I know there was another thread for this but it didn't help all. It's really frustrating, so I need an expert's help.
ComboFix 10-02-10.01 - Stefanie 02/10/2010 14:47:22.2.2 - x86
Microsoft Windows Vista Home Premium 6.0.6001.1.1252.1.1033.18.1978.992 [GMT -8:00]
Running from: c:\users\Stefanie\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programdata\sysReserve.ini
c:\users\Stefanie\AppData\Local\{761304F6-9DA7-4127-8E14-12FB034BD339}
c:\users\Stefanie\AppData\Local\{761304F6-9DA7-4127-8E14-12FB034BD339}\chrome.manifest
c:\users\Stefanie\AppData\Local\{761304F6-9DA7-4127-8E14-12FB034BD339}\chrome\content\_cfg.js
c:\users\Stefanie\AppData\Local\{761304F6-9DA7-4127-8E14-12FB034BD339}\chrome\content\overlay.xul
c:\users\Stefanie\AppData\Local\{761304F6-9DA7-4127-8E14-12FB034BD339}\install.rdf
c:\users\Stefanie\AppData\Local\uiwwht
c:\users\Stefanie\AppData\Local\uiwwht\owepsftav.exe
c:\windows\system32\oem3.inf
.
((((((((((((((((((((((((( Files Created from 2010-01-10 to 2010-02-10 )))))))))))))))))))))))))))))))
.
2010-02-10 22:55 . 2010-02-10 22:55 -------- d-----w- c:\users\Joan\AppData\Local\temp
2010-02-10 22:55 . 2010-02-10 22:55 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-02-05 03:15 . 2010-02-05 03:41 -------- d-----w- c:\users\Stefanie\AppData\Roaming\gtk-2.0
2010-02-05 03:15 . 2010-02-05 03:15 -------- d-----w- c:\users\Stefanie\.thumbnails
2010-02-05 03:13 . 2010-02-05 04:02 -------- d-----w- c:\users\Stefanie\.gimp-2.6
2010-02-05 03:12 . 2010-02-05 03:12 -------- d-----w- c:\program files\GIMP-2.0
2010-02-03 02:13 . 2010-02-03 02:13 -------- d-----w- c:\program files\iPod
2010-02-03 02:04 . 2010-02-03 02:04 72488 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-01-15 04:11 . 2010-01-15 04:11 -------- d-----w- c:\users\Stefanie\AppData\Roaming\Xilisoft Corporation
2010-01-15 04:08 . 2010-01-15 04:08 -------- d-----w- c:\program files\Xilisoft
2010-01-12 23:43 . 2009-10-19 14:27 156672 ----a-w- c:\windows\system32\t2embed.dll
2010-01-12 23:43 . 2009-10-19 14:24 72704 ----a-w- c:\windows\system32\fontsub.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-10 22:43 . 2009-06-03 04:17 12 ----a-w- c:\windows\bthservsdp.dat
2010-02-10 01:44 . 2009-08-15 18:30 6756 ----a-w- c:\users\Stefanie\AppData\Local\d3d9caps.dat
2010-02-03 02:14 . 2009-12-02 02:16 -------- d-----w- c:\program files\iTunes
2010-02-03 02:13 . 2009-09-26 15:29 -------- d-----w- c:\program files\Common Files\Apple
2010-01-21 23:36 . 2010-01-09 01:29 120 ----a-w- c:\users\Stefanie\AppData\Local\Ufosusoyaqoxisi.dat
2010-01-21 23:36 . 2010-01-09 01:29 0 ----a-w- c:\users\Stefanie\AppData\Local\Yyitilobakamo.bin
2010-01-20 21:25 . 2009-06-03 06:01 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-14 19:12 . 2009-10-02 20:44 181120 ------w- c:\windows\system32\MpSigStub.exe
2010-01-13 00:02 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-12-18 13:05 . 2010-01-21 23:45 833024 ----a-w- c:\windows\system32\wininet.dll
2009-12-18 13:01 . 2010-01-21 23:45 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-12-18 10:14 . 2010-01-21 23:45 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-12-17 03:50 . 2009-12-17 03:50 -------- d-----w- c:\program files\AVCWare
2009-12-15 01:07 . 2009-08-23 02:39 -------- d-----w- c:\programdata\avg8
2009-12-04 18:03 . 2009-12-04 18:03 251376 ----a-w- c:\users\Stefanie\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2009-06-03 05:00 . 2009-06-03 04:53 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392]
"Google Update"="c:\users\Stefanie\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-08-22 133104]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-09-09 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-09-09 178712]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-09-09 154136]
|
|