ComboFix 11-02-28.07 - Josh 01/03/2011 13:40:22.1.2 - x86
Microsoft Windows 7 Professional 6.1.7600.0.1252.2.1033.18.2036.1279 [GMT -5:00]
Running from: c:\users\Josh\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Install.exe
.
((((((((((((((((((((((((( Files Created from 2011-02-01 to 2011-03-01 )))))))))))))))))))))))))))))))
.
2011-03-01 18:45 . 2011-03-01 18:45 -------- d-----w- c:\users\Josh\AppData\Local\temp
2011-03-01 18:45 . 2011-03-01 18:45 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-03-01 17:39 . 2011-03-01 17:39 28752 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{4832F45A-BFEF-4254-9780-F54FFBF93108}\MpKsl6de67b55.sys
2011-03-01 16:43 . 2011-03-01 16:43 -------- d-----w- c:\users\Josh\AppData\Local\{5D43246E-9CDC-425F-9DF1-29D80E1D7683}
2011-03-01 05:26 . 2009-12-04 06:51 258560 ----a-w- c:\windows\system32\drivers\usbhub.sys
2011-03-01 05:26 . 2009-12-04 06:51 41984 ----a-w- c:\windows\system32\drivers\usbehci.sys
2011-03-01 05:25 . 2009-11-14 07:11 27736 ----a-w- c:\windows\system32\drivers\msahci.sys
2011-03-01 05:25 . 2009-11-12 19:42 86528 ----a-w- c:\windows\system32\isoburn.exe
2011-03-01 05:24 . 2009-10-07 02:30 246784 ----a-w- c:\windows\system32\drivers\udfs.sys
2011-03-01 05:24 . 2009-09-11 03:00 35840 ----a-w- c:\windows\system32\drivers\winusb.sys
2011-03-01 05:13 . 2011-02-23 14:35 5943120 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{4832F45A-BFEF-4254-9780-F54FFBF93108}\mpengine.dll
2011-03-01 04:38 . 2011-03-01 04:39 -------- d-----w- c:\users\Josh\AppData\Local\{DBCBB8DF-B67E-4C56-9E09-7C73AF1DBF4D}
2011-03-01 04:36 . 2011-03-01 04:36 -------- d-----w- c:\users\Josh\AppData\Local\{6899910E-239D-458F-9900-0AE575E7D0E7}
2011-03-01 04:29 . 2011-03-01 04:29 -------- d-----w- c:\users\Josh\AppData\Local\{C5AE69C5-EA75-4E12-B620-870B1E2BFBC0}
2011-03-01 04:23 . 2011-03-01 04:23 -------- d-----w- c:\users\Josh\AppData\Roaming\RegistryKeys
2011-02-28 21:08 . 2011-02-28 21:08 -------- d-----w- c:\program files\Feedback Tool
2011-02-28 19:51 . 2011-02-28 19:51 -------- d-----w- c:\windows\Sun
2011-02-28 15:43 . 2011-02-28 15:43 -------- d-----w- c:\users\Josh\AppData\Local\{1CD382EA-7C70-4539-9DBD-F81BF6BDCE3C}
2011-02-28 08:17 . 2011-02-28 08:17 -------- d-----w- c:\users\Josh\AppData\Roaming\Intel Corporation
2011-02-28 05:55 . 2010-11-30 15:43 439632 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{437009F1-B0D3-47FF-BC2E-CEEE0289627E}\gapaengine.dll
2011-02-28 05:43 . 2011-02-28 05:43 -------- d-----w- c:\program files\Microsoft Security Client
2011-02-28 05:42 . 2010-04-09 07:24 240008 ----a-w- c:\windows\system32\drivers\netio.sys
2011-02-28 05:41 . 2011-02-28 05:41 -------- d-----w- c:\program files\ESET
2011-02-28 05:38 . 2010-11-06 04:39 354840 ----a-w- c:\windows\system32\drivers\iaStor.sys
2011-02-28 05:38 . 2011-02-28 05:38 -------- d-----w- c:\users\Josh\AppData\Roaming\InstallShield
