dds and combofix logs
Hi Blade81
DDS (Ver_09-09-29.01) - NTFSx86
Run by Owner at 17:06:03.09 on Thu 02/11/2010
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.767.363 [GMT 11:00]
AV: avast! Antivirus *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Owner\Desktop\Clean up stuff\dds.com
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.facebook.com/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
TB: &Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [OM_Monitor] c:\program files\olympus\olympus master\Monitor.exe -NoStart
uRun: [OM2_Monitor] "c:\program files\olympus\olympus master 2\MMonitor.exe" -NoStart
uRun: [ccleaner] "c:\program files\ccleaner\ccleaner.exe" /AUTO
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime
mRun: [OM_Monitor] c:\program files\olympus\olympus master\FirstStart.exe
mRun: [OM2_Monitor] "c:\program files\olympus\olympus master 2\FirstStart.exe" /OM
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [OpwareSE4] "c:\program files\scansoft\omnipagese4\OpwareSE4.exe"
mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon
mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui
StartupFolder: c:\docume~1\owner\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\owner\startm~1\programs\startup\pictur~1.lnk - c:\program files\sony\sony picture utility\pmbcore\SPUVolumeWatcher.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1233614657859
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
============= SERVICES / DRIVERS ===============
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2008-11-8 163280]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-11-8 19024]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-2-10 40384]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-2-10 40384]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-2-10 40384]
=============== Created Last 30 ================
2010-02-10 13:17 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Alwil Software
2010-02-08 16:38 4,984 a------- c:\windows\system32\drivers\nvphy.bin
2010-02-08 16:38 <DIR> --d----- c:\program files\Microsoft CAPICOM 2.1.0.2
2010-02-05 19:57 274,288 a------- c:\windows\system32\mucltui.dll
2010-02-05 19:57 215,920 a------- c:\windows\system32\muweb.dll
2010-02-05 19:57 16,736 a------- c:\windows\system32\mucltui.dll.mui
2010-02-02 17:41 <DIR> --d----- c:\docume~1\owner\applic~1\Malwarebytes
2010-02-02 17:40 38,224 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-02 17:40 19,160 a------- c:\windows\system32\drivers\mbam.sys
2010-02-02 17:40 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-02-02 17:40 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2010-02-01 16:41 261,632 a------- c:\windows\PEV.exe
2010-02-01 16:41 161,792 a------- c:\windows\SWREG.exe
2010-02-01 16:41 98,816 a------- c:\windows\sed.exe
2010-02-01 16:41 77,312 a------- c:\windows\MBR.exe
2010-01-21 22:47 <DIR> --d----- c:\program files\common files\Windows Live
2010-01-13 10:17 471,552 -c------ c:\windows\system32\dllcache\aclayers.dll
==================== Find3M ====================
2010-01-05 21:00 832,512 -------- c:\windows\system32\wininet.dll
2010-01-05 21:00 78,336 a------- c:\windows\system32\ieencode.dll
2010-01-05 21:00 17,408 a------- c:\windows\system32\corpol.dll
2009-11-22 02:51 471,552 a------- c:\windows\apppatch\aclayers.dll
2009-03-31 13:29 17,528 a------- c:\docume~1\owner\applic~1\GDIPFONTCACHEV1.DAT
============= FINISH: 17:06:32.51 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-09-29.01)
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 6/23/2008 9:52:47 AM
System Uptime: 2/11/2010 4:59:10 PM (1 hours ago)
Motherboard: Gigabyte Technology Co., Ltd. | | GA-M51GM-S2G
Processor: AMD Sempron(tm) Processor 3200+ | Socket M2 | 1808/200mhz
==== Disk Partitions =========================
A: is Removable
C: is FIXED (NTFS) - 68 GiB total, 55.047 GiB free.
D: is Removable
E: is Removable
F: is Removable
G: is Removable
H: is FIXED (FAT32) - 6 GiB total, 0.798 GiB free.
