Thanks, here is the report.
ComboFix 10-05-16.02 - dpadgett 05/17/2010 18:23:13.2.2 - x86
Microsoft
Windows Vista
Business 6.0.6002.2.1252.1.1033.18.2037.1066 [GMT -4:00]
Running from: c:\users\dpadgett\Desktop\ComboFix.exe
Command switches used :: c:\users\dpadgett\Desktop\CFScript.txt
AV: Symantec Endpoint Protection *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
FW: Symantec Endpoint Protection *disabled* {BE898FE3-CD0B-4014-85A9-03DB9923DDB6}
SP: Symantec Endpoint Protection *disabled* (Updated) {6C85A515-B91D-4D2B-AF18-40984A4A8493}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Files Created from 2010-04-17 to 2010-05-17 )))))))))))))))))))))))))))))))
.
2010-05-17 22:34 . 2010-05-17 22:34 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-05-17 22:34 . 2010-05-17 22:34 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-05-17 22:34 . 2010-05-17 22:34 -------- d-----w- c:\users\cphuah\AppData\Local\temp
2010-05-17 22:34 . 2010-05-17 22:34 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2010-05-17 22:16 . 2010-05-17 22:17 -------- d-----w- C:\32788R22FWJFW
2010-05-17 00:30 . 2010-05-17 22:34 -------- d-----w- c:\users\dpadgett\AppData\Local\temp
2010-05-14 14:10 . 2010-05-14 14:10 -------- d-----w- c:\program files\ESET
2010-05-14 13:16 . 2010-05-14 13:16 -------- d-----w- c:\program files\Common Files\Adobe
2010-05-14 13:15 . 2010-05-14 13:15 86016 ----a-w- c:\programdata\NOS\Adobe_Downloads\arh.exe
2010-05-14 13:14 . 2010-05-14 13:14 -------- d-----w- c:\program files\Common Files\Java
2010-05-13 22:38 . 2010-05-13 22:38 -------- d-----w- C:\_OTL
2010-05-12 14:56 . 2010-05-14 13:13 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-05-12 14:52 . 2010-05-12 14:52 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-05-12 14:51 . 2010-05-14 13:59 -------- d-----w- c:\programdata\NOS
2010-05-11 22:41 . 2010-05-11 21:11 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-05-11 21:11 . 2010-02-04 15:53 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-05-11 21:11 . 2010-05-11 21:11 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-05-11 21:05 . 2010-05-11 21:05 -------- dc-h--w- c:\programdata\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-05-11 21:05 . 2010-02-04 15:53 2954656 -c--a-w- c:\programdata\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}\Ad-AwareInstaller.exe
2010-05-11 21:04 . 2010-05-11 21:11 -------- d-----w- c:\programdata\Lavasoft
2010-05-11 21:04 . 2010-05-11 21:06 -------- d-----w- c:\program files\Lavasoft
2010-05-11 18:37 . 2010-05-12 17:30 680 ----a-w- c:\users\dpadgett\AppData\Local\d3d9caps.dat
2010-05-11 15:01 . 2010-05-11 15:01 79160 ----a-w- c:\programdata\WebEx\WebEx\924\atinst.exe
2010-05-11 15:01 . 2010-05-11 15:01 75064 ----a-w- c:\programdata\WebEx\WebEx\924\atmccli.dll
2010-05-11 15:01 . 2010-05-11 15:01 173368 ----a-w- c:\programdata\WebEx\WebEx\924\atmgr.exe
2010-05-10 14:25 . 2010-05-10 14:25 -------- d-----w- c:\users\dpadgett\AppData\Roaming\Malwarebytes
