ComboFix 09-11-30.05 - adam 06/12/2009 10:15.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.2814.2010 [GMT 0:00]
Running from: c:\users\[removed]\Desktop\AdamskyyCF.exe.exe
Command switches used :: /killall
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\tdlclk.dll
.
((((((((((((((((((((((((( Files Created from 2009-11-06 to 2009-12-06 )))))))))))))))))))))))))))))))
.
2009-12-06 10:21 . 2009-12-06 10:22 4096 d-----w- c:\users\adam\AppData\Local\temp
2009-12-06 10:21 . 2009-12-06 10:21 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-12-06 10:21 . 2009-12-06 10:21 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-12-05 11:07 . 2009-12-05 11:07 784136 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-3\SpotlightResources.dll
2009-12-03 15:38 . 2009-10-11 04:17 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-01 19:47 . 2009-12-06 10:14 4096 d-----w- c:\program files\PeerBlock
2009-11-30 14:02 . 2009-11-30 14:02 -------- d-----w- C:\_OTL
2009-11-28 23:14 . 2009-11-28 23:14 -------- d-----w- C:\temp
2009-11-28 23:13 . 2009-11-28 23:13 -------- d-----w- c:\users\adam\AppData\Local\Pinnacle
2009-11-28 23:06 . 2006-04-11 16:03 233472 ------w- c:\windows\system32\DiskIO.dll
2009-11-28 23:06 . 2006-04-11 16:03 184320 ------w- c:\windows\system32\RALMain.dll
2009-11-28 23:06 . 2001-12-11 23:21 73728 ------w- c:\windows\system32\MMAviAx.dll
2009-11-28 23:06 . 2006-07-06 14:32 39936 ------w- c:\windows\system32\CacheX.dll
2009-11-28 23:06 . 2005-12-12 16:57 32768 ------w- c:\windows\system32\MLPagAx.dll
2009-11-28 23:06 . 2004-01-02 13:28 126976 ------w- c:\windows\system32\AVIPrAx.dll
2009-11-28 23:04 . 2005-06-02 19:28 171008 ----a-w- c:\windows\system32\drivers\MarvinBus.sys
2009-11-28 23:02 . 2005-12-21 10:14 19712 ----a-w- c:\windows\system32\drivers\emAudio.sys
2009-11-28 23:00 . 2002-01-05 13:40 487424 ------w- c:\windows\system32\MSVCP70.DLL
2009-11-28 23:00 . 2002-01-05 12:18 84992 ------w- c:\windows\system32\ATL70.DLL
2009-11-28 22:59 . 2009-11-28 23:01 -------- d-----w- c:\programdata\Pinnacle
2009-11-28 22:59 . 2009-11-28 23:00 -------- d-----w- c:\program files\Pinnacle
2009-11-28 22:59 . 2009-11-28 22:59 -------- d-----w- c:\users\adam\AppData\Roaming\InstallShield
2009-11-28 10:38 . 2009-11-28 10:38 -------- d-----w- C:\MGADiagToolOutput
2009-11-28 10:37 . 2009-11-28 10:37 -------- d-----w- c:\programdata\Office Genuine Advantage
2009-11-26 09:59 . 2009-10-29 09:41 2048 ----a-w- c:\windows\system32\tzres.dll
2009-11-25 11:27 . 2009-08-10 11:01 1399296 ----a-w- c:\windows\system32\msxml6.dll
2009-11-25 11:27 . 2009-08-10 11:00 1257472 ----a-w- c:\windows\system32\msxml3.dll
2009-11-24 12:09 . 2009-11-24 12:09 -------- d-----w- c:\users\adam\AppData\Local\Temporary Projects
2009-11-24 11:49 . 2009-11-24 11:49 -------- d-----w- c:\program files\Windows Resource Kits
2009-11-23 21:47 . 2009-11-23 21:47 -------- d-----w- c:\program files\Microsoft Synchronization Services
