Jump to content

Malwarebytes

Help remove kwave.sys and mrxdavv.sys

- - - - -

24 replies to this topic

#1
Fletch55

    New Member

  • Members
  • Pip
  • 18 posts
Ok I had some bugs get into my drive. I had windows antivirus pro and a few others and got them gone but I still get kwave.sys (Trojan.Agent) and mrxdavv.sys(Rootkit.Agent.H) everytime I run MBAM even though it says it will delet upon restart. Ok I have run the MBAM and I ran smitfraud which got the windows antivirus pro out and then I ran combofix which said it got an active rootkit removed and a ton of other stuff.Lot of my images were removed by combofix for some reason must have gotten infected.. Anywas sdo I am here looking for some help getting these lat 2 problems removed. Here are my most recent logs from MBAM,Combofix, and Hijack this in the same order below. I thank you for any help in advance you may have to offer....

Malwarebytes' Anti-Malware 1.39
Database version: 2421
Windows 6.0.6002 Service Pack 2

8/21/2009 11:25:30
mbam-log-2009-08-21 (11-25-30).txt

Scan type: Quick Scan
Objects scanned: 86186
Time elapsed: 12 minute(s), 16 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Windows\system32\drivers\mrxdavv.sys (Rootkit.Agent.H) -> Delete on reboot.
C:\Windows\system32\kwave.sys (Trojan.Agent) -> Delete on reboot.
________________________________________________________________________________
________________________________________________________________
Combofix log
I may have to run this again as I can not remember where thew log was saved by combofix.I will keep looking if anyone knows default place it saves let me know or if need I'll run again
________________________________________________________________________________
________________________________________________________________


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:06:00, on 8/21/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Sony\AppMonUtil\AppMonUtility.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe
C:\Program Files\AOL 9.5\waol.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\Program Files\AOL 9.5\shellmon.exe
C:\Program Files\Common Files\AOL\1241668092\ee\aolsoftware.exe
C:\Program Files\Common Files\AOL\Topspeed\3.0\aoltpsd3.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [AppMon Utility] "C:\Program Files\Sony\AppMonUtil\AppMonUtility.exe" @@@Start
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-18\..\Run: [minix32] C:\Windows\system32\minix32.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [minix32] C:\Windows\system32\minix32.exe (User 'Default user')
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: CopySafe Helper Service (CSHelper) - Unknown owner - C:\Windows\system32\CSHelper.exe
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - FirebirdSQL Project - C:\Program Files\Firebird\Firebird_2_1\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - FirebirdSQL Project - C:\Program Files\Firebird\Firebird_2_1\bin\fbserver.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 7139 bytes

#2
Fletch55

    New Member

  • Members
  • Pip
  • 18 posts
Ok here is the combofix log file....

ComboFix 09-08-20.07 - Ownwer 08/21/2009 13:25.2.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2045.1194 [GMT -5:00]
Running from: c:\users\Ownwer\Downloads\ComboFix.exe
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_kbiwkmtrcipqxj
-------\Service_kbiwkmtrcipqxj


((((((((((((((((((((((((( Files Created from 2009-07-21 to 2009-08-21 )))))))))))))))))))))))))))))))
.

2009-08-21 18:32 . 2009-08-21 18:32 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-08-21 18:32 . 2009-08-21 18:32 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-08-21 18:32 . 2009-08-21 18:32 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2009-08-21 18:05 . 2009-08-21 18:05 -------- d-----w- c:\program files\Trend Micro
2009-08-21 17:49 . 2009-08-21 17:49 -------- d-----w- c:\users\Ownwer\AppData\Local\Apple
2009-08-21 17:09 . 2009-08-21 18:34 -------- d-----w- c:\users\Ownwer\AppData\Local\temp
2009-08-21 15:43 . 2009-08-21 15:43 35 ----a-w- c:\users\Ownwer\AppData\Roaming\SetValue.bat
2009-08-21 14:53 . 2009-08-21 14:53 585736 ----a-w- c:\windows\system32\minix32.exe
2009-08-21 13:46 . 2009-08-21 13:46 16 ----a-w- c:\windows\pxydb.dat
2009-08-21 13:46 . 2009-08-21 13:46 8432 ----a-w- c:\windows\system32\drivers\nwlnkfwd.sys
2009-08-21 13:46 . 2009-08-21 13:46 8432 ----a-w- c:\windows\system32\drivers\nwlnkflt.sys
2009-08-21 13:46 . 2009-08-21 13:46 8432 ----a-w- c:\windows\system32\drivers\ipinip.sys
2009-08-21 13:46 . 2009-08-21 13:46 8432 ----a-w- c:\windows\system32\drivers\blbdrive.sys
2009-08-21 13:46 . 2009-08-21 13:46 8432 ----a-w- c:\windows\system32\rgadta.sys
2009-08-20 22:22 . 2009-06-15 14:54 175104 ----a-w- c:\windows\system32\wdigest.dll
2009-08-20 22:22 . 2009-06-15 14:53 270848 ----a-w- c:\windows\system32\schannel.dll
2009-08-20 22:22 . 2009-06-15 14:53 218624 ----a-w- c:\windows\system32\msv1_0.dll
2009-08-20 22:22 . 2009-06-15 14:52 499712 ----a-w- c:\windows\system32\kerberos.dll
2009-08-20 22:22 . 2009-06-15 23:15 439864 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-08-20 22:22 . 2009-06-15 14:53 72704 ----a-w- c:\windows\system32\secur32.dll
2009-08-20 22:22 . 2009-06-15 14:52 1259008 ----a-w- c:\windows\system32\lsasrv.dll
2009-08-20 22:22 . 2009-06-15 12:48 9728 ----a-w- c:\windows\system32\lsass.exe
2009-08-20 20:32 . 2009-08-20 20:32 -------- d-----w- c:\program files\Brice Lambson
2009-08-20 17:33 . 2009-08-20 17:33 -------- d-----w- c:\users\Ownwer\AppData\Roaming\Nero
2009-08-20 17:12 . 2009-08-20 17:19 -------- d-----w- c:\program files\Nero
2009-08-20 17:12 . 2009-08-20 17:20 -------- d-----w- c:\program files\Common Files\Nero
2009-08-20 17:12 . 2009-08-20 17:14 -------- d-----w- c:\progra~2\Nero
2009-08-20 14:17 . 2009-08-20 14:18 -------- d-----w- c:\users\Ownwer\AppData\Local\AOL
2009-08-20 05:58 . 2009-08-20 05:58 -------- d-----w- c:\users\Ownwer\AppData\Local\Adobe
2009-08-17 14:11 . 2009-08-17 14:11 -------- d-----w- c:\program files\Linksys
2009-08-17 14:10 . 2009-08-17 14:10 -------- d-----w- c:\windows\{7F7635FC-B887-49FA-8526-094724C01A6E}
2009-08-12 22:14 . 2009-07-17 13:54 71680 ----a-w- c:\windows\system32\atl.dll
2009-08-12 22:14 . 2009-06-10 11:42 160256 ----a-w- c:\windows\system32\wkssvc.dll
2009-08-12 22:14 . 2009-06-04 12:07 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-08-12 22:14 . 2009-06-10 11:38 91136 ----a-w- c:\windows\system32\avifil32.dll
2009-08-12 22:14 . 2009-07-15 12:39 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-08-12 22:14 . 2009-07-15 12:39 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-08-12 22:14 . 2009-07-15 12:39 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-08-12 22:14 . 2009-07-15 12:40 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-08-12 14:41 . 2009-08-13 13:35 -------- d-----w- c:\program files\AOL 9.5
2009-08-11 22:13 . 2009-08-11 22:13 -------- d-----w- c:\program files\PFPortChecker
2009-08-07 21:54 . 2008-08-13 02:08 16896 ----a-w- c:\windows\system32\drivers\VirtualAudio.sys
2009-08-07 21:54 . 2009-08-07 21:54 -------- d-----w- c:\program files\Daniusoft
2009-08-07 18:41 . 2009-08-07 18:41 -------- d-----w- c:\users\Ownwer\AppData\Roaming\TigerPlayer
2009-08-07 18:40 . 2009-08-07 18:40 -------- d-----w- c:\program files\MpcStar
2009-08-06 23:09 . 2009-08-06 23:12 -------- d-----w- c:\users\Ownwer\AppData\Roaming\DivX
2009-08-06 23:06 . 2009-08-06 23:06 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2009-08-06 23:05 . 2009-08-06 23:06 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-08-06 23:05 . 2009-08-06 23:07 -------- d-----w- c:\program files\DivX
2009-08-06 15:34 . 2009-08-06 15:47 -------- d-----w- c:\program files\AOL 9.5h
2009-08-04 22:30 . 2009-08-04 22:30 266240 ----a-w- c:\windows\system32\CSHelper.exe
2009-08-04 22:30 . 2009-08-04 22:30 225280 ----a-w- c:\windows\system32\CSInstru.DLL
2009-08-03 23:12 . 2009-08-03 23:12 -------- d-----w- c:\program files\SpacialAudio
2009-08-03 23:12 . 2007-10-16 15:07 442368 ----a-w- c:\windows\system32\GDS32.DLL
2009-08-03 23:12 . 2005-09-23 05:05 626688 ----a-w- c:\windows\system32\msvcr80.dll
2009-08-03 23:12 . 2005-09-23 05:05 548864 ----a-w- c:\windows\system32\msvcp80.dll
2009-08-03 23:12 . 2009-08-03 23:12 -------- d-----w- c:\program files\Firebird
2009-07-27 14:29 . 2009-07-25 10:23 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-23 20:01 . 2009-07-23 20:01 -------- d-----w- c:\program files\Common Files\Software Update Utility
2009-07-23 20:00 . 2009-07-24 14:06 -------- d-----w- c:\program files\AOL 9.5g

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-21 15:54 . 2009-05-12 00:44 -------- d-----w- c:\program files\Media Resizer PRO
2009-08-21 15:43 . 2009-08-21 15:43 691 ----a-w- c:\users\Ownwer\AppData\Roaming\GetValue.vbs
2009-08-20 22:17 . 2009-05-07 00:48 -------- d-----w- c:\program files\BitComet
2009-08-20 21:13 . 2009-05-13 18:21 -------- d-----w- c:\users\Ownwer\AppData\Roaming\Corel
2009-08-17 14:11 . 2007-01-09 20:14 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-14 14:43 . 2009-07-08 22:30 -------- d-----w- c:\program files\HP
2009-08-12 14:43 . 2009-05-07 03:51 -------- d-----w- c:\users\Ownwer\AppData\Roaming\AOL
2009-08-12 14:41 . 2007-10-02 05:03 -------- d-----w- c:\program files\Common Files\AOL
2009-08-12 14:41 . 2009-05-07 03:48 -------- d-----w- c:\program files\Common Files\aolshare
2009-08-12 14:41 . 2009-05-07 03:48 -------- d-----w- c:\progra~2\AOL
2009-08-12 14:40 . 2009-05-07 00:39 -------- d-----w- c:\progra~2\AOL Downloads
2009-08-10 02:44 . 2009-07-02 05:35 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-08-10 02:44 . 2009-07-02 05:35 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-08-07 18:40 . 2009-06-05 17:54 -------- d-----w- c:\program files\QuickTime
2009-08-07 18:40 . 2009-06-05 17:54 -------- d-----w- c:\progra~2\Apple Computer
2009-08-05 13:56 . 2007-01-09 19:39 -------- d-----w- c:\program files\Java
2009-07-27 14:27 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-07-23 19:44 . 2009-05-20 16:33 54832 ----a-w- c:\windows\system32\AOLParconLink.exe
2009-07-22 16:32 . 2009-07-08 23:11 -------- d-----w- c:\users\Ownwer\AppData\Roaming\HP
2009-07-22 15:10 . 2009-05-11 14:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-21 21:52 . 2009-07-29 14:11 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-07-29 14:11 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-07-29 14:11 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-07-29 14:11 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-17 20:20 . 2009-07-14 15:59 9264 ----a-w- c:\windows\system32\msqtvcap.dat
2009-07-16 18:56 . 2009-05-07 00:55 205128 ----a-w- c:\users\Ownwer\AppData\Local\GDIPFONTCACHEV1.DAT
2009-07-16 18:53 . 2009-07-16 18:53 -------- d-----w- c:\program files\Sling Media
2009-07-16 18:53 . 2009-07-16 18:53 -------- d-----w- c:\progra~2\Sling Media
2009-07-15 21:53 . 2009-07-15 21:53 -------- d-----w- c:\users\Ownwer\AppData\Roaming\Plazmic
2009-07-15 21:53 . 2009-07-15 21:51 -------- d--h--w- c:\program files\Zero G Registry
2009-07-15 21:53 . 2009-07-15 21:51 -------- d-----w- c:\program files\Plazmic CDK 4.7
2009-07-14 15:58 . 2009-07-14 15:58 -------- d-----w- c:\program files\Alibaba
2009-07-13 18:36 . 2009-05-11 14:21 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-13 18:36 . 2009-05-11 14:21 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-09 23:01 . 2009-05-08 03:31 -------- d-----w- c:\users\Ownwer\AppData\Roaming\VSO
2009-07-09 23:00 . 2009-07-09 14:34 256 ----a-w- c:\windows\system32\pool.bin
2009-07-09 15:37 . 2009-07-09 14:20 -------- d-----w- c:\program files\Common Files\Research In Motion
2009-07-09 14:34 . 2009-07-09 14:34 -------- d-----w- c:\users\Ownwer\AppData\Roaming\Research In Motion
2009-07-09 14:29 . 2009-06-16 00:24 -------- d-----w- c:\progra~2\Roxio
2009-07-09 14:29 . 2007-10-02 05:49 -------- d-----w- c:\program files\Common Files\Roxio Shared
2009-07-09 14:29 . 2007-01-09 20:14 -------- d-----w- c:\program files\Common Files\InstallShield
2009-07-09 14:20 . 2009-07-09 14:20 -------- d-----w- c:\program files\Research In Motion
2009-07-08 23:12 . 2009-07-08 23:12 -------- d-----w- c:\progra~2\WEBREG
2009-07-08 23:11 . 2009-07-08 22:57 184137 ----a-w- c:\windows\hpwins22.dat
2009-07-08 23:10 . 2009-07-08 22:27 -------- d-----w- c:\progra~2\HP
2009-07-08 23:09 . 2009-07-08 23:09 -------- d-----w- c:\progra~2\HP Product Assistant
2009-07-08 23:00 . 2009-07-08 23:00 -------- d-----w- c:\program files\Common Files\HP
2009-07-08 23:00 . 2009-07-08 23:00 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2009-07-08 23:00 . 2009-07-08 23:00 -------- d-----w- c:\program files\Hewlett-Packard
2009-06-30 22:07 . 2009-05-11 14:25 117760 ----a-w- c:\users\Ownwer\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-06-29 18:08 . 2009-05-07 17:29 -------- d-----w- c:\users\Ownwer\AppData\Roaming\AntsSoft
2009-06-29 18:07 . 2009-06-29 18:07 -------- d-----w- c:\program files\UltraButton
2009-06-29 17:44 . 2009-06-29 17:43 -------- d-----w- c:\program files\Amara - Photo Animation Software
2009-06-29 17:33 . 2009-06-29 17:33 -------- d-----w- c:\program files\Mix-FX
2009-06-25 18:37 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-06-25 18:37 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2009-06-25 18:37 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2009-06-25 18:36 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2009-06-25 18:36 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2009-06-25 18:36 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2009-06-25 18:36 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-06-24 16:51 . 2009-05-07 17:28 -------- d-----w- c:\program files\SWFText
2009-06-24 16:02 . 2009-06-24 16:51 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-06-24 16:02 . 2009-06-24 16:02 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-06-24 15:58 . 2009-06-24 15:58 -------- dc-h--w- c:\progra~2\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-24 15:58 . 2009-06-04 17:16 -------- d-----w- c:\program files\Lavasoft
2009-06-24 15:58 . 2009-06-04 17:16 -------- d-----w- c:\progra~2\Lavasoft
2009-06-15 14:53 . 2009-07-15 14:05 156672 ----a-w- c:\windows\system32\t2embed.dll
2009-06-15 14:52 . 2009-07-15 14:05 23552 ----a-w- c:\windows\system32\lpk.dll
2009-06-15 14:52 . 2009-07-15 14:05 72704 ----a-w- c:\windows\system32\fontsub.dll
2009-06-15 14:51 . 2009-07-15 14:05 10240 ----a-w- c:\windows\system32\dciman32.dll
2009-06-15 12:42 . 2009-07-15 14:05 289792 ----a-w- c:\windows\system32\atmfd.dll
2009-05-13 21:55 . 2009-05-13 21:55 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-13 21:55 . 2009-05-13 21:55 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2006-05-03 10:06 . 2009-05-13 01:58 163328 --sha-r- c:\windows\System32\flvDX.dll
2007-02-21 11:47 . 2009-05-13 01:58 31232 --sh--r- c:\windows\System32\msfDX.dll
2008-03-16 13:30 . 2009-05-13 01:58 216064 --sh--r- c:\windows\System32\nbDX.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-08-21_17.01.46 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-01-09 20:18 . 2009-08-21 17:52 52280 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-08-21 17:52 78762 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-05-07 00:56 . 2009-08-21 17:52 13034 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3615268277-3926800693-1650498289-1005_UserData.bin
+ 2006-11-02 10:33 . 2009-08-21 17:58 650720 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2009-08-21 16:55 650720 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-08-21 17:58 122622 c:\windows\System32\perfc009.dat
- 2006-11-02 10:33 . 2009-08-21 16:55 122622 c:\windows\System32\perfc009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2006-11-13 118784]
"AppMon Utility"="c:\program files\Sony\AppMonUtil\AppMonUtility.exe" [2006-11-15 415864]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2006-11-11 43128]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-09-29 151552]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-02-20 7770112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-02-20 81920]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"minix32"="c:\windows\system32\minix32.exe" [2009-08-21 585736]

c:\progra~2\MICROS~1\Windows\STARTM~1\Programs\Startup\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2006-11-25 2134016]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 16:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2006-12-14 23:06 73728 ----a-w- c:\windows\System32\VESWinlogon.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rgadta.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=c:\windows\pss\Adobe Reader Synchronizer.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Free WebSite Tools.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Free WebSite Tools.lnk
backup=c:\windows\pss\Free WebSite Tools.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=c:\windows\pss\QuickBooks Update Agent.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^Users^Ownwer^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\users\Ownwer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"="0x00000000"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(<_<:62,01,3a,34,c5,f5,c9,01