2011-02-28 03:43 . 2011-02-28 03:43 -------- d-----w- c:\users\Josh\AppData\Local\{04FEDA6A-49B5-43A8-AC79-E0383BE301EA}
2011-02-28 03:36 . 2011-02-28 03:36 -------- d--h--w- c:\windows\system32\WLANProfiles
2011-02-28 03:35 . 2011-02-28 06:05 -------- d-----w- c:\users\Josh\AppData\Roaming\Intel
2011-02-28 03:34 . 2011-02-28 06:05 -------- d-----w- c:\programdata\Intel
2011-02-28 03:30 . 2011-02-28 03:30 -------- d-----w- c:\programdata\NVIDIA Corporation
2011-02-28 03:30 . 2011-01-08 03:27 941160 ----a-w- c:\windows\system32\nvdispco322090.dll
2011-02-28 03:30 . 2011-01-08 03:27 837736 ----a-w- c:\windows\system32\nvgenco322040.dll
2011-02-28 03:30 . 2011-01-08 03:27 57960 ----a-w- c:\windows\system32\OpenCL.dll
2011-02-28 03:30 . 2011-01-08 03:27 5653096 ----a-w- c:\windows\system32\nvwgf2um.dll
2011-02-28 03:30 . 2011-01-08 03:27 4941928 ----a-w- c:\windows\system32\nvcuda.dll
2011-02-28 03:30 . 2011-01-08 03:27 2895976 ----a-w- c:\windows\system32\nvcuvid.dll
2011-02-28 03:30 . 2011-01-08 03:27 2251368 ----a-w- c:\windows\system32\nvcuvenc.dll
2011-02-28 03:30 . 2011-01-08 03:27 1965672 ----a-w- c:\windows\system32\nvapi.dll
2011-02-28 03:30 . 2011-01-08 03:27 15047272 ----a-w- c:\windows\system32\nvoglv32.dll
2011-02-28 03:30 . 2011-01-08 03:27 13011560 ----a-w- c:\windows\system32\nvcompiler.dll
2011-02-28 03:27 . 2011-02-28 03:27 -------- d-----w- c:\users\Josh\AppData\Local\{9ACEF8CE-39C7-43B8-9972-2B2D4870610E}
2011-02-28 03:24 . 2011-01-08 03:27 10467656 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2011-02-28 03:23 . 2011-02-28 03:32 -------- d-----w- c:\program files\NVIDIA Corporation
2011-02-28 03:23 . 2011-02-28 03:23 -------- d-----w- C:\NVIDIA
2011-02-28 01:54 . 2011-02-28 01:54 -------- d-----w- c:\users\Josh\AppData\Local\{0378BDCD-3D51-4BD1-B532-6852A07F637A}
2011-02-26 17:00 . 2011-02-26 17:00 -------- d-----w- c:\users\Josh\AppData\Local\{23D56190-4E24-4FF4-9393-8B538C969F72}
2011-02-26 07:03 . 2011-02-26 07:03 -------- d-----w- c:\users\Josh\AppData\Local\{78EC3A9A-A405-448E-BF56-D26B92C93BF8}
2011-02-26 00:58 . 2011-02-26 19:58 -------- d-----w- c:\program files\Microsoft Office Communicator
2011-02-26 00:36 . 2011-02-26 00:36 -------- d-----w- c:\users\Josh\AppData\Local\Apps
2011-02-26 00:36 . 2011-03-01 05:04 -------- d-----w- c:\users\Josh\AppData\Local\Deployment
2011-02-26 00:21 . 2011-02-26 00:21 -------- d-----w- c:\program files\SystemRequirementsLab
2011-02-26 00:20 . 2011-02-26 00:20 -------- d-----w- c:\users\Josh\AppData\Roaming\SystemRequirementsLab
2011-02-25 23:28 . 2011-02-25 23:28 -------- d-----r- C:\MSOCache
2011-02-25 19:02 . 2011-02-25 19:03 -------- d-----w- c:\users\Josh\AppData\Local\{4A101EFF-D47B-4337-86E2-962FE0FE8E2F}
2011-02-24 22:07 . 2011-02-24 22:07 -------- d-----w- c:\users\Josh\AppData\Local\{9347E397-EDF8-4558-8FDA-E6911DF804B5}
2011-02-24 21:33 . 2011-02-24 21:33 -------- d-----w- c:\users\Josh\AppData\Local\{63C17E77-7649-4E4F-A6C7-0686D54DCCC9}