2010-05-10 14:24 . 2010-04-29 19:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-10 14:24 . 2010-05-10 14:24 -------- d-----w- c:\programdata\Malwarebytes
2010-05-10 14:24 . 2010-04-29 19:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-05-10 14:24 . 2010-05-14 11:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-04-28 14:06 . 2010-04-28 14:06 -------- d-----w- c:\program files\iPod
2010-04-28 14:06 . 2010-04-28 14:08 -------- d-----w- c:\program files\iTunes
2010-04-28 13:56 . 2010-04-28 13:56 73000 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.1.1.11\SetupAdmin.exe
2010-04-21 13:09 . 2010-04-21 13:10 -------- d-----w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-04-21 13:03 . 2010-04-21 13:03 -------- d-----w- c:\program files\QuickTime
2010-04-21 12:08 . 2010-05-06 14:12 -------- d-----w- c:\program files\Bonjour
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-17 12:20 . 2008-10-23 20:56 -------- d-----w- c:\programdata\Microsoft Help
2010-05-17 00:51 . 2008-10-24 20:15 -------- d-----w- c:\program files\Trillian
2010-05-17 00:42 . 2008-10-23 20:48 0 ----a-w- c:\users\dpadgett\AppData\Local\WavXMapDrive.bat
2010-05-16 21:21 . 2008-10-24 19:47 -------- d-----w- c:\users\dpadgett\AppData\Roaming\Apple Computer
2010-05-14 13:08 . 2008-10-14 20:34 -------- d-----w- c:\program files\Java
2010-05-11 15:01 . 2009-01-06 19:05 239496 ----a-w- c:\programdata\WebEx\atgpcext.dll
2010-05-08 14:30 . 2008-10-14 21:02 -------- d-----w- c:\program files\Google
2010-05-07 18:53 . 2009-09-11 13:26 2828 --sha-w- c:\windows\system32\KGyGaAvL.sys
2010-05-07 18:53 . 2009-09-09 12:59 -------- d-----w- c:\users\dpadgett\AppData\Roaming\Corel
2010-05-07 18:52 . 2009-09-08 21:17 -------- d-----w- c:\programdata\Dl_cats
2010-05-07 18:52 . 2009-09-11 13:26 88 --sh--r- c:\windows\system32\A4C3588ABF.sys
2010-04-28 14:06 . 2008-10-24 19:41 -------- d-----w- c:\program files\Common Files\Apple
2010-04-22 19:11 . 2009-01-05 22:47 -------- d-----w- c:\users\dpadgett\AppData\Roaming\Webex
2010-04-21 16:34 . 2009-05-19 21:43 -------- d-----w- c:\program files\Quicken WillMaker Plus 2009
2010-04-16 17:53 . 2010-04-16 17:53 -------- d-----w- c:\programdata\Hewlett-Packard
2010-04-12 19:08 . 2009-01-06 19:05 62776 ----a-w- c:\programdata\WebEx\atinst.exe
2010-04-08 17:20 . 2010-04-08 17:20 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-04-08 17:20 . 2010-04-08 17:20 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-03-25 03:23 . 2010-03-25 03:22 -------- d-----w- c:\program files\Essentials Codec Pack
2010-03-25 03:16 . 2010-03-25 02:02 -------- d-----w- c:\users\dpadgett\AppData\Roaming\Sonarca Sound Recorder Free
2010-03-25 03:10 . 2010-03-25 03:10 -------- d-----w- c:\programdata\PC Drivers HeadQuarters
2010-03-25 01:55 . 2009-09-01 12:30 -------- d-----w- c:\program files\Yahoo!
2010-03-25 01:54 . 2009-09-01 12:30 -------- d-----w- c:\programdata\Yahoo!
