I have 4 gigs of ram which should be more than enough to keep it fast.
*****************************************************
This is the copy of the
Take 4 log.......
ComboFix 10-06-17.02 - Micheal 18/06/2010 16:02:46.4.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.61.1033.18.3326.1806 [GMT 10:00]
Running from: c:\users\Micheal\Desktop\ComboFix.exe
Command switches used :: c:\users\Micheal\Desktop\CFScript.txt
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\win.com
.
--------------- FCopy ---------------
c:\windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys --> c:\windows\System32\drivers\atapi.sys
.
((((((((((((((((((((((((( Files Created from 2010-05-18 to 2010-06-18 )))))))))))))))))))))))))))))))
.
2010-06-18 06:07 . 2010-06-18 06:07 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2010-06-18 06:07 . 2010-06-18 06:07 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-06-18 06:07 . 2010-06-18 06:07 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-06-18 06:01 . 2010-06-18 06:01 -------- d-----w- C:\32788R22FWJFW
2010-06-17 05:33 . 2010-06-17 05:33 -------- d-----w- c:\program files\Windows Portable Devices
2010-06-16 10:02 . 2009-09-04 07:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2010-06-16 10:02 . 2009-09-04 07:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll
2010-06-16 10:00 . 2009-10-01 01:02 30208 ----a-w- c:\windows\system32\WPDShextAutoplay.exe
2010-06-16 09:57 . 2010-06-16 09:57 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2010-06-16 09:51 . 2010-02-20 23:06 24064 ----a-w- c:\windows\system32\nshhttp.dll
2010-06-16 09:51 . 2010-02-20 23:05 30720 ----a-w- c:\windows\system32\httpapi.dll
2010-06-16 09:51 . 2010-02-20 20:53 411648 ----a-w- c:\windows\system32\drivers\http.sys
2010-06-16 09:48 . 2009-10-19 13:38 156672 ----a-w- c:\windows\system32\t2embed.dll
2010-06-16 09:47 . 2009-12-11 11:43 302080 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-16 09:47 . 2009-12-11 11:43 98816 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-06-16 09:46 . 2009-08-11 16:44 1401856 ----a-w- c:\windows\system32\msxml6.dll
2010-06-16 09:46 . 2009-08-11 16:44 1248768 ----a-w- c:\windows\system32\msxml3.dll
2010-06-16 09:46 . 2010-01-29 15:40 738816 ----a-w- c:\windows\system32\inetcomm.dll
2010-06-16 09:45 . 2010-02-23 11:10 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-06-16 09:45 . 2010-02-23 11:10 79360 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-06-16 09:45 . 2010-02-23 11:10 106496 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-06-16 09:44 . 2010-02-18 14:07 3600776 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-06-16 09:44 . 2010-02-18 14:07 3548040 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-06-16 09:44 . 2010-03-05 14:01 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-06-16 09:43 . 2010-04-05 17:01 67072 ----a-w- c:\windows\system32\asycfilt.dll
2010-06-16 09:43 . 2010-04-23 14:13 2048 ----a-w- c:\windows\system32\tzres.dll
2010-06-16 09:41 . 2010-05-26 17:06 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-06-16 09:41 . 2010-05-26 14:47 289792 ----a-w- c:\windows\system32\atmfd.dll
2010-06-16 09:41 . 2009-10-19 13:35 72704 ----a-w- c:\windows\system32\fontsub.dll
2010-06-16 09:39 . 2010-02-18 14:07 904576 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-06-16 09:39 . 2010-02-18 13:30 200704 ----a-w- c:\windows\system32\iphlpsvc.dll
2010-06-16 09:39 . 2010-02-18 11:28 25088 ----a-w- c:\windows\system32\drivers\tunnel.sys
2010-06-16 09:39 . 2009-12-08 17:26 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2010-06-16 09:38 . 2010-01-25 12:00 471552 ----a-w- c:\windows\system32\secproc_isv.dll
2010-06-16 09:38 . 2010-01-25 12:00 471552 ----a-w- c:\windows\system32\secproc.dll