2011-02-24 07:31 . 2011-02-24 07:31 -------- d-----w- c:\users\Josh\AppData\Local\{21168C4C-E856-421C-9D5B-1813D2FE7491}
2011-02-23 21:55 . 2011-02-23 21:55 -------- d-----w- c:\users\Josh\AppData\Local\ElevatedDiagnostics
2011-02-23 18:47 . 2011-02-23 18:47 -------- d-----w- c:\users\Josh\AppData\Roaming\Malwarebytes
2011-02-23 18:47 . 2011-02-23 18:47 -------- d-----w- c:\programdata\Malwarebytes
2011-02-23 18:47 . 2010-12-20 23:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-02-23 18:47 . 2011-02-23 18:47 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-02-23 18:47 . 2010-12-20 23:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-02-23 18:25 . 2011-02-23 18:26 -------- d-----w- c:\users\Josh\AppData\Local\{EDC89F5E-B87C-4CEA-A197-54A87CFA292D}
2011-02-23 05:59 . 2011-02-23 05:59 -------- d-----w- c:\users\Josh\AppData\Local\{ECF4905E-F63C-4360-B2A4-753F4634F067}
2011-02-22 17:58 . 2011-02-22 17:59 -------- d-----w- c:\users\Josh\AppData\Local\{1D60EE89-F623-4C8F-BAF7-4E189DF99E8C}
2011-02-21 19:57 . 2011-02-21 19:57 -------- d-----w- c:\users\Josh\AppData\Local\{C047F7F7-59AC-40B9-ACE1-488263B89964}
2011-02-20 22:08 . 2011-02-20 22:08 -------- d-----w- c:\users\Josh\AppData\Local\{A1160CD2-E60B-4B36-B2EB-41D4A7C07C9B}
2011-02-20 18:52 . 2011-02-20 18:52 -------- d-----w- c:\users\Josh\AppData\Local\{78CAD3BA-404B-41C7-8D9A-C0D9750151AF}
2011-02-20 06:52 . 2011-02-20 06:52 -------- d-----w- c:\users\Josh\AppData\Local\{936C8E36-E48B-4BEC-9F4D-3AD55E7DE0C6}
2011-02-19 18:49 . 2011-02-19 18:52 -------- d-----w- c:\users\Josh\AppData\Local\{9BF0085D-B2F2-49E0-A4A7-5FF1D9216F78}
2011-02-19 15:34 . 2011-02-19 15:34 -------- d-----w- c:\users\Josh\AppData\Local\{4E113944-CC83-4D45-9558-450F6820CB07}
2011-02-18 15:54 . 2011-02-18 15:54 -------- d-----w- c:\users\Josh\AppData\Local\{BC70CEB9-2E0A-47CC-965D-F422DDF5728D}
2011-02-18 01:20 . 2010-11-02 04:35 1170944 ----a-w- c:\windows\system32\d3d10warp.dll
2011-02-18 01:20 . 2010-11-02 04:35 739840 ----a-w- c:\windows\system32\d2d1.dll
2011-02-18 01:20 . 2010-11-02 04:35 1074176 ----a-w- c:\windows\system32\DWrite.dll
2011-02-18 01:20 . 2010-11-02 04:36 801792 ----a-w- c:\windows\system32\FntCache.dll
2011-02-18 01:20 . 2010-11-02 04:41 442880 ----a-w- c:\windows\system32\XpsPrint.dll
2011-02-18 01:20 . 2010-11-02 04:41 283648 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-02-18 01:20 . 2010-11-02 04:35 218624 ----a-w- c:\windows\system32\d3d10_1core.dll
2011-02-18 01:20 . 2010-06-26 05:14 1495040 ----a-w- c:\windows\system32\ExplorerFrame.dll
2011-02-18 01:19 . 2010-11-02 04:41 135168 ----a-w- c:\windows\system32\XpsRasterService.dll
2011-02-18 01:19 . 2010-11-02 04:35 161792 ----a-w- c:\windows\system32\d3d10_1.dll
2011-02-18 01:17 . 2010-10-27 04:40 1289536 ----a-w- c:\windows\system32\ntdll.dll
