ComboFix 10-04-19.08 - Amy 04/20/2010 12:11:51.3.2 - x86
Microsoft® Windows Vista™ Business 6.0.6002.2.1252.1.1033.18.1918.859 [GMT -4:00]
Running from: c:\users\Amy\Desktop\ComboFix.exe
AV: ESET NOD32 antivirus system 2.70 *On-access scanning enabled* (Updated) {E5E70D32-0101-
4F12-8FB0-D96ACA4F34C0}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\%appdata%
.
((((((((((((((((((((((((( Files Created from 2010-03-20 to 2010-04-20 )))))))))))))))))))))))))))))))
.
2010-04-20 16:18 . 2010-04-20 16:18 -------- d-----w- c:\users\QBDataServiceUser17
\AppData\Local\temp
2010-04-20 16:18 . 2010-04-20 16:18 -------- d-----w- c:\users\Leni\AppData\Local\temp
2010-04-20 16:18 . 2010-04-20 16:18 -------- d-----w- c:\users\John\AppData\Local\temp
2010-04-20 16:18 . 2010-04-20 16:18 -------- d-----w- c:\users\iTF\AppData\Local\temp
2010-04-20 16:18 . 2010-04-20 16:18 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-04-20 16:18 . 2010-04-20 16:18 -------- d-----w- c:\users\AWT
Employees\AppData\Local\temp
2010-04-19 20:07 . 2010-04-19 20:07 93056 ----a-w- C:\uwdyykow.sys
2010-04-19 14:52 . 2010-04-19 14:52 -------- d-----w- c:\program files\Common Files\Apple
2010-04-19 14:51 . 2010-04-19 14:51 -------- d-----w- c:\program files\Apple Software Update
2010-04-16 13:13 . 2008-04-07 09:38 22872 ----a-r- c:\windows\system32\AdobePDFUI.dll
2010-04-16 13:13 . 2008-04-07 09:38 45392 ----a-r- c:\windows\system32\AdobePDF.dll
2010-04-14 16:49 . 2010-04-14 16:31 19024 ----a-w- c:\windows\system32
\drivers\aswFsBlk.sys
2010-04-14 16:49 . 2010-04-14 16:35 162768 ----a-w- c:\windows\system32
\drivers\aswSP.sys
2010-04-14 16:49 . 2010-04-14 16:31 23376 ----a-w- c:\windows\system32
\drivers\aswRdr.sys
2010-04-14 16:49 . 2010-04-14 16:35 46672 ----a-w- c:\windows\system32
\drivers\aswTdi.sys
2010-04-14 16:49 . 2010-04-14 16:31 51792 ----a-w- c:\windows\system32
\drivers\aswMonFlt.sys
2010-04-14 16:47 . 2010-04-14 16:47 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-04-14 16:47 . 2010-04-14 16:47 153184 ----a-w- c:\windows\system32\aswBoot.exe
2010-04-14 16:45 . 2010-04-14 16:45 -------- d-----w- c:\programdata\Alwil Software
2010-04-14 16:30 . 2010-03-29 19:24 38224 ----a-w- c:\windows\system32
\drivers\mbamswissarmy.sys
2010-04-14 16:30 . 2010-03-29 19:24 20824 ----a-w- c:\windows\system32
\drivers\mbam.sys
2010-04-14 16:24 . 2010-04-14 16:24 -------- d-----w-
c:\users\Amy\AppData\Roaming\SUPERAntiSpyware.com
2010-04-14 16:23 . 2010-04-14 16:23 -------- d-----w- c:\program files\Common Files\Wise
Installation Wizard
2010-04-14 16:10 . 2010-04-14 16:10 -------- d-----w- c:\programdata\Kaspersky Lab Setup
Files
2010-04-14 12:13 . 2010-02-23 11:10 79360 ----a-w- c:\windows\system32
\drivers\mrxsmb20.sys
2010-04-14 12:13 . 2010-02-23 11:10 212992 ----a-w- c:\windows\system32
\drivers\mrxsmb10.sys
2010-04-14 12:13 . 2010-02-23 11:10 106496 ----a-w- c:\windows\system32
\drivers\mrxsmb.sys
2010-04-14 12:13 . 2010-02-18 14:07 3548040 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-04-14 12:13 . 2010-02-18 14:07 3600776 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-04-14 12:13 . 2010-03-05 14:01 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-04-14 12:12 . 2010-02-18 14:07 904576 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-04-14 12:12 . 2010-02-18 11:28 25088 ----a-w- c:\windows\system32
