ComboFix 10-02-07.01 - Mike 02/07/2010 10:08:38.15.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2039.1287 [GMT -7:00]
Running from: c:\users\Mike\Desktop\ComboFix.exe
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
.
((((((((((((((((((((((((( Files Created from 2010-01-07 to 2010-02-07 )))))))))))))))))))))))))))))))
.
2010-02-07 17:18 . 2010-02-07 17:18 -------- d-----w- c:\users\The McNabs\AppData\Local\temp
2010-02-07 17:18 . 2010-02-07 17:18 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-02-07 17:18 . 2010-02-07 17:18 -------- d-----w- c:\users\Guest\AppData\Local\temp
2010-02-07 17:18 . 2010-02-07 17:18 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-02-07 16:53 . 2009-04-11 06:32 19944 ----a-w- C:\atapi.sys
2010-02-07 09:43 . 2010-02-07 08:02 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000520\maindata.sys
2010-02-06 09:40 . 2010-02-06 08:01 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000519\maindata.sys
2010-02-05 10:19 . 2010-02-05 08:01 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000518\maindata.sys
2010-02-04 20:58 . 2010-01-07 23:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-04 20:58 . 2010-02-04 20:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-04 20:58 . 2010-01-07 23:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-04 09:43 . 2010-02-04 08:01 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000517\maindata.sys
2010-02-03 10:13 . 2010-02-03 08:05 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000516\maindata.sys
2010-02-02 09:52 . 2010-02-02 08:04 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000515\maindata.sys
2010-02-01 10:16 . 2010-02-01 08:03 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000514\maindata.sys
2010-01-31 10:02 . 2010-01-31 08:03 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000513\maindata.sys
2010-01-30 10:20 . 2010-01-30 08:01 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000512\maindata.sys
2010-01-29 09:45 . 2010-01-29 08:01 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000511\maindata.sys
2010-01-28 01:49 . 2010-01-28 01:49 -------- d-----w- c:\program files\Common Files\Java
2010-01-28 01:35 . 2010-01-28 01:35 -------- d-----w- c:\program files\ERUNT
2010-01-28 01:19 . 2010-02-07 17:19 -------- d-----w- c:\users\Mike\AppData\Local\temp
2010-01-26 10:07 . 2010-01-26 08:01 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000510\maindata.sys
2010-01-24 10:08 . 2010-01-24 08:03 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000509\maindata.sys
2010-01-23 10:11 . 2010-01-23 08:01 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000508\maindata.sys
2010-01-23 04:13 . 2010-01-27 04:13 -------- d-----w- c:\program files\SpywareBlaster
2010-01-22 10:12 . 2010-01-22 08:03 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000507\maindata.sys
2010-01-21 10:12 . 2010-01-21 08:03 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000506\maindata.sys
2010-01-20 10:11 . 2010-01-20 08:03 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000505\maindata.sys
2010-01-19 10:08 . 2010-01-19 08:03 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000504\maindata.sys
2010-01-18 10:09 . 2010-01-18 08:03 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000503\maindata.sys
2010-01-17 10:07 . 2010-01-17 08:01 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000502\maindata.sys
2010-01-16 10:45 . 2010-01-16 08:05 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000501\maindata.sys
2010-01-15 11:21 . 2010-01-15 08:03 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000500\maindata.sys
2010-01-14 10:52 . 2010-01-14 08:06 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000499\maindata.sys
2010-01-13 11:35 . 2010-01-13 08:01 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000498\maindata.sys
2010-01-13 01:05 . 2009-10-19 13:38 156672 ----a-w- c:\windows\system32\t2embed.dll
2010-01-13 01:05 . 2009-10-19 13:35 72704 ----a-w- c:\windows\system32\fontsub.dll
2010-01-12 10:12 . 2010-01-12 08:03 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000497\maindata.sys
2010-01-11 10:12 . 2010-01-11 08:01 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000496\maindata.sys
2010-01-10 10:12 . 2010-01-10 08:01 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000495\maindata.sys
