Happy New Year!
ESET LOG:
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6419
# api_version=3.0.2
# EOSSerial=f7314e96e115d7409b091f5f79cd223a
# end=finished
# remove_checked=false
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-01-02 01:43:46
# local_time=2011-01-01 05:43:46 (-0800, Pacific Standard Time)
# country="United States"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=768 16777215 100 0 0 0 0 0
# compatibility_mode=5892 16776573 100 56 533386 130527585 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=163432
# found=0
# cleaned=0
# scan_time=3747
*****************************************
Just an FYI, while running combofix: Windows notified that it could not close "PEV.cfxxe."
Combofix Log:
ComboFix 11-01-01.01 - Cyrus 01/01/2011 18:02:44.1.2 - x64
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3962.2213 [GMT -8:00]
Running from: c:\users\Cyrus\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
SP: avast! Antivirus *Disabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Install.exe
.
((((((((((((((((((((((((( Files Created from 2010-12-02 to 2011-01-02 )))))))))))))))))))))))))))))))
.
2011-01-02 02:14 . 2011-01-02 02:14 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-01-02 02:14 . 2011-01-02 02:14 -------- d-----w- c:\users\Cyrus\AppData\Local\temp
2011-01-01 03:44 . 2011-01-01 03:44 -------- d-----w- c:\users\Cyrus\AppData\Local\{8B439BEF-4A2C-41CF-AE6F-B8C072EECCBB}
2010-12-31 06:05 . 2010-12-31 06:05 -------- d-----w- c:\users\Cyrus\AppData\Local\{B5305135-33C5-4A95-A56F-619E65F324CE}
2010-12-30 06:16 . 2010-12-30 06:16 -------- d-----w- c:\users\Cyrus\AppData\Local\{923BD3E2-147E-4183-919A-A9A0BAD1DA3D}
2010-12-29 08:31 . 2010-12-29 13:23 -------- d-----w- c:\users\Cyrus\AppData\Local\{72CBA11C-A3E3-48D6-BF7A-FEBD422E0F95}
2010-12-29 08:31 . 2010-12-29 08:31 -------- d-----w- c:\users\Cyrus\AppData\Local\{79268C15-4210-4DB9-958D-E41F9862E76D}
2010-12-28 08:16 . 2010-12-28 08:16 -------- d-----w- c:\users\Cyrus\AppData\Local\{C92CDEDA-1EF0-4BEA-AC99-17732A810128}
2010-12-27 04:50 . 2010-12-27 04:50 -------- d-----w- c:\users\Cyrus\AppData\Local\{D4DEBF4A-107B-4A19-A87B-34CD3744BA3C}
2010-12-26 10:30 . 2010-12-26 10:30 -------- d-----w- c:\program files (x86)\Pure Motion
2010-12-26 10:30 . 2010-12-26 10:30 -------- d-----w- c:\program files (x86)\Sonic Foundry
2010-12-26 10:30 . 2010-12-26 10:38 -------- d-----w- c:\program files (x86)\DebugMode
2010-12-26 09:54 . 2010-12-26 10:04 -------- d-----w- c:\users\Cyrus\AppData\Roaming\vlc
2010-12-26 09:54 . 2010-12-26 09:54 -------- d-----w- c:\program files (x86)\VideoLAN
2010-12-26 09:47 . 2010-12-26 09:47 -------- d-----w- c:\program files\DivX
2010-12-26 09:45 . 2010-12-26 09:51 -------- d-----w- c:\programdata\DivX
2010-12-26 09:39 . 2010-12-26 09:39 -------- d-----w- c:\program files (x86)\Xvid
2010-12-26 09:39 . 2009-06-08 00:25 77824 ----a-w- c:\windows\SysWow64\xvid.ax
2010-12-26 09:39 . 2009-06-08 00:24 180224 ----a-w- c:\windows\SysWow64\xvidvfw.dll
2010-12-26 09:39 . 2009-06-08 00:16 819200 ----a-w- c:\windows\SysWow64\xvidcore.dll
