Hello Dave,
Gosh you must be very very busy.
Here is the log from Security Check:
Results of screen317's Security Check version 0.99.10
Windows Vista Service Pack 2 (UAC is enabled)
Internet Explorer 7
Out of date! ``````````````````````````````
Antivirus/Firewall Check: Windows Firewall Enabled!
avast! Internet Security
WMI entry may not exist for antivirus; attempting automatic update. ```````````````````````````````
Anti-malware/Other Utilities Check: Malwarebytes' Anti-Malware
CCleaner
Java(TM) 6 Update 24
Java(TM) SE Runtime Environment 6
Adobe Flash Player 10.2.152.32
Adobe Reader 8.1.2
Out of date Adobe Reader installed! Mozilla Firefox (3.6.16)
Firefox Out of Date! Mozilla Thunderbird (3.1.7)
Thunderbird Out of Date! ````````````````````````````````
Process Check:
objlist.exe by Laurent Windows Defender MSASCui.exe
Windows Defender MSASCui.exe
system32 AvastSvc.exe -?-
Alwil Software Avast5 AvastUI.exe
``````````End of Log```````````` ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Here is my log from ComboFix:
ComboFix 11-04-01.01 - User-2 04/01/2011 21:26:42.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1013.386 [GMT -10:00]
Running from: c:\users\User-2\Desktop\ComboFix.exe
AV: avast! Internet Security *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
FW: avast! Internet Security *Disabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47}
SP: avast! Internet Security *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\netzeroinstaller\NetZeroInstaller.exe
c:\programdata\ntuser.dat
c:\programdata\xp
c:\programdata\xp\EBLib.dll
c:\programdata\xp\TPwSav.sys
.
.
((((((((((((((((((((((((( Files Created from 2011-03-02 to 2011-04-02 )))))))))))))))))))))))))))))))
.
.
2011-04-02 07:38 . 2011-04-02 07:38 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-04-01 02:49 . 2011-04-01 02:49 388096 ----a-r- c:\users\User-2\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-04-01 02:49 . 2011-04-01 02:54 -------- d-----w- c:\program files\Trend Micro
2011-03-31 07:41 . 2011-03-31 07:41 -------- d-----w- c:\users\User-2\AppData\Roaming\Malwarebytes
2011-03-31 07:40 . 2011-03-31 07:40 -------- d-----w- c:\programdata\Malwarebytes
2011-03-31 07:40 . 2010-12-21 04:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-03-31 07:40 . 2011-03-31 07:41 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-03-31 07:40 . 2010-12-21 04:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-03-31 01:23 . 2011-03-31 01:23 -------- d-----w- c:\users\User-2\AppData\Roaming\SUPERAntiSpyware.com
2011-03-31 01:23 . 2011-03-31 01:23 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2011-03-31 01:23 . 2011-03-31 01:23 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-03-31 00:44 . 2011-03-31 00:44 -------- d-----w- c:\program files\CCleaner
2011-03-27 22:27 . 2011-03-15 04:05 6792528 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{13ABB5D9-2672-4397-8609-3C2111F8CA69}\mpengine.dll
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-02-23 15:04 . 2010-06-30 10:01 40648 ----a-w- c:\windows\avastSS.scr
2011-02-23 15:04 . 2007-08-02 02:16 190016 ----a-w- c:\windows\system32\aswBoot.exe
2011-02-23 14:57 . 2010-02-27 08:37 101976 ----a-w- c:\windows\system32\drivers\aswFW.sys
2011-02-23 14:56 . 2010-02-27 08:37 371544 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-02-23 14:56 . 2008-12-25 09:10 301528 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-02-23 14:56 . 2010-02-27 08:35 192728 ----a-w- c:\windows\system32\drivers\aswNdis2.sys
2011-02-23 14:55 . 2007-08-02 02:16 49240 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-02-23 14:55 . 2007-08-02 02:16 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-02-23 14:55 . 2007-08-02 02:16 53592 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-02-23 14:54 . 2008-12-25 09:10 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-02-03 07:40 . 2010-06-15 17:21 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-02-03 04:11 . 2009-10-02 17:35 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-01-20 16:37 . 2011-03-01 04:14 638336 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-01-20 16:08 . 2011-03-01 04:14 478720 ----a-w- c:\windows\system32\dxgi.dll
2011-01-20 16:08 . 2011-03-01 04:14 219648 ----a-w- c:\windows\system32\d3d10_1core.dll
2011-01-20 16:08 . 2011-03-01 04:14 160768 ----a-w- c:\windows\system32\d3d10_1.dll
2011-01-20 16:08 . 2011-03-01 04:14 1029120 ----a-w- c:\windows\system32\d3d10.dll
2011-01-20 16:08 . 2011-03-01 04:14 189952 ----a-w- c:\windows\system32\d3d10core.dll
2011-01-20 16:07 . 2011-03-01 04:14 37376 ----a-w- c:\windows\system32\cdd.dll
2011-01-20 16:07 . 2011-03-01 04:14 258048 ----a-w- c:\windows\system32\winspool.drv
2011-01-20 16:07 . 2011-03-01 04:14 586240 ----a-w- c:\windows\system32\stobject.dll
2011-01-20 16:06 . 2011-03-01 04:14 2873344 ----a-w- c:\windows\system32\mf.dll
2011-01-20 16:06 . 2011-03-01 04:14 26112 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll
2011-01-20 16:04 . 2011-03-01 04:14 209920 ----a-w- c:\windows\system32\mfplat.dll
2011-01-20 16:04 . 2011-03-01 04:14 98816 ----a-w- c:\windows\system32\mfps.dll
2011-01-20 14:28 . 2011-03-01 04:14 1554432 ----a-w- c:\windows\system32\xpsservices.dll
2011-01-20 14:27 . 2011-03-01 04:14 876032 ----a-w- c:\windows\system32\XpsPrint.dll
2011-01-20 14:26 . 2011-03-01 04:14 667648 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
2011-01-20 14:25 . 2011-03-01 04:14 847360 ----a-w- c:\windows\system32\OpcServices.dll
2011-01-20 14:24 . 2011-03-01 04:14 288768 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-01-20 14:24 . 2011-03-01 04:14 135680 ----a-w- c:\windows\system32\XpsRasterService.dll
2011-01-20 14:15 . 2011-03-01 04:14 979456 ----a-w- c:\windows\system32\MFH264Dec.dll
2011-01-20 14:14 . 2011-03-01 04:14 357376 ----a-w- c:\windows\system32\MFHEAACdec.dll
2011-01-20 14:14 . 2011-03-01 04:14 302592 ----a-w- c:\windows\system32\mfmp4src.dll
2011-01-20 14:14 . 2011-03-01 04:14 261632 ----a-w- c:\windows\system32\mfreadwrite.dll
2011-01-20 14:12 . 2011-03-01 04:14 1172480 ----a-w- c:\windows\system32\d3d10warp.dll
2011-01-20 14:11 . 2011-03-01 04:14 486400 ----a-w- c:\windows\system32\d3d10level9.dll
2011-01-20 13:47 . 2011-03-01 04:14 683008 ----a-w- c:\windows\system32\d2d1.dll
2011-01-20 13:44 . 2011-03-01 04:14 1068544 ----a-w- c:\windows\system32\DWrite.dll
2011-01-20 13:44 . 2011-03-01 04:14 797184 ----a-w- c:\windows\system32\FntCache.dll
2011-01-08 08:47 . 2011-03-01 04:09 34304 ----a-w- c:\windows\system32\atmlib.dll
2011-01-08 06:28 . 2011-03-01 04:09 292352 ----a-w- c:\windows\system32\atmfd.dll
2010-04-12 00:19 . 2010-04-12 00:19 14336 ----a-w- c:\program files\wmdmhelper.dll
2010-04-12 00:19 . 2010-04-12 00:19 712704 ----a-w- c:\program files\dtdr3260.dll
2010-04-12 00:19 . 2010-04-12 00:19 356352 ----a-w- c:\program files\rjdlg.dll
2010-04-12 00:19 . 2010-04-12 00:19 19456 ----a-w- c:\program files\rjprog.dll
2010-04-12 00:19 . 2010-04-12 00:19 139264 ----a-w- c:\program files\DUNZIP32.dll
2010-04-12 00:19 . 2010-04-12 00:19 651264 ----a-w- c:\program files\rjbres.dll
2010-04-12 00:19 . 2010-04-12 00:19 36352 ----a-w- c:\program files\ierjplug.dll
2010-04-12 00:19 . 2010-04-12 00:19 6656 ----a-w- c:\program files\fixrjb.exe
2010-04-12 00:19 . 2010-04-12 00:19 41472 ----a-w- c:\program files\mmcdda32.dll
2010-04-12 00:19 . 2010-04-12 00:19 19456 ----a-w- c:\program files\tnetdtct.dll
2010-04-12 00:19 . 2010-04-12 00:19 81920 ----a-w- c:\program files\tsasdk.dll
2010-04-12 00:19 . 2010-04-12 00:19 57344 ----a-w- c:\program files\tpasdk.dll
2010-04-12 00:19 . 2010-04-12 00:19 32768 ----a-w- c:\program files\rpwa3260.dll
2010-04-12 00:19 . 2010-04-12 00:19 16296 ----a-w- c:\program files\realtfon.fon
2010-04-12 00:19 . 2010-04-12 00:19 43056 ----a-w- c:\program files\rpshellsearch.dll
2010-04-12 00:18 . 2010-04-12 00:18 719360 ----a-w- c:\program files\dbghelp.dll
2010-04-12 00:18 . 2010-04-12 00:18 65536 ----a-w- c:\program files\rjwmapln.dll
2010-04-12 00:18 . 2010-04-12 00:18 53248 ----a-w- c:\program files\rpau3260.dll
2010-04-12 00:18 . 2010-04-12 00:18 102400 ----a-w- c:\program files\HXAudioDeviceHook.dll
2010-04-12 00:18 . 2010-04-12 00:18 86016 ----a-w- c:\program files\rpplugprot.dll
2010-04-12 00:18 . 2010-04-12 00:18 63016 ----a-w- c:\program files\rpshell.dll
2010-04-12 00:18 . 2010-04-12 00:18 112168 ----a-w- c:\program files\rdsf3260.dll
2010-04-12 00:18 . 2010-04-12 00:18 7168 ----a-w- c:\program files\realjbox.exe
2010-04-12 00:18 . 2010-04-12 00:18 14888 ----a-w- c:\program files\rphelperapp.exe
2010-04-12 00:17 . 2010-04-12 00:17 488968 ----a-w- c:\program files\realplay.exe
2010-04-12 00:17 . 2010-04-12 00:17 407104 ----a-w- c:\program files\RecordingManager.exe
2010-08-13 09:04 . 2008-12-13 06:43 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-02-23 15:04 122512 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-09-20 39408]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-10-12 14940040]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-03-20 1451304]
"RtHDVCpl"="RtHDVCpl.exe" [2006-11-09 3784704]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2005-12-16 188416]
"NDSTray.exe"="NDSTray.exe" [BU]
"HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2006-11-01 413696]
"SVPWUTIL"="c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe" [2006-01-19 421888]
"KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2006-11-07 34352]
"PINGER"="c:\toshiba\IVP\ISM\pinger.exe" [2006-07-20 151552]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-08-13 30192]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-30 249064]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2011-02-23 3451496]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-07-22 141608]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-12 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-12 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-12 133656]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-30 421888]
.
