SD - This is from ComboFix
ComboFix 10-01-04.01 - debby 01/05/2010 18:42:28.1.1 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.1.1033.18.1919.1111 [GMT -5:00]
Running from: c:\users\debby\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-2365545147-1999384947-2466353664-500
c:\recycler\S-1-5-21-1343024091-1993962763-682003330-1003
.
((((((((((((((((((((((((( Files Created from 2009-12-05 to 2010-01-05 )))))))))))))))))))))))))))))))
.
2010-01-05 23:48 . 2010-01-05 23:48 -------- d-----w- c:\users\debby\AppData\Local\temp
2010-01-05 23:48 . 2010-01-05 23:48 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-01-03 03:24 . 2010-01-03 03:24 -------- d-----w- c:\program files\Trend Micro
2010-01-03 03:07 . 2010-01-03 03:07 -------- d-----w- c:\users\debby\AppData\Roaming\Malwarebytes
2010-01-03 03:07 . 2009-12-30 19:55 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-03 03:07 . 2010-01-03 03:07 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-03 03:07 . 2010-01-03 03:07 -------- d-----w- c:\programdata\Malwarebytes
2010-01-03 03:07 . 2009-12-30 19:54 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-02 22:30 . 2010-01-02 22:30 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2010-01-02 22:29 . 2010-01-02 22:29 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-01-02 22:29 . 2010-01-02 22:29 -------- d-----w- c:\users\debby\AppData\Roaming\SUPERAntiSpyware.com
2010-01-02 22:28 . 2010-01-02 22:28 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-01-02 21:08 . 2010-01-02 21:08 -------- d-----w- c:\program files\CCleaner
2009-12-31 01:24 . 2009-12-31 01:24 -------- d-----w- c:\users\debby\AppData\Local\Apps
2009-12-31 01:15 . 2009-12-31 01:15 -------- d-----w- c:\program files\MSECache
2009-12-26 20:18 . 2009-12-26 20:18 -------- d-----w- c:\programdata\Seagate
2009-12-26 20:18 . 2009-12-26 20:18 -------- d-----w- c:\program files\Seagate
2009-12-26 20:16 . 2009-12-26 20:24 -------- d-----w- c:\users\debby\AppData\Local\Downloaded Installations
2009-12-26 20:15 . 2009-12-26 20:15 -------- d-sh--w- c:\windows\ftpcache
2009-12-26 20:12 . 2009-12-26 20:12 -------- d-----w- c:\users\debby\AppData\Roaming\Leadertech
2009-12-20 05:00 . 2009-12-20 05:00 -------- d-----w- c:\users\debby\AppData\Roaming\F-Secure
2009-12-19 00:52 . 1995-08-01 09:44 212480 ----a-w- c:\windows\PCDLIB32.DLL
2009-12-19 00:50 . 2009-12-19 00:51 -------- d-----w- c:\program files\EPSON Print CD
2009-12-19 00:45 . 2009-12-19 00:50 -------- d-----w- c:\program files\EPSON
2009-12-19 00:44 . 2003-05-21 07:27 64000 ----a-w- c:\windows\system32\E_FBCBAIA.DLL
2009-12-19 00:44 . 2004-11-25 10:07 79679 ----a-w- c:\windows\system32\E_FLMAIA.DLL
2009-12-19 00:44 . 2004-06-24 06:20 309760 ----a-w- c:\windows\system32\EAL32.DLL
2009-12-19 00:44 . 2004-03-12 06:30 82944 ----a-w- c:\windows\system32\EAL.EXE
2009-12-19 00:44 . 2000-06-07 06:01 34304 ----a-w- c:\windows\system32\E_FBCHAIA.DLL
2009-12-19 00:27 . 2006-08-25 00:00 9216 ----a-w- c:\windows\system32\escdev.dll
2009-12-19 00:27 . 2007-11-29 05:00 73216 ----a-w- c:\windows\system32\eswia7c.dll
2009-12-19 00:27 . 2007-10-18 05:00 65793 ----a-w- c:\windows\system32\esfw7c.bin
2009-12-19 00:27 . 2007-10-18 05:00 221184 ----a-w- c:\windows\system32\esint7c.dll
2009-12-19 00:27 . 2006-03-10 05:00 3584 ----a-w- c:\windows\system32\eswiaml.dll
2009-12-17 23:52 . 2009-12-17 23:53 -------- d-----w- c:\program files\eMusic Download Manager
2009-12-15 18:34 . 2009-12-15 18:34 -------- d-----w- c:\users\debby\AppData\Roaming\eMusic
2009-12-15 18:34 . 2009-12-15 18:34 -------- d-----w- c:\users\debby\AppData\Local\eMusic
2009-12-14 04:44 . 2000-03-21 05:55 118784 ----a-w- c:\windows\system32\vbalNCSM6.dll