2010-12-26 02:36 . 2010-12-26 02:37 -------- d-----w- c:\users\Cyrus\AppData\Local\{C4F4119E-74EB-494B-B64F-9F1C5E45551C}
2010-12-26 02:28 . 2010-12-26 02:28 -------- d-----w- c:\program files\Windows Live
2010-12-26 02:26 . 2010-12-29 08:31 -------- d-----w- c:\users\Cyrus\AppData\Local\Windows Live
2010-12-26 02:00 . 2010-12-26 02:00 -------- d-----w- c:\windows\SysWow64\spool
2010-12-26 02:00 . 2010-12-26 02:00 -------- d-----w- c:\program files (x86)\Windows Portable Devices
2010-12-26 02:00 . 2010-12-26 02:00 -------- d-----w- c:\program files\Windows Portable Devices
2010-12-26 01:20 . 2009-10-08 21:08 234496 ----a-w- c:\windows\SysWow64\oleacc.dll
2010-12-26 01:20 . 2009-10-08 21:07 4096 ----a-w- c:\windows\SysWow64\oleaccrc.dll
2010-12-26 01:20 . 2009-10-08 21:08 555520 ----a-w- c:\windows\SysWow64\UIAutomationCore.dll
2010-12-26 01:15 . 2009-09-10 02:00 92672 ----a-w- c:\windows\SysWow64\UIAnimation.dll
2010-12-26 01:15 . 2009-09-10 02:01 3023360 ----a-w- c:\windows\SysWow64\UIRibbon.dll
2010-12-26 01:15 . 2009-09-10 02:00 1164800 ----a-w- c:\windows\SysWow64\UIRibbonRes.dll
2010-12-26 01:11 . 2010-11-03 10:53 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2010-12-26 01:11 . 2010-11-03 10:51 2409784 ----a-w- c:\program files (x86)\Windows Mail\OESpamFilter.dat
2010-12-26 01:10 . 2009-09-10 15:27 1486848 ----a-w- c:\program files\Windows Media Player\setup_wm.exe
2010-12-26 01:10 . 2009-09-10 14:58 1418752 ----a-w- c:\program files (x86)\Windows Media Player\setup_wm.exe
2010-12-26 01:10 . 2009-09-10 14:58 310784 ----a-w- c:\windows\SysWow64\unregmp2.exe
2010-12-26 01:10 . 2009-10-23 17:10 714240 ----a-w- c:\windows\SysWow64\timedate.cpl
2010-12-26 01:10 . 2010-05-04 19:13 231424 ----a-w- c:\windows\SysWow64\msshsq.dll
2010-12-26 01:09 . 2010-01-25 12:00 471552 ----a-w- c:\windows\SysWow64\secproc_isv.dll
2010-12-26 01:09 . 2010-01-25 12:00 471552 ----a-w- c:\windows\SysWow64\secproc.dll
2010-12-26 01:09 . 2010-01-25 12:00 152576 ----a-w- c:\windows\SysWow64\secproc_ssp_isv.dll
2010-12-26 01:09 . 2010-01-25 12:00 152064 ----a-w- c:\windows\SysWow64\secproc_ssp.dll
2010-12-26 01:09 . 2010-01-25 08:21 526336 ----a-w- c:\windows\SysWow64\RMActivate_isv.exe
2010-12-26 01:09 . 2010-01-25 08:21 346624 ----a-w- c:\windows\SysWow64\RMActivate_ssp_isv.exe
2010-12-26 01:09 . 2010-01-25 08:21 518144 ----a-w- c:\windows\SysWow64\RMActivate.exe
2010-12-26 01:09 . 2010-01-25 08:21 347136 ----a-w- c:\windows\SysWow64\RMActivate_ssp.exe
2010-12-26 01:09 . 2010-01-25 11:58 332288 ----a-w- c:\windows\SysWow64\msdrm.dll
2010-12-26 01:07 . 2010-08-26 16:34 1696256 ----a-w- c:\windows\SysWow64\gameux.dll
2010-12-26 01:07 . 2010-08-26 16:33 28672 ----a-w- c:\windows\SysWow64\Apphlpdm.dll
2010-12-26 01:07 . 2010-08-26 14:23 4240384 ----a-w- c:\windows\SysWow64\GameUXLegacyGDFs.dll
2010-12-26 00:43 . 2010-12-26 00:44 -------- d-----w- c:\windows\SysWow64\ca-ES
2010-12-26 00:43 . 2010-12-26 00:43 -------- d-----w- c:\windows\SysWow64\eu-ES
2010-12-26 00:43 . 2010-12-26 00:43 -------- d-----w- c:\windows\SysWow64\vi-VN
2010-12-26 00:09 . 2009-04-11 07:28 876032 ----a-w- c:\windows\SysWow64\wer.dll
