ComboFix 11-04-20.01 - Robert Hornshaw 20/04/2011 20:18:43.3.4 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3292.2383 [GMT 1:00]
Running from: c:\users\Robert Hornshaw\Desktop\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
FW: McAfee Firewall *Enabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
SP: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Resident AV is active
.
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Robert Hornshaw\GoToAssistDownloadHelper.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-03-20 to 2011-04-20 )))))))))))))))))))))))))))))))
.
.
2011-04-20 19:27 . 2011-04-20 19:27 -------- d-----w- c:\users\Robert Hornshaw\AppData\Local\temp
2011-04-20 19:27 . 2011-04-20 19:27 -------- d-----w- c:\users\Public\AppData\Local\temp
2011-04-20 19:27 . 2011-04-20 19:27 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-04-16 08:59 . 2011-04-16 08:59 -------- d-----w- c:\program files\Common Files\Java
2011-04-15 21:03 . 2011-03-03 15:42 739328 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-15 21:03 . 2011-02-17 06:23 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-04-10 16:33 . 2011-04-10 16:33 -------- d-----w- c:\users\Robert Hornshaw\AppData\Roaming\PCDr
2011-04-08 11:24 . 2011-04-08 11:24 -------- d-----w- c:\users\Robert Hornshaw\AppData\Roaming\SUPERAntiSpyware.com
2011-04-08 10:39 . 2011-04-08 10:47 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-04-05 08:39 . 2011-04-05 08:39 322476 ----a-w- c:\programdata\SPLEC05.tmp
2011-04-05 08:38 . 2011-04-05 08:38 322476 ----a-w- c:\programdata\SPLB5D8.tmp
2011-04-01 17:16 . 2011-04-01 17:17 -------- d-----w- c:\program files\armadacustomtoolbar
2011-03-31 19:26 . 2011-03-31 19:26 -------- d-----w- c:\programdata\McAfee Security Scan
2011-03-31 19:26 . 2011-04-03 06:05 -------- d-----w- c:\program files\McAfee Security Scan
2011-03-31 17:06 . 2011-03-31 17:07 -------- d-----w- c:\users\Robert Hornshaw\AppData\Roaming\UseNeXT
2011-03-31 17:06 . 2011-04-01 17:24 -------- d-----w- c:\program files\UseNeXT
2011-03-31 15:14 . 2011-03-31 15:15 -------- d-----w- c:\users\Robert Hornshaw\AppData\Roaming\Apple Computer
2011-03-31 15:14 . 2011-03-31 15:14 -------- d-----w- c:\users\Robert Hornshaw\AppData\Local\Apple Computer
2011-03-31 15:13 . 2011-04-07 14:43 -------- d-----w- c:\program files\iPod
2011-03-31 15:13 . 2011-04-07 14:43 -------- d-----w- c:\program files\iTunes
2011-03-31 15:13 . 2011-03-31 15:13 -------- d-----w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-03-31 15:12 . 2011-03-31 15:12 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin7.dll
2011-03-31 15:12 . 2011-03-31 15:12 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin6.dll
2011-03-31 15:12 . 2011-03-31 15:12 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin5.dll
2011-03-31 15:12 . 2011-03-31 15:12 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin4.dll
2011-03-31 15:12 . 2011-03-31 15:12 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin3.dll
2011-03-31 15:12 . 2011-03-31 15:12 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin2.dll
2011-03-31 15:12 . 2011-03-31 15:12 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin.dll
2011-03-31 15:11 . 2011-03-31 15:13 -------- d-----w- c:\programdata\Apple Computer
2011-03-31 15:11 . 2011-03-31 15:12 -------- d-----w- c:\program files\QuickTime
2011-03-31 15:11 . 2011-03-31 15:11 -------- d-----w- c:\users\Robert Hornshaw\AppData\Local\Apple
2011-03-31 15:11 . 2011-03-31 15:11 -------- d-----w- c:\program files\Apple Software Update
2011-03-31 15:09 . 2011-03-31 15:09 -------- d-----w- c:\program files\Bonjour
2011-03-31 15:08 . 2011-03-31 15:13 -------- d-----w- c:\program files\Common Files\Apple
2011-03-31 15:08 . 2011-03-31 15:11 -------- d-----w- c:\programdata\Apple
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-12 12:43 . 2011-03-12 12:43 2503808 ----a-w- c:\programdata\SPL6576.tmp
2011-03-12 12:42 . 2011-03-12 12:42 2503808 ----a-w- c:\programdata\SPL40E6.tmp
2011-03-12 12:31 . 2011-03-12 12:31 2513040 ----a-w- c:\programdata\SPL1C1D.tmp
2011-03-12 09:44 . 2011-03-12 09:44 333337 ----a-w- c:\programdata\SPLE649.tmp
2011-03-12 09:43 . 2011-03-12 09:43 333337 ----a-w- c:\programdata\SPLCA8F.tmp
2011-02-28 14:22 . 2011-02-28 14:22 325828 ----a-w- c:\programdata\SPLA106.tmp
2011-02-28 14:20 . 2011-02-28 14:20 325828 ----a-w- c:\programdata\SPL5038.tmp
2011-02-25 15:46 . 2011-02-25 15:46 52844 ----a-w- c:\programdata\SPLEFC3.tmp
2011-02-25 15:44 . 2011-02-25 15:44 52844 ----a-w- c:\programdata\SPL40BD.tmp
2011-02-21 09:43 . 2011-02-21 09:43 110635 ----a-w- c:\programdata\SPL235A.tmp
2011-02-21 09:41 . 2011-02-21 09:41 143173 ----a-w- c:\programdata\SPLB50D.tmp