c:\users\User-2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Microsoft Office OneNote 2003 Quick Launch.lnk - c:\program files\Microsoft Office\OFFICE11\ONENOTEM.EXE [2007-4-19 64864]
Oneeko.lnk - c:\program files\Oneeko\ONEEKO.EXE [N/A]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-3-15 113664]
Microsoft Office OneNote 2003 Quick Launch.lnk - c:\program files\Microsoft Office\OFFICE11\ONENOTEM.EXE [2007-4-19 64864]
ymetray.lnk - c:\program files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2008-2-5 54512]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
.
R2 avast! Firewall;avast! Firewall;c:\program files\Alwil Software\Avast5\afwServ.exe [2011-02-23 121000]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate1cad9d4d0da1331;Google Update Service (gupdate1cad9d4d0da1331);c:\program files\Google\Update\GoogleUpdate.exe [2010-04-12 133104]
R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-08-13 30192]
R3 USB_RNDIS_VISTA;Westell USB Network Interface;c:\windows\system32\DRIVERS\usb8023.sys [2009-04-11 15872]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\aswNdis.sys [2010-01-09 12112]
S0 aswNdis2;avast! Firewall Core Firewall Service;
S1 aswFW;avast! TDI Firewall driver;
S1 aswSnx;aswSnx;
S1 aswSP;aswSP;
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
S2 aswFsBlk;aswFsBlk;
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-02-23 53592]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2011-04-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-12 00:11]
.
2011-04-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-12 00:11]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://us.mc624.mail.yahoo.com/mc/welcome?.gx=1&.tm=1253477804&.rand=8lrtg7plic7v6
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://my.netzero.net/s/search?r=minisearch
IE: Display All Images with Full Quality - c:\program files\NetZero\qsacc\appres.dll/228
IE: Display Image with Full Quality - c:\program files\NetZero\qsacc\appres.dll/227
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Note this (Google Notebook) - c:\program files\Google\Google Notebook\gnotes1.0.2.19-742769657.dll/gn_menu1.html
IE: Note this item (Google Notebook) - c:\program files\Google\Google Notebook\gnotes1.0.2.19-742769657.dll/gn_menu2.html
FF - ProfilePath - c:\users\User-2\AppData\Roaming\Mozilla\Firefox\Profiles\leonb54p.default\
FF - prefs.js: browser.startup.homepage - hxxp://Google.Com/ig
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?sourceid=navclient&hl=en&q=
FF - Ext: The Browser Highlighter:
[email protected] - c:\program files\Mozilla Firefox\extensions\
[email protected]FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - %profile%\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-TOSCDSPD - TOSCDSPD.EXE
HKLM-Run-TPwrMain - %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
HKLM-Run-HSON - %ProgramFiles%\TOSHIBA\TBS\HSON.exe
HKLM-Run-SmoothView - %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
HKLM-Run-00TCrdMain - %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
AddRemove-Oneeko - c:\program files\Oneeko\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-04-01 21:38
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aifc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aiff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flac\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.midi\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pls\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.snd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.spx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
.
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Completion time: 2011-04-01 21:43:41
ComboFix-quarantined-files.txt 2011-04-02 07:43
.
Pre-Run: 38,726,467,584 bytes free
Post-Run: 38,641,799,168 bytes free
.
Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 835781CA807612FC2D7A87808F500F6B
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
I am confused about the new HijackThis log. I don't have one since I did'nt click the
Do a system scan and save a log file button as per your instructions. Should I run one again clicking that
Do a system scan and save a log file button?
Thank you for your patient assistance,
Nari