2010-03-24 18:30 . 2010-03-24 18:30 49152 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\Components\nprpffbrowserrecordext.dll
2010-03-24 18:30 . 2010-03-24 18:30 45056 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimwmp.dll
2010-03-24 18:30 . 2010-03-24 18:30 45056 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimswf.dll
2010-03-24 18:30 . 2010-03-24 18:30 45056 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimrp.dll
2010-03-24 18:30 . 2010-03-24 18:30 45056 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimqt.dll
2010-03-24 18:30 . 2010-03-24 18:30 308808 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Common\rpmainbrowserrecordplugin.dll
2010-03-24 18:30 . 2010-03-24 18:30 14848 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
2010-03-24 18:30 . 2010-03-24 18:30 40960 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
2010-03-24 18:30 . 2010-03-24 18:30 341600 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
2010-03-24 18:30 . 2009-01-08 07:33 -------- d-----w- c:\program files\Common Files\Real
2010-03-24 18:29 . 2010-03-24 18:28 -------- d-----w- c:\program files\real
2010-03-24 18:29 . 2010-03-24 18:29 -------- d-----w- c:\program files\Common Files\xing shared
2010-03-24 18:25 . 2010-03-24 18:25 734728 ----a-w- c:\users\dpadgett\AppData\Roaming\Real\RealPlayer\setup\AU_setup13.exe
2010-03-24 18:17 . 2010-03-24 08:04 952768 ----a-w- c:\programdata\Adobe\Reader\9.3\ARM\21340\AdobeARM.exe
2010-03-24 18:17 . 2010-03-24 08:04 70584 ----a-w- c:\programdata\Adobe\Reader\9.3\ARM\21340\AdobeExtractFiles.dll
2010-03-24 18:17 . 2010-03-24 08:04 326056 ----a-w- c:\programdata\Adobe\Reader\9.3\ARM\21340\ReaderUpdater.exe
2010-03-24 18:17 . 2010-03-24 08:04 326056 ----a-w- c:\programdata\Adobe\Reader\9.3\ARM\21340\AcrobatUpdater.exe
2010-03-20 19:34 . 2010-03-20 19:33 20846064 ----a-w- c:\users\dpadgett\AppData\Roaming\Real\Update\setup3.10\rp\RealPlayerSPGold.exe
2010-03-20 19:33 . 2010-03-20 19:33 8405312 ----a-w- c:\users\dpadgett\AppData\Roaming\Real\Update\setup3.10\gtb\GOOGLE_TOOLBAR\GoogleToolbarInstaller.exe
2010-03-20 19:33 . 2010-03-20 19:33 149000 ----a-w- c:\users\dpadgett\AppData\Roaming\Real\Update\setup3.10\chr_helper\LaunchHelper.exe
2010-03-20 19:32 . 2010-03-20 19:32 10309448 ----a-w- c:\users\dpadgett\AppData\Roaming\Real\Update\setup3.10\chr\ChromeInstaller.exe
2010-03-20 19:32 . 2010-03-20 19:32 181768 ----a-w- c:\users\dpadgett\AppData\Roaming\Real\Update\setup3.10\carb\LaunchHelper.exe
2010-03-20 19:32 . 2010-03-20 19:32 283280 ----a-w- c:\users\dpadgett\AppData\Roaming\Real\Update\setup3.10\carb\CarboniteSetupLiteRealPreinstaller.exe
2010-03-20 19:32 . 2010-03-20 19:32 79368 ----a-w- c:\users\dpadgett\AppData\Roaming\Real\Update\setup3.10\RUP\vista.exe
2010-03-20 19:32 . 2010-03-20 19:32 64000 ----a-w- c:\users\dpadgett\AppData\Roaming\Real\Update\setup3.10\RUP\inst_config\gcapi_dll.dll
2010-03-20 19:32 . 2010-03-20 19:32 52288 ----a-w- c:\users\dpadgett\AppData\Roaming\Real\Update\setup3.10\RUP\inst_config\gtapi.dll
2010-03-20 19:32 . 2010-03-20 19:32 50688 ----a-w- c:\users\dpadgett\AppData\Roaming\Real\Update\setup3.10\RUP\inst_config\fftbapi.dll
2010-03-20 19:32 . 2010-03-20 19:32 49152 ----a-w- c:\users\dpadgett\AppData\Roaming\Real\Update\setup3.10\RUP\inst_config\CarboniteCompatibility.dll
2010-03-20 19:32 . 2010-03-20 19:32 118784 ----a-w- c:\users\dpadgett\AppData\Roaming\Real\Update\setup3.10\RUP\inst_config\compat.dll
2010-03-20 11:32 . 2010-03-20 11:32 439816 ----a-w- c:\users\dpadgett\AppData\Roaming\Real\Update\setup3.10\setup.exe
2010-03-12 05:31 . 2010-03-12 05:31 38 ----a-w- c:\users\dpadgett\AppData\Local\MvA2873.tmp
2010-03-11 03:09 . 2010-03-11 03:09 38 ----a-w- c:\users\dpadgett\AppData\Local\MvAB6D8.tmp
2010-03-10 04:39 . 2010-03-10 04:39 38 ----a-w- c:\users\dpadgett\AppData\Local\MvA5999.tmp
