ComboFix 11-07-31.01 - user 01/08/2011 12:52:31.2.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.5815.4121 [GMT 1:00]
Running from: c:\users\user\Documents\Malware Removal Stuff\ComboFix.exe
Command switches used :: c:\users\user\Desktop\CFScript.txt
AV: BitDefender Antivirus *Enabled/Updated* {50909708-FF80-02AF-F814-B28405891E92}
FW: BitDefender Firewall *Enabled* {68AB162D-B5EF-03F7-D34B-1BB1FB5A59E9}
SP: BitDefender Antispyware *Enabled/Updated* {EBF176EC-D9BA-0D21-C2A4-89F67E0E542F}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
FILE ::
"c:\windows\explorer.exe"
"c:\windows\SysWow64\ConduitEngine.tmp"
"c:\windows\SysWow64\explorer.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files (x86)\Ask.com
c:\program files (x86)\Ask.com\cobrand.ico
c:\program files (x86)\Ask.com\config.xml
c:\program files (x86)\Ask.com\favicon.ico
c:\program files (x86)\Ask.com\fv_8b7c.ico
c:\program files (x86)\Ask.com\GenericAskToolbar.dll
c:\program files (x86)\Ask.com\mupcfg.xml
c:\program files (x86)\Ask.com\SaUpdate.exe
c:\program files (x86)\Ask.com\UpdateTask.exe
c:\program files (x86)\Conduit
c:\program files (x86)\Conduit\Community Alerts\Alert.dll
c:\program files (x86)\ConduitEngine
c:\program files (x86)\ConduitEngine\appContextMenu.xml
c:\program files (x86)\ConduitEngine\ConduitEngin.dll
c:\program files (x86)\ConduitEngine\ConduitEngineHelper.exe
c:\program files (x86)\ConduitEngine\ConduitEngineUninstall.exe
c:\program files (x86)\ConduitEngine\engineContextMenu.xml
c:\program files (x86)\ConduitEngine\EngineSettings.json
c:\program files (x86)\ConduitEngine\ldrConduitEngin.dll
c:\program files (x86)\ConduitEngine\prxConduitEngin.dll
c:\program files (x86)\ConduitEngine\toolbar.cfg
c:\program files (x86)\uTorrent
c:\program files (x86)\uTorrent\uTorrent.exe
c:\program files (x86)\uTorrentBar
c:\program files (x86)\uTorrentBar\GottenAppsContextMenu.xml
c:\program files (x86)\uTorrentBar\ldrtbuTor.dll
c:\program files (x86)\uTorrentBar\OtherAppsContextMenu.xml
c:\program files (x86)\uTorrentBar\prxtbuTor.dll
c:\program files (x86)\uTorrentBar\SharedAppsContextMenu.xml
c:\program files (x86)\uTorrentBar\tbuTor.dll
c:\program files (x86)\uTorrentBar\toolbar.cfg
c:\program files (x86)\uTorrentBar\ToolbarContextMenu.xml
c:\program files (x86)\uTorrentBar\uninstall.exe
c:\program files (x86)\uTorrentBar\uTorrentBarToolbarHelper.exe
c:\programdata\Dumps
c:\users\user\AppData\Local\Conduit
c:\users\user\AppData\Local\Conduit\CT2786678\uTorrentBarAutoUpdateHelper.exe
c:\users\user\AppData\Local\uTorrent
c:\users\user\AppData\Roaming\uTorrent
c:\users\user\AppData\Roaming\uTorrent\(PSP) 50 Cent - Bulletproof G-Unit Edition [ResourceRG Games by KloWn].torrent
c:\users\user\AppData\Roaming\uTorrent\(PSP) Megaman - Powered Up [ResourceRG Games by KloWn].torrent
c:\users\user\AppData\Roaming\uTorrent\(PSP) Mortal Kombat - Unchained [ResourceRG Games by KloWn].torrent
c:\users\user\AppData\Roaming\uTorrent\(PSP) Scarface - Money,Power,Respect [ResourceRG Games by KloWn].torrent
c:\users\user\AppData\Roaming\uTorrent\(PSP) Space Invaders Evolution [ResourceRg Games by KloWn].torrent
c:\users\user\AppData\Roaming\uTorrent\(PSX-PSP) Capcom vs. SNK - Millennium Fight 2000 Pro converted properly [ResourceRG Games by KloWn].torrent
c:\users\user\AppData\Roaming\uTorrent\(PSX-PSP) Legacy Of Kain-Soul Reaver converted properly [ResourceRG Games by KloWn].torrent
c:\users\user\AppData\Roaming\uTorrent\(PSX-PSP) Oddworld 1 & 2 converted properly [ResourceRG Games by KloWn].torrent
c:\users\user\AppData\Roaming\uTorrent\(PSX-PSP) Pandemonium! 1 & 2 converted properly [ResourceRG Games by KloWn].torrent
c:\users\user\AppData\Roaming\uTorrent\(PSX-PSP) R-Type Delta converted properly [ResourceRG Games by KloWn].torrent
c:\users\user\AppData\Roaming\uTorrent\(PSX-PSP) Tekken 3 converted properly [ResourceRG Games by KloWn].torrent
c:\users\user\AppData\Roaming\uTorrent\[
www.TorrentDay.com ] - Penn.And.Teller.Fool.Us.S01E08.HDTV.XviD-ANGELiC.torrent
c:\users\user\AppData\Roaming\uTorrent\[
www.Torrentday.com ] - The.Family.Crews.S02E01.HDTV.XviD-CRiMSON.torrent
c:\users\user\AppData\Roaming\uTorrent\[
www.TorrentDay.com ] - The.Family.Crews.S02E03.HDTV.XviD-CRiMSON.torrent
c:\users\user\AppData\Roaming\uTorrent\[
www.TorrentDay.com ] - The.Family.Crews.S02E04.HDTV.XviD-CRiMSON.torrent
