ComboFix 10-03-13.01 - test 03/13/2010 20:00:29.6.2 - x86
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.2038.1045 [GMT -5:00]
Running from: c:\users\test\Desktop\Security Issues 03.2010\ComboFix.exe
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
* Resident AV is active
.
((((((((((((((((((((((((( Files Created from 2010-02-14 to 2010-03-14 )))))))))))))))))))))))))))))))
.
2010-03-14 01:20 . 2010-03-14 01:20 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-03-14 01:20 . 2010-03-14 01:20 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-03-11 03:18 . 2010-03-12 12:38 -------- d-----w- c:\users\test\AppData\Local\Adobe
2010-03-10 10:21 . 2010-03-10 10:24 20829680 ----a-w- c:\users\test\AppData\Roaming\Real\Update\setup3.10\rp\RealPlayerSPGold.exe
2010-03-10 10:21 . 2010-03-10 10:21 8405312 ----a-w- c:\users\test\AppData\Roaming\Real\Update\setup3.10\gtb\GOOGLE_TOOLBAR\GoogleToolbarInstaller.exe
2010-03-10 10:20 . 2010-03-10 10:20 149000 ----a-w- c:\users\test\AppData\Roaming\Real\Update\setup3.10\chr_helper\LaunchHelper.exe
2010-03-10 10:19 . 2010-03-10 10:20 10309448 ----a-w- c:\users\test\AppData\Roaming\Real\Update\setup3.10\chr\ChromeInstaller.exe
2010-03-10 10:17 . 2010-03-10 10:17 181768 ----a-w- c:\users\test\AppData\Roaming\Real\Update\setup3.10\carb\LaunchHelper.exe
2010-03-10 10:17 . 2010-03-10 10:17 283280 ----a-w- c:\users\test\AppData\Roaming\Real\Update\setup3.10\carb\CarboniteSetupLiteRealPreinstaller.exe
2010-03-10 10:17 . 2010-03-10 10:17 79368 ----a-w- c:\users\test\AppData\Roaming\Real\Update\setup3.10\RUP\vista.exe
2010-03-10 10:17 . 2010-03-10 10:17 64000 ----a-w- c:\users\test\AppData\Roaming\Real\Update\setup3.10\RUP\inst_config\gcapi_dll.dll
2010-03-10 10:17 . 2010-03-10 10:17 52288 ----a-w- c:\users\test\AppData\Roaming\Real\Update\setup3.10\RUP\inst_config\gtapi.dll
2010-03-10 10:17 . 2010-03-10 10:17 50688 ----a-w- c:\users\test\AppData\Roaming\Real\Update\setup3.10\RUP\inst_config\fftbapi.dll
2010-03-10 10:17 . 2010-03-10 10:17 118784 ----a-w- c:\users\test\AppData\Roaming\Real\Update\setup3.10\RUP\inst_config\compat.dll
2010-03-10 10:17 . 2010-03-10 10:17 49152 ----a-w- c:\users\test\AppData\Roaming\Real\Update\setup3.10\RUP\inst_config\CarboniteCompatibility.dll
2010-03-10 01:06 . 2010-03-10 01:06 439816 ----a-w- c:\users\test\AppData\Roaming\Real\Update\setup3.10\setup.exe
2010-03-10 01:02 . 2010-03-10 01:02 -------- d-----w- c:\users\test\AppData\Roaming\Malwarebytes
2010-03-10 01:01 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-10 01:01 . 2010-03-10 01:01 -------- d-----w- c:\programdata\Malwarebytes
2010-03-10 01:01 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-10 01:01 . 2010-03-10 01:02 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-07 14:02 . 2010-03-07 14:02 -------- d-----w- c:\program files\IKEA HomePlanner
2010-03-06 22:41 . 2010-03-06 22:41 -------- d-----w- C:\7ffedab50166b21aa56df2d5d6f345fc
2010-03-06 12:33 . 2010-03-06 12:33 -------- d-----w- c:\programdata\WinZip
2010-03-05 04:10 . 2010-03-07 14:01 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-03-02 08:11 . 2010-03-02 08:11 -------- d-----w- c:\windows\Sun
2010-03-01 01:28 . 2010-03-01 01:28 -------- d-----w- c:\users\test\.jmf
2010-03-01 01:27 . 2010-03-01 01:30 -------- d-----w- c:\users\test\Spark
2010-03-01 01:27 . 2010-03-01 01:27 -------- d-----w- c:\program files\Spark
2010-02-24 19:12 . 2010-02-24 19:12 -------- d-----w- c:\program files\ERUNT
