ComboFix 10-07-14.01 - admin 07/15/2010 18:59:26.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.959.632 [GMT -4:00]
Running from: e:\documents and settings\admin\Desktop\ComboFix.exe
Command switches used :: e:\documents and settings\admin\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1229 [VPS 100715-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FILE ::
"e:\windows\S8A42E3D0.tmp"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
e:\windows\S8A42E3D0.tmp . . . . failed to delete
.
((((((((((((((((((((((((( Files Created from 2010-06-15 to 2010-07-15 )))))))))))))))))))))))))))))))
.
2010-07-12 00:14 . 2010-07-12 00:14 -------- d-----w- e:\documents and settings\All Users\Application Data\IK Multimedia
2010-07-11 18:52 . 2010-07-11 18:57 -------- d-----w- e:\program files\7-Zip
2010-07-11 01:33 . 2010-07-11 01:33 -------- d-----w- e:\documents and settings\admin\Application Data\TH1
2010-07-10 15:42 . 2010-07-10 15:42 -------- d-----w- e:\program files\MSXML 6.0
2010-07-09 04:44 . 2010-07-09 04:44 -------- d-----w- e:\documents and settings\admin\TruePianos Settings
2010-07-09 04:43 . 2010-07-09 04:43 -------- d-----w- e:\documents and settings\admin\Application Data\Cakewalk
2010-07-08 00:19 . 2010-07-08 00:19 -------- d-----w- e:\program files\ESET
2010-07-07 20:44 . 2010-07-07 20:44 -------- d-----w- e:\documents and settings\Shelley\Application Data\Malwarebytes
2010-07-07 19:20 . 2010-07-07 19:20 -------- d-----w- e:\documents and settings\admin\Application Data\Malwarebytes
2010-07-07 19:19 . 2010-04-29 19:39 38224 ----a-w- e:\windows\system32\drivers\mbamswissarmy.sys
2010-07-07 19:19 . 2010-07-07 19:20 -------- d-----w- e:\program files\Malwarebytes' Anti-Malware
2010-07-07 19:19 . 2010-07-07 19:19 -------- d-----w- e:\documents and settings\All Users\Application Data\Malwarebytes
2010-07-07 19:19 . 2010-04-29 19:39 20952 ----a-w- e:\windows\system32\drivers\mbam.sys
2010-07-07 17:25 . 2010-07-07 17:25 -------- d-----w- e:\windows\system32\CatRoot_bak
2010-07-07 17:23 . 2008-06-13 13:10 272128 -c----w- e:\windows\system32\dllcache\bthport.sys
2010-07-07 17:22 . 2010-02-24 12:31 454016 -c----w- e:\windows\system32\dllcache\mrxsmb.sys
2010-07-07 17:20 . 2010-02-16 13:17 2137088 -c----w- e:\windows\system32\dllcache\ntkrnlmp.exe
2010-07-07 17:20 . 2010-02-16 13:19 2181376 -c----w- e:\windows\system32\dllcache\ntoskrnl.exe
2010-07-07 17:20 . 2010-02-16 12:39 2016768 -c----w- e:\windows\system32\dllcache\ntkrpamp.exe
2010-07-07 17:20 . 2010-02-16 12:39 2058368 -c----w- e:\windows\system32\dllcache\ntkrnlpa.exe
2010-07-06 21:25 . 2010-07-06 21:25 -------- d-----w- e:\program files\Common Files\DigiDesign
2010-07-06 21:25 . 2010-07-06 21:25 -------- d-----w- e:\documents and settings\admin\Application Data\InstallShield
2010-07-06 20:49 . 2010-07-06 20:50 -------- d-----w- e:\documents and settings\admin\Application Data\Propellerhead Software
2010-07-06 18:38 . 2010-07-06 18:38 -------- d-----w- e:\program files\MusicLab
2010-07-06 18:33 . 2010-07-06 18:33 -------- d-----w- e:\program files\DAEMON Tools Toolbar
2010-07-06 18:32 . 2010-07-06 18:38 -------- d-----w- e:\documents and settings\admin\Application Data\DAEMON Tools Lite
2010-07-06 18:32 . 2010-07-06 18:32 -------- d-----w- e:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2010-07-06 05:29 . 2004-08-04 12:00 14848 -c--a-w- e:\windows\system32\dllcache\register.exe
2010-07-06 05:28 . 2004-08-04 12:00 10129408 -c--a-w- e:\windows\system32\dllcache\hwxkor.dll
2010-07-06 05:27 . 2004-08-04 12:00 29184 -c--a-w- e:\windows\system32\dllcache\asptxn.dll
