ComboFix 11-06-30.05 - Tendai 01/07/2011 15:39:41.1.1 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.44.1033.18.1917.1159 [GMT 1:00]
Running from: c:\users\Tendai\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
FW: Online Armor Firewall *Enabled* {32E71E58-6AAE-2557-2ABD-EA739069CE41}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Tendai\AppData\Roaming\Microsoft\Windows\Recent\Palatial Masterpiece - Alpharetta, Georgia.url
c:\users\Tendai\qhi498fh.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-06-01 to 2011-07-01 )))))))))))))))))))))))))))))))
.
.
2011-07-01 14:54 . 2011-07-01 14:54 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-01 11:44 . 2011-07-01 13:30 -------- d-----w- c:\windows\system32\MpEngineStore
2011-06-30 19:15 . 2011-06-07 07:55 7074640 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9F1221F5-E0E7-48CC-B829-2AECD2B846A6}\mpengine.dll
2011-06-30 17:57 . 2009-12-31 13:02 212992 ----a-w- c:\windows\system32\PuranDefrag.dll
2011-06-30 17:57 . 2011-04-08 15:06 229376 ----a-w- c:\windows\system32\PuranDC.exe
2011-06-30 17:57 . 2011-04-08 15:06 109056 ----a-w- c:\windows\system32\PuranDefragBT.exe
2011-06-30 17:57 . 2011-04-08 15:06 233472 ----a-w- c:\windows\system32\PuranDefragS.exe
2011-06-30 17:57 . 2011-04-08 15:06 1114112 ----a-w- c:\windows\system32\PuranFD.exe
2011-06-30 17:57 . 2011-06-30 17:57 -------- d-----w- c:\program files\Puran Defrag
2011-06-30 16:54 . 2011-06-30 16:54 -------- dc----w- C:\_OTL
2011-06-30 16:25 . 2002-07-25 16:06 282624 ----a-w- c:\program files\Common Files\InstallShield\UpdateService\agent.exe
2011-06-30 16:07 . 2011-06-30 16:08 -------- d-----w- c:\program files\EPSON Print CD
2011-06-30 16:06 . 2011-06-30 16:15 -------- d-----w- c:\programdata\UDL
2011-06-30 16:01 . 2005-06-01 03:10 495616 ----a-w- c:\windows\system32\PICSDK2.dll
2011-06-30 16:01 . 2005-05-31 23:10 73728 ----a-w- c:\windows\system32\PICSDK.dll
2011-06-30 16:01 . 2005-06-01 02:10 77824 ----a-w- c:\windows\system32\PICEntry.dll
2011-06-30 16:01 . 2004-03-03 05:10 114688 ----a-w- c:\windows\system32\EpPicPrt.dll
2011-06-30 16:01 . 2004-03-03 05:10 65536 ----a-w- c:\windows\system32\EPPicMgr.dll
2011-06-30 01:16 . 2011-06-30 09:23 -------- d-----w- c:\programdata\OnlineArmor
2011-06-30 01:03 . 2011-04-06 12:02 39048 ----a-w- c:\windows\system32\drivers\oahlp32.sys
2011-06-30 01:03 . 2011-04-06 12:01 25192 ----a-w- c:\windows\system32\drivers\OAmon.sys
2011-06-30 01:03 . 2011-04-06 12:01 205864 ----a-w- c:\windows\system32\drivers\OADriver.sys
2011-06-30 00:58 . 2011-07-01 13:42 -------- d-----w- c:\program files\Online Armor
2011-06-30 00:19 . 2011-06-30 21:27 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-06-30 00:01 . 2011-06-30 00:01 -------- d-----w- c:\program files\OpenDNS Updater
2011-06-29 18:42 . 2011-06-29 18:42 100736 -c--a-w- C:\kgliipob.sys
2011-06-29 18:18 . 2011-06-29 18:27 -------- d-----w- c:\program files\Canon
2011-06-29 03:20 . 2011-04-29 15:59 276992 ----a-w- c:\windows\system32\schannel.dll
2011-06-29 01:01 . 2011-06-29 01:07 -------- d-----w- c:\program files\Microsoft ATS
2011-06-27 16:06 . 2011-06-27 16:06 -------- d--h--w- c:\programdata\Common Files
2011-06-27 15:29 . 2011-06-29 18:35 -------- d-----w- c:\programdata\AVG10
2011-06-27 15:05 . 2011-06-27 15:05 -------- d-----w- c:\program files\AVG