2009-11-23 21:46 . 2009-11-23 21:46 193824 ----a-w- c:\programdata\Microsoft\VBExpress\9.0\1033\ResourceCache.dll
2009-11-23 21:46 . 2009-11-23 21:46 416 ----a-w- c:\programdata\Microsoft\MSDN\9.0\1033\ResourceCache.dll
2009-11-23 21:45 . 2009-11-23 21:45 -------- d-----w- c:\users\adam\AppData\Local\Microsoft Help
2009-11-23 21:43 . 2009-11-23 21:47 4096 d-----w- c:\program files\Microsoft Visual Studio 9.0
2009-11-23 21:43 . 2009-11-23 21:43 -------- d-----w- c:\program files\Microsoft SDKs
2009-11-21 11:42 . 2009-12-05 21:57 69 ----a-w- c:\users\adam\jagex_runescape_preferences2.dat
2009-11-21 11:42 . 2009-12-05 21:57 39 ----a-w- c:\users\adam\jagex_runescape_preferences.dat
2009-11-21 10:46 . 2009-11-21 10:58 -------- d-----w- c:\users\adam\AppData\Roaming\ImgBurn
2009-11-21 10:36 . 2009-11-21 10:36 4096 d-----w- c:\program files\ImgBurn
2009-11-20 13:43 . 2009-11-19 19:30 497944 ----a-w- c:\programdata\avg9\update\backup\avgchjwx.dll
2009-11-20 13:43 . 2009-11-19 19:30 3963648 ----a-w- c:\programdata\avg9\update\backup\avgcorex.dll
2009-11-20 13:41 . 2009-11-19 19:30 877848 ----a-w- c:\programdata\avg9\update\backup\avgupd.exe
2009-11-20 13:41 . 2009-11-19 19:30 1657112 ----a-w- c:\programdata\avg9\update\backup\avgupd.dll
2009-11-19 19:30 . 2009-11-19 19:35 -------- d-----w- C:\$AVG
2009-11-19 19:30 . 2009-11-19 19:30 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-11-19 19:30 . 2009-11-19 19:30 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-11-19 19:30 . 2009-11-19 19:30 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-11-19 19:30 . 2009-11-19 19:30 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-11-19 19:30 . 2009-12-06 10:14 4096 d-----w- c:\windows\system32\drivers\Avg
2009-11-19 19:30 . 2009-11-19 19:30 -------- d-----w- c:\program files\AVG
2009-11-19 19:30 . 2009-12-02 12:30 4096 d-----w- c:\programdata\avg9
2009-11-19 18:40 . 2009-11-19 18:40 -------- d-----w- c:\programdata\Kaspersky Lab Setup Files
2009-11-19 17:58 . 2009-11-19 17:58 -------- d-----w- c:\program files\Trend Micro
2009-11-19 16:36 . 2009-08-14 13:53 2035712 ----a-w- c:\windows\system32\win32k.sys
2009-11-19 16:35 . 2009-11-02 20:42 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-11-18 21:06 . 2009-11-18 21:16 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-11-18 21:06 . 2009-11-18 21:06 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-11-18 20:45 . 2009-11-18 20:45 -------- d-----w- c:\users\adam\AppData\Roaming\Malwarebytes
2009-11-18 20:45 . 2009-11-18 20:45 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-18 20:45 . 2009-11-18 20:45 -------- d-----w- c:\programdata\Malwarebytes
2009-11-15 20:29 . 2009-11-15 20:29 -------- d-----w- c:\program files\Quantum
2009-11-13 13:33 . 2009-11-13 13:33 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-11-11 13:53 . 2009-11-11 13:53 -------- d-----w- c:\users\adam\AppData\Local\LogiShrd