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3615268277-3926800693-1650498289-1005]
"EnableNotificationsRef"=dword:00000002

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{40BAA052-6F21-4FB5-A872-CC8BA96FA69B}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{37CC52F2-39F4-4731-935C-94CC8F312C7F}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{841DC118-DC5B-46AB-8AD0-5346AA9C6B47}"= UDP:c:\program files\BitComet\BitComet.exe:BitComet.exe
"{5C1FA1D5-7339-475B-A6FD-E40A8884D2C4}"= TCP:c:\program files\BitComet\BitComet.exe:BitComet.exe
"{97E94798-B24B-476C-90C8-CA53770352F9}"= UDP:c:\program files\Common Files\AOL\acs\AOLDial.exe:AOL Connectivity Service Dialer
"{BC1688CF-7179-43E7-9683-05B9B521CE0C}"= TCP:c:\program files\Common Files\AOL\acs\AOLDial.exe:AOL Connectivity Service Dialer
"{5EA6C23E-BC0C-483F-8216-BC2754D91B5D}"= UDP:c:\program files\Common Files\AOL\acs\AOLacsd.exe:AOL Connectivity Service
"{169957EF-0E93-425B-9712-D627FC07444D}"= TCP:c:\program files\Common Files\AOL\acs\AOLacsd.exe:AOL Connectivity Service
"{FA8D70FB-5211-487A-B9EB-34FB9E9E88A7}"= UDP:c:\program files\Common Files\AOL\1241668092\ee\aolsoftware.exe:AOL Shared Components
"{A8360307-1BDE-4942-B1E0-8AA1CDAF7838}"= TCP:c:\program files\Common Files\AOL\1241668092\ee\aolsoftware.exe:AOL Shared Components
"{943C826E-17A1-4C3E-9F4E-B1729D97C2EF}"= UDP:c:\program files\AOL 9.5\waol.exe:AOL
"{758EBDDD-981E-439F-BF24-4F243A2D1180}"= TCP:c:\program files\AOL 9.5\waol.exe:AOL
"{A759DFBF-6AB2-487D-AEDE-453AC1E48212}"= UDP:c:\program files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe:AOL TopSpeed
"{6C483883-4CFF-4FAC-9483-174538DF5CDC}"= TCP:c:\program files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe:AOL TopSpeed
"{B745CF04-F3FE-4758-8141-3FBD82A23101}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{961D9C77-2734-4CE1-8926-06DCD8556DB4}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{73D2FFFC-B8A8-4430-819A-0241A126AF42}"= UDP:c:\program files\Common Files\AOL\System Information\sinf.exe:AOL System Information
"{4B58E94F-4C3E-4BDB-9ED1-0A6603220C5C}"= TCP:c:\program files\Common Files\AOL\System Information\sinf.exe:AOL System Information
"{C9B1A609-022C-4A47-9652-F3974B553161}"= UDP:13285:BitComet 13285 TCP
"{D037E8AF-1295-47BF-9C2A-04E638AF4093}"= TCP:13285:BitComet 13285 UDP
"TCP Query User{A43929CE-881A-4CC7-82F5-7B1ED30D5DE0}c:\\program files\\bitcomet\\bitcomet.exe"= UDP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"UDP Query User{802EFC40-D9F3-46E4-AA94-77456608C424}c:\\program files\\bitcomet\\bitcomet.exe"= TCP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"{C1C127E5-0C8F-4B53-873F-FED2CDC1BD90}"= Disabled:UDP:5353:Adobe CSI CS4
"{40527ECD-B9D7-4F0D-970D-CD7C64614FEC}"= Disabled:UDP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{B3057D6C-B043-469A-9FAF-636A80848CD6}"= Disabled:TCP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"TCP Query User{3A9F951F-5947-4C29-8A40-109FF58ADFC9}c:\\program files\\icq6.5\\icq.exe"= UDP:c:\program files\icq6.5\icq.exe:ICQ
"UDP Query User{4F0C3FF4-5D0A-4B36-86A8-7DBE55F4E110}c:\\program files\\icq6.5\\icq.exe"= TCP:c:\program files\icq6.5\icq.exe:ICQ
"{6ADEA974-7745-47F9-9A88-11C7443552DF}"= UDP:21203:Bit Comet
"{C96D0FC7-D010-46EE-AEEB-B6DD11EA6348}"= TCP:21203:BitComet 21203 UDP
"{853FECD1-A5B1-49D7-8453-D992EC01B594}"= Disabled:UDP:c:\program files\Adobe\Adobe Photoshop CS4\Photoshop.exe:Adobe Photoshop CS4
"{4D799B11-6623-450B-AA76-C7DE683C915B}"= Disabled:TCP:c:\program files\Adobe\Adobe Photoshop CS4\Photoshop.exe:Adobe Photoshop CS4
"TCP Query User{83BD6E2D-5AAB-4180-846A-61C3DC78319A}c:\\program files\\aol 9.5\\waol.exe"= UDP:c:\program files\aol 9.5\waol.exe:AOL Software
"UDP Query User{E5B66B7F-A7A6-43FD-A943-ED95F812D7E5}c:\\program files\\aol 9.5\\waol.exe"= TCP:c:\program files\aol 9.5\waol.exe:AOL Software
"{9FB6AE73-2661-489A-888A-01BAEB67193C}"= UDP:21203:BitComet 21203 TCP
"{847344ED-3778-40ED-AABB-6526300DF2BF}"= TCP:21203:BitComet 21203 UDP
"{6D7F3A44-7D7C-45D7-AF1D-EE2946118136}"= UDP:c:\program files\Common Files\AOL\acs\AOLDial.exe:AOL Connectivity Service Dialer
"{3BB238BE-AE2E-4017-9B1E-40524B019D91}"= TCP:c:\program files\Common Files\AOL\acs\AOLDial.exe:AOL Connectivity Service Dialer
"{ADAF0980-A9E0-48A0-9A77-66B001EA04FD}"= UDP:c:\program files\Common Files\AOL\acs\AOLacsd.exe:AOL Connectivity Service
"{CC00F8C3-D10D-405F-9C21-2E81C315904F}"= TCP:c:\program files\Common Files\AOL\acs\AOLacsd.exe:AOL Connectivity Service
"{F41B951F-D61F-45D0-BB91-F7C740F0A0FB}"= UDP:c:\program files\Common Files\AOL\1241668092\ee\aolsoftware.exe:AOL Shared Components
"{70D36294-391F-4826-BCC1-794E0228BA1A}"= TCP:c:\program files\Common Files\AOL\1241668092\ee\aolsoftware.exe:AOL Shared Components
"{5C2ED012-78A5-49BB-A0E9-48F85506BDD9}"= UDP:c:\program files\AOL 9.5a\waol.exe:AOL
"{B8EB4792-828B-44F5-91BB-8A78DD886049}"= TCP:c:\program files\AOL 9.5a\waol.exe:AOL
"{8601CEF8-4E8D-4E01-91BA-43C183CD1B63}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{F30DA1B4-73FF-442A-B773-1279F3DD82CB}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{DEFB26F1-76D6-484B-A875-A64594796A9E}"= UDP:c:\program files\Common Files\AOL\System Information\sinf.exe:AOL System Information
"{B2C39C37-9C17-4846-A920-7FEE41EA50A0}"= TCP:c:\program files\Common Files\AOL\System Information\sinf.exe:AOL System Information
"{DFD1315C-1455-44F7-9397-0521CDF00C2B}"= UDP:c:\program files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe:AOL
"{F3D290E0-EC7E-403B-89C9-832F6CD0E2F1}"= TCP:c:\program files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe:AOL
"TCP Query User{8CF1AA9F-64F4-4664-9D78-654923AE24F3}c:\\program files\\warez\\warez.exe"= UDP:c:\program files\warez\warez.exe:Warez
"UDP Query User{A493BC83-54FF-486D-B396-DC9F0C90BF85}c:\\program files\\warez\\warez.exe"= TCP:c:\program files\warez\warez.exe:Warez
"{37411C69-05AF-4BAD-BB17-C25921811899}"= UDP:9000:warez
"{888391BB-99C9-46E8-8436-29F9FE96BFEB}"= UDP:c:\program files\AOL 9.5b\waol.exe:AOL
"{712B919F-B742-4DA1-A136-2466D833E008}"= TCP:c:\program files\AOL 9.5b\waol.exe:AOL
"{C551ADF0-37EF-4E58-BBAD-646FA2E472AB}"= UDP:c:\program files\AOL 9.5c\waol.exe:AOL
"{697B1478-1915-445A-99FA-E87271EBC87B}"= TCP:c:\program files\AOL 9.5c\waol.exe:AOL
"{FF24500F-7EF4-41F3-9D0F-99C764297831}"= UDP:c:\program files\AOL 9.5d\waol.exe:AOL
"{0FBCEB51-7742-456D-9F60-10186220B021}"= TCP:c:\program files\AOL 9.5d\waol.exe:AOL
"{FD148DFC-6537-412D-A223-BD040F677E44}"= UDP:c:\program files\AOL 9.5e\waol.exe:AOL
"{6EF1EB1B-1708-480F-B8CD-138CDBF8284B}"= TCP:c:\program files\AOL 9.5e\waol.exe:AOL
"{03EB1BFC-C696-483F-B4B4-F29D13A280E1}"= h:\setup\hpznui01.exe:hpznui01.exe
"{B8E3C04A-93BD-4186-8BF6-DDFF4B4E3391}"= TCP:427|RPort=427|c:\windows\system32\svchost.exe|Svc=HPSLPSVC:SLP_Service
"{468D631B-DE87-4B4B-B4B7-EB8C8230FF07}"= c:\program files\HP\digital imaging\bin\hpqtra08.exe:hpqtra08.exe
"{3D6FDB19-41BF-42CE-BC3C-DD731DF1A3B8}"= c:\program files\HP\digital imaging\bin\hpqste08.exe:hpqste08.exe
"{660482BB-0B27-428D-8BDE-EE52E8B85C1F}"= c:\program files\HP\digital imaging\bin\hpofxm08.exe:hpofxm08.exe
"{7CB13788-062D-4789-9354-0660A68F6793}"= c:\program files\HP\digital imaging\bin\hposfx08.exe:hposfx08.exe
"{6923878F-E860-44DE-BB8F-15D3B3ABF4A6}"= c:\program files\HP\digital imaging\bin\hposid01.exe:hposid01.exe
"{7C602645-4EC5-4A7F-A99A-548AA9147389}"= c:\program files\HP\digital imaging\bin\hpqkygrp.exe:hpqkygrp.exe
"{96742C78-9FA4-4471-999D-E6F1D1EAF052}"= c:\program files\HP\digital imaging\bin\hpzwiz01.exe:hpzwiz01.exe
"{592025E4-7947-440F-AFB3-7A03B2E0EAD4}"= UDP:c:\program files\AOL 9.5f\waol.exe:AOL
"{E24EE7DA-5047-4900-A793-E6531584BAED}"= TCP:c:\program files\AOL 9.5f\waol.exe:AOL

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [6/24/2009 11:02 64160]
R1 rgadta;RAMDAC XGPU Controller;c:\windows\System32\rgadta.sys [8/21/2009 08:46 8432]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [1/15/2009 16:17 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/15/2009 16:17 55024]
R2 CSHelper;CopySafe Helper Service;c:\windows\System32\CSHelper.exe [8/4/2009 17:30 266240]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\Firebird\Firebird_2_1\bin\fbguard.exe -s DefaultInstance --> c:\program files\Firebird\Firebird_2_1\bin\fbguard.exe -s DefaultInstance [?]
R2 MSSQL$VAIO_VEDB;SQL Server (VAIO_VEDB);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [12/1/2006 15:11 28933976]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\Firebird\Firebird_2_1\bin\fbserver.exe -s DefaultInstance --> c:\program files\Firebird\Firebird_2_1\bin\fbserver.exe -s DefaultInstance [?]
R3 R5U870FLx86;R5U870 UVC Lower Filter ;c:\windows\System32\drivers\R5U870FLx86.sys [1/9/2007 14:18 72704]
R3 R5U870FUx86;R5U870 UVC Upper Filter ;c:\windows\System32\drivers\R5U870FUx86.sys [1/9/2007 14:18 43904]
R3 slim;Sony Lucid Integrated Mpeg encoder;c:\windows\System32\drivers\slim.sys [1/9/2007 14:30 699264]
R3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\System32\drivers\SonyImgF.sys [1/9/2007 15:10 30976]
R3 ti21sony;ti21sony;c:\windows\System32\drivers\ti21sony.sys [1/9/2007 14:29 227328]
R3 wsvad_driver;WS Audio Device;c:\windows\System32\drivers\VirtualAudio.sys [8/7/2009 16:54 16896]
S3 netr28u;Linksys USB Wireless LAN Card Driver for Vista;c:\windows\System32\drivers\netr28u.sys [12/14/2007 18:16 570880]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [1/15/2009 16:17 7408]
S3 USBAVCap;AVerMedia USB TV Tuner Device;c:\windows\System32\drivers\USBAVCap.sys [1/9/2007 14:17 774528]
S3 VAIOMediaPlatform-UCLS-AppServer;VAIO Media Content Collection;c:\program files\Sony\VAIO Media Integrated Server\UCLS.exe [10/2/2007 00:57 741376]
S3 VAIOMediaPlatform-UCLS-HTTP;VAIO Media Content Collection (HTTP);c:\program files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe [10/2/2007 00:57 397312]
S3 VAIOMediaPlatform-UCLS-UPnP;VAIO Media Content Collection (UPnP);c:\program files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe [10/2/2007 00:57 1089536]
S4 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [6/8/2009 14:55 108289]
S4 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 14:06 1003344]
S4 SlingAgentService;SlingAgentService;c:\program files\Sling Media\SlingAgent\SlingAgentService.exe [4/27/2009 18:09 93960]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
.
------- Supplementary Scan -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
Trusted Zone: musicmatch.com\online
FF - ProfilePath - c:\users\Ownwer\AppData\Roaming\Mozilla\Firefox\Profiles\9s40vgdk.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.aol.com/aolcom/search?invocationType=tb50ffTB50CL-chromesbox-en-us&query=
FF - prefs.js: browser.search.selectedEngine - AOL Search
FF - prefs.js: browser.startup.homepage - hxxp://www.aol.com
FF - prefs.js: keyword.URL - hxxp://search.aol.com/aolcom/search?invocationType=tb50ffTB50CL-ab-en-us&query=
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\MpcStar\Codecs\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\MpcStar\Codecs\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - plugin: c:\users\Ownwer\AppData\Local\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: protocol-handler.warn-external.dnUpdate - falsec:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.

**************************************************************************
scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files:

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\audiodg.exe
c:\program files\Sony\Wireless Switch Setting Utility\Switcher.exe
c:\program files\Sony\VAIO Update 3\VAIOUpdt.exe
c:\program files\Firebird\Firebird_2_1\bin\fbguard.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\program files\Sony\VAIO Event Service\VESMgr.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
c:\windows\System32\drivers\XAudio.exe
c:\program files\Sony\VAIO Event Service\VESMgrSub.exe
c:\windows\System32\WUDFHost.exe
c:\program files\Apoint\ApMsgFwd.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
c:\program files\Firebird\Firebird_2_1\bin\fbserver.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Apoint\ApntEx.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosOBEX.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe
c:\windows\System32\wbem\WMIADAP.exe
.
**************************************************************************
.
Completion time: 2009-08-21 13:42 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-21 18:42
ComboFix2.txt 2009-08-21 17:09

Pre-Run: 143,895,580,672 bytes free
Post-Run: 143,768,285,184 bytes free

480 --- E O F --- 2009-08-20 22:26

#3
Fletch55

    New Member

  • Members
  • Pip
  • 18 posts
So no one can help me with the removal of this malware???Mods anyone?

#4
Fletch55

    New Member

  • Members
  • Pip
  • 18 posts
Ok well think I got it all cured now. I used spyware doctor and it grabbed both trouble makers and supposedly 256 other issues were fixed. So here is a final hijack liost if no issues seem to be seen let me know and I guess the thread is resolved by simply using spyware doctor...

