hi Blade81..
Thanks again for help. And sorry for replying late.
ComboFix log:
ComboFix 09-08-20.07 - Aditya 08/23/2009 5:18.4.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1014.391 [GMT -7:00]
Running from: c:\users\Aditya\Desktop\ComboFix.exe
Command switches used :: c:\users\Aditya\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: BitDefender Antivirus *On-access scanning enabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: BitDefender Firewall *disabled* {4055920F-2E99-48A8-A270-4243D2B8F242}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: BitDefender Antispyware *enabled* (Updated) {8B2012EC-32D4-494F-BC03-832DB3BDF911}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *enabled* (Outdated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\uTorrent
.
((((((((((((((((((((((((( Files Created from 2009-07-23 to 2009-08-23 )))))))))))))))))))))))))))))))
.
2009-08-23 12:29 . 2009-08-23 12:29 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-08-23 12:29 . 2009-08-23 12:29 -------- d-----w- c:\users\Aditya\AppData\Local\temp
2009-08-23 12:29 . 2009-08-23 12:29 -------- d-----w- c:\users\Adi\AppData\Local\temp
2009-08-22 13:47 . 2009-08-22 13:47 -------- d-----w- c:\users\Aditya\AppData\Roaming\Sony Corporation
2009-08-22 13:23 . 2009-08-22 13:23 -------- d-----w- c:\users\Adi\AppData\Roaming\PC Suite
2009-08-22 11:37 . 2009-08-22 11:37 -------- d-----w- c:\users\Aditya\AppData\Roaming\Media Player Classic
2009-08-22 11:13 . 2009-08-22 11:14 -------- d-----w- c:\users\Aditya\AppData\Roaming\vlc
2009-08-21 21:28 . 2009-08-21 21:28 -------- d-----w- c:\windows\Sun
2009-08-21 20:52 . 2009-08-21 20:52 680 ----a-w- c:\users\Aditya\AppData\Local\d3d9caps.dat
2009-08-21 19:42 . 2009-08-21 19:42 -------- d-----w- c:\programdata\NortonInstaller
2009-08-21 19:27 . 2009-08-21 19:27 -------- d--h--w- c:\users\Aditya\AppData\Roaming\mount
2009-08-21 19:27 . 2009-08-21 19:27 -------- d--h--w- c:\users\Aditya\AppData\Roaming\modules
2009-08-21 19:27 . 2009-08-21 19:27 -------- d--h--w- c:\users\Aditya\AppData\Roaming\apps
2009-08-21 17:31 . 2009-08-21 17:31 -------- d-----w- c:\users\Aditya\AppData\Local\Labcenter Electronics
2009-08-21 07:46 . 2009-08-21 19:17 81984 ----a-w- c:\windows\system32\bdod.bin
2009-08-20 16:00 . 2009-08-20 16:00 -------- d-----w- c:\users\Aditya\AppData\Roaming\Microchip
2009-08-20 13:06 . 2009-08-23 11:11 -------- d-----w- c:\users\Aditya\AppData\Roaming\Winamp
2009-08-20 10:57 . 2009-08-20 10:57 -------- d-----w- c:\users\Aditya\AppData\Roaming\GRETECH
2009-08-20 10:48 . 2009-08-20 10:49 117760 ----a-w- c:\users\Aditya\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-08-20 10:48 . 2009-08-20 10:48 -------- d-----w- c:\users\Aditya\AppData\Roaming\SUPERAntiSpyware.com
2009-08-20 09:45 . 2009-08-21 16:27 104456 ----a-w- c:\windows\system32\drivers\bdfndisf.sys
2009-08-20 08:10 . 2009-08-20 08:10 -------- d-----w- c:\users\Adi\AppData\Roaming\Malwarebytes
2009-08-20 07:49 . 2009-08-20 07:49 -------- d-----w- c:\programdata\Sony Corporation
2009-08-20 04:53 . 2009-08-22 13:24 117760 ----a-w- c:\users\Adi\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-08-20 04:52 . 2009-08-20 04:52 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2009-08-20 04:51 . 2009-08-20 04:52 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-08-20 04:51 . 2009-08-20 04:51 -------- d-----w- c:\users\Adi\AppData\Roaming\SUPERAntiSpyware.com
2009-08-20 04:50 . 2009-08-20 04:50 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-08-19 20:59 . 2009-08-19 21:00 -------- d-----w- c:\users\Adi\AppData\Local\Microsoft Games
2009-08-19 20:57 . 2009-08-19 21:22 -------- d-----w- c:\users\Adi\AppData\Roaming\Winamp
2009-08-19 20:35 . 2009-08-19 20:35 -------- d-----w- c:\users\Adi\AppData\Roaming\GRETECH
2009-08-19 20:34 . 2009-08-19 20:34 -------- d-----w- c:\users\Adi\AppData\Roaming\Nokia
2009-08-19 20:30 . 2009-08-20 05:52 -------- d-----w- c:\users\Adi\AppData\Local\Google
2009-08-19 19:12 . 2009-08-19 19:12 -------- d-----w- c:\users\Adi\AppData\Local\Mozilla
2009-08-19 18:27 . 2009-08-19 18:27 108280 ----a-w- c:\users\Adi\AppData\Local\GDIPFONTCACHEV1.DAT
2009-08-19 18:25 . 2009-08-19 18:25 -------- d-----w- c:\users\Adi\AppData\Roaming\BitDefender
2009-08-19 18:24 . 2009-08-19 18:24 -------- d-----w- c:\users\Adi\AppData\Roaming\ZoneIDTrimmer
2009-08-19 18:13 . 2009-08-19 18:13 -------- d-----w- c:\programdata\WindowsSearch
2009-08-19 17:57 . 2009-08-19 17:57 -------- d-----w- c:\users\Aditya\AppData\Roaming\PC Suite
2009-08-19 17:56 . 2009-08-19 17:56 -------- d-----w- c:\programdata\PC Suite
2009-08-19 17:56 . 2009-08-19 17:57 -------- d-----w- c:\users\Aditya\AppData\Roaming\Nokia
