ComboFix 09-06-05.07 - Administrator 06/08/2009 13:41.1 - NTFSx86
Microsoft
Windows Vista
Home Premium 6.0.6000.0.1252.1.1033.18.1790.1359 [GMT -4:00]
Running from: c:\users\Administrator\Desktop\Combo-Fix.exe
AV: Spyware Doctor with AntiVirus *On-access scanning enabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
SP: Spyware Doctor *disabled* (Updated) {1C3EDD79-273E-46ac-99F8-EFA9E7CBC301}
SP: Windows Defender *enabled* (Outdated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\ShoppingReport
c:\program files\zango
c:\users\Administrator\AppData\Roaming\
020000000e861978598C.manifest
c:\users\Administrator\AppData\Roaming\
020000000e861978598O.manifest
c:\users\Administrator\AppData\Roaming\
020000000e861978598P.manifest
c:\users\Administrator\AppData\Roaming\
020000000e861978598S.manifest
c:\windows\system32\drivers\Msft_Kernel_Apfiltr_01005.Wdf
c:\windows\system32\drivers\UACfmypqifhmbticyj.sys
c:\windows\system32\UACgnasusnvmxpptuy.dll
c:\windows\system32\UAChvaibehlvoyecrd.log
c:\windows\system32\UACijrordxgrwgkvoe.dat
c:\windows\system32\uacinit.dll
c:\windows\system32\UACshcmpbejitmugjs.dll
c:\windows\system32\UACsmjvwmfvslydjhu.dll
c:\windows\system32\UACspopqjypwixodyb.dll
c:\windows\system32\UACtxxbxtvrdlneggi.log
c:\windows\system32\UACwnshtlevujtrnju.dll
c:\windows\system32\UACxseiwwmdukekcvp.log
c:\windows\system32\x64
c:\windows\system32\x64\csnp2uvc.dll
c:\windows\system32\x64\rsnpvc64.dll
c:\windows\system32\x64\sncduvc.sys
c:\windows\system32\x64\snp2uvc.sys
c:\windows\system32\x64\vsnpvc64.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_UACd.sys
((((((((((((((((((((((((( Files Created from 2009-05-08 to 2009-06-08 )))))))))))))))))))))))))))))))
.
2009-06-08 17:45 . 2009-06-08 17:45 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2009-06-08 17:32 . 2009-06-08 17:45 -------- d-s---w- \Combo-Fix
2009-06-08 17:01 . 2009-06-08 17:01 -------- d-----w- c:\users\Administrator\AppData\Local\Apple
2009-06-08 16:31 . 2009-06-08 16:31 0 ----a-w- c:\windows\nsreg.dat
2009-06-08 16:31 . 2009-06-08 16:31 -------- d-----w- c:\users\Administrator\AppData\Local\Mozilla
2009-06-06 05:04 . 2009-06-06 05:50 -------- d-sh--w- \Config.Msi
2009-06-06 04:22 . 2009-06-06 04:23 -------- d-----w- \Qoobox
2009-06-05 21:58 . 2009-06-05 21:58 -------- d-----w- c:\program files\trend micro
2009-06-05 21:58 . 2009-06-05 21:58 -------- d-----w- C:\rsit
2009-06-05 21:58 . 2009-06-05 21:58 -------- d-----w- \rsit
2009-06-05 16:02 . 2009-06-05 16:02 70104 ----a-w- c:\users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2009-06-05 14:23 . 2009-06-07 22:12 680 ----a-w- c:\users\Administrator\AppData\Local\d3d9caps.dat
2009-06-05 14:23 . 2009-06-05 14:23 -------- d-----w- c:\users\Administrator\AppData\Local\Windows Live Writer
2009-06-05 14:22 . 2009-06-07 22:02 -------- d-----w- c:\users\Administrator\AppData\Local\Google
2009-06-02 18:08 . 2009-06-02 18:08 -------- d-----w- c:\users\Administrator\AppData\Roaming\yahoo!
