Hi SuperDave, not much is working. SecurityCheck only gave a black screen that said it was running and then said that it was done. Nothing else. Combofix put me thru many hoops and I'm not sure if this is going to work either but I'll attempt to send that log. Thanks,again. overthehill
ComboFix 10-09-01.02 - Bonham 09/01/2010 21:42:53.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2439 [GMT -5:00]
Running from: c:\documents and settings\Bonham\Desktop\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: Online Armor Firewall *disabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Bonham\Local Settings\~GLH000f.TMP
c:\windows\system32\csftxctl.ocx
c:\windows\system32\zlibwapi.dll
.
((((((((((((((((((((((((( Files Created from 2010-08-02 to 2010-09-02 )))))))))))))))))))))))))))))))
.
2010-09-02 00:02 . 2010-09-02 00:02 388096 ----a-r- c:\documents and settings\Bonham\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-09-02 00:02 . 2010-09-02 00:02 -------- d-----w- c:\program files\Trend Micro
2010-08-31 18:37 . 2010-08-31 18:37 -------- d-----w- c:\program files\Common Files\Java
2010-08-31 18:37 . 2010-08-31 18:37 -------- d-----w- c:\program files\Sun
2010-08-30 20:05 . 2010-08-30 20:05 -------- d-----w- c:\windows\system32\wbem\Repository
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-01 14:02 . 2010-06-27 04:48 -------- d-----w- c:\program files\SpeedFan
2010-08-31 18:36 . 2010-04-15 16:04 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-08-31 18:35 . 2010-02-05 04:41 -------- d-----w- c:\program files\Java
2010-08-30 05:09 . 2010-01-29 01:57 -------- d-----w- c:\documents and settings\Bonham\Application Data\U3
2010-08-29 14:15 . 2010-05-24 05:30 -------- d-----w- c:\documents and settings\Bonham\Application Data\Folding@home-x86
2010-08-25 04:31 . 2010-03-25 20:57 -------- d-----w- c:\program files\FileHippo.com
2010-08-25 04:27 . 2007-03-23 16:44 70696 -c--a-w- c:\documents and settings\Bonham\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-08-16 18:52 . 2008-09-13 17:18 -------- d-----w- c:\program files\CCleaner
2010-08-16 17:42 . 2007-12-06 17:08 -------- d-----w- c:\program files\NCH Swift Sound
2010-08-16 04:30 . 2010-02-11 00:49 -------- d-----w- c:\program files\Opera
2010-08-10 03:56 . 2010-02-02 22:09 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-08-10 03:54 . 2009-02-07 04:59 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-08-01 19:57 . 2009-02-15 06:38 -------- d-----w- c:\program files\MSECACHE
2010-07-21 02:47 . 2010-07-21 02:47 -------- d-----w- c:\documents and settings\Bonham\Application Data\Foxit Software
2010-07-18 05:55 . 2010-07-18 05:10 -------- d-----w- c:\program files\Motherboard Monitor 5
2010-07-18 04:07 . 2010-04-01 16:29 -------- d-----w- c:\program files\IZArc
2010-07-18 03:51 . 2010-07-18 03:51 257257 ----a-w- c:\documents and settings\Bonham\Application Data\OpenCandy\OpenCandy_8BA1ABBB15EF4F428868FEB343C44A8D\DLMGR3.exe
2010-07-18 03:51 . 2010-07-18 03:51 -------- d-----w- c:\documents and settings\Bonham\Application Data\OpenCandy
2010-07-17 17:34 . 2010-07-17 17:34 63488 ----a-w- c:\documents and settings\Bonham\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-07-17 17:34 . 2010-07-17 17:34 52224 ----a-w- c:\documents and settings\Bonham\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-07-17 17:34 . 2010-07-17 17:34 117760 ----a-w- c:\documents and settings\Bonham\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-07-17 17:33 . 2010-07-17 17:33 -------- d-----w- c:\documents and settings\Bonham\Application Data\SUPERAntiSpyware.com
2010-07-17 17:32 . 2010-02-13 02:04 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-07-17 04:04 . 2010-07-17 04:04 19724 ----a-w- c:\program files\FAHlog.txt
2010-07-15 00:13 . 2010-07-15 00:13 1683456 ----a-w- c:\documents and settings\Bonham\Application Data\Folding@home-x86\FahCore_82.exe
2010-07-12 21:29 . 2006-09-20 00:54 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-07-12 21:29 . 2010-07-12 21:29 -------- d-----w- c:\documents and settings\Bonham\Application Data\Intel
2010-07-12 21:29 . 2010-07-12 21:29 -------- d-----w- c:\documents and settings\Bonham\Application Data\Avocent AdminWorks
2010-07-12 21:29 . 2010-07-12 21:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Avocent AdminWorks
2010-07-12 21:29 . 2010-03-01 17:01 -------- d-----w- c:\program files\Intel