2009-08-19 17:39 . 2009-08-19 17:39 -------- d-----w- c:\users\Aditya\AppData\Roaming\Malwarebytes
2009-08-19 17:39 . 2009-08-03 20:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-19 17:39 . 2009-08-19 17:39 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-19 17:39 . 2009-08-19 17:39 -------- d-----w- c:\programdata\Malwarebytes
2009-08-19 17:39 . 2009-08-03 20:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-19 16:56 . 2009-08-19 16:56 0 ----a-w- c:\windows\nsreg.dat
2009-08-19 16:56 . 2009-08-19 16:56 -------- d-----w- c:\users\Aditya\AppData\Local\Mozilla
2009-08-19 16:48 . 2009-08-19 16:48 -------- d-----w- c:\users\Aditya\AppData\Roaming\BitDefender
2009-08-19 16:31 . 2009-08-19 16:31 -------- d-----w- c:\users\Aditya\AppData\Roaming\ZoneIDTrimmer
2009-08-19 16:26 . 2009-08-19 16:56 -------- d-----w- c:\users\Aditya\AppData\Local\Google
2009-08-19 16:26 . 2009-08-19 16:26 -------- d-----w- c:\programdata\BitDefender
2009-08-19 16:26 . 2009-08-19 16:26 108280 ----a-w- c:\users\Aditya\AppData\Local\GDIPFONTCACHEV1.DAT
2009-08-19 16:14 . 2009-08-20 10:47 -------- d-----w- c:\programdata\Autorun Eater
2009-08-19 15:46 . 2009-08-19 15:46 -------- d-----w- c:\program files\Gasanov.net
2009-08-18 19:22 . 2009-08-18 19:22 -------- d-----w- c:\program files\SCRABBLE
2009-08-16 20:44 . 2009-08-16 20:44 -------- d-----w- C:\RootkitNO
2009-08-16 20:43 . 2009-08-16 20:43 2 --shatr- c:\windows\winstart.bat
2009-08-16 20:42 . 2009-08-20 10:53 -------- d-----w- c:\program files\UnHackMe
2009-08-16 20:21 . 2009-08-16 20:21 -------- d-----w- c:\program files\Security Task Manager
2009-08-16 19:05 . 2009-08-16 19:05 -------- d-----w- c:\program files\Trend Micro
2009-08-16 11:24 . 2009-08-19 16:47 -------- d-----w- c:\program files\BitDefender
2009-08-16 11:22 . 2009-08-16 11:22 -------- d-----w- c:\windows\system32\URTTEMP
2009-08-16 11:21 . 2009-08-16 11:24 -------- d-----w- c:\program files\Common Files\BitDefender
2009-08-07 09:40 . 2009-08-07 09:40 -------- d-----w- c:\program files\D-Tools
2009-08-07 09:32 . 2009-08-07 09:32 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2009-08-07 09:21 . 2009-08-07 09:21 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-08-05 08:22 . 2003-10-27 21:06 505104 ----a-w- c:\windows\system32\msxml.dll
2009-08-05 08:22 . 2003-10-27 21:06 69632 ----a-w- c:\windows\system32\xmltok.dll
2009-08-05 08:22 . 2003-10-27 21:06 36864 ----a-w- c:\windows\system32\xmlparse.dll
2009-08-05 08:22 . 2003-10-27 21:06 28432 ----a-w- c:\windows\system32\msxmlr.dll
2009-08-05 08:22 . 2003-10-27 21:06 26096 ----a-w- c:\windows\system32\xmlinst.exe
2009-08-05 08:22 . 2003-10-27 21:06 24576 ----a-w- c:\windows\system32\msxml3a.dll
2009-08-05 08:14 . 2009-08-05 08:22 -------- d-----w- c:\program files\UBISOFT
2009-08-01 05:30 . 2009-08-01 05:30 262144 ----a-w- C:\ntuser.dat
2009-07-31 05:00 . 2009-07-25 12:23 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-31 05:00 . 2009-08-21 21:37 -------- d-----w- c:\program files\Java
2009-07-31 04:59 . 2009-07-31 04:59 -------- d-----w- c:\program files\JonDo
2009-07-30 06:17 . 2009-07-30 06:17 -------- d-----w- c:\program files\Microsoft Reader
2009-07-30 06:17 . 2003-06-06 00:15 57436 ----a-w- c:\windows\DASShp.dll
2009-07-29 05:20 . 2009-07-29 05:21 -------- d-----w- c:\windows\system32\ca-ES
2009-07-29 05:20 . 2009-07-29 05:21 -------- d-----w- c:\windows\system32\eu-ES
2009-07-29 05:20 . 2009-07-29 05:21 -------- d-----w- c:\windows\system32\vi-VN
2009-07-29 05:08 . 2009-07-29 05:08 -------- d-----w- c:\windows\system32\SPReview
2009-07-29 04:51 . 2009-04-11 06:28 928768 ----a-w- c:\windows\system32\scavenge.dll
2009-07-29 04:51 . 2009-04-11 06:27 57856 ----a-w- c:\windows\system32\compcln.exe
2009-07-29 04:49 . 2009-04-11 06:28 61440 ----a-w- c:\windows\system32\davclnt.dll
2009-07-29 04:48 . 2009-04-11 06:27 710144 ----a-w- c:\windows\system32\Magnify.exe
2009-07-29 04:47 . 2009-04-11 06:28 558080 ----a-w- c:\windows\system32\sysmain.dll
2009-07-29 04:46 . 2009-04-11 06:28 190464 ----a-w- c:\windows\system32\sperror.dll
2009-07-29 04:39 . 2009-07-29 04:39 -------- d-----w- c:\windows\system32\EventProviders
2009-07-28 09:36 . 2009-07-28 09:36 -------- d-----w- C:\PerfLogs
2009-07-28 08:40 . 2008-01-19 06:33 193024 ----a-w- c:\windows\system32\recdisc.exe
2009-07-28 08:40 . 2008-01-19 06:36 6656 ----a-w- c:\windows\system32\sdspres.dll
2009-07-28 08:40 . 2008-01-19 06:36 28160 ----a-w- c:\windows\system32\sxproxy.dll
2009-07-28 08:38 . 2008-01-19 06:35 237056 ----a-w- c:\windows\system32\netprofm.dll
2009-07-28 08:37 . 2008-01-19 06:33 68096 ----a-w- c:\windows\system32\basesrv.dll
2009-07-28 08:36 . 2008-01-19 06:37 22016 ----a-w- c:\windows\system32\wmpcm.dll