2010-02-24 14:29 . 2010-02-24 14:29 -------- d-----w- c:\users\test\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2010-02-24 06:49 . 2009-12-13 09:30 641536 ----a-w- c:\windows\system32\CPFilters.dll
2010-02-24 06:49 . 2009-12-13 09:29 417792 ----a-w- c:\windows\system32\msdri.dll
2010-02-24 06:49 . 2009-12-13 09:30 465408 ----a-w- c:\windows\system32\psisdecd.dll
2010-02-24 06:48 . 2010-02-02 07:45 2048 ----a-w- c:\windows\system32\tzres.dll
2010-02-24 00:52 . 2010-02-24 00:52 38784 ----a-w- c:\users\Default\AppData\Roaming\Macromedia\Flash Player\
www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-02-24 00:51 . 2010-02-24 00:51 86016 ----a-w- c:\programdata\NOS\Adobe_Downloads\arh.exe
2010-02-24 00:51 . 2010-02-24 13:19 -------- d-----w- c:\programdata\NOS
2010-02-20 17:48 . 2010-02-23 04:36 -------- d-----w- c:\program files\Windows Live Safety Center
2010-02-20 15:59 . 2010-02-20 15:59 3262 ----a-r- c:\users\test\AppData\Roaming\Microsoft\Installer\{AACD915A-A897-43FA-BC5B-00D06DFDCD2F}\_13B08E6A0151F39DE3437C.exe
2010-02-20 15:59 . 2010-02-20 15:59 2238 ----a-r- c:\users\test\AppData\Roaming\Microsoft\Installer\{AACD915A-A897-43FA-BC5B-00D06DFDCD2F}\_6FEFF9B68218417F98F549.exe
2010-02-20 15:59 . 2010-02-20 15:59 -------- d-----w- c:\program files\Microsoft Office SharePoint Server 2007 Training (Standalone Edition)
2010-02-20 14:29 . 2010-03-13 19:01 -------- d-----w- c:\program files\Microsoft Security Essentials
2010-02-16 20:23 . 2010-02-19 04:34 -------- d-----w- c:\users\test\AppData\Roaming\GetRightToGo
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-14 01:13 . 2009-12-18 20:07 -------- d-----w- c:\programdata\Webroot
2010-03-13 19:27 . 2009-03-18 06:30 -------- d-----w- c:\users\test\AppData\Roaming\Skype
2010-03-11 08:13 . 2006-12-18 04:50 -------- d-----w- c:\programdata\Microsoft Help
2010-03-11 00:24 . 2006-12-18 05:26 -------- d-----w- c:\program files\Java
2010-03-01 10:32 . 2009-09-21 13:03 3803208 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2010-02-24 14:16 . 2009-10-03 13:11 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-02-24 00:55 . 2006-12-18 04:57 -------- d-----w- c:\program files\Common Files\Adobe
2010-02-24 00:52 . 2009-06-02 14:56 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-02-24 00:52 . 2009-06-02 14:50 38784 ----a-w- c:\users\test\AppData\Roaming\Macromedia\Flash Player\
www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-02-11 15:04 . 2010-02-11 15:04 -------- d-----w- c:\programdata\McAfee
2010-02-11 14:42 . 2009-02-15 05:31 -------- d-----w- c:\program files\Google
2010-02-05 18:17 . 2009-10-28 18:34 106648 ----a-w- c:\users\test\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-05 17:38 . 2009-06-19 04:24 389784 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2010-02-05 17:38 . 2009-06-19 04:23 823928 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2010-02-05 17:38 . 2009-06-19 04:23 1181328 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AAWService.exe
2010-02-02 02:26 . 2010-02-02 02:26 509552 ----a-w- c:\programdata\Google\Google Toolbar\Update\gtb64AB.tmp.exe
2010-01-30 22:43 . 2010-01-30 22:43 509552 ----a-w- c:\programdata\Google\Google Toolbar\Update\gtb5E1D.tmp.exe
2010-01-27 17:40 . 2009-06-19 04:24 862040 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\threatwork.exe
2010-01-27 17:40 . 2009-06-01 13:40 15880 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\lsdelete.exe
2010-01-27 17:40 . 2009-04-13 14:34 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-01-27 17:40 . 2009-06-19 04:24 206944 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\lavamessage.dll