2009-12-14 04:44 . 1999-02-19 13:54 40960 ----a-w- c:\windows\system32\SSubTmr6.dll
2009-12-14 04:44 . 1999-03-26 05:00 101888 ----a-w- c:\windows\system32\Vb6stkit.dll
2009-12-14 04:42 . 2009-12-14 04:42 -------- d-----w- c:\program files\eGames
2009-12-13 19:43 . 2009-12-13 19:44 -------- d-----w- c:\users\debby\AppData\Roaming\Template
2009-12-13 04:44 . 2009-12-13 04:44 -------- d-----w- c:\users\debby\AppData\Roaming\KodakCredentialStore
2009-12-13 04:43 . 2009-12-13 04:43 -------- d-----w- c:\users\debby\AppData\Local\KodakGallery
2009-12-13 04:42 . 2009-12-13 04:42 -------- d-----w- c:\users\debby\AppData\Roaming\Skinux
2009-12-13 04:38 . 2009-12-13 04:38 -------- d-----w- c:\users\debby\AppData\Local\ArcSoft
2009-12-13 04:38 . 2009-12-13 04:38 -------- d-----w- c:\users\debby\AppData\Roaming\Arcsoft
2009-12-13 04:37 . 2009-12-13 04:38 -------- d-----w- c:\programdata\ArcSoft
2009-12-13 04:36 . 2009-12-26 20:27 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-13 04:36 . 2009-12-19 00:52 -------- d-----w- c:\program files\ArcSoft
2009-12-13 04:36 . 2009-12-13 04:37 -------- d-----w- c:\program files\Common Files\ArcSoft
2009-12-13 04:10 . 2009-12-13 04:10 -------- d-----w- c:\windows\system32\BWKDLogs
2009-12-13 04:10 . 2009-12-13 04:33 -------- d-----w- c:\program files\Common Files\Kodak
2009-12-13 04:10 . 2009-12-13 04:33 -------- d-----w- c:\windows\system32\color
2009-12-13 04:09 . 2009-12-13 04:34 -------- d-----w- c:\program files\Kodak
2009-12-13 04:08 . 2009-12-13 04:20 -------- d-----w- c:\programdata\Kodak
2009-12-12 17:15 . 2009-12-12 17:15 -------- d-----w- c:\program files\Windows Portable Devices
2009-12-12 15:36 . 2009-09-10 02:00 92672 ----a-w- c:\windows\system32\UIAnimation.dll
2009-12-12 15:36 . 2009-09-10 02:00 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2009-12-12 15:36 . 2009-09-10 02:01 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
2009-12-12 15:34 . 2009-10-01 01:02 30208 ----a-w- c:\windows\system32\WPDShextAutoplay.exe
2009-12-12 15:33 . 2009-10-08 21:07 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2009-12-12 15:33 . 2009-10-08 21:08 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2009-12-12 15:33 . 2009-10-08 21:08 234496 ----a-w- c:\windows\system32\oleacc.dll
2009-12-12 15:33 . 2009-12-12 15:33 -------- d-----w- c:\program files\MSXML 4.0
2009-12-12 00:22 . 2009-12-12 00:22 -------- d-----w- c:\programdata\TomTom
2009-12-12 00:20 . 2009-12-12 00:20 -------- d-----w- c:\users\debby\AppData\Roaming\TomTom
2009-12-12 00:20 . 2009-12-12 00:20 -------- d-----w- c:\users\debby\AppData\Local\TomTom
2009-12-12 00:20 . 2009-12-12 00:20 -------- d-----w- c:\program files\TomTom International B.V
2009-12-12 00:19 . 2009-12-12 00:19 -------- d-----w- c:\program files\TomTom HOME 2
2009-12-12 00:18 . 2009-12-12 00:18 -------- d-----w- c:\program files\TomTom DesktopSuite
2009-12-11 23:57 . 2009-12-11 23:59 -------- d-----w- c:\users\debby\AppData\Roaming\acccore
2009-12-11 23:57 . 2009-12-11 23:57 -------- d-----w- c:\users\debby\AppData\Local\AOL
2009-12-11 23:57 . 2009-12-11 23:57 -------- d-----w- c:\users\debby\AppData\Local\AIM
2009-12-11 23:57 . 2009-12-11 23:57 -------- d-----w- c:\programdata\AIM
2009-12-11 23:57 . 2009-12-11 23:57 -------- d-----w- c:\program files\AIM
2009-12-11 23:57 . 2009-12-11 23:57 -------- d-----w- c:\program files\Common Files\Software Update Utility
2009-12-11 23:57 . 2009-12-11 23:57 -------- d-----w- c:\program files\Common Files\AOL
2009-12-11 23:07 . 2009-12-11 23:07 -------- d-----w- c:\program files\Shockwave.com
2009-12-11 22:40 . 2009-12-15 18:36 -------- d-----w- c:\users\debby\AppData\Local\Apple Computer