2009-07-28 08:32 . 2007-12-06 04:04 6656 ----a-w- c:\windows\system32\kbd106n.dll
2009-07-28 08:26 . 2009-07-28 08:26 -------- d-----w- C:\79065638b8d03199de49
2009-07-26 08:53 . 2009-07-26 08:53 -------- d-----w- c:\program files\Auslogics
2009-07-26 04:47 . 2009-07-26 04:47 -------- d-----w- c:\program files\Defraggler
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-22 20:40 . 2007-08-21 23:07 204592 ----a-w- c:\windows\system32\prfh0404.dat
2009-08-22 20:40 . 2007-08-21 23:07 72878 ----a-w- c:\windows\system32\prfc0404.dat
2009-08-21 21:39 . 2009-08-21 21:38 -------- d-----w- c:\programdata\SecTaskMan
2009-08-21 19:44 . 2008-12-17 11:00 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-08-20 09:43 . 2008-04-24 01:34 192512 ----a-w- c:\windows\system32\txmlutil.dll
2009-08-20 09:43 . 2008-08-13 01:40 242184 ----a-w- c:\windows\system32\drivers\bdfsfltr.sys
2009-08-20 09:43 . 2008-08-13 01:40 111112 ----a-w- c:\windows\system32\drivers\bdfm.sys
2009-08-20 09:43 . 2008-07-02 20:07 82696 ----a-w- c:\windows\system32\drivers\BDVEDISK.sys
2009-08-19 16:40 . 2009-06-30 00:57 -------- d-----w- c:\program files\Common Files\GTK
2009-08-18 04:28 . 2008-12-17 10:46 -------- d-----w- c:\program files\Common Files\Adobe
2009-08-10 09:03 . 2009-08-10 09:03 2855 ----a-w- c:\windows\pif\autorun.PIF
2009-08-10 09:03 . 2009-08-10 09:03 2855 ----a-w- c:\windows\pif\setup.PIF
2009-08-05 08:14 . 2007-08-21 20:38 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-30 16:43 . 2009-07-30 16:43 0 ---ha-w- c:\windows\system32\drivers\Msft_User_PCCSWpdDriver_01_05_00.Wdf
2009-07-30 05:02 . 2008-12-17 12:54 -------- d-----w- c:\program files\Winamp
2009-07-29 05:21 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2009-07-29 05:21 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-07-29 05:21 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-07-29 05:21 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2009-07-29 05:21 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2009-07-29 05:21 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2009-07-29 05:21 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2009-07-29 05:20 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-07-29 05:17 . 2009-07-29 05:17 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2009-07-28 09:12 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2009-07-28 09:12 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
2009-06-30 00:58 . 2009-06-30 00:58 -------- d-----w- c:\program files\Pidgin
2009-06-26 05:11 . 2009-06-26 05:11 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-06-26 05:11 . 2009-06-26 05:11 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-06-26 05:11 . 2009-06-26 05:11 503864 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2009-06-26 05:11 . 2009-06-26 05:11 35896 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2009-06-26 05:11 . 2009-06-26 05:11 3 ----a-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Inbox_Critical.Wdf
2009-08-20 09:42 . 2008-08-14 02:02 49664 ----a-w- c:\program files\mozilla firefox\components\FFComm.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-08-19_19.00.45 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-08-21 20:26 . 2009-08-22 04:23 54118 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-08-22 04:23 69968 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-12-17 13:08 . 2009-08-22 04:23 13228 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-4169990286-166398427-1375796538-1003_UserData.bin
+ 2009-01-24 10:16 . 2009-08-21 21:22 88589 c:\windows\System32\Macromed\Flash\uninstall_activeX.exe
- 2008-12-17 13:05 . 2009-08-19 18:23 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-12-17 13:05 . 2009-08-19 21:01 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-12-17 13:05 . 2009-08-19 18:23 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-12-17 13:05 . 2009-08-19 21:01 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-12-17 13:05 . 2009-08-19 18:23 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-12-17 13:05 . 2009-08-19 21:01 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-08-20 04:52 . 2009-08-20 04:52 65024 c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
+ 2009-08-20 04:52 . 2009-08-20 04:52 18944 c:\windows\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
+ 2008-12-17 11:54 . 2009-08-21 19:45 5742 c:\windows\System32\WDI\ERCQueuedResolutions.dat
- 2008-12-17 11:54 . 2009-08-19 18:17 5742 c:\windows\System32\WDI\ERCQueuedResolutions.dat