2010-07-12 05:14 . 2006-09-20 00:54 -------- d-----w- c:\program files\Common Files\InstallShield
2010-07-06 03:27 . 2010-03-18 03:27 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-07-06 03:26 . 2010-03-18 03:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-06-30 12:31 . 2006-09-20 16:19 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-28 20:57 . 2010-06-29 03:41 38848 ----a-w- c:\windows\avastSS.scr
2010-06-28 20:57 . 2009-11-05 15:28 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-06-28 20:37 . 2009-11-05 15:28 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-06-28 20:37 . 2009-11-05 15:28 165456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-06-28 20:33 . 2009-11-05 15:28 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-06-28 20:32 . 2009-11-05 15:28 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-06-28 20:32 . 2009-11-05 15:28 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-06-28 20:32 . 2009-11-05 15:28 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-06-28 20:32 . 2009-11-05 15:28 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-06-27 06:09 . 2010-06-27 06:09 4484 ----a-w- c:\windows\system32\drivers\cpuidlep.sys
2010-06-24 23:57 . 2010-06-24 23:57 2338816 ----a-w- c:\documents and settings\Bonham\Application Data\Folding@home-x86\FahCore_78.exe
2010-06-24 12:22 . 2006-09-20 16:20 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-23 13:44 . 2007-02-27 00:28 1851904 ----a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27 . 2006-09-20 16:19 354304 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-17 14:03 . 2006-09-20 16:17 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-14 14:31 . 2006-09-20 16:17 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-14 07:41 . 2006-09-20 16:18 1172480 ----a-w- c:\windows\system32\msxml3.dll
2010-04-07 03:25 . 2010-04-07 03:25 327002 ----a-w- c:\program files\Jumble.jpg
2010-04-02 00:49 . 2010-04-02 00:49 768191 ----a-w- c:\program files\scan0001.pdf
2010-04-02 00:29 . 2010-04-02 00:29 5613568 ----a-w- c:\program files\Doc1.doc
2009-03-31 05:01 . 2009-03-27 14:24 648064 ----a-w- c:\program files\autoruns.exe
2009-03-31 05:01 . 2009-03-27 14:24 540544 ----a-w- c:\program files\autorunsc.exe
2009-03-31 05:01 . 2008-12-16 21:46 49244 ----a-w- c:\program files\autoruns.chm
2009-03-31 05:01 . 2006-07-28 13:32 7005 -c--a-w- c:\program files\Eula.txt
2007-11-27 06:38 . 2007-11-27 06:41 21216112 -c--a-w- c:\program files\aaw2007.exe
2007-11-21 22:41 . 2007-11-21 22:41 550690 ----a-w- c:\program files\sbstar11.exe
2007-11-17 17:06 . 2007-11-17 17:06 3458671 ----a-w- c:\program files\PCTuneUpSetup.exe
2007-11-15 03:00 . 2007-11-15 03:00 10138931 -c--a-w- c:\program files\setupLE.exe
2007-06-06 21:31 . 2007-06-06 21:31 6820520 ----a-w- c:\program files\FirefoxGoogleToolbarSetup.exe
2007-02-26 23:17 . 2007-02-26 23:17 0 -csha-w- c:\windows\SMINST\HPCD.sys
2006-05-03 10:06 . 2010-03-11 16:16 163328 --sh--r- c:\windows\system32\flvDX.dll
2007-02-21 11:47 . 2010-03-11 16:16 31232 --sh--r- c:\windows\system32\msfDX.dll
2008-03-16 13:30 . 2010-03-11 16:16 216064 --sh--r- c:\windows\system32\nbDX.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-02-04 1197448]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2010-02-04 1197448]
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IncrediMail"="c:\program files\IncrediMail\bin\IncMail.exe" [2009-09-07 251336]
"WhatPulse"="c:\program files\WhatPulse\WhatPulse.exe" [2009-04-08 2814976]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-06-28 2837864]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2010-05-31 323976]
"@OnlineArmor GUI"="c:\program files\Tall Emu\Online Armor\oaui.exe" [2010-04-20 6678008]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-03-16 13670504]
"ipTray.exe"="c:\program files\Intel\IDU\iptray.exe" [2005-12-02 1687552]
"awTray.exe"="c:\program files\Intel\IDU\awtray.exe" [2005-12-01 1305600]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-18 421888]
c:\documents and settings\Bonham\Start Menu\Programs\Startup\
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-8-29 360448]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
LaunchU3.exe.lnk - c:\windows\Installer\{D8E363A7-88B7-446D-B2C0-E26CE4DC8E54}\_294823.exe [2010-5-2 22486]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= "c:\progra~1\TALLEM~1\ONLINE~1\oaevent.dll" [2010-04-20 925688]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^Bonham^Start Menu^Programs^Startup^