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:49:52, on 8/24/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Sony\AppMonUtil\AppMonUtility.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\AOL\1241668092\ee\aolsoftware.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\AOL 9.5\waol.exe
C:\Program Files\AOL 9.5\shellmon.exe
C:\Program Files\Common Files\AOL\Topspeed\3.0\aoltpsd3.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [AppMon Utility] "C:\Program Files\Sony\AppMonUtil\AppMonUtility.exe" @@@Start
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.5\AOL.EXE" -b
O4 - HKUS\S-1-5-18\..\Run: [minix32] C:\Windows\system32\minix32.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [minix32] C:\Windows\system32\minix32.exe (User 'Default user')
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: CopySafe Helper Service (CSHelper) - Unknown owner - C:\Windows\system32\CSHelper.exe
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - FirebirdSQL Project - C:\Program Files\Firebird\Firebird_2_1\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - FirebirdSQL Project - C:\Program Files\Firebird\Firebird_2_1\bin\fbserver.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 6911 bytes

#5
Fletch55

    New Member

  • Members
  • Pip
  • 18 posts
Ok so both have returned. They were gone almost a full day thern when I restarted this morning and did a scan mbam now finds them again. I need some help on these

#6
screen317

    MBAM Sentinel

  • Moderators
  • PipPipPipPipPipPip
  • 16,432 posts
  • Gender:Male
  • Location:Los Angeles
Hi Fletch55 and welcome to Malwarebytes.

Bumping your topic makes it seem like you are already being helped, and as you've noticed, you were overlooked because of it.

Please update MBAM, run a Quick Scan, and post its log.

Please delete your copy of ComboFix and download the latest version from here.

1. Save it to your Desktop.
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log, as well as a fresh HijackThis log, in your next reply.


-screen317
Chris Fistonich
Consumer Support Specialist

Posted Image

Follow us: Twitter, Become a fan: Facebook

#7
Fletch55

    New Member

  • Members
  • Pip
  • 18 posts
Ok thanks for the reply. yeah i found out the hardway the boards are a little different then the ones I have used in the past and see how it works now. Glad you came and found me...Back to business hopefully quick and painless. I just updated MBAM and redownloaded Combofix from your link..Here are the 2 reports as requested MBAM first then the new Hijack log.

Malwarebytes' Anti-Malware 1.40
Database version: 2699
Windows 6.0.6002 Service Pack 2

8/26/2009 11:16:53 AM
mbam-log-2009-08-26 (11-16-53).txt

Scan type: Quick Scan
Objects scanned: 89986
Time elapsed: 5 minute(s), 8 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Windows\system32\drivers\mrxdavv.sys (Rootkit.Agent.H) -> Delete on reboot.
C:\Windows\system32\kwave.sys (Trojan.Agent) -> Delete on reboot.
________________________________________________________________________________
_______________________________________________________________


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:17:48 AM, on 8/26/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Sony\AppMonUtil\AppMonUtility.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\Program Files\AOL 9.5\waol.exe
C:\Program Files\AOL 9.5\shellmon.exe
C:\Program Files\Common Files\AOL\1241668092\ee\aolsoftware.exe
C:\Program Files\Common Files\AOL\Topspeed\3.0\aoltpsd3.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [AppMon Utility] "C:\Program Files\Sony\AppMonUtil\AppMonUtility.exe" @@@Start
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: CopySafe Helper Service (CSHelper) - Unknown owner - C:\Windows\system32\CSHelper.exe
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - FirebirdSQL Project - C:\Program Files\Firebird\Firebird_2_1\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - FirebirdSQL Project - C:\Program Files\Firebird\Firebird_2_1\bin\fbserver.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 6865 bytes

#8
Fletch55

    New Member

  • Members
  • Pip
  • 18 posts
Ok kind of forgot to run combofix before lkast post so the post above is the mbam report log and then a hijack log after that but before combofix was run. Here is the combofix log and a new hijack report now that both mbam and combofix have been run. My apologies...

ComboFix 09-08-25.05 - Ownwer 08/26/2009 11:22.3.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2045.1050 [GMT -5:00]
Running from: c:\users\Ownwer\Desktop\ComboFix.exe
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\Drivers\axhqf.sys
c:\windows\system32\Drivers\fkuegwg.sys
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
c:\users\Ownwer\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms . . . . failed to delete
c:\windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms . . . . failed to delete
c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms . . . . failed to delete

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_hsmzewwz
-------\Service_zxfg


((((((((((((((((((((((((( Files Created from 2009-07-26 to 2009-08-26 )))))))))))))))))))))))))))))))
.

2009-08-26 16:31 . 2009-08-26 16:31 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-08-26 16:22 . 2009-08-26 16:22 -------- d-----w- c:\users\Ownwer\AppData\Local\Adobe
2009-08-25 17:32 . 2009-08-26 16:23 -------- d-----w- c:\users\Ownwer\AppData\Local\AOL
2009-08-25 15:44 . 2009-08-25 16:01 680 ----a-w- c:\users\Ownwer\AppData\Local\d3d9caps.dat
2009-08-25 15:14 . 2009-08-26 16:34 -------- d-----w- c:\users\Ownwer\AppData\Local\temp
2009-08-24 14:54 . 2009-08-24 16:01 -------- d-----w- c:\program files\Common Files\PC Tools
2009-08-24 14:54 . 2009-08-24 16:01 -------- d-----w- c:\program files\Spyware Doctor
2009-08-21 18:05 . 2009-08-21 18:05 -------- d-----w- c:\program files\Trend Micro
2009-08-21 15:43 . 2009-08-25 15:24 35 ----a-w- c:\users\Ownwer\AppData\Roaming\SetValue.bat
2009-08-21 13:46 . 2009-08-21 13:46 16 ----a-w- c:\windows\pxydb.dat
2009-08-21 13:46 . 2009-08-21 13:46 8432 ----a-w- c:\windows\system32\drivers\nwlnkfwd.sys
2009-08-21 13:46 . 2009-08-21 13:46 8432 ----a-w- c:\windows\system32\drivers\nwlnkflt.sys
2009-08-21 13:46 . 2009-08-21 13:46 8432 ----a-w- c:\windows\system32\drivers\ipinip.sys
2009-08-21 13:46 . 2009-08-21 13:46 8432 ----a-w- c:\windows\system32\drivers\blbdrive.sys
2009-08-20 22:22 . 2009-06-15 14:54 175104 ----a-w- c:\windows\system32\wdigest.dll
2009-08-20 22:22 . 2009-06-15 14:53 270848 ----a-w- c:\windows\system32\schannel.dll
2009-08-20 22:22 . 2009-06-15 14:53 218624 ----a-w- c:\windows\system32\msv1_0.dll
2009-08-20 22:22 . 2009-06-15 14:52 499712 ----a-w- c:\windows\system32\kerberos.dll
2009-08-20 22:22 . 2009-06-15 23:15 439864 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-08-20 22:22 . 2009-06-15 14:53 72704 ----a-w- c:\windows\system32\secur32.dll
2009-08-20 22:22 . 2009-06-15 14:52 1259008 ----a-w- c:\windows\system32\lsasrv.dll
2009-08-20 22:22 . 2009-06-15 12:48 9728 ----a-w- c:\windows\system32\lsass.exe
2009-08-20 20:32 . 2009-08-20 20:32 -------- d-----w- c:\program files\Brice Lambson
2009-08-20 17:33 . 2009-08-20 17:33 -------- d-----w- c:\users\Ownwer\AppData\Roaming\Nero
2009-08-20 17:12 . 2009-08-20 17:19 -------- d-----w- c:\program files\Nero
2009-08-20 17:12 . 2009-08-20 17:20 -------- d-----w- c:\program files\Common Files\Nero
2009-08-20 17:12 . 2009-08-20 17:14 -------- d-----w- c:\programdata\Nero
2009-08-17 14:11 . 2009-08-17 14:11 -------- d-----w- c:\program files\Linksys
2009-08-17 14:10 . 2009-08-17 14:10 -------- d-----w- c:\windows\{7F7635FC-B887-49FA-8526-094724C01A6E}
2009-08-12 22:14 . 2009-07-17 13:54 71680 ----a-w- c:\windows\system32\atl.dll
2009-08-12 22:14 . 2009-06-10 11:42 160256 ----a-w- c:\windows\system32\wkssvc.dll
2009-08-12 22:14 . 2009-06-04 12:07 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-08-12 22:14 . 2009-06-10 11:38 91136 ----a-w- c:\windows\system32\avifil32.dll
2009-08-12 22:14 . 2009-07-15 12:39 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-08-12 22:14 . 2009-07-15 12:39 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-08-12 22:14 . 2009-07-15 12:39 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-08-12 22:14 . 2009-07-15 12:40 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-08-12 14:41 . 2009-08-13 13:35 -------- d-----w- c:\program files\AOL 9.5
2009-08-11 22:13 . 2009-08-11 22:13 -------- d-----w- c:\program files\PFPortChecker
2009-08-07 21:54 . 2008-08-13 02:08 16896 ----a-w- c:\windows\system32\drivers\VirtualAudio.sys
2009-08-07 21:54 . 2009-08-07 21:54 -------- d-----w- c:\program files\Daniusoft
2009-08-07 18:41 . 2009-08-07 18:41 -------- d-----w- c:\users\Ownwer\AppData\Roaming\TigerPlayer
2009-08-07 18:40 . 2009-08-07 18:40 -------- d-----w- c:\program files\MpcStar
2009-08-06 23:09 . 2009-08-06 23:12 -------- d-----w- c:\users\Ownwer\AppData\Roaming\DivX
2009-08-06 23:06 . 2009-08-06 23:06 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2009-08-06 23:05 . 2009-08-06 23:06 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-08-06 23:05 . 2009-08-06 23:07 -------- d-----w- c:\program files\DivX
2009-08-06 15:34 . 2009-08-06 15:47 -------- d-----w- c:\program files\AOL 9.5h
2009-08-04 22:30 . 2009-08-04 22:30 266240 ----a-w- c:\windows\system32\CSHelper.exe
2009-08-04 22:30 . 2009-08-04 22:30 225280 ----a-w- c:\windows\system32\CSInstru.DLL
2009-08-03 23:12 . 2009-08-03 23:12 -------- d-----w- c:\program files\SpacialAudio
2009-08-03 23:12 . 2007-10-16 15:07 442368 ----a-w- c:\windows\system32\GDS32.DLL
2009-08-03 23:12 . 2005-09-23 05:05 626688 ----a-w- c:\windows\system32\msvcr80.dll
2009-08-03 23:12 . 2005-09-23 05:05 548864 ----a-w- c:\windows\system32\msvcp80.dll
2009-08-03 23:12 . 2009-08-03 23:12 -------- d-----w- c:\program files\Firebird

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-26 16:00 . 2009-05-11 14:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-26 16:00 . 2009-05-11 14:22 3942048 ----a-w- c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-08-25 17:28 . 2009-05-12 00:44 -------- d-----w- c:\program files\Media Resizer PRO
2009-08-25 16:01 . 2009-05-07 17:20 -------- d-----w- c:\program files\UltraExplorer
2009-08-25 15:30 . 2009-05-11 14:25 117760 ----a-w- c:\users\Ownwer\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-08-25 15:24 . 2009-08-21 15:43 691 ----a-w- c:\users\Ownwer\AppData\Roaming\GetValue.vbs
2009-08-24 16:36 . 2009-05-07 00:55 204720 ----a-w- c:\users\Ownwer\AppData\Local\GDIPFONTCACHEV1.DAT
2009-08-24 15:27 . 2009-05-07 00:48 -------- d-----w- c:\program files\BitComet
2009-08-24 14:42 . 2009-05-13 18:21 -------- d-----w- c:\users\Ownwer\AppData\Roaming\Corel
2009-08-17 14:11 . 2007-01-09 20:14 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-14 14:43 . 2009-07-08 22:30 -------- d-----w- c:\program files\HP
2009-08-12 14:43 . 2009-05-07 03:51 -------- d-----w- c:\users\Ownwer\AppData\Roaming\AOL
2009-08-12 14:41 . 2007-10-02 05:03 -------- d-----w- c:\program files\Common Files\AOL
2009-08-12 14:41 . 2009-05-07 03:48 -------- d-----w- c:\program files\Common Files\aolshare
2009-08-12 14:41 . 2009-05-07 03:48 -------- d-----w- c:\programdata\AOL
2009-08-10 02:44 . 2009-07-02 05:35 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-08-10 02:44 . 2009-07-02 05:35 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-08-07 18:40 . 2009-06-05 17:54 -------- d-----w- c:\program files\QuickTime
2009-08-07 18:40 . 2009-06-05 17:54 -------- d-----w- c:\programdata\Apple Computer
2009-08-05 13:56 . 2007-01-09 19:39 -------- d-----w- c:\program files\Java
2009-08-03 22:32 . 2009-08-06 15:30 900968 ----a-w- c:\programdata\AOL Downloads\SUD4444\waol-0.4337.89.1.exe
2009-08-03 22:10 . 2009-08-06 15:30 1914000 ----a-w- c:\programdata\AOL Downloads\SUD4444\comps\flash\flashax.exe
2009-08-03 22:09 . 2009-08-06 15:30 1612544 ----a-w- c:\programdata\AOL Downloads\SUD4444\comps\acs\comps\acslang.exe
2009-08-03 22:09 . 2009-08-06 15:30 964544 ----a-w- c:\programdata\AOL Downloads\SUD4444\comps\acs\comps\acslaeu.exe
2009-08-03 22:09 . 2009-08-06 15:30 45864 ----a-w- c:\programdata\AOL Downloads\SUD4444\comps\acs\comps\AcsInstA.dll
2009-08-03 22:09 . 2009-08-06 15:30 37672 ----a-w- c:\programdata\AOL Downloads\SUD4444\comps\acs\comps\AcsInstC.dll
2009-08-03 22:09 . 2009-08-06 15:30 45864 ----a-w- c:\programdata\AOL Downloads\SUD4444\comps\acs\AcsInstA.dll
2009-08-03 22:09 . 2009-08-06 15:30 1484136 ----a-w- c:\programdata\AOL Downloads\SUD4444\comps\acs\comps\acscore.exe
2009-08-03 18:36 . 2009-05-11 14:21 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 18:36 . 2009-05-11 14:21 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-27 14:32 . 2009-07-27 14:32 713992 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-07-27 14:27 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-07-25 10:23 . 2009-07-27 14:29 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-24 14:06 . 2009-07-23 20:00 -------- d-----w- c:\program files\AOL 9.5g
2009-07-23 20:01 . 2009-07-23 20:01 -------- d-----w- c:\program files\Common Files\Software Update Utility
2009-07-23 19:58 . 2009-07-23 19:58 62248 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\comps\ocpgc.exe
2009-07-23 19:58 . 2009-07-23 19:58 260040 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\ecuinst.exe
2009-07-23 19:58 . 2009-07-23 19:58 93992 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\instph.dll
2009-07-23 19:58 . 2009-07-23 19:58 21288 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\comps\acsshutd.exe
2009-07-23 19:58 . 2009-07-23 19:58 45864 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\AcsInstA.dll
2009-07-23 19:58 . 2009-07-23 19:58 223152 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\afix\wsfinst.exe
2009-07-23 19:58 . 2009-07-23 19:58 15920 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\ccu\ocpchk.dll
2009-07-23 19:58 . 2009-07-23 19:48 23542688 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\noneCodesignFilesBundle.exe
2009-07-23 19:48 . 2009-07-23 19:48 607392 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\tpspd\wbsetup.exe
2009-07-23 19:48 . 2009-07-23 19:48 45864 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\comps\AcsInstA.dll
2009-07-23 19:48 . 2009-07-23 19:48 188064 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\desk\dtblpins.exe
2009-07-23 19:48 . 2009-07-23 19:48 10800 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\afix\wsfixchk.dll
2009-07-23 19:48 . 2009-07-23 19:47 3346208 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\comps\ocpinst.exe
2009-07-23 19:47 . 2009-07-23 19:47 67120 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\ccu\instSup.dll
2009-07-23 19:47 . 2009-07-23 19:47 11312 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\ecuchk.dll
2009-07-23 19:47 . 2009-07-23 19:46 964544 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\comps\acslaeu.exe
2009-07-23 19:46 . 2009-07-23 19:45 1878296 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\toolbar\aol_toolbar.exe
2009-07-23 19:45 . 2009-07-23 19:45 74536 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\comps\instSup.dll
2009-07-23 19:45 . 2009-07-23 19:45 127224 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\afix\afixlang.exe
2009-07-23 19:45 . 2009-07-23 19:45 168744 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\setup.exe
2009-07-23 19:45 . 2009-07-23 19:45 1362936 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\msvcr9\msvc9rt.exe
2009-07-23 19:45 . 2009-07-23 19:45 147984 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\comps\acsrollb.exe
2009-07-23 19:45 . 2009-07-23 19:45 472872 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\gui.dll
2009-07-23 19:45 . 2009-07-23 19:44 469776 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\desk\dtbsetup.exe
2009-07-23 19:44 . 2009-07-23 19:44 54832 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\parcon\AOLParconLink.exe
2009-07-23 19:44 . 2009-07-23 19:44 355592 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\afix\afixinst.exe
2009-07-23 19:44 . 2009-05-20 16:33 54832 ----a-w- c:\windows\system32\AOLParconLink.exe
2009-07-23 19:44 . 2009-07-23 19:44 390704 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\afix\WinsockFix.exe
2009-07-23 19:44 . 2009-07-23 19:44 900904 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\waol-0.4337.80.1.exe
2009-07-23 19:44 . 2009-07-23 19:44 339840 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\desk\dskcore.exe
2009-07-23 19:44 . 2009-07-23 19:44 711592 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\sysinfo\SinfInst.exe
2009-07-23 19:44 . 2009-07-23 19:44 37672 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\comps\AcsInstC.dll
2009-07-23 19:44 . 2009-07-23 19:44 404568 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\tb\tbsetup.exe
2009-07-23 19:44 . 2009-07-23 19:44 124264 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\comps\cpwinst.exe
2009-07-23 19:43 . 2009-07-23 19:43 2439824 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\ccu\ocpinsti.exe
2009-07-23 19:43 . 2009-07-23 19:41 2395720 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\desk\dskcorlp.exe
2009-07-23 19:41 . 2009-07-23 19:41 35624 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\postproc.exe
2009-07-23 19:41 . 2009-07-23 19:40 1612544 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\comps\acslang.exe
2009-07-23 19:40 . 2009-07-23 19:40 15144 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\comps\ocpchk.dll
2009-07-23 19:40 . 2009-07-23 19:40 75048 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\instSup.dll
2009-07-23 19:40 . 2009-07-23 19:38 1484136 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\comps\acscore.exe
2009-07-22 16:32 . 2009-07-08 23:11 -------- d-----w- c:\users\Ownwer\AppData\Roaming\HP
2009-07-21 21:52 . 2009-07-29 14:11 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-07-29 14:11 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-07-29 14:11 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-07-29 14:11 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-21 03:12 . 2009-07-21 03:12 6144 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\afix\ocfcheck.dll
2009-07-21 03:12 . 2009-07-21 03:12 1914000 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\flash\flashax.exe
2009-07-21 03:12 . 2009-07-21 03:12 845802 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\muinst\muinst.exe
2009-07-21 03:12 . 2009-07-21 03:12 6144 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\tb\tbinst.dll
2009-07-21 03:12 . 2009-07-21 03:12 57344 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\tpspd\tsverchk.dll
2009-07-21 03:12 . 2009-07-21 03:12 49152 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\tpspd\Dacldll.dll
2009-07-21 03:12 . 2009-07-21 03:12 45056 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\sysinfo\SiNdInst.dll
2009-07-21 03:12 . 2009-07-21 03:12 61440 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\vwpt\VPPrePop.exe
2009-07-21 03:12 . 2009-07-21 03:12 49152 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\vwpt\AOLVPChk.dll
2009-07-21 03:12 . 2009-07-21 03:12 3858056 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\vwpt\Vwpt.exe
2009-07-17 20:20 . 2009-07-14 15:59 9264 ----a-w- c:\windows\system32\msqtvcap.dat
2009-07-16 18:53 . 2009-07-16 18:53 -------- d-----w- c:\program files\Sling Media
2009-07-16 18:53 . 2009-07-16 18:53 -------- d-----w- c:\programdata\Sling Media
2009-07-15 21:53 . 2009-07-15 21:53 -------- d-----w- c:\users\Ownwer\AppData\Roaming\Plazmic
2009-07-15 21:53 . 2009-07-15 21:51 -------- d--h--w- c:\program files\Zero G Registry
2009-07-15 21:53 . 2009-07-15 21:51 -------- d-----w- c:\program files\Plazmic CDK 4.7
2009-07-14 15:58 . 2009-07-14 15:58 -------- d-----w- c:\program files\Alibaba
2009-07-10 15:19 . 2009-07-10 15:18 469680 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.74.1\comps\desk\dtbsetup.exe
2009-07-10 15:18 . 2009-07-10 15:18 355592 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.74.1\comps\afix\afixinst.exe
2009-05-13 21:55 . 2009-05-13 21:55 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-13 21:55 . 2009-05-13 21:55 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2006-05-03 10:06 . 2009-05-13 01:58 163328 --sha-r- c:\windows\System32\flvDX.dll
2007-02-21 11:47 . 2009-05-13 01:58 31232 --sh--r- c:\windows\System32\msfDX.dll
2008-03-16 13:30 . 2009-05-13 01:58 216064 --sh--r- c:\windows\System32\nbDX.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-08-24_15.52.03 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-01-09 20:18 . 2009-08-26 13:57 53428 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-08-26 16:36 79430 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-05-07 00:56 . 2009-08-26 16:36 13564 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3615268277-3926800693-1650498289-1005_UserData.bin
+ 2009-08-26 16:33 . 2009-08-26 16:33 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-08-26 16:33 . 2009-08-26 16:33 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2006-11-02 10:33 . 2009-08-26 14:02 650720 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-08-26 14:02 122622 c:\windows\System32\perfc009.dat
+ 2009-06-05 13:59 . 2009-08-25 15:50 143504545 c:\windows\winsxs\ManifestCache\6.0.6002.18005_001c11ba_blobs.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"AOL Fast Start"="c:\program files\AOL 9.5\AOL.EXE" [2009-08-10 50536]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2006-11-13 118784]
"AppMon Utility"="c:\program files\Sony\AppMonUtil\AppMonUtility.exe" [2006-11-15 415864]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2006-11-11 43128]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-09-29 151552]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-02-20 7770112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-02-20 81920]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2006-11-25 2134016]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 16:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2006-12-14 23:06 73728 ----a-w- c:\windows\System32\VESWinlogon.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=c:\windows\pss\Adobe Reader Synchronizer.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Free WebSite Tools.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Free WebSite Tools.lnk
backup=c:\windows\pss\Free WebSite Tools.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=c:\windows\pss\QuickBooks Update Agent.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^Users^Ownwer^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\users\Ownwer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"="0x00000000"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(:D:62,01,3a,34,c5,f5,c9,01