2011-02-18 01:17 . 2010-10-27 04:43 3901824 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-02-18 01:17 . 2010-10-27 04:43 3957120 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-02-18 01:17 . 2010-11-02 04:46 728448 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-02-18 01:17 . 2011-02-03 05:45 219008 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2011-02-18 01:17 . 2010-11-02 04:23 107520 ----a-w- c:\windows\system32\cdd.dll
2011-02-17 22:30 . 2011-02-17 22:30 -------- d-----w- c:\users\Josh\AppData\Local\{8E79EC23-6380-4268-BCB1-E1CC4B110F37}
2011-02-17 20:06 . 2011-02-17 20:06 -------- d-----w- c:\users\Josh\AppData\Local\{FF7BF02A-F485-408B-9501-17663F5AFA50}
2011-02-17 07:54 . 2011-02-17 07:55 -------- d-----w- c:\users\Josh\AppData\Local\{C1E3ECC6-4820-4EF1-BA02-77FADF379A1C}
2011-02-16 19:54 . 2011-02-16 19:54 -------- d-----w- c:\users\Josh\AppData\Local\{51787B91-92DF-46F7-A0E2-EB2E5F679F32}
2011-02-15 16:33 . 2011-02-15 16:33 -------- d-----w- c:\users\Josh\AppData\Local\{7E291459-8DA3-4B29-9A85-56FA2CDE57EC}
2011-02-15 04:23 . 2011-02-15 04:23 -------- d-----w- c:\users\Josh\AppData\Local\{0DB76792-7B2F-473E-8A6A-D07B33DC2506}
2011-02-14 16:22 . 2011-02-14 16:23 -------- d-----w- c:\users\Josh\AppData\Local\{9B8E6EEE-BB22-4A4D-B324-C15A3252D22D}
2011-02-13 16:57 . 2011-02-13 16:57 -------- d-----w- c:\users\Josh\AppData\Local\{E4A7613D-026D-4088-B8EB-D4DBF5C3DAF3}
2011-02-12 20:20 . 2011-02-12 20:20 -------- d-----w- c:\users\Josh\AppData\Local\{A0B01840-94F5-4E6E-986E-0F0DA5C8B6C7}
2011-02-12 07:19 . 2011-02-12 07:20 -------- d-----w- c:\users\Josh\AppData\Local\{0F060004-2D8D-4302-8C3B-947D17D8BBE9}
2011-02-11 19:19 . 2011-02-11 19:19 -------- d-----w- c:\users\Josh\AppData\Local\{226D063F-0321-4A14-8150-0FFB9590BE79}
2011-02-11 17:41 . 2011-02-11 17:41 -------- d-----w- c:\users\Josh\AppData\Local\{C4D6E8EA-81F9-4FF5-87A2-33ADB9EDDBB3}
2011-02-11 04:29 . 2011-02-11 04:29 -------- d-----w- c:\users\Josh\AppData\Local\{1BFCF343-2668-411A-B485-4E0F5E04D90A}
2011-02-10 16:28 . 2011-02-10 16:28 -------- d-----w- c:\users\Josh\AppData\Local\{B094CF6E-23E8-430D-B10F-EF3DBFE93459}
2011-02-10 04:28 . 2011-02-10 04:28 -------- d-----w- c:\users\Josh\AppData\Local\{AAC92AFF-544F-4DE0-B17C-DC3F2469273E}
2011-02-09 16:28 . 2011-02-09 16:28 -------- d-----w- c:\users\Josh\AppData\Local\{7486C2A9-1139-4362-A7E1-DA78E9B23F43}
2011-02-08 15:09 . 2011-02-08 15:09 -------- d-----w- c:\users\Josh\AppData\Local\{7E9ADE80-4A35-44CD-B22A-A8809DE53841}
2011-02-08 03:08 . 2011-02-08 03:09 -------- d-----w- c:\users\Josh\AppData\Local\{2F6197FC-D18A-49CC-9C01-72C9A4953CEB}
2011-02-07 15:08 . 2011-02-07 15:08 -------- d-----w- c:\users\Josh\AppData\Local\{131505F0-872A-4F9C-A67B-2699FB1F87EA}
2011-02-06 22:34 . 2011-02-06 22:34 -------- d-----w- c:\users\Josh\AppData\Local\{0A848BB3-48DB-4C58-BE9D-D8F395F04515}
2011-02-06 18:52 . 2011-02-06 18:52 -------- d-----w- c:\users\Josh\AppData\Local\{7FEB8CF1-CCB0-41E6-8346-AD8EE941E681}
2011-02-05 16:51 . 2011-02-05 16:51 -------- d-----w- c:\programdata\Hewlett-Packard
2011-02-05 16:51 . 2009-07-14 01:15 280064 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\hpzppw71.dll
