ComboFix 11-12-22.01 - rhizogen 12/22/2011 7:37:52.2.2 - x86
Microsoft® Windows Vista™ Business 6.0.6002.2.1252.1.1033.18.1791.918 [GMT -6:00]
Running from: C:\Users\rhizogen\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
((((((((((((((((((((((((( Files Created from 2011-11-22 to 2011-12-22 )))))))))))))))))))))))))))))))
2011-12-22 13:44:43 . 2011-12-22 13:44:43 -------- d-----w- C:\Users\Default\AppData\Local\temp
2011-12-20 19:27:05 . 2011-12-22 13:44:48 -------- d-----w- C:\Users\rhizogen\AppData\Local\temp
2011-12-19 15:07:29 . 2011-12-19 15:07:29 -------- d-----w- C:\_OTL
2011-12-16 21:14:13 . 2011-12-16 21:14:13 -------- d-----w- C:\Users\rhizogen\AppData\Roaming\Malwarebytes
2011-12-16 21:14:03 . 2011-12-16 21:14:03 -------- d-----w- C:\ProgramData\Malwarebytes
2011-12-16 21:14:01 . 2011-12-16 21:14:05 -------- d-----w- C:\Program Files\Malwarebytes' Anti-Malware
2011-12-16 21:14:01 . 2011-08-31 23:00:50 22216 ----a-w- C:\Windows\system32\drivers\mbam.sys
2011-12-16 15:06:44 . 2011-04-21 13:58:27 273408 ----a-w- C:\Windows\system32\drivers\afd.sys
2011-12-15 17:23:05 . 2011-12-15 17:46:56 -------- d-----w- C:\Windows\system32\sdtmp
2011-12-15 04:05:07 . 2011-10-27 08:01:53 3602816 ----a-w- C:\Windows\system32\ntkrnlpa.exe
2011-12-15 04:05:07 . 2011-10-27 08:01:53 3550080 ----a-w- C:\Windows\system32\ntoskrnl.exe
2011-12-15 04:04:44 . 2011-10-14 16:02:19 429056 ----a-w- C:\Windows\system32\EncDec.dll
2011-12-15 04:03:31 . 2011-11-23 13:37:27 2043904 ----a-w- C:\Windows\system32\win32k.sys
2011-12-15 04:03:28 . 2011-11-08 12:10:10 2409784 ----a-w- C:\Program Files\Windows Mail\OESpamFilter.dat
2011-12-15 04:01:25 . 2011-10-25 15:56:04 49152 ----a-w- C:\Windows\system32\csrsrv.dll
2011-12-15 04:01:03 . 2011-11-08 14:42:19 2048 ----a-w- C:\Windows\system32\tzres.dll
2011-12-13 08:10:28 . 2011-11-21 10:47:38 6823496 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{9BB067C9-E1A7-46CA-BF50-F87E60497AB4}\mpengine.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2011-10-07 11:49:11 . 2011-03-09 19:59:31 83360 ----a-w- C:\Windows\system32\LMIRfsClientNP.dll
2011-10-07 11:49:10 . 2011-03-09 19:59:32 52096 ----a-w- C:\Windows\system32\Spool\prtprocs\w32x86\LMIproc.dll
2011-10-07 11:49:08 . 2011-03-09 19:59:32 30592 ----a-w- C:\Windows\system32\LMIport.dll
2011-10-07 11:49:08 . 2011-03-09 19:59:29 87424 ----a-w- C:\Windows\system32\LMIinit.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Malwarebytes' Anti-Malware"="C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 23:00:48 449608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"ST Recovery Launcher"="C:\Windows\SMINST\launcher.exe" [2008-02-22 19:20:16 44168]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Attendance Rx.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Attendance Rx.lnk
backup=C:\Windows\pss\Attendance Rx.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-30 04:59:06 937920 ----a-r- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-06-08 04:02:26 37296 ----a-w- C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\amd_dc_opt]
2007-07-23 19:06:28 77824 ----a-w- C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 17:44:34 31072 ----a-w- C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2010-03-12 18:08:54 49208 ----a-w- C:\Program Files\HP\HP Software Update\hpwuschd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndexSearch]
2007-10-12 01:01:26 46368 ----a-w- C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn GUI]
2010-09-17 20:40:06 63048 ----a-w- C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2011-08-31 23:00:48 449608 ----a-w- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware (reboot)]
2011-08-31 23:00:48 1047208 ----a-w- C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD]
2007-10-12 01:03:10 29984 ----a-w- C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RIMBBLaunchAgent.exe]
2011-02-18 16:47:12 79192 ----a-w- C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SetRefresh]
2003-11-20 18:01:08 525824 ----a-w- C:\Program Files\HP\SetRefresh\SetRefresh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-11 06:28:03 1233920 ----a-w- C:\Program Files\Windows Sidebar\sidebar.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmileboxTray]
2011-12-01 18:43:04 313160 ----a-w- C:\Users\rhizogen\AppData\Roaming\Smilebox\SmileboxTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
2007-07-10 04:40:30 1282048 ----a-w- C:\Program Files\Analog Devices\Core\smax4pnp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 16:44:46 248552 ----a-w- C:\Program Files\Common Files\Java\Java Update\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\USB Storage Toolbox]
2005-07-11 19:52:48 73728 ----a-w- C:\Program Files\USB Disk Win98 Driver\Res.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2008-01-21 02:25:56 202240 ----a-w- C:\Program Files\Windows Media Player\wmpnscfg.exe
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 18:16:28 130384]
R3 HPFXFAX;HPFXFAX;C:\Windows\system32\drivers\hpfxfax.sys [2007-07-16 21:29:43 20504]
R3 MBAMSwissArmy;MBAMSwissArmy;C:\Windows\system32\drivers\mbamswissarmy.sys [x]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 18:16:28 753504]
R4 LMIGuardianSvc;LMIGuardianSvc;C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe [2011-10-07 11:49:08 374152]
S2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files\LogMeIn\x86\RaInfo.sys [2010-09-17 20:40:06 12856]
S2 MBAMService;MBAMService;C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 23:00:48 366152]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\b57nd60x.sys [2007-09-17 13:12:32 180736]
S3 MBAMProtector;MBAMProtector;C:\Windows\system32\drivers\mbam.sys [2011-08-31 23:00:50 22216]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08
------- Supplementary Scan -------
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=all&pf=cmdt
IE: Add to AVI Video Converter... - C:\Program Files\Media Player Utilities 4.29\AMVConverter\grab.html
IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
TCP: Interfaces\{25108261-8D72-49CC-80B9-4C97455452C0}: NameServer = 68.28.186.91,68.28.178.91
DPF: {DAF7E6E6-D53A-439A-B28D-12271406B8A9} - hxxp://mobileapps.blackberry.com/devicesoftware/AxLoader.cab
FF - ProfilePath - C:\Users\rhizogen\AppData\Roaming\Mozilla\Firefox\Profiles\6zgw1gw8.default\
FF - prefs.js: browser.search.selectedEngine - Inbox Search
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF - prefs.js: keyword.URL - hxxp://toolbar.inbox.com/search/dispatcher.aspx?tp=sf&tbid=80179&language=en&qkw=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - user.js: yahoo.homepage.dontask - true
------- File Associations -------
.scr=DWGTrueViewScriptFile