ComboFix 11-07-10.03 - Feutz 07/10/2011 9:15.1.2 - x86
Running from: c:\users\Feutz\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Public\_rise_of_the_scarrid.exe
c:\windows\system32\AutoRun.inf
c:\windows\system32\msconfig.exe
c:\windows\system32\no
c:\windows\system32\SV
c:\windows\system32\SV\toscdspd.cpl.mui
.
.
((((((((((((((((((((((((( Files Created from 2011-06-10 to 2011-07-10 )))))))))))))))))))))))))))))))
.
.
2011-07-10 16:36 . 2011-07-10 16:36 -------- d-----w- c:\users\Robin\AppData\Local\temp
2011-07-10 16:36 . 2011-07-10 16:36 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-07-09 22:15 . 2011-07-09 22:15 -------- d-----w- c:\program files\ConduitEngine
2011-07-09 22:14 . 2011-07-09 22:14 -------- d-----w- c:\users\Feutz\AppData\Local\Conduit
2011-07-09 22:14 . 2011-07-09 22:14 -------- d-----w- c:\program files\Vuze_Remote
2011-07-09 16:37 . 2011-07-09 16:37 -------- d-----w- C:\found.005
2011-07-09 16:30 . 2011-07-09 16:30 -------- d-----w- C:\40d9b26e2a8b3f767a
2011-07-09 03:07 . 2011-07-10 16:13 179428 ----a-w- c:\windows\system32\drivers\APPFCONT.DAT
2011-07-09 03:07 . 2010-09-09 23:23 193864 ----a-w- c:\windows\system32\drivers\idsflt.sys
2011-07-09 03:07 . 2009-09-25 21:54 46856 ----a-w- c:\windows\system32\drivers\wnmflt.sys
2011-07-09 03:07 . 2009-09-25 21:54 53256 ----a-w- c:\windows\system32\drivers\dsaflt.sys
2011-07-09 03:06 . 2011-01-31 23:41 83528 ----a-w- c:\windows\system32\drivers\APPFLT.SYS
2011-07-09 03:06 . 2009-09-25 21:54 22024 ----a-w- c:\windows\system32\drivers\fnetmon.sys
2011-07-09 03:06 . 2009-09-25 21:54 159112 ----a-w- c:\windows\system32\drivers\NETFLTDI.SYS
2011-07-08 22:15 . 2011-06-20 15:57 7074640 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{39B46583-8D1C-412D-8F9B-1A6B8892B1F2}\mpengine.dll
2011-07-07 10:00 . 2011-07-07 10:00 -------- d-----w- C:\ef60c58cdd1f56bf95401cfaf20940ef
2011-07-07 00:18 . 2011-07-07 00:18 -------- d-----w- C:\78584a5e440f81cc72
2011-07-05 10:00 . 2011-07-05 10:00 -------- d-----w- C:\760eb5305c2b3efcab91dcc17084bd
2011-07-04 23:18 . 2011-07-04 23:18 -------- d-----w- C:\found.004
2011-07-04 22:45 . 2011-07-04 22:45 -------- d-----w- c:\windows\system32\x64
2011-07-04 22:45 . 2008-02-12 03:13 920088 ----a-w- c:\windows\system32\igxpun.exe
2011-07-03 18:51 . 2011-07-03 18:51 -------- d-----w- c:\users\Feutz\AppData\Local\Panda Security
2011-07-03 18:45 . 2010-06-23 01:13 26696 ----a-w- c:\windows\system32\drivers\pavboot.sys
2011-07-03 18:45 . 2007-03-16 02:38 54832 ----a-w- c:\windows\system32\pavcpl.cpl
2011-07-03 18:45 . 2003-10-23 01:23 446464 ----a-w- c:\windows\system32\HHActiveX.dll
2011-07-03 18:45 . 2010-06-22 00:02 193344 ----a-w- c:\windows\system32\TpUtil.dll
2011-07-03 18:45 . 2010-06-22 00:01 520000 ----a-w- c:\windows\system32\PavSHook.dll
2011-07-03 18:45 . 2010-06-22 00:01 87360 ----a-w- c:\windows\system32\PavLspHook.dll
2011-07-03 18:45 . 2010-06-22 00:01 55616 ----a-w- c:\windows\system32\pavipc.dll
2011-07-03 18:45 . 2007-02-08 17:53 107568 ----a-w- c:\windows\system32\SYSTOOLS.DLL
2011-07-03 18:44 . 2011-07-03 18:45 -------- d-----w- c:\program files\Panda Security
2011-07-03 18:44 . 2011-07-03 18:44 -------- d-----w- c:\windows\system32\PAV
2011-07-03 18:44 . 2011-07-03 18:44 -------- d-----w- c:\users\Feutz\AppData\Roaming\Panda Security
2011-07-03 18:44 . 2011-07-03 18:44 -------- d-----w- c:\programdata\Panda Security
2011-07-03 18:44 . 2010-09-01 18:09 201032 ----a-w- c:\windows\system32\drivers\neti1644.sys
2011-07-03 18:44 . 2010-05-21 20:50 54344 ----a-w- c:\windows\system32\drivers\amm8660.sys
2011-07-03 18:44 . 2010-03-24 19:55 55552 ----a-w- c:\windows\system32\avldr.dll
2011-07-01 20:05 . 2011-07-01 20:05 388096 ----a-r- c:\users\Feutz\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-07-01 01:28 . 2011-07-01 01:28 -------- d-----w- c:\users\Feutz\AppData\Roaming\SUPERAntiSpyware.com
2011-07-01 01:28 . 2011-07-01 01:28 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2011-07-01 01:28 . 2011-07-01 01:28 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-06-30 13:03 . 2011-06-30 13:03 -------- d-----w- C:\d6aaef27f533ca95ed452bdd47deb9