2009-12-11 22:40 . 2009-12-11 22:43 -------- d-----w- c:\users\debby\AppData\Roaming\Apple Computer
2009-12-11 22:40 . 2009-12-11 22:40 -------- dc----w- c:\windows\system32\DRVSTORE
2009-12-11 22:40 . 2009-05-18 19:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-12-11 22:40 . 2008-04-17 18:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-12-11 22:39 . 2009-12-11 22:39 -------- d-----w- c:\program files\iPod
2009-12-11 22:39 . 2009-12-11 22:40 -------- d-----w- c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-12-11 22:39 . 2009-12-11 22:40 -------- d-----w- c:\program files\iTunes
2009-12-11 22:39 . 2009-12-11 22:39 -------- d-----w- c:\program files\Bonjour
2009-12-11 22:38 . 2009-12-11 22:39 -------- d-----w- c:\program files\QuickTime
2009-12-11 22:38 . 2009-12-11 22:39 -------- d-----w- c:\programdata\Apple Computer
2009-12-11 22:37 . 2009-12-11 22:37 -------- d-----w- c:\users\debby\AppData\Local\Apple
2009-12-11 22:37 . 2009-12-11 22:37 -------- d-----w- c:\program files\Apple Software Update
2009-12-11 22:35 . 2009-12-11 22:39 -------- d-----w- c:\program files\Common Files\Apple
2009-12-11 22:35 . 2009-12-11 22:35 -------- d-----w- c:\programdata\Apple
2009-12-11 21:38 . 2009-12-11 21:38 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-11 21:37 . 2009-12-11 21:37 -------- d-----w- c:\program files\Java
2009-12-11 21:08 . 2009-04-23 17:52 750984 ----a-w- c:\windows\system32\Magentic Screensaver.scr
2009-12-11 21:08 . 2009-12-11 21:25 -------- d-----w- c:\users\debby\AppData\Local\Magentic
2009-12-11 21:08 . 2009-12-11 21:13 -------- d-----w- c:\program files\Magentic
2009-12-11 20:57 . 2009-12-11 20:59 -------- d-----w- c:\users\debby\AppData\Local\IM
2009-12-11 20:56 . 2009-12-11 20:56 -------- d-----w- c:\programdata\IncrediMail
2009-12-11 20:56 . 2009-12-11 20:57 -------- d-----w- c:\programdata\IM
2009-12-11 20:56 . 2009-12-11 20:56 -------- d-----w- c:\program files\IncrediMail
2009-12-11 20:48 . 2008-01-19 04:34 89600 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\HPZPPLHN.DLL
2009-12-11 19:42 . 2009-12-13 06:56 -------- d-----w- c:\users\debby\AppData\Local\MigWiz
2009-12-11 18:26 . 2009-10-29 09:17 2048 ----a-w- c:\windows\system32\tzres.dll
2009-12-11 03:59 . 2009-12-11 03:59 -------- d-----w- c:\users\debby\AppData\Roaming\Webshots
2009-12-11 03:59 . 2009-12-26 20:45 -------- d-----w- c:\program files\Webshots
2009-12-11 03:59 . 2009-12-11 03:59 -------- d-----w- c:\program files\AGI
2009-12-11 03:57 . 2009-12-11 03:59 -------- d-----w- c:\programdata\agi
2009-12-11 03:25 . 2009-12-29 05:24 -------- d-----w- c:\users\debby\AppData\Local\Microsoft Games
2009-12-11 01:49 . 2009-12-11 01:55 33920 ----a-w- c:\windows\system32\drivers\fsbts.sys
2009-12-11 01:49 . 2009-07-09 09:33 35680 ----a-w- c:\windows\system32\drivers\fses.sys
2009-12-11 01:49 . 2009-07-09 09:35 572512 ----a-w- c:\windows\system32\msvcp50.dll
2009-12-11 01:49 . 2009-07-09 09:33 71040 ----a-w- c:\windows\system32\drivers\fsdfw.sys
2009-12-11 01:48 . 2009-12-11 01:56 -------- d-----w- c:\program files\F-Secure
2009-12-11 01:48 . 2009-12-11 01:48 -------- d-----w- c:\programdata\fssg
2009-12-11 01:45 . 2009-12-11 01:49 -------- d-----w- c:\programdata\f-secure
2009-12-11 01:39 . 2009-12-11 01:39 -------- d-----w- c:\windows\ShellNew
2009-12-11 01:38 . 2009-12-11 01:38 -------- d-----w- c:\windows\Twain32
2009-12-11 01:38 . 2009-12-11 01:38 -------- d-----w- c:\users\debby\AppData\Roaming\Microsoft Web Folders
2009-12-11 01:30 . 2009-12-11 01:30 -------- d-----w- c:\windows\system32\RTCOM
2009-12-11 01:30 . 2009-12-11 01:30 -------- d-----w- c:\program files\Realtek
2009-12-11 01:23 . 2009-12-11 01:23 319456 ----a-w- c:\windows\DIFxAPI.dll
