Laptop running very well , thank you.
ComboFix 10-01-26.02 - charlie 27/01/2010 3:30.3.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.44.1033.18.2038.1063 [GMT 0:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Spybot - Search and Destroy *enabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Files Created from 2009-12-27 to 2010-01-27 )))))))))))))))))))))))))))))))
.
2010-01-27 03:15 . 2010-01-27 03:15 ——– d—–w- C:\$AVG
2010-01-27 02:39 . 2010-01-27 02:25 1260800 —-a-w- c:\programdata\avg9\update\backup\avgfrw.exe
2010-01-27 02:39 . 2010-01-27 02:25 3777280 —-a-w- c:\programdata\avg9\update\backup\setup.exe
2010-01-27 02:27 . 2010-01-27 02:27 360584 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-27 02:24 . 2010-01-27 02:24 ——– d—–w- c:\programdata\avg9
2010-01-26 02:47 . 2010-01-26 02:47 ——– d—–w- c:\users\new user avcccount\AppData\Local\VirtualStore
2010-01-26 01:50 . 2010-01-26 01:51 ——– d—–w- c:\users\new user avcccount\AppData\Local\PokerStars
2010-01-25 23:21 . 2009-04-17 06:18 ——– d—–w- c:\users\new user avcccount\AppData\Local\Microsoft Help
2010-01-25 23:21 . 2006-11-02 12:37 ——– d—–w- c:\users\new user avcccount\AppData\Roaming\Media Center Programs
2010-01-23 18:01 . 2010-01-23 18:01 ——– d–h–w- c:\windows\PIF
2010-01-19 18:14 . 2010-01-19 18:14 ——– d—–w- c:\program files\ERUNT
2010-01-16 16:10 . 2009-10-19 14:42 156672 —-a-w- c:\windows\system32\t2embed.dll
2010-01-16 16:10 . 2009-10-19 14:39 24064 —-a-w- c:\windows\system32\lpk.dll
2010-01-16 16:10 . 2009-10-19 14:37 72704 —-a-w- c:\windows\system32\fontsub.dll
2010-01-16 16:10 . 2009-10-19 14:37 10240 —-a-w- c:\windows\system32\dciman32.dll
2010-01-16 16:10 . 2009-10-19 14:36 34304 —-a-w- c:\windows\system32\atmlib.dll
2010-01-16 16:10 . 2009-10-19 11:45 289792 —-a-w- c:\windows\system32\atmfd.dll
2010-01-14 16:29 . 2010-01-27 03:15 ——– d—–w- c:\windows\system32\wbem\repository
2010-01-07 21:22 . 2010-01-07 21:22 ——– d—–w- c:\program files\KeyTweak
2010-01-07 15:02 . 2010-01-07 15:02 ——– d—–w- c:\program files\AutoHotkey
2010-01-02 14:00 . 2009-09-02 10:58 1107200 —-a-w- c:\programdata\AVG Security Toolbar\IEToolbar.dll
2010-01-01 19:54 . 2010-01-01 19:54 ——– d—–w- c:\program files\Stoxpoker.com
2009-12-29 16:52 . 2009-12-29 16:52 56 —ha-w- c:\windows\system32\ezsidmv.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-27 02:27 . 2008-05-05 11:01 ——– d—–w- c:\programdata\avg8
2010-01-27 02:27 . 2008-05-05 11:01 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-01-27 02:27 . 2008-05-05 11:01 333192 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-01-27 02:27 . 2008-05-05 11:01 28424 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-01-27 02:24 . 2008-05-05 11:01 ——– d—–w- c:\program files\AVG
2010-01-26 23:18 . 2009-12-17 18:48 ——– d—–w- c:\program files\PokerTracker 3
2010-01-26 13:01 . 2008-03-10 16:03 ——– d—–w- c:\programdata\Spybot - Search & Destroy
2010-01-26 13:01 . 2009-06-12 07:58 ——– d—–w- c:\programdata\AVG Security Toolbar
2010-01-26 13:01 . 2009-04-15 13:13 ——– d—–w- c:\programdata\Microsoft Help
2010-01-26 13:01 . 2008-05-12 16:07 ——– d—–w- c:\programdata\HP Product Assistant
2010-01-26 13:01 . 2008-05-05 11:01 ——– d—–w- c:\programdata\avg8(836)
2010-01-26 13:01 . 2008-03-10 16:03 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-01-26 13:01 . 2009-12-17 12:03 ——– d—–w- c:\program files\mIRC
2010-01-26 13:01 . 2009-12-16 21:23 ——– d—–w- c:\program files\CamStudio
2010-01-26 13:01 . 2009-03-26 16:14 ——– d—–w- c:\program files\S2 PCSync
2010-01-26 13:01 . 2008-05-22 20:26 ——– d—–w- c:\program files\PokerStars
2010-01-25 02:02 . 2009-06-12 07:58 ——– d—–w- c:\programdata\AVG Security Toolbar(101)
2010-01-20 19:13 . 2008-03-30 13:01 ——– d—–w- c:\users\charlie\AppData\Roaming\uTorrent
2010-01-19 19:32 . 2009-06-06 07:48 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-19 06:02 . 2009-12-17 12:03 ——– d—–w- c:\users\charlie\AppData\Roaming\mIRC
2010-01-16 16:14 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2010-01-14 11:12 . 2009-10-04 09:13 181120 ——w- c:\windows\system32\MpSigStub.exe
2010-01-10 05:35 . 2009-12-08 09:44 ——– d—–w- c:\users\charlie\AppData\Roaming\TeamViewer
2010-01-08 15:40 . 2008-04-04 12:37 ——– d—–w- c:\users\charlie\AppData\Roaming\Vso
2010-01-08 15:15 . 2008-04-05 17:57 ——– d—–w- c:\programdata\vsosdk
2010-01-07 19:25 . 2008-04-22 18:48 ——– d—–w- c:\program files\Nokia
2010-01-07 18:58 . 2008-03-31 18:25 ——– d—–w- c:\program files\Google
