No problems with any of that 'combofix' part. Will let you know how it goes. The start up 'explorer.exe' problem is very random so it may be a few days until i know it is fixed.
Here is the combofix log.
ComboFix 12-10-26.05 - Simon King 27/10/2012 15:54:02.1.4 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3327.2692 [GMT 1:00]
Running from: c:\documents and settings\Simon King\Desktop\ComboFix.exe
FW: ZoneAlarm Extreme Security Firewall *Disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\1322084635.bdinstall.bin
c:\documents and settings\All Users\Application Data\1322151705.bdinstall.bin
c:\documents and settings\All Users\Application Data\1322388806.bdinstall.bin
c:\documents and settings\All Users\Application Data\1322388995.bdinstall.bin
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\Simon King\Application Data\IDM\idmmzcc3
c:\documents and settings\Simon King\Application Data\IDM\idmmzcc3\chrome.manifest
c:\documents and settings\Simon King\Application Data\IDM\idmmzcc3\chrome\idmmzcc.jar
c:\documents and settings\Simon King\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
c:\documents and settings\Simon King\Application Data\IDM\idmmzcc3\components\iIDMMzCC.xpt
c:\documents and settings\Simon King\Application Data\IDM\idmmzcc3\install.js
c:\documents and settings\Simon King\Application Data\IDM\idmmzcc3\install.rdf
c:\documents and settings\Simon King\Application Data\IDM\idmmzcc3\META-INF\manifest.mf
c:\documents and settings\Simon King\Application Data\IDM\idmmzcc3\META-INF\zigbert.rsa
c:\documents and settings\Simon King\Application Data\IDM\idmmzcc3\META-INF\zigbert.sf
c:\documents and settings\Simon King\WINDOWS
c:\program files\xfire_installer_43094.exe
c:\windows\system32\PowerToyReadme.htm
.
.
((((((((((((((((((((((((( Files Created from 2012-09-27 to 2012-10-27 )))))))))))))))))))))))))))))))
.
.
2012-10-26 16:00 . 2012-10-26 16:06 13952 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2012-10-19 08:10 . 2012-10-19 08:10 -------- d-----w- c:\documents and settings\Simon King\Local Settings\Application Data\Research In Motion
2012-10-19 08:10 . 2012-10-19 08:11 -------- d-----w- c:\documents and settings\Simon King\Application Data\Research In Motion
2012-10-19 08:09 . 2011-07-20 13:13 35328 ----a-r- c:\windows\system32\drivers\RimSerial.sys
2012-10-19 08:08 . 2012-10-19 08:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Research In Motion
2012-10-19 08:08 . 2012-10-19 08:09 -------- d-----w- c:\program files\Common Files\Research In Motion
2012-10-19 08:08 . 2012-10-19 08:08 -------- d-----w- c:\program files\Common Files\XCPCSync.OEM
2012-10-19 08:08 . 2012-10-19 08:08 -------- d-----w- c:\program files\Research In Motion
2012-10-08 13:53 . 2012-10-08 13:53 -------- d-----w- c:\documents and settings\Simon King\Local Settings\Application Data\Imaginova Canada
2012-10-08 13:52 . 2012-10-08 13:52 -------- d-----w- c:\program files\Common Files\ASCOM
2012-10-08 13:52 . 2002-06-02 16:07 110592 ----a-w- c:\windows\system32\libfli.dll
2012-10-08 13:52 . 2000-12-05 23:00 209608 ----a-w- c:\windows\system32\TABCTL32.OCX
2012-10-08 13:52 . 2000-05-22 14:58 244416 ----a-w- c:\windows\system32\system32MSFLXGRD.OCX
2012-10-08 13:52 . 1998-06-24 09:56 103744 ----a-w- c:\windows\system32\MSCOMM32.OCX
2012-10-08 13:50 . 2012-10-08 13:50 -------- d-----w- c:\windows\Cache
2012-10-08 13:50 . 2012-10-08 13:50 -------- d-----w- c:\documents and settings\All Users\Application Data\QuickTime
2012-10-08 13:37 . 2012-10-18 19:28 -------- d-----w- c:\program files\Starry Night Pro 5
2012-10-08 13:37 . 2012-10-08 13:49 -------- d--h--w- c:\program files\Zero G Registry