2010-12-25 23:25 . 2010-12-25 23:25 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2010-12-25 23:20 . 2010-09-06 16:20 9728 ----a-w- c:\windows\SysWow64\sscore.dll
2010-12-25 23:20 . 2010-09-06 16:19 17920 ----a-w- c:\windows\SysWow64\netevent.dll
2010-12-25 23:20 . 2010-03-05 14:01 420352 ----a-w- c:\windows\SysWow64\vbscript.dll
2010-12-25 23:20 . 2009-08-24 11:36 377344 ----a-w- c:\windows\SysWow64\winhttp.dll
2010-12-25 23:18 . 2010-05-27 20:08 739328 ----a-w- c:\windows\SysWow64\inetcomm.dll
2010-12-25 21:31 . 2010-11-16 20:01 8199504 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{47240EEA-EF62-4EAD-A2C5-83B259A662AF}\mpengine.dll
2010-12-25 21:14 . 2010-02-20 23:06 24064 ----a-w- c:\windows\SysWow64\nshhttp.dll
2010-12-25 21:14 . 2010-02-20 23:05 30720 ----a-w- c:\windows\SysWow64\httpapi.dll
2010-12-25 20:54 . 2009-11-08 18:55 99176 ----a-w- c:\windows\SysWow64\PresentationHostProxy.dll
2010-12-25 20:54 . 2009-11-08 18:55 49472 ----a-w- c:\windows\SysWow64\netfxperf.dll
2010-12-25 20:54 . 2009-11-08 18:55 297808 ----a-w- c:\windows\SysWow64\mscoree.dll
2010-12-25 20:54 . 2009-11-08 18:55 295264 ----a-w- c:\windows\SysWow64\PresentationHost.exe
2010-12-25 20:54 . 2009-11-08 18:55 1130824 ----a-w- c:\windows\SysWow64\dfshim.dll
2010-12-25 20:42 . 2010-10-19 04:56 7680 ----a-w- c:\program files\Internet Explorer\iecompat.dll
2010-12-25 20:42 . 2010-10-19 04:27 7680 ----a-w- c:\program files (x86)\Internet Explorer\iecompat.dll
2010-12-25 20:39 . 2010-11-02 06:03 638232 ----a-w- c:\program files (x86)\Internet Explorer\iexplore.exe
2010-12-25 20:37 . 2009-03-08 11:40 115712 ----a-w- c:\program files\Internet Explorer\ielowutil.exe
2010-12-25 20:37 . 2009-03-08 11:34 115712 ----a-w- c:\program files (x86)\Internet Explorer\ielowutil.exe
2010-12-25 20:37 . 2009-03-08 11:32 72704 ----a-w- c:\windows\SysWow64\admparse.dll
2010-12-25 20:37 . 2009-03-08 11:33 18944 ----a-w- c:\windows\SysWow64\corpol.dll
2010-12-25 20:01 . 2009-09-10 16:48 218624 ----a-w- c:\windows\SysWow64\msv1_0.dll
2010-12-25 20:00 . 2009-07-15 12:39 313344 ----a-w- c:\windows\SysWow64\wmpdxm.dll
2010-12-25 20:00 . 2009-07-15 10:21 43520 ----a-w- c:\windows\SysWow64\msdxm.tlb
2010-12-25 20:00 . 2009-07-15 10:21 18432 ----a-w- c:\windows\SysWow64\amcompat.tlb
2010-12-25 19:58 . 2009-08-11 16:44 1401856 ----a-w- c:\windows\SysWow64\msxml6.dll
2010-12-25 19:58 . 2009-06-10 11:41 2868224 ----a-w- c:\windows\SysWow64\mf.dll
2010-12-25 19:58 . 2009-04-11 06:28 98816 ----a-w- c:\windows\SysWow64\mfps.dll
2010-12-25 19:58 . 2009-04-11 06:27 53248 ----a-w- c:\windows\SysWow64\rrinstaller.exe
2010-12-25 19:58 . 2009-04-11 06:27 24576 ----a-w- c:\windows\SysWow64\mfpmp.exe
2010-12-25 19:58 . 2009-04-11 04:54 2048 ----a-w- c:\windows\SysWow64\mferror.dll
2010-12-25 19:58 . 2009-07-17 13:54 71680 ----a-w- c:\windows\SysWow64\atl.dll
2010-12-25 19:57 . 2010-08-31 15:44 531968 ----a-w- c:\windows\SysWow64\comctl32.dll
2010-12-25 19:57 . 2010-06-17 18:34 16361984 ----a-w- c:\program files\Movie Maker\MOVIEMK.dll
2010-12-25 19:57 . 2010-06-17 16:47 150528 ----a-w- c:\program files\Movie Maker\MOVIEMK.exe