2009-06-02 18:01 . 2009-06-02 18:01 -------- d-----w- c:\users\Administrator\AppData\Local\AOL
2009-06-02 17:48 . 2009-06-02 17:48 -------- d-----w- c:\program files\AVG
2009-05-27 00:20 . 2009-05-27 00:20 -------- d-----w- c:\program files\Common Files\Uninstall
2009-05-17 02:31 . 2009-05-17 02:31 1372 ----a-w- c:\windows\system32\Vy8pM7a3Jbrnc.vbs
2009-05-17 02:30 . 2009-05-17 02:30 1372 ----a-w- c:\windows\system32\efsxl.vbs
2009-05-17 02:29 . 2009-05-17 02:29 1372 ----a-w- c:\windows\system32\zkmSCos.vbs
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-08 17:35 . 2008-01-03 19:06 2191851520 --sha-w- \pagefile.sys
2009-06-07 20:54 . 2008-05-17 21:14 -------- d-----w- c:\progra~2\Google Updater
2009-06-06 05:50 . 2007-07-25 11:10 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-06-06 05:39 . 2007-07-25 11:11 -------- d-----w- c:\progra~2\Symantec
2009-06-06 05:38 . 2007-07-25 11:11 -------- d-----w- c:\program files\Symantec
2009-06-02 18:09 . 2007-07-25 11:00 -------- d-----w- c:\program files\Acer GameZone
2009-06-02 18:08 . 2008-05-08 00:20 -------- d-----w- c:\progra~2\Yahoo!
2009-06-02 18:08 . 2008-03-21 17:20 -------- d-----w- c:\program files\Yahoo!
2009-06-02 18:07 . 2008-12-19 23:47 -------- d-----w- c:\program files\Angle Interactive
2009-06-02 18:06 . 2009-05-09 03:01 -------- d-----w- c:\program files\Pando Networks
2009-06-02 18:05 . 2008-05-07 23:54 -------- d-----w- c:\program files\MySpace
2009-06-02 18:05 . 2008-03-28 04:18 -------- d-----w- c:\progra~2\GamesBar
2009-06-02 18:02 . 2008-08-31 20:44 -------- d-----w- c:\program files\Common Files\AOL
2009-06-01 20:26 . 2009-05-02 12:30 -------- d-----w- c:\progra~2\NVIDIA
2009-06-01 20:26 . 2009-05-02 12:30 42237 ----a-w- c:\progra~2\nvModes.dat
2009-06-01 20:06 . 2009-05-02 23:43 -------- d-----w- c:\program files\LimeWire
2009-05-26 23:41 . 2008-05-01 06:57 -------- d-----w- c:\program files\Google
2009-05-16 10:04 . 2007-07-25 10:51 -------- d-----w- c:\progra~2\Microsoft Help
2009-05-09 03:15 . 2009-05-09 03:15 -------- d-----w- c:\program files\Common Files\INCA Shared
2009-05-09 03:10 . 2009-05-09 03:10 -------- d-----w- c:\program files\Subagames
2009-04-26 04:10 . 2009-04-26 04:09 -------- d-----w- c:\program files\SweetIM
2009-04-26 04:09 . 2009-04-26 04:09 -------- d-----w- c:\progra~2\SweetIM
2009-03-17 03:16 . 2009-04-17 02:54 14848 ----a-w- c:\windows\system32\apilogen.dll
2009-03-17 03:16 . 2009-04-17 02:54 25600 ----a-w- c:\windows\system32\amxread.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2008-10-08 19:22 1172792 ----a-w- c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-03-23 1232896]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-17 68856]
"WindowsWelcomeCenter"="oobefldr.dll" - c:\windows\System32\oobefldr.dll [2006-11-02 2159104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-04 13556256]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-12-04 92704]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Empowering Technology Launcher.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Empowering Technology Launcher.lnk
backup=c:\windows\pss\Empowering Technology Launcher.lnk.CommonStartup
backupExtension=.CommonStartup