+ 2009-08-22 04:21 . 2009-08-22 04:21 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-08-19 18:23 . 2009-08-19 18:23 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-08-22 04:21 . 2009-08-22 04:21 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-08-19 18:23 . 2009-08-19 18:23 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-12-18 04:05 . 2009-08-23 09:40 277024 c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2006-11-02 10:33 . 2009-08-22 20:40 607356 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-08-22 20:40 106220 c:\windows\System32\perfc009.dat
+ 2009-07-18 03:12 . 2009-07-18 03:12 257440 c:\windows\System32\Macromed\Flash\FlashUtil10c.exe
+ 2009-08-21 21:37 . 2009-07-25 12:23 149280 c:\windows\System32\javaws.exe
+ 2009-08-21 21:37 . 2009-07-25 12:23 145184 c:\windows\System32\javaw.exe
+ 2009-08-21 21:37 . 2009-07-25 12:23 145184 c:\windows\System32\java.exe
+ 2009-08-20 04:52 . 2009-08-20 04:52 1516544 c:\windows\Installer\240223e.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ZoneIDTrimmer]
@="{EF8DB711-E846-423B-AAE7-077B1F264591}"
[HKEY_CLASSES_ROOT\CLSID\{EF8DB711-E846-423B-AAE7-077B1F264591}]
2009-03-30 04:42 278848 ----a-w- c:\windows\System32\mscoree.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2007-06-10 118784]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-02-26 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-02-26 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-02-26 150552]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2009\IEShow.exe" [2009-08-20 69632]
"BDAgent"="c:\program files\BitDefender\BitDefender 2009\bdagent.exe" [2009-08-21 782336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 19:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2007-07-25 02:26 98304 ----a-w- c:\windows\System32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):6a,2b,6c,bf,0d,10,ca,01
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-4169990286-166398427-1375796538-1003]
"EnableNotificationsRef"=dword:00000002
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{8F38F027-ECCB-4A59-8F81-77669BF0CF61}"= Disabled:UDP:c:\program files\Sony\VAIO Media 6.0\Vc.exe:[VAIO Media] VAIO Media
"{CFCCC725-5C43-4D08-BDC2-30D235AC1FDC}"= Disabled:TCP:c:\program files\Sony\VAIO Media 6.0\Vc.exe:[VAIO Media] VAIO Media
"{BBEC2E59-6077-4BCF-9550-ED9E483FC762}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{4C5E83A0-C0B4-4B35-BDC8-DB8D272AD68F}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{7E93EEEA-3F17-412F-AEEA-D796D70B7224}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{55900B83-C890-4C60-B531-21A5F045F0FC}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{BA8E0D10-F872-4DF3-88CB-168FA662D3F5}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{3398FD12-100D-4521-959D-0417062BCEE5}"= Disabled:UDP:c:\program files\Adobe\Photoshop Elements 5.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{B2DB603E-90EC-48F7-BB20-CDC649EA1A24}"= Disabled:TCP:c:\program files\Adobe\Photoshop Elements 5.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"TCP Query User{7EC1079E-7AE0-43A1-8E55-22C1F16DED89}d:\\essentials\\ip msg.exe"= UDP:d:\essentials\ip msg.exe:Wing Enthu
"UDP Query User{D3093E08-9E52-4D6E-BF0B-54663CB65FD6}d:\\essentials\\ip msg.exe"= TCP:d:\essentials\ip msg.exe:Wing Enthu
"TCP Query User{4BC1CFB4-49AA-4AD2-8D67-18A12003D090}d:\\essentials\\ip msg.exe"= UDP:d:\essentials\ip msg.exe:Wing Enthu
"UDP Query User{4A301307-3276-4DD1-9B8C-EB5E82E0F131}d:\\essentials\\ip msg.exe"= TCP:d:\essentials\ip msg.exe:Wing Enthu
"{37C76CCD-6177-4B31-8B74-01BDFA989B81}"= UDP:c:\users\Aditya\AppData\Roaming\Google\Google Talk\googletalk.exe:Google Talk
"{C8248826-A531-4EDE-B033-D3E7747BE2D0}"= TCP:c:\users\Aditya\AppData\Roaming\Google\Google Talk\googletalk.exe:Google Talk
"{6AE85A53-19D3-41A1-9912-A17A48972022}"= UDP:c:\program files\Google\Google Talk\googletalk.exe:Google Talk
"{3771FAC2-59FD-463C-80FE-1A1E49FE5012}"= TCP:c:\program files\Google\Google Talk\googletalk.exe:Google Talk
"TCP Query User{1CB72C13-3A78-4468-8BCA-E859385ED0B2}c:\\program files\\matlab71\\bin\\win32\\matlab.exe"= UDP:c:\program files\matlab71\bin\win32\matlab.exe:MATLAB
"UDP Query User{CC3C347B-2B8A-47ED-9C62-EA0F35A1F61E}c:\\program files\\matlab71\\bin\\win32\\matlab.exe"= TCP:c:\program files\matlab71\bin\win32\matlab.exe:MATLAB
"{8392ACF8-36DC-4CED-8E42-F6600EABC5C9}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{6A95FB1B-5704-4FE0-81D0-751A034F383A}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"TCP Query User{40C8F8BA-F0DE-4442-86F9-39B927CF17E0}c:\\program files\\kicad\\bin\\pcbnew.exe"= UDP:c:\program files\kicad\bin\pcbnew.exe

cbnew
"UDP Query User{CBF00A21-090D-4CF2-9563-97842F2B412F}c:\\program files\\kicad\\bin\\pcbnew.exe"= TCP:c:\program files\kicad\bin\pcbnew.exe

cbnew