c:\users\user\AppData\Roaming\uTorrent\[
www.TorrentDay.com ] - The.Family.Crews.S02E05.HDTV.XviD-CRiMSON.torrent
c:\users\user\AppData\Roaming\uTorrent\[
www.TorrentDay.com ] - The.Family.Crews.S02E06.HDTV.XviD-CRiMSON.1.torrent
c:\users\user\AppData\Roaming\uTorrent\[
www.TorrentDay.com ] - The.Family.Crews.S02E06.HDTV.XviD-CRiMSON.torrent
c:\users\user\AppData\Roaming\uTorrent\[
www.TorrentDay.com ] - The.Family.Crews.S02E07.HDTV.XviD-CRiMSON.1.torrent
c:\users\user\AppData\Roaming\uTorrent\[
www.TorrentDay.com ] - The.Family.Crews.S02E07.HDTV.XviD-CRiMSON.torrent
c:\users\user\AppData\Roaming\uTorrent\[
www.TorrentDay.com ] - The.Family.Crews.S02E08.HDTV.XviD-CRiMSON.torrent
c:\users\user\AppData\Roaming\uTorrent\[
www.TorrentDay.com ] - The.Family.Crews.S02E09.HDTV.XviD-CRiMSON.1.torrent
c:\users\user\AppData\Roaming\uTorrent\[
www.TorrentDay.com ] - The.Family.Crews.S02E09.HDTV.XviD-CRiMSON.torrent
c:\users\user\AppData\Roaming\uTorrent\[
www.TorrentDay.com ] - The.Family.Crews.S02E10.HDTV.XviD-CRiMSON.torrent
c:\users\user\AppData\Roaming\uTorrent\[
www.TorrentDay.com ] - The.Family.Crews.S02E11.HDTV.XviD-CRiMSON.torrent
c:\users\user\AppData\Roaming\uTorrent\[
www.Torrenting.com ] - The.Family.Crews.S02E02.HDTV.XviD-CRiMSON.torrent
c:\users\user\AppData\Roaming\uTorrent\[PSP].Fifa.Street.2.[EUR].-.[
www.ESPALPSP.com].rar.torrent
c:\users\user\AppData\Roaming\uTorrent\[PSP]Chili.con.Carnage.[EUR][FULL].-.[ESPALPSP.com].rar.torrent
c:\users\user\AppData\Roaming\uTorrent\[PSP]Dark Mirror.torrent
c:\users\user\AppData\Roaming\uTorrent\[PSP]The Warriors[Multi 5] TANKATORRENTS-com.torrent
c:\users\user\AppData\Roaming\uTorrent\[PSX-PSP]Medievil[EUR][ESPALPSP.com].rar.torrent
c:\users\user\AppData\Roaming\uTorrent\{
www.SceneTime.com } - The.Family.Crews.S02E04.HDTV.XviD-CRiMSON.torrent
c:\users\user\AppData\Roaming\uTorrent\{
www.SceneTime.com } - The.Family.Crews.S02E05.HDTV.XviD-CRiMSON.torrent
c:\users\user\AppData\Roaming\uTorrent\Aarakshan [2011-MP3-VBR-320Kbps] - xDR.torrent
c:\users\user\AppData\Roaming\uTorrent\Amy Winehouse - Back To Black (Deluxe Edition).torrent
c:\users\user\AppData\Roaming\uTorrent\Amy Winehouse - Back To Black[Deluxe Edition][
www.lokotorrents.com][mp3].torrent
c:\users\user\AppData\Roaming\uTorrent\apps\3609FC884502A1DF0AA5D9D160C827BB1BD51FC9.btapp
c:\users\user\AppData\Roaming\uTorrent\apps\4585805A0BEAAAA6F570825EB241201C227B5E09.btapp
c:\users\user\AppData\Roaming\uTorrent\arcsoft-webcam-companion-4.0.exe.torrent
c:\users\user\AppData\Roaming\uTorrent\ArcSoft WebCam Companion 2.0 & Magic-i Visual Effects 2.0.torrent
c:\users\user\AppData\Roaming\uTorrent\Atomix Virtual DJ Pro V7.02 {Precracked} + Addons {blaze69}.torrent
c:\users\user\AppData\Roaming\uTorrent\AVG Anti-Virus Professional 9.0 Build 663a1706 + Keygen [RH].torrent
c:\users\user\AppData\Roaming\uTorrent\avira-antivir-personal-free-antivirus-10.0.0.635.exe.torrent
c:\users\user\AppData\Roaming\uTorrent\AVIRA Antivir 2011 V.10.0.0.641 WITH key.torrent
c:\users\user\AppData\Roaming\uTorrent\Avira Antivirus Premuim 10 + Key to 2012.torrent
c:\users\user\AppData\Roaming\uTorrent\Big Bass Anthems 2011VBR MP3 BLOWA TLS.torrent
c:\users\user\AppData\Roaming\uTorrent\BitDefender 2011 All Products + Trial Reset till 2045 [RH].torrent
c:\users\user\AppData\Roaming\uTorrent\BitDefender Total Security 2011 x86 x64 - TESTiNG.torrent
c:\users\user\AppData\Roaming\uTorrent\BURNOUT LEGENDS.cso.torrent
c:\users\user\AppData\Roaming\uTorrent\CyberLink YouCam Deluxe 4.0.913.12934 Incl Serial Key.torrent
c:\users\user\AppData\Roaming\uTorrent\dht.dat
c:\users\user\AppData\Roaming\uTorrent\dht.dat.old
c:\users\user\AppData\Roaming\uTorrent\DJ Badboy & Danny B Present-The Mid-Season Vibez [2011-MP3-320Kbps] ~M2Tv~.torrent
c:\users\user\AppData\Roaming\uTorrent\DJ Mystery & Y.G.C.-The Game Classic Collabos-(Bootleg)-2009-MIXFIEND.torrent
c:\users\user\AppData\Roaming\uTorrent\Dj Zunils.torrent
c:\users\user\AppData\Roaming\uTorrent\dlimagecache\10E6FBE4D921B475FA5FEC6E9A535A540D6FEED1
c:\users\user\AppData\Roaming\uTorrent\dlimagecache\2D78C93EC367E6C1D9894103FA04B3BE5B20A84E
c:\users\user\AppData\Roaming\uTorrent\dlimagecache\BBEEC0395D21A2A7F91889D7C7509F3D5D46FC05
c:\users\user\AppData\Roaming\uTorrent\Dragon Balls.rar.torrent