2010-03-05 15:58 . 2010-03-05 15:58 18432 ----a-w- c:\programdata\WebEx\WebEx\924\atconc.dll
2010-03-05 15:58 . 2010-03-05 15:58 122880 ----a-w- c:\programdata\WebEx\WebEx\924\flvstrm.dll
2010-03-05 15:58 . 2010-03-05 15:58 81408 ----a-w- c:\programdata\WebEx\WebEx\924\atjpeg60.dll
2010-03-05 15:58 . 2010-03-05 15:58 49152 ----a-w- c:\programdata\WebEx\WebEx\924\wbxtrace.dll
2010-03-05 15:58 . 2010-03-05 15:58 401462 ----a-w- c:\programdata\WebEx\WebEx\924\msvcp60.dll
2010-03-05 15:58 . 2010-03-05 15:58 254005 ----a-w- c:\programdata\WebEx\WebEx\924\msvcrt.dll
2010-03-05 15:58 . 2009-01-06 19:05 103736 ----a-w- c:\programdata\WebEx\atmgr.exe
2010-03-05 15:58 . 2009-01-06 19:05 46392 ----a-w- c:\programdata\WebEx\atmccli.dll
2010-03-05 15:58 . 2009-01-06 19:05 28472 ----a-w- c:\programdata\WebEx\atgpcdec.dll
2010-03-05 14:01 . 2010-04-15 12:33 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-02-23 11:10 . 2010-04-15 12:33 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-02-23 11:10 . 2010-04-15 12:33 79360 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-02-23 11:10 . 2010-04-15 12:33 106496 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-23 06:39 . 2010-04-11 22:50 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-23 06:33 . 2010-04-11 22:50 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-02-23 06:33 . 2010-04-11 22:50 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-02-23 04:55 . 2010-04-11 22:50 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-02-20 23:06 . 2010-03-10 04:36 24064 ----a-w- c:\windows\system32\nshhttp.dll
2010-02-20 23:05 . 2010-03-10 04:36 30720 ----a-w- c:\windows\system32\httpapi.dll
2010-02-20 20:53 . 2010-03-10 04:36 411648 ----a-w- c:\windows\system32\drivers\http.sys
2010-02-18 14:07 . 2010-04-15 12:32 904576 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-02-18 14:07 . 2010-04-15 12:33 3548040 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-18 14:07 . 2010-04-15 12:33 3600776 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-18 13:30 . 2010-04-15 12:31 200704 ----a-w- c:\windows\system32\iphlpsvc.dll
2010-02-18 11:28 . 2010-04-15 12:31 25088 ----a-w- c:\windows\system32\drivers\tunnel.sys
2009-12-12 17:25 . 2009-12-12 17:25 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2009-09-25 16:41 . 2009-09-25 16:41 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-09-25 16:41 . 2009-09-25 16:41 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2008-10-14 22:59 . 2008-10-14 22:58 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((( SnapShot@2010-05-17_00.25.53 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-05-17 12:16 . 2010-01-29 13:49 84480 c:\windows\winsxs\x86_microsoft-windows-mail-comm-dll_31bf3856ad364e35_6.0.6002.22325_none_7c10a4356edc41af\INETRES.dll
+ 2010-05-17 12:16 . 2010-01-29 13:56 84480 c:\windows\winsxs\x86_microsoft-windows-mail-comm-dll_31bf3856ad364e35_6.0.6001.22621_none_7a26312571b9872f\INETRES.dll
+ 2008-10-22 22:37 . 2010-05-17 20:31 49152 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-10-22 22:37 . 2010-05-16 01:51 49152 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-10-22 22:37 . 2010-05-17 20:31 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-10-22 22:37 . 2010-05-16 01:51 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-01-02 15:17 . 2010-05-17 00:37 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-01-02 15:17 . 2010-05-11 01:52 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-01-02 15:17 . 2010-05-17 00:37 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-01-02 15:17 . 2010-05-11 01:52 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-01-02 15:17 . 2010-05-11 01:52 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-01-02 15:17 . 2010-05-17 00:37 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-10-23 21:00 . 2010-04-15 12:53 35088 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\oisicon.exe