2011-02-03 16:05 . 2011-02-03 16:05 -------- d-----w- c:\users\Josh\AppData\Local\{7932F47D-AF69-428D-AE28-18C6BA707192}
2011-02-03 02:05 . 2011-02-03 02:05 -------- d-----w- c:\users\Josh\AppData\Local\{F246F09D-61BE-4A27-8D2F-2A2A1B0862AB}
2011-02-02 14:17 . 2011-02-02 14:17 -------- d-----w- c:\users\Josh\AppData\Local\{55B7FFDA-FF8B-4458-9BDF-776AAB355897}
2011-02-01 18:38 . 2011-02-01 18:38 -------- d-----w- c:\users\Josh\AppData\Local\{085A2C04-E7F2-47EC-B655-F4B3DF4F2A3A}
2011-02-01 04:53 . 2011-02-01 04:53 -------- d-----w- c:\users\Josh\AppData\Local\{C1AE37F4-6D46-4C80-B49F-C8B5660A0C8C}
2011-01-31 16:52 . 2011-01-31 16:53 -------- d-----w- c:\users\Josh\AppData\Local\{72836812-9D1C-4E9A-A55C-5F2BC94393F9}
2011-01-30 19:33 . 2011-01-30 19:33 -------- d-----w- c:\users\Josh\AppData\Local\Research In Motion
2011-01-30 19:32 . 2011-01-30 19:33 -------- d-----w- c:\users\Josh\AppData\Roaming\Research In Motion
2011-01-30 19:31 . 2009-01-09 21:18 27136 ----a-w- c:\windows\system32\drivers\RimSerial.sys
2011-01-30 19:30 . 2011-01-30 19:30 -------- d-----w- c:\programdata\Research In Motion
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-01 05:07 . 2011-01-26 02:16 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-01-26 15:38 . 2011-01-26 15:38 697328 ----a-w- c:\windows\system32\drivers\sptd.sys
2011-01-20 15:39 . 2011-01-25 22:35 5890896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{EE71F9FA-7716-4D97-BD7B-0565C097B78D}\mpengine.dll
2011-01-08 03:27 . 2011-02-28 03:24 10920 ----a-w- c:\windows\system32\drivers\nvBridge.kmd
2011-01-08 03:27 . 2011-01-14 16:17 10078312 ----a-w- c:\windows\system32\nvd3dum.dll
2011-01-08 02:06 . 2011-01-08 02:06 580200 ----a-w- c:\windows\system32\easyUpdatusAPIU.dll
2011-01-08 02:06 . 2011-01-08 02:06 3597416 ----a-w- c:\windows\system32\nvcpl.dll
2011-01-08 02:06 . 2011-01-08 02:06 2620520 ----a-w- c:\windows\system32\nvsvc.dll
2011-01-08 02:06 . 2011-01-08 02:06 608872 ----a-w- c:\windows\system32\nvvsvc.exe
2011-01-08 02:06 . 2011-01-08 02:06 288872 ----a-w- c:\windows\system32\nvhotkey.dll
2011-01-08 02:06 . 2011-01-08 02:06 2558568 ----a-w- c:\windows\system32\nvsvcr.dll
2011-01-08 02:06 . 2011-01-08 02:06 111208 ----a-w- c:\windows\system32\nvmctray.dll
2010-12-23 16:09 . 2011-01-14 17:17 53248 ----a-w- c:\windows\system32\CSVer.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-11-10 4240760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-12-21 200704]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2009-07-31 458844]
"Broadcom Wireless Manager UI"="c:\program files\Dell\Dell Wireless WLAN Card\WLTRAY.exe" [2009-04-30 3888640]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-01-25 421160]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976]
"NVHotkey"="c:\windows\system32\nvHotkey.dll" [2011-01-08 288872]
"IAStorIcon"="c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-11-06 283160]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ida]