2010-06-16 09:38 . 2010-01-25 12:00 152576 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-06-16 09:38 . 2010-01-25 12:00 152064 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-06-16 09:38 . 2010-01-25 11:58 332288 ----a-w- c:\windows\system32\msdrm.dll
2010-06-16 09:38 . 2010-01-25 08:21 526336 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-06-16 09:38 . 2010-01-25 08:21 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-06-16 09:38 . 2010-01-25 08:21 518144 ----a-w- c:\windows\system32\RMActivate.exe
2010-06-16 09:38 . 2010-01-25 08:21 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-06-16 09:36 . 2010-01-06 15:39 1696256 ----a-w- c:\windows\system32\gameux.dll
2010-06-16 09:36 . 2010-01-06 15:38 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2010-06-16 09:36 . 2010-01-06 13:30 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2010-06-16 09:35 . 2010-05-01 14:13 2037248 ----a-w- c:\windows\system32\win32k.sys
2010-06-16 09:35 . 2009-10-07 11:36 243712 ----a-w- c:\windows\system32\rastls.dll
2010-06-16 09:32 . 2009-12-04 18:30 12288 ----a-w- c:\windows\system32\tsbyuv.dll
2010-06-16 09:32 . 2009-12-04 18:29 1314816 ----a-w- c:\windows\system32\quartz.dll
2010-06-16 09:32 . 2009-12-04 18:28 22528 ----a-w- c:\windows\system32\msyuv.dll
2010-06-16 09:32 . 2009-12-04 18:28 31744 ----a-w- c:\windows\system32\msvidc32.dll
2010-06-16 09:32 . 2009-12-04 18:28 123904 ----a-w- c:\windows\system32\msvfw32.dll
2010-06-16 09:32 . 2009-12-04 18:28 13312 ----a-w- c:\windows\system32\msrle32.dll
2010-06-16 09:32 . 2009-12-04 18:28 82944 ----a-w- c:\windows\system32\mciavi32.dll
2010-06-16 09:32 . 2009-12-04 18:28 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2010-06-16 09:32 . 2009-12-04 18:27 91136 ----a-w- c:\windows\system32\avifil32.dll
2010-06-16 09:31 . 2009-06-04 12:07 2066432 ----a-w- c:\windows\system32\mstscax.dll
2010-06-16 09:30 . 2009-09-10 14:58 310784 ----a-w- c:\windows\system32\unregmp2.exe
2010-06-16 09:30 . 2009-09-10 14:59 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2010-06-16 08:30 . 2009-12-23 11:33 172032 ----a-w- c:\windows\system32\wintrust.dll
2010-06-16 08:30 . 2010-01-13 17:34 98304 ----a-w- c:\windows\system32\cabview.dll
2010-06-13 03:50 . 2010-06-18 06:07 -------- d-----w- c:\users\Micheal\AppData\Local\temp
2010-06-06 08:03 . 2010-06-06 08:03 293376 ----a-w- C:\e7th6rgo.exe
2010-06-05 04:27 . 2010-06-05 04:23 293376 ----a-w- C:\uckleeh5.exe
2010-06-01 11:01 . 2010-06-01 11:01 -------- d-----w- c:\users\Default\AppData\Local\Apple
2010-05-30 00:24 . 2010-05-30 00:24 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\ArcSoft
2010-05-30 00:24 . 2010-05-30 00:24 -------- d-----w- c:\users\Default\AppData\Roaming\Hewlett-Packard
2010-05-29 04:01 . 2010-05-29 04:01 -------- d-----w- c:\windows\system32\config\systemprofile\DoctorWeb
2010-05-29 03:39 . 2010-05-29 03:39 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\Western_Digital
2010-05-29 03:39 . 2010-05-29 03:39 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Roaming\Western Digital
2010-05-29 03:39 . 2010-05-29 03:39 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\Western Digital
2010-05-29 03:39 . 2010-05-29 03:39 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\Hewlett-Packard
2010-05-29 03:39 . 2010-05-30 11:24 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Roaming\ArcSoft
2010-05-29 03:39 . 2010-05-29 03:39 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\Apple Computer
2010-05-29 03:39 . 2010-06-06 07:23 -------- d-----w- c:\windows\system32\config\systemprofile\Tracing
2010-05-29 03:39 . 2010-05-29 03:39 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Roaming\Hewlett-Packard
2010-05-29 03:39 . 2010-05-29 03:39 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Roaming\Logitech
2010-05-27 09:40 . 2010-05-27 09:40 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\Mozilla