"TCP Query User{55DB11EB-1D98-4232-BE9C-EB987136DD16}c:\\users\\aditya\\desktop\\ip msg.exe"= UDP:c:\users\aditya\desktop\ip msg.exe:ip msg.exe
"UDP Query User{0871525D-26CD-4EA7-A1B0-0E734159495D}c:\\users\\aditya\\desktop\\ip msg.exe"= TCP:c:\users\aditya\desktop\ip msg.exe:ip msg.exe
"TCP Query User{D934D6D6-4801-42AF-9DB8-63CB276F1848}c:\\users\\aditya\\desktop\\ip msg.exe"= UDP:c:\users\aditya\desktop\ip msg.exe:ip msg.exe
"UDP Query User{EDFF5398-FA1D-474C-97B6-4B753C478F10}c:\\users\\aditya\\desktop\\ip msg.exe"= TCP:c:\users\aditya\desktop\ip msg.exe:ip msg.exe
"TCP Query User{35FCC15F-2B33-4FE6-BE02-722C621321DC}d:\\aoe\\age2_x1.exe"= UDP:d:\aoe\age2_x1.exe:Age of Empires II Expansion
"UDP Query User{F50D3401-0602-4F66-ACF9-699C20D58340}d:\\aoe\\age2_x1.exe"= TCP:d:\aoe\age2_x1.exe:Age of Empires II Expansion
"TCP Query User{2B53F0B4-1A6B-456F-B52C-045CBF952CF2}d:\\aoe\\age2_x1.exe"= UDP:d:\aoe\age2_x1.exe:Age of Empires II Expansion
"UDP Query User{11D4BDA7-016A-40DA-8580-B79EC76D1607}d:\\aoe\\age2_x1.exe"= TCP:d:\aoe\age2_x1.exe:Age of Empires II Expansion
"TCP Query User{603E3415-253F-4184-83DD-DD8132B04434}c:\\users\\aditya\\desktop\\ip\\ip msg.exe"= UDP:c:\users\aditya\desktop\ip\ip msg.exe:ip msg.exe
"UDP Query User{22E58F1E-19D7-44DF-A457-DDB4A1656E04}c:\\users\\aditya\\desktop\\ip\\ip msg.exe"= TCP:c:\users\aditya\desktop\ip\ip msg.exe:ip msg.exe
"TCP Query User{F640FA98-2538-4741-990B-142434AC0F36}c:\\users\\aditya\\desktop\\ip\\ip msg.exe"= UDP:c:\users\aditya\desktop\ip\ip msg.exe:ip msg.exe
"UDP Query User{6A51F7B8-236B-435F-B723-7CF6A32141D8}c:\\users\\aditya\\desktop\\ip\\ip msg.exe"= TCP:c:\users\aditya\desktop\ip\ip msg.exe:ip msg.exe
"TCP Query User{6FC6511A-CCBE-4628-AA06-A18BB0845ECE}c:\\program files\\kicad\\bin\\eeschema.exe"= UDP:c:\program files\kicad\bin\eeschema.exe:eeschema
"UDP Query User{D55AD615-E97A-4A2D-A4FE-5E37D93044ED}c:\\program files\\kicad\\bin\\eeschema.exe"= TCP:c:\program files\kicad\bin\eeschema.exe:eeschema
"TCP Query User{2C0D819B-1488-4FB7-A191-46C084A25386}c:\\program files\\kicad\\bin\\pcbnew.exe"= UDP:c:\program files\kicad\bin\pcbnew.exe

cbnew
"UDP Query User{A672198F-F0F4-46DF-A9F4-86057C2193B5}c:\\program files\\kicad\\bin\\pcbnew.exe"= TCP:c:\program files\kicad\bin\pcbnew.exe

cbnew
"TCP Query User{05789BA0-E83A-4A37-A4E3-D00CF2A39CA9}c:\\users\\aditya\\desktop\\age of e\\empires2.exe"= UDP:c:\users\aditya\desktop\age of e\empires2.exe:empires2.exe
"UDP Query User{81955FEA-94C6-4975-94C5-7177929BDD2B}c:\\users\\aditya\\desktop\\age of e\\empires2.exe"= TCP:c:\users\aditya\desktop\age of e\empires2.exe:empires2.exe
"TCP Query User{61A94B8D-970B-43DB-93D9-1C8428B40F17}c:\\users\\aditya\\desktop\\age of e\\empires2.exe"= UDP:c:\users\aditya\desktop\age of e\empires2.exe:empires2.exe
"UDP Query User{E083A966-C8E6-4FE1-AF82-64403356379C}c:\\users\\aditya\\desktop\\age of e\\empires2.exe"= TCP:c:\users\aditya\desktop\age of e\empires2.exe:empires2.exe
"TCP Query User{E285D099-59E6-40A8-A75C-B069B6A1320D}c:\\games\\aoe\\age2_x1.exe"= UDP:c:\games\aoe\age2_x1.exe:Age of Empires II Expansion
"UDP Query User{F5A1BF9B-AAAD-415C-890A-366C0DF70E37}c:\\games\\aoe\\age2_x1.exe"= TCP:c:\games\aoe\age2_x1.exe:Age of Empires II Expansion
"{DB76F373-20B2-4679-B4AA-95A077ED0245}"= UDP:c:\games\AOE 3 INSTALL\age3x.exe:Age of Empires III - The WarChiefs
"{BD721A5F-4A4F-40CD-B744-3092D5CD5814}"= TCP:c:\games\AOE 3 INSTALL\age3x.exe:Age of Empires III - The WarChiefs
"TCP Query User{E17F11E1-64F5-4BE7-8520-23A69BAD650A}c:\\users\\aditya\\appdata\\local\\temp\\ipmsg.exe"= UDP:c:\users\aditya\appdata\local\temp\ipmsg.exe:ipmsg.exe
"UDP Query User{7AD813AA-C19F-4149-9371-469C9FDFB0F8}c:\\users\\aditya\\appdata\\local\\temp\\ipmsg.exe"= TCP:c:\users\aditya\appdata\local\temp\ipmsg.exe:ipmsg.exe
"{B1B62E78-3EE0-412E-94C9-EB6FC2160951}"= UDP:c:\users\Aditya\AppData\Local\Google\Google Talk, Labs Edition\GoogleTalkLabsEdition.exe:Google Talk, Labs Edition
"{7306C7B4-7B42-4A7E-97E7-3BFD82119786}"= TCP:c:\users\Aditya\AppData\Local\Google\Google Talk, Labs Edition\GoogleTalkLabsEdition.exe:Google Talk, Labs Edition
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
R0 Stealth;Stealth;c:\windows\System32\drivers\stealth.sys [6/21/2002 10:58 AM 80896]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [8/5/2009 4:06 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [8/5/2009 4:06 PM 74480]
R2 BDVEDISK;BDVEDISK;c:\program files\BitDefender\BitDefender 2009\BDVEDISK.sys [7/2/2008 1:07 PM 82696]
R3 bdfm;BDFM;c:\windows\System32\drivers\bdfm.sys [8/12/2008 6:40 PM 111112]
R3 BTCAMDRV;Mobiola Web Camera driver;c:\windows\System32\drivers\BTCamDrv.sys [2/19/2009 12:40 AM 219264]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [8/5/2009 4:06 PM 7408]