2010-09-01 13:09 27352 ----a-w- c:\program files\Ida\IdaLaunch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MaxMenuMgr]
2009-05-01 19:35 185640 ----a-w- c:\program files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2010-11-10 07:54 4240760 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-10-25 43392]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-25 54144]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 206360]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2011-01-26 697328]
S1 MpKsl6de67b55;MpKsl6de67b55;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{4832F45A-BFEF-4254-9780-F54FFBF93108}\MpKsl6de67b55.sys [2011-03-01 28752]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_450b431403c091e3\aestsrv.exe [2009-03-02 81920]
S2 alssvc;Ambient Light Sensor;c:\program files\Dell\Ambient Light Sensor\AlsSvc.exe [2008-06-03 382232]
S2 Credential Vault Host Control Service;Credential Vault Host Control Service;c:\program files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe [2010-03-24 812448]
S2 Credential Vault Host Storage;Credential Vault Host Storage;c:\program files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe [2010-03-24 27040]
S2 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe [2009-05-01 181544]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-11-06 13336]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-01-08 378984]
S3 cvusbdrv;Dell ControlVault;c:\windows\system32\Drivers\cvusbdrv.sys [2009-11-03 33832]
S3 e1yexpress;Intel(R) Gigabit Network Connections Driver;c:\windows\system32\DRIVERS\e1y6232.sys [2009-06-13 221912]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - MPKSL6DE67B55
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc SensrSvc
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MICROS~4\Office14\ONBttnIE.dll/105
DPF: {8CFCF42C-1C64-47D6-AEEC-F9D001832ED3} - hxxp://xserv.dell.com/DellDriverScanner/DellSystem.CAB
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-OfficeSyncProcess - c:\program files\Microsoft Office\Office14\MSOSYNC.EXE
MSConfigStartUp-BCSSync - c:\program files\Microsoft Office\Office14\BCSSync.exe
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-2909803291-1122864382-4214253459-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
[HKEY_USERS\S-1-5-21-2909803291-1122864382-4214253459-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*S*0*4*ݹT3\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
[HKEY_USERS\S-1-5-21-2909803291-1122864382-4214253459-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*S*0*4*wÌ$1\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
[HKEY_USERS\S-1-5-21-2909803291-1122864382-4214253459-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-03-01 13:46:42
ComboFix-quarantined-files.txt 2011-03-01 18:46
Pre-Run: 70,753,914,880 bytes free
Post-Run: 70,424,174,592 bytes free
- - End Of File - - 6FCBBA04C1022AD19BEE53D00EDE7D70