2010-01-27 17:40 . 2009-06-19 04:24 390288 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\lavalicense.dll
2010-01-27 17:40 . 2009-11-07 23:38 537576 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\aawapi.dll
2010-01-27 17:40 . 2009-06-01 13:38 163728 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\ShellExt.dll
2010-01-27 17:40 . 2009-06-19 04:24 8 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Savapibridge.dll
2010-01-27 17:40 . 2009-06-19 04:24 6296864 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Resources.dll
2010-01-27 17:39 . 2009-06-01 13:28 327000 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\RPAPI.dll
2010-01-27 17:39 . 2009-06-01 13:28 87496 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2010-01-27 17:39 . 2009-06-19 04:24 933120 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\CEAPI.dll
2010-01-27 17:39 . 2009-06-19 04:23 816784 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2010-01-27 17:39 . 2009-06-19 04:23 1643272 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2010-01-27 17:39 . 2009-06-19 04:23 788880 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AAWTray.exe
2010-01-23 00:14 . 2009-06-23 01:48 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-18 23:29 . 2010-02-10 00:03 365568 ----a-w- c:\windows\system32\secproc_isv.dll
2010-01-18 23:29 . 2010-02-10 00:03 85504 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-01-18 23:29 . 2010-02-10 00:03 85504 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-01-18 23:29 . 2010-02-10 00:03 369152 ----a-w- c:\windows\system32\secproc.dll
2010-01-18 23:28 . 2010-02-10 00:03 324608 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-01-18 23:28 . 2010-02-10 00:03 277504 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-01-18 23:28 . 2010-02-10 00:03 320512 ----a-w- c:\windows\system32\RMActivate.exe
2010-01-18 23:28 . 2010-02-10 00:03 280064 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-01-13 20:00 . 2009-02-23 03:59 -------- d-----w- c:\program files\TurboTax
2010-01-08 03:18 . 2010-02-10 00:03 221184 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-01-08 03:17 . 2010-02-10 00:03 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-12-29 17:17 . 2009-12-29 17:17 25214 ----a-r- c:\users\test\AppData\Roaming\Microsoft\Installer\{E296E0ED-038F-4A5A-9513-642F2FA17A59}\ARPPRODUCTICON.exe
2009-12-29 17:14 . 2009-12-29 17:10 32262536 ----a-w- c:\users\test\AppData\Roaming\Smith Micro\Updates\VZAM_7.2.1_2420b_Pantech_UM150.exe
2009-12-19 09:02 . 2010-01-22 00:19 977920 ----a-w- c:\windows\system32\wininet.dll
2009-12-19 09:02 . 2010-02-10 00:03 12288 ----a-w- c:\windows\system32\tsbyuv.dll
2009-12-19 09:02 . 2010-02-10 00:03 1328640 ----a-w- c:\windows\system32\quartz.dll
2009-12-19 09:02 . 2010-02-10 00:03 22016 ----a-w- c:\windows\system32\msyuv.dll
2009-12-19 09:02 . 2010-02-10 00:03 31744 ----a-w- c:\windows\system32\msvidc32.dll
2009-12-19 09:02 . 2010-02-10 00:03 13312 ----a-w- c:\windows\system32\msrle32.dll
2009-12-19 09:02 . 2010-02-10 00:03 84480 ----a-w- c:\windows\system32\mciavi32.dll
2009-12-19 09:02 . 2010-02-10 00:03 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2009-12-19 09:02 . 2010-02-10 00:03 91648 ----a-w- c:\windows\system32\avifil32.dll
2009-12-18 20:10 . 2009-12-18 20:10 4991352 ----a-w- c:\program files\Common Files\wruninstall.exe
2009-12-18 20:10 . 2009-12-18 20:10 712072 ----a-w- c:\program files\Common Files\GenericSB.dll
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.