\drivers\tunnel.sys
2010-04-14 12:12 . 2010-02-18 13:30 200704 ----a-w- c:\windows\system32\iphlpsvc.dll
2010-04-14 12:07 . 2009-12-23 11:33 172032 ----a-w- c:\windows\system32\wintrust.dll
2010-04-14 12:07 . 2010-01-13 17:34 98304 ----a-w- c:\windows\system32\cabview.dll
2010-04-06 17:56 . 2010-04-06 17:56 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-04-06 17:56 . 2010-04-07 11:47 -------- d-----w-
c:\users\Amy\AppData\Roaming\skypePM
2010-04-06 17:55 . 2010-04-07 11:51 -------- d-----w- c:\users\Amy\AppData\Roaming\Skype
2010-03-31 11:56 . 2010-03-31 11:56 -------- d-----w- c:\program files\Common Files\Java
2010-03-29 18:07 . 2010-03-29 18:07 -------- d-----w- c:\users\John\AppData\Roaming\DivX
2010-03-26 12:41 . 2010-03-26 12:41 -------- d-----w- c:\users\AWT
Employees\AppData\Roaming\WD
2010-03-26 12:41 . 2010-04-19 11:08 -------- d-----w- c:\users\AWT
Employees\AppData\Local\Adobe
2010-03-26 12:41 . 2010-03-26 12:41 -------- d-----w- c:\users\AWT
Employees\AppData\Roaming\Logitech
2010-03-26 12:41 . 2010-03-26 12:41 -------- d-----w- c:\users\AWT
Employees\AppData\Roaming\ATI
2010-03-26 12:41 . 2010-03-26 12:41 -------- d-----w- c:\users\AWT
Employees\AppData\Local\ATI
2010-03-26 12:41 . 2010-03-26 12:41 123112 ----a-w- c:\users\AWT
Employees\AppData\Local\GDIPFONTCACHEV1.DAT
2010-03-26 12:41 . 2010-03-26 12:41 -------- d-----w- c:\users\AWT
Employees\AppData\Local\Google
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-19 20:50 . 2010-01-07 14:04 3028 ----a-w- c:\programdata\Intuit\QuickBooks
2010\qbbackup.sys
2010-04-19 14:53 . 2008-09-16 18:57 -------- d-----w- c:\programdata\Apple Computer
2010-04-16 16:50 . 2009-04-28 12:01 -------- d-----w- c:\programdata\Roxio
2010-04-16 13:47 . 2010-01-29 15:29 -------- d-----w- c:\program files\MSECACHE
2010-04-16 13:02 . 2009-09-16 14:43 -------- d-----w-
c:\users\Amy\AppData\Roaming\Download Manager
2010-04-14 17:39 . 2009-08-27 12:27 -------- d-----w- c:\programdata\Spybot - Search &
Destroy
2010-04-14 16:25 . 2010-04-14 16:25 52224 ----a-w-
c:\users\Amy\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-04-14 16:25 . 2010-04-14 16:25 117760 ----a-w-
c:\users\Amy\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-04-14 16:13 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-04-14 16:12 . 2009-08-26 19:41 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-04-13 16:54 . 2010-01-18 14:07 -------- d-----w- c:\programdata\Skype
2010-04-13 11:54 . 2009-08-27 12:27 -------- d-----w- c:\program files\Spybot - Search &
Destroy
2010-04-12 17:12 . 2009-09-10 14:39 -------- d-----w- c:\program files\Microsoft
2010-04-12 16:49 . 2008-07-17 15:07 -------- d-----w- c:\program files\Windows Live
2010-03-31 11:54 . 2009-09-08 14:39 -------- d-----w- c:\program files\Java
2010-03-09 08:28 . 2008-12-19 12:54 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-02-25 14:21 . 2008-07-15 13:27 123112 ----a-w-
c:\users\John\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-24 18:50 . 2008-07-07 15:58 123112 ----a-w-