c:\users\user\AppData\Roaming\uTorrent\Everybody On Dance Floor 12 [2011-MP3-VBR] - [DJLUV].torrent
c:\users\user\AppData\Roaming\uTorrent\Family Guy [MULTI5][
WwW.GamesTorrents.CoM].torrent
c:\users\user\AppData\Roaming\uTorrent\Futurama.S06E18.HDTV.XviD-ASAP.avi.torrent
c:\users\user\AppData\Roaming\uTorrent\Futurama.S06E19.HDTV.XviD-ASAP.avi.torrent
c:\users\user\AppData\Roaming\uTorrent\Futurama.S06E20.All.the.Presidents.Heads.HDTV.XviD-FQM.avi.torrent
c:\users\user\AppData\Roaming\uTorrent\Harry Potter and the Deathly Hallows Part 1[2010]DVDRip XviD-ExtraTorrentRG.torrent
c:\users\user\AppData\Roaming\uTorrent\ie\ie.1310840575.tmp
c:\users\user\AppData\Roaming\uTorrent\ie\ie.1311300188.tmp
c:\users\user\AppData\Roaming\uTorrent\ie\ie.1311300194.tmp
c:\users\user\AppData\Roaming\uTorrent\Jim Jones (The Diplomats Present) - On My Way To Church (RETAIL) 2004-C4.torrent
c:\users\user\AppData\Roaming\uTorrent\Lumines II (PSP).torrent
c:\users\user\AppData\Roaming\uTorrent\M.O.S. Anthems - Hip Hop 2011.torrent
c:\users\user\AppData\Roaming\uTorrent\Magic ISO Maker 5.5.rar.torrent
c:\users\user\AppData\Roaming\uTorrent\MalwareBytes Anti Malware v1.51.0.1200 with Serial.torrent
c:\users\user\AppData\Roaming\uTorrent\Man.vs.Wild.S07E01.Men.vs.Wild.with.Jake.Gyllenhaal.HDTV.XviD-MOMENTUM.avi.torrent
c:\users\user\AppData\Roaming\uTorrent\Man.vs.Wild.S07E02.New.Zealand.South.Island.HDTV.XviD-MOMENTUM.avi.torrent
c:\users\user\AppData\Roaming\uTorrent\Mario_Forever_Advance.exe.torrent
c:\users\user\AppData\Roaming\uTorrent\Medievil Resurrection [PSP ~ Multi5].rar.torrent
c:\users\user\AppData\Roaming\uTorrent\Microsoft Office 2010.torrent
c:\users\user\AppData\Roaming\uTorrent\Need.For.Speed.Undercover.EUR.PSP-GLoBAL.torrent
c:\users\user\AppData\Roaming\uTorrent\Now 79 - 2CDs.2011[
www.lokotorrents.com][mp3].torrent
c:\users\user\AppData\Roaming\uTorrent\NOW That's What I Call Music Vol. 79.torrent
c:\users\user\AppData\Roaming\uTorrent\Pokemon Emerald (U).gba.torrent
c:\users\user\AppData\Roaming\uTorrent\PowerISO v4.7 + Serials [ChattChitto RG].torrent
c:\users\user\AppData\Roaming\uTorrent\PSP - Def Jam Fight For New York The Take Over - ENG.ISO.torrent
c:\users\user\AppData\Roaming\uTorrent\PSP - Exit [USA] [
www.GamesTorrents.com].torrent
c:\users\user\AppData\Roaming\uTorrent\PSP - Family Guy.cso.torrent
c:\users\user\AppData\Roaming\uTorrent\PSP - The Godfather Mob Wars [English] [
WwW.GamesTorrents.CoM].torrent
c:\users\user\AppData\Roaming\uTorrent\PSP 145 Iso Games.1.torrent
c:\users\user\AppData\Roaming\uTorrent\PSP 145 Iso Games.torrent
c:\users\user\AppData\Roaming\uTorrent\PSP.Game.MegamanMaverickHunterX.English.ISO408MB.ByCombateMortal.rar.torrent
c:\users\user\AppData\Roaming\uTorrent\PSP.PSX_Game.MegaManX6.English.Eboot.305MB.torrent
c:\users\user\AppData\Roaming\uTorrent\ratchet_and_clank_size_matters.cso.torrent
c:\users\user\AppData\Roaming\uTorrent\resume.dat
c:\users\user\AppData\Roaming\uTorrent\resume.dat.old
c:\users\user\AppData\Roaming\uTorrent\Roll Deep.torrent
c:\users\user\AppData\Roaming\uTorrent\ROXIO 2011.torrent
c:\users\user\AppData\Roaming\uTorrent\rss.dat
c:\users\user\AppData\Roaming\uTorrent\rss.dat.old
c:\users\user\AppData\Roaming\uTorrent\settings.dat
c:\users\user\AppData\Roaming\uTorrent\settings.dat.old
c:\users\user\AppData\Roaming\uTorrent\Spyware Doctor v7.0.0.545 + New-Serial -TrT.torrent
c:\users\user\AppData\Roaming\uTorrent\SpyZooka.v2.5.9.6.Cracked-F4CG.torrent
c:\users\user\AppData\Roaming\uTorrent\The.Family.Crews.S01E01.DSR.XviD-CRiMSON - [
www.torrentday.com ].torrent
c:\users\user\AppData\Roaming\uTorrent\The.Family.Crews.S01E02.DSR.XviD-CRiMSON - [
www.torrentday.com ].torrent
c:\users\user\AppData\Roaming\uTorrent\The.Family.Crews.S01E03.DSR.XviD-CRiMSON - [
www.torrentday.com ].torrent
c:\users\user\AppData\Roaming\uTorrent\The.Family.Crews.S01E04.DSR.XviD-CRiMSON - [
www.torrentday.com ].1.torrent
c:\users\user\AppData\Roaming\uTorrent\The.Family.Crews.S01E04.DSR.XviD-CRiMSON - [
www.torrentday.com ].torrent
c:\users\user\AppData\Roaming\uTorrent\The.Family.Crews.S01E06.DSR.XviD-DVSKY.torrent
c:\users\user\AppData\Roaming\uTorrent\The.Family.Crews.S01E07.DSR.XviD-CRiMSON - [
www.torrentday.com ].torrent
c:\users\user\AppData\Roaming\uTorrent\The.Family.Crews.S01E08.DSR.XviD-CRiMSON - [
www.torrentday.com ].torrent
