Hi Gringo,
Please find below log from Combofix.
I did not encounter any problem so far, and the internet/computer are faster now.I will do another health check couple hours later.
Based on the log analysis so far, are the real problem due to spyware or virus? any further clean up required?
**************************************
ComboFix 13-03-31.01 - USER 01/04/2013 8:13.5.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.60.1033.18.2038.1132 [GMT 3:00]
Running from: c:\users\USER\Documents\Downloads\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\USER\AppData\Local\CouponDropDown
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\chrome.manifest
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\funmoods.css
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\funmoods.xul
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\images\pref.jpg
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\imgs\arwDwn.gif
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\imgs\flgs\ae.png
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\imgs\flgs\bg.png
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\imgs\flgs\ch.png
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\imgs\flgs\cn.png
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\imgs\flgs\cz.png
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\imgs\flgs\de.png
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\imgs\flgs\eg.png
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\imgs\flgs\en.png
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\imgs\flgs\es.png
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\imgs\flgs\fr.png
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\imgs\flgs\gr.png
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\imgs\flgs\he.png
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\imgs\flgs\il.png
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\imgs\flgs\it.png
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\imgs\flgs\ja.png
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\imgs\flgs\jp.png
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\imgs\flgs\nl.png
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\imgs\flgs\no.png
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\imgs\flgs\pl.png
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\imgs\flgs\pt.png
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\imgs\flgs\ro.png
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\imgs\flgs\ru.png
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\imgs\flgs\sa.png
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\imgs\flgs\se.png
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\imgs\flgs\sv.png
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\imgs\flgs\tr.png
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\imgs\flgs\ua.png
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\imgs\flgs\us.png
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\imgs\help_16.gif
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\imgs\home.gif
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\imgs\logo.png
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\imgs\privecy_16_hot.gif
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\imgs\tellafriend.gif
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\loader.xul
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\mtstart.js
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\preferences.xul
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\content\tmplt.js
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\install.rdf
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\META-INF\le_c6a58f26_4d2d_4341_b387_c4f2289b6170.rsa
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\META-INF\le_c6a58f26_4d2d_4341_b387_c4f2289b6170.sf
c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\extensions\
[email protected]\META-INF\manifest.mf
c:\windows\myfav
.
.
((((((((((((((((((((((((( Files Created from 2013-03-01 to 2013-04-01 )))))))))))))))))))))))))))))))
.
.
2013-04-01 05:27 . 2013-04-01 05:27 -------- d-----w- c:\users\Public\AppData\Local\temp
2013-04-01 05:27 . 2013-04-01 05:27 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-03-30 12:07 . 2013-03-30 12:07 -------- d-----w- c:\programdata\Licenses
2013-03-30 10:48 . 2013-03-30 10:48 405360 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-03-20 19:49 . 2013-02-12 01:57 15872 ----a-w- c:\windows\system32\drivers\usb8023.sys
2013-03-13 17:59 . 2013-03-13 17:59 -------- d-----w- c:\users\USER\AppData\Roaming\Funmoods
2013-03-10 18:31 . 2013-03-10 18:31 -------- d-----w- c:\program files\Retsina Software
2013-03-04 18:26 . 2013-01-08 22:01 768000 ----a-w- c:\program files\Common Files\Microsoft Shared\vgx\VGX.dll
2013-03-04 16:29 . 2013-01-04 01:38 2048512 ----a-w- c:\windows\system32\win32k.sys
2013-03-04 16:28 . 2012-11-08 03:48 1314816 ----a-w- c:\windows\system32\quartz.dll
2013-03-04 16:28 . 2013-01-04 11:28 905576 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-03-04 16:26 . 2013-01-05 05:26 3602808 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-03-04 16:26 . 2013-01-05 05:26 3550072 ----a-w- c:\windows\system32\ntoskrnl.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-08 08:31 . 2010-01-08 08:31 7912808 ----a-w- c:\program files\Firefox Setup 3.5.7.exe
2009-11-11 23:10 . 2009-11-11 23:10 1564666 ----a-w- c:\program files\a-pdf-rr.exe
2009-09-10 16:31 . 2009-09-10 16:31 502168 ----a-w- c:\program files\SpyHunter-Installer.exe
2013-03-07 14:30 . 2013-03-09 09:34 263064 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe" [2007-01-22 417792]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-11-01 4763008]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-03-29 138008]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-03-29 154392]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-03-29 133912]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-14 4399104]
"NDSTray.exe"="NDSTray.exe" [BU]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-02-02 835584]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2006-12-07 55416]
"UIExec"="c:\program files\Connection Manager\UIExec.exe" [2010-04-26 139088]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"QuickTime Task"="C:\QTTask.exe" [2011-10-24 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-11-12 421736]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2012-12-14 824232]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"TkBellExe"="c:\program files\Real\RealPlayer\Update\realsched.exe" [2012-08-20 296096]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2012-09-02 348664]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-10-27 221184]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-08-25 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-08-25 81920]
.
c:\users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
IMVU.lnk - c:\users\USER\AppData\Roaming\IMVUClient\IMVUQualityAgent.exe [N/A]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\3.0.318\SSScheduler.exe [2013-2-5 272248]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\00TCrdMain]
2007-03-23 06:41 538744 ----a-w- c:\program files\Toshiba\FlashCards\TCrdMain.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Camera Assistant Software]
2007-03-21 09:23 413696 ----a-w- c:\program files\Camera Assistant Software for Toshiba\traybar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Flashget]
2007-09-25 08:10 2007088 ----a-w- c:\program files\FlashGet\flashget.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-26 16:47 31016 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-11 06:28 1233920 ----a-w- c:\program files\Windows Sidebar\sidebar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2012-11-09 08:27 17877168 ----a-r- c:\program files\Skype\Phone\Skype.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmoothView]
2007-03-22 03:46 448632 ----a-w- c:\program files\Toshiba\SmoothView\SmoothView.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPwrMain]
2006-12-19 15:16 411768 ----a-w- c:\program files\Toshiba\Power Saver\TPwrMain.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-19 07:38 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=""
"FirewallOverride"=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2898391138-219693507-328901587-1000]
"EnableNotificationsRef"=dword:00000001
.