2009-11-11 13:52 . 2009-11-11 13:52 -------- d-----w- c:\users\adam\AppData\Roaming\Leadertech
2009-11-11 13:49 . 2009-11-12 14:50 -------- d-----w- c:\programdata\LogiShrd
2009-11-11 13:49 . 2009-11-11 13:52 -------- d-----w- c:\program files\Logitech
2009-11-11 11:28 . 2009-08-10 13:05 351232 ----a-w- c:\windows\system32\WSDApi.dll
2009-11-11 11:28 . 2009-08-10 13:05 351232 ----a-w- c:\windows\system32\WSDApi(543).dll
2009-11-09 22:03 . 2009-11-09 22:04 -------- d-----w- c:\program files\Web Site Change Monitor
2009-11-06 20:26 . 2009-11-25 16:49 -------- d-----w- C:\Games
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-06 10:24 . 2009-10-08 13:28 4096 d-----w- c:\users\adam\AppData\Roaming\Skype
2009-12-06 10:22 . 2009-11-30 14:10 0 ----a-w- c:\windows\system32\drivers\lvuvc.hs
2009-12-06 10:06 . 2009-10-08 13:30 4096 d-----w- c:\users\adam\AppData\Roaming\skypePM
2009-12-03 16:11 . 2009-10-25 12:07 12288 d-----w- c:\program files\SwiftKit
2009-12-03 15:38 . 2009-10-06 13:41 -------- d-----w- c:\program files\Java
2009-12-02 12:11 . 2009-10-03 17:43 4096 d-----w- c:\users\adam\AppData\Roaming\mIRC
2009-12-02 11:55 . 2009-10-03 17:43 4096 d-----w- c:\program files\mIRC
2009-11-29 11:46 . 2009-10-12 14:19 4096 d-----w- c:\users\adam\AppData\Roaming\vlc
2009-11-28 23:11 . 2009-10-05 16:13 79904 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2009-11-28 23:00 . 2009-01-09 18:12 8192 d--h--w- c:\program files\InstallShield Installation Information
2009-11-25 11:30 . 2009-10-06 12:21 784120 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-11-23 21:47 . 2009-10-08 14:40 -------- d-----w- c:\program files\Microsoft SQL Server
2009-11-23 21:47 . 2009-01-09 18:50 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-11-23 21:47 . 2009-01-09 18:30 12288 d-----w- c:\programdata\Microsoft Help
2009-11-20 21:21 . 2006-11-02 11:18 4096 d-----w- c:\program files\Windows Mail
2009-11-20 14:43 . 2009-01-09 19:00 4096 d-----w- c:\program files\Acer GameZone
2009-11-20 13:45 . 2009-10-11 21:13 -------- d-----w- c:\program files\freebird
2009-11-19 18:48 . 2009-01-09 18:38 4096 d-----w- c:\program files\McAfee
2009-11-19 18:48 . 2009-01-09 18:37 4096 d-----w- c:\programdata\McAfee
2009-11-19 16:16 . 2009-10-03 15:31 8224 ----a-w- c:\users\adam\AppData\Local\GDIPFONTCACHEV1.DAT
2009-11-19 16:11 . 2009-01-09 18:32 32768 d-----w- c:\program files\Microsoft Works
2009-11-19 16:11 . 2009-10-03 19:26 4096 d-----w- c:\program files\Common Files\logishrd
2009-11-17 16:13 . 2009-10-17 16:10 -------- d-----w- c:\users\adam\AppData\Roaming\Pamela
2009-11-07 11:56 . 2009-10-21 17:37 4096 d-----w- c:\users\adam\AppData\Roaming\Vso
2009-11-02 16:28 . 2009-11-02 16:28 -------- d-----w- c:\program files\CCleaner
2009-11-02 13:43 . 2009-01-09 18:45 4096 d-----w- c:\program files\Google
2009-11-01 12:03 . 2009-11-01 12:03 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll
2009-11-01 11:04 . 2009-10-11 10:23 -------- d-----w- c:\program files\Yahoo!