c:\users\user\AppData\Roaming\uTorrent\The.Family.Crews.S01E09.DSR.XviD-CRiMSON - [
www.torrentday.com ].torrent
c:\users\user\AppData\Roaming\uTorrent\The.Family.Crews.S01E10.DSR.XviD-CRiMSON - [
www.torrentday.com ].torrent
c:\users\user\AppData\Roaming\uTorrent\The.Family.Crews.S02E06.HDTV.XviD-CRiMSON.torrent
c:\users\user\AppData\Roaming\uTorrent\The.Family.Crews.S02E11.HDTV.XviD-CRiMSON.torrent
c:\users\user\AppData\Roaming\uTorrent\TonyHawksUnderground2Remix.zip.torrent
c:\users\user\AppData\Roaming\uTorrent\Top.Gear.17x05.HDTV.XviD-FoV.avi.torrent
c:\users\user\AppData\Roaming\uTorrent\utorrent.lng
c:\users\user\AppData\Roaming\uTorrent\V.A. - Addicted To Bass 2011 (3CD) (2011) DutchReleaseTeam.torrent
c:\users\user\AppData\Roaming\uTorrent\Va Ministry Of Sound Runnign Trax 3 (split tracks)1.torrent
c:\users\user\AppData\Roaming\uTorrent\Various DJ Mixes - April 2011 - [2 C D Pack] - Dj Rajiv.torrent
c:\users\user\AppData\Roaming\uTorrent\Various DJ Mixes - July 2011 - Dj Rajiv.torrent
c:\users\user\AppData\Roaming\uTorrent\WebCamMax 7.1.7.6 MultiLanguage Software + Crack.torrent
c:\users\user\AppData\Roaming\uTorrent\WinRAR 3.93 Final 32Bit And 64Bit Full {blaze69}.torrent
c:\users\user\AppData\Roaming\uTorrent\Zelda - the Minish Cap.GBA.torrent
.
.
((((((((((((((((((((((((( Files Created from 2011-07-01 to 2011-08-01 )))))))))))))))))))))))))))))))
.
.
2011-08-01 11:57 . 2011-08-01 11:57 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-08-01 11:39 . 2011-08-01 11:39 -------- d-----w- C:\_OTM
2011-07-30 23:31 . 2011-07-30 23:31 -------- d-----w- c:\program files (x86)\ESET
2011-07-29 01:23 . 2011-07-29 01:23 2301208 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\markup.dll
2011-07-29 01:23 . 2011-07-29 01:23 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM-2\StartResources.dll
2011-07-29 01:23 . 2011-07-29 01:23 710976 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll
2011-07-28 12:22 . 2011-07-31 01:07 -------- d-----w- c:\programdata\Avira
2011-07-27 02:00 . 2011-07-27 02:00 -------- d-----w- c:\program files (x86)\MSXML 4.0
2011-07-27 01:35 . 2011-07-27 01:35 -------- d-----w- c:\programdata\Uninstall
2011-07-27 01:31 . 2011-07-27 01:31 -------- d-----w- c:\program files\Roxio
2011-07-27 01:16 . 2011-07-27 01:16 -------- d-----w- c:\program files (x86)\PowerISO
2011-07-27 01:16 . 2010-04-12 08:55 91568 ----a-w- c:\windows\system32\drivers\scdemu.sys
2011-07-25 00:39 . 2011-07-25 00:39 -------- d-----w- C:\FIND_MOZ_EXT
2011-07-25 00:38 . 2011-07-25 18:32 -------- d-----w- c:\programdata\WebcamMax
2011-07-25 00:37 . 2011-07-25 00:42 -------- d-----w- c:\program files (x86)\WebcamMax
2011-07-25 00:09 . 2011-07-25 00:09 66048 --sha-r- c:\windows\SysWow64\wpdshextl.dll
2011-07-24 01:07 . 2011-07-24 01:07 -------- d-----w- c:\program files (x86)\Winamp Detect
2011-07-24 01:06 . 2011-07-27 01:35 -------- d-----w- c:\program files (x86)\Common Files\PX Storage Engine
2011-07-24 01:06 . 2011-07-24 01:08 -------- d-----w- c:\program files (x86)\Winamp
2011-07-21 18:19 . 2009-01-09 14:02 31744 ----a-w- c:\windows\system32\drivers\RimSerial_AMD64.sys
2011-07-21 18:19 . 2011-07-21 18:19 -------- d-----w- c:\programdata\Research In Motion
2011-07-21 18:19 . 2011-07-21 18:19 -------- d-----w- c:\program files (x86)\Common Files\Research In Motion
2011-07-21 18:19 . 2011-07-21 18:19 -------- d-----w- c:\program files (x86)\Research In Motion
2011-07-21 10:53 . 2011-07-21 10:53 -------- d-----w- c:\program files (x86)\Mp3tag
2011-07-19 17:18 . 2011-07-19 17:18 -------- d-----w- c:\program files (x86)\softendo.com
2011-07-18 23:05 . 2011-07-18 23:05 2301208 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
2011-07-18 23:05 . 2011-07-18 23:05 42776 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\dSM\StartResources.dll
2011-07-18 23:05 . 2011-07-18 23:05 710976 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-07-17 23:27 . 2011-07-17 23:29 -------- d-----w- c:\program files (x86)\VirtualDJ
2011-07-17 23:23 . 2011-07-17 23:23 -------- d-----w- c:\windows\system32\SPReview
2011-07-17 22:58 . 2011-07-17 22:58 -------- d-----w- c:\windows\system32\EventProviders
2011-07-17 19:34 . 2011-07-17 19:34 -------- d-----w- c:\programdata\regid.1986-12.com.adobe
2011-07-17 19:32 . 2011-07-17 19:34 -------- d-----w- c:\program files\Common Files\Adobe