((((((((((((((((((((((((((((( SnapShot@2010-03-09_02.15.34 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-11-29 04:19 . 2010-03-09 03:51 33182 c:\windows\System32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 04:55 . 2010-03-14 00:55 36312 c:\windows\System32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2009-10-30 14:13 . 2010-03-14 00:55 10372 c:\windows\System32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2613721486-2466184251-1953233058-1000_UserData.bin
+ 2009-10-28 17:36 . 2010-03-14 00:53 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-10-28 17:36 . 2010-03-08 23:09 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-10-28 17:36 . 2010-03-14 00:53 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-10-28 17:36 . 2010-03-08 23:09 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:41 . 2010-03-14 00:53 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:41 . 2010-03-08 23:09 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:34 . 2010-03-13 03:24 78752 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
+ 2009-10-28 22:13 . 2010-03-14 01:11 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-10-28 22:13 . 2010-03-09 02:14 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-10-28 22:13 . 2010-03-14 01:11 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-10-28 22:13 . 2010-03-09 02:14 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-10-28 22:13 . 2010-03-09 02:14 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-10-28 22:13 . 2010-03-14 01:11 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-02-19 04:29 . 2010-02-21 12:54 35088 c:\windows\Installer\{91120000-003B-0000-0000-0000000FF1CE}\oisicon.exe
+ 2010-02-19 04:29 . 2010-03-11 08:13 35088 c:\windows\Installer\{91120000-003B-0000-0000-0000000FF1CE}\oisicon.exe
- 2010-02-19 04:29 . 2010-02-21 12:54 18704 c:\windows\Installer\{91120000-003B-0000-0000-0000000FF1CE}\mspicons.exe
+ 2010-02-19 04:29 . 2010-03-11 08:13 18704 c:\windows\Installer\{91120000-003B-0000-0000-0000000FF1CE}\mspicons.exe
- 2010-02-19 04:29 . 2010-02-21 12:54 20240 c:\windows\Installer\{91120000-003B-0000-0000-0000000FF1CE}\cagicon.exe
+ 2010-02-19 04:29 . 2010-03-11 08:13 20240 c:\windows\Installer\{91120000-003B-0000-0000-0000000FF1CE}\cagicon.exe
+ 2006-12-18 04:53 . 2010-03-11 08:12 35088 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
- 2006-12-18 04:53 . 2010-02-05 18:03 35088 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
- 2006-12-18 04:53 . 2010-02-05 18:03 18704 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
+ 2006-12-18 04:53 . 2010-03-11 08:12 18704 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
- 2006-12-18 04:53 . 2010-02-05 18:03 20240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
+ 2006-12-18 04:53 . 2010-03-11 08:12 20240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
+ 2009-07-13 23:26 . 2009-07-14 01:03 2560 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.1.7600.20655_none_0ca29ea86ca54783\AcRes.dll
+ 2009-07-13 23:26 . 2009-07-14 01:03 2560 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.1.7600.16539_none_0c32a2dd5373d533\AcRes.dll
+ 2010-03-09 03:46 . 2010-03-09 03:46 3584 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{4F5248D4-2B2E-11DF-A8BE-001B245685E9}.dat
+ 2010-03-09 03:46 . 2010-03-09 03:46 4096 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{4F5248D5-2B2E-11DF-A8BE-001B245685E9}.dat