2010-05-27 09:35 . 2010-05-29 04:27 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\Adobe
2010-05-24 14:41 . 2010-05-24 14:41 -------- d-----w- c:\program files\Common Files\Logitech
2010-05-20 00:30 . 2010-05-24 04:51 0 ----a-w- c:\users\Micheal\AppData\Local\prvlcl.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-18 05:32 . 2009-02-02 23:51 -------- d-----w- c:\programdata\Google Updater
2010-06-18 05:31 . 2009-11-20 05:22 35085 ----a-w- c:\programdata\nvModes.dat
2010-06-17 06:10 . 2008-07-08 03:37 100432 ----a-w- c:\users\Micheal\AppData\Local\GDIPFONTCACHEV1.DAT
2010-06-17 06:09 . 2008-07-08 04:14 -------- d-----w- c:\programdata\NVIDIA
2010-06-17 06:06 . 2008-08-27 12:36 5676 ----a-w- c:\windows\bthservsdp.dat
2010-06-17 05:56 . 2008-07-08 07:12 -------- d-----w- c:\programdata\Microsoft Help
2010-06-17 05:54 . 2009-08-23 10:58 -------- d-----w- c:\program files\Microsoft Works
2010-06-17 05:50 . 2009-10-01 03:56 -------- d-----w- c:\program files\Microsoft
2010-06-17 05:33 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-06-17 05:33 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2010-06-17 05:07 . 2010-06-17 05:07 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2010-06-17 05:07 . 2010-06-17 05:07 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2010-06-17 05:06 . 2009-10-01 04:00 -------- d-----w- c:\program files\Microsoft Silverlight
2010-06-06 07:27 . 2010-02-24 01:25 15944 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2010-06-05 03:21 . 2006-11-02 13:02 8484 ----a-w- c:\windows\system32\config\systemprofile\AppData\Local\d3d9caps.dat
2010-05-30 00:24 . 2008-07-08 03:36 99864 ----a-w- c:\windows\system32\config\systemprofile\AppData\Local\GDIPFONTCACHEV1.DAT
2010-05-30 00:18 . 2008-07-08 03:37 7808 ----a-w- c:\users\Micheal\AppData\Local\d3d9caps.dat
2010-05-26 11:15 . 2009-02-02 23:51 -------- d-----w- c:\program files\Google
2010-05-24 06:34 . 2008-07-08 03:49 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-05-24 05:13 . 2010-03-28 01:59 -------- d-----w- c:\users\Micheal\AppData\Roaming\vlc
2010-05-24 05:13 . 2008-07-24 02:13 -------- d-----w- c:\users\Micheal\AppData\Roaming\Winamp
2010-05-24 05:13 . 2010-03-13 02:06 -------- d-----w- c:\programdata\HP Product Assistant
2010-05-24 05:13 . 2010-01-04 04:46 -------- d-----w- c:\program files\QuickTime
2010-05-24 05:13 . 2009-09-02 10:33 -------- d-----w- c:\program files\PokerStars
2010-05-24 05:13 . 2010-01-04 04:47 -------- d-----w- c:\program files\iTunes
2010-05-24 05:13 . 2010-02-24 01:24 -------- d-----w- c:\program files\Hitman Pro 3.5
2010-05-24 05:13 . 2010-01-04 04:47 -------- d-----w- c:\program files\iPod
2010-05-24 05:13 . 2009-10-31 19:18 -------- d-----w- c:\program files\Bonjour
2010-05-24 05:13 . 2008-07-22 10:26 -------- d-----w- c:\program files\Common Files\Adobe
2010-05-24 05:13 . 2008-07-20 01:25 -------- d-----w- c:\program files\Common Files\Apple
2010-05-24 04:15 . 2010-04-01 07:49 -------- d-----w- c:\program files\Bonjour(94)
2010-05-24 04:15 . 2010-04-01 07:54 -------- d-----w- c:\program files\iPod(142)
2010-05-18 10:49 . 2010-05-18 10:49 -------- d-----w- c:\programdata\avg9
2010-05-18 10:49 . 2009-11-11 07:24 -------- d-----w- c:\program files\AVG
2010-05-17 08:48 . 2010-05-17 08:48 -------- d-----w- c:\programdata\WindowsSearch
2010-05-17 07:54 . 2010-05-17 07:54 -------- d-----w- c:\programdata\Team MediaPortal
2010-05-04 05:59 . 2010-06-16 09:37 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 05:55 . 2010-06-16 09:37 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-05-04 05:55 . 2010-06-16 09:37 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-05-04 04:31 . 2010-06-16 09:37 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-05-02 02:05 . 2010-05-02 02:01 -------- d-----w- c:\program files\Microsoft SQL Server