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3615268277-3926800693-1650498289-1005]
"EnableNotificationsRef"=dword:00000002

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{40BAA052-6F21-4FB5-A872-CC8BA96FA69B}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{37CC52F2-39F4-4731-935C-94CC8F312C7F}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{841DC118-DC5B-46AB-8AD0-5346AA9C6B47}"= UDP:c:\program files\BitComet\BitComet.exe:BitComet.exe
"{5C1FA1D5-7339-475B-A6FD-E40A8884D2C4}"= TCP:c:\program files\BitComet\BitComet.exe:BitComet.exe
"{97E94798-B24B-476C-90C8-CA53770352F9}"= UDP:c:\program files\Common Files\AOL\acs\AOLDial.exe:AOL Connectivity Service Dialer
"{BC1688CF-7179-43E7-9683-05B9B521CE0C}"= TCP:c:\program files\Common Files\AOL\acs\AOLDial.exe:AOL Connectivity Service Dialer
"{5EA6C23E-BC0C-483F-8216-BC2754D91B5D}"= UDP:c:\program files\Common Files\AOL\acs\AOLacsd.exe:AOL Connectivity Service
"{169957EF-0E93-425B-9712-D627FC07444D}"= TCP:c:\program files\Common Files\AOL\acs\AOLacsd.exe:AOL Connectivity Service
"{FA8D70FB-5211-487A-B9EB-34FB9E9E88A7}"= UDP:c:\program files\Common Files\AOL\1241668092\ee\aolsoftware.exe:AOL Shared Components
"{A8360307-1BDE-4942-B1E0-8AA1CDAF7838}"= TCP:c:\program files\Common Files\AOL\1241668092\ee\aolsoftware.exe:AOL Shared Components
"{943C826E-17A1-4C3E-9F4E-B1729D97C2EF}"= UDP:c:\program files\AOL 9.5\waol.exe:AOL
"{758EBDDD-981E-439F-BF24-4F243A2D1180}"= TCP:c:\program files\AOL 9.5\waol.exe:AOL
"{A759DFBF-6AB2-487D-AEDE-453AC1E48212}"= UDP:c:\program files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe:AOL TopSpeed
"{6C483883-4CFF-4FAC-9483-174538DF5CDC}"= TCP:c:\program files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe:AOL TopSpeed
"{B745CF04-F3FE-4758-8141-3FBD82A23101}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{961D9C77-2734-4CE1-8926-06DCD8556DB4}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{73D2FFFC-B8A8-4430-819A-0241A126AF42}"= UDP:c:\program files\Common Files\AOL\System Information\sinf.exe:AOL System Information
"{4B58E94F-4C3E-4BDB-9ED1-0A6603220C5C}"= TCP:c:\program files\Common Files\AOL\System Information\sinf.exe:AOL System Information
"{C9B1A609-022C-4A47-9652-F3974B553161}"= UDP:13285:BitComet 13285 TCP
"{D037E8AF-1295-47BF-9C2A-04E638AF4093}"= TCP:13285:BitComet 13285 UDP
"TCP Query User{A43929CE-881A-4CC7-82F5-7B1ED30D5DE0}c:\\program files\\bitcomet\\bitcomet.exe"= UDP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"UDP Query User{802EFC40-D9F3-46E4-AA94-77456608C424}c:\\program files\\bitcomet\\bitcomet.exe"= TCP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"{C1C127E5-0C8F-4B53-873F-FED2CDC1BD90}"= Disabled:UDP:5353:Adobe CSI CS4
"{40527ECD-B9D7-4F0D-970D-CD7C64614FEC}"= Disabled:UDP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{B3057D6C-B043-469A-9FAF-636A80848CD6}"= Disabled:TCP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"TCP Query User{3A9F951F-5947-4C29-8A40-109FF58ADFC9}c:\\program files\\icq6.5\\icq.exe"= UDP:c:\program files\icq6.5\icq.exe:ICQ
"UDP Query User{4F0C3FF4-5D0A-4B36-86A8-7DBE55F4E110}c:\\program files\\icq6.5\\icq.exe"= TCP:c:\program files\icq6.5\icq.exe:ICQ
"{6ADEA974-7745-47F9-9A88-11C7443552DF}"= UDP:21203:Bit Comet
"{C96D0FC7-D010-46EE-AEEB-B6DD11EA6348}"= TCP:21203:BitComet 21203 UDP
"{853FECD1-A5B1-49D7-8453-D992EC01B594}"= Disabled:UDP:c:\program files\Adobe\Adobe Photoshop CS4\Photoshop.exe:Adobe Photoshop CS4
"{4D799B11-6623-450B-AA76-C7DE683C915B}"= Disabled:TCP:c:\program files\Adobe\Adobe Photoshop CS4\Photoshop.exe:Adobe Photoshop CS4
"TCP Query User{83BD6E2D-5AAB-4180-846A-61C3DC78319A}c:\\program files\\aol 9.5\\waol.exe"= UDP:c:\program files\aol 9.5\waol.exe:AOL Software
"UDP Query User{E5B66B7F-A7A6-43FD-A943-ED95F812D7E5}c:\\program files\\aol 9.5\\waol.exe"= TCP:c:\program files\aol 9.5\waol.exe:AOL Software
"{9FB6AE73-2661-489A-888A-01BAEB67193C}"= UDP:21203:BitComet 21203 TCP
"{847344ED-3778-40ED-AABB-6526300DF2BF}"= TCP:21203:BitComet 21203 UDP
"{6D7F3A44-7D7C-45D7-AF1D-EE2946118136}"= UDP:c:\program files\Common Files\AOL\acs\AOLDial.exe:AOL Connectivity Service Dialer
"{3BB238BE-AE2E-4017-9B1E-40524B019D91}"= TCP:c:\program files\Common Files\AOL\acs\AOLDial.exe:AOL Connectivity Service Dialer
"{ADAF0980-A9E0-48A0-9A77-66B001EA04FD}"= UDP:c:\program files\Common Files\AOL\acs\AOLacsd.exe:AOL Connectivity Service
"{CC00F8C3-D10D-405F-9C21-2E81C315904F}"= TCP:c:\program files\Common Files\AOL\acs\AOLacsd.exe:AOL Connectivity Service
"{F41B951F-D61F-45D0-BB91-F7C740F0A0FB}"= UDP:c:\program files\Common Files\AOL\1241668092\ee\aolsoftware.exe:AOL Shared Components
"{70D36294-391F-4826-BCC1-794E0228BA1A}"= TCP:c:\program files\Common Files\AOL\1241668092\ee\aolsoftware.exe:AOL Shared Components
"{5C2ED012-78A5-49BB-A0E9-48F85506BDD9}"= UDP:c:\program files\AOL 9.5a\waol.exe:AOL
"{B8EB4792-828B-44F5-91BB-8A78DD886049}"= TCP:c:\program files\AOL 9.5a\waol.exe:AOL
"{8601CEF8-4E8D-4E01-91BA-43C183CD1B63}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{F30DA1B4-73FF-442A-B773-1279F3DD82CB}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{DEFB26F1-76D6-484B-A875-A64594796A9E}"= UDP:c:\program files\Common Files\AOL\System Information\sinf.exe:AOL System Information
"{B2C39C37-9C17-4846-A920-7FEE41EA50A0}"= TCP:c:\program files\Common Files\AOL\System Information\sinf.exe:AOL System Information
"{DFD1315C-1455-44F7-9397-0521CDF00C2B}"= UDP:c:\program files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe:AOL
"{F3D290E0-EC7E-403B-89C9-832F6CD0E2F1}"= TCP:c:\program files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe:AOL
"TCP Query User{8CF1AA9F-64F4-4664-9D78-654923AE24F3}c:\\program files\\warez\\warez.exe"= UDP:c:\program files\warez\warez.exe:Warez
"UDP Query User{A493BC83-54FF-486D-B396-DC9F0C90BF85}c:\\program files\\warez\\warez.exe"= TCP:c:\program files\warez\warez.exe:Warez
"{37411C69-05AF-4BAD-BB17-C25921811899}"= UDP:9000:warez
"{888391BB-99C9-46E8-8436-29F9FE96BFEB}"= UDP:c:\program files\AOL 9.5b\waol.exe:AOL
"{712B919F-B742-4DA1-A136-2466D833E008}"= TCP:c:\program files\AOL 9.5b\waol.exe:AOL
"{C551ADF0-37EF-4E58-BBAD-646FA2E472AB}"= UDP:c:\program files\AOL 9.5c\waol.exe:AOL
"{697B1478-1915-445A-99FA-E87271EBC87B}"= TCP:c:\program files\AOL 9.5c\waol.exe:AOL
"{FF24500F-7EF4-41F3-9D0F-99C764297831}"= UDP:c:\program files\AOL 9.5d\waol.exe:AOL
"{0FBCEB51-7742-456D-9F60-10186220B021}"= TCP:c:\program files\AOL 9.5d\waol.exe:AOL
"{FD148DFC-6537-412D-A223-BD040F677E44}"= UDP:c:\program files\AOL 9.5e\waol.exe:AOL
"{6EF1EB1B-1708-480F-B8CD-138CDBF8284B}"= TCP:c:\program files\AOL 9.5e\waol.exe:AOL
"{03EB1BFC-C696-483F-B4B4-F29D13A280E1}"= h:\setup\hpznui01.exe:hpznui01.exe
"{B8E3C04A-93BD-4186-8BF6-DDFF4B4E3391}"= TCP:427|RPort=427|c:\windows\system32\svchost.exe|Svc=HPSLPSVC:SLP_Service
"{468D631B-DE87-4B4B-B4B7-EB8C8230FF07}"= c:\program files\HP\digital imaging\bin\hpqtra08.exe:hpqtra08.exe
"{3D6FDB19-41BF-42CE-BC3C-DD731DF1A3B8}"= c:\program files\HP\digital imaging\bin\hpqste08.exe:hpqste08.exe
"{660482BB-0B27-428D-8BDE-EE52E8B85C1F}"= c:\program files\HP\digital imaging\bin\hpofxm08.exe:hpofxm08.exe
"{7CB13788-062D-4789-9354-0660A68F6793}"= c:\program files\HP\digital imaging\bin\hposfx08.exe:hposfx08.exe
"{6923878F-E860-44DE-BB8F-15D3B3ABF4A6}"= c:\program files\HP\digital imaging\bin\hposid01.exe:hposid01.exe
"{7C602645-4EC5-4A7F-A99A-548AA9147389}"= c:\program files\HP\digital imaging\bin\hpqkygrp.exe:hpqkygrp.exe
"{96742C78-9FA4-4471-999D-E6F1D1EAF052}"= c:\program files\HP\digital imaging\bin\hpzwiz01.exe:hpzwiz01.exe
"{592025E4-7947-440F-AFB3-7A03B2E0EAD4}"= UDP:c:\program files\AOL 9.5f\waol.exe:AOL
"{E24EE7DA-5047-4900-A793-E6531584BAED}"= TCP:c:\program files\AOL 9.5f\waol.exe:AOL

