ComboFix 11-12-15.02 - SouthernBell 12/15/2011 12:17:36.3.2 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.1.1033.18.2037.1243 [GMT -6:00]
Running from: c:\users\SouthernBell\Desktop\ComboFix.exe
* Created a new restore point
.
.
((((((((((((((((((((((((( Files Created from 2011-11-15 to 2011-12-15 )))))))))))))))))))))))))))))))
.
.
2011-12-15 18:28 . 2011-12-15 18:30 -------- d-----w- c:\users\SouthernBell\AppData\Local\temp
2011-12-15 18:28 . 2011-12-15 18:28 -------- d-----w- c:\users\Public\AppData\Local\temp
2011-12-15 18:28 . 2011-12-15 18:28 -------- d-----w- c:\users\Guest\AppData\Local\temp
2011-12-15 18:28 . 2011-12-15 18:28 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-12-15 18:28 . 2011-12-15 18:28 -------- d-----w- c:\users\colortyme\AppData\Local\temp
2011-12-15 04:43 . 2011-12-15 04:43 29904 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{32ED2984-505E-433E-A39C-A1159DF8A848}\MpKsl8438294d.sys
2011-12-15 04:43 . 2011-12-15 04:43 56200 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{32ED2984-505E-433E-A39C-A1159DF8A848}\offreg.dll
2011-12-15 03:41 . 2011-12-15 03:41 -------- d-----w- c:\users\SouthernBell\AppData\Roaming\Malwarebytes
2011-12-15 03:41 . 2011-12-15 03:41 -------- d-----w- c:\programdata\Malwarebytes
2011-12-15 03:41 . 2011-08-31 23:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-12-15 03:41 . 2011-12-15 03:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-12-15 03:26 . 2011-11-21 10:47 6823496 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{32ED2984-505E-433E-A39C-A1159DF8A848}\mpengine.dll
2011-12-15 03:22 . 2011-12-15 04:49 735142 ----a-w- c:\windows\system32\PerfStringBackup.TMP
2011-12-15 03:14 . 2011-12-15 03:14 -------- d-----w- C:\_OTL
2011-12-14 19:41 . 2011-12-14 19:41 -------- d-----w- c:\users\Guest\AppData\Local\VirtualStore
2011-12-14 04:03 . 2011-12-14 04:32 -------- d-----w- c:\program files\GridinSoft Trojan Killer
2011-12-08 02:36 . 2011-12-08 02:36 -------- d--h--w- c:\users\SouthernBell\AppData\Roaming\Spotify
2011-11-22 20:21 . 2011-11-22 20:21 404640 ---ha-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-21 10:47 . 2011-10-22 23:48 6823496 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-10-12 01:58 . 2006-11-02 08:57 66048 ---ha-w- c:\windows\system32\drivers\smb.sys
2011-10-04 22:22 . 2011-10-27 23:18 703824 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A50AFB11-0EE6-48C4-A630-47BCE84B92F5}\gapaengine.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-17 221184]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-17 81920]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-08-31 1047208]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AudioEndpointBuilder]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Audiosrv]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HdAudAddService]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HDAudBus]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MMCSS]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96C-E325-11CE-BFC1-08002BE10318}]
@="[6cFgE][S?û?d, ?ìdeô ??d gª?è ¢o?tr?l?è?š !!! !!! !]"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{640167b4-59b0-47a6-b335-a6b3c0695aea}]
@="Portable Media Devices"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^BlackBerry Desktop Redirector.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\BlackBerry Desktop Redirector.lnk
backup=c:\windows\pss\BlackBerry Desktop Redirector.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Desktop Manager.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Desktop Manager.lnk
backup=c:\windows\pss\Desktop Manager.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HotSync Manager.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HotSync Manager.lnk
backup=c:\windows\pss\HotSync Manager.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Connections.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Connections.lnk
backup=c:\windows\pss\HP Connections.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^VProperty.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\VProperty.lnk
backup=c:\windows\pss\VProperty.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^colortyme^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^palmOne Registration.lnk]
path=c:\users\colortyme\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\palmOne Registration.lnk