R3 ti21sony;ti21sony;c:\windows\System32\drivers\ti21sony.sys [8/21/2007 12:44 PM 812544]
S3 Arrakis3;BitDefender Arrakis Server;c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe [7/17/2008 1:06 PM 118784]
S3 VAIOMediaPlatform-UCLS-AppServer;VAIO Media Content Collection;c:\program files\Sony\VAIO Media Integrated Server\UCLS.exe [12/17/2008 4:30 AM 745472]
S3 VAIOMediaPlatform-UCLS-HTTP;VAIO Media Content Collection (HTTP);c:\program files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe [12/17/2008 4:30 AM 397312]
S3 VAIOMediaPlatform-UCLS-UPnP;VAIO Media Content Collection (UPnP);c:\program files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe [12/17/2008 4:30 AM 1089536]
S3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe [12/17/2008 4:27 AM 79736]
S4 NSUService;NSUService;c:\program files\Sony\Network Utility\NSUService.exe [12/17/2008 4:37 AM 200704]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Settings,ProxyServer = 10.1.101.150:3128
uInternet Settings,ProxyOverride = <local>
IE: &Winamp Search - c:\programdata\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Aditya\AppData\Roaming\Mozilla\Firefox\Profiles\dgvfwhbb.default\
FF - component: c:\program files\Mozilla Firefox\components\FFComm.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Java\jre6\bin\npdeploytk.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.
**************************************************************************
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-08-23 5:33
ComboFix-quarantined-files.txt 2009-08-23 12:33
ComboFix2.txt 2009-08-21 22:25
ComboFix3.txt 2009-08-19 19:04
Pre-Run: 3,499,614,208 bytes free
Post-Run: 3,476,852,736 bytes free
389
DDS log:
DDS (Ver_09-07-30.01) - NTFSx86
Run by Aditya at 2:51:07.83 on Sat 08/22/2009
Internet Explorer: 7.0.6002.18005 BrowserJavaVersion: 1.6.0_15
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1014.190 [GMT -7:00]
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: BitDefender Antivirus *On-access scanning enabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
SP: BitDefender Antispyware *enabled* (Updated) {8B2012EC-32D4-494F-BC03-832DB3BDF911}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Windows Defender *enabled* (Outdated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
FW: BitDefender Firewall *disabled* {4055920F-2E99-48A8-A270-4243D2B8F242}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Users\Aditya\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = about:blank
uInternet Settings,ProxyServer = 10.1.101.150:3128
uInternet Settings,ProxyOverride = <local>
mURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
TB: Winamp Toolbar: {ebf2ba02-9094-4c5a-858b-bb198f3d8de2} - c:\program files\winamp toolbar\winamptb.dll
uRun: [Google Update] "c:\users\aditya\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [PC Suite Tray] "c:\program files\nokia\nokia pc suite 7\PCSuite.exe" -onlytray
uRun: [googletalk] c:\users\aditya\appdata\roaming\google\google talk\googletalk.exe /autostart
mRun: [Apoint] c:\program files\apoint\Apoint.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [DAEMON Tools-1033] "c:\program files\d-tools\daemon.exe" -lang 1033
mRun: [BDAgent] "c:\program files\bitdefender\bitdefender 2009\bdagent.exe"
mRun: [BitDefender Antiphishing Helper] "c:\program files\bitdefender\bitdefender 2009\IEShow.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: &Winamp Search - c:\programdata\winamp toolbar\ietoolbar\resources\en-us\local\search.html
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\ssv.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: igfxcui - igfxdev.dll
Notify: VESWinlogon - VESWinlogon.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
================= FIREFOX ===================
FF - ProfilePath - c:\users\aditya\appdata\roaming\mozilla\firefox\profiles\dgvfwhbb.default\
FF - component: c:\program files\mozilla firefox\components\FFComm.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\java\jre6\bin\npdeploytk.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
============= SERVICES / DRIVERS ===============
R0 Stealth;Stealth;c:\windows\system32\drivers\stealth.sys [2002-6-21 80896]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-8-5 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-8-5 74480]
R2 BDVEDISK;BDVEDISK;c:\program files\bitdefender\bitdefender 2009\BDVEDISK.sys [2008-7-2 82696]
R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [2008-8-12 111112]
R3 BTCAMDRV;Mobiola Web Camera driver;c:\windows\system32\drivers\BTCamDrv.sys [2009-2-19 219264]
R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2007-8-21 812544]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-8-5 7408]