c:\users\Amy\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-24 14:16 . 2009-10-05 11:59 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-02-23 06:39 . 2010-03-31 11:47 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-23 06:33 . 2010-03-31 11:47 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-02-23 06:33 . 2010-03-31 11:47 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-02-23 04:55 . 2010-03-31 11:47 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-02-20 23:06 . 2010-03-10 21:47 24064 ----a-w- c:\windows\system32\nshhttp.dll
2010-02-20 23:05 . 2010-03-10 21:47 30720 ----a-w- c:\windows\system32\httpapi.dll
2010-02-20 20:53 . 2010-03-10 21:47 411648 ----a-w- c:\windows\system32\drivers\http.sys
2010-02-02 13:21 . 2010-01-07 14:03 869720 ----a-w- c:\programdata\Intuit\QuickBooks
2010\Components\DownloadQB19\Patch\qbpatch.exe
2010-01-25 12:00 . 2010-02-24 13:02 471552 ----a-w- c:\windows\system32\secproc_isv.dll
2010-01-25 12:00 . 2010-02-24 13:02 152576 ----a-w- c:\windows\system32
\secproc_ssp_isv.dll
2010-01-25 12:00 . 2010-02-24 13:02 152064 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-01-25 12:00 . 2010-02-24 13:02 471552 ----a-w- c:\windows\system32\secproc.dll
2010-01-25 11:58 . 2010-02-24 13:02 332288 ----a-w- c:\windows\system32\msdrm.dll
2010-01-25 08:21 . 2010-02-24 13:02 526336 ----a-w- c:\windows\system32
\RMActivate_isv.exe
2010-01-25 08:21 . 2010-02-24 13:02 346624 ----a-w- c:\windows\system32
\RMActivate_ssp_isv.exe
2010-01-25 08:21 . 2010-02-24 13:02 347136 ----a-w- c:\windows\system32
\RMActivate_ssp.exe
2010-01-25 08:21 . 2010-02-24 13:02 518144 ----a-w- c:\windows\system32\RMActivate.exe
2010-01-23 09:26 . 2010-02-24 13:03 2048 ----a-w- c:\windows\system32\tzres.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"SUPERAntiSpyware"="d:\programs\SUPERAntiSpyware.exe" [2010-03-29 2012912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 76304]
"RtHDVCpl"="RtHDVCpl.exe" [2007-04-23 4435968]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2008-06-23 949376]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\11.0
\SharedCOM\RoxWatchTray11.exe" [2008-08-14 240112]
"CPMonitor"="c:\program files\Roxio Creator 2009\5.0\CPMonitor.exe" [2008-08-10 80368]
"WD Anywhere Backup"="c:\program files\WD\WD Anywhere Backup\MemeoLauncher2.exe" [2009-
04-17 197856]
"Adobe Acrobat Speed Launcher"="d:\programs\Adobe Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06
-12 37232]
"Acrobat Assistant 8.0"="d:\programs\Adobe Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-12 640376]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18
248040]
"Intuit SyncManager"="c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe" [2008-11
-18 623880]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-
04-04 36272]
"avast5"="d:\programs\Avast\avastUI.exe" [2010-04-14 2790472]
"QuickTime Task"="d:\programs\QTTask.exe" [2010-03-18 421888]
c:\users\Amy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
QuickBooks Pro 2010.lnk - c:\program files\Intuit\QuickBooks 2009\QBW32Pro.exe [2010-1-25
693592]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-6-23 805392]
Microsoft Office Outlook 2007.lnk - c:\windows\Installer\{91120000-0030-0000-0000-
0000000FF1CE}\outicon.exe [2009-9-1 845584]
QuickBooks Update Agent.lnk - c:\program files\Common
Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2010-1-25 984408]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "d:\programs\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!
