I completed tyhe combofix run and log file is as follows:
ComboFix 12-08-31.08 - Weston 09/01/2012 16:03:11.1.4 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3582.2799 [GMT -5:00]
Running from: i:\documents and settings\Weston\Desktop\ComboFix.exe
AV: Lavasoft Ad-Aware *Disabled/Updated* {964FCE60-0B18-4D30-ADD6-EB178909041C}
FW: Lavasoft Ad-Aware *Disabled* {FF1CD5B7-1553-4625-A258-1775385CED33}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
i:\documents and settings\All Users\Application Data\E75EF94CC3.sys
i:\documents and settings\All Users\Application Data\TEMP
i:\windows\system32\dllcache\dlimport.exe
i:\windows\system32\URTTemp
i:\windows\system32\URTTemp\fusion.dll
i:\windows\system32\URTTemp\mscoree.dll
i:\windows\system32\URTTemp\mscoree.dll.local
i:\windows\system32\URTTemp\mscorsn.dll
i:\windows\system32\URTTemp\mscorwks.dll
i:\windows\system32\URTTemp\msvcr71.dll
i:\windows\system32\URTTemp\regtlib.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-08-01 to 2012-09-01 )))))))))))))))))))))))))))))))
.
.
2012-08-31 15:24 . 2012-08-31 15:26 -------- d-----w- I:\rei
2012-08-31 15:24 . 2012-08-31 15:24 -------- d-----w- i:\program files\Reimage
2012-08-29 21:29 . 2012-08-29 21:29 -------- d-----w- i:\documents and settings\Mason\Local Settings\Application Data\adaware
2012-08-29 21:29 . 2012-08-29 21:29 -------- d-----w- i:\documents and settings\Mason\Application Data\Ad-Aware Antivirus
2012-08-29 20:48 . 2012-08-29 20:48 -------- d-----w- i:\documents and settings\Coleman\Local Settings\Application Data\adaware
2012-08-29 20:48 . 2012-08-29 20:48 -------- d-----w- i:\documents and settings\Coleman\Application Data\Ad-Aware Antivirus
2012-08-29 17:14 . 2012-08-29 17:14 73696 ----a-w- i:\program files\Mozilla Firefox\breakpadinjector.dll
2012-08-28 19:26 . 2012-08-28 19:26 -------- d-----w- i:\documents and settings\LocalService\Application Data\Ad-Aware Antivirus
2012-08-28 19:20 . 2012-08-28 20:18 -------- d-----w- i:\documents and settings\Weston\Local Settings\Application Data\adaware
2012-08-28 19:20 . 2011-11-29 11:59 77816 ----a-w- i:\windows\system32\drivers\sbapifs.sys
2012-08-28 19:20 . 2011-11-29 11:59 21240 ----a-w- i:\windows\system32\drivers\sbaphd.sys
2012-08-28 19:20 . 2012-08-28 19:20 -------- d-----w- i:\documents and settings\All Users\Application Data\Lavasoft
2012-08-28 19:20 . 2012-08-28 19:20 -------- d-----w- i:\windows\system32\drivers\VDD
2012-08-28 19:20 . 2012-08-28 19:27 -------- d-----w- i:\program files\Ad-Aware Antivirus
2012-08-28 19:19 . 2012-08-28 19:19 -------- d-----w- i:\documents and settings\Weston\Local Settings\Application Data\Downloaded Installations
2012-08-28 19:19 . 2012-09-01 14:04 -------- d-----w- i:\documents and settings\All Users\Application Data\Ad-Aware Browsing Protection
2012-08-28 19:18 . 2012-08-28 19:18 -------- d-----w- i:\program files\Toolbar Cleaner
2012-08-28 19:18 . 2012-08-28 19:18 -------- d-----w- i:\documents and settings\Weston\Application Data\adawaretb
2012-08-28 19:18 . 2012-08-28 19:18 -------- d-----w- i:\program files\adawaretb
2012-08-28 19:17 . 2012-08-28 21:13 -------- d-----w- i:\documents and settings\Weston\Application Data\Ad-Aware Antivirus
2012-08-28 19:07 . 2012-08-28 19:08 -------- d-----w- i:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2012-08-28 19:07 . 2012-08-28 19:07 -------- d-----w- i:\program files\Spybot - Search & Destroy
2012-08-27 02:35 . 2012-08-27 02:44 -------- d-----w- i:\documents and settings\All Users\Application Data\SecTaskMan
2012-08-27 02:34 . 2012-08-27 02:34 -------- d-----w- i:\program files\Security Task Manager