2010-01-07 18:55 . 2009-03-25 15:22 ——– d—–w- c:\program files\Bonjour
2010-01-07 18:52 . 2009-03-25 15:21 ——– d—–w- c:\program files\Common Files\Apple
2009-12-29 18:25 . 2009-07-25 12:36 ——– d—–w- c:\users\charlie\AppData\Roaming\Skype
2009-12-29 16:52 . 2009-07-25 12:38 ——– d—–w- c:\users\charlie\AppData\Roaming\skypePM
2009-12-23 08:07 . 2009-12-12 13:43 2066200 —-a-w- c:\programdata\avg8(836)\update\backup\avgcorex.dll
2009-12-22 13:55 . 2008-06-10 15:14 ——– d—–w- c:\program files\PokerStove
2009-12-18 12:52 . 2010-01-26 13:15 832512 —-a-w- c:\windows\system32\wininet.dll
2009-12-18 12:48 . 2010-01-26 13:15 56320 —-a-w- c:\windows\system32\iesetup.dll
2009-12-18 12:48 . 2010-01-26 13:15 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-12-18 12:48 . 2010-01-26 13:15 52736 —-a-w- c:\windows\AppPatch\iebrshim.dll
2009-12-18 12:46 . 2010-01-26 13:15 72704 —-a-w- c:\windows\system32\admparse.dll
2009-12-18 10:18 . 2010-01-26 13:15 26624 —-a-w- c:\windows\system32\ieUnatt.exe
2009-12-18 08:45 . 2010-01-26 13:15 48128 —-a-w- c:\windows\system32\mshtmler.dll
2009-12-17 18:56 . 2009-12-17 18:56 ——– d—–w- c:\program files\PostgreSQL
2009-12-13 15:23 . 2009-09-01 10:18 ——– d—–w- c:\users\charlie\AppData\Roaming\HpUpdate
2009-12-11 15:17 . 2009-05-05 20:39 ——– d—–w- c:\users\charlie\AppData\Roaming\FrostWire
2009-12-08 09:44 . 2009-12-08 09:44 ——– d—–w- c:\program files\QS
2009-12-04 10:50 . 2008-03-13 17:53 ——– d—–w- c:\program files\Java
2009-12-04 07:38 . 2009-12-04 07:38 784136 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-11-23 21:18 . 2009-12-17 18:58 38208 —-a-w- c:\users\postgres.laptop\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-11-23 21:18 . 2009-11-23 21:20 38208 —-a-w- c:\users\Default\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-11-21 12:00 . 2008-04-03 14:45 6648 —-a-w- c:\users\charlie\AppData\Local\d3d9caps.dat
2009-11-16 03:13 . 2009-11-16 03:13 216576 —-a-w- c:\windows\system32\drivers\Rtlh86.sys
2009-11-12 07:24 . 2009-11-12 07:24 94208 —-a-w- c:\windows\system32\RTNUninst32.dll
2009-11-09 13:34 . 2009-12-09 09:11 24064 —-a-w- c:\windows\system32\nshhttp.dll
2009-11-09 13:30 . 2009-12-09 09:11 31232 —-a-w- c:\windows\system32\httpapi.dll
2009-11-09 11:17 . 2009-12-09 09:11 396800 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-29 07:59 . 2009-11-26 17:36 2048 —-a-w- c:\windows\system32\tzres.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-01-27_03.06.14 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-12-19 00:29 . 2010-01-27 03:18 74090 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-03-08 17:44 . 2010-01-27 03:18 14838 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3934529276-3636103968-3449759745-1000_UserData.bin
- 2008-03-08 17:37 . 2010-01-27 02:47 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-03-08 17:37 . 2010-01-27 03:27 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-03-08 18:17 . 2010-01-27 03:13 5164 c:\windows\System32\WDI\ERCQueuedResolutions.dat
- 2010-01-27 02:34 . 2010-01-27 02:34 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2010-01-27 03:14 . 2010-01-27 03:14 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2010-01-27 03:14 . 2010-01-27 03:14 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2010-01-27 02:34 . 2010-01-27 02:34 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2006-11-02 13:05 . 2010-01-27 03:18 101602 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 10:33 . 2010-01-27 03:19 623342 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2010-01-27 02:42 623342 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2010-01-27 02:42 108526 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:33 . 2010-01-27 03:19 108526 c:\windows\System32\perfc009.dat
- 2008-03-08 17:37 . 2010-01-27 02:47 475136 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-03-08 17:37 . 2010-01-27 03:27 475136 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-03-08 17:37 . 2010-01-27 02:47 851968 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-03-08 17:37 . 2010-01-27 03:27 851968 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2009-04-02 11:47 333192 —-a-w- c:\program files\AskBarDis\bar\bin\askBar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-11-25 13:01 1230080 —-a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2009-04-02 333192]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-03-08 1232896]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-08-05 39408]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2007-12-18 1006264]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-13 4399104]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-11-22 630784]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-02-27 153136]