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [6/24/2009 11:02 AM 64160]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [1/15/2009 4:17 PM 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/15/2009 4:17 PM 55024]
R2 CSHelper;CopySafe Helper Service;c:\windows\System32\CSHelper.exe [8/4/2009 5:30 PM 266240]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\Firebird\Firebird_2_1\bin\fbguard.exe -s DefaultInstance --> c:\program files\Firebird\Firebird_2_1\bin\fbguard.exe -s DefaultInstance [?]
R2 MSSQL$VAIO_VEDB;SQL Server (VAIO_VEDB);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [12/1/2006 3:11 PM 28933976]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\Firebird\Firebird_2_1\bin\fbserver.exe -s DefaultInstance --> c:\program files\Firebird\Firebird_2_1\bin\fbserver.exe -s DefaultInstance [?]
R3 R5U870FLx86;R5U870 UVC Lower Filter ;c:\windows\System32\drivers\R5U870FLx86.sys [1/9/2007 2:18 PM 72704]
R3 R5U870FUx86;R5U870 UVC Upper Filter ;c:\windows\System32\drivers\R5U870FUx86.sys [1/9/2007 2:18 PM 43904]
R3 slim;Sony Lucid Integrated Mpeg encoder;c:\windows\System32\drivers\slim.sys [1/9/2007 2:30 PM 699264]
R3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\System32\drivers\SonyImgF.sys [1/9/2007 3:10 PM 30976]
R3 ti21sony;ti21sony;c:\windows\System32\drivers\ti21sony.sys [1/9/2007 2:29 PM 227328]
R3 wsvad_driver;WS Audio Device;c:\windows\System32\drivers\VirtualAudio.sys [8/7/2009 4:54 PM 16896]
S3 netr28u;Linksys USB Wireless LAN Card Driver for Vista;c:\windows\System32\drivers\netr28u.sys [12/14/2007 6:16 PM 570880]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [1/15/2009 4:17 PM 7408]
S3 USBAVCap;AVerMedia USB TV Tuner Device;c:\windows\System32\drivers\USBAVCap.sys [1/9/2007 2:17 PM 774528]
S3 VAIOMediaPlatform-UCLS-AppServer;VAIO Media Content Collection;c:\program files\Sony\VAIO Media Integrated Server\UCLS.exe [10/2/2007 12:57 AM 741376]
S3 VAIOMediaPlatform-UCLS-HTTP;VAIO Media Content Collection (HTTP);c:\program files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe [10/2/2007 12:57 AM 397312]
S3 VAIOMediaPlatform-UCLS-UPnP;VAIO Media Content Collection (UPnP);c:\program files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe [10/2/2007 12:57 AM 1089536]
S4 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [6/8/2009 2:55 PM 108289]
S4 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 2:06 PM 1003344]
S4 SlingAgentService;SlingAgentService;c:\program files\Sling Media\SlingAgent\SlingAgentService.exe [4/27/2009 6:09 PM 93960]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - NWLNKFWD

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-08-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3615268277-3926800693-1650498289-1005Core.job
- c:\users\Ownwer\AppData\Local\Google\Update\GoogleUpdate.exe [2009-06-12 15:48]

2009-08-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3615268277-3926800693-1650498289-1005UA.job
- c:\users\Ownwer\AppData\Local\Google\Update\GoogleUpdate.exe [2009-06-12 15:48]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
Trusted Zone: musicmatch.com\online
FF - ProfilePath - c:\users\Ownwer\AppData\Roaming\Mozilla\Firefox\Profiles\9s40vgdk.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.aol.com/aolcom/search?invocationType=tb50ffTB50CL-chromesbox-en-us&query=
FF - prefs.js: browser.search.selectedEngine - AOL Search
FF - prefs.js: browser.startup.homepage - hxxp://www.aol.com
FF - prefs.js: keyword.URL - hxxp://search.aol.com/aolcom/search?invocationType=tb50ffTB50CL-ab-en-us&query=
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\MpcStar\Codecs\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\MpcStar\Codecs\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - plugin: c:\users\Ownwer\AppData\Local\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: protocol-handler.warn-external.dnUpdate - falsec:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.

**************************************************************************
scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files:

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\audiodg.exe
c:\program files\Firebird\Firebird_2_1\bin\fbguard.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
c:\program files\Sony\VAIO Event Service\VESMgr.exe
c:\program files\Sony\VAIO Update 3\VAIOUpdt.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
c:\program files\Sony\Wireless Switch Setting Utility\Switcher.exe
c:\program files\Sony\VAIO Event Service\VESMgrSub.exe
c:\windows\System32\drivers\XAudio.exe
c:\windows\System32\WUDFHost.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
c:\program files\Apoint\ApMsgFwd.exe
c:\program files\AOL 9.5\waol.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\program files\Apoint\ApntEx.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosOBEX.exe
c:\program files\Firebird\Firebird_2_1\bin\fbserver.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Common Files\AOL\acs\AOLacsd.exe
c:\program files\AOL 9.5\shellmon.exe
c:\program files\Common Files\AOL\1241668092\ee\aolsoftware.exe
.
**************************************************************************
.
Completion time: 2009-08-26 11:42 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-26 16:42
ComboFix2.txt 2009-08-25 15:14
ComboFix3.txt 2009-08-24 15:54
ComboFix4.txt 2009-08-21 18:42
ComboFix5.txt 2009-08-26 16:22

Pre-Run: 141,531,381,760 bytes free
Post-Run: 141,644,730,368 bytes free

532 --- E O F --- 2009-08-20 22:26
________________________________________________________________________________
_________________________________________________________________

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:54:06 AM, on 8/26/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Sony\AppMonUtil\AppMonUtility.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\AOL 9.5\waol.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Apoint\Apntex.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\Program Files\AOL 9.5\shellmon.exe
C:\Program Files\Common Files\AOL\1241668092\ee\aolsoftware.exe
C:\Program Files\Common Files\AOL\Topspeed\3.0\aoltpsd3.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Common Files\AOL\1241668092\ee\aolsoftware.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [AppMon Utility] "C:\Program Files\Sony\AppMonUtil\AppMonUtility.exe" @@@Start
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.5\AOL.EXE" -b
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: CopySafe Helper Service (CSHelper) - Unknown owner - C:\Windows\system32\CSHelper.exe
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - FirebirdSQL Project - C:\Program Files\Firebird\Firebird_2_1\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - FirebirdSQL Project - C:\Program Files\Firebird\Firebird_2_1\bin\fbserver.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 7103 bytes

#9
screen317

    MBAM Sentinel

  • Moderators
  • PipPipPipPipPipPip
  • 16,432 posts
  • Gender:Male
  • Location:Los Angeles
Hi,

Please use the Internet Explorer browser and click here to use the F-Secure Online Scanner.
  • Click Start Scanning.
  • You should get a notification bar (on top) to install the ActiveX control.
  • Click on it and select to install the ActiveX.
  • Once the ActiveX is installed, you should accept the License terms by clicking OK below to start the scan.
  • In case you are having problems with installing the ActiveX/starting the scan, please read here.
  • Click the Full System Scan button.
  • It will start to download scanner components and databases. This can take a while.
  • The main scan will start.
  • Once the scan has finished scanning, click the Automatic cleaning (recommended) button
  • It could be possible that your firewall gives an alert - allow it, because that's a connection you establish to submit infected files to F-Secure.
  • The cleaning can take a while, so please be patient.
  • Then click the Show report button and Copy/Paste what is present under results in your next reply.

Next, download my Security Check from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

-screen317
Chris Fistonich
Consumer Support Specialist

Posted Image

Follow us: Twitter, Become a fan: Facebook

#10
Fletch55

    New Member

  • Members
  • Pip
  • 18 posts
Ok downloaded the 2 programs and ran the scans which might I say took forever 3 hours to scan lol..Anywasy here are the reports in order as requested..
Scanning Report
Thursday, August 27, 2009 09:49:08 - 11:17:13

Computer name: OWNWER-PC
Scanning type: Scan system for malware, spyware and rootkits
Target: C:\
14 malware found
TrackingCookie.Questionmarket (spyware)

* System (Disinfected)

TrackingCookie.2o7 (spyware)

* System (Disinfected)

TrackingCookie.Advertising (spyware)

* System (Disinfected)

TrackingCookie.Atdmt (spyware)

* System (Disinfected)

TrackingCookie.Doubleclick (spyware)

* System (Disinfected)

TrackingCookie.Mediaplex (spyware)

* System (Disinfected)

TrackingCookie.Atwola (spyware)

* System (Disinfected)

Gen:Rootkit.Heur.auW@t49K!ho (spyware)

* System (Disinfected)

TrackingCookie.Yieldmanager (spyware)

* System (Disinfected)

Gen:Rootkit.Heur.auW@t49K!ho (virus)

* C:\WINDOWS\SYSTEM32\DRIVERS\BLBDRIVE.SYS (Renamed & Submitted)

Gen:Rootkit.Heur.auW@t49K!ho (virus)

* C:\WINDOWS\SYSTEM32\DRIVERS\IPINIP.SYS (Not cleaned & Submitted)

Gen:Rootkit.Heur.auW@t49K!ho (virus)

* C:\WINDOWS\SYSTEM32\DRIVERS\NWLNKFLT.SYS (Not cleaned & Submitted)

Gen:Rootkit.Heur.auW@t49K!ho (virus)

* C:\WINDOWS\SYSTEM32\DRIVERS\NWLNKFWD.SYS (Not cleaned & Submitted)

Trojan.Generic.1754471 (virus)

* C:\PROGRAM FILES\WONDERSHARE\FLASH SLIDESHOW BUILDER\WS_FLASHPLAYER.EXE (Renamed & Submitted)

Statistics
Scanned:

* Files: 161994
* System: 4606
* Not scanned: 19

Actions:

* Disinfected: 9
* Renamed: 2
* Deleted: 0
* Not cleaned: 3
* Submitted: 5

Files not scanned:

* C:\PAGEFILE.SYS
* C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT
* C:\WINDOWS\SYSTEM32\CONFIG\SAM
* C:\WINDOWS\SYSTEM32\CONFIG\SECURITY
* C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE
* C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM
* C:\WINDOWS\SYSTEM32\CONFIG\COMPONENTS
* C:\WINDOWS\SYSTEM32\CONFIG\REGBACK\COMPONENTS
* C:\WINDOWS\SYSTEM32\CONFIG\REGBACK\DEFAULT
* C:\WINDOWS\SYSTEM32\CONFIG\REGBACK\SECURITY
* C:\WINDOWS\SYSTEM32\CONFIG\REGBACK\SAM
* C:\WINDOWS\SYSTEM32\CONFIG\REGBACK\SYSTEM
* C:\WINDOWS\SYSTEM32\CONFIG\REGBACK\SOFTWARE
* C:\WINDOWS\SYSTEM32\CATROOT2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\CATDB
* C:\WINDOWS\SYSTEM32\CATROOT2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\CATDB
* C:\SYSTEM VOLUME INFORMATION\MOUNTPOINTMANAGERREMOTEDATABASE
* C:\SYSTEM VOLUME INFORMATION\{ECCACB74-9247-11DE-8FFB-0016FEF4718C}{3808876B-C176-4E48-B7AE-04046E6CC752}
* C:\PROGRAMDATA\MICROSOFT\CRYPTO\RSA\MACHINEKEYS\DF7A4E0CFC34F70BD64E5BCBC27CC091_82FC3CE2-981F-45AC-AF5C-24B443E8C595
* C:\BOOT\BCD

Options
Scanning engines:

Scanning options:

* Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB LNK WSF {* PDF ZL? XML XXX ANI AVB BAT CMD JOB LSP MAP MHT MIF PHP POT SWF WMF NWS TAR
* Use advanced heuristics

Copyright © 1998-2009 Product support | Send virus sample to F-Secure
F-Secure assumes no responsibility for material created or published by third parties that F-Secure World Wide Web pages have a link to. Unless you have clearly stated otherwise, by submitting material to any of our servers, for example by E-mail or via our F-Secure's CGI E-mail, you agree that the material you make available may be published in the F-Secure World Wide Pages or hard-copy publications. You will reach F-Secure public web site by clicking on underlined links. While doing this, your access will be logged to our private access statistics with your domain name. This information will not be given to any third party. You agree not to take action against us in relation to material that you submit. Unless you have clearly stated otherwise, by submitting material you warrant that F-Secure may incorporate any concepts described in it in the F-Secure products/publications without liability.



________________________________________________________________________________
__________________________________________________________________



Results of screen317's Security Check version 0.98.9
Windows Vista Service Pack 2
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Disabled!
Avira AntiVir Personal - Free Antivirus


WMIC entry does not exist for antivirus; attempting automatic update.
Avira updated!
``````````````````````````````
Anti-malware/Other Utilities Check:

Ad-Aware
CoffeeCup Spyware Remover 2.0
SUPERAntiSpyware Free Edition
Malwarebytes' Anti-Malware
HijackThis 2.0.2
CCleaner (remove only)
Java™ 6 Update 15
Java™ SE Runtime Environment 6
Adobe Flash Player 10
Adobe Reader 8.1.6
Out of date Adobe Reader installed!
``````````````````````````````
Process Check:
objlist.exe by Laurent

Ad-Aware AAWService.exe is disabled!
Ad-Aware AAWTray.exe is disabled!


``````````````````````````````
DNS Vulnerability Check:

GREAT! (Not vulnerable to DNS cache poisoning)

`````````End of Log```````````

#11
Fletch55

    New Member

  • Members
  • Pip
  • 18 posts
Ok i know you havent asked yet but since we are on what seems to be opposite schedules of the day to be here I ran a new mbam scan and hijack and here are the logs.Just in case this would be needed for the next step.

Malwarebytes' Anti-Malware 1.40
Database version: 2699
Windows 6.0.6002 Service Pack 2

8/27/2009 11:31:50 AM
mbam-log-2009-08-27 (11-31-50).txt

Scan type: Quick Scan
Objects scanned: 91408
Time elapsed: 6 minute(s), 17 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Windows\system32\drivers\mrxdavv.sys (Rootkit.Agent.H) -> Delete on reboot.
C:\Windows\system32\kwave.sys (Trojan.Agent) -> Delete on reboot.


________________________________________________________________________________
_________________________________________________________________-

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:33:53 AM, on 8/27/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Sony\AppMonUtil\AppMonUtility.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\Program Files\AOL 9.5\waol.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\Program Files\AOL 9.5\shellmon.exe
C:\Program Files\Common Files\AOL\1241668092\ee\aolsoftware.exe
C:\Program Files\Common Files\AOL\Topspeed\3.0\aoltpsd3.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [AppMon Utility] "C:\Program Files\Sony\AppMonUtil\AppMonUtility.exe" @@@Start
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.5\AOL.EXE" -b
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O16 - DPF: {076169AA-8C3D-4CFC-AC23-3ACA88FC21B5} (F-Secure Online Scanner Launcher) - http://download.sp.f-secure.com/ols/f-secu.../fslauncher.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: CopySafe Helper Service (CSHelper) - Unknown owner - C:\Windows\system32\CSHelper.exe
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - FirebirdSQL Project - C:\Program Files\Firebird\Firebird_2_1\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - FirebirdSQL Project - C:\Program Files\Firebird\Firebird_2_1\bin\fbserver.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 7539 bytes

#12
screen317

    MBAM Sentinel

  • Moderators
  • PipPipPipPipPipPip
  • 16,432 posts
  • Gender:Male
  • Location:Los Angeles
Hi,

Please delete your copy of ComboFix, download the latest version from here, and save it to your Desktop. Do not run it yet.


Next, please open Notepad. Copy and paste the text in the Code box below into Notepad:

http://www.malwarebytes.org/forums/index.php?showtopic=22234
Collect::
C:\WINDOWS\SYSTEM32\DRIVERS\BLBDRIVE.SYS
C:\WINDOWS\SYSTEM32\DRIVERS\IPINIP.SYS
C:\WINDOWS\SYSTEM32\DRIVERS\NWLNKFLT.SYS
C:\WINDOWS\SYSTEM32\DRIVERS\NWLNKFWD.SYS
C:\Windows\system32\drivers\mrxdavv.sys
C:\Windows\system32\kwave.sys

Save this as CFScript.txt


Posted Image


Refering to the picture above, drag CFScript.txt into ComboFix.exe

When finished, it shall produce a log for you. Post that log in your next reply.

**Note**

When CF finishes running, the ComboFix log will open along with a message box--do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.

-screen317
Chris Fistonich
Consumer Support Specialist

Posted Image

Follow us: Twitter, Become a fan: Facebook

#13
Fletch55

    New Member

  • Members
  • Pip
  • 18 posts
Ok did as instructed and have the log from the combofix run. Must be doing some good as i also ran mbam again after a restart and both seem to be gone. I am also posting the mbam and hijack logs I got after the combofix run.

ComboFix 09-08-27.A3 - Ownwer 08/28/2009 9:24.5.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2045.965 [GMT -5:00]
Running from: c:\users\Ownwer\Desktop\ComboFix.exe
Command switches used :: c:\users\Ownwer\Desktop\CFScript.txt
AV: Doctor Web Anti-Virus *On-access scanning enabled* (Updated) {3454C8F1-ECBC-4180-A6F4-04632FBA762B}
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

file zipped: c:\windows\SYSTEM32\DRIVERS\IPINIP.SYS
file zipped: c:\windows\SYSTEM32\DRIVERS\NWLNKFLT.SYS
file zipped: c:\windows\SYSTEM32\DRIVERS\NWLNKFWD.SYS
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\SYSTEM32\DRIVERS\IPINIP.SYS
c:\windows\SYSTEM32\DRIVERS\NWLNKFLT.SYS
c:\windows\SYSTEM32\DRIVERS\NWLNKFWD.SYS
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe

.
((((((((((((((((((((((((( Files Created from 2009-07-28 to 2009-08-28 )))))))))))))))))))))))))))))))
.