2011-06-27 14:34 . 2011-06-29 18:13 -------- d-----w- c:\programdata\MFAData
2011-06-26 20:17 . 2011-06-27 14:10 -------- d-----w- c:\program files\Emsisoft Anti-Malware
2011-06-24 14:12 . 2011-06-28 16:41 -------- d-----w- c:\programdata\Kaspersky Lab
2011-06-24 13:39 . 2009-09-25 16:59 128016 ----a-w- c:\windows\system32\drivers\38013711.sys
2011-06-23 21:03 . 2010-07-25 21:23 56496 ----a-w- c:\windows\system32\wbhelp2.dll
2011-06-23 21:03 . 2010-07-25 21:23 544768 ----a-w- c:\windows\system32\wbocx.ocx
2011-06-23 21:03 . 2010-07-25 21:23 258352 ----a-w- c:\windows\system32\unicows.dll
2011-06-23 21:03 . 2010-07-25 21:23 33968 ----a-w- c:\windows\system32\anim.dll
2011-06-23 21:03 . 2010-07-25 21:23 4608 ----a-w- c:\windows\system32\W95INF32.DLL
2011-06-23 21:03 . 2010-07-25 21:23 2272 ----a-w- c:\windows\system32\W95INF16.DLL
2011-06-23 20:27 . 2011-06-23 20:27 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2011-06-22 21:10 . 2011-06-08 09:53 10833920 ----a-w- c:\windows\system32\libmfxsw32.dll
2011-06-22 21:10 . 2011-06-08 09:53 10915840 ----a-w- c:\windows\system32\libmfxhw32.dll
2011-06-22 21:09 . 2011-06-22 21:18 -------- d-----w- c:\program files\Common Files\AVSMedia
2011-06-22 21:08 . 2011-06-08 09:54 24576 ----a-w- c:\windows\system32\msxml3a.dll
2011-06-22 21:08 . 2011-06-22 21:28 -------- d-----w- c:\programdata\AVS4YOU
2011-06-22 21:06 . 2011-06-23 16:54 -------- d-----w- c:\program files\AVS4YOU
2011-06-22 20:41 . 2011-06-24 02:33 -------- d-----w- c:\program files\NOS
2011-06-22 20:41 . 2011-06-23 17:36 -------- d-----w- c:\programdata\NOS
2011-06-22 16:59 . 2011-06-22 16:59 -------- d-----w- c:\programdata\WindowsSearch
2011-06-22 15:24 . 2011-06-22 15:24 -------- d-----w- c:\program files\ArcSoft
2011-06-22 15:24 . 1999-05-26 08:46 212480 ----a-w- c:\windows\pcdlib32.dll
2011-06-22 02:25 . 2009-07-14 17:45 38480 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2011-06-22 02:25 . 2009-07-14 17:45 445008 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2011-06-22 02:14 . 2011-06-22 02:14 1700352 ----a-w- c:\windows\system32\gdiplus.dll
2011-06-21 23:50 . 2003-01-26 12:41 40960 ----a-w- c:\windows\system32\ssubtmr6.dll
2011-06-21 23:50 . 2007-08-31 17:36 36864 ----a-w- c:\windows\system32\trayicon_handler.ocx
2011-06-21 23:50 . 2011-06-21 23:50 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-21 22:01 . 2011-06-21 22:01 -------- d-----w- c:\program files\Free YouTube Downloader
2011-06-21 21:58 . 2011-05-29 08:11 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-06-21 21:58 . 2011-05-29 08:11 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-06-21 21:58 . 2011-06-21 21:59 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-06-21 14:57 . 2011-06-07 07:55 7074640 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-06-21 07:59 . 2011-06-21 07:57 439632 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F81E6C7C-CA5F-45E6-B761-4FDB87E176A2}\gapaengine.dll
2011-06-21 06:56 . 2011-06-21 21:56 -------- d-----w- c:\programdata\AVAST Software
2011-06-21 06:56 . 2011-06-21 06:56 -------- d-----w- c:\program files\AVAST Software
2011-06-21 06:38 . 2011-06-21 06:43 -------- d-----w- c:\program files\Microsoft Security Client
2011-06-21 06:34 . 2010-04-05 20:00 221568 ----a-w- c:\windows\system32\drivers\netio.sys
2011-06-21 03:16 . 2011-06-21 03:16 -------- d-----w- c:\programdata\Malwarebytes