SASWinLogon]
2009-09-03 19:21 548352 ----a-w- d:\programs\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
2001-12-21 03:34 24576 ----a-w- c:\program files\Stardock\Object
Desktop\ThemeManager\fastload.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\beep.sys]
@="beep"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):43,48,5c,39,47,36,ca,01
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1467385788-3812229184-
58112958-1000]
"EnableNotificationsRef"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1467385788-3812229184-
58112958-1001]
"EnableNotificationsRef"=dword:00000001
R2 Roxio Upnp Server 11;Roxio Upnp Server 11;c:\program files\Roxio Creator 2009\Digital Home 11
\RoxioUpnpService11.exe [2008-08-14 367088]
R2 RoxLiveShare11;LiveShare P2P Server 11;c:\program files\Common Files\Roxio Shared\11.0
\SharedCOM\RoxLiveShare11.exe [2008-08-14 309744]
R2 RoxWatch11;Roxio Hard Drive Watcher 11;c:\program files\Common Files\Roxio Shared\11.0
\SharedCOM\RoxWatch11.exe [2008-08-14 170480]
R3 Roxio UPnP Renderer 11;Roxio UPnP Renderer 11;c:\program files\Roxio Creator 2009\Digital
Home 11\RoxioUPnPRenderer11.exe [2008-08-14 313840]
R3 RoxMediaDB11;RoxMediaDB11;c:\program files\Common Files\Roxio Shared\11.0
\SharedCOM\RoxMediaDB11.exe [2008-08-14 1124848]
S1 aswSP;aswSP; [x]
S1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2008-06-23 15424]
S1 SASDIFSV;SASDIFSV;d:\programs\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL;d:\programs\SASKUTIL.SYS [2010-02-17 66632]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-04-14 51792]
S2 MemeoBackgroundService;MemeoBackgroundService;c:\program files\WD\WD Anywhere
Backup\MemeoBackgroundService.exe [2009-04-17 25824]
S2 SBSDWSCService;SBSD Security Center Service;d:\programs\Spybot - Search &
Destroy\SDWinSec.exe [2009-01-26 1153368]
S3 SASENUM;SASENUM;d:\programs\SASENUM.SYS [2010-02-17 12872]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.aqualibrium.ca/
IE: Append Link Target to Existing PDF - c:\program files\Common
Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common
Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common
Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common
Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
LSP: c:\windows\system32\imon.dll
Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-86486D72E749} - c:\program
files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll
FF - ProfilePath - c:\users\Amy\AppData\Roaming\Mozilla\Firefox\Profiles\snfr3dd2.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.aqualibrium.ca/
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: d:\programs\DivX\DivX Player\npDivxPlayerPlugin.dll
FF - plugin: d:\programs\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: d:\programs\Plugins\npqtplugin.dll
FF - plugin: d:\programs\Plugins\npqtplugin2.dll
FF - plugin: d:\programs\Plugins\npqtplugin3.dll
FF - plugin: d:\programs\Plugins\npqtplugin4.dll
FF - plugin: d:\programs\Plugins\npqtplugin5.dll
FF - plugin: d:\programs\Plugins\npqtplugin6.dll
FF - plugin: d:\programs\Plugins\npqtplugin7.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-
08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation
Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref
("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark",
32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref
("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref
("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref
("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref
("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref
("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual",
"http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref
("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-
a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-
a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add",
"addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36",
"getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled",
true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref
("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet",
false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable",
false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime",
20);
.
