ComboFix 11-04-01.01 - Silvi 02/04/2011 16:50:02.3.2 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.44.1033.18.2013.1006 [GMT 1:00]
Running from: C:\Users\Silvi\Desktop\ComboFix.exe
Command switches used :: C:\Users\Silvi\Desktop\CFScript.txt
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
FILE ::
"C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job"
"C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job"
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\ProgramData\hEp24512nInJj24512
C:\ProgramData\hEp24512nInJj24512\hEp24512nInJj24512
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
---- Previous Run -------
C:\ProgramData\FullRemove.exe
C:\Windows\system32\service
((((((((((((((((((((((((( Files Created from 2011-03-02 to 2011-04-02 )))))))))))))))))))))))))))))))
2011-04-02 14:07:45 . 2011-04-02 14:07:45 -------- d-----w- C:\Users\Silvi\AppData\Roaming\Malwarebytes
2011-04-02 14:07:40 . 2010-12-20 17:09:00 38224 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2011-04-02 14:07:39 . 2011-04-02 14:07:39 -------- d-----w- C:\ProgramData\Malwarebytes
2011-04-02 14:07:36 . 2011-04-02 14:07:40 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-04-02 14:07:36 . 2010-12-20 17:08:40 24152 ----a-w- C:\Windows\system32\drivers\mbam.sys
2011-03-10 16:21:41 . 2010-12-23 06:07:50 1118720 ----a-w- C:\Windows\system32\sbe.dll
2011-03-10 16:21:41 . 2010-12-23 06:07:49 961024 ----a-w- C:\Windows\system32\CPFilters.dll
2011-03-10 16:21:41 . 2010-12-23 06:07:49 723968 ----a-w- C:\Windows\system32\EncDec.dll
2011-03-10 16:21:41 . 2010-12-23 05:28:28 642048 ----a-w- C:\Windows\SysWow64\CPFilters.dll
2011-03-10 16:21:41 . 2010-12-23 05:28:28 534528 ----a-w- C:\Windows\SysWow64\EncDec.dll
2011-03-10 16:21:40 . 2010-12-23 06:02:33 259072 ----a-w- C:\Windows\system32\mpg2splt.ax
2011-03-10 16:21:40 . 2010-12-23 05:28:29 850432 ----a-w- C:\Windows\SysWow64\sbe.dll
2011-03-10 16:21:40 . 2010-12-23 05:24:02 199680 ----a-w- C:\Windows\SysWow64\mpg2splt.ax
2011-03-10 16:21:39 . 2010-12-18 06:12:28 3138048 ----a-w- C:\Windows\system32\mstscax.dll
2011-03-10 16:21:38 . 2010-12-18 06:08:15 1097216 ----a-w- C:\Windows\system32\mstsc.exe
2011-03-10 16:21:38 . 2010-12-18 05:30:20 2690560 ----a-w- C:\Windows\SysWow64\mstscax.dll
2011-03-10 16:21:38 . 2010-12-18 05:26:55 1034240 ----a-w- C:\Windows\SysWow64\mstsc.exe
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2011-02-13 19:39:58 . 2011-02-13 19:18:36 867064 ----a-w- C:\Windows\system32\drivers\sptd.sys
2011-01-07 08:06:50 . 2011-02-12 23:35:52 46080 ----a-w- C:\Windows\system32\atmlib.dll
2011-01-07 07:27:11 . 2011-02-12 23:35:52 34304 ----a-w- C:\Windows\SysWow64\atmlib.dll
2011-01-07 05:49:20 . 2011-02-12 23:35:52 366080 ----a-w- C:\Windows\system32\atmfd.dll
2011-01-07 05:33:11 . 2011-02-12 23:35:52 294400 ----a-w- C:\Windows\SysWow64\atmfd.dll
2011-01-05 06:20:30 . 2011-02-12 23:36:22 612352 ----a-w- C:\Windows\system32\vbscript.dll
2011-01-05 05:37:33 . 2011-02-12 23:36:22 428032 ----a-w- C:\Windows\SysWow64\vbscript.dll
2011-01-05 04:00:16 . 2011-02-12 23:37:50 3127808 ----a-w- C:\Windows\system32\win32k.sys
2009-04-08 17:31:56 . 2009-04-08 17:31:56 106496 ----a-w- C:\Program Files (x86)\Common Files\CPInstallAction.dll
2008-08-12 04:45:20 . 2008-08-12 04:45:20 155648 ----a-w- C:\Program Files (x86)\Common Files\MSIactionall.dll
((((((((((((((((((((((((((((( SnapShot@2011-04-02_15.14.06 )))))))))))))))))))))))))))))))))))))))))
+ 2009-07-14 04:54:17 . 2011-04-02 15:55:21 16384 C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54:17 . 2011-04-02 15:05:03 16384 C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-07-14 04:54:17 . 2011-04-02 15:05:03 32768 C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54:17 . 2011-04-02 15:55:21 32768 C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54:17 . 2011-04-02 15:05:03 16384 C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54:17 . 2011-04-02 15:55:21 16384 C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-02-10 02:07:53 . 2011-04-02 15:55:37 16384 C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-02-10 02:07:53 . 2011-04-02 15:05:13 16384 C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-02-10 02:07:53 . 2011-04-02 15:55:37 32768 C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2011-02-10 02:07:53 . 2011-04-02 15:05:13 32768 C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54:19 . 2011-04-02 15:05:13 16384 C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54:19 . 2011-04-02 15:55:37 16384 C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-02-09 11:31:59 . 2011-04-02 15:56:20 16384 C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-02-09 11:31:59 . 2011-04-02 15:05:42 16384 C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-02-09 11:31:59 . 2011-04-02 15:05:42 32768 C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2011-02-09 11:31:59 . 2011-04-02 15:56:20 32768 C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2011-02-09 11:31:59 . 2011-04-02 15:05:42 16384 C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-02-09 11:31:59 . 2011-04-02 15:56:20 16384 C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2011-02-09 19:17:50 . 2011-04-02 15:05:44 16384 C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-02-09 19:17:50 . 2011-04-02 15:56:22 16384 C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2011-02-09 19:17:50 . 2011-04-02 15:05:44 16384 C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-02-09 19:17:50 . 2011-04-02 15:56:22 16384 C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2011-04-02 15:55:14 . 2011-04-02 15:55:14 2048 C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-04-02 15:05:00 . 2011-04-02 15:05:00 2048 C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-04-02 15:05:00 . 2011-04-02 15:05:00 2048 C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-04-02 15:55:14 . 2011-04-02 15:55:14 2048 C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-02-13 09:44:09 . 2011-04-02 15:44:15 215104 C:\Windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S4.bin