2010-12-25 19:57 . 2009-04-11 07:11 336896 ----a-w- c:\program files\Movie Maker\WMM2AE.dll
2010-12-25 19:57 . 2009-04-11 07:11 26624 ----a-w- c:\program files\Movie Maker\WMM2EXT.dll
2010-12-25 19:57 . 2009-06-04 12:07 2066432 ----a-w- c:\windows\SysWow64\mstscax.dll
2010-12-25 19:57 . 2009-04-11 06:28 53248 ----a-w- c:\windows\SysWow64\tsgqec.dll
2010-12-25 19:57 . 2009-04-11 06:28 136192 ----a-w- c:\windows\SysWow64\aaclient.dll
2010-12-25 19:57 . 2010-10-28 13:20 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2010-12-25 19:55 . 2010-10-12 17:43 35328 ----a-w- c:\program files\Windows Mail\wabfind.dll
2010-12-25 19:54 . 2009-12-04 18:29 1314816 ----a-w- c:\windows\SysWow64\quartz.dll
2010-12-25 19:54 . 2009-12-04 18:30 12288 ----a-w- c:\windows\SysWow64\tsbyuv.dll
2010-12-25 19:54 . 2009-12-04 18:28 31744 ----a-w- c:\windows\SysWow64\msvidc32.dll
2010-12-25 19:54 . 2009-12-04 18:28 22528 ----a-w- c:\windows\SysWow64\msyuv.dll
2010-12-25 19:54 . 2009-12-04 18:28 123904 ----a-w- c:\windows\SysWow64\msvfw32.dll
2010-12-25 19:54 . 2009-12-04 18:28 13312 ----a-w- c:\windows\SysWow64\msrle32.dll
2010-12-25 19:54 . 2009-12-04 18:28 82944 ----a-w- c:\windows\SysWow64\mciavi32.dll
2010-12-25 19:54 . 2009-12-04 18:28 50176 ----a-w- c:\windows\SysWow64\iyuv_32.dll
2010-12-25 19:54 . 2009-12-04 18:27 91136 ----a-w- c:\windows\SysWow64\avifil32.dll
2010-12-25 19:54 . 2010-08-20 16:05 867328 ----a-w- c:\windows\SysWow64\wmpmde.dll
2010-12-25 19:45 . 2010-11-04 18:55 352768 ----a-w- c:\windows\SysWow64\taskschd.dll
2010-12-25 19:45 . 2010-11-04 18:55 270336 ----a-w- c:\windows\SysWow64\taskcomp.dll
2010-12-25 19:45 . 2010-11-04 16:34 171520 ----a-w- c:\windows\SysWow64\taskeng.exe
2010-12-25 09:08 . 2009-08-07 02:24 35552 ----a-w- c:\windows\SysWow64\wups.dll
2010-12-25 09:08 . 2009-08-07 02:23 575704 ----a-w- c:\windows\SysWow64\wuapi.dll
2010-12-25 09:08 . 2009-08-07 01:44 87552 ----a-w- c:\windows\SysWow64\wudriver.dll
2010-12-25 09:08 . 2009-08-07 03:23 171608 ----a-w- c:\windows\SysWow64\wuwebv.dll
2010-12-25 09:08 . 2009-08-07 02:44 33792 ----a-w- c:\windows\SysWow64\wuapp.exe
2010-12-25 08:28 . 2010-12-27 00:10 -------- d-----w- c:\users\Cyrus\Logs
2010-12-25 08:25 . 2010-12-25 08:25 -------- d-----w- c:\users\Cyrus\AppData\Roaming\Malwarebytes
2010-12-25 08:24 . 2010-12-21 02:09 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
2010-12-25 08:24 . 2010-12-25 08:24 -------- d-----w- c:\programdata\Malwarebytes
2010-12-25 08:24 . 2010-12-25 08:24 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2010-12-20 09:05 . 2010-12-31 20:06 38848 ----a-w- c:\windows\avastSS.scr
2010-12-20 09:02 . 2010-12-31 20:06 188216 ----a-w- c:\windows\SysWow64\aswBoot.exe
2010-12-20 09:02 . 2010-12-20 09:02 -------- d-----w- c:\programdata\Alwil Software
2010-12-20 09:02 . 2010-12-20 09:02 -------- d-----w- c:\program files\Alwil Software
2010-12-20 08:54 . 2010-12-20 08:55 -------- d-----w- c:\program files (x86)\SpywareBlaster
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-30 01:38 . 2010-11-30 01:38 94208 ----a-w- c:\windows\SysWow64\QuickTimeVR.qtx