2010-07-06 05:25 . 2004-08-04 12:00 16384 -c--a-w- e:\windows\system32\dllcache\isignup.exe
2010-07-06 05:18 . 2001-08-17 16:13 27165 ----a-w- e:\windows\system32\drivers\fetnd5.sys
2010-07-06 05:10 . 2004-08-04 12:00 24661 -c--a-w- e:\windows\system32\dllcache\spxcoins.dll
2010-07-06 05:10 . 2004-08-04 12:00 24661 ----a-w- e:\windows\system32\spxcoins.dll
2010-07-06 05:10 . 2004-08-04 12:00 13312 -c--a-w- e:\windows\system32\dllcache\irclass.dll
2010-07-06 05:10 . 2004-08-04 12:00 13312 ----a-w- e:\windows\system32\irclass.dll
2010-07-06 05:09 . 2010-07-06 05:09 -------- d-s---w- e:\windows\system32\config\systemprofile\History
2010-07-04 04:18 . 2010-07-06 18:30 -------- d-----w- e:\documents and settings\admin\Application Data\DAEMON Tools
2010-07-04 00:19 . 2010-07-04 00:19 160704 ----a-w- e:\windows\system32\drivers\afcdp.sys
2010-07-04 00:19 . 2010-07-04 00:19 911680 ----a-w- e:\windows\system32\drivers\tdrpm258.sys
2010-07-04 00:18 . 2010-07-04 00:19 581984 ----a-w- e:\windows\system32\drivers\timntr.sys
2010-07-04 00:18 . 2010-07-04 00:18 166272 ----a-w- e:\windows\system32\drivers\snapman.sys
2010-07-04 00:18 . 2010-07-04 00:19 -------- d-----w- e:\program files\Common Files\Acronis
2010-07-04 00:18 . 2010-07-04 00:18 -------- d-----w- e:\program files\Acronis
2010-07-03 00:22 . 2010-07-03 00:22 -------- d--h--w- e:\windows\PIF
2010-07-01 22:21 . 2010-07-01 22:21 63488 ----a-w- e:\documents and settings\admin\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-07-01 22:21 . 2010-07-01 22:21 52224 ----a-w- e:\documents and settings\admin\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-07-01 22:21 . 2010-07-01 22:21 117760 ----a-w- e:\documents and settings\admin\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-07-01 22:20 . 2010-07-01 22:20 -------- d-----w- e:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-07-01 22:20 . 2010-07-01 22:20 -------- d-----w- e:\documents and settings\admin\Application Data\SUPERAntiSpyware.com
2010-07-01 22:20 . 2010-07-01 22:20 -------- d-----w- e:\program files\SUPERAntiSpyware
2010-06-30 06:26 . 2010-06-30 06:26 -------- d-----w- e:\documents and settings\David\TruePianos Settings
2010-06-30 06:25 . 2010-06-30 06:26 -------- d-----w- E:\Cakewalk Projects
2010-06-30 06:25 . 2010-06-30 06:25 -------- d-----w- e:\documents and settings\David\Application Data\Cakewalk
2010-06-30 00:25 . 2010-07-09 04:16 36624 ----a-w- e:\documents and settings\admin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-30 00:18 . 2010-06-30 00:27 -------- d-----w- e:\program files\Antares
2010-06-28 18:15 . 2010-06-28 18:15 -------- d-----w- e:\program files\Xvid
2010-06-28 18:15 . 2009-06-07 20:24 180224 ----a-w- e:\windows\system32\xvidvfw.dll
2010-06-28 18:15 . 2009-06-07 20:16 819200 ----a-w- e:\windows\system32\xvidcore.dll
2010-06-27 19:18 . 2010-06-27 19:38 -------- d-----w- e:\documents and settings\admin\Application Data\vlc
2010-06-27 18:08 . 2010-06-27 18:08 -------- d-----w- e:\documents and settings\admin\Local Settings\Application Data\Ahead
2010-06-25 21:05 . 2010-06-25 21:06 -------- d-----w- e:\documents and settings\admin\Application Data\Vso
2010-06-25 21:05 . 2010-06-25 21:05 47360 ----a-w- e:\documents and settings\admin\Application Data\pcouffin.sys
2010-06-25 21:05 . 2010-02-09 19:37 65602 ----a-w- e:\windows\system32\cook3260.dll
2010-06-25 21:05 . 2010-02-09 19:37 626688 ----a-w- e:\windows\system32\vp7vfw.dll
2010-06-25 21:05 . 2010-02-09 19:37 217127 ----a-w- e:\windows\system32\drv43260.dll
2010-06-25 21:05 . 2010-02-09 19:37 208935 ----a-w- e:\windows\system32\drv33260.dll