2012-10-08 13:37 . 2012-10-08 13:37 -------- d--h--w- c:\documents and settings\Simon King\InstallAnywhere
2012-10-08 11:20 . 2012-10-08 11:20 -------- d-----w- C:\hplanet
2012-10-01 15:02 . 2012-10-01 15:02 -------- d-----w- c:\documents and settings\Simon King\Local Settings\Application Data\Downloaded Installations
2012-10-01 14:48 . 2012-10-01 14:48 -------- d-----w- c:\documents and settings\All Users\Application Data\TomTom
2012-10-01 14:48 . 2012-10-01 14:48 -------- d-----w- c:\documents and settings\Simon King\Local Settings\Application Data\TomTom
2012-10-01 14:48 . 2012-10-01 14:48 -------- d-----w- c:\documents and settings\Simon King\Application Data\TomTom
2012-10-01 14:47 . 2012-10-01 14:47 -------- d-----w- c:\program files\TomTom International B.V
2012-10-01 14:47 . 2012-10-01 15:03 -------- d-----w- c:\program files\TomTom HOME 2
2012-10-01 14:41 . 2012-10-01 14:41 -------- d-----w- c:\program files\TomTom DesktopSuite
2012-10-01 10:18 . 2012-10-01 10:18 -------- d-----w- c:\documents and settings\Simon King\Local Settings\Application Data\Sun
2012-10-01 10:18 . 2012-10-01 10:18 -------- d-----w- c:\program files\Common Files\Java
2012-10-01 10:17 . 2012-10-01 10:16 821736 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-10-01 10:17 . 2012-10-01 10:16 93672 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-26 18:10 . 2011-02-24 19:46 138376 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2012-10-26 18:10 . 2011-02-24 19:46 202448 ----a-w- c:\windows\system32\PnkBstrB.exe
2012-10-09 11:18 . 2012-04-18 15:05 696760 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-09 11:18 . 2011-05-20 06:15 73656 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-10-01 10:16 . 2011-02-23 12:04 746984 ----a-w- c:\windows\system32\deployJava1.dll
2012-10-01 10:16 . 2011-02-23 12:04 143872 ----a-w- c:\windows\system32\javacpl.cpl
2012-09-25 15:05 . 2003-03-18 20:14 499712 ----a-w- c:\windows\system32\msvcp71.dll
2012-09-25 15:05 . 2003-02-21 04:42 348160 ----a-w- c:\windows\system32\msvcr71.dll
2012-09-07 19:22 . 2012-09-07 19:12 81920 ------r- c:\windows\bwUnin-6.1.4.36-8876480L.exe
2012-08-28 15:14 . 2008-04-14 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-08-28 15:14 . 2008-04-14 12:00 43520 ------w- c:\windows\system32\licmgr10.dll
2012-08-28 15:14 . 2008-04-14 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-08-28 12:07 . 2008-04-14 12:00 385024 ------w- c:\windows\system32\html.iec
2012-08-24 13:53 . 2008-04-14 12:00 177664 ----a-w- c:\windows\system32\wintrust.dll
2012-08-21 13:33 . 2008-04-14 12:00 2148864 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-08-21 12:58 . 2008-04-14 00:01 2027520 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-12-19 15:09 . 2011-12-19 15:05 127592 ----a-w- c:\program files\Intro_Video.exe
2011-12-19 15:05 . 2011-12-19 15:05 102400 ----a-w- c:\program files\srEXT_Unzip.dll
2011-12-19 15:05 . 2011-12-19 15:05 90185 ----a-w- c:\program files\srDD_Glide3x.dll
2011-12-19 15:05 . 2011-12-19 15:05 741438 ----a-w- c:\program files\sr.dll
2011-12-19 15:05 . 2011-12-19 15:05 57434 ----a-w- c:\program files\srEXT_LWOImporter.dll
2011-12-19 15:05 . 2011-12-19 15:05 53337 ----a-w- c:\program files\srEXT_default.dll
2011-12-19 15:05 . 2011-12-19 15:05 45142 ----a-w- c:\program files\srEXT_Inspector.dll
2011-12-19 15:05 . 2011-12-19 15:05 36942 ----a-w- c:\program files\srDD_OpenGL.dll
2011-12-19 15:05 . 2011-12-19 15:05 118876 ----a-w- c:\program files\srEXT_JPEGImporter.dll
2011-03-07 16:45 . 2011-03-07 16:45 5296197 ----a-w- c:\program files\CheatEngine60.exe
2011-03-06 20:23 . 2011-03-06 20:21 38147376 ----a-w- c:\program files\QuickTimeInstaller.exe