+ 2008-10-23 21:00 . 2010-05-17 12:20 35088 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\oisicon.exe
- 2008-10-23 21:00 . 2010-04-15 12:53 18704 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\mspicons.exe
+ 2008-10-23 21:00 . 2010-05-17 12:20 18704 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\mspicons.exe
+ 2008-10-23 21:00 . 2010-05-17 12:20 20240 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\cagicon.exe
- 2008-10-23 21:00 . 2010-04-15 12:53 20240 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\cagicon.exe
+ 2009-12-22 00:09 . 2009-12-22 00:09 16832 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\ViewerPS.dll
+ 2009-12-22 05:57 . 2009-12-22 05:57 35760 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\reader_sl.exe
+ 2009-12-22 00:02 . 2009-12-22 00:02 79280 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\PDFPrevHndlr.dll
+ 2009-12-22 03:21 . 2009-12-22 03:21 99776 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\eula.exe
+ 2009-12-22 03:37 . 2009-12-22 03:37 27048 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\acrotextextractor.exe
+ 2009-12-21 22:39 . 2009-12-21 22:39 15288 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\AcroRd32Info.exe
+ 2009-12-21 22:27 . 2009-12-21 22:27 75200 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\acroiehelpershim.dll
+ 2009-12-21 22:27 . 2009-12-21 22:27 61888 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\AcroIEHelper.dll
+ 2010-05-17 14:10 . 2010-05-17 14:10 32768 c:\windows\Downloaded Program Files\WebEx\924\ptexmeet.dll
+ 2010-05-17 14:10 . 2010-05-06 15:18 74309 c:\windows\Downloaded Program Files\ptIEGpc.dll
+ 2010-05-17 14:10 . 2010-05-06 15:18 92228 c:\windows\Downloaded Program Files\ptgpcext.dll
+ 2010-05-17 14:10 . 2010-05-06 15:18 18432 c:\windows\Downloaded Program Files\ptgpcdec.dll
+ 2010-05-17 14:10 . 2010-05-17 14:10 28472 c:\windows\Downloaded Program Files\atgpcdec.dll
- 2010-05-17 00:07 . 2010-05-17 00:07 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2010-05-17 00:37 . 2010-05-17 00:37 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2010-05-17 00:07 . 2010-05-17 00:07 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-05-17 00:37 . 2010-05-17 00:37 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2010-05-17 12:16 . 2010-01-29 16:07 738816 c:\windows\winsxs\x86_microsoft-windows-mail-comm-dll_31bf3856ad364e35_6.0.6002.22325_none_7c10a4356edc41af\inetcomm.dll
+ 2010-05-17 12:16 . 2010-01-29 15:40 738816 c:\windows\winsxs\x86_microsoft-windows-mail-comm-dll_31bf3856ad364e35_6.0.6002.18197_none_7b3d56a455f59b03\inetcomm.dll
+ 2010-05-17 12:16 . 2010-01-29 16:08 738304 c:\windows\winsxs\x86_microsoft-windows-mail-comm-dll_31bf3856ad364e35_6.0.6001.22621_none_7a26312571b9872f\inetcomm.dll
+ 2010-05-17 12:16 . 2010-01-29 16:21 738304 c:\windows\winsxs\x86_microsoft-windows-mail-comm-dll_31bf3856ad364e35_6.0.6001.18416_none_79ac63d2588f4d00\inetcomm.dll
+ 2010-05-14 14:00 . 2010-05-17 20:31 425984 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-05-14 14:00 . 2010-05-16 01:51 425984 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-10-23 21:00 . 2010-05-17 12:20 888080 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\wordicon.exe
- 2008-10-23 21:00 . 2010-04-15 12:53 888080 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\wordicon.exe
+ 2008-10-23 21:00 . 2010-05-17 12:20 272648 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\pubs.exe
- 2008-10-23 21:00 . 2010-04-15 12:53 272648 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\pubs.exe
- 2008-10-23 21:00 . 2010-04-15 12:53 922384 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\pptico.exe
+ 2008-10-23 21:00 . 2010-05-17 12:20 922384 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\pptico.exe