- 2009-07-14 05:12:52 . 2011-04-02 15:05:13 262144 C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-07-14 05:12:52 . 2011-04-02 15:55:37 262144 C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2009-07-14 02:34:08 . 2011-04-02 15:18:11 10223616 C:\Windows\system32\SMI\Store\Machine\schema.dat
- 2009-07-14 02:34:08 . 2011-04-02 13:25:19 10223616 C:\Windows\system32\SMI\Store\Machine\schema.dat
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-02 00:08:18 143360 ----a-w- C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2009-07-14 01:39:41 1475072]
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"UpdateLBPShortCut"="C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2009-05-20 05:16:16 222504]
"UpdateP2GoShortCut"="C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-20 05:16:16 222504]
"Boingo Wi-Fi"="C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo.lnk" [2010-07-10 04:19:31 2429]
"HDAudDeck"="C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2009-09-17 07:40:21 2245120]
"HControlUser"="C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe" [2009-06-19 17:29:42 105016]
"ATKOSD2"="C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe" [2009-08-17 16:58:46 6859392]
"ATKMEDIA"="C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe" [2009-08-20 03:31:48 170624]
"Malwarebytes' Anti-Malware (reboot)"="C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 17:08:46 963976]
C:\Users\Silvi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Lingea Update Center.lnk - C:\Program Files (x86)\Common Files\Lingea Shared\luc.exe [2011-2-22 275736]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
FancyStart daemon.lnk - C:\Windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe [2010-7-10 12862]
SRS Premium Sound.lnk - C:\Windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe [2010-7-10 156952]
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
R0 sptd;sptd;C:\Windows\System32\Drivers\sptd.sys [x]
R2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-07-10 04:19:12 135664]
R3 ipswuio;ipswuio;C:\Windows\system32\DRIVERS\ipswuio.sys [x]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 10:41:00 51456888]
R3 ose64;Office 64 Source Engine;C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 21:20:56 174440]
R3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 21:34:24 4925184]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;C:\Windows\system32\DRIVERS\SiSG664.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe [x]
S0 lullaby;lullaby;C:\Windows\system32\DRIVERS\lullaby.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys [x]
S2 AFBAgent;AFBAgent;C:\Windows\system32\FBAgent.exe [x]
S2 ASMMAP64;ASMMAP64;C:\Program Files\ATKGFNEX\ASMMAP64.sys [2007-07-24 18:11:32 14904]
S3 ETD;ELAN PS/2 Port Input Device;C:\Windows\system32\DRIVERS\ETD.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;C:\Windows\system32\drivers\viahduaa.sys [x]
--------- x86-64 -----------
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1]
@="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}"
[HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}]
2007-06-01 23:52:58 159744 ----a-w- C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt1_64.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B]
@="{6D4133E5-0742-4ADC-8A8C-9303440F7190}"
[HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}]
2009-11-26 05:49:40 70656 ----a-w- C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O]
@="{64174815-8D98-4CE6-8646-4C039977D808}"
[HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}]
2009-11-26 05:49:40 70656 ----a-w- C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ETDWare"="C:\Program Files\Elantech\ETDCtrl.exe" [2009-09-30 03:55:25 621440]
"ASUS WebStorage"="C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe" [2010-03-16 01:48:34 1754448]
"AmIcoSinglun64"="C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2009-09-01 07:10:27 323584]
"Setwallpaper"="c:\programdata\SetWallpaper.cmd" [BU]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2010-08-26 03:45:04 161304]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2010-08-26 03:44:54 386584]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2010-08-26 03:45:00 415256]
"BCSSync"="C:\Program Files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 14:54:26 112512]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
------- Supplementary Scan -------
uStart Page =
hxxp://asus.msn.comuLocal Page = C:\Windows\system32\blank.htm
mLocal Page = C:\Windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
FF - ProfilePath - C:\Users\Silvi\AppData\Roaming\Mozilla\Firefox\Profiles\7hiybbh7.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.sympatico.ca/default.aspxFF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
- - - - ORPHANS REMOVED - - - -
Toolbar-Locked - (no file)
Toolbar-Locked - (no file)