2010-06-25 21:05 . 2010-02-09 19:37 176165 ----a-w- e:\windows\system32\drv23260.dll
2010-06-25 21:05 . 2010-02-09 19:37 1184984 ----a-w- e:\windows\system32\wvc1dmod.dll
2010-06-25 21:05 . 2010-02-09 19:37 102439 ----a-w- e:\windows\system32\sipr3260.dll
2010-06-23 17:19 . 2010-06-23 17:19 -------- d-----w- e:\documents and settings\admin\Local Settings\Application Data\PCHealth
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-15 23:20 . 2010-07-15 23:20 0 ----a-w- e:\windows\S8A42E3D0.tmp
2010-07-15 22:36 . 2007-04-10 16:42 552 ----a-w- e:\windows\system32\d3d8caps.dat
2010-07-14 23:03 . 2007-04-01 15:15 664 ----a-w- e:\windows\system32\d3d9caps.dat
2010-07-12 01:25 . 2009-05-07 03:09 48 ----a-w- e:\windows\msocreg32.dat
2010-07-12 00:15 . 2007-03-02 20:27 -------- d--h--w- e:\program files\InstallShield Installation Information
2010-07-11 01:31 . 2008-09-11 17:47 -------- d-----w- e:\documents and settings\admin\Application Data\uTorrent
2010-07-10 00:01 . 2007-03-02 17:20 36624 ----a-w- e:\documents and settings\David\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-06 21:27 . 2009-05-07 03:05 -------- d-----w- e:\program files\IK Multimedia
2010-07-06 18:33 . 2007-12-31 03:40 -------- d-----w- e:\program files\DAEMON Tools Lite
2010-07-06 18:33 . 2007-12-31 03:37 691696 ----a-w- e:\windows\system32\drivers\sptd.sys
2010-07-06 05:41 . 2007-12-31 03:40 -------- d-----w- e:\documents and settings\David\Application Data\DAEMON Tools
2010-07-06 05:24 . 2007-03-02 18:20 22720 ----a-w- e:\windows\system32\emptyregdb.dat
2010-06-30 00:18 . 2007-11-07 04:31 -------- d-----w- e:\program files\Digidesign
2010-06-29 23:18 . 2008-11-20 01:43 -------- d-----w- e:\program files\WIDI
2010-06-25 21:05 . 2007-10-12 17:50 47360 ----a-w- e:\windows\system32\drivers\pcouffin.sys
2010-06-25 21:05 . 2007-10-12 17:50 -------- d-----w- e:\program files\VSO
2010-06-20 17:22 . 2007-06-16 02:57 -------- d-----w- e:\documents and settings\Shelley\Application Data\uTorrent
2010-06-17 01:30 . 2008-01-17 23:09 -------- d-----w- e:\program files\uTorrent
2010-06-14 14:30 . 2007-03-02 18:20 743936 ----a-w- e:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-14 03:48 . 2010-06-14 03:46 536 ---ha-w- E:\os252866.bin
2010-06-06 05:59 . 2008-08-23 01:10 -------- d-----w- e:\program files\Microsoft Silverlight
2010-06-06 03:45 . 2007-05-13 17:02 36176 ----a-w- e:\documents and settings\Shelley\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-01 22:46 . 2010-06-01 22:46 -------- d-----w- e:\documents and settings\David\Application Data\Mozilla-Cache
2010-05-27 22:40 . 2009-04-16 00:07 -------- d-----w- e:\program files\PokerStars
2010-05-27 20:11 . 2010-03-29 02:53 -------- d-----w- e:\documents and settings\David\Application Data\OpenOffice.org2
2010-05-02 05:56 . 2004-08-04 12:00 1850880 ----a-w- e:\windows\system32\win32k.sys
2010-04-20 05:51 . 2004-08-04 12:00 285696 ----a-w- e:\windows\system32\atmfd.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- e:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- e:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-07-15_02.42.39 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-07-15 23:20 . 2010-07-15 23:20 16384 e:\windows\Temp\Perflib_Perfdata_678.dat
+ 2010-07-15 23:20 . 2010-07-15 23:20 16384 e:\windows\Temp\Perflib_Perfdata_544.dat
+ 2010-07-15 22:31 . 2010-07-15 23:20 32768 e:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-03-02 18:25 . 2010-07-15 23:20 32768 e:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-03-02 18:25 . 2010-07-15 23:20 49152 e:\windows\system32\config\systemprofile\Cookies\index.dat