2010-11-30 01:38 . 2010-11-30 01:38 69632 ----a-w- c:\windows\SysWow64\QuickTime.qts
2010-11-12 00:44 . 2010-11-12 00:44 94208 ----a-w- c:\windows\SysWow64\dpl100.dll
2010-11-10 10:54 . 2010-11-10 10:54 49016 ----a-w- c:\windows\SysWow64\sirenacm.dll
2010-11-10 10:26 . 2010-11-10 10:26 73728 ----a-r- c:\users\Cyrus\AppData\Roaming\Microsoft\Installer\{EBFEEB3F-3E3B-4725-A4E0-376144CE4F76}\liteico.exe.827545C6_7013_4DE1_8E6C_DAEE4C57F54A.exe
2010-11-10 10:26 . 2010-11-10 10:26 73728 ----a-r- c:\users\Cyrus\AppData\Roaming\Microsoft\Installer\{EBFEEB3F-3E3B-4725-A4E0-376144CE4F76}\ARPICON.exe
2010-11-08 22:57 . 2010-11-08 22:57 353592 ----a-w- c:\windows\SysWow64\DivXControlPanelApplet.cpl
2010-10-07 20:23 . 2010-10-07 20:23 91424 ----a-w- c:\windows\SysWow64\dnssd.dll
2010-10-07 20:23 . 2010-10-07 20:23 197920 ----a-w- c:\windows\SysWow64\dnssdX.dll
2010-10-07 20:23 . 2010-10-07 20:23 107808 ----a-w- c:\windows\SysWow64\dns-sd.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"googletalk"="c:\users\Cyrus\AppData\Roaming\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-07-03 152064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Intuit SyncManager"="c:\program files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe" [2008-09-09 623880]
"VWLASU"="c:\program files\Sony\VAIO Wireless Wizard\AutoLaunchWLASU.exe" [2008-05-20 24576]
"ISBMgr.exe"="c:\program files (x86)\Sony\ISB Utility\ISBMgr.exe" [2008-04-04 317280]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-30 421888]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2010-12-14 421160]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2010-12-09 1226608]
c:\users\Cyrus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-10-14 1062440]
QuickBooks Update Agent.lnk - c:\program files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2008-9-11 984352]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2008-11-07 36392]
R3 SOHCImp;VAIO Media plus Content Importer;c:\program files (x86)\Sony\VAIO Media plus\SOHCImp.exe [2008-10-21 103712]
R3 SOHDms;VAIO Media plus Digital Media Server;c:\program files (x86)\Sony\VAIO Media plus\SOHDms.exe [2008-10-21 353568]
R3 SOHDs;VAIO Media plus Device Searcher;c:\program files (x86)\Sony\VAIO Media plus\SOHDs.exe [2008-10-21 62752]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2010-09-28 51712]
R3 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [2008-10-02 369952]
R3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe [2008-09-19 108832]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2010-07-12 55856]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-09-26 834544]
S1 aswSP;aswSP; [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2010-02-17 14920]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2010-02-17 12360]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2010-06-29 128752]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-12-31 62032]
S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-10-20 47632]
S2 uCamMonitor;CamMonitor;c:\program files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [2008-09-18 104960]