2011-07-17 19:31 . 2011-07-17 19:31 -------- d-----w- c:\program files (x86)\Adobe Media Player
2011-07-17 19:14 . 2010-10-21 08:38 749936 ----a-w- c:\windows\system32\Pen_Touch_Tablet.dll
2011-07-17 19:14 . 2010-10-21 08:38 642928 ----a-w- c:\windows\SysWow64\Pen_Touch_Tablet.dll
2011-07-17 19:13 . 2011-07-17 19:14 -------- d-----w- c:\program files (x86)\TabletPlugins
2011-07-17 19:13 . 2010-10-05 12:26 18288 ----a-w- c:\windows\system32\drivers\wacmoumonitor.sys
2011-07-17 19:13 . 2010-10-05 12:26 12848 ------w- c:\windows\system32\drivers\wacommousefilter.sys
2011-07-17 19:13 . 2010-10-05 12:26 16168 ------w- c:\windows\system32\drivers\wacomvhid.sys
2011-07-17 19:13 . 2010-10-21 08:38 756592 ------w- c:\windows\system32\Pen_Tablet.dll
2011-07-17 19:13 . 2010-10-21 08:38 600432 ----a-w- c:\windows\system32\Wintab32.dll
2011-07-17 19:13 . 2010-10-21 08:38 506736 ----a-w- c:\windows\SysWow64\Wintab32.dll
2011-07-17 19:13 . 2010-10-21 08:38 650096 ----a-w- c:\windows\SysWow64\Pen_Tablet.dll
2011-07-17 19:13 . 2011-07-17 19:14 -------- d-----w- c:\program files\Tablet
2011-07-17 17:10 . 2011-07-17 17:11 -------- d-----w- c:\users\Guest
2011-07-17 16:41 . 2010-11-20 13:27 1900544 ----a-w- c:\windows\system32\setupapi.dll
2011-07-17 16:40 . 2010-11-20 13:27 303104 ----a-w- c:\program files\DVD Maker\WMM2CLIP.dll
2011-07-17 16:39 . 2010-11-20 12:21 363008 ----a-w- c:\windows\SysWow64\wbemcomn.dll
2011-07-17 16:39 . 2010-11-20 12:19 606208 ----a-w- c:\windows\SysWow64\wbem\fastprox.dll
2011-07-17 16:37 . 2010-11-20 13:27 529408 ----a-w- c:\windows\system32\wbemcomn.dll
2011-07-17 16:37 . 2010-11-20 13:27 1225216 ----a-w- c:\windows\system32\wbem\wbemcore.dll
2011-07-17 16:37 . 2010-11-20 13:27 524288 ----a-w- c:\windows\system32\wmicmiplugin.dll
2011-07-17 16:37 . 2010-11-20 13:27 933376 ----a-w- c:\windows\system32\SmiEngine.dll
2011-07-17 16:37 . 2010-11-20 13:25 199168 ----a-w- c:\windows\system32\PkgMgr.exe
2011-07-17 16:36 . 2010-11-20 13:26 422912 ----a-w- c:\windows\system32\drvstore.dll
2011-07-17 16:36 . 2010-11-20 13:26 399872 ----a-w- c:\windows\system32\dpx.dll
2011-07-17 13:04 . 2011-07-17 13:04 -------- d-----w- c:\windows\SysWow64\Wat
2011-07-17 13:04 . 2011-07-17 13:04 -------- d-----w- c:\windows\system32\Wat
2011-07-17 10:53 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
2011-07-17 03:05 . 2011-07-17 03:05 -------- d-----w- c:\programdata\bdch
2011-07-17 03:05 . 2011-04-09 06:58 142336 ----a-w- c:\windows\system32\poqexec.exe
2011-07-17 03:05 . 2011-04-09 05:56 123904 ----a-w- c:\windows\SysWow64\poqexec.exe
2011-07-17 03:05 . 2011-02-25 06:19 2871808 ------w- c:\windows\explorer.exe
2011-07-17 03:05 . 2011-02-25 05:30 2616320 ----a-w- c:\windows\SysWow64\explorer.exe
2011-07-17 03:05 . 2010-12-23 10:42 1118720 ----a-w- c:\windows\system32\sbe.dll
2011-07-17 03:05 . 2010-12-23 10:42 961024 ----a-w- c:\windows\system32\CPFilters.dll
2011-07-17 03:05 . 2010-12-23 10:42 723968 ----a-w- c:\windows\system32\EncDec.dll
2011-07-17 03:05 . 2010-12-23 10:36 259072 ----a-w- c:\windows\system32\mpg2splt.ax
2011-07-17 03:05 . 2010-12-23 05:54 642048 ----a-w- c:\windows\SysWow64\CPFilters.dll
2011-07-17 03:05 . 2010-12-23 05:54 534528 ----a-w- c:\windows\SysWow64\EncDec.dll
2011-07-17 02:58 . 2011-07-17 03:00 -------- d-----w- c:\program files\BitDefender
2011-07-17 02:56 . 2011-07-17 02:56 -------- d-----w- c:\programdata\e9230000-51dd-4f99-eee6-47fb13627d99
2011-07-17 02:54 . 2011-03-03 06:24 183296 ----a-w- c:\windows\system32\dnsrslvr.dll
2011-07-17 02:54 . 2011-03-03 06:21 30208 ----a-w- c:\windows\system32\dnscacheugc.exe
2011-07-17 02:54 . 2011-03-03 05:36 28672 ----a-w- c:\windows\SysWow64\dnscacheugc.exe
2011-07-17 02:52 . 2011-03-12 12:08 1465344 ----a-w- c:\windows\system32\XpsPrint.dll
2011-07-17 02:52 . 2011-03-12 11:23 870912 ----a-w- c:\windows\SysWow64\XpsPrint.dll
2011-07-17 02:52 . 2011-03-11 06:34 1359872 ----a-w- c:\windows\system32\mfc42u.dll
2011-07-17 02:52 . 2011-03-11 06:34 1395712 ----a-w- c:\windows\system32\mfc42.dll
2011-07-17 02:52 . 2011-03-11 05:33 1164288 ----a-w- c:\windows\SysWow64\mfc42u.dll
2011-07-17 02:52 . 2011-03-11 05:33 1137664 ----a-w- c:\windows\SysWow64\mfc42.dll
2011-07-17 02:52 . 2011-04-22 22:15 27520 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2011-07-17 02:52 . 2011-02-19 12:03 46080 ----a-w- c:\windows\system32\atmlib.dll