I: is CDROM ()
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP331: 11/13/2009 2:24:03 PM - Software Distribution Service 3.0
RP332: 11/14/2009 3:20:31 PM - System Checkpoint
RP333: 11/15/2009 4:05:53 PM - System Checkpoint
RP334: 11/16/2009 6:35:09 PM - System Checkpoint
RP335: 11/17/2009 8:41:09 PM - System Checkpoint
RP336: 11/18/2009 8:51:41 PM - System Checkpoint
RP337: 11/20/2009 5:43:48 PM - System Checkpoint
RP338: 11/22/2009 11:24:13 AM - System Checkpoint
RP339: 11/23/2009 2:43:40 PM - System Checkpoint
RP340: 11/24/2009 5:00:23 PM - System Checkpoint
RP341: 11/25/2009 5:24:20 PM - System Checkpoint
RP342: 11/26/2009 6:14:34 PM - System Checkpoint
RP343: 11/27/2009 6:32:06 PM - System Checkpoint
RP344: 11/27/2009 7:54:06 PM - Software Distribution Service 3.0
RP345: 11/28/2009 8:51:36 PM - System Checkpoint
RP346: 11/29/2009 8:54:43 PM - System Checkpoint
RP347: 12/1/2009 7:26:59 PM - System Checkpoint
RP348: 12/2/2009 7:59:42 PM - System Checkpoint
RP349: 12/3/2009 8:14:42 PM - System Checkpoint
RP350: 12/5/2009 5:27:14 PM - System Checkpoint
RP351: 12/6/2009 6:11:25 PM - System Checkpoint
RP352: 12/8/2009 8:47:10 PM - System Checkpoint
RP353: 12/9/2009 5:41:40 PM - Installed ScanSoft OmniPage SE 4
RP354: 12/9/2009 8:52:07 PM - Software Distribution Service 3.0
RP355: 12/11/2009 6:49:54 PM - System Checkpoint
RP356: 12/12/2009 7:42:43 PM - System Checkpoint
RP357: 12/13/2009 8:24:37 PM - System Checkpoint
RP358: 12/16/2009 8:06:31 PM - System Checkpoint
RP359: 12/17/2009 12:27:53 PM - Installed 101 Card & Board Games
RP360: 12/17/2009 12:31:12 PM - Removed 101 Card & Board Games
RP361: 12/18/2009 6:13:25 PM - System Checkpoint
RP362: 12/19/2009 7:07:25 PM - System Checkpoint
RP363: 12/20/2009 7:27:39 PM - System Checkpoint
RP364: 12/21/2009 4:40:22 PM - Removed MobileMe Control Panel
RP365: 12/21/2009 4:42:03 PM - Removed Apple Mobile Device Support
RP366: 12/22/2009 6:12:40 PM - System Checkpoint
RP367: 12/23/2009 6:36:09 PM - System Checkpoint
RP368: 12/25/2009 6:37:09 PM - System Checkpoint
RP369: 12/27/2009 6:18:00 PM - System Checkpoint
RP370: 12/28/2009 6:56:45 PM - System Checkpoint
RP371: 12/29/2009 8:36:29 PM - System Checkpoint
RP372: 12/31/2009 11:58:14 AM - System Checkpoint
RP373: 1/1/2010 2:28:52 PM - System Checkpoint
RP374: 1/2/2010 5:17:44 PM - System Checkpoint
RP375: 1/3/2010 6:11:36 PM - System Checkpoint
RP376: 1/4/2010 7:19:08 PM - System Checkpoint
RP377: 1/8/2010 5:12:09 PM - System Checkpoint
RP378: 1/9/2010 7:00:29 PM - System Checkpoint
RP379: 1/10/2010 9:49:20 PM - System Checkpoint
RP380: 1/12/2010 12:39:52 PM - System Checkpoint
RP381: 1/13/2010 10:59:04 AM - Software Distribution Service 3.0
RP382: 1/15/2010 8:38:41 PM - System Checkpoint
RP383: 1/17/2010 6:05:02 PM - System Checkpoint
RP384: 1/18/2010 9:29:37 AM - Software Distribution Service 3.0
RP385: 1/20/2010 3:03:28 PM - System Checkpoint
RP386: 1/23/2010 11:39:39 AM - System Checkpoint
RP387: 1/25/2010 10:27:13 AM - Software Distribution Service 3.0
RP388: 1/26/2010 6:48:28 PM - System Checkpoint
RP389: 1/29/2010 3:52:35 PM - System Checkpoint
RP390: 1/30/2010 5:38:29 PM - System Checkpoint
RP391: 2/2/2010 12:36:54 PM - System Checkpoint
RP392: 2/2/2010 5:36:14 PM - Removed Adobe Reader 8.1.2
RP393: 2/3/2010 6:12:55 PM - System Checkpoint
RP394: 2/4/2010 6:40:23 PM - System Checkpoint
RP395: 2/5/2010 8:20:27 PM - System Checkpoint
RP396: 2/8/2010 4:37:59 PM - Software Distribution Service 3.0