2010-01-09 11:13 . 2010-01-09 08:06 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000494\maindata.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-07 17:19 . 2007-12-11 02:23 -------- d-----w- c:\program files\Weather Watcher
2010-02-07 16:59 . 2009-05-21 19:54 -------- d-----w- c:\program files\GE Security Supra
2010-02-07 12:34 . 2007-10-10 14:53 -------- d-----w- c:\programdata\Google Updater
2010-02-07 00:49 . 2009-02-26 15:01 -------- d-----w- c:\users\Mike\AppData\Roaming\SolidDocuments
2010-02-06 03:44 . 2008-02-15 21:00 -------- d-----w- c:\users\Mike\AppData\Roaming\CoreFTP
2010-02-05 03:39 . 2009-03-30 17:35 65 ----a-w- c:\windows\system32\bd8460n.dat
2010-02-01 14:17 . 2007-10-10 14:53 -------- d-----w- c:\program files\Google
2010-01-28 14:45 . 2007-10-11 00:13 -------- d-----w- c:\program files\Common Files\Adobe
2010-01-28 01:49 . 2009-03-16 02:10 -------- d-----w- c:\program files\Java
2010-01-23 04:20 . 2009-12-19 03:47 -------- d-----w- c:\program files\PokerStars
2010-01-22 10:21 . 2008-07-20 15:42 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-16 16:37 . 2009-07-30 17:03 -------- d-----w- c:\program files\Citrix
2010-01-16 16:37 . 2007-10-08 22:15 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-14 18:12 . 2009-10-03 08:40 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-13 10:08 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-01-08 08:02 . 2010-01-08 11:22 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000493\maindata.sys
2010-01-07 08:03 . 2010-01-07 10:59 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000492\maindata.sys
2010-01-06 08:05 . 2010-01-06 12:04 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000491\maindata.sys
2010-01-05 08:06 . 2010-01-05 10:54 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000490\maindata.sys
2010-01-04 08:03 . 2010-01-04 10:14 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000489\maindata.sys
2010-01-03 08:03 . 2010-01-03 10:15 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000488\maindata.sys
2010-01-02 08:01 . 2010-01-02 10:07 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000487\maindata.sys
2010-01-02 06:38 . 2010-01-21 23:20 916480 ----a-w- c:\windows\system32\wininet.dll
2010-01-02 06:32 . 2010-01-21 23:20 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-01-02 06:32 . 2010-01-21 23:20 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-01-02 04:57 . 2010-01-21 23:20 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-01-01 08:02 . 2010-01-01 10:08 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000486\maindata.sys
2009-12-31 08:04 . 2009-12-31 10:14 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000485\maindata.sys
2009-12-28 08:04 . 2009-12-28 11:25 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000484\maindata.sys
2009-12-27 08:05 . 2009-12-27 11:12 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000483\maindata.sys
2009-12-26 08:04 . 2009-12-26 11:19 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000482\maindata.sys
2009-12-25 08:03 . 2009-12-25 10:18 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000481\maindata.sys
2009-12-24 08:02 . 2009-12-24 10:10 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000480\maindata.sys
2009-12-23 08:02 . 2009-12-23 10:07 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000479\maindata.sys
2009-12-22 08:01 . 2009-12-22 10:04 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000478\maindata.sys
2009-12-21 08:01 . 2009-12-21 10:01 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000477\maindata.sys
2009-12-20 08:04 . 2009-12-20 10:11 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000476\maindata.sys
2009-12-19 08:03 . 2009-12-19 10:13 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000475\maindata.sys
2009-12-18 08:03 . 2009-12-18 10:06 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000474\maindata.sys
2009-12-18 00:14 . 2009-03-16 02:11 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-17 08:03 . 2009-12-17 10:15 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000473\maindata.sys
2009-12-16 08:03 . 2009-12-16 10:13 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000472\maindata.sys
2009-12-15 08:02 . 2009-12-15 10:08 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000471\maindata.sys