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-03-29 05:17 1642448 ----a-w- c:\program files\Google\Chrome\Application\26.0.1410.43\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-04-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-07-31 03:35]
.
2013-04-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-07-31 03:35]
.
2013-03-30 c:\windows\Tasks\ReclaimerUpdateFiles_USER.job
- c:\users\USER\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.40\agent\rnupgagent.exe [2013-03-24 19:09]
.
2013-03-31 c:\windows\Tasks\ReclaimerUpdateXML_USER.job
- c:\users\USER\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.40\agent\rnupgagent.exe [2013-03-24 19:09]
.
2013-04-01 c:\windows\Tasks\RNUpgradeHelperLogonPrompt_USER.job
- c:\users\USER\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\10.40\agent\rnupgagent.exe [2013-03-24 19:09]
.
.
------- Supplementary Scan -------
.
uStart Page = www.yahoo.com/
mStart Page = hxxp://www.google.com
IE: &Download All with FlashGet - c:\program files\FlashGet\jc_all.htm
IE: &Download with FlashGet - c:\program files\FlashGet\jc_link.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: ?????? - c:\program files\Thunder Network\Thunder\Program\geturl.htm
IE: ?????????? - c:\program files\Thunder Network\Thunder\Program\getallurl.htm
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IMVU\Run IMVU.lnk
LSP: c:\program files\Avira\AntiVir Desktop\avsda.dll
TCP: DhcpNameServer = 192.168.1.1 192.168.1.1
FF - ProfilePath - c:\users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\1nixb31g.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2405280&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Search Results
FF - prefs.js: browser.startup.homepage - hxxp://malaysia.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid=0&systemid=413&sr=0&q=
FF - user.js: extensions.funmoods.hmpg - true
FF - user.js: extensions.funmoods.hmpgUrl - hxxp://searchfunmoods.com/?f=1&a=download&chnl=download&cd=2XzuyEtN2Y1L1QzutDtD0AtD0DtCzy0ByE0B0CyE0CtDyEtBtN0D0Tzu0CtBzytAtN1L2XzutBtFtBtFtDtFtAyEyE&cr=927736190
FF - user.js: extensions.funmoods.dfltSrch - true
FF - user.js: extensions.funmoods.srchPrvdr - Search
FF - user.js: extensions.funmoods.dnsErr - true
FF - user.js: extensions.funmoods_i.newTab - true
FF - user.js: extensions.funmoods.newTabUrl - hxxp://searchfunmoods.com/?f=2&a=download&chnl=download&cd=2XzuyEtN2Y1L1QzutDtD0AtD0DtCzy0ByE0B0CyE0CtDyEtBtN0D0Tzu0CtBzytAtN1L2XzutBtFtBtFtDtFtAyEyE&cr=927736190
FF - user.js: extensions.funmoods.tlbrSrchUrl - hxxp://searchfunmoods.com/?f=3&a=download&chnl=download&cd=2XzuyEtN2Y1L1QzutDtD0AtD0DtCzy0ByE0B0CyE0CtDyEtBtN0D0Tzu0CtBzytAtN1L2XzutBtFtBtFtDtFtAyEyE&cr=927736190&q=
FF - user.js: extensions.funmoods.id - 00A0D19B4BC4C042
FF - user.js: extensions.funmoods.instlDay - 15632
FF - user.js: extensions.funmoods.vrsn - 1.5.23.22
FF - user.js: extensions.funmoods.vrsni - 1.5.23.22
FF - user.js: extensions.funmoods_i.vrsnTs - 1.5.23.2217:38:0
FF - user.js: extensions.funmoods.prtnrId - funmoods
FF - user.js: extensions.funmoods.prdct - funmoods
FF - user.js: extensions.funmoods.aflt - download
FF - user.js: extensions.funmoods_i.smplGrp - none
FF - user.js: extensions.funmoods.tlbrId - base
FF - user.js: extensions.funmoods.instlRef - download
FF - user.js: extensions.funmoods.dfltLng -
FF - user.js: extensions.funmoods.excTlbr - false
FF - user.js: extensions.funmoods.autoRvrt - false
FF - user.js: extensions.funmoods.envrmnt - production
FF - user.js: extensions.funmoods.isdcmntcmplt - true
FF - user.js: extensions.funmoods.mntrvrsn - 1.3.0
.
- - - - ORPHANS REMOVED - - - -
.
SafeBoot-WudfPf
SafeBoot-WudfRd
AddRemove-UseNeXT_is1 - c:\program files\UseNeXT\unins000.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2013-04-01 08:28
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
TOSCDSPD = c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe?/i?????????\p??(?>?P?>???>???>???
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2013-04-01 08:38:00
ComboFix-quarantined-files.txt 2013-04-01 05:37
ComboFix2.txt 2010-06-19 12:11
ComboFix3.txt 2010-06-19 07:36
ComboFix4.txt 2010-04-07 20:17
.
Pre-Run: 83,464,118,272 bytes free
Post-Run: 85,388,742,656 bytes free
.
- - End Of File - - D3DA6AECFDF205C6D531198418F45185