+ 2008-10-23 21:00 . 2010-05-17 12:20 845584 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\outicon.exe
- 2008-10-23 21:00 . 2010-04-15 12:53 845584 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\outicon.exe
+ 2008-10-23 21:00 . 2010-05-17 12:20 217864 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\misc.exe
- 2008-10-23 21:00 . 2010-04-15 12:53 217864 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\misc.exe
+ 2008-10-23 21:00 . 2010-05-17 12:20 159504 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\inficon.exe
- 2008-10-23 21:00 . 2010-04-15 12:53 159504 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\inficon.exe
+ 2009-12-21 22:35 . 2009-12-21 22:35 378264 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\pdfshell.dll
+ 2009-12-21 22:34 . 2009-12-21 22:34 103864 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\nppdf32.dll
+ 2009-11-09 23:18 . 2009-11-09 23:18 684032 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\JP2KLib.dll
+ 2009-12-22 00:02 . 2009-12-22 00:02 542168 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\AdobeCollabSync.exe
+ 2009-12-21 22:43 . 2009-12-21 22:43 120240 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\AcroRdIF.dll
+ 2009-12-22 05:57 . 2009-12-22 05:57 349616 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\AcroRd32.exe
+ 2009-12-21 22:15 . 2009-12-21 22:15 660912 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\AcroPDF.dll
+ 2009-12-21 23:32 . 2009-12-21 23:32 280024 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\acrobroker.exe
+ 2009-12-21 23:15 . 2009-12-21 23:15 251296 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\a3dutility.exe
+ 2010-05-17 14:10 . 2010-05-17 14:10 561152 c:\windows\Downloaded Program Files\WebEx\924\mvc.dll
+ 2010-05-17 14:10 . 2010-05-17 14:10 630784 c:\windows\Downloaded Program Files\WebEx\924\mutiltpd.dll
+ 2010-05-17 14:10 . 2010-05-17 14:10 548864 c:\windows\Downloaded Program Files\WebEx\924\mmssl32.dll
+ 2010-05-17 14:10 . 2010-05-17 14:10 458752 c:\windows\Downloaded Program Files\WebEx\924\atwbxui7.dll
+ 2010-05-17 14:10 . 2010-05-17 14:10 376832 c:\windows\Downloaded Program Files\WebEx\924\atpollk2.dll
+ 2010-05-17 14:10 . 2010-05-17 14:10 173368 c:\windows\Downloaded Program Files\WebEx\924\atmgr.exe
+ 2010-05-17 14:10 . 2010-05-17 14:10 396168 c:\windows\Downloaded Program Files\WebEx\924\atasctrl.dll
+ 2010-05-17 14:10 . 2010-05-17 14:10 239496 c:\windows\Downloaded Program Files\atgpcext.dll
+ 2010-05-17 12:16 . 2010-01-29 13:49 2836992 c:\windows\winsxs\x86_microsoft-windows-mail-core-dll_31bf3856ad364e35_6.0.6002.22325_none_5ade3b513b99bff2\MSOERES.dll
+ 2010-05-17 12:16 . 2010-01-29 16:08 1616384 c:\windows\winsxs\x86_microsoft-windows-mail-core-dll_31bf3856ad364e35_6.0.6002.22325_none_5ade3b513b99bff2\msoe.dll
+ 2010-05-17 12:16 . 2010-01-29 15:40 1616384 c:\windows\winsxs\x86_microsoft-windows-mail-core-dll_31bf3856ad364e35_6.0.6002.18197_none_5a0aedc022b31946\msoe.dll
+ 2010-05-17 12:16 . 2010-01-29 13:57 2836992 c:\windows\winsxs\x86_microsoft-windows-mail-core-dll_31bf3856ad364e35_6.0.6001.22621_none_58f3c8413e770572\MSOERES.dll
+ 2010-05-17 12:16 . 2010-01-29 16:09 1616384 c:\windows\winsxs\x86_microsoft-windows-mail-core-dll_31bf3856ad364e35_6.0.6001.22621_none_58f3c8413e770572\msoe.dll
+ 2010-05-17 12:16 . 2010-01-29 16:22 1616384 c:\windows\winsxs\x86_microsoft-windows-mail-core-dll_31bf3856ad364e35_6.0.6001.18416_none_5879faee254ccb43\msoe.dll
+ 2009-10-16 11:08 . 2009-10-16 11:08 2237952 c:\windows\Installer\282828d.msp
+ 2010-04-09 19:21 . 2010-04-09 19:21 5025792 c:\windows\Installer\2828278.msp
- 2008-10-23 21:00 . 2010-04-15 12:53 1172240 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\xlicons.exe
+ 2008-10-23 21:00 . 2010-05-17 12:20 1172240 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\xlicons.exe