2009-12-14 08:01 . 2009-12-14 10:06 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000470\maindata.sys
2009-12-13 08:04 . 2009-12-13 10:06 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000469\maindata.sys
2009-12-12 08:03 . 2009-12-12 10:03 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000468\maindata.sys
2009-12-11 08:02 . 2009-12-11 10:00 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000467\maindata.sys
2009-12-10 08:01 . 2009-12-10 10:03 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000466\maindata.sys
2009-12-09 08:01 . 2009-12-09 09:45 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000465\maindata.sys
2009-12-08 08:01 . 2009-12-08 09:57 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000464\maindata.sys
2009-12-07 08:00 . 2009-12-07 09:54 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000463\maindata.sys
2009-12-06 08:01 . 2009-12-06 09:54 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000462\maindata.sys
2009-12-05 08:01 . 2009-12-05 09:58 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000461\maindata.sys
2009-12-04 08:00 . 2009-12-04 09:55 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000460\maindata.sys
2009-12-03 08:03 . 2009-12-03 10:50 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000459\maindata.sys
2009-12-02 08:02 . 2009-12-02 10:53 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000458\maindata.sys
2009-12-01 08:03 . 2009-12-01 11:06 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000457\maindata.sys
2009-11-30 08:03 . 2009-11-30 10:54 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000456\maindata.sys
2009-11-29 08:06 . 2009-11-29 10:57 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000455\maindata.sys
2009-11-28 17:50 . 2009-09-21 17:50 3695616 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2009-11-28 08:07 . 2009-11-28 10:40 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000454\maindata.sys
2009-11-27 08:05 . 2009-11-27 10:06 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000453\maindata.sys
2009-11-26 08:03 . 2009-11-26 10:02 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000452\maindata.sys
2009-11-25 08:02 . 2009-11-25 09:59 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000451\maindata.sys
2009-11-25 02:40 . 2009-11-25 02:40 975648 ----a-w- c:\programdata\Intuit\QuickBooks 2010\Components\DownloadQB20\Patch\qbpatch.exe
2009-11-25 02:40 . 2009-11-25 02:40 499712 ----a-w- c:\programdata\Intuit\QuickBooks 2010\Components\DownloadQB20\Patch\msvcp71.dll
2009-11-25 02:40 . 2009-11-25 02:40 348160 ----a-w- c:\programdata\Intuit\QuickBooks 2010\Components\DownloadQB20\Patch\msvcr71.dll
2009-11-24 08:04 . 2009-11-24 10:05 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000450\maindata.sys
2009-11-23 21:46 . 2007-10-08 21:09 229352 ----a-w- c:\users\Mike\AppData\Local\GDIPFONTCACHEV1.DAT
2009-11-21 08:03 . 2009-11-21 10:05 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000449\maindata.sys
2009-11-20 08:04 . 2009-11-20 10:10 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000448\maindata.sys
2009-11-19 15:18 . 2009-11-19 15:18 1745 ----a-w- c:\programdata\Intuit\QuickBooks 2010\qbbackup.sys
2009-11-19 08:03 . 2009-11-19 10:02 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000447\maindata.sys
2009-11-18 08:01 . 2009-11-18 09:58 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000446\maindata.sys
2009-11-17 08:04 . 2009-11-17 10:05 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000445\maindata.sys
2009-11-16 08:02 . 2009-11-16 10:06 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000444\maindata.sys
2009-11-15 08:03 . 2009-11-15 10:08 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000443\maindata.sys
2009-11-14 08:01 . 2009-11-14 10:00 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000442\maindata.sys
2009-11-13 08:02 . 2009-11-13 11:41 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000441\maindata.sys
2009-11-12 08:03 . 2009-11-12 10:00 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000440\maindata.sys
2009-11-11 08:03 . 2009-11-11 10:01 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000439\maindata.sys
2009-11-10 08:03 . 2009-11-10 10:10 1109 ----a-w- c:\users\Mike\AppData\Roaming\Genie-Soft\GBMHome8\Jobs\Backup Job\00000438\maindata.sys
.