2009-12-11 01:22 . 2009-12-11 01:23 -------- d--h--w- c:\program files\Temp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-05 21:58 . 2009-12-13 04:37 720 ----a-w- c:\programdata\ArcSoft\kodak-printcreations-22-080812-oem\acforall.dll
2010-01-03 02:48 . 2010-01-02 22:30 117760 ----a-w- c:\users\debby\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-01-02 22:30 . 2010-01-02 22:30 52224 ----a-w- c:\users\debby\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2009-12-17 23:30 . 2009-12-17 23:30 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2009-12-13 19:38 . 2009-12-13 19:38 0 ----a-w- c:\users\debby\AppData\Roaming\wklnhst.dat
2009-12-13 04:38 . 2009-12-13 04:38 2380538 ----a-w- c:\programdata\ArcSoft\Global Deploy\CheckUpdate\ArcConnect.exe
2009-12-13 04:30 . 2009-12-13 04:30 77824 ----a-w- c:\programdata\Kodak\EasyShareSetup\ESS\bindbins\bindbins.exe
2009-12-13 04:30 . 2009-12-13 04:30 225280 ----a-w- c:\programdata\Kodak\EasyShareSetup\*censored*\finish.exe
2009-12-13 04:30 . 2009-12-13 04:30 175104 ----a-w- c:\programdata\Kodak\EasyShareSetup\reduced_contents_PrintCreation_expanded\setup.exe
2009-12-13 04:30 . 2009-12-13 04:30 225280 ----a-w- c:\programdata\Kodak\EasyShareSetup\*censored*\update.exe
2009-12-13 04:30 . 2009-12-13 04:30 45056 ----a-w- c:\programdata\Kodak\EasyShareSetup\SysFiles\kb945060\kb945060.exe
2009-12-13 04:30 . 2009-12-13 04:29 225280 ----a-w- c:\programdata\Kodak\EasyShareSetup\*censored*\start.exe
2009-12-13 04:29 . 2009-12-13 04:29 1187840 ----a-w- c:\programdata\Kodak\EasyShareSetup\$SETUP_1e0001_63347\EasyShrx.Dll
2009-12-13 04:20 . 2009-12-13 04:20 114688 ----a-w- c:\programdata\Kodak\EasyShareSetup\$Registration\KodakCameraAPI_8.0.30.1.dll
2009-12-13 04:09 . 2009-12-13 04:09 163840 ----a-w- c:\programdata\Kodak\EasyShareSetup\KDEVICES\CR2\cr_stop.exe
2009-12-13 04:09 . 2009-12-13 04:09 69632 ----a-w- c:\programdata\Kodak\EasyShareSetup\Ksu\ksustop.exe
2009-12-13 04:08 . 2009-12-13 04:08 167936 ----a-w- c:\programdata\Kodak\EasyShareSetup\CCS\CCSStop.exe
2009-12-13 04:08 . 2009-12-13 04:08 425984 ----a-w- c:\programdata\Kodak\EasyShareSetup\$SETUP_140011_2556d0a\EasyShrx.Dll
2009-12-12 17:15 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-12-12 17:15 . 2009-12-12 17:15 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-12-11 18:43 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-12-11 01:52 . 2009-12-08 20:31 67448 ----a-w- c:\users\debby\AppData\Local\GDIPFONTCACHEV1.DAT
2009-12-11 01:40 . 2009-12-11 01:40 5058 ----a-w- c:\windows\Help\hhcolreg.dat
2009-12-11 01:02 . 2006-12-23 01:12 358912 ----a-w- c:\windows\system32\nvraiins.dll
2009-12-11 01:02 . 2006-12-23 01:12 358912 ----a-w- c:\windows\system32\nvraidco.dll
2009-12-11 01:02 . 2006-12-23 01:07 93696 ----a-w- c:\windows\system32\drivers\nvstor32.sys
2009-12-11 01:02 . 2007-01-15 22:35 1032104 ----a-w- c:\windows\system32\drivers\nvmfdx32.sys
2009-12-11 01:02 . 2007-01-15 21:46 198656 ----a-w- c:\windows\system32\fdco1.dll
2009-12-10 23:51 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Sidebar
2009-12-10 23:51 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Calendar
2009-12-10 23:51 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Photo Gallery
2009-12-10 23:51 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Defender
2009-12-10 23:51 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Collaboration
2009-12-10 23:34 . 2009-12-10 23:34 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2009-12-10 22:42 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2009-12-10 22:41 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
2009-11-12 22:07 . 2009-11-12 22:07 79144 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-10-27 14:11 . 2009-12-10 23:16 834048 ----a-w- c:\windows\system32\wininet.dll