2011-06-19 22:40 . 2011-06-19 22:40 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2011-06-19 22:36 . 2011-06-21 03:22 -------- d-----w- c:\program files\Microsoft Silverlight
2011-06-18 01:47 . 2011-06-18 01:47 -------- d-----w- c:\programdata\InterVideo
2011-06-17 15:59 . 2011-03-12 21:55 876032 ----a-w- c:\windows\system32\XpsPrint.dll
2011-06-17 15:32 . 2011-06-17 15:32 -------- d-----w- c:\program files\Windows Portable Devices
2011-06-17 15:07 . 2009-09-10 02:00 92672 ----a-w- c:\windows\system32\UIAnimation.dll
2011-06-17 15:07 . 2009-09-10 02:01 3023360 ----a-w- c:\windows\system32\UIRibbon.dll
2011-06-17 15:07 . 2009-09-10 02:00 1164800 ----a-w- c:\windows\system32\UIRibbonRes.dll
2011-06-17 15:01 . 2009-10-08 21:08 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2011-06-17 15:01 . 2009-10-08 21:08 234496 ----a-w- c:\windows\system32\oleacc.dll
2011-06-17 15:01 . 2009-10-08 21:07 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2011-06-17 14:59 . 2011-06-17 14:59 98816 ----a-w- c:\windows\system32\mfps.dll
2011-06-17 14:59 . 2011-06-17 14:59 979456 ----a-w- c:\windows\system32\MFH264Dec.dll
2011-06-17 14:59 . 2011-06-17 14:59 357376 ----a-w- c:\windows\system32\MFHEAACdec.dll
2011-06-17 14:59 . 2011-06-17 14:59 302592 ----a-w- c:\windows\system32\mfmp4src.dll
2011-06-17 14:59 . 2011-06-17 14:59 2873344 ----a-w- c:\windows\system32\mf.dll
2011-06-17 14:59 . 2011-06-17 14:59 261632 ----a-w- c:\windows\system32\mfreadwrite.dll
2011-06-17 14:59 . 2011-06-17 14:59 586240 ----a-w- c:\windows\system32\stobject.dll
2011-06-17 14:59 . 2011-06-17 14:59 209920 ----a-w- c:\windows\system32\mfplat.dll
2011-06-17 14:43 . 2011-01-20 16:08 160768 ----a-w- c:\windows\system32\d3d10_1.dll
2011-06-17 14:43 . 2011-01-20 14:12 1172480 ----a-w- c:\windows\system32\d3d10warp.dll
2011-06-17 14:43 . 2011-01-20 13:47 683008 ----a-w- c:\windows\system32\d2d1.dll
2011-06-17 14:43 . 2011-02-22 13:33 1068544 ----a-w- c:\windows\system32\DWrite.dll
2011-06-17 14:43 . 2011-02-22 13:33 797696 ----a-w- c:\windows\system32\FntCache.dll
2011-06-17 14:43 . 2011-01-20 16:08 1029120 ----a-w- c:\windows\system32\d3d10.dll
2011-06-17 14:43 . 2011-01-20 14:11 486400 ----a-w- c:\windows\system32\d3d10level9.dll
2011-06-17 14:43 . 2011-02-22 14:13 288768 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-06-17 14:43 . 2011-01-20 16:08 219648 ----a-w- c:\windows\system32\d3d10_1core.dll
2011-06-17 14:43 . 2011-01-20 16:08 189952 ----a-w- c:\windows\system32\d3d10core.dll
2011-06-17 14:43 . 2011-01-20 14:28 1554432 ----a-w- c:\windows\system32\xpsservices.dll
2011-06-17 14:43 . 2011-01-20 14:25 847360 ----a-w- c:\windows\system32\OpcServices.dll
2011-06-17 14:41 . 2010-05-04 19:13 231424 ----a-w- c:\windows\system32\msshsq.dll
2011-06-17 14:35 . 2011-05-24 18:12 6962000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A65DB2DA-DF0D-43A1-9838-28F7C7B6354D}\mpengine.dll
2011-06-17 13:27 . 2011-06-17 13:27 -------- d-----w- c:\program files\Microsoft.NET
2011-06-17 10:10 . 2011-06-17 10:12 -------- d-----w- c:\windows\system32\ca-ES
2011-06-17 10:10 . 2011-06-17 10:12 -------- d-----w- c:\windows\system32\eu-ES
2011-06-17 10:10 . 2011-06-17 10:12 -------- d-----w- c:\windows\system32\vi-VN
2011-06-17 09:00 . 2011-06-17 09:00 -------- d-----w- c:\windows\system32\EventProviders