2009-08-28 14:32 . 2009-08-28 14:32 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-08-28 14:32 . 2009-08-28 14:32 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-08-28 14:32 . 2009-08-28 14:32 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2009-08-27 20:33 . 2009-08-28 13:54 -------- d-----w- c:\program files\AOL 9.5a
2009-08-27 20:32 . 2009-08-27 20:32 45872 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.101.2\comps\acs\AcsInstA.dll
2009-08-27 20:30 . 2009-08-27 20:30 74536 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.101.2\comps\acs\comps\instSup.dll
2009-08-27 20:29 . 2009-08-27 20:29 35688 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.101.2\comps\acs\postproc.exe
2009-08-27 20:29 . 2009-08-27 20:29 1485840 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.101.2\comps\acs\comps\acscore.exe
2009-08-27 20:29 . 2009-08-27 20:29 54832 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.101.2\comps\parcon\AOLParconLink.exe
2009-08-27 20:29 . 2009-08-27 20:29 188160 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.101.2\comps\desk\dtblpins.exe
2009-08-27 20:29 . 2009-08-27 20:29 10800 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.101.2\comps\afix\wsfixchk.dll
2009-08-27 20:29 . 2009-08-27 20:29 711592 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.101.2\comps\sysinfo\SinfInst.exe
2009-08-27 20:29 . 2009-08-27 20:29 62248 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.101.2\comps\acs\comps\ocpgc.exe
2009-08-27 20:29 . 2009-08-27 20:29 11312 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.101.2\comps\acs\ecuchk.dll
2009-08-27 18:38 . 2009-04-07 21:01 101496 ----a-w- c:\windows\system32\drivers\dwprot.sys
2009-08-27 18:38 . 2009-08-27 18:38 -------- d-----w- c:\program files\Common Files\Doctor Web
2009-08-27 18:38 . 2009-08-28 14:13 -------- d-----w- c:\program files\DrWeb
2009-08-27 18:38 . 2009-08-27 18:38 -------- d-----w- c:\programdata\Doctor Web
2009-08-27 17:45 . 2009-08-27 20:10 -------- d-----w- c:\users\Ownwer\DoctorWeb
2009-08-27 16:59 . 2009-08-28 14:32 -------- d-----w- c:\users\Ownwer\AppData\Local\temp
2009-08-27 16:01 . 2009-08-27 19:19 -------- d-----w- c:\users\Ownwer\AppData\Local\Adobe
2009-08-27 14:48 . 2009-08-27 14:48 -------- d-----w- c:\programdata\F-Secure
2009-08-26 16:44 . 2009-06-22 10:09 2048 ----a-w- c:\windows\system32\tzres.dll
2009-08-25 19:00 . 2009-08-25 19:00 1962544 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.101.2\comps\flash\flashax.exe
2009-08-25 19:00 . 2009-08-25 19:00 6144 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.101.2\comps\afix\ocfcheck.dll
2009-08-25 19:00 . 2009-08-25 19:00 57344 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.101.2\comps\tpspd\tsverchk.dll
2009-08-25 19:00 . 2009-08-25 19:00 49152 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.101.2\comps\tpspd\Dacldll.dll
2009-08-25 19:00 . 2009-08-25 19:00 45056 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.101.2\comps\sysinfo\SiNdInst.dll
2009-08-25 19:00 . 2009-08-25 19:00 845814 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.101.2\comps\muinst\muinst.exe
2009-08-25 19:00 . 2009-08-25 19:00 6144 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.101.2\comps\tb\tbinst.dll
2009-08-25 19:00 . 2009-08-25 19:00 3858056 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.101.2\comps\vwpt\Vwpt.exe
2009-08-25 19:00 . 2009-08-25 19:00 61440 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.101.2\comps\vwpt\VPPrePop.exe
2009-08-25 19:00 . 2009-08-25 19:00 49152 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.101.2\comps\vwpt\AOLVPChk.dll
2009-08-25 18:56 . 2009-08-25 18:56 499712 ----a-w- c:\windows\system32\msvcp71.dll
2009-08-25 18:56 . 2009-08-25 18:56 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-08-25 17:32 . 2009-08-27 16:41 -------- d-----w- c:\users\Ownwer\AppData\Local\AOL
2009-08-25 15:44 . 2009-08-25 16:01 680 ----a-w- c:\users\Ownwer\AppData\Local\d3d9caps.dat
2009-08-24 14:54 . 2009-08-24 16:01 -------- d-----w- c:\program files\Common Files\PC Tools
2009-08-24 14:54 . 2009-08-24 16:01 -------- d-----w- c:\program files\Spyware Doctor
2009-08-21 18:05 . 2009-08-21 18:05 -------- d-----w- c:\program files\Trend Micro
2009-08-21 15:43 . 2009-08-25 15:24 35 ----a-w- c:\users\Ownwer\AppData\Roaming\SetValue.bat
2009-08-21 13:46 . 2009-08-21 13:46 16 ----a-w- c:\windows\pxydb.dat
2009-08-20 22:22 . 2009-06-15 14:54 175104 ----a-w- c:\windows\system32\wdigest.dll
2009-08-20 22:22 . 2009-06-15 14:53 270848 ----a-w- c:\windows\system32\schannel.dll
2009-08-20 22:22 . 2009-06-15 14:53 218624 ----a-w- c:\windows\system32\msv1_0.dll
2009-08-20 22:22 . 2009-06-15 14:52 499712 ----a-w- c:\windows\system32\kerberos.dll
2009-08-20 22:22 . 2009-06-15 23:15 439864 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-08-20 22:22 . 2009-06-15 14:53 72704 ----a-w- c:\windows\system32\secur32.dll
2009-08-20 22:22 . 2009-06-15 14:52 1259008 ----a-w- c:\windows\system32\lsasrv.dll
2009-08-20 22:22 . 2009-06-15 12:48 9728 ----a-w- c:\windows\system32\lsass.exe
2009-08-20 20:32 . 2009-08-20 20:32 -------- d-----w- c:\program files\Brice Lambson
2009-08-20 17:33 . 2009-08-20 17:33 -------- d-----w- c:\users\Ownwer\AppData\Roaming\Nero
2009-08-20 17:12 . 2009-08-20 17:19 -------- d-----w- c:\program files\Nero
2009-08-20 17:12 . 2009-08-20 17:20 -------- d-----w- c:\program files\Common Files\Nero
2009-08-20 17:12 . 2009-08-20 17:14 -------- d-----w- c:\programdata\Nero
2009-08-18 11:17 . 2009-08-18 11:17 103216 ----a-w- c:\windows\system32\AOLDial.dll
2009-08-18 11:17 . 2009-08-18 11:17 33400 ----a-w- c:\windows\system32\drivers\atwpkt264.sys
2009-08-18 11:17 . 2009-08-18 11:17 24368 ----a-w- c:\windows\system32\drivers\atwpkt2.sys
2009-08-17 14:11 . 2009-08-17 14:11 -------- d-----w- c:\program files\Linksys
2009-08-17 14:10 . 2009-08-17 14:10 -------- d-----w- c:\windows\{7F7635FC-B887-49FA-8526-094724C01A6E}
2009-08-12 22:14 . 2009-07-17 13:54 71680 ----a-w- c:\windows\system32\atl.dll
2009-08-12 22:14 . 2009-06-10 11:42 160256 ----a-w- c:\windows\system32\wkssvc.dll
2009-08-12 22:14 . 2009-06-04 12:07 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-08-12 22:14 . 2009-06-10 11:38 91136 ----a-w- c:\windows\system32\avifil32.dll
2009-08-12 22:14 . 2009-07-15 12:39 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-08-12 22:14 . 2009-07-15 12:39 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-08-12 22:14 . 2009-07-15 12:39 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-08-12 22:14 . 2009-07-15 12:40 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-08-12 14:41 . 2009-08-13 13:35 -------- d-----w- c:\program files\AOL 9.5
2009-08-11 22:13 . 2009-08-11 22:13 -------- d-----w- c:\program files\PFPortChecker
2009-08-07 21:54 . 2008-08-13 02:08 16896 ----a-w- c:\windows\system32\drivers\VirtualAudio.sys
2009-08-07 21:54 . 2009-08-07 21:54 -------- d-----w- c:\program files\Daniusoft
2009-08-07 18:41 . 2009-08-07 18:41 -------- d-----w- c:\users\Ownwer\AppData\Roaming\TigerPlayer
2009-08-07 18:40 . 2009-08-07 18:40 -------- d-----w- c:\program files\MpcStar
2009-08-06 23:09 . 2009-08-06 23:12 -------- d-----w- c:\users\Ownwer\AppData\Roaming\DivX
2009-08-06 23:06 . 2009-08-06 23:06 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2009-08-06 23:05 . 2009-08-06 23:06 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-08-06 23:05 . 2009-08-06 23:07 -------- d-----w- c:\program files\DivX
2009-08-06 15:34 . 2009-08-06 15:47 -------- d-----w- c:\program files\AOL 9.5h
2009-08-04 22:30 . 2009-08-04 22:30 266240 ----a-w- c:\windows\system32\CSHelper.exe
2009-08-04 22:30 . 2009-08-04 22:30 225280 ----a-w- c:\windows\system32\CSInstru.DLL
2009-08-03 23:12 . 2009-08-03 23:12 -------- d-----w- c:\program files\SpacialAudio
2009-08-03 23:12 . 2007-10-16 15:07 442368 ----a-w- c:\windows\system32\GDS32.DLL
2009-08-03 23:12 . 2005-09-23 05:05 626688 ----a-w- c:\windows\system32\msvcr80.dll
2009-08-03 23:12 . 2005-09-23 05:05 548864 ----a-w- c:\windows\system32\msvcp80.dll
2009-08-03 23:12 . 2009-08-03 23:12 -------- d-----w- c:\program files\Firebird

