ComboFix 11-07-08.03 - Taylor 07/09/2011 9:48.3.1 - x86 NETWORK Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2942.2357 [GMT -5:00] Running from: c:\users\Taylor\Desktop\ComboFix.exe AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . ---- Previous Run ------- . c:\windows\TEMP\logishrd\LVPrcInj01.dll . . ((((((((((((((((((((((((( Files Created from 2011-06-09 to 2011-07-09 ))))))))))))))))))))))))))))))) . . 2011-07-09 14:55 . 2011-07-09 14:55 -------- d-----w- c:\users\Taylor\AppData\Local\temp 2011-07-09 14:55 . 2011-07-09 14:55 -------- d-----w- c:\users\Default\AppData\Local\temp 2011-07-09 14:36 . 2011-07-09 14:36 -------- d-----w- c:\program files\Apple Software Update 2011-07-07 06:30 . 2011-07-07 06:30 -------- d-----w- C:\_OTL 2011-07-07 04:29 . 2011-06-07 15:55 7074640 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{DA94BFA7-B26B-4EDA-8021-7799DFA05167}\mpengine.dll 2011-07-05 05:21 . 2011-07-05 05:26 -------- d-----w- c:\program files\Windows Live 2011-07-05 05:19 . 2011-07-05 05:19 -------- d-----w- c:\users\Taylor\AppData\Local\Windows Live 2011-07-05 05:19 . 2011-07-05 05:19 -------- d-----w- c:\program files\Common Files\Windows Live 2011-07-05 05:19 . 2009-08-04 08:02 754688 ----a-w- c:\windows\system32\webservices.dll 2011-07-05 05:02 . 2010-01-25 12:00 471552 ----a-w- c:\windows\system32\secproc_isv.dll 2011-07-05 05:02 . 2010-01-25 12:00 471552 ----a-w- c:\windows\system32\secproc.dll 2011-07-05 05:02 . 2010-01-25 08:21 526336 ----a-w- c:\windows\system32\RMActivate_isv.exe 2011-07-05 05:02 . 2010-01-25 12:00 152576 ----a-w- c:\windows\system32\secproc_ssp_isv.dll 2011-07-05 05:02 . 2010-01-25 12:00 152064 ----a-w- c:\windows\system32\secproc_ssp.dll 2011-07-05 05:02 . 2010-01-25 08:21 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe 2011-07-05 05:02 . 2010-01-25 08:21 518144 ----a-w- c:\windows\system32\RMActivate.exe 2011-07-05 05:02 . 2010-01-25 08:21 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe 2011-07-05 05:02 . 2010-01-25 11:58 332288 ----a-w- c:\windows\system32\msdrm.dll 2011-07-05 05:02 . 2011-05-02 12:02 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat 2011-07-02 04:09 . 2008-07-31 15:41 238088 ----a-w- c:\windows\system32\xactengine3_2.dll 2011-07-02 04:09 . 2008-07-31 15:41 68616 ----a-w- c:\windows\system32\XAPOFX1_1.dll 2011-07-02 04:09 . 2008-07-31 15:40 509448 ----a-w- c:\windows\system32\XAudio2_2.dll 2011-07-02 04:09 . 2008-07-10 16:01 467984 ----a-w- c:\windows\system32\d3dx10_39.dll 2011-07-02 04:09 . 2008-07-10 16:00 3851784 ----a-w- c:\windows\system32\D3DX9_39.dll 2011-07-02 04:09 . 2008-07-10 16:00 1493528 ----a-w- c:\windows\system32\D3DCompiler_39.dll 2011-07-01 06:49 . 2011-07-01 06:49 -------- d-----w- c:\program files\7-Zip 2011-07-01 06:37 . 2011-07-01 06:37 43520 ----a-w- c:\windows\system32\CmdLineExt03.dll 2011-06-28 23:23 . 2011-04-29 15:59 276992 ----a-w- c:\windows\system32\schannel.dll 2011-06-26 16:06 . 2009-04-06 16:37 704384 ----a-w- c:\windows\system32\drivers\SandBox.sys 2011-06-26 16:06 . 2011-06-26 16:06 -------- d-----w- c:\users\Taylor\{f1b84d14-8e77-4905-855e-0f330230a8e8} 2011-06-26 16:06 . 2009-02-10 21:12 307224 ----a-w- c:\windows\system32\drivers\afwcore.sys 2011-06-26 16:04 . 2009-02-18 22:27 29208 ----a-w- c:\windows\system32\drivers\afw.sys 2011-06-26 16:04 . 2011-06-26 16:04 -------- d-----w- c:\program files\Agnitum 2011-06-26 16:03 . 2011-06-26 16:22 -------- d-----w- c:\programdata\Agnitum 2011-06-26 05:32 . 2011-06-26 05:32 -------- d-----w- c:\program files\BillP Studios 2011-06-26 05:32 . 2011-06-26 05:32 -------- d-----w- c:\programdata\InstallMate 2011-06-23 04:19 . 2011-06-23 04:19 2106216 ----a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll 2011-06-23 04:19 . 2011-06-23 04:19 1998168 ----a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll 2011-06-18 16:39 . 2011-04-25 15:29 141104 ----a-w- c:\program files\Internet Explorer\sqmapi.dll 2011-06-18 16:39 . 