- 2007-03-02 18:25 . 2010-07-15 02:33 49152 e:\windows\system32\config\systemprofile\Cookies\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="e:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="e:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"NeroFilterCheck"="e:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SunJavaUpdateSched"="e:\program files\Java\jre6\bin\jusched.exe" [2009-02-08 136600]
"CTSysVol"="e:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-02-15 57344]
"P17Helper"="P17.dll" [2005-05-03 64512]
"UpdReg"="e:\windows\UpdReg.EXE" [2000-05-11 90112]
"QuickTime Task"="e:\program files\QT Lite\QTTask.exe" [2009-09-05 417792]
"DivXUpdate"="e:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-03-05 1135912]
"TrueImageMonitor.exe"="e:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2010-03-27 5107232]
"Acronis Scheduler2 Service"="e:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2010-03-27 362232]
"SoundMan"="SOUNDMAN.EXE" [2005-09-22 90112]
e:\documents and settings\David\Start Menu\Programs\Startup\
Adobe Gamma.lnk - e:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "e:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- e:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi1"=mapledxp.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"e:\\Documents and Settings\\David\\Desktop\\utorrent150.exe"=
"e:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"e:\\Program Files\\uTorrent\\uTorrent.exe"=
"e:\\Program Files\\Messenger\\msmsgs.exe"=
"e:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"e:\\Program Files\\Free Music Zilla\\FMZilla.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"e:\\WINDOWS\\system32\\lxducoms.exe"=
"e:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"e:\\Program Files\\Skype\\Phone\\Skype.exe"=
"e:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"e:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowOutboundDestinationUnreachable"= 1 (0x1)
R0 tdrpman258;Acronis Try&Decide and Restore Points filter (build 258);e:\windows\system32\drivers\tdrpm258.sys [7/3/2010 8:19 PM 911680]
R1 aswSP;avast! Self Protection;e:\windows\system32\drivers\aswSP.sys [9/14/2008 6:41 PM 78416]
R1 mapledxp;mapledxp;e:\windows\system32\drivers\mapledxp.sys [10/10/2007 1:12 PM 24720]
R1 SASDIFSV;SASDIFSV;e:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 2:25 PM 12872]
R1 SASKUTIL;SASKUTIL;e:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 2:41 PM 67656]
R2 afcdpsrv;Acronis Nonstop Backup service;e:\program files\Common Files\Acronis\CDP\afcdpsrv.exe [7/3/2010 8:19 PM 2480048]
R2 aswFsBlk;aswFsBlk;e:\windows\system32\drivers\aswFsBlk.sys [9/14/2008 6:41 PM 20560]
R2 LF30FS;LF30FS;e:\program files\Everstrike Software\Lock Folder XP 3.6\LF30XP.sys [11/19/2004 7:07 PM 101488]
R2 lxdu_device;lxdu_device;e:\windows\system32\lxducoms.exe -service --> e:\windows\system32\lxducoms.exe -service [?]
R3 afcdp;afcdp;e:\windows\system32\drivers\afcdp.sys [7/3/2010 8:19 PM 160704]
R3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);e:\windows\system32\drivers\vrtaucbl.sys [5/8/2009 2:53 PM 50944]
S3 ipMIDI;nerds.de ipMIDI - Ethernet Midi Ports SvcDesc(WDM);e:\windows\system32\drivers\ipmidi.sys [4/5/2010 12:14 PM 18688]
S4 sptd;sptd;e:\windows\system32\drivers\sptd.sys [12/30/2007 11:37 PM 691696]
.
Contents of the 'Scheduled Tasks' folder
2010-07-15 e:\windows\Tasks\WGASetup.job
- e:\windows\system32\KB905474\wgasetup.exe [2009-05-12 02:18]
.
.
------- Supplementary Scan -------
.