2011-02-18 15:36 . 2011-02-18 15:36 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2011-02-18 15:36 . 2011-02-18 15:36 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll
2011-02-13 20:47 . 2011-02-13 20:47 25857583 ----a-w- c:\programdata\SPL4E38.tmp
2011-02-04 20:39 . 2011-02-04 20:39 259507 ----a-w- c:\programdata\SPLA968.tmp
2011-02-04 20:38 . 2011-02-04 20:38 259507 ----a-w- c:\programdata\SPL83FD.tmp
2011-02-04 20:35 . 2011-02-04 20:35 238987 ----a-w- c:\programdata\SPLEE92.tmp
2011-02-04 20:33 . 2011-02-04 20:33 238987 ----a-w- c:\programdata\SPLBD46.tmp
2011-02-02 20:40 . 2010-05-10 20:13 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-02-02 08:06 . 2011-02-02 08:06 67404 ----a-w- c:\programdata\SPLC5A1.tmp
2011-02-02 08:02 . 2011-02-02 08:02 67404 ----a-w- c:\programdata\SPL9D67.tmp
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{29c0f5ff-3564-46bc-9f4a-50c73f426486}]
2010-10-27 20:13 81920 ----a-w- c:\program files\armadacustomtoolbar\armadacustomtoolbarX.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D9B924B9-98DF-4E68-BFFF-F11F3CD601E1}]
2010-08-19 03:12 109056 ----a-w- c:\program files\LiveFo\LiveFo.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{29c0f5ff-3564-46bc-9f4a-50c73f426486}"= "c:\program files\armadacustomtoolbar\armadacustomtoolbarX.dll" [2010-10-27 81920]
.
[HKEY_CLASSES_ROOT\clsid\{29c0f5ff-3564-46bc-9f4a-50c73f426486}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\MOBK]
@="{3c3f3c1a-9153-7c05-f938-622e7003894d}"
[HKEY_CLASSES_ROOT\CLSID\{3c3f3c1a-9153-7c05-f938-622e7003894d}]
2010-04-13 20:11 2872120 ----a-w- c:\program files\McAfee Online Backup\MOBKshell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\MOBK2]
@="{e6ea1d7d-144e-b977-98c4-84c53c1a69d0}"
[HKEY_CLASSES_ROOT\CLSID\{e6ea1d7d-144e-b977-98c4-84c53c1a69d0}]
2010-04-13 20:11 2872120 ----a-w- c:\program files\McAfee Online Backup\MOBKshell.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\MOBK3]
@="{b4caf489-1eec-c617-49ad-8d7088598c06}"
[HKEY_CLASSES_ROOT\CLSID\{b4caf489-1eec-c617-49ad-8d7088598c06}]
2010-04-13 20:11 2872120 ----a-w- c:\program files\McAfee Online Backup\MOBKshell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-08-20 39408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-03-16 2423752]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2008-07-18 6246400]
"diagnostics"="c:\program files\Thomson\ST330\diagnostics\diagnostics.exe" [2009-06-21 557149]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-06-03 206064]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-25 136216]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-25 171032]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-25 170520]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-03-07 421160]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
.
c:\users\Robert Hornshaw\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-2-27 1316192]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-2-27 1316192]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2010-12-16 10:25 13672 ----a-w- c:\program files\Citrix\GoToAssist\615\g2awinlogon.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
%ProgramFiles%\Windows Defender\MSASCui.exe -hide [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-20 23:07 932288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-01-31 08:44 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dellsupportcenter]
2009-06-03 13:46 206064 ----a-w- c:\program files\Dell Support Center\bin\sprtcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2010-03-18 09:00 136176 ----atw- c:\users\Robert Hornshaw\AppData\Local\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxdnamon]
2008-03-27 15:13 16040 ----a-w- c:\program files\Lexmark 2600 Series\lxdnamon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxdnmon.exe]
2008-03-27 15:13 660136 ----a-w- c:\program files\Lexmark 2600 Series\lxdnmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
2010-12-20 17:08 963976 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (rootkit-scan)]
2010-12-20 17:08 963976 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mcui_exe]
2010-11-22 18:15 1193848 ----a-w- c:\program files\McAfee.com\Agent\mcagent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-26 16:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nmapp]
2008-05-21 16:26 451896 ----a-w- c:\program files\Pure Networks\Network Magic\nmapp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-10-29 13:49 249064 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2011-03-16 22:24 2423752 ----a-w- c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-08-20 08:41 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2587230002-3812537154-1661091937-1000]
"EnableNotificationsRef"=dword:00000007
.