=============== Created Last 30 ================
2009-08-21 14:38 <DIR> --d----- c:\programdata\SecTaskMan
2009-08-21 14:38 <DIR> --d----- c:\progra~2\SecTaskMan
2009-08-21 13:33 <DIR> --dsh--- C:\$RECYCLE.BIN
2009-08-21 13:05 <DIR> --d----- c:\program files\uTorrent
2009-08-21 12:42 <DIR> --d----- c:\programdata\NortonInstaller
2009-08-21 12:42 <DIR> --d----- c:\progra~2\NortonInstaller
2009-08-21 12:27 <DIR> --d-h--- c:\users\aditya\appdata\roaming\temp
2009-08-21 12:27 <DIR> --d-h--- c:\users\aditya\appdata\roaming\mount
2009-08-21 12:27 <DIR> --d-h--- c:\users\aditya\appdata\roaming\modules
2009-08-21 12:27 <DIR> --d-h--- c:\users\aditya\appdata\roaming\apps
2009-08-21 02:40 <DIR> a-d----- c:\programdata\TEMP
2009-08-21 00:47 121 a------- c:\windows\bdagent.INI
2009-08-21 00:46 81,984 a------- c:\windows\system32\bdod.bin
2009-08-21 00:45 707 a------- c:\windows\system32\BDUpdateV1.xml
2009-08-20 09:00 <DIR> --d----- c:\users\aditya\appdata\roaming\Microchip
2009-08-20 03:48 <DIR> --d----- c:\users\aditya\appdata\roaming\SUPERAntiSpyware.com
2009-08-20 02:45 228,672 a------- c:\windows\system32\drivers\bdfsfltr.sys.bak
2009-08-20 02:45 108,864 a------- c:\windows\system32\drivers\bdfm.sys.bak
2009-08-20 02:45 104,456 a------- c:\windows\system32\drivers\bdfndisf.sys
2009-08-20 02:45 82,568 a------- c:\windows\system32\drivers\BDVEDISK.sys.bak
2009-08-20 00:49 <DIR> --d----- c:\programdata\Sony Corporation
2009-08-20 00:49 <DIR> --d----- c:\progra~2\Sony Corporation
2009-08-19 21:52 <DIR> --d----- c:\programdata\SUPERAntiSpyware.com
2009-08-19 21:52 <DIR> --d----- c:\progra~2\SUPERAntiSpyware.com
2009-08-19 21:51 <DIR> --d----- c:\program files\SUPERAntiSpyware
2009-08-19 21:50 <DIR> --d----- c:\program files\common files\Wise Installation Wizard
2009-08-19 11:33 228,864 a------- c:\windows\PEV.exe
2009-08-19 11:33 161,792 a------- c:\windows\SWREG.exe
2009-08-19 11:33 98,816 a------- c:\windows\sed.exe
2009-08-19 11:13 <DIR> --d----- c:\programdata\WindowsSearch
2009-08-19 10:56 <DIR> --d----- c:\programdata\PC Suite
2009-08-19 10:39 <DIR> --d----- c:\users\aditya\appdata\roaming\Malwarebytes
2009-08-19 10:39 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-19 10:39 19,096 a------- c:\windows\system32\drivers\mbam.sys
2009-08-19 10:39 <DIR> --d----- c:\programdata\Malwarebytes
2009-08-19 10:39 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-08-19 10:39 <DIR> --d----- c:\progra~2\Malwarebytes
2009-08-19 09:48 <DIR> --d----- c:\users\aditya\appdata\roaming\BitDefender
2009-08-19 09:43 <DIR> --d----- c:\programdata\Adobe
2009-08-19 09:31 <DIR> --d----- c:\users\aditya\appdata\roaming\ZoneIDTrimmer
2009-08-19 09:26 <DIR> --d----- c:\programdata\BitDefender
2009-08-19 09:26 <DIR> --d----- c:\progra~2\BitDefender
2009-08-19 09:14 <DIR> --d----- c:\programdata\Autorun Eater
2009-08-19 09:14 <DIR> --d----- c:\progra~2\Autorun Eater
2009-08-19 08:46 <DIR> --d----- c:\program files\Gasanov.net
2009-08-18 12:22 <DIR> --d----- c:\program files\SCRABBLE
2009-08-17 06:55 54,156 a---h--- c:\windows\QTFont.qfn
2009-08-17 06:55 1,409 a------- c:\windows\QTFont.for
2009-08-16 13:55 123 a------- c:\windows\rootkitno.ini
2009-08-16 13:44 <DIR> --d----- C:\RootkitNO
2009-08-16 13:43 2 a--shrot c:\windows\winstart.bat
2009-08-16 13:42 <DIR> --d----- c:\program files\UnHackMe
2009-08-16 13:21 <DIR> --d----- c:\program files\Security Task Manager
2009-08-16 12:05 <DIR> --d----- c:\program files\Trend Micro
2009-08-16 04:30 850 a------- c:\windows\system32\ProductTweaks.xml
2009-08-16 04:30 385 a------- c:\windows\system32\user_gensett.xml
2009-08-16 04:25 <DIR> --d----- c:\program files\common files\MSSoap
2009-08-16 04:24 <DIR> --d----- c:\program files\BitDefender
2009-08-16 04:22 <DIR> --d----- c:\windows\system32\URTTEMP
2009-08-16 04:21 <DIR> --d----- c:\program files\common files\BitDefender
2009-08-07 02:40 <DIR> --d----- c:\program files\D-Tools
2009-08-07 02:32 <DIR> --d----- c:\program files\DAEMON Tools Toolbar
2009-08-07 02:21 721,904 a------- c:\windows\system32\drivers\sptd.sys
2009-08-05 01:22 505,104 a------- c:\windows\system32\msxml.dll
2009-08-05 01:22 115,016 a------- c:\windows\system32\MSINET.OCX
2009-08-05 01:22 69,632 a------- c:\windows\system32\xmltok.dll
2009-08-05 01:22 36,864 a------- c:\windows\system32\xmlparse.dll
2009-08-05 01:22 35,840 a------- c:\windows\system32\comdlg32.oca
2009-08-05 01:22 29,184 a------- c:\windows\system32\MSINET.oca
2009-08-05 01:22 28,432 a------- c:\windows\system32\msxmlr.dll
2009-08-05 01:22 26,096 a------- c:\windows\system32\xmlinst.exe
2009-08-05 01:22 24,576 a------- c:\windows\system32\msxml3a.dll