2011-04-22 23:25 2382848 ----a-w- c:\windows\system32\mshtml.tlb 2011-06-18 16:39 . 2011-04-22 23:35 1797632 ----a-w- c:\windows\system32\jscript9.dll 2011-06-18 03:15 . 2011-04-14 14:59 75264 ----a-w- c:\windows\system32\drivers\dfsc.sys 2011-06-18 03:15 . 2011-04-21 13:58 273408 ----a-w- c:\windows\system32\drivers\afd.sys 2011-06-18 03:15 . 2011-04-29 13:25 146432 ----a-w- c:\windows\system32\drivers\srv2.sys 2011-06-18 03:15 . 2011-04-29 13:25 102400 ----a-w- c:\windows\system32\drivers\srvnet.sys 2011-06-18 03:15 . 2010-12-20 16:35 563712 ----a-w- c:\windows\system32\oleaut32.dll 2011-06-18 03:15 . 2011-05-02 17:16 739328 ----a-w- c:\windows\system32\inetcomm.dll 2011-06-18 03:15 . 2011-04-29 13:24 214016 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-06-18 03:15 . 2011-04-29 13:24 79872 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys 2011-06-18 03:15 . 2011-04-29 13:24 106496 ----a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-06-10 17:16 . 2011-06-10 17:16 -------- d-----w- c:\users\Taylor\AppData\Roaming\Foxit Software 2011-06-10 03:24 . 2011-06-10 03:24 -------- d-----w- c:\program files\iPod 2011-06-10 03:24 . 2011-06-10 03:25 -------- d-----w- c:\program files\iTunes 2011-06-10 03:16 . 2011-06-10 03:16 -------- d-----w- c:\program files\Bonjour 2011-06-10 03:12 . 2011-06-10 03:12 -------- d-----w- c:\program files\Common Files\Java . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-07-05 05:21 . 2010-06-24 16:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2011-07-04 11:43 . 2011-05-06 03:08 40112 ----a-w- c:\windows\avastSS.scr 2011-07-04 11:43 . 2011-05-06 03:08 199304 ----a-w- c:\windows\system32\aswBoot.exe 2011-07-04 11:36 . 2011-05-06 03:09 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2011-07-04 11:36 . 2011-05-06 03:09 309848 ----a-w- c:\windows\system32\drivers\aswSP.sys 2011-07-04 11:35 . 2011-05-06 03:09 43608 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2011-07-04 11:32 . 2011-05-06 03:09 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys 2011-07-04 11:32 . 2011-05-06 03:09 54104 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys 2011-07-04 11:32 . 2011-05-06 03:09 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2011-07-03 03:52 . 2011-05-19 21:17 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-06-10 03:11 . 2010-05-03 23:09 472808 ----a-w- c:\windows\system32\deployJava1.dll 2011-05-29 14:11 . 2011-04-18 15:33 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-05-29 14:11 . 2010-04-26 00:06 22712 ----a-w- c:\windows\system32\drivers\mbam.sys 2011-05-25 00:14 . 2009-10-02 17:24 222080 ------w- c:\windows\system32\MpSigStub.exe 2011-05-23 07:04 . 2011-05-23 07:04 161792 ----a-w- c:\windows\system32\msls31.dll 2011-05-23 07:04 . 2011-05-23 07:04 1126912 ----a-w- c:\windows\system32\wininet.dll 2011-05-23 07:04 . 2011-05-23 07:04 86528 ----a-w- c:\windows\system32\iesysprep.dll 2011-05-23 07:04 . 2011-05-23 07:04 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2011-05-23 07:04 . 2011-05-23 07:04 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe 2011-05-23 07:04 . 2011-05-23 07:04 48640 ----a-w- c:\windows\system32\mshtmler.dll 2011-05-23 07:04 . 2011-05-23 07:04 74752 ----a-w- c:\windows\system32\iesetup.dll 2011-05-23 07:04 . 2011-05-23 07:04 63488 ----a-w- c:\windows\system32\tdc.ocx 2011-05-23 07:04 . 2011-05-23 07:04 367104 ----a-w- c:\windows\system32\html.iec 2011-05-23 07:04 . 2011-05-23 07:04 1427456 ----a-w- c:\windows\system32\inetcpl.cpl 2011-05-23 07:04 . 2011-05-23 07:04 420864 ----a-w- c:\windows\system32\vbscript.dll 2011-05-23 07:04 . 2011-05-23 07:04 23552 ----a-w- c:\windows\system32\licmgr10.dll 2011-05-23 07:04 . 2011-05-23 07:04 152064 ----a-w- c:\windows\system32\wextract.exe 2011-05-23 07:04 . 2011-05-23 07:04 150528 ----a-w- c:\windows\system32\iexpress.exe 2011-05-23 07:04 . 2011-05-23 07:04 142848 ----a-w- c:\windows\system32\ieUnatt.exe 2011-05-23 07:04 . 