RP397: 2/10/2010 1:17:45 PM - avast! Free Antivirus Setup
RP398: 2/11/2010 1:30:04 PM - System Checkpoint
==== Installed Programs ======================
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Media Player
Agere Systems PCI-SV92PP Soft Modem
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Athlon 64 Processor Driver
ATI - Software Uninstall Utility
ATI Catalyst Control Center
ATI Control Panel
ATI Display Driver
avast! Free Antivirus
Bonjour
Canon MP Navigator EX 1.0
Canon MP210 series
Canon My Printer
Canon Utilities Easy-PhotoPrint EX
Canon Utilities Solution Menu
CCleaner
Critical Update for Windows Media Player 11 (KB959772)
ERUNT 1.1j
Google Toolbar for Internet Explorer
High Definition Audio Driver Package - KB888111
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
iTunes
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office XP Professional with FrontPage
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 Parser and SDK
Nero Suite
NVIDIA Drivers
OLYMPUS Master
OLYMPUS Master 2
PowerDVD
QuickTime
Realtek High Definition Audio Driver
ScanSoft OmniPage SE 4
Security Update for CAPICOM (KB931906)
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 7 (KB976325)
Security Update for Windows Internet Explorer 7 (KB978207)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Sonic UDF Reader
Sony Picture Utility
Spybot - Search & Destroy
Update for Windows Internet Explorer 7 (KB976749)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
WebFldrs XP
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Live Messenger
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
==== Event Viewer Messages From Past Week ========
2/5/2010 7:56:25 PM, error: ati2mtag [45062] -
==== End Of File ===========================
ComboFix 10-02-10.04 - Owner 02/11/2010 16:53:31.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.767.414 [GMT 11:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\cfscript.txt
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((( Files Created from 2010-01-11 to 2010-02-11 )))))))))))))))))))))))))))))))
.
2010-02-10 02:17 . 2010-02-10 02:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-02-08 05:38 . 2008-07-07 21:45 4984 ----a-w- c:\windows\system32\drivers\nvphy.bin
2010-02-08 05:38 . 2010-02-08 05:38 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2010-02-05 08:57 . 2009-08-06 08:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2010-02-05 08:57 . 2009-08-06 08:23 215920 ----a-w- c:\windows\system32\muweb.dll
2010-02-02 06:41 . 2010-02-02 06:41 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes
2010-02-02 06:40 . 2010-01-07 05:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-02 06:40 . 2010-02-02 06:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-02 06:40 . 2010-01-07 05:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-02 06:40 . 2010-02-02 06:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-21 11:47 . 2010-01-21 11:47 -------- d-----w- c:\program files\Common Files\Windows Live
2010-01-18 23:35 . 2010-01-18 23:35 -------- d-----w- c:\program files\ERUNT
2010-01-12 23:17 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-10 02:19 . 2008-11-08 10:21 -------- d-----w- c:\program files\Alwil Software
2010-02-02 06:36 . 2008-06-23 01:08 -------- d-----w- c:\program files\Common Files\Adobe
2010-02-02 01:09 . 2009-12-22 05:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-28 22:09 . 2008-11-08 10:22 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-01-28 22:09 . 2008-11-08 10:21 152672 ----a-w- c:\windows\system32\aswBoot.exe