- - - - ORPHANS REMOVED - - - -
ActiveSetup-ccc-core-static - msiexec
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-04-20 12:24
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(4372)
c:\program files\Logitech\SetPoint\lgscroll.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
d:\programs\Avast\AvastSvc.exe
c:\program files\Eset\nod32krn.exe
c:\program files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\RtHDVCpl.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
c:\progra~1\Intuit\QUICKB~2\QBDBMgr.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2010-04-20 12:29:11 - machine was rebooted
ComboFix-quarantined-files.txt 2010-04-20 16:29
Pre-Run: 508,006,400 bytes free
Post-Run: 833,646,592 bytes free
- - End Of File - - D989B3D0A01E8124F3F0AF6EB9884B69
DDS (Ver_10-03-17.01) - NTFSx86
Run by Amy at 12:35:07.67 on Tue 04/20/2010
Internet Explorer: 8.0.6001.18904 BrowserJavaVersion: 1.6.0_19
Microsoft® Windows Vista™ Business 6.0.6002.2.1252.1.1033.18.1918.698 [GMT -4:00]
AV: ESET NOD32 antivirus system 2.70 *On-access scanning enabled* (Updated) {E5E70D32-0101-
4F12-8FB0-D96ACA4F34C0}
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: SUPERAntiSpyware *enabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\Ati2evxx.exe
D:\Programs\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\WD\WD Anywhere Backup\MemeoBackgroundService.exe
C:\Program Files\Eset\nod32krn.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
D:\Programs\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Roxio Creator 2009\5.0\CPMonitor.exe
D:\Programs\Adobe Acrobat 9.0\Acrobat\acrotray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
D:\Programs\Avast\AvastUI.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Intuit\QuickBooks 2009\QBW32Pro.exe
C:\Windows\system32\taskeng.exe
C:\PROGRA~1\Intuit\QUICKB~2\QBDBMgr.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\Explorer.exe
C:\Windows\system32\notepad.exe
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
C:\Program Files\Intuit\QuickBooks 2009\qbw32.exe
C:\Program Files\Common Files\Intuit\QuickBooks\axlbridge.exe
C:\Program Files\ESET\nod32kui.exe
D:\Programs\SUPERAntiSpyware.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Computer Problems\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.aqualibrium.ca/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common
files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program
files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program
files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program
files\java\jre6\bin\jp2ssv.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files\common
files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common
files\adobe\acrobat\activex\AcroIEFavClient.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [StartCCC] c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe
uRun: [SUPERAntiSpyware] d:\programs\SUPERAntiSpyware.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [nod32kui] "c:\program files\eset\nod32kui.exe" /WAITSERVICE
mRun: [googletalk] c:\program files\google\google talk\googletalk.exe /autostart
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\11.0
\sharedcom\RoxWatchTray11.exe"
mRun: [CPMonitor] "c:\program files\roxio creator 2009\5.0\CPMonitor.exe"
mRun: [WD Anywhere Backup] c:\program files\wd\wd anywhere backup\MemeoLauncher2.exe --
silent
mRun: [Adobe Acrobat Speed Launcher] "d:\programs\adobe acrobat 9.0\acrobat\Acrobat_sl.exe"
mRun: [Acrobat Assistant 8.0] "d:\programs\adobe acrobat 9.0\acrobat\Acrotray.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Intuit SyncManager] c:\program files\common files\intuit\sync\IntuitSyncManager.exe
startup
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [avast5] d:\programs\avast\avastUI.exe /nogui
mRun: [QuickTime Task] "d:\programs\QTTask.exe" -atboottime
StartupFolder: c:\users\amy\appdata\roaming\micros~1\windows\startm~1
\programs\startup\quickb~1.lnk - c:\program files\intuit\quickbooks 2009\QBW32Pro.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\logite~1.lnk - c:\program
files\logitech\setpoint\SetPoint.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\micros~1.lnk -
c:\windows\installer\{91120000-0030-0000-0000-0000000ff1ce}\outicon.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickb~1.lnk -
c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Append Link Target to Existing PDF - c:\program files\common
files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\common
files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\common
