ComboFix 10-01-04.01 - Stacey Brown 01/06/2010 13:31:33.2.2 - x86
Microsoft
Windows Vista
Home Premium 6.0.6002.2.1252.1.1033.18.3061.1421 [GMT -7:00]
Running from: c:\users\Stacey Brown\Desktop\ComboFix.exe
Command switches used :: c:\users\Stacey Brown\CFScript.txt
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_SessionLauncher
((((((((((((((((((((((((( Files Created from 2009-12-06 to 2010-01-06 )))))))))))))))))))))))))))))))
.
2010-01-06 20:37 . 2010-01-06 20:37 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-01-05 16:37 . 2010-01-05 16:37 -------- d-----w- c:\users\Stacey Brown\AppData\Roaming\Malwarebytes
2010-01-05 16:37 . 2009-12-30 21:55 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-05 16:37 . 2010-01-05 16:37 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-05 16:37 . 2009-12-30 21:54 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-14 15:06 . 2009-11-09 12:31 24064 ----a-w- c:\windows\system32\nshhttp.dll
2009-12-14 15:06 . 2009-11-09 12:30 30720 ----a-w- c:\windows\system32\httpapi.dll
2009-12-14 15:06 . 2009-11-09 10:36 411648 ----a-w- c:\windows\system32\drivers\http.sys
2009-12-13 23:19 . 2009-10-07 11:36 243712 ----a-w- c:\windows\system32\rastls.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-06 20:42 . 2009-05-02 19:19 -------- d-----w- c:\users\Stacey Brown\AppData\Roaming\skypePM
2010-01-06 20:41 . 2009-05-02 19:17 -------- d-----w- c:\users\Stacey Brown\AppData\Roaming\Skype
2010-01-06 20:38 . 2009-01-08 16:48 12 ----a-w- c:\windows\bthservsdp.dat
2010-01-05 00:42 . 2008-05-11 21:35 -------- d-----w- c:\program files\Google
2010-01-04 23:54 . 2009-10-08 14:53 -------- d-----w- c:\program files\Windows Live
2010-01-04 23:53 . 2009-09-23 20:57 -------- d-----w- c:\program files\NCH Swift Sound
2010-01-04 23:51 . 2009-02-04 17:02 -------- d-----w- c:\program files\Lavasoft
2010-01-03 00:00 . 2008-05-26 14:17 -------- d-----w- c:\program files\Intuit
2009-12-30 16:00 . 2008-05-11 21:41 -------- d-----w- c:\program files\Common Files\Roxio Shared
2009-12-30 16:00 . 2008-05-11 21:41 -------- d-----w- c:\program files\Roxio
2009-12-30 16:00 . 2008-05-11 21:42 -------- d-----w- c:\program files\Common Files\Sonic Shared
2009-12-30 16:00 . 2008-05-11 21:42 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2009-12-14 15:21 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-12-02 20:48 . 2008-05-27 15:34 -------- d-----w- c:\users\Stacey Brown\AppData\Roaming\Move Networks
2009-12-01 20:24 . 2009-05-07 23:52 127325 ----a-w- c:\users\Stacey Brown\AppData\Roaming\Move Networks\uninstall.exe
2009-12-01 20:24 . 2009-08-13 19:21 4187512 ----a-w- c:\users\Stacey Brown\AppData\Roaming\Move Networks\plugins\npqmp071505000011.dll
2009-11-30 16:37 . 2008-05-17 15:27 -------- d-----w- c:\program files\AVG
2009-11-30 16:03 . 2009-09-23 20:58 -------- d-----w- c:\users\Stacey Brown\AppData\Roaming\NCH Swift Sound
2009-11-30 01:41 . 2009-11-08 17:10 -------- d-----w- c:\program files\Escape The Museum
2009-11-30 00:27 . 2009-01-21 02:40 256 ----a-w- c:\windows\system32\pool.bin
2009-11-21 14:57 . 2008-05-18 23:25 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-11-21 06:40 . 2009-12-13 23:20 916480 ----a-w- c:\windows\system32\wininet.dll
2009-11-21 06:34 . 2009-12-13 23:20 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-11-21 06:34 . 2009-12-13 23:20 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-11-21 04:59 . 2009-12-13 23:20 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-11-18 14:36 . 2009-11-18 14:36 -------- d-----w- c:\program files\Windows Portable Devices
2009-11-18 14:36 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-11-18 14:28 . 2009-11-18 14:28 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2009-11-18 14:26 . 2009-11-18 14:26 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-11 12:23 . 2009-05-02 19:16 -------- d-----r- c:\program files\Skype
2009-11-11 12:23 . 2009-11-11 12:23 -------- d-----w- c:\program files\Common Files\Skype
2009-11-11 11:22 . 2009-11-11 11:22 104512 ----a-w- c:\windows\system32\drivers\AnyDVD.sys
2009-11-03 03:42 . 2009-10-03 14:33 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-11-01 15:36 . 2009-11-01 15:36 175756 ---ha-w- c:\windows\system32\mlfcache.dat
2009-10-29 09:17 . 2009-11-27 14:29 2048 ----a-w- c:\windows\system32\tzres.dll
2009-10-08 21:08 . 2009-11-18 03:42 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2009-10-08 21:08 . 2009-11-18 03:42 234496 ----a-w- c:\windows\system32\oleacc.dll
2009-10-08 21:07 . 2009-11-18 03:42 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2008-05-12 05:02 . 2008-05-12 04:47 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-11 68856]
"AnyDVD"="c:\program files\SlySoft\AnyDVD\AnyDVDtray.exe" [2009-11-11 3124160]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2008-10-24 206112]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2008-02-29 17920]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-01-25 167936]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-03-06 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-03-06 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-03-06 133656]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-21 1548288]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-03-21 174872]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-05-11 29744]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2008-11-06 184320]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-11-12 405504]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdcBase.exe" [2007-05-31 648072]