2011-06-30 04:59 . 2011-06-30 04:59 -------- d-----w- C:\60dd7279dace78af16
2011-06-29 14:05 . 2011-06-29 14:05 -------- d-----w- C:\6bd801315f181fe169cd3798
2011-06-29 13:14 . 2011-06-29 13:14 -------- d-----w- C:\058d8e97ce6d35b88fe00fef6563
2011-06-29 00:42 . 2011-06-29 00:43 -------- d-----w- C:\SMCLPAV
2011-06-28 12:54 . 2005-04-04 06:02 753664 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iKernel.dll
2011-06-28 12:54 . 2005-04-04 06:02 69714 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\ctor.dll
2011-06-28 12:54 . 2005-04-04 06:01 274432 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iscript.dll
2011-06-28 12:54 . 2005-04-04 06:00 184320 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iuser.dll
2011-06-28 12:54 . 2005-04-04 05:59 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\DotNetInstaller.exe
2011-06-28 12:54 . 2011-06-28 12:54 200836 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iGdi.dll
2011-06-28 12:54 . 2011-06-28 12:54 331908 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\setup.dll
2011-06-26 17:25 . 2011-07-05 05:12 -------- d-----w- c:\users\Feutz\AppData\Roaming\QuickScan
2011-06-26 17:22 . 2011-06-26 17:22 -------- d-----w- c:\users\Feutz\AppData\Local\Mozilla
2011-06-26 14:44 . 2011-06-26 14:44 -------- d-----w- C:\a8b79eb2bb60353fc6
2011-06-25 16:25 . 2011-06-25 16:32 -------- d-----w- c:\users\Feutz\AppData\Local\ElevatedDiagnostics
2011-06-20 17:40 . 2011-06-20 17:40 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-06-19 20:15 . 2011-06-19 20:15 -------- d-----w- c:\program files\BeerSmith2
2011-06-19 16:28 . 2011-06-19 16:28 -------- d-----w- C:\5cee7e0f1b01fbec51c15a1462
2011-06-19 14:16 . 2011-06-20 17:41 -------- d-----w- c:\program files\Common Files\Java
2011-06-19 14:16 . 2011-06-19 14:16 -------- d-----w- C:\4756e36812682c0f88ddac0bd9665fb6
2011-06-19 13:54 . 2011-06-19 13:54 -------- d-----w- C:\found.003
2011-06-19 01:08 . 2011-06-19 01:08 -------- d-----w- C:\found.002
2011-06-17 01:28 . 2011-06-17 01:28 -------- d-----w- C:\found.001
2011-06-17 00:52 . 2011-04-14 14:59 75264 ----a-w- c:\windows\system32\drivers\dfsc.sys
2011-06-17 00:52 . 2011-04-21 13:58 273408 ----a-w- c:\windows\system32\drivers\afd.sys
2011-06-17 00:52 . 2011-04-29 13:25 146432 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-06-17 00:52 . 2011-04-29 13:25 102400 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-06-17 00:37 . 2011-06-17 00:37 -------- d-----w- c:\users\Robin\AppData\Roaming\AVG10
2011-06-16 02:54 . 2011-06-16 02:59 -------- d-----w- c:\users\Feutz\AppData\Roaming\AVG
2011-06-16 02:08 . 2010-12-20 16:35 563712 ----a-w- c:\windows\system32\oleaut32.dll
2011-06-16 02:08 . 2011-05-02 17:16 739328 ----a-w- c:\windows\system32\inetcomm.dll
2011-06-16 02:08 . 2011-04-29 13:24 214016 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-06-16 02:08 . 2011-04-29 13:24 79872 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-06-16 02:08 . 2011-04-29 13:24 106496 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-06-16 02:08 . 2011-05-02 12:02 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-06-16 01:03 . 2011-06-16 01:03 -------- d-----w- C:\$AVG
2011-06-16 00:29 . 2011-06-16 00:29 -------- d--h--w- c:\programdata\Common Files
2011-06-16 00:27 . 2011-06-30 00:21 -------- d-----w- c:\programdata\AVG10
2011-06-16 00:16 . 2011-07-01 00:28 -------- d-----w- c:\program files\AVG
2011-06-16 00:11 . 2011-06-30 00:21 -------- d-----w- c:\programdata\MFAData
2011-06-15 17:59 . 2011-07-04 21:14 -------- d-----w- c:\programdata\Norton
2011-06-15 00:54 . 2011-06-15 00:54 -------- d-----w- c:\program files\Trend Micro
2011-06-13 22:38 . 2011-06-25 15:46 -------- d-----w- c:\programdata\Kaspersky Lab
2011-06-13 22:38 . 2011-06-15 00:39 -------- d-----w- c:\program files\Kaspersky Lab
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-02 12:52 . 2011-06-02 12:52 161792 ----a-w- c:\windows\system32\msls31.dll