2011-05-23 07:04 35840 ----a-w- c:\windows\system32\imgutil.dll 2011-05-23 07:04 . 2011-05-23 07:04 11776 ----a-w- c:\windows\system32\mshta.exe 2011-05-23 07:04 . 2011-05-23 07:04 110592 ----a-w- c:\windows\system32\IEAdvpack.dll 2011-05-23 07:04 . 2011-05-23 07:04 101888 ----a-w- c:\windows\system32\admparse.dll 2011-05-23 07:03 . 2011-05-23 07:03 98816 ----a-w- c:\windows\system32\mfps.dll 2011-05-23 07:03 . 2011-05-23 07:03 979456 ----a-w- c:\windows\system32\MFH264Dec.dll 2011-05-23 07:03 . 2011-05-23 07:03 357376 ----a-w- c:\windows\system32\MFHEAACdec.dll 2011-05-23 07:03 . 2011-05-23 07:03 302592 ----a-w- c:\windows\system32\mfmp4src.dll 2011-05-23 07:03 . 2011-05-23 07:03 2873344 ----a-w- c:\windows\system32\mf.dll 2011-05-23 07:03 . 2011-05-23 07:03 261632 ----a-w- c:\windows\system32\mfreadwrite.dll 2011-05-23 07:03 . 2011-05-23 07:03 209920 ----a-w- c:\windows\system32\mfplat.dll 2011-05-23 07:03 . 2011-05-23 07:03 586240 ----a-w- c:\windows\system32\stobject.dll 2011-05-23 07:03 . 2011-05-23 07:03 683008 ----a-w- c:\windows\system32\d2d1.dll 2011-05-23 07:03 . 2011-05-23 07:03 486400 ----a-w- c:\windows\system32\d3d10level9.dll 2011-05-23 07:03 . 2011-05-23 07:03 135680 ----a-w- c:\windows\system32\XpsRasterService.dll 2011-05-23 07:03 . 2011-05-23 07:03 847360 ----a-w- c:\windows\system32\OpcServices.dll 2011-05-23 07:03 . 2011-05-23 07:03 667648 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe 2011-05-23 07:03 . 2011-05-23 07:03 638336 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys 2011-05-23 07:03 . 2011-05-23 07:03 478720 ----a-w- c:\windows\system32\dxgi.dll 2011-05-23 07:03 . 2011-05-23 07:03 37376 ----a-w- c:\windows\system32\cdd.dll 2011-05-23 07:03 . 2011-05-23 07:03 26112 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll 2011-05-23 07:03 . 2011-05-23 07:03 258048 ----a-w- c:\windows\system32\winspool.drv 2011-05-23 07:03 . 2011-05-23 07:03 219648 ----a-w- c:\windows\system32\d3d10_1core.dll 2011-05-23 07:03 . 2011-05-23 07:03 189952 ----a-w- c:\windows\system32\d3d10core.dll 2011-05-23 07:03 . 2011-05-23 07:03 160768 ----a-w- c:\windows\system32\d3d10_1.dll 2011-05-23 07:03 . 2011-05-23 07:03 1554432 ----a-w- c:\windows\system32\xpsservices.dll 2011-05-23 07:03 . 2011-05-23 07:03 1172480 ----a-w- c:\windows\system32\d3d10warp.dll 2011-05-23 07:03 . 2011-05-23 07:03 1029120 ----a-w- c:\windows\system32\d3d10.dll 2011-05-23 07:02 . 2011-05-23 07:02 4096 ----a-w- c:\windows\system32\drivers\en-US\dxgkrnl.sys.mui 2011-05-23 07:02 . 2011-05-23 07:02 369664 ----a-w- c:\windows\system32\WMPhoto.dll 2011-05-23 07:02 . 2011-05-23 07:02 252928 ----a-w- c:\windows\system32\dxdiag.exe 2011-05-23 07:02 . 2011-05-23 07:02 195584 ----a-w- c:\windows\system32\dxdiagn.dll 2011-05-23 07:02 . 2011-05-23 07:02 519680 ----a-w- c:\windows\system32\d3d11.dll 2011-05-23 07:02 . 2011-05-23 07:02 974848 ----a-w- c:\windows\system32\WindowsCodecs.dll 2011-05-23 07:02 . 2011-05-23 07:02 321024 ----a-w- c:\windows\system32\PhotoMetadataHandler.dll 2011-05-23 07:02 . 2011-05-23 07:02 189440 ----a-w- c:\windows\system32\WindowsCodecsExt.dll 2011-04-24 22:14 . 2011-05-19 21:39 225856 ----a-w- c:\windows\system32\drivers\keyscrambler.sys 2011-06-23 04:19 . 2011-03-23 05:35 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2011-07-04 11:43 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-07-01 2424192] "OpenDNS Updater"="c:\program files\OpenDNS Updater\OpenDNSUpdater.exe" [2010-06-16 839680] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"="RtHDVCpl.exe" [2008-07-03 6266880] "hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072] "DVDAgent"="c:\program files\Hewlett-Packard\Media\DVD\DVDAgent.exe" [2009-09-09 1148200] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-07-04 3493720] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-23 13539872] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-23 92704] "WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2011-05-15 