2009-11-01 11:02 . 2009-10-17 16:02 4096 d-----w- c:\program files\HotRecorder
2009-11-01 11:00 . 2009-10-20 17:21 4096 d-----w- c:\program files\Free DVD Creator
2009-11-01 11:00 . 2009-10-13 13:06 4096 d-----w- c:\program files\Freecorder
2009-10-25 12:07 . 2009-10-25 12:07 -------- d-----w- c:\programdata\SwiftKit
2009-10-23 14:08 . 2009-10-23 14:08 4096 d-----w- c:\program files\DivX
2009-10-23 14:08 . 2009-10-23 14:08 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-10-22 12:03 . 2009-10-21 18:24 4096 d-----w- c:\programdata\vsosdk
2009-10-21 17:37 . 2009-10-21 17:37 47360 ----a-w- c:\windows\system32\drivers\pcouffin.sys
2009-10-21 17:37 . 2009-10-21 17:37 47360 ----a-w- c:\users\adam\AppData\Roaming\pcouffin.sys
2009-10-21 17:37 . 2009-10-21 17:37 47360 ----a-w- c:\users\adam\AppData\Roaming\pcouffin.sys
2009-10-21 17:37 . 2009-10-21 17:37 -------- d-----w- c:\program files\VSO
2009-10-20 17:37 . 2009-10-20 17:21 8192 d-----w- c:\program files\ffdshow
2009-10-20 17:14 . 2009-10-20 17:14 -------- d-----w- c:\users\adam\AppData\Roaming\Broad Intelligence
2009-10-20 17:14 . 2009-10-20 17:13 4096 d-----w- c:\program files\MediaCoder
2009-10-20 16:54 . 2009-10-20 16:54 59992 ----a-w- c:\programdata\Kaspersky Lab Setup Files\Kaspersky Internet Security 2010 9.0.0.736\English\setup.exe
2009-10-17 16:10 . 2009-10-17 16:10 4096 d-----w- c:\program files\Pamela
2009-10-17 16:10 . 2009-10-17 16:10 155136 ----a-w- c:\windows\system32\RemoteControl.dll
2009-10-17 15:57 . 2009-10-13 13:06 737280 ----a-w- c:\windows\iun6002.exe
2009-10-17 15:55 . 2009-10-17 15:48 4096 d-----w- c:\users\adam\AppData\Roaming\Call Graph
2009-10-17 15:50 . 2009-10-17 15:50 -------- d-----w- c:\users\adam\AppData\Roaming\Sedna Wireless
2009-10-17 15:48 . 2009-10-17 15:48 4096 d-----w- c:\program files\Call Graph
2009-10-14 21:29 . 2009-10-14 21:24 4096 d-----w- c:\program files\Acez Mp3 Wav Converter
2009-10-14 21:03 . 2009-10-14 21:03 -------- d-----w- c:\program files\Common Files\SWF Studio
2009-10-12 14:18 . 2009-10-12 14:18 -------- d-----w- c:\program files\VideoLAN
2009-10-11 21:20 . 2009-10-11 21:20 -------- d-----w- c:\users\adam\AppData\Roaming\Screaming Bee
2009-10-08 15:00 . 2009-10-08 15:00 -------- d-----w- c:\users\adam\AppData\Roaming\Publish Providers
2009-10-08 15:00 . 2009-10-08 14:39 -------- d-----w- c:\users\adam\AppData\Roaming\Sony
2009-10-08 14:39 . 2009-10-08 14:38 -------- d-----w- c:\programdata\Sony
2009-10-08 14:38 . 2009-10-08 14:38 -------- d-----w- c:\program files\Vstplugins
2009-10-08 14:37 . 2009-10-08 14:37 -------- d-----w- c:\program files\Sony
2009-10-08 14:35 . 2009-10-08 14:35 -------- d-----w- c:\program files\Sony Setup
2009-10-08 13:30 . 2009-10-08 13:30 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-10-08 13:28 . 2009-10-08 13:27 -------- d-----r- c:\program files\Skype
2009-10-08 13:27 . 2009-10-08 13:27 -------- d-----w- c:\program files\Common Files\Skype
2009-10-08 13:27 . 2009-10-08 13:21 -------- d-----w- c:\programdata\Skype
2009-10-06 12:21 . 2009-10-06 12:21 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll
2009-10-03 21:03 . 2009-10-03 21:02 108 ----a-w- c:\programdata\Last.fm\Client\uninst2.bat
2009-10-03 21:03 . 2009-10-03 21:03 683801 ----a-w- c:\programdata\Last.fm\Client\UninstWMP\unins000.exe
2009-10-03 21:02 . 2009-10-03 21:02 683801 ----a-w- c:\programdata\Last.fm\Client\UninstITW\unins000.exe
2009-10-03 19:02 . 2009-10-03 19:02 4096 ----a-w- c:\windows\d3dx.dat
2009-10-03 17:26 . 2009-10-03 17:26 17801 ----a-w- c:\windows\system32\drivers\AegisP.sys
2009-10-03 16:23 . 2009-10-03 16:23 0 ----a-w- c:\windows\nsreg.dat
2009-09-21 16:09 . 2009-09-21 16:09 79144 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.1.8\SetupAdmin.exe
2009-09-16 09:22 . 2009-01-09 18:40 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-09-16 09:22 . 2009-01-09 18:40 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-09-16 09:22 . 2009-01-09 18:40 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-09-16 09:22 . 2009-01-09 18:40 214664 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-09-16 09:22 . 2009-01-09 18:40 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys
2009-09-14 09:44 . 2009-10-16 13:16 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2009-09-10 20:45 . 2009-10-28 09:38 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-09-10 20:45 . 2009-10-28 09:38 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-09-10 17:30 . 2009-10-16 13:17 213504 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-10 15:24 . 2009-10-28 09:38 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-09-10 15:21 . 2009-10-28 09:38 310784 ----a-w- c:\windows\system32\unregmp2.exe
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-12-01_13.55.34 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-21 01:58 . 2009-12-06 10:24 58448 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-12-06 10:24 85510 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2009-10-03 23:22 . 2009-12-01 11:43 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-10-03 23:22 . 2009-12-06 10:09 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-10-03 23:22 . 2009-12-06 10:09 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-10-03 23:22 . 2009-12-01 11:43 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-10-03 23:22 . 2009-12-06 10:09 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-10-03 23:22 . 2009-12-01 11:43 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-11-27 15:39 . 2009-11-30 14:11 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-11-27 15:39 . 2009-12-06 10:22 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-11-27 15:39 . 2009-11-30 14:11 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-11-27 15:39 . 2009-12-06 10:22 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-11-27 15:39 . 2009-12-06 10:22 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-11-27 15:39 . 2009-11-30 14:11 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-11-27 13:39 . 2009-12-06 10:22 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-11-27 13:39 . 2009-12-01 11:43 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-11-27 13:39 . 2009-12-01 11:43 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-11-27 13:39 . 2009-12-06 10:22 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-11-27 13:39 . 2009-12-01 11:43 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-11-27 13:39 . 2009-12-06 10:22 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-10-25 12:10 . 2009-12-01 11:59 49152 c:\windows\.jagex_cache_32\runescape\jagmisc.dll
+ 2009-10-25 12:10 . 2009-12-05 21:56 49152 c:\windows\.jagex_cache_32\runescape\jagmisc.dll
+ 2009-10-25 12:10 . 2009-12-05 21:56 81920 c:\windows\.jagex_cache_32\runescape\jaggl.dll
- 2009-10-25 12:10 . 2009-12-01 11:59 81920 c:\windows\.jagex_cache_32\runescape\jaggl.dll
+ 2009-10-03 15:30 . 2009-12-06 10:24 8808 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-887134994-1243305392-2542070696-1000_UserData.bin
- 2009-12-01 11:43 . 2009-12-01 11:43 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-12-06 10:22 . 2009-12-06 10:22 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-12-01 11:43 . 2009-12-01 11:43 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-12-06 10:22 . 2009-12-06 10:22 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2006-11-02 10:33 . 2009-12-06 10:10 617772 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-12-01 11:48 617772 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-12-01 11:48 113132 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:33 . 2009-12-06 10:10 113132 c:\windows\System32\perfc009.dat
+ 2009-12-03 15:38 . 2009-10-11 04:17 149280 c:\windows\System32\javaws.exe
+ 2009-12-03 15:38 . 2009-10-11 04:17 145184 c:\windows\System32\javaw.exe