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-28 14:19 . 2009-05-12 00:44 -------- d-----w- c:\program files\Media Resizer PRO
2009-08-27 20:40 . 2009-05-07 03:51 -------- d-----w- c:\users\Ownwer\AppData\Roaming\AOL
2009-08-27 20:34 . 2007-10-02 05:03 -------- d-----w- c:\program files\Common Files\AOL
2009-08-27 20:33 . 2009-05-07 03:48 -------- d-----w- c:\program files\Common Files\aolshare
2009-08-27 20:33 . 2009-05-07 03:48 -------- d-----w- c:\programdata\AOL
2009-08-27 20:32 . 2009-08-27 20:31 23684192 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.101.2\noneCodesignFilesBundle.exe
2009-08-27 20:31 . 2009-08-27 20:31 75112 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.101.2\comps\acs\instSup.dll
2009-08-27 20:31 . 2009-08-27 20:31 223152 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.101.2\comps\afix\wsfinst.exe
2009-08-27 20:31 . 2009-08-27 20:31 127224 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.101.2\comps\afix\afixlang.exe
2009-08-27 20:31 . 2009-08-27 20:31 15144 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.101.2\comps\acs\comps\ocpchk.dll
2009-08-27 20:31 . 2009-08-27 20:31 260040 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.101.2\comps\acs\ecuinst.exe
2009-08-27 20:31 . 2009-08-27 20:31 3346736 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.101.2\comps\acs\comps\ocpinst.exe
2009-08-27 20:31 . 2009-08-27 20:31 21296 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.101.2\comps\acs\comps\acsshutd.exe
2009-08-27 20:31 . 2009-08-27 20:31 45872 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.101.2\comps\acs\comps\AcsInstA.dll
2009-08-27 20:31 . 2009-08-27 20:31 355592 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.101.2\comps\afix\afixinst.exe
2009-08-27 20:31 . 2009-08-27 20:31 900968 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.101.2\waol-0.4337.101.2.exe
2009-08-27 20:31 . 2009-08-27 20:31 470224 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.101.2\comps\desk\dtbsetup.exe
2009-08-27 20:31 . 2009-08-27 20:30 964168 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.101.2\comps\acs\comps\acslaeu.exe
2009-08-26 16:00 . 2009-05-11 14:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-26 16:00 . 2009-05-11 14:22 3942048 ----a-w- c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-08-25 16:01 . 2009-05-07 17:20 -------- d-----w- c:\program files\UltraExplorer
2009-08-25 15:30 . 2009-05-11 14:25 117760 ----a-w- c:\users\Ownwer\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-08-25 15:24 . 2009-08-21 15:43 691 ----a-w- c:\users\Ownwer\AppData\Roaming\GetValue.vbs
2009-08-24 16:36 . 2009-05-07 00:55 204720 ----a-w- c:\users\Ownwer\AppData\Local\GDIPFONTCACHEV1.DAT
2009-08-24 15:27 . 2009-05-07 00:48 -------- d-----w- c:\program files\BitComet
2009-08-24 14:42 . 2009-05-13 18:21 -------- d-----w- c:\users\Ownwer\AppData\Roaming\Corel
2009-08-21 13:46 . 2009-08-21 13:46 8432 ----a-w- c:\windows\system32\drivers\BLBDRIVE.0YS
2009-08-17 14:11 . 2007-01-09 20:14 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-14 14:43 . 2009-07-08 22:30 -------- d-----w- c:\program files\HP
2009-08-07 18:40 . 2009-06-05 17:54 -------- d-----w- c:\program files\QuickTime
2009-08-07 18:40 . 2009-06-05 17:54 -------- d-----w- c:\programdata\Apple Computer
2009-08-05 13:56 . 2007-01-09 19:39 -------- d-----w- c:\program files\Java
2009-08-03 22:32 . 2009-08-06 15:30 900968 ----a-w- c:\programdata\AOL Downloads\SUD4444\waol-0.4337.89.1.exe
2009-08-03 22:10 . 2009-08-06 15:30 1914000 ----a-w- c:\programdata\AOL Downloads\SUD4444\comps\flash\flashax.exe
2009-08-03 22:09 . 2009-08-06 15:30 1612544 ----a-w- c:\programdata\AOL Downloads\SUD4444\comps\acs\comps\acslang.exe
2009-08-03 22:09 . 2009-08-06 15:30 964544 ----a-w- c:\programdata\AOL Downloads\SUD4444\comps\acs\comps\acslaeu.exe
2009-08-03 22:09 . 2009-08-06 15:30 45864 ----a-w- c:\programdata\AOL Downloads\SUD4444\comps\acs\comps\AcsInstA.dll
2009-08-03 22:09 . 2009-08-06 15:30 37672 ----a-w- c:\programdata\AOL Downloads\SUD4444\comps\acs\comps\AcsInstC.dll
2009-08-03 22:09 . 2009-08-06 15:30 45864 ----a-w- c:\programdata\AOL Downloads\SUD4444\comps\acs\AcsInstA.dll
2009-08-03 22:09 . 2009-08-06 15:30 1484136 ----a-w- c:\programdata\AOL Downloads\SUD4444\comps\acs\comps\acscore.exe
2009-08-03 18:36 . 2009-05-11 14:21 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-03 18:36 . 2009-05-11 14:21 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-27 14:32 . 2009-07-27 14:32 713992 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-07-27 14:27 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-07-25 10:23 . 2009-07-27 14:29 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-24 14:06 . 2009-07-23 20:00 -------- d-----w- c:\program files\AOL 9.5g
2009-07-23 20:01 . 2009-07-23 20:01 -------- d-----w- c:\program files\Common Files\Software Update Utility
2009-07-23 19:58 . 2009-07-23 19:58 62248 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\comps\ocpgc.exe
2009-07-23 19:58 . 2009-07-23 19:58 260040 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\ecuinst.exe
2009-07-23 19:58 . 2009-07-23 19:58 93992 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\instph.dll
2009-07-23 19:58 . 2009-07-23 19:58 21288 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\comps\acsshutd.exe
2009-07-23 19:58 . 2009-07-23 19:58 45864 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\AcsInstA.dll
2009-07-23 19:58 . 2009-07-23 19:58 223152 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\afix\wsfinst.exe
2009-07-23 19:58 . 2009-07-23 19:58 15920 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\ccu\ocpchk.dll
2009-07-23 19:58 . 2009-07-23 19:48 23542688 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\noneCodesignFilesBundle.exe
2009-07-23 19:48 . 2009-07-23 19:48 607392 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\tpspd\wbsetup.exe
2009-07-23 19:48 . 2009-07-23 19:48 45864 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\comps\AcsInstA.dll
2009-07-23 19:48 . 2009-07-23 19:48 188064 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\desk\dtblpins.exe
2009-07-23 19:48 . 2009-07-23 19:48 10800 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\afix\wsfixchk.dll
2009-07-23 19:48 . 2009-07-23 19:47 3346208 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\comps\ocpinst.exe
2009-07-23 19:47 . 2009-07-23 19:47 67120 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\ccu\instSup.dll
2009-07-23 19:47 . 2009-07-23 19:47 11312 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\ecuchk.dll
2009-07-23 19:47 . 2009-07-23 19:46 964544 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\comps\acslaeu.exe
2009-07-23 19:46 . 2009-07-23 19:45 1878296 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\toolbar\aol_toolbar.exe
2009-07-23 19:45 . 2009-07-23 19:45 74536 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\comps\instSup.dll
2009-07-23 19:45 . 2009-07-23 19:45 127224 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\afix\afixlang.exe
2009-07-23 19:45 . 2009-07-23 19:45 168744 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\setup.exe
2009-07-23 19:45 . 2009-07-23 19:45 1362936 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\msvcr9\msvc9rt.exe
2009-07-23 19:45 . 2009-07-23 19:45 147984 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\comps\acsrollb.exe
2009-07-23 19:45 . 2009-07-23 19:45 472872 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\gui.dll
2009-07-23 19:45 . 2009-07-23 19:44 469776 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\desk\dtbsetup.exe
2009-07-23 19:44 . 2009-07-23 19:44 54832 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\parcon\AOLParconLink.exe
2009-07-23 19:44 . 2009-07-23 19:44 355592 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\afix\afixinst.exe
2009-07-23 19:44 . 2009-05-20 16:33 54832 ----a-w- c:\windows\system32\AOLParconLink.exe
2009-07-23 19:44 . 2009-07-23 19:44 390704 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\afix\WinsockFix.exe
2009-07-23 19:44 . 2009-07-23 19:44 900904 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\waol-0.4337.80.1.exe
2009-07-23 19:44 . 2009-07-23 19:44 339840 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\desk\dskcore.exe
2009-07-23 19:44 . 2009-07-23 19:44 711592 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\sysinfo\SinfInst.exe
2009-07-23 19:44 . 2009-07-23 19:44 37672 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\comps\AcsInstC.dll
2009-07-23 19:44 . 2009-07-23 19:44 404568 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\tb\tbsetup.exe
2009-07-23 19:44 . 2009-07-23 19:44 124264 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\comps\cpwinst.exe
2009-07-23 19:43 . 2009-07-23 19:43 2439824 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\ccu\ocpinsti.exe
2009-07-23 19:43 . 2009-07-23 19:41 2395720 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\desk\dskcorlp.exe
2009-07-23 19:41 . 2009-07-23 19:41 35624 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\postproc.exe
2009-07-23 19:41 . 2009-07-23 19:40 1612544 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\comps\acslang.exe
2009-07-23 19:40 . 2009-07-23 19:40 15144 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\comps\ocpchk.dll
2009-07-23 19:40 . 2009-07-23 19:40 75048 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\instSup.dll
2009-07-23 19:40 . 2009-07-23 19:38 1484136 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\acs\comps\acscore.exe
2009-07-22 16:32 . 2009-07-08 23:11 -------- d-----w- c:\users\Ownwer\AppData\Roaming\HP
2009-07-21 21:52 . 2009-07-29 14:11 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-07-29 14:11 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-07-29 14:11 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-07-29 14:11 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-07-21 03:12 . 2009-07-21 03:12 6144 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\afix\ocfcheck.dll
2009-07-21 03:12 . 2009-07-21 03:12 1914000 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\flash\flashax.exe
2009-07-21 03:12 . 2009-07-21 03:12 845802 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\muinst\muinst.exe
2009-07-21 03:12 . 2009-07-21 03:12 6144 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\tb\tbinst.dll
2009-07-21 03:12 . 2009-07-21 03:12 57344 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\tpspd\tsverchk.dll
2009-07-21 03:12 . 2009-07-21 03:12 49152 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\tpspd\Dacldll.dll
2009-07-21 03:12 . 2009-07-21 03:12 45056 ----a-w- c:\programdata\AOL Downloads\waol\0.4337.80.1\comps\sysinfo\SiNdInst.dll
2009-05-13 21:55 . 2009-05-13 21:55 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-13 21:55 . 2009-05-13 21:55 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2006-05-03 10:06 . 2009-05-13 01:58 163328 --sha-r- c:\windows\System32\flvDX.dll
2007-02-21 11:47 . 2009-05-13 01:58 31232 --sh--r- c:\windows\System32\msfDX.dll
2008-03-16 13:30 . 2009-05-13 01:58 216064 --sh--r- c:\windows\System32\nbDX.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-08-24_15.52.03 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-08-26 16:44 . 2009-06-22 10:13 18944 c:\windows\winsxs\x86_microsoft-windows-i..rnational-timezones_31bf3856ad364e35_6.0.6002.22155_none_17865cb11ffa07ae\tzupd.exe
+ 2009-05-07 14:59 . 2009-05-07 14:59 18944 c:\windows\winsxs\x86_microsoft-windows-i..rnational-timezones_31bf3856ad364e35_6.0.6002.18054_none_16fbbf9c06dd4e8d\tzupd.exe
+ 2009-08-26 16:44 . 2009-06-22 10:26 18944 c:\windows\winsxs\x86_microsoft-windows-i..rnational-timezones_31bf3856ad364e35_6.0.6001.22454_none_159eea7f22d49933\tzupd.exe
+ 2009-05-07 14:59 . 2009-05-07 14:59 18944 c:\windows\winsxs\x86_microsoft-windows-i..rnational-timezones_31bf3856ad364e35_6.0.6001.18275_none_1500ac4009c64d7b\tzupd.exe
+ 2009-08-26 16:44 . 2009-06-22 10:21 18944 c:\windows\winsxs\x86_microsoft-windows-i..rnational-timezones_31bf3856ad364e35_6.0.6000.21070_none_139ee11525c210e3\tzupd.exe
+ 2009-08-26 16:44 . 2009-06-22 10:30 18944 c:\windows\winsxs\x86_microsoft-windows-i..rnational-timezones_31bf3856ad364e35_6.0.6000.16873_none_13186d060ca189dc\tzupd.exe
+ 2007-01-09 20:18 . 2009-08-28 13:55 54594 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-08-28 13:55 79946 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2009-05-07 00:56 . 2009-08-28 13:55 13978 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3615268277-3926800693-1650498289-1005_UserData.bin
- 2009-08-10 02:44 . 2009-08-10 02:44 27648 c:\windows\System32\jgpl400.dll
+ 2009-08-25 18:56 . 2009-08-25 18:56 27648 c:\windows\System32\jgpl400.dll
+ 2009-05-07 00:52 . 2009-08-28 14:08 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-05-07 00:52 . 2009-08-24 15:32 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-05-07 00:52 . 2009-08-24 15:32 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-05-07 00:52 . 2009-08-28 14:08 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-05-07 00:52 . 2009-08-28 14:08 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-05-07 00:52 . 2009-08-24 15:32 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-08-27 18:38 . 2009-08-27 18:38 32038 c:\windows\Installer\{2BD3661D-1384-4EF4-9E5C-DFDB8EE6E3EA}\ARPPRODUCTICON.exe
+ 2009-08-26 16:44 . 2009-06-22 10:13 2048 c:\windows\winsxs\x86_microsoft-windows-i..rnational-timezones_31bf3856ad364e35_6.0.6002.22155_none_17865cb11ffa07ae\tzres.dll
+ 2009-08-26 16:44 . 2009-06-22 10:09 2048 c:\windows\winsxs\x86_microsoft-windows-i..rnational-timezones_31bf3856ad364e35_6.0.6002.18054_none_16fbbf9c06dd4e8d\tzres.dll
+ 2009-08-26 16:44 . 2009-06-22 10:26 2048 c:\windows\winsxs\x86_microsoft-windows-i..rnational-timezones_31bf3856ad364e35_6.0.6001.22454_none_159eea7f22d49933\tzres.dll
+ 2009-08-26 16:44 . 2009-06-22 10:22 2048 c:\windows\winsxs\x86_microsoft-windows-i..rnational-timezones_31bf3856ad364e35_6.0.6001.18275_none_1500ac4009c64d7b\tzres.dll
+ 2009-08-26 16:44 . 2009-06-22 08:44 2048 c:\windows\winsxs\x86_microsoft-windows-i..rnational-timezones_31bf3856ad364e35_6.0.6000.21070_none_139ee11525c210e3\tzres.dll
+ 2009-08-26 16:44 . 2009-06-22 08:44 2048 c:\windows\winsxs\x86_microsoft-windows-i..rnational-timezones_31bf3856ad364e35_6.0.6000.16873_none_13186d060ca189dc\tzres.dll
+ 2009-08-28 13:53 . 2009-08-28 13:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-08-28 13:53 . 2009-08-28 13:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2006-11-02 10:33 . 2009-08-28 13:59 650720 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-08-28 13:59 122622 c:\windows\System32\perfc009.dat
+ 2009-08-25 18:56 . 2009-08-25 18:56 163840 c:\windows\System32\jgdw400.dll
- 2009-08-10 02:44 . 2009-08-10 02:44 163840 c:\windows\System32\jgdw400.dll
+ 2009-07-10 15:39 . 2009-07-10 15:39 406640 c:\windows\Downloaded Program Files\fslauncher.dll
- 2006-11-02 10:22 . 2009-08-20 22:27 6553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2006-11-02 10:22 . 2009-08-26 16:46 6553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-08-27 18:38 . 2009-08-27 18:38 2196480 c:\windows\Installer\431e2f.msi
+ 2009-06-05 13:59 . 2009-08-26 16:46 144213675 c:\windows\winsxs\ManifestCache\6.0.6002.18005_001c11ba_blobs.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"AOL Fast Start"="c:\program files\AOL 9.5a\AOL.EXE" [2009-08-25 50536]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2006-11-13 118784]
"AppMon Utility"="c:\program files\Sony\AppMonUtil\AppMonUtility.exe" [2006-11-15 415864]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2006-11-11 43128]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-09-29 151552]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-02-20 7770112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-02-20 81920]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"SpIDerAgent"="c:\program files\DrWeb\SpIDerAgent.exe" [2009-06-01 447728]
"SpIDerMail"="c:\program files\DrWeb\spiderml.exe" [2009-07-01 644336]
"SpIDerNT"="c:\progra~1\DrWeb\spiderui.exe" [2009-04-16 251144]
"HostManager"="c:\program files\Common Files\AOL\1241668092\ee\AOLSoftware.exe" [2009-07-20 41264]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2006-11-25 2134016]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 16:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2006-12-14 23:06 73728 ----a-w- c:\windows\System32\VESWinlogon.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=c:\windows\pss\Adobe Reader Synchronizer.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Free WebSite Tools.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Free WebSite Tools.lnk
backup=c:\windows\pss\Free WebSite Tools.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=c:\windows\pss\QuickBooks Update Agent.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^Users^Ownwer^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\users\Ownwer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
backupExtension=.Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"="0x00000000"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(:):62,01,3a,34,c5,f5,c9,01

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3615268277-3926800693-1650498289-1005]
"EnableNotificationsRef"=dword:00000002

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{40BAA052-6F21-4FB5-A872-CC8BA96FA69B}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{37CC52F2-39F4-4731-935C-94CC8F312C7F}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{841DC118-DC5B-46AB-8AD0-5346AA9C6B47}"= UDP:c:\program files\BitComet\BitComet.exe:BitComet.exe
"{5C1FA1D5-7339-475B-A6FD-E40A8884D2C4}"= TCP:c:\program files\BitComet\BitComet.exe:BitComet.exe
"{97E94798-B24B-476C-90C8-CA53770352F9}"= UDP:c:\program files\Common Files\AOL\acs\AOLDial.exe:AOL Connectivity Service Dialer
"{BC1688CF-7179-43E7-9683-05B9B521CE0C}"= TCP:c:\program files\Common Files\AOL\acs\AOLDial.exe:AOL Connectivity Service Dialer
"{5EA6C23E-BC0C-483F-8216-BC2754D91B5D}"= UDP:c:\program files\Common Files\AOL\acs\AOLacsd.exe:AOL Connectivity Service
"{169957EF-0E93-425B-9712-D627FC07444D}"= TCP:c:\program files\Common Files\AOL\acs\AOLacsd.exe:AOL Connectivity Service
"{FA8D70FB-5211-487A-B9EB-34FB9E9E88A7}"= UDP:c:\program files\Common Files\AOL\1241668092\ee\aolsoftware.exe:AOL Shared Components
"{A8360307-1BDE-4942-B1E0-8AA1CDAF7838}"= TCP:c:\program files\Common Files\AOL\1241668092\ee\aolsoftware.exe:AOL Shared Components
"{943C826E-17A1-4C3E-9F4E-B1729D97C2EF}"= UDP:c:\program files\AOL 9.5\waol.exe:AOL
"{758EBDDD-981E-439F-BF24-4F243A2D1180}"= TCP:c:\program files\AOL 9.5\waol.exe:AOL
"{A759DFBF-6AB2-487D-AEDE-453AC1E48212}"= UDP:c:\program files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe:AOL TopSpeed
"{6C483883-4CFF-4FAC-9483-174538DF5CDC}"= TCP:c:\program files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe:AOL TopSpeed
"{B745CF04-F3FE-4758-8141-3FBD82A23101}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{961D9C77-2734-4CE1-8926-06DCD8556DB4}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{73D2FFFC-B8A8-4430-819A-0241A126AF42}"= UDP:c:\program files\Common Files\AOL\System Information\sinf.exe:AOL System Information
"{4B58E94F-4C3E-4BDB-9ED1-0A6603220C5C}"= TCP:c:\program files\Common Files\AOL\System Information\sinf.exe:AOL System Information
"{C9B1A609-022C-4A47-9652-F3974B553161}"= UDP:13285:BitComet 13285 TCP
"{D037E8AF-1295-47BF-9C2A-04E638AF4093}"= TCP:13285:BitComet 13285 UDP
"TCP Query User{A43929CE-881A-4CC7-82F5-7B1ED30D5DE0}c:\\program files\\bitcomet\\bitcomet.exe"= UDP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"UDP Query User{802EFC40-D9F3-46E4-AA94-77456608C424}c:\\program files\\bitcomet\\bitcomet.exe"= TCP:c:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"{C1C127E5-0C8F-4B53-873F-FED2CDC1BD90}"= Disabled:UDP:5353:Adobe CSI CS4
"{40527ECD-B9D7-4F0D-970D-CD7C64614FEC}"= Disabled:UDP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{B3057D6C-B043-469A-9FAF-636A80848CD6}"= Disabled:TCP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"TCP Query User{3A9F951F-5947-4C29-8A40-109FF58ADFC9}c:\\program files\\icq6.5\\icq.exe"= UDP:c:\program files\icq6.5\icq.exe:ICQ
"UDP Query User{4F0C3FF4-5D0A-4B36-86A8-7DBE55F4E110}c:\\program files\\icq6.5\\icq.exe"= TCP:c:\program files\icq6.5\icq.exe:ICQ
"{6ADEA974-7745-47F9-9A88-11C7443552DF}"= UDP:21203:Bit Comet
"{C96D0FC7-D010-46EE-AEEB-B6DD11EA6348}"= TCP:21203:BitComet 21203 UDP
"{853FECD1-A5B1-49D7-8453-D992EC01B594}"= Disabled:UDP:c:\program files\Adobe\Adobe Photoshop CS4\Photoshop.exe:Adobe Photoshop CS4
"{4D799B11-6623-450B-AA76-C7DE683C915B}"= Disabled:TCP:c:\program files\Adobe\Adobe Photoshop CS4\Photoshop.exe:Adobe Photoshop CS4
"TCP Query User{83BD6E2D-5AAB-4180-846A-61C3DC78319A}c:\\program files\\aol 9.5\\waol.exe"= UDP:c:\program files\aol 9.5\waol.exe:AOL Software
"UDP Query User{E5B66B7F-A7A6-43FD-A943-ED95F812D7E5}c:\\program files\\aol 9.5\\waol.exe"= TCP:c:\program files\aol 9.5\waol.exe:AOL Software
"{9FB6AE73-2661-489A-888A-01BAEB67193C}"= UDP:21203:BitComet 21203 TCP
"{847344ED-3778-40ED-AABB-6526300DF2BF}"= TCP:21203:BitComet 21203 UDP
"{6D7F3A44-7D7C-45D7-AF1D-EE2946118136}"= UDP:c:\program files\Common Files\AOL\acs\AOLDial.exe:AOL Connectivity Service Dialer
"{3BB238BE-AE2E-4017-9B1E-40524B019D91}"= TCP:c:\program files\Common Files\AOL\acs\AOLDial.exe:AOL Connectivity Service Dialer
"{ADAF0980-A9E0-48A0-9A77-66B001EA04FD}"= UDP:c:\program files\Common Files\AOL\acs\AOLacsd.exe:AOL Connectivity Service
"{CC00F8C3-D10D-405F-9C21-2E81C315904F}"= TCP:c:\program files\Common Files\AOL\acs\AOLacsd.exe:AOL Connectivity Service
"{F41B951F-D61F-45D0-BB91-F7C740F0A0FB}"= UDP:c:\program files\Common Files\AOL\1241668092\ee\aolsoftware.exe:AOL Shared Components
"{70D36294-391F-4826-BCC1-794E0228BA1A}"= TCP:c:\program files\Common Files\AOL\1241668092\ee\aolsoftware.exe:AOL Shared Components
"{5C2ED012-78A5-49BB-A0E9-48F85506BDD9}"= UDP:c:\program files\AOL 9.5a\waol.exe:AOL
"{B8EB4792-828B-44F5-91BB-8A78DD886049}"= TCP:c:\program files\AOL 9.5a\waol.exe:AOL
"{8601CEF8-4E8D-4E01-91BA-43C183CD1B63}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{F30DA1B4-73FF-442A-B773-1279F3DD82CB}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{DEFB26F1-76D6-484B-A875-A64594796A9E}"= UDP:c:\program files\Common Files\AOL\System Information\sinf.exe:AOL System Information
"{B2C39C37-9C17-4846-A920-7FEE41EA50A0}"= TCP:c:\program files\Common Files\AOL\System Information\sinf.exe:AOL System Information
"{DFD1315C-1455-44F7-9397-0521CDF00C2B}"= UDP:c:\program files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe:AOL
"{F3D290E0-EC7E-403B-89C9-832F6CD0E2F1}"= TCP:c:\program files\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe:AOL
"TCP Query User{8CF1AA9F-64F4-4664-9D78-654923AE24F3}c:\\program files\\warez\\warez.exe"= UDP:c:\program files\warez\warez.exe:Warez
"UDP Query User{A493BC83-54FF-486D-B396-DC9F0C90BF85}c:\\program files\\warez\\warez.exe"= TCP:c:\program files\warez\warez.exe:Warez
"{37411C69-05AF-4BAD-BB17-C25921811899}"= UDP:9000:warez
"{888391BB-99C9-46E8-8436-29F9FE96BFEB}"= UDP:c:\program files\AOL 9.5b\waol.exe:AOL
"{712B919F-B742-4DA1-A136-2466D833E008}"= TCP:c:\program files\AOL 9.5b\waol.exe:AOL
"{C551ADF0-37EF-4E58-BBAD-646FA2E472AB}"= UDP:c:\program files\AOL 9.5c\waol.exe:AOL
"{697B1478-1915-445A-99FA-E87271EBC87B}"= TCP:c:\program files\AOL 9.5c\waol.exe:AOL
"{FF24500F-7EF4-41F3-9D0F-99C764297831}"= UDP:c:\program files\AOL 9.5d\waol.exe:AOL
"{0FBCEB51-7742-456D-9F60-10186220B021}"= TCP:c:\program files\AOL 9.5d\waol.exe:AOL
"{FD148DFC-6537-412D-A223-BD040F677E44}"= UDP:c:\program files\AOL 9.5e\waol.exe:AOL
"{6EF1EB1B-1708-480F-B8CD-138CDBF8284B}"= TCP:c:\program files\AOL 9.5e\waol.exe:AOL
"{03EB1BFC-C696-483F-B4B4-F29D13A280E1}"= h:\setup\hpznui01.exe:hpznui01.exe
"{B8E3C04A-93BD-4186-8BF6-DDFF4B4E3391}"= TCP:427|RPort=427|c:\windows\system32\svchost.exe|Svc=HPSLPSVC:SLP_Service
"{468D631B-DE87-4B4B-B4B7-EB8C8230FF07}"= c:\program files\HP\digital imaging\bin\hpqtra08.exe:hpqtra08.exe
"{3D6FDB19-41BF-42CE-BC3C-DD731DF1A3B8}"= c:\program files\HP\digital imaging\bin\hpqste08.exe:hpqste08.exe
"{660482BB-0B27-428D-8BDE-EE52E8B85C1F}"= c:\program files\HP\digital imaging\bin\hpofxm08.exe:hpofxm08.exe
"{7CB13788-062D-4789-9354-0660A68F6793}"= c:\program files\HP\digital imaging\bin\hposfx08.exe:hposfx08.exe
"{6923878F-E860-44DE-BB8F-15D3B3ABF4A6}"= c:\program files\HP\digital imaging\bin\hposid01.exe:hposid01.exe
"{7C602645-4EC5-4A7F-A99A-548AA9147389}"= c:\program files\HP\digital imaging\bin\hpqkygrp.exe:hpqkygrp.exe
"{96742C78-9FA4-4471-999D-E6F1D1EAF052}"= c:\program files\HP\digital imaging\bin\hpzwiz01.exe:hpzwiz01.exe
"{592025E4-7947-440F-AFB3-7A03B2E0EAD4}"= UDP:c:\program files\AOL 9.5f\waol.exe:AOL
"{E24EE7DA-5047-4900-A793-E6531584BAED}"= TCP:c:\program files\AOL 9.5f\waol.exe:AOL
"{062F4AB0-82D9-445D-96BA-139BE2928A8E}"= UDP:c:\program files\AOL 9.5a\waol.exe:AOL
"{57D68EB9-BAA0-410D-BACC-710DFCEED9E2}"= TCP:c:\program files\AOL 9.5a\waol.exe:AOL