2011-06-02 12:52 . 2011-06-02 12:52 1126912 ----a-w- c:\windows\system32\wininet.dll
2011-06-02 12:52 . 2011-06-02 12:52 86528 ----a-w- c:\windows\system32\iesysprep.dll
2011-06-02 12:52 . 2011-06-02 12:52 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-06-02 12:52 . 2011-06-02 12:52 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-06-02 12:52 . 2011-06-02 12:52 63488 ----a-w- c:\windows\system32\tdc.ocx
2011-06-02 12:52 . 2011-06-02 12:52 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-06-02 12:52 . 2011-06-02 12:52 367104 ----a-w- c:\windows\system32\html.iec
2011-06-02 12:52 . 2011-06-02 12:52 74752 ----a-w- c:\windows\system32\iesetup.dll
2011-06-02 12:52 . 2011-06-02 12:52 23552 ----a-w- c:\windows\system32\licmgr10.dll
2011-06-02 12:52 . 2011-06-02 12:52 152064 ----a-w- c:\windows\system32\wextract.exe
2011-06-02 12:52 . 2011-06-02 12:52 150528 ----a-w- c:\windows\system32\iexpress.exe
2011-06-02 12:52 . 2011-06-02 12:52 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
2011-06-02 12:52 . 2011-06-02 12:52 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-06-02 12:52 . 2011-06-02 12:52 35840 ----a-w- c:\windows\system32\imgutil.dll
2011-06-02 12:52 . 2011-06-02 12:52 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-06-02 12:52 . 2011-06-02 12:52 1797632 ----a-w- c:\windows\system32\jscript9.dll
2011-06-02 12:52 . 2011-06-02 12:52 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2011-06-02 12:52 . 2011-06-02 12:52 11776 ----a-w- c:\windows\system32\mshta.exe
2011-06-02 12:52 . 2011-06-02 12:52 101888 ----a-w- c:\windows\system32\admparse.dll
2011-06-02 12:52 . 2011-06-02 12:52 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-05-29 16:11 . 2011-03-30 00:03 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-25 02:14 . 2010-06-27 01:40 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-04-14 16:26 . 2011-06-26 17:22 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files\Vuze_Remote\prxtbVuze.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 23:54 175912 ----a-w- c:\program files\ConduitEngine\prxConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
2011-01-17 23:54 175912 ----a-w- c:\program files\Vuze_Remote\prxtbVuze.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{ba14329e-9550-4989-b3f2-9732e92d17cc}"= "c:\program files\Vuze_Remote\prxtbVuze.dll" [2011-01-17 175912]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\prxConduitEngine.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{ba14329e-9550-4989-b3f2-9732e92d17cc}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2008-07-04 430080]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-30 4911104]
"Camera Assistant Software"="c:\program files\Camera Assistant Software for Toshiba\traybar.exe" [2007-10-26 413696]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-08-14 1348904]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2008-01-17 431456]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-30 583048]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-12 49152]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2008-01-22 712704]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2007-11-01 54608]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2008-06-29 52168]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-01 421160]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"APVXDWIN"="c:\program files\Panda Security\Panda Antivirus Pro 2012\APVXDWIN.EXE" [2011-04-13 1000768]
"SCANINICIO"="c:\program files\Panda Security\Panda Antivirus Pro 2012\Inicio.exe" [2011-02-02 70464]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-12 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-12 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-12 133656]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2008-02-26 443968]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]
2010-03-24 19:55 55552 ----a-w- c:\windows\System32\avldr.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PskSvcRetail]
@="Service"
.