2010-01-28 21:57 . 2008-11-08 10:22 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-01-28 21:57 . 2008-11-08 10:22 163280 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-01-28 21:54 . 2008-11-08 10:22 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-01-28 21:54 . 2008-11-08 10:22 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-01-28 21:54 . 2008-11-08 10:22 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-01-28 21:54 . 2008-11-08 10:22 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-01-28 21:53 . 2008-11-08 10:22 28240 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-01-11 05:54 . 2010-01-11 05:54 -------- d-----w- c:\program files\Trend Micro
2010-01-05 10:00 . 2006-02-28 12:00 832512 ------w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2006-02-28 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2006-02-28 12:00 17408 ----a-w- c:\windows\system32\corpol.dll
2010-01-05 03:41 . 2010-01-05 03:41 -------- d-----w- c:\program files\Adobe Media Player
2010-01-05 03:41 . 2010-01-05 03:41 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-01-05 03:41 . 2010-01-05 03:41 38784 ----a-w- c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-01-05 03:41 . 2008-07-06 06:10 38784 ----a-w- c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-12-24 03:28 . 2009-12-24 03:27 -------- d-----w- c:\program files\iTunes
2009-12-24 03:27 . 2009-12-24 03:27 -------- d-----w- c:\program files\iPod
2009-12-24 03:27 . 2008-12-30 08:21 -------- d-----w- c:\program files\Common Files\Apple
2009-12-24 03:24 . 2008-07-11 03:50 -------- d-----w- c:\program files\QuickTime
2009-12-24 03:20 . 2009-12-24 03:20 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-12-22 06:53 . 2009-12-22 05:57 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-12-21 05:56 . 2009-12-21 05:56 0 ----a-w- c:\windows\nsreg.dat
2009-12-21 05:39 . 2008-06-23 01:10 -------- d-----w- c:\program files\MSN Messenger
2009-12-21 05:34 . 2009-12-21 05:34 -------- d-----w- c:\program files\CCleaner
2009-12-17 01:27 . 2008-06-22 23:56 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-11-21 15:51 . 2006-02-28 12:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-02-01_05.48.17 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-11 13:02 . 2009-07-11 13:02 51008 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_f0ccd4aa\vcomp90.dll
+ 2009-07-11 13:02 . 2009-07-11 13:02 59728 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90rus.dll
+ 2009-07-11 13:02 . 2009-07-11 13:02 42832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90kor.dll
+ 2009-07-11 13:02 . 2009-07-11 13:02 43344 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90jpn.dll
+ 2009-07-11 13:02 . 2009-07-11 13:02 61264 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90ita.dll
+ 2009-07-11 13:02 . 2009-07-11 13:02 62800 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90fra.dll
+ 2009-07-11 13:02 . 2009-07-11 13:02 61760 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esp.dll
+ 2009-07-11 13:02 . 2009-07-11 13:02 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esn.dll
+ 2009-07-11 13:02 . 2009-07-11 13:02 53568 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90enu.dll
+ 2009-07-11 13:02 . 2009-07-11 13:02 63296 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90deu.dll