2011-03-06 19:31 . 2011-03-06 19:31 670992 ----a-w- c:\program files\RealPlayer.exe
2011-02-26 19:41 . 2011-02-26 19:41 3194296 ----a-w- c:\program files\spywareblastersetup44.exe
2011-02-26 17:04 . 2011-02-26 17:03 16883056 ----a-w- c:\program files\IE8-WindowsXP-x86-ENU.exe
2010-12-22 19:00 . 2010-12-22 19:00 565313 ----a-w- c:\program files\Supreme_v1.035.exe
2010-12-22 19:00 . 2010-12-22 19:00 565313 ----a-w- c:\program files\Supreme.exe
2010-11-14 07:00 . 2010-11-14 07:00 30720 ----a-w- c:\program files\Display_Config.exe
2012-08-14 17:57 . 2011-10-27 22:22 136672 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-02-24 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ZoneAlarm"="c:\program files\CheckPoint\ZoneAlarm\zatray.exe" [2011-12-18 73360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2011-12-06 16:05 16680 ----a-w- c:\program files\Citrix\GoToAssist\570\g2awinlogon.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-07-03 08:04 252848 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2012-09-25 15:05 296096 ----a-w- c:\program files\Real\RealPlayer\Update\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
2012-08-28 06:41 247768 ----a-w- c:\program files\TomTom HOME 2\TomTomHOMERunner.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZoneAlarm]
2011-12-18 20:04 73360 ----a-w- c:\program files\CheckPoint\ZoneAlarm\zatray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\amd driver updater, xp, 32 bit\\Setup.exe"=
"c:\\Program Files\\Origin Games\\Tiger Woods 12\\TWOLauncher.exe"=
"c:\\Program Files\\Call of Duty Game of the Year Edition\\CoDUOMP.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Logitech\\Logitech Vid\\Vid.exe"=
"c:\\Program Files\\Research In Motion\\BlackBerry Desktop\\Rim.Desktop.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\skyrim\\SkyrimLauncher.exe"=
.
R1 CLBStor;InstantBurn Storage Helper Driver;c:\windows\system32\drivers\CLBStor.sys [01/03/2011 17:00 16048]
R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [14/10/2010 17:08 11352]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [22/07/2011 17:27 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12/07/2011 22:55 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [12/08/2011 00:38 116608]
R2 CLBUDF;CyberLink InstantBurn UDF Filesystem;c:\windows\system32\drivers\CLBUDF.sys [01/03/2011 17:00 162096]
R2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [06/06/2011 08:04 21992]
R2 ISWKL;ZoneAlarm ForceField ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [03/11/2011 15:44 27016]
R2 IswSvc;ZoneAlarm ForceField IswSvc;c:\program files\CheckPoint\ZAForceField\ISWSVC.exe [03/11/2011 15:44 497280]
R2 Start BT in service;Start BT in service;c:\program files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe [27/12/2007 16:39 51816]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [28/08/2012 07:41 92632]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdXP3.sys [02/03/2012 18:01 100368]
R3 icsak;icsak;c:\program files\CheckPoint\ZAForceField\AK\icsak.sys [03/11/2011 15:44 36744]
R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [12/03/2011 20:37 27632]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [24/02/2011 19:46 136176]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [18/04/2012 16:05 250808]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [23/02/2011 20:39 1691480]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [24/02/2011 19:46 136176]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [25/05/2012 20:34 113120]
S3 MSICDSetup;MSICDSetup;\??\d:\cdriver.sys --> d:\CDriver.sys [?]