325512] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696] "OutpostMonitor"="c:\progra~1\Agnitum\OUTPOS~1\op_mon.exe" [2009-04-28 2374464] "OutpostFeedBack"="c:\program files\Agnitum\Outpost Firewall\feedback.exe" [2009-04-28 428032] "Adobe ARM"="c:\program files\COMMON FILES\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920] . c:\users\Taylor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360] NETGEAR WPN311 Smart Wizard.lnk - c:\program files\NETGEAR\WPN311\wlancfg5.exe [2007-4-10 1695744] Snapfish Media Detector.lnk - c:\program files\Snapfish Picture Mover\SnapfishMediaDetector.exe [2007-5-7 1273856] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "EnableShellExecuteHooks"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\progra~1\Agnitum\OUTPOS~1\wl_hook.dll . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 . R1 aswSnx;aswSnx; [x] R1 aswSP;aswSP; [x] R1 SandBox;SandBox;c:\windows\system32\drivers\SandBox.sys [2009-04-06 704384] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656] R2 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\OUTPOS~1\acs.exe [2009-04-28 1195008] R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952] R2 aswFsBlk;aswFsBlk; [x] R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-07-04 54104] R2 gupdate1c9bc0011877bf5;Google Update Service (gupdate1c9bc0011877bf5);c:\program files\Google\Update\GoogleUpdate.exe [2009-04-13 133104] R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652] R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [2009-02-10 307224] R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2009-04-13 133104] S1 afw;Agnitum Firewall Driver;c:\windows\system32\DRIVERS\afw.sys [2009-02-18 29208] S3 KeyScrambler;KeyScrambler;c:\windows\system32\drivers\keyscrambler.sys [2011-04-24 225856] . . --- Other Services/Drivers In Memory --- . *NewlyCreated* - ECACHE . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache . Contents of the 'Scheduled Tasks' folder . 2011-07-09 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-04 15:42] . 2011-07-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-04-13 06:20] . 2011-07-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-04-13 06:20] . 2008-10-28 c:\windows\Tasks\WebReg HP Deskjet F4200 series.job - c:\program files\HP\Digital Imaging\bin\hpqwrg.exe [2008-03-26 01:42] . . ------- Supplementary Scan ------- . uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cndt mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Presario&pf=cndt uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 10.0.0.1 TCP: Interfaces\{A61E1BE4-9615-4559-9135-3AB04F6099A9}: NameServer = 208.67.222.222,208.67.220.220 FF - ProfilePath - c:\users\Taylor\AppData\Roaming\Mozilla\Firefox\Profiles\loem8u10.default\ FF - prefs.js: browser.startup.homepage - hxxp://en-US.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official . - - - - ORPHANS REMOVED - - - - . Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\Ask.com\GenericAskToolbar.dll HKCU-Run-AdobeUpdater - c:\program files\COMMON FILES\ADOBE\UPDATER5\ADOBEUPDATER.EXE HKLM-Run-HP Health Check Scheduler - [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe HKLM-Run-hpqSRMon - (no file) ShellExecuteHooks-{4F07DA45-8170-4859-9B5F-037EF2970034} - (no file) AddRemove-sp41121 - c:\hp\Softpaq\sp41121\sp41121.exe AddRemove-sp44626 - c:\hp\Softpaq\sp44626\sp44626.exe AddRemove-{7B63B2922B174135AFC0E1377DD81EC2} - c:\program files\DivX\DivXCodecUninstall.exe AddRemove-Octoshape add-in for Adobe Flash Player - c:\users\Taylor\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2011-07-09 09:55 Windows 6.0.6002 Service Pack 2 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . Completion time: 2011-07-09 09:58:13 ComboFix-quarantined-files.txt 2011-07-09 14:58 . Pre-Run: 306,711,990,272 bytes free Post-Run: 306,589,048,832 bytes free . - - End Of File - - 712A37BC3FC67B68B9FC1505F416FC47