Let me mention, I always leave my desktop PC running. I just log on and log off my system. Occasionally I reboot the machine…..This AM I logged on and clicked on my temporary desktop icon for WTT. It took almost 3 minutes to get the site up……This is what I mean about being slow getting to the Internet. The strange thing about this situtation is, the wireless laptop I have sitting nearby can access the Internet quickly without a problem…..Below is the Combofix Log……also let me add, It took approx 30 seconds after clicking on "Add Reply" to send you the Combofix log. I am curious, what are you looking for in the Combofix Log? This slow activity to the net has just started last week on my Desktop.
Thanks!
ComboFix 11-11-25.01 - Compaq_Administrator 11/25/2011 8:44.5.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.434 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator\WINDOWS
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\Application Data\TEMP\{479F8C12-576B-4A58-AB78-4B70F7012AA8}\PostBuild.exe
c:\documents and settings\All Users\Application Data\TEMP\{516A7A9D-5659-4DF1-ADCA-3AB2770664F6}\PostBuild.exe
c:\documents and settings\All Users\Application Data\TEMP\{E9B10AA5-E5F6-4DEF-A435-FB20704AF1E8}\PostBuild.exe
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\1.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\a.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\b.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\c.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\d.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\e.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\f.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\g.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\h.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\i.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\J.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\k.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\l.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\m.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\mru.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\n.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\o.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\p.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\q.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\r.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\s.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\t.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\u.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\v.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\w.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\x.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\y.xml
c:\documents and settings\Compaq_Administrator\Application Data\PriceGong\Data\z.xml
c:\documents and settings\Compaq_Administrator\WINDOWS
c:\documents and settings\Default User\WINDOWS
c:\documents and settings\Guest\WINDOWS
c:\documents and settings\UpdatusUser\WINDOWS
c:\windows\CSC\d6
c:\windows\HPCPCUninstaller-6.3.2.116-5577497.exe
c:\windows\system32\config\systemprofile\WINDOWS
c:\windows\system32\Thumbs.db
.
.
((((((((((((((((((((((((( Files Created from 2011-10-25 to 2011-11-25 )))))))))))))))))))))))))))))))
.
.
2011-11-24 21:42 . 2011-11-24 21:42 ——– d—–w- c:\documents and settings\Compaq_Administrator\Local Settings\Application Data\Sun
2011-11-24 20:55 . 2011-11-24 20:58 ——– dc-h–w- c:\windows\ie8
2011-11-24 20:49 . 2011-08-16 10:45 6144 ——w- c:\windows\system32\dllcache\iecompat.dll
2011-11-24 20:47 . 2011-08-22 23:48 743424 ——w- c:\windows\system32\dllcache\iedvtool.dll
2011-11-24 20:47 . 2011-08-22 23:48 247808 ——w- c:\windows\system32\dllcache\ieproxy.dll
2011-11-24 15:50 . 2011-10-07 03:48 6668624 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{223EC48C-A4D5-4D6B-8898-665ED563F252}\mpengine.dll
2011-11-21 01:11 . 2011-11-21 01:11 ——– d—–w- c:\documents and settings\Compaq_Administrator\Application Data\Roxio
2011-11-21 00:58 . 2011-11-21 00:58 ——– d—–w- c:\program files\Common Files\SureThing Shared
2011-11-21 00:57 . 2011-11-21 01:13 ——– d—–w- c:\program files\Roxio
2011-11-20 22:01 . 2011-11-20 22:01 ——– d—–w- c:\documents and settings\All Users\Application Data\Uninstall
2011-11-20 22:00 . 2011-11-21 00:57 ——– d—–w- c:\program files\Common Files\Roxio Shared
2011-11-01 18:54 . 2011-11-01 18:54 ——– d—–w- C:\lj628
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-24 21:22 . 2010-08-17 04:53 128000 —-a-w- c:\windows\system32\javacpl.cpl
2011-11-24 21:22 . 2010-08-17 04:53 544656 —-a-w- c:\windows\system32\deployJava1.dll
2011-11-06 05:48 . 2011-07-09 13:27 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-10 14:22 . 2004-08-09 21:00 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-10-07 03:48 . 2011-07-16 14:34 6668624 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-09-28 07:06 . 2004-08-09 21:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41 . 2008-07-29 23:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41 . 2004-08-09 21:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41 . 2004-08-09 21:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-09-06 13:20 . 2004-08-09 21:00 1858944 —-a-w- c:\windows\system32\win32k.sys
2011-08-31 21:00 . 2008-05-31 18:04 22216 -c–a-w- c:\windows\system32\drivers\mbam.sys
2011-09-12 17:33 . 2011-09-12 17:33 119808 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-11-07 4617600]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-05-25 13895272]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568]
.