2011-06-17 08:57 . 2009-04-11 05:03 12240896 ----a-w- c:\windows\system32\NlsLexicons0007.dll
2011-06-17 08:57 . 2009-04-11 06:28 1081344 ----a-w- c:\windows\system32\SLCExt.dll
2011-06-17 08:57 . 2009-04-11 06:27 3408896 ----a-w- c:\windows\system32\SLsvc.exe
2011-06-17 08:57 . 2009-04-11 06:28 2134528 ----a-w- c:\windows\system32\FunctionDiscoveryFolder.dll
2011-06-17 08:57 . 2009-04-11 06:27 65536 ----a-w- c:\windows\system32\DevicePairingWizard.exe
2011-06-17 08:57 . 2009-04-11 05:03 2644480 ----a-w- c:\windows\system32\NlsLexicons0009.dll
2011-06-17 08:57 . 2009-04-11 06:28 1480704 ----a-w- c:\windows\system32\mssrch.dll
2011-06-17 08:57 . 2009-04-11 02:52 684032 ----a-w- c:\windows\system32\drivers\spsys.sys
2011-06-17 08:55 . 2009-04-11 06:28 368640 ----a-w- c:\windows\system32\mspbde40.dll
2011-06-17 08:54 . 2009-04-11 06:28 342528 ----a-w- c:\windows\system32\zipfldr.dll
2011-06-17 08:53 . 2009-04-11 06:28 83968 ----a-w- c:\windows\system32\wbem\wmiutils.dll
2011-06-17 08:53 . 2009-04-11 06:28 744448 ----a-w- c:\windows\system32\wbem\wbemcore.dll
2011-06-17 08:53 . 2009-04-11 06:28 30208 ----a-w- c:\windows\system32\wbem\wbemprox.dll
2011-06-17 08:53 . 2009-04-11 06:28 265728 ----a-w- c:\windows\system32\wbem\repdrvfs.dll
2011-06-17 08:53 . 2009-04-11 06:28 189440 ----a-w- c:\windows\system32\wbem\mofd.dll
2011-06-17 08:53 . 2009-04-11 06:28 614912 ----a-w- c:\windows\system32\wbem\fastprox.dll
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-17 14:58 . 2011-06-17 14:58 4096 ----a-w- c:\windows\system32\drivers\en-US\dxgkrnl.sys.mui
2011-06-16 16:44 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2011-06-16 16:44 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
2011-06-15 15:47 . 2011-06-15 15:47 36864 ----a-w- c:\windows\system32\drivers\en-US\http.sys.mui
2011-06-15 03:52 . 2011-06-15 03:52 2560 ----a-w- c:\windows\apppatch\AcRes.dll
2011-04-22 09:35 . 2011-04-22 09:35 1460608 ----a-w- c:\windows\system32\WdfCoInstaller01009.dll
2011-06-22 21:01 . 2011-06-15 01:32 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OpenDNS Updater"="c:\program files\OpenDNS Updater\OpenDNSUpdater.exe" [2010-06-16 839680]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-06-30 2424192]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2006-12-14 411768]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2006-12-14 493688]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2006-12-11 530552]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-07-11 90112]
"RtHDVCpl"="RtHDVCpl.exe" [2006-11-01 3772416]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-27 815104]
"TOSHIBA Volume Indicator"="c:\program files\Toshiba\Utilities\VolControl.exe" [2006-12-13 94208]
"NDSTray.exe"="NDSTray.exe" [BU]
"topi"="c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2006-12-15 577536]
"Toshiba Registration"="c:\program files\Toshiba\Registration\ToshibaRegistration.exe" [2006-12-13 554640]
"Toshiba TEMPRO"="c:\program files\Toshiba TEMPRO\TemproTray.exe" [2010-08-27 1050072]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-05-29 449584]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jaureg.exe" [2010-05-14 237800]
"@OnlineArmor GUI"="c:\program files\Online Armor\oaui.exe" [2011-04-06 2477032]
"EEventManager"="c:\program files\EPSON\Creativity Suite\Event Manager\EEventManager.exe" [2005-04-08 102400]
.