((((((((((((((((((((((((((((( SnapShot_2010-02-04_16.23.04 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-10-08 21:43 . 2010-02-07 17:01 50708 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2010-02-07 17:01 61290 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2007-10-08 21:10 . 2010-02-07 17:01 13868 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1304129043-3560768821-2314269622-1000_UserData.bin
- 2006-11-02 13:02 . 2010-02-04 16:03 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2006-11-02 13:02 . 2010-02-07 16:59 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2006-11-02 13:02 . 2010-02-07 16:59 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2006-11-02 13:02 . 2010-02-04 16:03 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-06-04 00:42 . 2010-02-04 09:54 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-06-04 00:42 . 2010-02-07 16:59 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-06-04 00:42 . 2010-02-04 09:54 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-06-04 00:42 . 2010-02-07 16:59 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-06-04 00:42 . 2010-02-04 09:54 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-06-04 00:42 . 2010-02-07 16:59 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-01-28 01:21 . 2010-02-04 09:54 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2010-02-07 16:59 . 2010-02-07 16:59 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2010-02-07 16:59 . 2010-02-07 16:59 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2010-01-28 01:21 . 2010-02-04 09:54 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-05-29 16:02 . 2010-02-04 15:54 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-05-29 16:02 . 2010-02-07 16:59 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2006-11-02 13:02 . 2010-02-04 16:03 409600 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2006-11-02 13:02 . 2010-02-07 16:59 409600 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2010-02-07 17:00 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\2-7-2010\ERDNT.EXE
+ 2010-02-06 02:32 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\2-5-2010\ERDNT.EXE
- 2006-11-02 10:22 . 2010-01-27 14:51 6553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2006-11-02 10:22 . 2010-02-06 03:25 6553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2010-02-07 17:00 . 2010-02-07 17:00 5312512 c:\windows\ERDNT\AutoBackup\2-7-2010\Users\00000002\UsrClass.dat
+ 2010-02-07 17:00 . 2010-02-07 17:00 7979008 c:\windows\ERDNT\AutoBackup\2-7-2010\Users\00000001\NTUSER.DAT
+ 2010-02-06 02:32 . 2010-02-06 02:32 5296128 c:\windows\ERDNT\AutoBackup\2-5-2010\Users\00000002\UsrClass.dat
+ 2010-02-06 02:32 . 2010-02-06 02:32 7979008 c:\windows\ERDNT\AutoBackup\2-5-2010\Users\00000001\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WeatherWatcher"="c:\program files\Weather Watcher\ww.exe" [2007-09-24 1024000]
"HeavyWeatherPublisher"="c:\heavyweather\HeavyWeatherPublisher.exe" [2004-02-23 1302528]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-10 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2006-12-18 622592]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-12 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-12 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-12 133656]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-09-21 520024]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2006-07-19 65536]
"eFax 4.4"="c:\program files\eFax Messenger 4.4\J2GDllCmd.exe" [2008-10-07 95744]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
"Intuit SyncManager"="c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe" [2009-08-31 996616]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2009-12-18 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
c:\users\Mike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