backup=c:\windows\pss\palmOne Registration.lnk.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^colortyme^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^TurboApps WinMobile Conduit.lnk]
path=c:\users\colortyme\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TurboApps WinMobile Conduit.lnk
backup=c:\windows\pss\TurboApps WinMobile Conduit.lnk.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^SouthernBell^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^FrostWire On Startup.lnk]
path=c:\users\SouthernBell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FrostWire On Startup.lnk
backup=c:\windows\pss\FrostWire On Startup.lnk.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^SouthernBell^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^IMVU.lnk]
path=c:\users\SouthernBell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\IMVU.lnk
backup=c:\windows\pss\IMVU.lnk.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^SouthernBell^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Logitech . Product Registration.lnk]
path=c:\users\SouthernBell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Product Registration.lnk
backup=c:\windows\pss\Logitech . Product Registration.lnk.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^SouthernBell^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^wkcalrem.LNK]
path=c:\users\SouthernBell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wkcalrem.LNK
backup=c:\windows\pss\wkcalrem.LNK.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-10-15 06:04 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service]
2008-11-20 16:06 178688 ---ha-w- c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CarboniteSetupLite]
2009-08-04 07:49 318096 ----a-w- c:\program files\Carbonite\CarbonitePreinstaller.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
2007-01-10 05:59 115816 ----a-w- c:\program files\Common Files\Symantec Shared\ccApp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2006-11-06 09:05 106496 ---ha-w- c:\windows\System32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
2006-11-28 23:42 46704 ----a-w- c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2008-12-08 21:50 54576 ---ha-w- c:\program files\HP\HP Software Update\hpwuschd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
2006-10-18 17:32 472800 ----a-w- c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2006-11-06 09:02 98304 ---ha-w- c:\windows\System32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2005-02-17 00:15 221184 ----a-w- c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2005-02-17 00:15 81920 ----a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-09-24 07:10 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-02-06 23:51 3885408 ---ha-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\osCheck]
2006-10-27 13:18 22696 ----a-w- c:\program files\Norton Internet Security\osCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2006-11-06 09:02 81920 ---ha-w- c:\windows\System32\igfxpers.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl]
2006-11-06 18:58 159744 ----a-w- c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
2006-11-24 23:33 167936 ----a-w- c:\program files\HP\QuickPlay\QPService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-09-08 16:17 421888 ---ha-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SPC610NC_Monitor]
2006-11-03 16:01 319488 ---ha-w- c:\windows\Philips\SPC610NC\Monitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-01-06 18:06 149280 ---ha-w- c:\program files\Java\jre6\bin\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec PIF AlertEng]
2007-11-29 01:51 583048 ----a-w- c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2006-11-15 05:02 815104 ---ha-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WAWifiMessage]
2006-10-18 17:56 317152 ----a-w- c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2006-11-02 12:33 1004136 ----a-w- c:\program files\Windows Defender\MSASCui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Mobile Device Center]
2007-05-31 15:21 648072 ---ha-w- c:\windows\WindowsMobile\wmdc.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Mobile-based device management]
2006-11-02 09:45 215552 ----a-w- c:\windows\WindowsMobile\wmdSync.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2378550397-1645097847-830149378-1001]
"EnableNotificationsRef"=dword:00000001
.