+ 2009-12-03 15:38 . 2009-10-11 04:17 145184 c:\windows\System32\java.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2008-07-30 01:52 121392 ----a-w- c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-07-03 135680]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-09-02 25623336]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"PeerBlock"="c:\program files\PeerBlock\peerblock.exe" [2009-09-28 1529432]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"Acer Empowering Technology Monitor"="c:\program files\Acer\Empowering Technology\SysMonitor.exe" [2008-10-01 319488]
"eDataSecurity Loader"="c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe" [2008-07-30 526896]
"PCMMediaSharing"="c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe" [2008-05-21 204908]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-08 13584928]
"wltray.exe"="c:\windows\system32\wltray.exe" [2005-01-29 696422]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2009-11-19 2020120]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-03-26 5369856]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [19/11/2009 19:30 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\System32\drivers\avgtdix.sys [19/11/2009 19:30 360584]
R2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [09/01/2009 18:54 269448]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [19/11/2009 19:30 906520]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [19/11/2009 19:30 285392]
R2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [09/01/2009 18:29 24576]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [23/09/2008 22:11 144632]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\System32\drivers\nvhda32v.sys [09/01/2009 16:50 43552]
R3 pbfilter;pbfilter;c:\program files\PeerBlock\pbfilter.sys [01/12/2009 19:47 16472]
R3 VCSVADHWSer;Avnex Virtual Audio Device (WDM);c:\windows\System32\drivers\vcsvad.sys [11/10/2009 21:02 17792]
S2 0201691259589367mcinstcleanup;McAfee Application Installer Cleanup (0201691259589367);c:\users\adam\AppData\Local\Temp\020169~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service --> c:\users\adam\AppData\Local\Temp\020169~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service [?]
S3 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [23/09/2008 22:11 50424]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\System32\drivers\ScreamingBAudio.sys [06/04/2009 12:19 23064]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://homepage.acer.com/rdr.aspx?b=ACA ... pire_x3200
mStart Page =
hxxp://homepage.acer.com/rdr.aspx?b=ACA ... pire_x3200
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) =
hxxp://www.google.com/search/?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: %SYSTEMROOT%\system32\nvLsp.dll
FF - ProfilePath - c:\users\adam\AppData\Roaming\Mozilla\Firefox\Profiles\nfqifbzn.default\
FF - prefs.js: browser.startup.homepage -
hxxp://facebook.com
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-12-06 10:22
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\users\adam\AppData\Roaming\Microsoft\Windows\Cookies\adam@msn[3].txt 394 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(5148)
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\sysenv.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\rundll32.exe
c:\windows\System32\wltrysvc.exe
c:\windows\System32\bcmwltry.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\bin32\nSvcAppFlt.exe
c:\program files\bin32\nSvcIp.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\WUDFHost.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\AVG\AVG9\avgtray.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\ehome\ehsched.exe
c:\windows\ehome\ehRecvr.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Windows Live\Contacts\wlcomm.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\windows\servicing\TrustedInstaller.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
.
**************************************************************************
.
Completion time: 2009-12-06 10:27 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-06 10:27
ComboFix2.txt 2009-12-01 13:59
Pre-Run: 88,600,170,496 bytes free
Post-Run: 88,558,227,456 bytes free
- - End Of File - - A139F4CAB710C312776B1F4A87804943