- 2010-03-06 16:55 . 2010-03-08 23:09 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2010-03-13 12:05 . 2010-03-14 00:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2010-03-06 16:55 . 2010-03-08 23:09 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-03-13 12:05 . 2010-03-14 00:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-13 23:26 . 2009-07-14 01:14 211968 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.1.7600.20655_none_0ca69fd06ca1acdf\AcXtrnal.dll
+ 2009-07-13 23:27 . 2009-07-14 01:14 559616 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.1.7600.20655_none_0ca69fd06ca1acdf\AcLayers.dll
+ 2009-07-13 23:26 . 2009-07-14 01:14 211968 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.1.7600.16539_none_0c36a40553703a8f\AcXtrnal.dll
+ 2009-07-13 23:27 . 2009-07-14 01:14 559616 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.1.7600.16539_none_0c36a40553703a8f\AcLayers.dll
+ 2009-10-28 20:02 . 2010-03-11 19:06 291656 c:\windows\System32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin
- 2009-07-14 02:05 . 2010-03-08 23:17 617036 c:\windows\System32\perfh009.dat
+ 2009-07-14 02:05 . 2010-03-14 01:00 617036 c:\windows\System32\perfh009.dat
+ 2009-07-14 02:05 . 2010-03-14 01:00 104418 c:\windows\System32\perfc009.dat
- 2009-07-14 02:05 . 2010-03-08 23:17 104418 c:\windows\System32\perfc009.dat
- 2009-12-01 22:15 . 2009-10-11 11:17 149280 c:\windows\System32\javaws.exe
+ 2010-03-11 00:23 . 2009-10-11 11:17 149280 c:\windows\System32\javaws.exe
- 2009-12-01 22:15 . 2009-10-11 11:17 145184 c:\windows\System32\javaw.exe
+ 2010-03-11 00:23 . 2009-10-11 11:17 145184 c:\windows\System32\javaw.exe
+ 2010-03-11 00:23 . 2009-10-11 11:17 145184 c:\windows\System32\java.exe
- 2009-12-01 22:15 . 2009-10-11 11:17 145184 c:\windows\System32\java.exe
+ 2010-03-10 23:15 . 2010-03-10 23:15 295606 c:\windows\Installer\{AC76BA86-7AD7-5464-3428-900000000004}\ARPPRODUCTICON.exe
- 2010-02-19 04:29 . 2010-02-21 12:54 239376 c:\windows\Installer\{91120000-003B-0000-0000-0000000FF1CE}\pj11icon.exe
+ 2010-02-19 04:29 . 2010-03-11 08:13 239376 c:\windows\Installer\{91120000-003B-0000-0000-0000000FF1CE}\pj11icon.exe
- 2010-02-19 04:29 . 2010-02-21 12:54 217864 c:\windows\Installer\{91120000-003B-0000-0000-0000000FF1CE}\misc.exe
+ 2010-02-19 04:29 . 2010-03-11 08:13 217864 c:\windows\Installer\{91120000-003B-0000-0000-0000000FF1CE}\misc.exe
- 2006-12-18 04:53 . 2010-02-05 18:03 888080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
+ 2006-12-18 04:53 . 2010-03-11 08:12 888080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
- 2006-12-18 04:53 . 2010-02-05 18:03 922384 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
+ 2006-12-18 04:53 . 2010-03-11 08:12 922384 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
- 2006-12-18 04:53 . 2010-02-05 18:03 217864 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
+ 2006-12-18 04:53 . 2010-03-11 08:12 217864 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
+ 2006-12-18 04:53 . 2010-03-11 08:12 184080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
- 2006-12-18 04:53 . 2010-02-05 18:03 184080 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
+ 2008-04-10 14:20 . 2008-04-10 14:20 638976 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA746454382090000000040\9.0.0\AdobeLinguistic.dll
+ 2010-03-13 12:07 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\3-13-2010\ERDNT.EXE
+ 2010-03-13 03:14 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\3-12-2010\ERDNT.EXE
+ 2010-03-11 10:16 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\3-11-2010\ERDNT.EXE