[email protected]]
path=c:\documents and settings\Bonham\Start Menu\Programs\Startup\
[email protected]backup=c:\windows\pss\
[email protected][HKLM\~\startupfolder\C:^Documents and Settings^Bonham^Start Menu^Programs^Startup^speedfan.lnk]
path=c:\documents and settings\Bonham\Start Menu\Programs\Startup\speedfan.lnk
backup=c:\windows\pss\speedfan.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImLc.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImApp.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IncrediMail_Install.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxs08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqfxt08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Roxio\\Easy Media Creator 8\\Digital Home\\RoxUpnpServer.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9999:UDP"= 9999:UDP:IDU Service UDP Port
"2804:TCP"= 2804:TCP:IDU Service TCP Port
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [11/5/2009 10:28 AM 165456]
R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [4/30/2010 11:30 AM 228216]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [4/30/2010 11:30 AM 24440]
R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [4/30/2010 11:30 AM 29560]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 1:25 PM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 1:41 PM 67656]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [11/5/2009 10:28 AM 17744]
R2 MotoConnect Service;MotoConnect Service;c:\program files\Motorola\MotoConnectService\MotoConnectService.exe [11/15/2009 6:56 PM 91392]
R2 OAcat;Online Armor Helper Service;c:\program files\Tall Emu\Online Armor\oacat.exe [4/30/2010 11:30 AM 1284600]
R3 FVDSCSI;FVDSCSI;c:\windows\system32\drivers\fvdscsi.sys [9/19/2006 8:01 PM 72478]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [3/25/2010 8:33 PM 58600]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [12/20/2009 8:35 PM 135664]
S2 SvcOnlineArmor;Online Armor;c:\program files\Tall Emu\Online Armor\oasrv.exe [4/30/2010 11:30 AM 3364856]
S3 cpudrv;cpudrv;c:\program files\SystemRequirementsLab\cpudrv.sys [12/18/2009 11:58 AM 11336]
S3 IAMTXP;Driver for Intel(R) Active Management Technology - KCS;c:\windows\system32\drivers\IAMTXP.sys [11/29/2005 7:07 AM 40448]
S3 NVIDIAHWAccess;NVIDIAHWAccess;\??\c:\documents and settings\Bonham\Application Data\NVIDIA\HWAccess.sys --> c:\documents and settings\Bonham\Application Data\NVIDIA\HWAccess.sys [?]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [6/17/2009 7:20 AM 12648]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2010-09-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-21 01:35]
2010-09-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-21 01:35]
2010-08-30 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2010-06-04 17:57]
2010-08-23 c:\windows\Tasks\switchShakeIcon.job
- c:\program files\NCH Swift Sound\Switch\switch.exe [2010-08-16 17:42]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.mymanitoba.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: eBay Search - c:\program files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
Trusted Zone: uclickgames.com\www
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-SpybotSD TeaTimer - c:\program files\Spybot - Search & Destroy\TeaTimer.exe
**************************************************************************
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\vsdatant]
"ImagePath"=""
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-3912740996-3383120692-1400082210-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-3912740996-3383120692-1400082210-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{92268181-0295-BF26-2F3E-4FB8F46590D7}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"oadhfdllpnncdggpgjgbnkconemonj"=hex:64,61,67,66,61,62,6e,6f,00,e0
"oahcgkkmfpfalamfmpkiiodoikgbfm"=hex:69,61,6f,67,6b,64,68,70,65,6c,61,69,6e,69,
68,66,61,6d,00,00
"nabiekbojhpfnondicbhiabbjjlp"=hex:6a,61,67,66,6b,62,65,69,62,61,6b,6b,69,6c,
6c,63,67,67,66,69,00,fd
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(484)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
Completion time: 2010-09-01 21:49:17
ComboFix-quarantined-files.txt 2010-09-02 02:49
Pre-Run: 204,928,028,672 bytes free
Post-Run: 204,930,916,352 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
- - End Of File - - DD18039B09210B0890A2C7774B007488