files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\common
files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~1\office12\EXCEL.EXE/3000
IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} -
c:\progra~1\micros~1\office12\REFIEBAR.DLL
LSP: c:\windows\system32\imon.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-
1_6_0_19-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-
1_6_0_19-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-
1_6_0_19-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} -
hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-86486D72E749} - c:\program
files\intuit\quickbooks 2009\HelpAsyncPluggableProtocol.dll
Notify: !SASWinLogon - d:\programs\SASWINLO.dll
Notify: WB - c:\program files\stardock\object desktop\thememanager\fastload.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} -
d:\programs\SASSEH.DLL
================= FIREFOX ===================
FF - ProfilePath - c:\users\amy\appdata\roaming\mozilla\firefox\profiles\snfr3dd2.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.aqualibrium.ca/
FF - plugin: d:\programs\divx\divx player\npDivxPlayerPlugin.dll
FF - plugin: d:\programs\divx\divx plus web player\npdivx32.dll
FF - plugin: d:\programs\plugins\npqtplugin.dll
FF - plugin: d:\programs\plugins\npqtplugin2.dll
FF - plugin: d:\programs\plugins\npqtplugin3.dll
FF - plugin: d:\programs\plugins\npqtplugin4.dll
FF - plugin: d:\programs\plugins\npqtplugin5.dll
FF - plugin: d:\programs\plugins\npqtplugin6.dll
FF - plugin: d:\programs\plugins\npqtplugin7.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-
08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation
foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla
firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla
firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla
firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref
("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref
("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref
("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref
("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref
("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref
("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual",
"http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref
("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-
a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-
a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add",
"addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36",
"getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled",
true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref
("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet",
false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable",
false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime",
20);
============= SERVICES / DRIVERS ===============
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-4-14 162768]
R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2008-6-23 15424]
R1 SASDIFSV;SASDIFSV;d:\programs\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;d:\programs\SASKUTIL.SYS [2010-2-17 66632]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-4-14 19024]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-4-14 51792]
R2 avast! Antivirus;avast! Antivirus;d:\programs\avast\AvastSvc.exe [2010-4-14 40384]
R2 MemeoBackgroundService;MemeoBackgroundService;c:\program files\wd\wd anywhere
backup\MemeoBackgroundService.exe [2009-4-17 25824]
R2 NOD32krn;NOD32 Kernel Service;c:\program files\eset\nod32krn.exe [2008-6-23 552064]
R2 SBSDWSCService;SBSD Security Center Service;d:\programs\spybot - search &
destroy\SDWinSec.exe [2010-4-14 1153368]
R3 avast! Web Scanner;avast! Web Scanner;d:\programs\avast\AvastSvc.exe [2010-4-14 40384]
R3 SASENUM;SASENUM;d:\programs\SASENUM.SYS [2010-2-17 12872]
S2 Roxio Upnp Server 11;Roxio Upnp Server 11;c:\program files\roxio creator 2009\digital home 11
\RoxioUpnpService11.exe [2008-8-14 367088]
S2 RoxLiveShare11;LiveShare P2P Server 11;c:\program files\common files\roxio shared\11.0
\sharedcom\RoxLiveShare11.exe [2008-8-14 309744]
S2 RoxWatch11;Roxio Hard Drive Watcher 11;c:\program files\common files\roxio shared\11.0
\sharedcom\RoxWatch11.exe [2008-8-14 170480]
S3 avast! Mail Scanner;avast! Mail Scanner;d:\programs\avast\AvastSvc.exe [2010-4-14 40384]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k
LocalServiceAndNoImpersonation [2008-1-20 21504]
S3 Roxio UPnP Renderer 11;Roxio UPnP Renderer 11;c:\program files\roxio creator 2009\digital home
11\RoxioUPnPRenderer11.exe [2008-8-14 313840]
