HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}] [HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd] . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2011-01-20 1305408] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-03-15 98304] "ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-10-06 1294136] "TWebCamera"="c:\program files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2010-02-24 2454840] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-02-23 3451496] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . R1 SASDIFSV;SASDIFSV;c:\users\owner\AppData\Local\Temp\SAS_SelfExtract\SASDIFSV64.SYS [x] R1 SASKUTIL;SASKUTIL;c:\users\owner\AppData\Local\Temp\SAS_SelfExtract\SASKUTIL64.SYS [x] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R3 dc3d;MS Hardware Device Detection Driver;c:\windows\system32\DRIVERS\dc3d.sys [x] R3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [x] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x] R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL6.SYS [x] R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV6.SYS [x] R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT6.SYS [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x] S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2010-02-26 252928] S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [x] S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [x] S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x] S3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [x] S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x] S3 QIOMem;Generic IO & Memory Access;c:\windows\system32\DRIVERS\QIOMem.sys [x] S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys [x] S3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 51512] S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-06 137560] S3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2010-02-24 835952] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x] . . --- Other Services/Drivers In Memory --- . *NewlyCreated* - ASWSNX . . --------- x86-64 ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2011-02-23 14:04 134384 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2010-01-29 517176] "SmartAudio"="c:\program files\CONEXANT\SAII\SAIICpl.exe" [2009-11-19 307768] "SynTPEnh"="%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe" [BU] "TPwrMain"="%ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE" [BU] "HSON"="%ProgramFiles%\TOSHIBA\TBS\HSON.exe" [BU] "SmoothView"="%ProgramFiles%\Toshiba\SmoothView\SmoothView.exe" [BU] "00TCrdMain"="%ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe" [BU] "TosWaitSrv"="%ProgramFiles%\TOSHIBA\TPHM\TosWaitSrv.exe" [BU] "Teco"="%ProgramFiles%\TOSHIBA\TECO\Teco.exe" [BU] "SmartFaceVWatcher"="%ProgramFiles%\Toshiba\SmartFaceV\SmartFaceVWatcher.exe" [BU] "TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376] "TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2010-02-06 709976] "TosNC"="%ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe" [BU] "TosReelTimeMonitor"="%ProgramFiles%\TOSHIBA\ReelTime\TosReelTimeMonitor.exe" [BU] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2010-07-21 2327952] . ------- Supplementary Scan ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com/ig?brand=TSNA&bmod=TSNA mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA mLocal Page = c:\windows\SYSTEM32\blank.htm uInternet Settings,ProxyOverride = IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~4\Office12\EXCEL.EXE/3000 FF - ProfilePath - c:\users\owner\AppData\Roaming\Mozilla\Firefox\Profiles\mvk2feeq.default\ FF - prefs.js: network.proxy.type - 0 FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: avast! WebRep: [removed] - c:\program files\AVAST Software\Avast\WebRep\FF . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file) . . . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_USERS\S-1-5-21-1341990520-4231836248-1779624025-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.Email.1" . [HKEY_USERS\S-1-5-21-1341990520-4231836248-1779624025-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice] @Denied: (2) (LocalSystem) "Progid"="WindowsLiveMail.VCard.1" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2011-03-22 01:26:48 ComboFix-quarantined-files.txt 2011-03-22 05:26 ComboFix2.txt 2011-03-20 19:33 ComboFix3.txt 2011-03-20 08:58 . Pre-Run: 258,299,301,888 bytes free Post-Run: 258,252,226,560 bytes free . - - End Of File - - 7657FACE4A68FED943348D2721919DE8