+ 2009-07-11 13:02 . 2009-07-11 13:02 36688 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90cht.dll
+ 2009-07-11 13:02 . 2009-07-11 13:02 35648 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90chs.dll
+ 2009-07-11 13:05 . 2009-07-11 13:05 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90u.dll
+ 2009-07-11 13:05 . 2009-07-11 13:05 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90.dll
+ 2010-02-08 05:38 . 2006-02-17 03:28 34176 c:\windows\system32\ReinstallBackups\0009\DriverFiles\nvefdxp.sys
+ 2010-02-08 05:38 . 2006-02-17 03:28 13056 c:\windows\system32\ReinstallBackups\0008\DriverFiles\nvnetbus.sys
+ 2010-02-08 05:38 . 2005-12-20 17:23 35840 c:\windows\system32\ReinstallBackups\0008\DriverFiles\nvconrm.dll
+ 2010-02-08 05:38 . 2001-11-09 04:01 24064 c:\windows\system32\ReinstallBackups\0006\DriverFiles\B_23265\ativcoxx.dll
+ 2010-02-08 05:38 . 2007-09-28 15:20 17408 c:\windows\system32\ReinstallBackups\0006\DriverFiles\B_23265\atitvo32.dll
+ 2010-02-08 05:38 . 2007-09-28 15:55 53248 c:\windows\system32\ReinstallBackups\0006\DriverFiles\B_23265\ATIDDC.DLL
+ 2010-02-08 05:38 . 2007-09-28 15:58 26112 c:\windows\system32\ReinstallBackups\0006\DriverFiles\B_23265\Ati2mdxx.exe
+ 2010-02-08 05:38 . 2007-09-28 15:19 49152 c:\windows\system32\ReinstallBackups\0006\DriverFiles\B_23265\ati2erec.dll
+ 2010-02-08 05:38 . 2007-09-28 15:58 43520 c:\windows\system32\ReinstallBackups\0006\DriverFiles\B_23265\ati2edxx.dll
+ 2005-05-04 02:24 . 2006-02-21 09:40 77824 c:\windows\system32\Oemdspif.dll
+ 2008-06-22 23:56 . 2008-08-01 07:36 22016 c:\windows\system32\drivers\nvnetbus.sys
+ 2008-06-22 23:56 . 2008-08-01 07:36 54784 c:\windows\system32\drivers\NVENETFD.sys
+ 2005-05-04 01:57 . 2006-02-21 09:09 40960 c:\windows\system32\drivers\ati2erec.dll
- 2001-11-09 15:01 . 2001-11-09 04:01 24064 c:\windows\system32\ativcoxx.dll
+ 2001-11-09 15:01 . 2001-11-08 22:01 24064 c:\windows\system32\ativcoxx.dll
- 2005-05-04 01:57 . 2007-09-28 15:20 17408 c:\windows\system32\atitvo32.dll
+ 2005-05-04 01:57 . 2006-02-21 09:10 17408 c:\windows\system32\atitvo32.dll
- 2005-05-04 02:22 . 2007-09-28 15:55 53248 c:\windows\system32\ATIDDC.DLL
+ 2005-05-04 02:22 . 2006-02-21 09:38 53248 c:\windows\system32\ATIDDC.DLL
- 2005-05-04 02:24 . 2007-09-28 15:58 26112 c:\windows\system32\Ati2mdxx.exe
+ 2005-05-04 02:24 . 2006-02-21 09:40 26112 c:\windows\system32\Ati2mdxx.exe
+ 2005-05-04 02:23 . 2006-02-21 09:40 61440 c:\windows\system32\ati2evxx.dll
+ 2005-05-04 02:24 . 2006-02-21 09:40 40960 c:\windows\system32\ati2edxx.dll
+ 2010-02-09 05:37 . 2010-02-09 05:37 12288 c:\windows\ERDNT\AutoBackup\2-9-2010\Users\00000002\UsrClass.dat
+ 2010-02-08 05:24 . 2010-02-08 05:24 12288 c:\windows\ERDNT\AutoBackup\2-8-2010\Users\00000002\UsrClass.dat
+ 2010-02-06 03:56 . 2010-02-06 03:56 12288 c:\windows\ERDNT\AutoBackup\2-6-2010\Users\00000002\UsrClass.dat
+ 2010-02-05 08:56 . 2010-02-05 08:56 12288 c:\windows\ERDNT\AutoBackup\2-5-2010\Users\00000002\UsrClass.dat
+ 2010-02-04 06:11 . 2010-02-04 06:11 12288 c:\windows\ERDNT\AutoBackup\2-4-2010\Users\00000002\UsrClass.dat
+ 2010-02-03 04:32 . 2010-02-03 04:32 12288 c:\windows\ERDNT\AutoBackup\2-3-2010\Users\00000002\UsrClass.dat
+ 2010-02-02 01:09 . 2010-02-02 01:09 12288 c:\windows\ERDNT\AutoBackup\2-2-2010\Users\00000002\UsrClass.dat
+ 2010-02-11 01:26 . 2010-02-11 01:26 12288 c:\windows\ERDNT\AutoBackup\2-11-2010\Users\00000002\UsrClass.dat
+ 2010-02-10 02:07 . 2010-02-10 02:07 12288 c:\windows\ERDNT\AutoBackup\2-10-2010\Users\00000002\UsrClass.dat