S2 VAIO Power Management;VAIO Power Management;c:\program files\Sony\VAIO Power Management\SPMService.exe [2008-09-05 407392]
S2 VCFw;VAIO Content Folder Watcher;c:\program files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [2008-09-04 446464]
S2 vpnagent;Cisco AnyConnect VPN Agent;c:\program files (x86)\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe [2010-05-06 583360]
S3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\system32\DRIVERS\ArcSoftKsUFilter.sys [2008-04-24 19968]
S3 CAXHWAZL;CAXHWAZL;c:\windows\system32\DRIVERS\CAXHWAZL.sys [2008-08-26 293376]
S3 NETw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\NETw5v64.sys [2008-08-29 4745216]
S3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\DRIVERS\SFEP.sys [2008-08-22 11392]
S3 yukonx64;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk60x64.sys [2008-05-31 393728]
.
--------- x86-64 -----------
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="%ProgramFiles%\Windows Defender\MSASCui.exe -hide" [X]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-11-06 151064]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-11-06 209432]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-11-06 181784]
"RtHDVCpl"="RAVCpl64.exe" [2008-09-16 6430208]
"Skytel"="Skytel.exe" [2008-09-16 1826816]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-08-19 1560872]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2008-01-21 225792]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=SNYR&bmod=SNYR
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-86486D72E749} - c:\program files (x86)\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll
FF - ProfilePath - c:\users\Cyrus\AppData\Roaming\Mozilla\Firefox\Profiles\2r3z2r1e.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.usc.edu/
FF - prefs.js: network.proxy.type - 4
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: NoScript: {73a6fe31-595d-460b-a920-fcc0f8843232} - %profile%\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
- - - - ORPHANS REMOVED - - - -
Wow6432Node-HKCU-Run-WMPNSCFG - c:\program files (x86)\Windows Media Player\WMPNSCFG.exe
Notify-VESWinlogon - VESWinlogon.dll
AddRemove-Octoshape add-in for Adobe Flash Player - c:\users\Cyrus\AppData\Roaming\Macromedia\Flash Player\
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10b.exe,-101"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10b.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx, 1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10b.ocx, 1"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}]
@Denied: (A 2) (Everyone)
@="IFlashBroker2"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@="Shockwave Flash"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@="FlashBroker"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes]
"SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-01-01 18:25:59
ComboFix-quarantined-files.txt 2011-01-02 02:25
Pre-Run: 156,002,648,064 bytes free
Post-Run: 155,597,402,112 bytes free
Current=1 Default=1 Failed=0 LastKnownGood=8 Sets=1,2,3,4,5,6,7,8
- - End Of File - - 34782AE38646862CE9FEAB332698F705