c:\documents and settings\Default User\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-5-4 27136]
.
c:\documents and settings\Compaq_Administrator\Start Menu\Programs\Startup\
WKCALREM.LNK - c:\program files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe [2004-6-23 15360]
.
c:\documents and settings\Compaq_Administrator\Start Menu\Programs\Startup\AutorunsDisabled
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
wkcalrem.lnk.disabled [2007-9-12 938]
wordweb.lnk.disabled [2007-8-3 1601]
.
c:\documents and settings\UpdatusUser\Start Menu\Programs\Startup\
Pin.lnk.disabled [2005-8-17 572]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ SDEarlyDelete \??\0autocheck autochk *
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Driver]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Guard]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk.disabled]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnk.disabledCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Compaq Connections.lnk.disabled]
backup=c:\windows\pss\Compaq Connections.lnk.disabledCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk.disabled]
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.disabledCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"LiveUpdate Notice Service"=2 (0x2)
"LiveUpdate Notice Ex"=2 (0x2)
"LiveUpdate"=3 (0x3)
"ISPwdSvc"=3 (0x3)
"comHost"=3 (0x3)
"CLTNetCnService"=2 (0x2)
"Automatic LiveUpdate Scheduler"=2 (0x2)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9
"PCPal"=c:\program files\PCPal\PalAgnt.exe /startup
"swg"=c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
"AVG8_TRAY"=c:\progra~1\AVG\AVG8\avgtray.exe
"SmartRAM"=e:\advanced windowscare v2\MemCleaner.exe /m
"MediaGet2"=c:\documents and settings\Compaq_Administrator\Local Settings\Application Data\MediaGet2\mediaget.exe –minimized
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
""=
"KBD"=c:\hp\KBD\KBD.EXE
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"AlwaysReady Power Message APP"=ARPWRMSG.EXE
"DISCover"=c:\program files\DISC\DISCover.exe
"nwiz"=nwiz.exe /install
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
"ISUSPM Startup"=c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
"ehTray"=c:\windows\ehome\ehtray.exe
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe"
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"COMODO Firewall Pro"="c:\program files\COMODO\Firewall\cfp.exe" -h
"NvMediaCenter"=RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
"HPDJ Taskbar Utility"=c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe
"HP Software Update"=c:\program files\Hp\HP Software Update\HPWuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DISC\\DISCover.exe"=
"c:\\Program Files\\DISC\\DiscStreamHub.exe"=
"c:\\Program Files\\DISC\\myFTP.exe"=
"c:\\Program Files\\Compaq Connections\\5577497\\Program\\Compaq Connections.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\DirecTV\\DirecTV\\DIRECTV2PC™.exe"=
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NVIDIA Updatus\\daemonu.exe"=
.