"recinfo256"="c:\recinfo\RecInfo.exe" [2007-10-23 2764800]
"FixCamera"="c:\windows\FixCamera.exe" [2007-04-19 20480]
"tsnpstd3"="c:\windows\tsnpstd3.exe" [2007-04-23 262144]
"snpstd3"="c:\windows\vsnpstd3.exe" [2007-04-25 831488]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-11 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-11 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-11 133656]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-12 342312]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2006-11-02 215552]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-01-27 2033432]
c:\users\charlie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
LAUNCH befrair or pokerstars.ahk - Shortcut.lnk - c:\users\charlie\Desktop\AUTIOHOTKEY SCRITS\LAUNCH befrair or pokerstars.ahk [2010-1-7 708]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [05/05/2008 11:01 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\System32\drivers\avgtdix.sys [27/01/2010 02:27 360584]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [27/01/2010 02:24 906520]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [27/01/2010 02:24 285392]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [28/08/2007 18:26 1153368]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\System32\drivers\seehcri.sys [04/12/2009 11:53 27632]
S2 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [01/09/2009 15:42 234888]
S2 OMSI download service;Sony Ericsson OMSI download service;c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [04/12/2009 11:53 90112]
S2 pgsql-8.3;PostgreSQL Database Server 8.3;c:\program files\PostgreSQL\8.3\bin\pg_ctl.exe [19/09/2008 03:03 65536]
S3 s1018bus;Sony Ericsson Device 1018 driver (WDM);c:\windows\System32\drivers\s1018bus.sys [04/12/2009 11:53 86824]
S3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter;c:\windows\System32\drivers\s1018mdfl.sys [04/12/2009 11:53 15016]
S3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver;c:\windows\System32\drivers\s1018mdm.sys [04/12/2009 11:53 114728]
S3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM);c:\windows\System32\drivers\s1018mgmt.sys [04/12/2009 11:53 106208]
S3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS);c:\windows\System32\drivers\s1018nd5.sys [04/12/2009 11:53 26024]
S3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface;c:\windows\System32\drivers\s1018obex.sys [04/12/2009 11:53 104744]
S3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM);c:\windows\System32\drivers\s1018unic.sys [04/12/2009 11:53 109864]
S3 S2usbser;S2 USB Device for Legacy Serial Communication;c:\windows\System32\drivers\S2usbser.sys [26/03/2009 16:14 103680]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
Contents of the 'Scheduled Tasks' folder
2010-01-27 c:\windows\Tasks\AWC Startup.job
- c:\program files\IObit\Advanced SystemCare 3\AWC.exe [2009-07-28 08:55]
2010-01-27 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-08-05 12:44]
2010-01-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3934529276-3636103968-3449759745-1000Core.job
- c:\users\charlie\AppData\Local\Google\Update\GoogleUpdate.exe [2009-04-26 07:17]
2010-01-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3934529276-3636103968-3449759745-1000UA.job
- c:\users\charlie\AppData\Local\Google\Update\GoogleUpdate.exe [2009-04-26 07:17]
2010-01-27 c:\windows\Tasks\User_Feed_Synchronization-{47A042AD-22BD-44BF-B24E-AE4915A77EE4}.job
- c:\windows\system32\msfeedssync.exe [2006-11-02 09:45]
2010-01-26 c:\windows\Tasks\User_Feed_Synchronization-{E39E7B80-A6B3-4B50-BFDE-1649ACE0D994}.job
- c:\windows\system32\msfeedssync.exe [2006-11-02 09:45]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-27 03:37
Windows 6.0.6000 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0009\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0010\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-01-27 03:39:27
ComboFix-quarantined-files.txt 2010-01-27 03:39
ComboFix2.txt 2010-01-27 03:08
Pre-Run: 13,211,119,616 bytes free
Post-Run: 12,950,753,280 bytes free
- - End Of File - - 33F9F3E90507F34201C5B7874B8C8F48