2011-07-17 02:52 . 2011-02-19 09:00 367616 ----a-w- c:\windows\system32\atmfd.dll
2011-07-17 02:52 . 2011-02-19 06:30 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2011-07-17 02:52 . 2011-02-19 04:34 294912 ----a-w- c:\windows\SysWow64\atmfd.dll
2011-07-17 02:40 . 2011-07-17 02:40 -------- d-----w- c:\programdata\45010000-ca18-485b-2f93-17ad8dc44da5
2011-07-17 02:32 . 2011-07-17 02:59 -------- d-----w- c:\programdata\BitDefender
2011-07-17 02:32 . 2011-07-17 02:58 -------- d-----w- c:\program files\Common Files\BitDefender
2011-07-17 02:32 . 2010-07-09 14:08 388168 ------w- c:\windows\system32\drivers\bdfsfltr.sys
2011-07-17 02:32 . 2011-07-17 03:00 846312 ----a-w- c:\programdata\bdinstall.bin
2011-07-17 02:29 . 2011-02-05 17:10 642944 ----a-w- c:\windows\system32\winload.efi
2011-07-17 02:29 . 2011-02-05 17:06 605552 ----a-w- c:\windows\system32\winload.exe
2011-07-17 02:29 . 2011-02-05 17:06 566208 ----a-w- c:\windows\system32\winresume.efi
2011-07-17 02:29 . 2011-02-05 17:06 518672 ----a-w- c:\windows\system32\winresume.exe
2011-07-17 02:29 . 2011-02-05 17:10 20352 ----a-w- c:\windows\system32\kdusb.dll
2011-07-17 02:29 . 2011-02-05 17:10 19328 ----a-w- c:\windows\system32\kd1394.dll
2011-07-17 02:29 . 2011-02-05 17:10 17792 ----a-w- c:\windows\system32\kdcom.dll
2011-07-17 02:29 . 2010-11-20 13:27 63488 ----a-w- c:\windows\system32\setbcdlocale.dll
2011-07-17 02:29 . 2011-07-17 02:29 -------- d-----w- c:\program files (x86)\DeskPins
2011-07-17 02:28 . 2011-04-29 03:06 467456 ----a-w- c:\windows\system32\drivers\srv.sys
2011-07-17 02:28 . 2011-04-29 03:05 410112 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-07-17 02:28 . 2011-04-29 03:05 168448 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-07-17 02:28 . 2011-06-11 03:07 3137536 ----a-w- c:\windows\system32\win32k.sys
2011-07-17 02:26 . 2011-02-12 11:34 267776 ----a-w- c:\windows\system32\FXSCOVER.exe
2011-07-17 02:26 . 2010-11-20 13:25 974336 ----a-w- c:\windows\system32\WFS.exe
2011-07-17 02:20 . 2011-07-25 00:04 -------- d-----w- c:\programdata\ArcSoft
2011-07-17 02:20 . 2005-04-27 15:36 245408 ----a-w- c:\windows\SysWow64\unicows.dll
2011-07-17 02:20 . 1995-07-31 12:44 212480 ----a-w- c:\windows\SysWow64\PCDLIB32.DLL
2011-07-17 02:20 . 2008-04-24 13:06 19968 ------w- c:\windows\system32\drivers\ArcSoftKsUFilter.sys
2011-07-17 02:20 . 2008-09-04 16:06 55808 ----a-w- c:\windows\system\ArcSoftKsUFilter.dll
2011-07-17 02:20 . 2011-07-25 14:07 -------- d-----w- c:\program files (x86)\ArcSoft
2011-07-17 02:20 . 2011-07-17 02:20 -------- d-----w- c:\program files (x86)\Common Files\ArcSoft
2011-07-17 01:09 . 2011-07-17 01:09 -------- d-----w- c:\program files (x86)\Microsoft Analysis Services
2011-07-17 01:09 . 2011-07-17 11:00 -------- d-----w- c:\programdata\Microsoft Help
2011-07-17 01:09 . 2011-07-17 01:09 -------- d-----r- C:\MSOCache
2011-07-17 00:45 . 2011-07-17 17:57 404640 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-07-17 00:45 . 2011-07-17 00:45 -------- d-----w- c:\windows\system32\Macromed
2011-07-17 00:26 . 2011-07-17 00:26 -------- d-----w- c:\program files\SystemRequirementsLab
2011-07-16 23:30 . 2011-06-20 07:57 8873296 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{B65C523C-D3DD-44AE-9700-DB3A7C65BDDA}\mpengine.dll
2011-07-16 23:30 . 2011-05-24 18:14 270720 ------w- c:\windows\system32\MpSigStub.exe
2011-07-16 18:49 . 2011-07-06 18:52 41272 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2011-07-16 18:49 . 2011-07-16 18:49 -------- d-----w- c:\programdata\Malwarebytes
2011-07-16 18:49 . 2011-07-16 18:50 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-17 23:33 . 2009-07-14 02:36 175616 ----a-w- c:\windows\system32\msclmd.dll
2011-07-17 23:33 . 2009-07-14 02:36 152576 ----a-w- c:\windows\SysWow64\msclmd.dll
2011-07-16 18:47 . 2010-06-24 10:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-06-03 05:57 . 2011-07-17 02:34 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2011-05-19 09:54 . 2011-05-19 09:54 507904 ----a-r- c:\windows\SysWow64\btwapi.dll
2010-07-08 09:37 . 2010-07-08 09:37 101544 ----a-w- c:\program files\Common Files\LinkInstaller.exe
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\programdata\e9230000-51dd-4f99-eee6-47fb13627d99 ----
.