S3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [10/03/2012 17:40 137600]
S3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [10/03/2012 17:40 8576]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [09/01/2010 21:37 4640000]
S3 PROCEXP151;PROCEXP151;\??\c:\windows\system32\Drivers\PROCEXP151.SYS --> c:\windows\system32\Drivers\PROCEXP151.SYS [?]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [23/06/2012 22:45 27064]
S3 RTCore32;RTCore32;c:\program files\MSI Afterburner\RTCore32.sys [25/05/2005 04:39 4608]
S3 WinAutomation Service;WinAutomation Service;c:\program files\WinAutomation\WinAutomation.ServiceAgent.exe [25/01/2011 14:25 166912]
.
Contents of the 'Scheduled Tasks' folder
.
2012-10-27 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-18 13:23]
.
2012-06-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 17:57]
.
2012-10-20 c:\windows\Tasks\expresszipShakeIcon.job
- c:\program files\NCH Software\ExpressZip\expresszip.exe [2011-09-02 10:53]
.
2012-09-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-24 18:46]
.
2012-09-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-02-24 18:46]
.
2012-06-14 c:\windows\Tasks\pixillionDowngrade.job
- c:\program files\NCH Software\Pixillion\pixillion.exe [2011-10-11 19:59]
.
2012-06-14 c:\windows\Tasks\pixillionShakeIcon.job
- c:\program files\NCH Software\Pixillion\pixillion.exe [2011-10-11 19:59]
.
2012-10-27 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1844237615-287218729-725345543-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-07-27 13:27]
.
2012-10-27 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1844237615-287218729-725345543-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-07-27 13:27]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: Se&nd to OneNote - c:\progra~1\MICROS~3\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\documents and settings\Simon King\Application Data\Mozilla\Firefox\Profiles\anb7uxoh.default\
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?sourceid=navclient&hl=en-GB&q=
FF - ExtSQL: 2012-09-25 16:06; {0153E448-190B-4987-BDE1-F256CADA672F}; c:\documents and settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-ISW - (no file)
SafeBoot-WudfPf
SafeBoot-WudfRd
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-10-27 15:59
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1844237615-287218729-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{414D94B0-F712-9582-A874-42D9ADDAD9FA}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):ac,46,35,9a,8d,4c,a9,d9,f0,80,6b,ad,7c,0c,a3,72,2a,de,24,a0,26,
33,9f,ba,0d,f4,21,0b,22,e6,43,18,be,2f,09,dc,49,38,40,8f,00,00,00,00,00,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{93c60861-b448-408d-a2b0-02b14f666fee}]
@Denied: (Full) (Everyone)
"Model"=dword:0000003e
"Therad"=dword:0000000e
.
[HKEY_LOCAL_MACHINE\software\Microsoft\DbgagD\1*]
"value"="?\0b\04\11\14-.t"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(760)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
c:\program files\Citrix\GoToAssist\570\G2AWinLogon.dll
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
c:\program files\CheckPoint\ZAForceField\AK\icsak.dll
.
- - - - - - - > 'lsass.exe'(816)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
c:\program files\CheckPoint\ZAForceField\AK\icsak.dll
.
- - - - - - - > 'csrss.exe'(720)
c:\program files\CheckPoint\ZAForceField\AK\akconsole.dll
.
Completion time: 2012-10-27 16:01:44
ComboFix-quarantined-files.txt 2012-10-27 15:01
.
Pre-Run: 663,681,282,048 bytes free
Post-Run: 663,707,873,280 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect /usepmtimer
.
- - End Of File - - 5CA8EFBE20D8575FFB6FB9DE291FC7E3