IE: E&xport to Microsoft Excel - e:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Name-Space Handler: ftp\* - {419A0123-4312-1122-A0C0-434FDA6DA542} - e:\program files\CoreFTP\pftpns.dll
FF - ProfilePath - e:\documents and settings\admin\Application Data\Mozilla\Firefox\Profiles\o7ubg68l.default\
FF - prefs.js: browser.search.selectedEngine - DAEMON Search
FF - plugin: e:\program files\Java\jre6\bin\npdeploytk.dll
FF - plugin: e:\program files\Java\jre6\bin\npjpi160_11.dll
FF - plugin: e:\program files\Java\jre6\bin\npoji610.dll
FF - plugin: e:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: e:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: e:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - e:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Adobe\Premiere Pro\1.5\DefaultPreset]
@DACL=(02 0000)
@="e:\\Program Files\\Adobe\\Premiere Pro 1.5 Tryout\\Settings\\DV - NTSC\\Standard 48kHz.prpreset"
[HKEY_LOCAL_MACHINE\software\Adobe\Premiere Pro\1.5\Help]
@DACL=(02 0000)
"AdobeMediaEncoder"="e:\\Program Files\\Adobe\\Premiere Pro 1.5 Tryout\\Help\\1_0_0_0.html"
"Contents"="e:\\Program Files\\Adobe\\Premiere Pro 1.5 Tryout\\Help\\1_0_0_0.html"
"ExportToDVD"="e:\\Program Files\\Adobe\\Premiere Pro 1.5 Tryout\\Help\\1_19_2_0.html"
"HowToUse"="e:\\Program Files\\Adobe\\Premiere Pro 1.5 Tryout\\Help\\0_0_0_0.html"
"Keyboard"="e:\\Program Files\\Adobe\\Premiere Pro 1.5 Tryout\\Help\\1_21_0_0.html"
"Search"="e:\\Program Files\\Adobe\\Premiere Pro 1.5 Tryout\\Help\\search.html"
"Support"="
http://www.adobe.com/support/products/premiere.html"
[HKEY_LOCAL_MACHINE\software\Adobe\Premiere Pro\2.0\DefaultPreset]
@DACL=(02 0000)
@="DV - NTSC\\Standard 48kHz.prpreset"
[HKEY_LOCAL_MACHINE\software\Adobe\Premiere Pro\2.0\Help]
@DACL=(02 0000)
"Support"="
http://www.adobe.com/support/products/premiere.html"
"Search"="e:\\Program Files\\Adobe\\Adobe Premiere Pro 2.0\\Help\\search.html"
"Keyboard"="e:\\Program Files\\Adobe\\Adobe Premiere Pro 2.0\\Help\\1_21_0_0.html"
"HowToUse"="e:\\Program Files\\Adobe\\Adobe Premiere Pro 2.0\\Help\\0_0_0_0.html"
"ExportToDVD"="e:\\Program Files\\Adobe\\Adobe Premiere Pro 2.0\\Help\\1_19_2_0.html"
"AdobeMediaEncoder"="e:\\Program Files\\Adobe\\Adobe Premiere Pro 2.0\\Help\\1_0_0_0.html"
"Contents"="e:\\Program Files\\Adobe\\Adobe Premiere Pro 2.0\\Help\\1_0_0_0.html"
"Registration"="\"
http://store.adobe.com/cgi-bin/WebObjects/WEC?pageID=RegMp1\""
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\|˙˙˙˙Ŕ|ůA~*]
"AB141C35E9F4BF344B9FC010BB17F68A"=""
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(872)
e:\program files\SUPERAntiSpyware\SASWINLO.DLL
- - - - - - - > 'explorer.exe'(3380)
e:\windows\system32\WPDShServiceObj.dll
e:\windows\system32\PortableDeviceTypes.dll
e:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
e:\program files\Alwil Software\Avast4\aswUpdSv.exe
e:\program files\Alwil Software\Avast4\ashServ.exe
e:\program files\Common Files\Acronis\Schedule2\schedul2.exe
e:\program files\Java\jre6\bin\jqs.exe
e:\windows\system32\lxducoms.exe
e:\program files\Alwil Software\Avast4\ashMaiSv.exe
e:\program files\Alwil Software\Avast4\ashWebSv.exe
e:\windows\system32\Rundll32.exe
e:\windows\SOUNDMAN.EXE
e:\program files\Internet Explorer\iexplore.exe
.
**************************************************************************
.
Completion time: 2010-07-15 19:25:23 - machine was rebooted
ComboFix-quarantined-files.txt 2010-07-15 23:25
ComboFix2.txt 2010-07-15 02:44
Pre-Run: 10,410,110,976 bytes free
Post-Run: 10,432,290,816 bytes free
Current=3 Default=3 Failed=0 LastKnownGood=5 Sets=1,2,3,4,5
- - End Of File - - EDE0579AA90FE8B801C5FDAC80CA83C0