2011-07-17 02:56 . 2011-07-17 02:56 3313 ----a-w- c:\programdata\e9230000-51dd-4f99-eee6-47fb13627d99\1310870917_1_01.xml
.
.
((((((((((((((((((((((((((((( SnapShot@2011-07-30_23.19.56 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-14 05:10 . 2011-08-01 11:42 37904 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2011-07-17 19:22 . 2011-07-30 22:11 61063 c:\windows\system32\config\systemprofile\AppData\Roaming\WTablet\Pen_Tablet.dat
+ 2011-07-17 19:22 . 2011-08-01 11:58 61063 c:\windows\system32\config\systemprofile\AppData\Roaming\WTablet\Pen_Tablet.dat
+ 2011-07-16 18:13 . 2011-08-01 11:42 8374 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3050388347-3726198533-3878670028-1000_UserData.bin
- 2011-07-30 23:18 . 2011-07-30 23:18 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2011-08-01 11:57 . 2011-08-01 11:57 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-07-30 23:18 . 2011-07-30 23:18 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-08-01 11:57 . 2011-08-01 11:57 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-07-16 11:09 . 2011-08-01 02:09 241548 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin
- 2009-07-14 02:36 . 2011-07-30 18:54 628460 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2011-08-01 02:11 628460 c:\windows\system32\perfh009.dat
+ 2009-07-14 02:36 . 2011-08-01 02:11 110612 c:\windows\system32\perfc009.dat
- 2009-07-14 02:36 . 2011-07-30 18:54 110612 c:\windows\system32\perfc009.dat
- 2009-07-14 05:01 . 2011-07-30 23:17 504788 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2011-08-01 11:57 504788 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2011-07-16 16:37 . 2011-08-01 11:39 2972296 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
- 2011-07-16 16:37 . 2011-07-28 00:21 2972296 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
+ 2011-07-17 02:09 . 2011-08-01 11:57 1329068 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3050388347-3726198533-3878670028-1000-8192.dat
- 2011-07-17 02:09 . 2011-07-30 23:17 1329068 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3050388347-3726198533-3878670028-1000-8192.dat
- 2011-07-17 19:20 . 2011-07-28 15:56 1359196 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3050388347-3726198533-3878670028-1000-12288.dat
+ 2011-07-17 19:20 . 2011-08-01 02:49 1359196 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3050388347-3726198533-3878670028-1000-12288.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2010-05-27 03:40 120176 ------w- c:\program files (x86)\EgisTec MyWinLocker\x86\PSDProtect.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-04-13 284696]
"SuiteTray"="c:\program files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" [2010-05-27 337264]
"EgisUpdate"="c:\program files (x86)\EgisTec IPS\EgisUpdate.exe" [2010-03-11 201584]
"EgisTecPMMUpdate"="c:\program files (x86)\EgisTec IPS\PmmUpdate.exe" [2010-03-11 407920]
"Norton Online Backup"="c:\program files (x86)\Symantec\Norton Online Backup\NOBuClient.exe" [2010-06-01 1155928]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]
"BackupManagerTray"="c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" [2010-06-28 265984]
"LManager"="c:\program files (x86)\Launch Manager\LManager.exe" [2010-08-10 975952]
"Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568]
"ArcSoft Connection Service"="c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-27 207424]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2011\Antispam32\ieshow.exe" [2010-08-10 71216]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"RIMBBLaunchAgent.exe"="c:\program files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe" [2011-02-18 79192]
"WinampAgent"="c:\program files (x86)\Winamp\winampa.exe" [2011-07-11 74752]
"PWRISOVM.EXE"="c:\program files (x86)\PowerISO\PWRISOVM.EXE" [2010-04-12 180224]
"RoxWatchTray"="c:\program files (x86)\Common Files\Roxio Shared\13.0\SharedCOM\RoxWatchTray13.exe" [2010-07-16 307184]
"CPMonitor"="c:\program files (x86)\Roxio 2011\5.0\CPMonitor.exe" [2010-07-13 84464]
"Desktop Disc Tool"="c:\program files (x86)\Roxio 2011\Roxio Burn\RoxioBurnLauncher.exe" [2010-06-30 477680]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http://www.avg.com/ww.special-uninstallation-feedback-app?lic=OABNAEUASAAtAFIAUQBFAFoAVAAtAEIAUQBKAEcAMwAtAEUANgA0AEYAQQAtADkAMgBMADcASAAtADYARQBNAEIAUgA&inst=NwA2AC0AOAA4ADAANQA1ADkANwAwADMALQBEAEQAVAArADAALQBEADMAOAAxAEwAKwA1AC0ASQA5ADAAKwAxAC0AUABMACsAOQAtAE4AMQBEACsAMQA&prod=54&ver=9.0.872" [?]