+ 2008-10-23 21:00 . 2010-05-17 12:20 1165584 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\accicons.exe
- 2008-10-23 21:00 . 2010-04-15 12:53 1165584 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\accicons.exe
+ 2009-12-21 22:29 . 2009-12-21 22:29 2409880 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\rt3d.dll
+ 2009-10-28 00:34 . 2009-10-28 00:34 5009408 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\authplay.dll
+ 2009-12-22 03:31 . 2009-12-22 03:31 5713920 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\AGM.dll
+ 2008-08-26 02:50 . 2008-08-26 02:50 2585592 c:\windows\Installer\$PatchCache$\Managed\00002109110000000000000000F01FEC\12.0.6425\VBE6.DLL
+ 2010-05-17 22:19 . 2010-05-17 22:19 6430720 c:\windows\ERDNT\Hiv-backup\SCHEMA.DAT
+ 2010-05-17 14:10 . 2010-05-17 14:10 2315576 c:\windows\Downloaded Program Files\WebEx\924\webexmgr.dll
+ 2010-05-17 14:10 . 2010-05-17 14:10 3043328 c:\windows\Downloaded Program Files\WebEx\924\atres.dll
+ 2010-05-17 14:10 . 2010-05-17 14:10 2084864 c:\windows\Downloaded Program Files\WebEx\924\atpdmod.dll
+ 2010-04-04 06:54 . 2010-04-04 06:54 11850240 c:\windows\Installer\4a0f9bb.msp
+ 2009-12-22 03:21 . 2009-12-22 03:21 20436408 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B7449A0300000010\9.3.0\AcroRd32.dll
+ 2009-12-07 01:10 . 2010-05-17 12:12 188175966 c:\windows\winsxs\ManifestCache\6.0.6002.18005_001c11ba_blobs.bin
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PTIM.exe"="c:\program files\WebEx\Productivity Tools\PTIM.exe" [2010-05-06 275768]
"PTOneClick"="c:\program files\WebEx\Productivity Tools\ptoneclk.exe" [2010-05-06 247096]
"Desktop Software"="c:\program files\Common Files\SupportSoft\bin\bcont.exe" [2009-04-24 1025320]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2007-01-26 159744]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-04-23 138008]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-04-23 154392]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-04-23 133912]
"WavXMgr"="c:\program files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe" [2007-09-10 85504]
"SecureUpgrade"="c:\program files\Wave Systems Corp\SecureUpgrade.exe" [2007-09-14 218424]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-12-12 30192]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-02-26 128296]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-08-14 115560]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2008-01-21 215552]
"dldomon.exe"="c:\program files\Dell 968 AIO Printer\dldomon.exe" [2007-10-05 455920]
"MemoryCardManager"="c:\program files\Dell 968 AIO Printer\memcard.exe" [2007-10-05 410864]
"Dell 968 AIO Printer Fax Server"="c:\program files\Dell 968 AIO Printer\fm3032.exe" [2007-10-05 312560]
"Sprint SmartView"="c:\program files\Sprint\Sprint SmartView\SprintSV.exe" [2009-12-02 75072]
"RDVCHG"="c:\program files\Sprint\Sprint SmartView\RDVCHG.exe" [2009-12-02 316736]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2008-01-03 405504]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-03-24 202256]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-24 142120]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"Corel Photo Downloader"="c:\program files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe" [2007-03-21 478800]
c:\users\dpadgett\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Trillian.lnk - c:\program files\Trillian\trillian.exe [2010-2-10 1930592]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-10-14 50688]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-12-29 813584]
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-2-22 1193240]
SonicWALL Global VPN Client.lnk - c:\program files\SonicWALL\SonicWALL Global VPN Client\SWGVpnClient.exe [2009-1-27 1160464]
VPN Client.lnk - c:\windows\Installer\{14FCFE7C-AB86-428A-9D2E-BFB6F5A7AA6E}\Icon3E5562ED7.ico [2008-10-24 6144]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gemsafe]