+ 2010-02-08 05:38 . 2006-02-17 03:26 9728 c:\windows\system32\ReinstallBackups\0008\DriverFiles\bdco1.dll
+ 2008-06-22 23:56 . 2008-08-01 07:34 9216 c:\windows\system32\bdco1ins.dll
+ 2008-06-22 23:56 . 2008-08-01 07:34 9216 c:\windows\system32\bdco1.dll
+ 2009-07-11 13:02 . 2009-07-11 13:02 653120 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll
+ 2009-07-11 13:02 . 2009-07-11 13:02 569664 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll
+ 2009-07-11 13:05 . 2009-07-11 13:05 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcm90.dll
+ 2009-07-11 13:02 . 2009-07-11 13:02 159032 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_353599c2\atl90.dll
+ 2010-02-08 05:38 . 2006-02-17 03:27 204288 c:\windows\system32\ReinstallBackups\0009\DriverFiles\fdco1.dll
+ 2010-02-08 05:38 . 2006-02-17 03:27 155136 c:\windows\system32\ReinstallBackups\0009\DriverFiles\fdco_l2052.dll
+ 2010-02-08 05:38 . 2006-02-17 03:27 158720 c:\windows\system32\ReinstallBackups\0009\DriverFiles\fdco_l1046.dll
+ 2010-02-08 05:38 . 2006-02-17 03:27 156672 c:\windows\system32\ReinstallBackups\0009\DriverFiles\fdco_l1042.dll
+ 2010-02-08 05:38 . 2006-02-17 03:27 156672 c:\windows\system32\ReinstallBackups\0009\DriverFiles\fdco_l1041.dll
+ 2010-02-08 05:38 . 2006-02-17 03:27 158720 c:\windows\system32\ReinstallBackups\0009\DriverFiles\fdco_l1040.dll
+ 2010-02-08 05:38 . 2006-02-17 03:27 159232 c:\windows\system32\ReinstallBackups\0009\DriverFiles\fdco_l1036.dll
+ 2010-02-08 05:38 . 2006-02-17 03:27 159232 c:\windows\system32\ReinstallBackups\0009\DriverFiles\fdco_l1034.dll
+ 2010-02-08 05:38 . 2006-02-17 03:27 159232 c:\windows\system32\ReinstallBackups\0009\DriverFiles\fdco_l1031.dll
+ 2010-02-08 05:38 . 2006-02-17 03:27 155648 c:\windows\system32\ReinstallBackups\0009\DriverFiles\fdco_l1028.dll
+ 2010-02-08 05:38 . 2006-02-17 03:28 222592 c:\windows\system32\ReinstallBackups\0008\DriverFiles\nvsnpu.sys
+ 2010-02-08 05:38 . 2006-02-17 03:28 305152 c:\windows\system32\ReinstallBackups\0008\DriverFiles\nvnrm.sys
+ 2010-02-08 05:38 . 2007-09-28 15:58 122880 c:\windows\system32\ReinstallBackups\0006\DriverFiles\B_23265\Oemdspif.dll
+ 2010-02-08 05:38 . 2007-09-28 15:58 143360 c:\windows\system32\ReinstallBackups\0006\DriverFiles\B_23265\atipdlxx.dll
+ 2010-02-08 05:38 . 2007-09-28 15:22 376832 c:\windows\system32\ReinstallBackups\0006\DriverFiles\B_23265\atikvmag.dll
+ 2010-02-08 05:38 . 2007-09-28 15:49 307200 c:\windows\system32\ReinstallBackups\0006\DriverFiles\B_23265\atiiiexx.dll
+ 2010-02-08 05:38 . 2007-08-14 10:11 156671 c:\windows\system32\ReinstallBackups\0006\DriverFiles\B_23265\atiicdxx.dat
+ 2010-02-08 05:38 . 2005-05-04 04:31 221184 c:\windows\system32\ReinstallBackups\0006\DriverFiles\B_23265\ATIDEMGR.dll
+ 2010-02-08 05:38 . 2007-09-28 15:56 483328 c:\windows\system32\ReinstallBackups\0006\DriverFiles\B_23265\ati2evxx.exe
+ 2010-02-08 05:38 . 2007-09-28 15:57 122880 c:\windows\system32\ReinstallBackups\0006\DriverFiles\B_23265\ati2evxx.dll
+ 2010-02-08 05:38 . 2007-09-28 16:06 268800 c:\windows\system32\ReinstallBackups\0006\DriverFiles\B_23265\ati2dvag.dll
+ 2010-02-08 05:38 . 2007-09-28 15:14 499712 c:\windows\system32\ReinstallBackups\0006\DriverFiles\B_23265\ati2cqag.dll
+ 2008-06-22 23:56 . 2008-07-29 09:33 446464 c:\windows\system32\nvunrm.exe
+ 2008-06-22 23:56 . 2008-07-29 09:33 446464 c:\windows\system32\NVUNINST.EXE
+ 2008-06-22 23:56 . 2008-07-29 09:33 122880 c:\windows\system32\nvconrm.dll