2010-05-02 02:02 . 2009-08-23 10:57 -------- d-----w- c:\program files\Microsoft.NET
2010-04-27 04:45 . 2010-04-27 04:45 72856 ----a-w- c:\windows\system32\xliveinstallhost.exe
2010-04-27 04:45 . 2010-04-27 04:45 187544 ----a-w- c:\windows\system32\xliveinstall.dll
2010-04-21 07:19 . 2008-08-07 06:08 -------- d-----w- c:\program files\BitLord
2010-04-21 06:40 . 2009-06-12 00:58 -------- d-----w- c:\program files\MediaCoder
2010-04-02 07:17 . 2010-04-02 07:17 15426200 ----a-w- c:\windows\system32\xlive.dll
2010-04-02 07:17 . 2010-04-02 07:17 13642904 ----a-w- c:\windows\system32\xlivefnt.dll
2010-03-24 07:38 . 2010-03-24 07:38 0 ----a-w- c:\windows\nsreg.dat
.
((((((((((((((((((((((((((((( SnapShot_2010-06-17_06.39.40 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-07-08 01:36 . 2010-06-18 05:41 98304 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-07-08 01:36 . 2010-06-17 06:09 98304 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-06-18 05:31 . 2010-06-18 05:41 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-07-08 01:36 . 2010-06-18 05:41 81920 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-07-08 01:36 . 2010-06-17 06:09 81920 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-02-28 08:27 . 2010-06-18 05:31 315616 c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2010-06-17 06:32 . 2010-06-18 06:02 6434816 c:\windows\ERDNT\Hiv-backup\schema.dat
- 2010-06-17 06:32 . 2010-06-17 06:32 6434816 c:\windows\ERDNT\Hiv-backup\schema.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{7E5BE89C-2067-4619-A53D-1EBF363C4370}"= "c:\program files\ROCKETON\rtb.dll" [2008-05-20 353792]
[HKEY_CLASSES_ROOT\clsid\{7e5be89c-2067-4619-a53d-1ebf363c4370}]
[HKEY_CLASSES_ROOT\rtb.Band.1]
[HKEY_CLASSES_ROOT\TypeLib\{CC36D8F4-9645-4CFD-BFB8-9F6DECA5A10C}]
[HKEY_CLASSES_ROOT\rtb.Band]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-10 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Bluetooth Connection Assistant"="LBTWIZ.EXE -silent" [X]
"RunTasktray"="c:\program files\Hewlett-Packard\HP Easy Printer Care\HPPRun.exe --regkeypath=Software\Hewlett-Packard\HP Easy Printer Care\HPPRun --valuename=InstallTTM" [X]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"lxbkbmgr.exe"="c:\program files\Lexmark X1100 Series\lxbkbmgr.exe" [2008-02-28 74408]
"iKeyWorks"="c:\program files\A4Tech\Keyboard\Ikeymain.exe" [2007-06-25 65536]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-28 76304]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-03-18 207360]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-05-04 161328]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-10 149280]
"RtHDVCpl"="RtHDVCpl.exe" [2008-03-26 5369856]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-08-19 150016]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"KnexStarter"="c:\program files\Common Files\Hewlett-Packard\HP Device Communication Services\Appinterfaces\HPDeviceService.exe" [2009-03-23 159744]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-04-19 484904]
c:\users\Micheal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-10-16 214360]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-10-27 805392]
TMMonitor.lnk - c:\program files\ArcSoft\TotalMedia 3.5\TMMonitor.exe [2010-5-24 258048]
WDDMStatus.lnk - c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe [2010-2-26 2057536]
WDSmartWare.lnk - c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe [2010-2-26 9136960]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):86,47,6b,0a,71,68,ca,01
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2939810174-3366620000-2785425234-1000]
"EnableNotificationsRef"=dword:00000001
R2 gupdate1c9859185c99a80;Google Update Service (gupdate1c9859185c99a80);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-02 133104]