2009-07-31 22:30 524,288 a--sh--- C:\ntuser.dat{fe0af781-7e56-11de-9808-001a801e7fe6}.TMContainer00000000000000000002.regtrans-ms
2009-07-31 22:30 524,288 a--sh--- C:\ntuser.dat{fe0af781-7e56-11de-9808-001a801e7fe6}.TMContainer00000000000000000001.regtrans-ms
2009-07-31 22:30 65,536 a--sh--- C:\ntuser.dat{fe0af781-7e56-11de-9808-001a801e7fe6}.TM.blf
2009-07-31 22:30 5,120 a---h--- C:\ntuser.dat.LOG1
2009-07-31 22:30 0 a---h--- C:\ntuser.dat.LOG2
2009-07-31 22:30 262,144 a------- C:\ntuser.dat
2009-07-30 22:00 411,368 a------- c:\windows\system32\deploytk.dll
2009-07-30 21:59 <DIR> --d----- c:\program files\JonDo
2009-07-30 09:43 0 a---h--- c:\windows\system32\drivers\Msft_User_PCCSWpdDriver_01_05_00.Wdf
2009-07-29 23:17 57,436 a------- c:\windows\DASShp.dll
2009-07-29 23:17 <DIR> --d----- c:\program files\Microsoft Reader
2009-07-28 22:20 <DIR> --d----- c:\windows\system32\eu-ES
2009-07-28 22:20 <DIR> --d----- c:\windows\system32\ca-ES
2009-07-28 22:20 <DIR> --d----- c:\windows\system32\vi-VN
2009-07-28 22:17 0 a---h--- c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2009-07-28 22:08 <DIR> --d----- c:\windows\system32\SPReview
2009-07-28 21:51 928,768 a------- c:\windows\system32\scavenge.dll
2009-07-28 21:51 57,856 a------- c:\windows\system32\compcln.exe
2009-07-28 21:49 1,856,512 a------- c:\windows\system32\dbgeng.dll
2009-07-28 21:48 3,662,128 a------- c:\windows\system32\locale.nls
2009-07-28 21:47 558,080 a------- c:\windows\system32\sysmain.dll
2009-07-28 21:46 9,239 a------- c:\windows\system32\spcinstrumentation.man
2009-07-28 21:39 <DIR> --d----- c:\windows\system32\EventProviders
2009-07-28 02:36 <DIR> --d----- C:\PerfLogs
2009-07-28 01:40 193,024 a------- c:\windows\system32\recdisc.exe
2009-07-28 01:40 6,656 a------- c:\windows\system32\sdspres.dll
2009-07-28 01:40 28,160 a------- c:\windows\system32\sxproxy.dll
2009-07-28 01:38 237,056 a------- c:\windows\system32\netprofm.dll
2009-07-28 01:37 334,336 a------- c:\windows\system32\bcdedit.exe
2009-07-28 01:36 22,016 a------- c:\windows\system32\wmpcm.dll
2009-07-28 01:32 6,656 a------- c:\windows\system32\kbd106n.dll
2009-07-28 01:27 32,768 a------- c:\windows\SPInstall.etl
2009-07-28 01:26 <DIR> --d----- C:\79065638b8d03199de49
2009-07-26 01:53 <DIR> --d----- c:\program files\Auslogics
2009-07-25 21:47 <DIR> --d----- c:\program files\Defraggler
==================== Find3M ====================
2009-08-20 02:43 192,512 a------- c:\windows\system32\txmlutil.dll
2009-08-20 02:43 242,184 a------- c:\windows\system32\drivers\bdfsfltr.sys
2009-08-20 02:43 111,112 a------- c:\windows\system32\drivers\bdfm.sys
2009-08-20 02:43 82,696 a------- c:\windows\system32\drivers\BDVEDISK.sys
2009-08-20 01:05 201,688 a------- c:\windows\system32\prfh0404.dat
2009-08-20 01:05 72,034 a------- c:\windows\system32\prfc0404.dat
2009-08-19 06:30 143,360 a------- c:\windows\inf\infstrng.dat
2009-08-19 06:30 51,200 a------- c:\windows\inf\infpub.dat
2009-08-10 02:03 2,855 a------- c:\windows\pif\autorun.PIF
2009-08-10 02:03 2,855 a------- c:\windows\pif\setup.PIF
2009-07-28 22:29 86,016 a------- c:\windows\inf\infstor.dat
2009-07-28 22:20 665,600 a------- c:\windows\inf\drvindex.dat
2009-07-28 02:50 174 a--sh--- c:\program files\desktop.ini
2009-07-28 02:12 101,888 a------- c:\windows\system32\ifxcardm.dll
2009-07-28 02:12 82,432 a------- c:\windows\system32\axaltocm.dll
2009-06-25 22:11 0 a---h--- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-06-25 22:11 0 a---h--- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-06-25 22:11 503,864 a------- c:\windows\system32\drivers\Wdf01000.sys
2009-06-25 22:11 35,896 a------- c:\windows\system32\drivers\WdfLdr.sys
2009-06-25 22:11 3 a------- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Inbox_Critical.Wdf
2007-08-21 16:06 116,540 a------- c:\windows\inf\perflib\0404\perfi.dat
2007-08-21 16:06 116,540 a------- c:\windows\inf\perflib\0404\perfh.dat
2007-08-21 16:06 30,674 a------- c:\windows\inf\perflib\0404\perfd.dat
2007-08-21 16:06 30,674 a------- c:\windows\inf\perflib\0404\perfc.dat
2006-11-02 05:42 287,440 a------- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 05:42 287,440 a------- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 05:42 30,674 a------- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 05:42 30,674 a------- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 02:20 287,440 a------- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 02:20 287,440 a------- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 02:20 30,674 a------- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 02:20 30,674 a------- c:\windows\inf\perflib\0000\perfc.dat
============= FINISH: 2:53:29.03 ===============