S3 RoxMediaDB11;RoxMediaDB11;c:\program files\common files\roxio shared\11.0
\sharedcom\RoxMediaDB11.exe [2009-3-3 1124848]
=============== Created Last 30 ================
2010-04-20 16:21:49 0 d-----w- C:\$RECYCLE.BIN
2010-04-20 16:04:48 77312 ----a-w- c:\windows\MBR.exe
2010-04-20 16:04:43 161792 ----a-w- c:\windows\SWREG.exe
2010-04-20 16:04:42 98816 ----a-w- c:\windows\sed.exe
2010-04-20 16:04:14 0 d-----w- C:\ComboFix
2010-04-19 20:07:28 93056 ----a-w- C:\uwdyykow.sys
2010-04-16 13:13:33 22872 ----a-r- c:\windows\system32\AdobePDFUI.dll
2010-04-16 13:13:16 45392 ----a-r- c:\windows\system32\AdobePDF.dll
2010-04-14 16:49:18 51792 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2010-04-14 16:45:55 0 d-----w- c:\programdata\Alwil Software
2010-04-14 16:30:08 38224 ----a-w- c:\windows\system32
\drivers\mbamswissarmy.sys
2010-04-14 16:30:04 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-14 16:24:50 0 d-----w-
c:\users\amy\appdata\roaming\SUPERAntiSpyware.com
2010-04-14 16:23:29 0 d-----w- c:\program files\common files\Wise Installation
Wizard
2010-04-14 16:10:42 0 d-----w- c:\programdata\Kaspersky Lab Setup Files
2010-04-14 12:13:23 79360 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-04-14 12:13:22 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-04-14 12:13:21 106496 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-04-14 12:13:10 3548040 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-04-14 12:13:09 3600776 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-04-14 12:13:04 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-04-14 12:12:50 62464 ----a-w- c:\windows\system32\l3codeca.acm
2010-04-14 12:12:50 220672 ----a-w- c:\windows\system32\l3codecp.acm
2010-04-14 12:12:14 904576 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-04-14 12:12:12 25088 ----a-w- c:\windows\system32\drivers\tunnel.sys
2010-04-14 12:12:11 200704 ----a-w- c:\windows\system32\iphlpsvc.dll
2010-04-14 12:07:14 172032 ----a-w- c:\windows\system32\wintrust.dll
2010-04-14 12:07:12 98304 ----a-w- c:\windows\system32\cabview.dll
2010-04-06 17:56:15 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-03-31 11:56:35 0 d-----w- c:\programdata\Sun
==================== Find3M ====================
2010-04-16 12:52:19 86016 ----a-w- c:\windows\inf\infstor.dat
2010-04-16 12:52:19 51200 ----a-w- c:\windows\inf\infpub.dat
2010-04-16 12:52:19 143360 ----a-w- c:\windows\inf\infstrng.dat
2010-03-12 22:02:38 261632 ----a-w- c:\windows\PEV.exe
2010-03-09 08:28:20 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-02-24 14:16:06 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-02-23 06:39:13 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-23 06:33:45 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-02-23 06:33:45 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-02-23 04:55:36 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-02-20 23:06:41 24064 ----a-w- c:\windows\system32\nshhttp.dll
2010-02-20 23:05:14 30720 ----a-w- c:\windows\system32\httpapi.dll
2010-02-20 20:53:34 411648 ----a-w- c:\windows\system32\drivers\http.sys
2010-01-25 12:00:35 471552 ----a-w- c:\windows\system32\secproc_isv.dll
2010-01-25 12:00:35 152576 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-01-25 12:00:35 152064 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-01-25 12:00:22 471552 ----a-w- c:\windows\system32\secproc.dll
2010-01-25 11:58:52 332288 ----a-w- c:\windows\system32\msdrm.dll
2010-01-25 08:21:20 526336 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-01-25 08:21:20 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-01-25 08:21:18 518144 ----a-w- c:\windows\system32\RMActivate.exe
2010-01-25 08:21:18 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-01-23 09:26:13 2048 ----a-w- c:\windows\system32\tzres.dll
2009-11-17 21:52:46 665600 ----a-w- c:\windows\inf\drvindex.dat
2008-01-21 02:43:58 174 --sha-w- c:\program files\desktop.ini
2006-11-02 12:42:07 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:07 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:07 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:07 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
============= FINISH: 12:36:02.40 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-03-17.01)
Microsoft® Windows Vista™ Business
Boot Device: \Device\HarddiskVolume1
Install Date: 6/23/2008 5:30:49 AM
System Uptime: 4/20/2010 12:20:47 PM (0 hours ago)
Motherboard: ASUSTeK Computer INC. | | M2A-VM
Processor: AMD Athlon(tm) 64 X2 Dual Core Processor 5200+ | Socket AM2 | 2600/200mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 32 GiB total, 0.839 GiB free.