- 2009-07-14 02:03 . 2010-03-08 23:31 6815744 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-07-14 02:03 . 2010-03-13 14:12 6815744 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
- 2009-07-14 04:34 . 2010-02-24 10:28 3843942 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
+ 2010-03-11 08:39 . 2010-03-11 08:39 3843942 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
+ 2010-02-04 22:24 . 2010-02-04 22:24 9122304 c:\windows\Installer\b3336c1.msp
+ 2010-02-21 06:00 . 2010-02-21 06:00 8480768 c:\windows\Installer\b333667.msp
+ 2010-02-24 10:16 . 2010-02-24 10:16 5527040 c:\windows\Installer\9515f9e.msp
+ 2006-12-18 04:53 . 2010-03-11 08:12 1172240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
- 2006-12-18 04:53 . 2010-02-05 18:03 1172240 c:\windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
+ 2009-10-28 03:34 . 2009-10-28 03:34 5009408 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\authplay.dll
+ 2010-03-13 12:07 . 2010-03-13 12:07 4653056 c:\windows\ERDNT\AutoBackup\3-13-2010\Users\00000002\UsrClass.dat
+ 2010-03-13 12:07 . 2010-03-13 12:07 4562944 c:\windows\ERDNT\AutoBackup\3-13-2010\Users\00000001\NTUSER.DAT
+ 2010-03-13 03:14 . 2010-03-13 03:14 4653056 c:\windows\ERDNT\AutoBackup\3-12-2010\Users\00000002\UsrClass.dat
+ 2010-03-13 03:14 . 2010-03-13 03:14 4562944 c:\windows\ERDNT\AutoBackup\3-12-2010\Users\00000001\NTUSER.DAT
+ 2010-03-11 10:16 . 2010-03-11 10:16 4653056 c:\windows\ERDNT\AutoBackup\3-11-2010\Users\00000002\UsrClass.dat
+ 2010-03-11 10:16 . 2010-03-11 10:16 4562944 c:\windows\ERDNT\AutoBackup\3-11-2010\Users\00000001\NTUSER.DAT
+ 2009-07-14 07:18 . 2010-03-10 10:28 63061549 c:\windows\winsxs\ManifestCache\e4e8be02b8fae2a7_blobs.bin
+ 2009-11-11 14:35 . 2010-03-02 05:30 31648712 c:\windows\System32\MRT.exe
+ 2009-11-21 04:46 . 2009-11-21 04:46 11524608 c:\windows\Installer\b3336d4.msp
+ 2010-03-10 23:14 . 2010-03-10 23:14 20672000 c:\windows\Installer\9516051.msi
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncBackedUp]
@="{6B78A880-15CA-468f-8422-A7960AD6FBB9}"
[HKEY_CLASSES_ROOT\CLSID\{6B78A880-15CA-468f-8422-A7960AD6FBB9}]
2009-12-10 21:26 145648 ----a-w- c:\program files\Webroot\Security\Current\plugins\sync\WebRootShellExt.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncPending]
@="{4EE7A346-5845-471e-9FAB-002EAF83F8B0}"
[HKEY_CLASSES_ROOT\CLSID\{4EE7A346-5845-471e-9FAB-002EAF83F8B0}]
2009-12-10 21:26 145648 ----a-w- c:\program files\Webroot\Security\Current\plugins\sync\WebRootShellExt.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncRoot]
@="{53DABC15-4F29-44ad-B09A-E0D0F9A3D075}"
[HKEY_CLASSES_ROOT\CLSID\{53DABC15-4F29-44ad-B09A-E0D0F9A3D075}]
2009-12-10 21:26 145648 ----a-w- c:\program files\Webroot\Security\Current\plugins\sync\WebRootShellExt.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncShared]
@="{493FC96E-B938-4924-9B38-C4088E9B8AC2}"
[HKEY_CLASSES_ROOT\CLSID\{493FC96E-B938-4924-9B38-C4088E9B8AC2}]
2009-12-10 21:26 145648 ----a-w- c:\program files\Webroot\Security\Current\plugins\sync\WebRootShellExt.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2009-07-14 144384]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-06 39408]
"Spark"="c:\program files\Spark\Spark.exe" [2007-11-14 434176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"snp2uvc"="c:\windows\vsnp2uvc.exe" [2008-08-02 675840]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-03-28 1045800]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2010-01-27 788880]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2006-10-18 472800]