2009-10-27 13:16 . 2009-12-10 23:16 78336 ----a-w- c:\windows\system32\ieencode.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2009-12-11 90191]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-12-11 7766016]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-12-11 81920]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-07-21 7625248]
"F-Secure Manager"="c:\program files\F-Secure\Common\FSM32.EXE" [2009-07-09 199264]
"F-Secure TNB"="c:\program files\F-Secure\FSGUI\TNBUtil.exe" [2009-07-09 2349664]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-11 149280]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2009-10-10 203264]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"MaxMenuMgr"="c:\program files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2009-09-26 185640]
c:\users\debby\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Webshots.lnk - c:\program files\Webshots\3.1.5.7617\Launcher.exe [2009-12-10 157088]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
2009-11-13 11:31 247144 ----a-w- c:\program files\TomTom HOME 2\TomTomHOMERunner.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):46,a8,66,5c,f4,79,ca,01
R0 fsbts;fsbts;c:\windows\System32\drivers\fsbts.sys [12/10/2009 8:49 PM 33920]
R1 F-Secure HIPS;F-Secure HIPS Driver;c:\program files\F-Secure\HIPS\drivers\fshs.sys [12/10/2009 8:48 PM 68064]
R1 FSES;F-Secure Email Scanning Driver;c:\windows\System32\drivers\fses.sys [12/10/2009 8:49 PM 35680]
R1 FSFW;F-Secure Firewall Driver;c:\windows\System32\drivers\fsdfw.sys [12/10/2009 8:49 PM 71040]
R1 fsvista;F-Secure Vista Support Driver;c:\program files\F-Secure\Anti-Virus\minifilter\fsvista.sys [12/10/2009 8:48 PM 12384]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [12/16/2009 4:26 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12/16/2009 4:26 PM 74480]
R2 AGCoreService;AG Core Services;c:\program files\AGI\core\4.2\AGCoreService.exe [12/10/2009 10:59 PM 20480]
R2 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe [9/25/2009 11:32 PM 189736]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [11/13/2009 6:31 AM 92008]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\F-Secure\Anti-Virus\minifilter\fsgk.sys [12/10/2009 8:48 PM 107104]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [12/16/2009 4:27 PM 7408]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [12/10/2009 5:24 PM 21504]
S3 FSORSPClient;F-Secure ORSP Client;c:\program files\F-Secure\ORSP Client\fsorsp.exe [12/10/2009 8:48 PM 55936]
S4 F-Secure Filter;F-Secure File System Filter;c:\program files\F-Secure\Anti-Virus\win2k\fsfilter.sys [12/10/2009 8:48 PM 39776]
S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\F-Secure\Anti-Virus\win2k\fsrec.sys [12/10/2009 8:48 PM 25184]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
2010-01-05 c:\windows\Tasks\Scheduled scanning task.job
- c:\progra~1\F-Secure\ANTI-V~1\fsav.exe [2009-12-11 09:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.comcast.net/mycomcast/
uInternet Settings,ProxyOverride = *.local
LSP: c:\program files\F-Secure\FSPS\program\FSLSP.DLL
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-{0BC6E3FA-78EF-4886-842C-5A1258C4455A} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-01-05 18:48
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(640)
c:\program files\f-secure\hips\fshook32.dll
- - - - - - - > 'lsass.exe'(608)
c:\program files\f-secure\hips\fshook32.dll
.
Completion time: 2010-01-05 18:53:44
ComboFix-quarantined-files.txt 2010-01-05 23:53
Pre-Run: 220,036,182,016 bytes free
Post-Run: 219,983,683,584 bytes free
- - End Of File - - 1BED114FC9630E723BCD68F008F7ACF1