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [07/22/2011 11:27 AM 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [07/12/2011 4:55 PM 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [08/11/2011 6:38 PM 116608]
R2 CLDTVHNService;CLDTVHNService;c:\program files\DirecTV\DirecTV\Kernel\DMP\CLDTVHNService.exe [09/17/2009 5:40 PM 75048]
R2 ntk_dtv;ntk_dtv;c:\program files\DirecTV\DirecTV\Kernel\DMP\ntk_dtv.sys [09/17/2009 5:40 PM 119792]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [05/14/2011 3:12 PM 2214504]
S1 MpKsl0c56d325;MpKsl0c56d325;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{901765C5-9C8D-498C-BCC7-71EED796FE73}\MpKsl0c56d325.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{901765C5-9C8D-498C-BCC7-71EED796FE73}\MpKsl0c56d325.sys [?]
S1 MpKsl57ecc620;MpKsl57ecc620;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{62C1D18D-2DCB-43B4-861A-073C1D072B6A}\MpKsl57ecc620.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{62C1D18D-2DCB-43B4-861A-073C1D072B6A}\MpKsl57ecc620.sys [?]
S1 MpKsl7a5ee8a9;MpKsl7a5ee8a9;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{223EC48C-A4D5-4D6B-8898-665ED563F252}\MpKsl7a5ee8a9.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{223EC48C-A4D5-4D6B-8898-665ED563F252}\MpKsl7a5ee8a9.sys [?]
S1 MpKsldcfa87e0;MpKsldcfa87e0;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9E9264E3-AE06-4F7C-B9F4-2B8DB8D4340E}\MpKsldcfa87e0.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9E9264E3-AE06-4F7C-B9F4-2B8DB8D4340E}\MpKsldcfa87e0.sys [?]
S1 MpKsle21cd2d6;MpKsle21cd2d6;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{29639311-F66C-4078-8998-9C0825128A66}\MpKsle21cd2d6.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{29639311-F66C-4078-8998-9C0825128A66}\MpKsle21cd2d6.sys [?]
S2 gupdate1c9316637dc9d00;Google Update Service (gupdate1c9316637dc9d00);c:\program files\Google\Update\GoogleUpdate.exe [10/18/2008 4:12 PM 133104]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [08/15/2007 8:31 AM 30192]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [10/18/2008 4:12 PM 133104]
S3 PCD5SRVC{8A863ACB-F5F6CC6A-05010003};PCD5SRVC{8A863ACB-F5F6CC6A-05010003} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\PC-DOC~1\PCD5SRVC.pkms [02/07/2006 8:38 PM 21120]
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
2011-11-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-10-18 21:19]
.
2011-11-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-10-18 21:19]
.
2011-11-25 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 19:39]
.
2007-11-22 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2007-03-17 20:31]
.
2011-11-25 c:\windows\Tasks\User_Feed_Synchronization-{BC3AEFBE-E14D-4663-828F-914798DAD592}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 09:31]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uStart Page = hxxp://msn.com/
uInternet Connection Wizard,ShellNext = iexplore
TCP: DhcpNameServer = 192.168.2.1
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CAB
FF - ProfilePath - c:\documents and settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\w14redor.default\
FF - prefs.js: browser.startup.homepage - hxxp://mirostart.com/?cfg=2-365-0-2Miqs
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - user.js: general.useragent.extra.brc - BRI/1
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
HKLM-Run-nwiz - nwiz.exe
Notify-WgaLogon - (no file)
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-11-25 08:54
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\PCD5SRVC{8A863ACB-F5F6CC6A-05010003}]
"ImagePath"="\??\c:\progra~1\PC-DOC~1\PCD5SRVC.pkms"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-3019693388-2064130007-760773113-1008\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(736)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
- - - - - - - > 'explorer.exe'(4052)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\windows\arservice.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
.
**************************************************************************
.
Completion time: 2011-11-25 09:03:40 - machine was rebooted
ComboFix-quarantined-files.txt 2011-11-25 14:03
.
Pre-Run: 202,387,337,216 bytes free
Post-Run: 202,274,312,192 bytes free
.
- - End Of File - - 2D3E33ACAE94CF662FADFC940FADA1FB