c:\users\Tendai\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Secunia PSI Tray.lnk - c:\program files\Secunia\PSI\psi_tray.exe [2011-4-19 291896]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= "c:\progra~1\ONLINE~1\oaevent.dll" [2011-04-06 354720]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R1 MpKsl04eaf06c;MpKsl04eaf06c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B27B764D-EBF1-4342-AF26-A1C2EE6F7DEE}\MpKsl04eaf06c.sys [x]
R1 oahlpXX;Online Armor helper driver;c:\windows\system32\drivers\oahlp32.sys [2011-04-06 39048]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-06-15 136176]
R2 SvcOnlineArmor;Online Armor;c:\program files\Online Armor\oasrv.exe [2011-04-06 4326472]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-10-24 43392]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-24 54144]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 206360]
R3 nosGetPlusHelper;getPlus® Helper 3004;c:\windows\System32\svchost.exe [2008-01-19 21504]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 PuranDefrag;PuranDefrag;c:\windows\system32\PuranDefragS.exe [2011-04-08 233472]
S1 38013711;38013711;c:\windows\system32\DRIVERS\38013711.sys [2009-09-25 128016]
S1 MpKsl194f0b8e;MpKsl194f0b8e;c:\windows\system32\MpEngineStore\MpKsl194f0b8e.sys [2011-07-01 28752]
S1 MpKsl788fa796;MpKsl788fa796;c:\windows\system32\MpEngineStore\MpKsl788fa796.sys [2011-07-01 28752]
S1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [2011-04-06 205864]
S1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [2011-04-06 25192]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-05-29 366640]
S2 OAcat;Online Armor Helper Service;c:\program files\Online Armor\OAcat.exe [2011-04-06 381512]
S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files\Secunia\PSI\PSIA.exe [2011-04-19 993848]
S2 Secunia Update Agent;Secunia Update Agent;c:\program files\Secunia\PSI\sua.exe [2011-04-19 399416]
S2 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files\Toshiba TEMPRO\TemproSvc.exe [2010-08-27 124368]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-05-29 22712]
S3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2010-09-01 15544]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - MPKSL788FA796
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
Contents of the 'Scheduled Tasks' folder
.
2011-07-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-06-15 01:17]
.
2011-07-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-06-15 01:17]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.buzqo.com/?cfg=2-401-0-...
TCP: DhcpNameServer = 192.168.1.1 192.168.1.1
TCP: Interfaces\{85B9BBD9-7474-4605-8E3F-FE01B97288A7}: NameServer = 208.67.222.222,208.67.220.220
FF - ProfilePath - c:\users\Tendai\AppData\Roaming\Mozilla\Firefox\Profiles\rsun6w2c.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-07-01 15:55
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Completion time: 2011-07-01 16:05:25
ComboFix-quarantined-files.txt 2011-07-01 15:05
.
Pre-Run: 21,431,263,232 bytes free
Post-Run: 21,442,142,208 bytes free
.
- - End Of File - - 30030F057C5A3325EEB9D036512BD7FF