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

P2 SPIDERNT;SpIDer Guard for Windows;c:\progra~1\DrWeb\spidernt.exe [4/16/2009 10:40 AM 251144]
R0 DwProt;DrWeb Protection;c:\windows\System32\drivers\dwprot.sys [8/27/2009 1:38 PM 101496]
R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [6/24/2009 11:02 AM 64160]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [1/15/2009 4:17 PM 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [1/15/2009 4:17 PM 55024]
R2 CSHelper;CopySafe Helper Service;c:\windows\System32\CSHelper.exe [8/4/2009 5:30 PM 266240]
R2 DrWebEngine;Dr.Web Scanning Engine (DrWebEngine);c:\program files\Common Files\Doctor Web\Scanning Engine\dwengine.exe [1/21/2009 4:09 PM 886072]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;c:\program files\Firebird\Firebird_2_1\bin\fbguard.exe -s DefaultInstance --> c:\program files\Firebird\Firebird_2_1\bin\fbguard.exe -s DefaultInstance [?]
R2 MSSQL$VAIO_VEDB;SQL Server (VAIO_VEDB);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [12/1/2006 3:11 PM 28933976]
R2 SPIDER;SpIDer Guard File System Monitor;c:\progra~1\DrWeb\spider.sys [4/16/2009 10:40 AM 394184]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;c:\program files\Firebird\Firebird_2_1\bin\fbserver.exe -s DefaultInstance --> c:\program files\Firebird\Firebird_2_1\bin\fbserver.exe -s DefaultInstance [?]
R3 R5U870FLx86;R5U870 UVC Lower Filter ;c:\windows\System32\drivers\R5U870FLx86.sys [1/9/2007 2:18 PM 72704]
R3 R5U870FUx86;R5U870 UVC Upper Filter ;c:\windows\System32\drivers\R5U870FUx86.sys [1/9/2007 2:18 PM 43904]
R3 slim;Sony Lucid Integrated Mpeg encoder;c:\windows\System32\drivers\slim.sys [1/9/2007 2:30 PM 699264]
R3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\System32\drivers\SonyImgF.sys [1/9/2007 3:10 PM 30976]
R3 ti21sony;ti21sony;c:\windows\System32\drivers\ti21sony.sys [1/9/2007 2:29 PM 227328]
R3 wsvad_driver;WS Audio Device;c:\windows\System32\drivers\VirtualAudio.sys [8/7/2009 4:54 PM 16896]
S3 netr28u;Linksys USB Wireless LAN Card Driver for Vista;c:\windows\System32\drivers\netr28u.sys [12/14/2007 6:16 PM 570880]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [1/15/2009 4:17 PM 7408]
S3 USBAVCap;AVerMedia USB TV Tuner Device;c:\windows\System32\drivers\USBAVCap.sys [1/9/2007 2:17 PM 774528]
S3 VAIOMediaPlatform-UCLS-AppServer;VAIO Media Content Collection;c:\program files\Sony\VAIO Media Integrated Server\UCLS.exe [10/2/2007 12:57 AM 741376]
S3 VAIOMediaPlatform-UCLS-HTTP;VAIO Media Content Collection (HTTP);c:\program files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe [10/2/2007 12:57 AM 397312]
S3 VAIOMediaPlatform-UCLS-UPnP;VAIO Media Content Collection (UPnP);c:\program files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe [10/2/2007 12:57 AM 1089536]
S4 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [6/8/2009 2:55 PM 108289]
S4 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 2:06 PM 1003344]
S4 SlingAgentService;SlingAgentService;c:\program files\Sling Media\SlingAgent\SlingAgentService.exe [4/27/2009 6:09 PM 93960]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-08-27 c:\windows\Tasks\Dr.Web Daily scan.job
- c:\program files\DrWeb\DrWeb32w.exe [2009-07-01 01:57]

2009-08-27 c:\windows\Tasks\Dr.Web Update.job
- c:\program files\DrWeb\DrWebUpW.exe [2009-07-01 01:50]

2009-08-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3615268277-3926800693-1650498289-1005Core.job
- c:\users\Ownwer\AppData\Local\Google\Update\GoogleUpdate.exe [2009-06-12 15:48]

2009-08-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3615268277-3926800693-1650498289-1005UA.job
- c:\users\Ownwer\AppData\Local\Google\Update\GoogleUpdate.exe [2009-06-12 15:48]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
LSP: c:\program files\DrWeb\drwebsp.dll
Trusted Zone: musicmatch.com\online
FF - ProfilePath - c:\users\Ownwer\AppData\Roaming\Mozilla\Firefox\Profiles\9s40vgdk.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.aol.com/aolcom/search?invocationType=tb50ffTB50CL-chromesbox-en-us&query=
FF - prefs.js: browser.search.selectedEngine - AOL Search
FF - prefs.js: browser.startup.homepage - hxxp://www.aol.com
FF - prefs.js: keyword.URL - hxxp://search.aol.com/aolcom/search?invocationType=tb50ffTB50CL-ab-en-us&query=
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\MpcStar\Codecs\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\MpcStar\Codecs\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - plugin: c:\users\Ownwer\AppData\Local\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: protocol-handler.warn-external.dnUpdate - falsec:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-28 09:32
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-08-28 9:35
ComboFix-quarantined-files.txt 2009-08-28 14:35
ComboFix2.txt 2009-08-27 16:59
ComboFix3.txt 2009-08-26 16:42
ComboFix4.txt 2009-08-25 15:14
ComboFix5.txt 2009-08-28 14:22

Pre-Run: 139,944,243,200 bytes free
Post-Run: 139,970,686,976 bytes free

573 --- E O F --- 2009-08-26 16:46
Upload was successful
________________________________________________________________________________
_________________________________________________________________


Malwarebytes' Anti-Malware 1.40
Database version: 2708
Windows 6.0.6002 Service Pack 2

8/28/2009 9:59:38 AM
mbam-log-2009-08-28 (09-59-38).txt

Scan type: Quick Scan
Objects scanned: 90013
Time elapsed: 5 minute(s), 48 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
________________________________________________________________________________
____________________________________________________________-

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:18:37 AM, on 8/28/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Sony\AppMonUtil\AppMonUtility.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
C:\Program Files\DrWeb\SpIDerAgent.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\DrWeb\SpIDerMl.exe
C:\Program Files\DrWeb\spiderui.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Program Files\AOL 9.5a\waol.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\Program Files\AOL 9.5a\shellmon.exe
C:\Program Files\Common Files\AOL\1241668092\ee\aolsoftware.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [AppMon Utility] "C:\Program Files\Sony\AppMonUtil\AppMonUtility.exe" @@@Start
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SpIDerAgent] "C:\Program Files\DrWeb\SpIDerAgent.exe"
O4 - HKLM\..\Run: [SpIDerMail] "C:\Program Files\DrWeb\spiderml.exe"
O4 - HKLM\..\Run: [SpIDerNT] C:\PROGRA~1\DrWeb\spiderui.exe /agent
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.5a\AOL.EXE" -b
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O16 - DPF: {076169AA-8C3D-4CFC-AC23-3ACA88FC21B5} (F-Secure Online Scanner Launcher) - http://download.sp.f-secure.com/ols/f-secu.../fslauncher.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: CopySafe Helper Service (CSHelper) - Unknown owner - C:\Windows\system32\CSHelper.exe
O23 - Service: Dr.Web Scanning Engine (DrWebEngine) (DrWebEngine) - Doctor Web, Ltd. - C:\Program Files\Common Files\Doctor Web\Scanning Engine\dwengine.exe
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - FirebirdSQL Project - C:\Program Files\Firebird\Firebird_2_1\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - FirebirdSQL Project - C:\Program Files\Firebird\Firebird_2_1\bin\fbserver.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SpIDer Guard for Windows (SPIDERNT) - Doctor Web, Ltd. - C:\PROGRA~1\DrWeb\spidernt.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 7830 bytes

#14
screen317

    MBAM Sentinel

  • Moderators
  • PipPipPipPipPipPip
  • 16,432 posts
  • Gender:Male
  • Location:Los Angeles
Hi,

Navigate to Start --> Run, and type Combofix /u in the box that appears. Click OK afterwards. Notice the space between the X and the /u

This uninstalls all of ComboFix's components.

Delete SecurityCheck.

After that, navigate to Start --> Control Panel --> Add or Remove Programs, and uninstall the following programs (if present):

Java™ SE Runtime Environment 6
Adobe Reader 8.1.6


I also recommend uninstalling Ad-Aware; its resident protection isn't enabled, and clearly it couldn't help for this infection.

Restart your computer.

Get the latest version of Adobe Reader.

Let me know what issues remain.

-screen317
Chris Fistonich
Consumer Support Specialist

Posted Image

Follow us: Twitter, Become a fan: Facebook

#15
Fletch55

    New Member

  • Members
  • Pip
  • 18 posts
Ok I removed the Java and the older Adobe reader then used the link you gave an installed the new adobe. is there a new java I need to install now that you had me remove the java I had? My scans come up clean now and I have done a clean up and defrag but system is pretty slow now when starting and opening files so not sure if the vista files were damaged in the infection or clean up and I dont know if there is a way to have the windows files scanned and repaired or replaced as I have a sony vio and sony gives no restore or system disks with the computer.. Any suggestions or anything else you could see in this final hijack log?..Oh i kept adware as i disabled it as I only have 2gb of ram which isnt much so less programs always running in the background the better I do a daily scan with it but if I based its removal on not getting these infections id have to remove mbam too as it finds stuff but isnt capable of deleting them either. Thanks again for all the help and let me know if you see anything else or have any info on my previous statements


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:17:26 PM, on 8/31/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Sony\AppMonUtil\AppMonUtility.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe
C:\Program Files\AOL 9.5a\waol.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\Program Files\AOL 9.5a\shellmon.exe
C:\Program Files\Common Files\AOL\1241668092\ee\aolsoftware.exe
C:\Program Files\Common Files\AOL\Topspeed\3.0\aoltpsd3.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [AppMon Utility] "C:\Program Files\Sony\AppMonUtil\AppMonUtility.exe" @@@Start
O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_15.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_15.dll
O16 - DPF: {076169AA-8C3D-4CFC-AC23-3ACA88FC21B5} (F-Secure Online Scanner Launcher) - http://download.sp.f-secure.com/ols/f-secu.../fslauncher.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: CopySafe Helper Service (CSHelper) - Unknown owner - C:\Windows\system32\CSHelper.exe
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - FirebirdSQL Project - C:\Program Files\Firebird\Firebird_2_1\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - FirebirdSQL Project - C:\Program Files\Firebird\Firebird_2_1\bin\fbserver.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 7703 bytes

#16
screen317

    MBAM Sentinel

  • Moderators
  • PipPipPipPipPipPip
  • 16,432 posts
  • Gender:Male
  • Location:Los Angeles
Hi,

Quote

is there a new java I need to install now that you had me remove the java I had?
No, you had two versions installed (one is the latest).

Please register (it's free, don't worry) with PCPitStop and run the full tests here. When the tests are complete, a results page will pop up. Copy and paste the URL of the Results screen and post it here for me.

-screen317
Chris Fistonich
Consumer Support Specialist

Posted Image

Follow us: Twitter, Become a fan: Facebook

#17
Fletch55

    New Member

  • Members
  • Pip
  • 18 posts
Ok signed up and installed and ran here is the link for the results with suggested fixews

http://www.pcpitstop...?conid=22617415

#18
screen317

    MBAM Sentinel

  • Moderators
  • PipPipPipPipPipPip
  • 16,432 posts
  • Gender:Male
  • Location:Los Angeles
Hi,

PCPitStop noted several things that you can do to improve the shape your computer is in.

Pay particular attention to these items:


• Delete Temporary Files/Tracking Cookies:

Please download CCleaner and save it to your desktop.
  • Run the CCleaner installer.
  • During installation process, please UNCHECK "Add CCleaner Yahoo! Toolbar".
  • Please do NOT run a scan yet!
Now, open CCleaner:
  • Click the "Windows" tab.
  • Select the following:
    • Check everything under the "Internet Explorer" section.
    • Check everything under the "Windows Explorer" section.
    • Check everything under the "System" section.
    • Check ONLY "Old Prefetch data" under the "Advanced" section.
  • Then, click the "Applications" tab:
    • CHECK everything there.
  • Next, click the "Options" button in the left pane, then click the "Advanced" button:
    • CHECK : "Only delete files in Windows Temp folders older than 48 hours".
  • Next, click the "Cleaner" button in the left pane, then click the "Run Cleaner" button (bottom right), click "OK" at the prompt.
  • When done, please exit CCleaner.
CAUTION: Please do NOT use the "Issues" button in the left pane. This is a built-in registry cleaner. If you don’t know how to use it, you may cause irreparable damage to your system.


• Defragment files (Drive C)
Defragmenting is a must. It's one of the large reasons for system slowdowns. I use JkDefrag to defragment. You can use it forever. I recommend installing it and defragmenting as soon as possible


• Update outdated device drivers:
Right click My Computer, click Properties, click the Hardware tab, and then click Device Manager. Update the drivers for your Sound card, Video card, Ethernet card. Use the trial of Driver Alert from PCPitStop (click • Update outdated device drivers), to see which drivers should be updated.


• Install more memory:
Your computer has 2GB of RAM. Upgrading RAM may lead to a performance boost (3GB is supported by 32bit Windows Vista).


Also take the time to take a look at the other tips PCPitStop reported. I've just highlighted some of the more important ones.

Let me know how it goes.

-screen317
Chris Fistonich
Consumer Support Specialist

Posted Image

Follow us: Twitter, Become a fan: Facebook

#19
Fletch55

    New Member

  • Members
  • Pip
  • 18 posts
Hi thanks again for the help. I already have CCleaner and it is up to date and I run twice a day just hadnt before the pitstop test. The driver updates it shows are not compatible with my computer. I check manually each week for hardware driver updates in my device manager but I went and found the ones pitstop said were need but when you go to install they all say this driver was not inteneded to be compatible with this computer so couldnt do that. This laptop only supports up to the 2GB of ram it has in it right now can not be upgraded any higher its maxed. I did a defrag 3 days ago with windows defrag but will download the one you give and give it a try and then Ill run a new pitscan and post the link back.

#20
screen317

    MBAM Sentinel

  • Moderators
  • PipPipPipPipPipPip
  • 16,432 posts
  • Gender:Male
  • Location:Los Angeles
Okay I await your reply.
Chris Fistonich
Consumer Support Specialist

Posted Image

Follow us: Twitter, Become a fan: Facebook





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us