[HKLM\~\startupfolder\C:^Users^Feutz^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\users\Feutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-08-10 12:15 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skytel]
2007-11-21 01:15 1826816 ----a-w- c:\windows\SkyTel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2011-02-06 23:25 202256 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
2010-08-24 09:38 247144 ----a-w- c:\program files\TomTom HOME 2\TomTomHOMERunner.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Persistence"=c:\windows\system32\igfxpers.exe
"IgfxTray"=c:\windows\system32\igfxtray.exe
"SmoothView"=%ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R0 30587362;30587362 Boot Guard Driver;c:\windows\system32\DRIVERS\30587362.sys
R1 30587361;30587361;c:\windows\system32\DRIVERS\30587361.sys
R1 setup_9.0.0.722_17.06.2011_02-59drv;setup_9.0.0.722_17.06.2011_02-59drv;c:\windows\system32\DRIVERS\3058736.sys
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 IO_Memory;IO_Memory;c:\windows\SYSTEM32\SYSPREP\Drivers\ioport.sys
R3 SVRPEDRV;SVRPEDRV;c:\windows\System32\sysprep\UP_date\PEDrv.sys
R3 utkwnty5;AVZ Kernel Driver;c:\windows\system32\Drivers\utkwnty5.sys
S0 pavboot;Panda boot driver;c:\windows\system32\Drivers\pavboot.sys [2010-06-23 26696]
S1 APPFLT;App Filter Plugin;c:\windows\system32\Drivers\APPFLT.SYS [2011-01-31 83528]
S1 DSAFLT;DSA Filter Plugin;c:\windows\system32\Drivers\DSAFLT.SYS [2009-09-25 53256]
S1 FNETMON;NetMon Filter Plugin;c:\windows\system32\Drivers\fnetmon.SYS [2009-09-25 22024]
S1 IDSFLT;Ids Filter Plugin;c:\windows\system32\Drivers\IDSFLT.SYS [2010-09-09 193864]
S1 NETFLTDI;Panda Net Driver [TDI Layer];c:\windows\system32\Drivers\NETFLTDI.SYS [2009-09-25 21:54 159112]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
S2 AmFSM;AmFSM;c:\windows\system32\DRIVERS\amm8660.sys [2010-05-21 54344]
S2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [2007-12-25 40960]
S2 PskSvcRetail;Panda PSK service;c:\program files\Panda Security\Panda Antivirus Pro 2012\PskSvc.exe [2010-08-16 28992]
S2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [2010-08-24 92008]
S2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [2007-12-04 126976]
S3 AvFlt;Antivirus Filter Driver;c:\windows\system32\drivers\av5flt.sys
S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [2006-11-20 7168]
S3 NETIMFLT01060044;PANDA NDIS IM Filter Miniport v1.6.0.44;c:\windows\system32\DRIVERS\neti1644.sys [2010-09-01 201032]
S3 PavSRK.sys;PavSRK.sys;c:\windows\system32\PavSRK.sys
S3 PavTPK.sys;PavTPK.sys;c:\windows\system32\PavTPK.sys
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
uInternet Settings,ProxyOverride = *.local;<local>
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
Trusted Zone: internet
Trusted Zone: mcafee.com
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Feutz\AppData\Roaming\Mozilla\Firefox\Profiles\6ut3ou0q.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-AppleSyncNotifier - c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
AddRemove-BeerSmith - d:\\setup.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-07-10 09:36
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-4017210073-3623525190-2501994021-1000\Software\SecuROM\License information*]
"datasecu"=hex:c4,80,29,ed,05,d0,45,d9,29,7e,6a,37,9e,64,ce,c2,e9,37,98,c4,c1,
7a,60,54,48,c8,de,53,bb,04,84,f3,48,bf,48,d0,5c,7b,fb,b9,8f,53,3c,c9,29,d9,\
"rkeysecu"=hex:cb,bd,f2,61,5a,4e,c6,95,f2,29,8b,82,ba,6b,3d,44
.
[HKEY_LOCAL_MACHINE\system\ControlSet004\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Completion time: 2011-07-10 09:39:54
ComboFix-quarantined-files.txt 2011-07-10 16:39
.
Pre-Run: 64,629,080,064 bytes free
Post-Run: 64,618,516,480 bytes free
.
- - End Of File - - 9BA2BF4A39A7726341E7AE7D0F85015D
Hope this helps