+ 2008-06-22 23:56 . 2008-08-01 07:35 200704 c:\windows\system32\fdco1ins.dll
+ 2008-06-22 23:56 . 2008-08-01 07:35 200704 c:\windows\system32\fdco1.dll
+ 2008-06-22 23:56 . 2008-08-01 07:35 955520 c:\windows\system32\drivers\nvnrm.sys
+ 2010-02-10 02:17 . 2010-02-10 02:17 262144 c:\windows\system32\config\systemprofile\NtUser.dat
+ 2005-05-04 02:08 . 2006-02-21 09:24 860480 c:\windows\system32\ativvaxx.dll
+ 2005-05-04 02:24 . 2006-02-21 09:41 114688 c:\windows\system32\atipdlxx.dll
+ 2005-05-04 01:57 . 2006-02-21 09:11 151552 c:\windows\system32\atikvmag.dll
- 2008-06-23 00:53 . 2007-09-28 15:49 307200 c:\windows\system32\atiiiexx.dll
+ 2008-06-23 00:53 . 2006-02-21 09:20 307200 c:\windows\system32\atiiiexx.dll
+ 2008-06-23 00:52 . 2006-02-13 02:29 121995 c:\windows\system32\atiicdxx.dat
+ 2005-05-04 04:31 . 2006-02-21 08:21 282624 c:\windows\system32\ATIDEMGR.dll
+ 2005-05-04 02:22 . 2006-02-21 09:39 405504 c:\windows\system32\ati2evxx.exe
+ 2005-05-04 02:28 . 2006-02-21 09:46 256512 c:\windows\system32\ati2dvag.dll
+ 2005-05-04 01:52 . 2006-02-21 09:04 258048 c:\windows\system32\ati2cqag.dll
+ 2010-02-08 05:38 . 2010-02-08 05:38 470528 c:\windows\Installer\df7a4.msi
+ 2010-02-10 02:18 . 2010-02-10 02:18 219648 c:\windows\Installer\adab4.msi
+ 2010-02-09 05:37 . 2005-10-20 01:02 163328 c:\windows\ERDNT\AutoBackup\2-9-2010\ERDNT.EXE
+ 2010-02-08 05:24 . 2005-10-20 01:02 163328 c:\windows\ERDNT\AutoBackup\2-8-2010\ERDNT.EXE
+ 2010-02-06 03:56 . 2005-10-20 01:02 163328 c:\windows\ERDNT\AutoBackup\2-6-2010\ERDNT.EXE
+ 2010-02-05 08:56 . 2005-10-20 01:02 163328 c:\windows\ERDNT\AutoBackup\2-5-2010\ERDNT.EXE
+ 2010-02-04 06:11 . 2005-10-20 01:02 163328 c:\windows\ERDNT\AutoBackup\2-4-2010\ERDNT.EXE
+ 2010-02-03 04:32 . 2005-10-20 01:02 163328 c:\windows\ERDNT\AutoBackup\2-3-2010\ERDNT.EXE
+ 2010-02-02 01:09 . 2005-10-20 01:02 163328 c:\windows\ERDNT\AutoBackup\2-2-2010\ERDNT.EXE
+ 2010-02-11 01:26 . 2005-10-20 01:02 163328 c:\windows\ERDNT\AutoBackup\2-11-2010\ERDNT.EXE
+ 2010-02-10 02:07 . 2005-10-20 01:02 163328 c:\windows\ERDNT\AutoBackup\2-10-2010\ERDNT.EXE
+ 2009-07-11 13:02 . 2009-07-11 13:02 3780424 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90u.dll
+ 2009-07-11 13:02 . 2009-07-11 13:02 3765048 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90.dll
+ 2010-02-08 05:38 . 2007-09-28 15:36 1593600 c:\windows\system32\ReinstallBackups\0006\DriverFiles\B_23265\ativvaxx.dll
+ 2010-02-08 05:38 . 2007-09-28 15:23 5435392 c:\windows\system32\ReinstallBackups\0006\DriverFiles\B_23265\atioglxx.dll
+ 2010-02-08 05:38 . 2005-05-04 03:52 6680576 c:\windows\system32\ReinstallBackups\0006\DriverFiles\B_23265\atioglx1.dll
+ 2010-02-08 05:38 . 2007-09-28 15:47 3130720 c:\windows\system32\ReinstallBackups\0006\DriverFiles\B_23265\ati3duag.dll
+ 2010-02-08 05:38 . 2007-09-28 16:06 2456064 c:\windows\system32\ReinstallBackups\0006\DriverFiles\B_23265\ati2mtag.sys
+ 2005-05-04 02:28 . 2006-02-21 09:46 1505792 c:\windows\system32\drivers\ati2mtag.sys
+ 2005-05-04 02:28 . 2006-02-21 09:46 1505792 c:\windows\system32\dllcache\ati2mtag.sys
+ 2005-05-04 02:44 . 2006-02-21 09:11 5124096 c:\windows\system32\atioglxx.dll
+ 2005-05-04 03:52 . 2006-02-21 09:27 6684672 c:\windows\system32\atioglx1.dll
+ 2005-05-04 02:14 . 2006-02-21 09:30 2636672 c:\windows\system32\ati3duag.dll
+ 2010-02-09 05:37 . 2010-02-09 05:37 7303168 c:\windows\ERDNT\AutoBackup\2-9-2010\Users\00000001\NTUSER.DAT