2012-08-21 18:46 . 2012-08-21 18:46 -------- d-----w- i:\documents and settings\Weston\Application Data\SUPERAntiSpyware.com
2012-08-21 18:46 . 2012-08-21 18:46 -------- d-----w- i:\program files\SUPERAntiSpyware
2012-08-21 18:46 . 2012-08-21 18:46 -------- d-----w- i:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2012-08-21 18:29 . 2012-08-21 18:29 -------- d-----w- i:\documents and settings\Weston\Application Data\Malwarebytes
2012-08-21 18:29 . 2012-08-21 18:29 -------- d-----w- i:\documents and settings\All Users\Application Data\Malwarebytes
2012-08-21 18:29 . 2012-08-21 18:29 -------- d-----w- i:\program files\Malwarebytes' Anti-Malware
2012-08-21 18:29 . 2012-07-03 18:46 22344 ----a-w- i:\windows\system32\drivers\mbam.sys
2012-08-19 22:17 . 2012-08-19 22:17 -------- d-----w- i:\documents and settings\Anna\.thumbnails
2012-08-19 19:49 . 2012-08-19 19:49 -------- d-----w- i:\documents and settings\Weston\Application Data\com.adobe.downloadassistant.AdobeDownloadAssistant
2012-08-19 19:49 . 2012-08-19 19:49 -------- d-----w- i:\program files\Adobe Download Assistant
2012-08-19 18:22 . 2012-08-19 18:22 -------- d-----w- i:\documents and settings\Weston\Local Settings\Application Data\IsolatedStorage
2012-08-18 17:57 . 2012-08-19 13:52 -------- d-----w- i:\program files\Kyodai Mahjongg 2006
2012-08-18 17:27 . 2012-08-18 17:27 -------- d-----w- i:\documents and settings\All Users\Application Data\NVIDIA
2012-08-18 17:27 . 2012-08-18 17:27 -------- d-----w- i:\documents and settings\UpdatusUser
2012-08-18 17:26 . 2012-03-22 06:09 27968 ----a-r- i:\windows\system32\nvhdap32.dll
2012-08-18 17:26 . 2012-03-22 06:09 123584 ----a-r- i:\windows\system32\drivers\nvhda32.sys
2012-08-18 17:26 . 2012-03-22 06:09 876864 ----a-r- i:\windows\system32\nvhdagenco3220103.dll
2012-08-16 18:27 . 2012-08-16 18:27 -------- d-sh--w- i:\documents and settings\Weston\UserData
2012-08-07 13:32 . 2012-08-07 13:32 -------- d-----w- i:\windows\_ISTMP5.DIR
2012-08-07 13:32 . 2012-08-07 13:32 -------- d-----w- i:\windows\_ISTMP6.DIR
2012-08-06 23:38 . 2012-08-06 23:38 -------- d-----w- i:\documents and settings\Weston\Application Data\Ipswitch
2012-08-06 23:38 . 2012-08-06 23:38 -------- d-----w- i:\program files\Ipswitch
2012-08-06 23:38 . 2012-08-06 23:38 -------- d-----w- i:\documents and settings\All Users\Application Data\Ipswitch
2012-08-06 22:04 . 2012-08-06 22:04 -------- d-----w- i:\program files\Filezilla
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-15 13:02 . 2012-05-29 16:08 70344 ----a-w- i:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-15 13:02 . 2012-05-29 16:08 426184 ----a-w- i:\windows\system32\FlashPlayerApp.exe
2012-07-06 13:58 . 2006-02-28 12:00 78336 ----a-w- i:\windows\system32\browser.dll
2012-07-04 14:05 . 2012-05-27 21:46 139784 ----a-w- i:\windows\system32\drivers\rdpwd.sys
2012-07-03 13:40 . 2006-02-28 12:00 1866112 ----a-w- i:\windows\system32\win32k.sys
2012-07-02 17:49 . 2006-02-28 12:00 916992 ----a-w- i:\windows\system32\wininet.dll
2012-07-02 17:49 . 2006-02-28 12:00 43520 ------w- i:\windows\system32\licmgr10.dll
2012-07-02 17:49 . 2006-02-28 12:00 1469440 ------w- i:\windows\system32\inetcpl.cpl
2012-07-02 12:05 . 2006-02-28 12:00 385024 ------w- i:\windows\system32\html.iec
2012-06-07 01:59 . 2012-06-07 01:59 1070152 ----a-w- i:\windows\system32\MSCOMCTL.OCX
2012-06-05 15:50 . 2012-05-27 23:32 1372672 ------w- i:\windows\system32\msxml6.dll
2012-06-05 15:50 . 2006-02-28 12:00 1172480 ----a-w- i:\windows\system32\msxml3.dll