D: is FIXED (NTFS) - 266 GiB total, 221.019 GiB free.
E: is CDROM ()
==== Disabled Device Manager Items =============
==== System Restore Points ===================
==== Installed Programs ======================
2007 Microsoft Office system
AAC Decoder
Adobe Acrobat 9 Standard - English, Français, Deutsch
Adobe Acrobat 9.2.0 - CPSID_50026
Adobe Common File Installer
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Help Center 1.0
Adobe Photoshop CS2
Adobe Reader 9.3.2
Adobe Stock Photos 1.0
Apple Application Support
Apple Software Update
ATI Catalyst Install Manager
AutoUpdate
avast! Free Antivirus
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Vista
ccc-core-static
ccc-utility
CCC Help English
CDDRV_Installer
Color LaserJet 2600n
DirectX 9 Runtime
DivX Codec
DivX Player
DivX Plus DirectShow Filters
DivX Plus Web Player
DivX Version Checker
ERUNT 1.1j
Google Talk (remove only)
H.264 Decoder
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Java Auto Updater
Java(TM) 6 Update 19
KhalInstallWrapper
Logitech SetPoint
Logitech Updater
Macromedia Flash Player 8
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Office 2007 Primary Interop Assemblies
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional Hybrid 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Visio 2007 Service Pack 2 (SP2)
Microsoft Office Visio Standard 2007
Microsoft Office Word MUI (English) 2007
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual Studio 2005 Tools for Office Runtime
Microsoft Windows Media Video 9 VCM
MKV Splitter
Mozilla Firefox (3.6.3)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB941833)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 Parser and SDK
neroxml
NOD32 antivirus system
NOD32 FiX
Octoshape add-in for Adobe Flash Player
QuickBooks
QuickBooks Pro 2010
QuickTime
Realtek High Definition Audio Driver
Roxio Activation Module
Roxio BackOnTrack
Roxio CinePlayer
Roxio CinePlayer Decoder Pack
Roxio Creator 2009
Roxio File Backup
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB973704)
Security Update for Microsoft Office Excel 2007 (KB973593)
Security Update for Microsoft Office Outlook 2007 (KB972363)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office Publisher 2007 (KB969693)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Skins
Skype™ 4.2
SmartSound Quicktracks Plugin
Spelling Dictionaries Support For Adobe Reader 9
Spybot - Search & Destroy
SUPERAntiSpyware Free Edition
SupportSoft Assisted Service
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office InfoPath 2007 (KB976416)
Update for Microsoft Office Infopath 2007 Help (KB963662)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Visio 2007 Help (KB963666)
Update for Microsoft Office Word 2007 (KB974561)
Update for Microsoft Office Word 2007 Help (KB963665)
Update for Outlook 2007 Junk Email Filter (kb976884)
VC80CRTRedist - 8.0.50727.4053
Visual Studio 2005 Tools for Office Second Edition Runtime
WD Anywhere Backup
Windows Live ID Sign-in Assistant
Windows Media Player Firefox Plugin
WinRAR archiver
==== End Of File ===========================