+ 2010-02-08 05:24 . 2010-02-08 05:24 7303168 c:\windows\ERDNT\AutoBackup\2-8-2010\Users\00000001\NTUSER.DAT
+ 2010-02-06 03:56 . 2010-02-06 03:56 7303168 c:\windows\ERDNT\AutoBackup\2-6-2010\Users\00000001\NTUSER.DAT
+ 2010-02-05 08:56 . 2010-02-05 08:56 7303168 c:\windows\ERDNT\AutoBackup\2-5-2010\Users\00000001\NTUSER.DAT
+ 2010-02-04 06:10 . 2010-02-04 06:11 7303168 c:\windows\ERDNT\AutoBackup\2-4-2010\Users\00000001\NTUSER.DAT
+ 2010-02-03 04:32 . 2010-02-03 04:32 7303168 c:\windows\ERDNT\AutoBackup\2-3-2010\Users\00000001\NTUSER.DAT
+ 2010-02-02 01:09 . 2010-02-02 01:09 7303168 c:\windows\ERDNT\AutoBackup\2-2-2010\Users\00000001\NTUSER.DAT
+ 2010-02-11 01:26 . 2010-02-11 01:26 7303168 c:\windows\ERDNT\AutoBackup\2-11-2010\Users\00000001\NTUSER.DAT
+ 2010-02-10 02:07 . 2010-02-10 02:07 7303168 c:\windows\ERDNT\AutoBackup\2-10-2010\Users\00000001\NTUSER.DAT
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"OM_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master\Monitor.exe" [2005-11-29 57344]
"OM2_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" [2008-11-07 95536]
"ccleaner"="c:\program files\CCleaner\ccleaner.exe" [2009-11-24 1738040]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-20 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-05-27 16208384]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-12-08 32768]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-03 344064]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-05-03 32768]
"OM_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master\FirstStart.exe" [2005-11-29 40960]
"OM2_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe" [2008-11-07 54576]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2006-06-12 127036]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-24 210472]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-04-03 644696]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 1603152]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-01-28 2757512]
c:\documents and settings\Owner\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2009-11-1 385024]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [11/8/2008 9:22 PM 163280]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [11/8/2008 9:22 PM 19024]
.
Contents of the 'Scheduled Tasks' folder
2009-12-31 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 01:34]
2010-02-01 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2009-12-22 04:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.facebook.com/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-02-11 17:00
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-823518204-436374069-682003330-1003\Software\SecuROM\License information*]
"datasecu"=hex:f0,b2,0f,5f,db,ed,28,01,d7,d7,bf,06,0b,05,5d,ff,c7,1a,6f,08,01,
ae,69,1c,61,1d,8e,67,b5,06,eb,3b,ce,94,14,2a,5f,16,4d,81,a4,13,c7,62,b2,2d,\
"rkeysecu"=hex:40,8f,ec,2c,d5,4b,8a,1d,e4,bc,98,08,1c,6a,d3,ce
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(684)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(712)
c:\windows\system32\WININET.dll
c:\program files\ScanSoft\OmniPageSE4\OpHookSE4.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\RTHDCPL.EXE
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2010-02-11 17:05:17 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-11 06:05
ComboFix2.txt 2010-02-01 05:50
Pre-Run: 59,118,993,408 bytes free
Post-Run: 59,081,555,968 bytes free
- - End Of File - - A927859BB917B69D75B9161FF44E6557
thanks for your patience