R0 szkg5;szkg5;c:\windows\system32\DRIVERS\szkg.sys [x]
R0 szkgfs;szkgfs;c:\windows\system32\drivers\szkgfs.sys [x]
R1 MpKsl02141418;MpKsl02141418;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BE1E524A-871F-46F4-9117-2BD53B97740B}\MpKsl02141418.sys [x]
R1 MpKsl17cb6a83;MpKsl17cb6a83;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{591BBD4F-D4F9-4B5A-9C11-958B1387156E}\MpKsl17cb6a83.sys [x]
R1 MpKsl2477acb6;MpKsl2477acb6;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6189334F-32F8-4961-9DC8-8F345FCCA8E6}\MpKsl2477acb6.sys [x]
R1 MpKsl376747fd;MpKsl376747fd;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{87D9F391-02B1-42B6-81A1-D2415688ADE7}\MpKsl376747fd.sys [x]
R1 MpKsl37ffeb39;MpKsl37ffeb39;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8EBF86C5-89DD-4DBA-A220-962A6427822C}\MpKsl37ffeb39.sys [x]
R1 MpKsl394acba6;MpKsl394acba6;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A25BBA2A-76EB-4FD7-8349-761F4297984F}\MpKsl394acba6.sys [x]
R1 MpKsl5e3160c2;MpKsl5e3160c2;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3106923C-0AB7-48EA-BF1D-FCB794A2F2F4}\MpKsl5e3160c2.sys [x]
R1 MpKsl83b93cd4;MpKsl83b93cd4;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{DA9FB80B-4FA3-48EB-858C-62F6A84E9574}\MpKsl83b93cd4.sys [x]
R1 MpKsl89d2da97;MpKsl89d2da97;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{78753302-D25B-4779-80A4-DEDC896D7ED2}\MpKsl89d2da97.sys [x]
R1 MpKslbacf7c01;MpKslbacf7c01;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6189334F-32F8-4961-9DC8-8F345FCCA8E6}\MpKslbacf7c01.sys [x]
R1 MpKslc3fea722;MpKslc3fea722;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{DA9FB80B-4FA3-48EB-858C-62F6A84E9574}\MpKslc3fea722.sys [x]
R1 MpKslc602097f;MpKslc602097f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3106923C-0AB7-48EA-BF1D-FCB794A2F2F4}\MpKslc602097f.sys [x]
R1 SASDIFSV;SASDIFSV;c:\users\SOUTHE~1\AppData\Local\Temp\SAS_SelfExtract\SASDIFSV.SYS [x]
R1 SASKUTIL;SASKUTIL;c:\users\SOUTHE~1\AppData\Local\Temp\SAS_SelfExtract\SASKUTIL.sys [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [x]
R3 SASENUM;SASENUM;c:\users\SOUTHE~1\AppData\Local\Temp\SAS_SelfExtract\SASENUM.SYS [x]
R3 SPC610NC;SPC 610NC Laptop Camera;c:\windows\system32\DRIVERS\SPC610NC.SYS [2007-01-19 409728]
S1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\idsdefs\20070308.001\IDSvix86.sys [2007-02-14 212280]
S1 MpKsl8438294d;MpKsl8438294d;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{32ED2984-505E-433E-A39C-A1159DF8A848}\MpKsl8438294d.sys [2011-12-15 29904]
S2 iPodDrv;iPodDrv;c:\windows\system32\drivers\iPodDrv.sys [2011-04-15 6656]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-08-31 22216]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 43392]
S3 SYMNDISV;SYMNDISV;c:\windows\System32\Drivers\SYMNDISV.SYS [2006-10-25 37008]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - 18930901
*NewlyCreated* - ASWMBR
*NewlyCreated* - COMHOST
*NewlyCreated* - MPKSL8438294D
*Deregistered* - 18930901
*Deregistered* - aswMBR
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
bthsvcs REG_MULTI_SZ BthServ
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-15 c:\windows\Tasks\User_Feed_Synchronization-{CC6CCA5F-ACEF-4CA9-BE0E-804557105330}.job
- c:\windows\system32\msfeedssync.exe [2006-11-02 09:45]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\users\SouthernBell\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IMVU\Run IMVU.lnk
TCP: DhcpNameServer = 24.116.2.50 24.116.2.34
.
- - - - ORPHANS REMOVED - - - -
.
SafeBoot-23709095.sys
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-12-15 12:30
Windows 6.0.6000 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-12-15 12:37:06
ComboFix-quarantined-files.txt 2011-12-15 18:37
ComboFix2.txt 2011-10-22 19:19
.
Pre-Run: 24,901,558,272 bytes free
Post-Run: 27,372,683,264 bytes free
.
- - End Of File - - 8FD08533FD2019E91E4F6D2F051E9BE2