heavy weather.lnk - c:\heavyweather\heavy weather.exe [2008-5-29 781312]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
APC UPS Status.lnk - c:\program files\APC\APC PowerChute Personal Edition\Display.exe [2007-10-16 267520]
DisplayKEY eSYNC Info.lnk - c:\program files\GE Security Supra\SyncInfoApp.exe [2009-5-21 102400]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2008-12-25 66864]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2009-9-3 1153824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):d6,05,a9,7a,15,33,ca,01
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1304129043-3560768821-2314269622-1000]
"EnableNotificationsRef"=dword:00000002
R0 AFS;AFS;c:\windows\System32\drivers\AFS.SYS [11/8/2009 5:01 PM 79052]
R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [4/25/2009 10:51 AM 64160]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [11/4/2007 11:31 AM 1153368]
R2 SPDFCreatorPlusReadSpool;SolidPDFPlusCreatorReadSpool;c:\windows\Installer\MSIF8BC.tmp [2/26/2009 8:00 AM 189696]
R2 SPDFToolsReadSpool;SolidPDFToolsCreatorReadSpool;c:\windows\Installer\MSIEE5E.tmp [2/26/2009 8:18 AM 189696]
S2 CSHelper;CopySafe Helper Service;c:\windows\System32\CSHelper.exe [3/15/2009 6:58 PM 192512]
S2 gupdate1c9bca6f4ea33cd;Google Update Service (gupdate1c9bca6f4ea33cd);c:\program files\Google\Update\GoogleUpdate.exe [4/13/2009 7:16 PM 133104]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [6/5/2008 8:46 AM 21504]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [1/18/2009 2:34 PM 1028432]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 17:14 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
2010-02-06 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 17:50]
2010-02-07 c:\windows\Tasks\GBM - Backup Job-Full.job
- c:\program files\Genie-Soft\GBMHome8\GBM8.exe [2007-10-08 12:28]
2010-02-07 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-10-10 06:07]
2010-02-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-14 02:15]
2010-02-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-14 02:15]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
Trusted Zone: bing.com
Trusted Zone: doccentral.com
Trusted Zone: fnismls.com
Trusted Zone: getmedianow.com
Trusted Zone: live.com
Trusted Zone: rdesk.com
Trusted Zone: rexplorer.net
Trusted Zone: safemls.net
Trusted Zone: showingtime.com
Trusted Zone: sitexdata.com
Trusted Zone: spellchecker.net
Trusted Zone: superior-host.com
Trusted Zone: transactionpoint.com
Trusted Zone: trpoint.com
Trusted Zone: virtualearth.net
Trusted Zone: xmlsweb.com
TCP: {30BBADAE-3AF0-48DB-BFFA-9AD645AF925A} = 208.67.220.220,208.67.222.222
Handler: intu-help-qb3 - {c5e479ea-0a65-4b05-8c6c-2fc8cc682eb4} - c:\program files\Intuit\QuickBooks 2010\HelpAsyncPluggableProtocol.dll
DPF: ImageUploader - hxxp://www.assetval.com/app/ImageUploader.CAB
DPF: Microsoft XML Parser for Java - file:///C:/Windows/Java/classes/xmldso.cab
DPF: {0CE0F418-1010-442D-871C-3454827DD539} - hxxp://facefun.com/FaceFun_webinstall/FaceFun.cab
DPF: {83A4D5A6-E2C1-4EDD-AD48-1A1C50BD06EF} - hxxp://www.riocentral.com/Image%20Uploader/ImageUploader6.cab
DPF: {97770E5B-2028-48AC-B4DA-1F991376D2B6} - hxxp://download.copysafe.net/plugins5/installers/Copysafe.cab
DPF: {F375116A-793C-11D2-BFE1-444553540001} - hxxp://pro.realquest.com/mapviewer/mapviewer.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-02-07 10:19
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SPDFCreatorPlusReadSpool]
"ImagePath"="c:\windows\Installer\MSIF8BC.tmp"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SPDFToolsReadSpool]
"ImagePath"="c:\windows\Installer\MSIEE5E.tmp"
.
Completion time: 2010-02-07 10:22:45
ComboFix-quarantined-files.txt 2010-02-07 17:22
ComboFix2.txt 2010-02-04 16:28
ComboFix3.txt 2010-01-27 03:15
ComboFix4.txt 2010-01-27 02:42
ComboFix5.txt 2010-02-07 17:06
Pre-Run: 44,370,751,488 bytes free
Post-Run: 44,510,015,488 bytes free
- - End Of File - - 5C568A96D206FE93A9A5FFBFB54F9986