"MaxMenuMgr"="c:\program files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2009-09-26 185640]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2006-11-24 167936]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2006-10-18 317152]
"PLFSetL"="c:\windows\PLFSetL.exe" [2008-07-03 94208]
"SNUVCDSM"="c:\windows\snuvcdsm.exe" [2009-08-10 27184]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"WebrootTrayApp"="c:\program files\Webroot\Security\Current\Framework\WRTray.exe" [2009-12-10 1034616]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-12 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-12 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-12 150552]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2009-06-01 1468296]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-10-27 198160]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
c:\users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Connections.lnk - c:\program files\HP Connections\6811507\Program\HP Connections.exe [2006-12-18 34520]
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@="Service"
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 135664]
R3 PTDMBus;PANTECH USB Modem Composite Device Driver ;c:\windows\system32\DRIVERS\PTDMBus.sys [2009-11-03 55056]
R3 PTDMMdm;PANTECH USB Modem Drivers ;c:\windows\system32\DRIVERS\PTDMMdm.sys [2009-11-03 160912]
R3 PTDMVsp;PANTECH USB Modem Serial Port ;c:\windows\system32\DRIVERS\PTDMVsp.sys [2009-11-03 160912]
R3 PTDMWFLT;PTDMWWAN Filter Driver;c:\windows\system32\DRIVERS\PTDMWFLT.sys [2009-11-03 13456]
R3 PTDMWWAN;PANTECH USB Modem WWAN Driver;c:\windows\system32\DRIVERS\PTDMWWAN.sys [2009-11-03 118800]
R3 SMSIVZAM5;SMSIVZAM5 NDIS Protocol Driver;c:\progra~1\VERIZO~1\VZACCE~1\SMSIVZAM5.SYS [2009-05-25 32408]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2009-09-23 64288]
S1 pwipf6;Privacyware Filter Driver;c:\windows\system32\DRIVERS\pwipf6.sys [2009-12-10 102224]
S2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [2008-09-16 169312]
S2 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe [2009-09-26 189736]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-02-05 1181328]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-27 1153368]
S2 ssfmonm;ssfmonm;c:\windows\system32\DRIVERS\ssfmonm.sys [2009-12-03 39400]
S2 WRConsumerService;Webroot Client Service;c:\program files\Webroot\Security\Current\Framework\WRConsumerService.exe [2009-12-10 2397536]
S3 dc3d;MS Hardware Device Detection Driver (HID);c:\windows\system32\DRIVERS\dc3d.sys [2009-11-04 17408]
S3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2010-03-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 19:27]
2010-03-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-02 19:27]
.
.
------- Supplementary Scan -------
.
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=71&bd=Pavilion&pf=laptop
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
Trusted Zone: intuit.com\ttlc
TCP: 351494E44514C435F5055524C49434 = 207.70.1.8,198.60.204.8
TCP: 3696E616 = 207.70.1.8,198.60.204.8
TCP: 6427564602D4569756270275966496 = 207.70.1.8,198.60.204.8
TCP: 8497164747 = 207.70.1.8,198.60.204.8
TCP: E45445745414250205F435 = 207.70.1.8,198.60.204.8
DPF: {C7DEDA04-2FFF-4B81-AE66-0A0E0EF4AD2F} - hxxp://www.ritzpix.com/net/Uploader/LPUploader57.cab
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2010-03-13 20:26:45
ComboFix-quarantined-files.txt 2010-03-14 01:26
ComboFix2.txt 2010-03-13 12:53
ComboFix3.txt 2010-03-09 02:20
Pre-Run: 95,168,356,352 bytes free
Post-Run: 95,117,672,448 bytes free
- - End Of File - - C0355E651C54379380B76E04A27CB21E