.
c:\users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
DeskPins.lnk - c:\program files (x86)\DeskPins\DeskPins.exe [2004-5-2 62464]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *bddel.exe
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-07-16 136176]
R2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files (x86)\Common Files\Roxio Shared\13.0\SharedCOM\RoxWatch13.exe [2010-07-16 354288]
R2 uCamMonitor;CamMonitor;c:\program files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [x]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-07-16 136176]
R3 MWLService;MyWinLocker Service;c:\program files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [2010-05-27 305520]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 RoxMediaDB13;RoxMediaDB13;c:\program files (x86)\Common Files\Roxio Shared\13.0\SharedCOM\RoxMediaDB13.exe [2010-07-16 1099248]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TurboBoost;TurboBoost;c:\program files\Intel\TurboBoost\TurboBoost.exe [2009-11-02 126352]
R3 Update Server;BitDefender Update Server v2;c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe [2010-07-21 467248]
R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 avc3;avc3;c:\windows\system32\DRIVERS\avc3.sys [x]
R4 avckf;avckf;c:\windows\system32\DRIVERS\avckf.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S0 Sahdad64;HDD Filter Driver;c:\windows\System32\Drivers\Sahdad64.sys [x]
S0 Saibad64;Volume Filter Driver;c:\windows\System32\Drivers\Saibad64.sys [x]
S1 Bdfndisf;BitDefender Firewall NDIS 6 Filter Driver;c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys [2010-06-18 88144]
S1 bdfwfpf;bdfwfpf;c:\program files\Common Files\BitDefender\BitDefender Firewall\bdfwfpf.sys [2010-06-18 98384]
S1 Bdvedisk;Bdvedisk;c:\windows\system32\DRIVERS\bdvedisk.sys [x]
S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys [x]
S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys [x]
S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys [x]
S1 SaibVdAd64;Virtual Disk Driver;c:\windows\system32\Drivers\SaibVdAd64.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269;Roxio SAIB Service;c:\program files (x86)\Roxio\BackOnTrack\App\SaibSVC.exe [2009-06-02 457200]
S2 BOT4Service;BOT4Service;c:\program files (x86)\Roxio\BackOnTrack\App\BService.exe [2010-07-14 32240]
S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe [2010-08-10 321104]
S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [2011-01-05 867712]
S2 GREGService;GREGService;c:\program files (x86)\Acer\Registration\GREGsvc.exe [2010-01-08 23584]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-04-13 13336]
S2 Live Updater Service;Live Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe [2011-01-31 244624]
S2 NOBU;Norton Online Backup;c:\program files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x]
S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2010-06-28 255744]
S2 TabletServicePen;TabletServicePen;c:\program files\Tablet\Pen\Pen_Tablet.exe [2010-10-21 5790064]
S2 TouchServicePen;Wacom Consumer Touch Service;c:\program files\Tablet\Pen\Pen_TouchService.exe [2010-10-21 487280]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [x]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-18 2320920]
S2 Updatesrv;BitDefender Desktop Update Service;c:\program files\BitDefender\BitDefender 2011\updatesrv.exe [2010-08-10 50664]
S3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\system32\DRIVERS\ArcSoftKsUFilter.sys [x]
S3 BDFM;BDFM;c:\windows\system32\DRIVERS\bdfm.sys [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2011-08-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-07-16 18:20]
.
2011-08-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-07-16 18:20]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2010-05-27 03:42 137584 ------w- c:\program files (x86)\EgisTec MyWinLocker\x64\PSDProtect.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mwlDaemon"="c:\program files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe" [2010-05-27 349552]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-07-23 161304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-07-23 386584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-07-23 415256]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-06-22 10920552]
"ETDWare"="c:\program files (x86)\Elantech\ETDCtrl.exe" [BU]
"PLFSetI"="c:\windows\PLFSetI.exe" [2011-07-11 206208]
"Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2011-01-05 860040]
"MDX.CloudPin"="c:\program files (x86)\Microsoft Digital Experience\Scripts\PinApps.vbs" [BU]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2011\ieshow.exe" [2010-08-10 76360]
"BDAgent"="c:\program files\BitDefender\BitDefender 2011\bdagent.exe" [2010-08-11 1971584]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~3\Office14\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_43C348BC2E93EB2B.dll/cmsidewiki.html
IE: Se&nd to OneNote - c:\progra~2\MICROS~3\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\users\user\AppData\Roaming\Mozilla\Firefox\Profiles\z288z4im.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
AddRemove-conduitEngine - c:\program files (x86)\ConduitEngine\ConduitEngineUninstall.exe
AddRemove-uTorrent - c:\program files (x86)\uTorrent\uTorrent.exe
AddRemove-uTorrentBar Toolbar - c:\program files (x86)\uTorrentBar\uninstall.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10u_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10u_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10u.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10u.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10u.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10u.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
c:\program files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
c:\program files\BitDefender\BitDefender 2011\Antispam32\pchooklaunch32.exe
c:\program files (x86)\Launch Manager\LMworker.exe
.
**************************************************************************
.
Completion time: 2011-08-01 13:04:32 - machine was rebooted
ComboFix-quarantined-files.txt 2011-08-01 12:04
ComboFix2.txt 2011-07-30 23:25
.
Pre-Run: 374,291,054,592 bytes free
Post-Run: 374,220,083,200 bytes free
.
- - End Of File - - 536A3F8D673B92CCE7E6724EC1DF2BFB