R2 ABP_InstallCheckerService;ABP_InstallCheckerService;c:\users\ROBERT~1\AppData\Local\Temp\nsgB854.tmp\ABP_InstallChecker.exe [x]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 135664]
R2 Mp3Rocket Toolbar Helper;Mp3Rocket Toolbar Helper;c:\program files\MP3 Rocket Toolbar\Mp3RocketSvc.exe [x]
R3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\NETGEAR\WN111v2\jswpsapi.exe [x]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-10-13 84264]
R3 PCD5SRVC{3F6A8B78-EC003E00-05040104};PCD5SRVC{3F6A8B78-EC003E00-05040104} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms [2008-11-04 22904]
R3 Revoflt;Revoflt;c:\windows\system32\DRIVERS\revoflt.sys [2009-12-30 27192]
S1 jswpslwf;JumpStart Wireless Filter Driver;c:\windows\system32\DRIVERS\jswpslwf.sys [2008-10-01 20384]
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2010-10-13 64304]
S1 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2010-10-13 164840]
S1 MOBKFilter;MOBKFilter;c:\windows\system32\DRIVERS\MOBK.sys [2010-04-13 54776]
S2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [2008-07-18 73728]
S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2008-12-18 155648]
S2 lxdn_device;lxdn_device;c:\windows\system32\lxdncoms.exe [2008-02-27 594600]
S2 lxdnCATSCustConnectService;lxdnCATSCustConnectService;c:\windows\system32\spool\DRIVERS\W32X86\3\\lxdnserv.exe [2008-02-27 98984]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2010-03-10 271480]
S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2010-03-10 271480]
S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2010-03-10 271480]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2010-10-13 188136]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2010-10-13 141792]
S2 MOBKbackup;McAfee Online Backup;c:\program files\McAfee Online Backup\MOBKbackup.exe [2010-04-13 229688]
S2 RtNdPt60;Realtek NDIS Protocol Driver;c:\windows\system32\DRIVERS\RtNdPt60.sys [2008-07-21 27648]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-10-13 55840]
S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2009-02-23 112128]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-10-13 313288]
.
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - mfeavfk01
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 09:47]
.
2011-04-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 09:47]
.
2011-04-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2587230002-3812537154-1661091937-1000Core.job
- c:\users\Robert Hornshaw\AppData\Local\Google\Update\GoogleUpdate.exe [2010-04-21 09:00]
.
2011-04-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2587230002-3812537154-1661091937-1000UA.job
- c:\users\Robert Hornshaw\AppData\Local\Google\Update\GoogleUpdate.exe [2010-04-21 09:00]
.
2011-04-20 c:\windows\Tasks\RtlNICDiagVistaStart.job
- c:\program files\Realtek\RTNICDiag\RTNICDiag.exe [2009-05-07 11:18]
.
2011-04-20 c:\windows\Tasks\User_Feed_Synchronization-{382A7587-33DD-4808-8928-734712285AAF}.job
- c:\windows\system32\msfeedssync.exe [2011-04-15 04:43]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.karoo.co.uk/uInternet Settings,ProxyOverride = *.local
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} -
DPF: Garmin Communicator Plug-In -
hxxps://my.garmin.com/static/m/cab/2.8.1/GarminAxControl.CAB.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
AddRemove-UseNeXT_is1 - c:\program files\UseNeXT\unins000.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-04-20 20:27
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PCD5SRVC{3F6A8B78-EC003E00-05040104}]
"ImagePath"="\??\c:\progra~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\st330service]
"ImagePath"="C:\Program Files/Thomson/ST330/service/st330service.exe -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2587230002-3812537154-1661091937-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*y*æ*i%\OpenWithList]
@Class="Shell"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-04-20 20:29:11
ComboFix-quarantined-files.txt 2011-04-20 19:29
ComboFix2.txt 2010-10-25 07:01
ComboFix3.txt 2009-09-26 07:44
.
Pre-Run: 361,576,722,432 bytes free
Post-Run: 361,942,728,704 bytes free
.
- - End Of File - - 098999F1B6D4504AD3BEB8A756D5C1A9