2006-11-16 20:20 73728 ----a-w- c:\program files\Gemplus\GemSafe Libraries\BIN\WLEventNotify.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 wvauth
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):d6,86,29,f5,e1,87,ca,01
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-05-03 136176]
R3 bcm;WiMAX Network Adapter;c:\windows\system32\DRIVERS\drxvi314.sys [2009-09-03 280576]
R3 bcmbusctr;WiMAX Bus Driver;c:\windows\system32\DRIVERS\BcmBusCtr.sys [2009-09-03 51456]
R3 CASprint;Sprint Con App Svc;c:\program files\Sprint\Sprint SmartView\ConAppsSvc.exe [2009-12-02 124224]
R3 cm_ser;C-motech USB Serial Port2 Driver;c:\windows\system32\DRIVERS\cm_ser.sys [2008-05-29 103680]
R3 COH_Mon;COH_Mon;c:\windows\system32\Drivers\COH_Mon.sys [2008-07-30 23888]
R3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2009-12-12 30192]
R4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2005-09-23 2799808]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2010-02-04 64288]
S1 RCFOX;SonicWALL IPsec Driver;c:\windows\system32\Drivers\RCFOX.sys [2007-09-27 101528]
S2 ASFIPmon;Broadcom ASF IP and SMBIOS Mailbox Monitor;c:\program files\Broadcom\ASFIPMon\AsfIpMon.exe [2006-12-19 79432]
S2 atashost;WebEx Service Host for Support Center;c:\windows\system32\atashost.exe [2009-01-06 20376]
S2 dldo_device;dldo_device;c:\windows\system32\dldocoms.exe [2007-10-05 595184]
S2 dldoCATSCustConnectService;dldoCATSCustConnectService;c:\windows\system32\spool\DRIVERS\W32X86\3\\dldoserv.exe [2007-10-05 99568]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-05-11 1291544]
S2 Wave UCSPlus;Wave UCSPlus;c:\windows\system32\dllhost.exe [2006-11-02 7168]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\b57nd60x.sys [2007-03-13 179712]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-08-27 102448]
S3 rcvpn;SonicWALL VPN Adapter;c:\windows\system32\DRIVERS\rcvpn.sys [2005-11-08 24876]
--- Other Services/Drivers In Memory ---
*Deregistered* - BMLoad
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
2010-05-17 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 21:10]
2010-05-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-03 14:22]
2010-05-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-03 14:22]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
LSP: bmnet.dll
DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://twcms.twcable.com/dana-cached/sc/JuniperSetupClient.cab
FF - ProfilePath - c:\users\dpadgett\AppData\Roaming\Mozilla\Firefox\Profiles\v72z7z5q.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - component: c:\program files\WebEx\Productivity Tools\components\ocff.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\programdata\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: c:\users\dpadgett\AppData\Roaming\Move Networks\plugins\npqmp071701000002.dll
FF - plugin: c:\users\dpadgett\AppData\Roaming\Move Networks\plugins\npqmp071705000014.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - ORPHANS REMOVED - - - -
SharedTaskScheduler-{E0F516C1-E05F-4C83-8842-0304D28E50EB} - c:\windows\system32\rhhetero.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-05-17 18:34
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\msftesql]
"ImagePath"="\"c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe\" -s:MSSQL.1 -f:MSSQLSERVER"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(680)
c:\windows\system32\wvauth.dll
c:\windows\system32\biolsp.dll
c:\windows\system32\bmnet.dll
- - - - - - - > 'Explorer.exe'(6328)
c:\program files\Logitech\SetPoint\lgscroll.dll
.
Completion time: 2010-05-17 18:40:14
ComboFix-quarantined-files.txt 2010-05-17 22:40
ComboFix2.txt 2010-05-17 00:30
Pre-Run: 41,734,459,392 bytes free
Post-Run: 41,708,998,656 bytes free
- - End Of File - - 9B572B10853EFFF13AC56E7E41827D9B