R3 Amps2prt;A4Tech PS/2 Port Mouse Driver;c:\windows\system32\DRIVERS\Amps2prt.sys [2007-06-16 14336]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [2009-01-27 10976]
R3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\DRIVERS\s0016bus.sys [2008-05-16 89256]
R3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s0016mdfl.sys [2008-05-16 15016]
R3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s0016mdm.sys [2008-05-16 120744]
R3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s0016mgmt.sys [2008-05-16 114216]
R3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\DRIVERS\s0016nd5.sys [2008-05-16 25512]
R3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s0016obex.sys [2008-05-16 110632]
R3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\DRIVERS\s0016unic.sys [2008-05-16 115752]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam.sys [2009-02-13 11520]
S0 mv61xx;mv61xx;c:\windows\system32\DRIVERS\mv61xx.sys [2008-05-19 150568]
S0 ntcdrdrv;ntcdrdrv;c:\windows\system32\DRIVERS\ntcdrdrv.sys [2007-05-16 13440]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2009-09-27 240232]
S2 WDDMService;WD SmartWare Drive Manager;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [2010-02-25 110592]
S2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [2009-06-15 20480]
S3 AF9035BDA;AF9035 BDA Devices;c:\windows\system32\Drivers\AF9035BDA.sys [2008-12-04 241792]
S3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2008-07-25 42280]
S3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2008-01-21 16896]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-04-19 03:23 452136 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
2010-06-18 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-02 02:59]
2010-06-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-02 23:53]
2010-06-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-02 23:53]
2010-06-18 c:\windows\Tasks\User_Feed_Synchronization-{BDFC15F3-0CC6-4EB9-BF80-F076C8E7E0CE}.job
- c:\windows\system32\msfeedssync.exe [2010-06-16 04:30]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.au/
uInternet Settings,ProxyOverride = *.local
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {{4571FE3F-1E0A-4a78-96BB-8BC1E3332F4B} - {7E5BE89C-2067-4619-A53D-1EBF363C4370} - c:\program files\ROCKETON\rtb.dll
Trusted Zone: hp.com
Handler: HPDCS - {ba135f49-a12c-4e26-a2c4-6ea945999072} - c:\program files\Common Files\Hewlett-Packard\HP Device Communication Services\APP\hpdcsapp.dll
Handler: hppfile - {C4E2084B-ED27-4893-A43D-488CA3F370E2} - c:\program files\Hewlett-Packard\HP Easy Printer Care\HPPCtrls.dll
Handler: hppsam - {C4E2084B-ED27-4893-A43D-488CA3F370E2} - c:\program files\Hewlett-Packard\HP Easy Printer Care\HPPCtrls.dll
Handler: hppzip - {C4E2084B-ED27-4893-A43D-488CA3F370E2} - c:\program files\Hewlett-Packard\HP Easy Printer Care\HPPCtrls.dll
FF - ProfilePath - c:\users\Micheal\AppData\Roaming\Mozilla\Firefox\Profiles\98v01kpb.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.au/
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.27\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\Micheal\AppData\Roaming\Mozilla\Firefox\Profiles\98v01kpb.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
**************************************************************************
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-2939810174-3366620000-2785425234-1000\Software\SecuROM\License information*]
@Allowed: (Read) (RestrictedCode)
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-06-18 16:09:52
ComboFix-quarantined-files.txt 2010-06-18 06:09
ComboFix2.txt 2010-06-17 06:41
ComboFix3.txt 2010-06-16 07:45
ComboFix4.txt 2010-06-13 03:50
Pre-Run: 383,369,035,776 bytes free
Post-Run: 383,322,894,336 bytes free
- - End Of File - - 5C784AE8F8C2F4C81A74B84F7BC01163