2012-06-04 21:50 . 2012-06-04 21:27 3766 --sha-w- i:\documents and settings\All Users\Application Data\KGyGaAvL.sys
2012-06-04 04:32 . 2006-02-28 12:00 152576 ----a-w- i:\windows\system32\schannel.dll
2012-08-29 17:14 . 2012-05-28 23:32 266720 ----a-w- i:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6c97a91e-4524-4019-86af-2aa2d567bf5c}]
2012-04-11 20:08 87440 ----a-w- i:\program files\adawaretb\adawareDx.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Green]
@="{95A27763-F62A-4114-9072-E81D87DE3B68}"
[HKEY_CLASSES_ROOT\CLSID\{95A27763-F62A-4114-9072-E81D87DE3B68}]
2012-05-09 04:39 1011344 ----a-r- i:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"
[HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}]
2012-05-09 04:39 1011344 ----a-r- i:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Yellow]
@="{5E529433-B50E-4bef-A63B-16A6B71B071A}"
[HKEY_CLASSES_ROOT\CLSID\{5E529433-B50E-4bef-A63B-16A6B71B071A}]
2012-05-09 04:39 1011344 ----a-r- i:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="i:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2012-07-09 4777856]
"SpybotSD TeaTimer"="i:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Ad-Aware Antivirus"="i:\program files\Ad-Aware Antivirus\AdAwareLauncher --windows-run" [X]
"SysTrayApp"="i:\program files\IDT\WDM\sttray.exe" [2008-04-11 413696]
"Carbonite Backup"="i:\program files\Carbonite\Carbonite Backup\CarboniteUI.exe" [2012-05-09 1061520]
"SBAutoUpdate"="i:\program files\SpywareBlaster\sbautoupdate.exe" [2012-02-06 939184]
"Garmin Lifetime Updater"="i:\program files\Garmin\Lifetime Updater\GarminLifetime.exe" [2012-06-04 1466760]
"APSDaemon"="i:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"AdobeAAMUpdater-1.0"="i:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-04-04 446392]
"AdobeCS6ServiceManager"="i:\program files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2012-03-09 1073312]
"NvMediaCenter"="NvMCTray.dll" [2012-04-26 108352]
"NvCplDaemon"="i:\windows\system32\NvCpl.dll" [2012-04-26 15496000]
"Malwarebytes' Anti-Malware"="i:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
"Ad-Aware Browsing Protection"="i:\documents and settings\All Users\Application Data\Ad-Aware Browsing Protection\adawarebp.exe" [2011-10-21 198032]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "i:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 ----a-w- i:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ad-Aware Service]
@="Ad-Aware Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"i:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"i:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"i:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"i:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"i:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"i:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"i:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"i:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"i:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"i:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"i:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"i:\\Documents and Settings\\Weston\\Local Settings\\Application Data\\Akamai\\netsession_win.exe"=
"i:\\Program Files\\Ipswitch\\WS_FTP 12\\wsftpgui.exe"=
"i:\\Program Files\\NVIDIA Corporation\\NVIDIA Update Core\\daemonu.exe"=
"i:\\Program Files\\Kyodai Mahjongg 2006\\kmj.exe"=
"i:\\Program Files\\adawaretb\\dtUser.exe"=
.
R1 SASDIFSV;SASDIFSV;i:\program files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011 11:27 AM 12880]
R1 SASKUTIL;SASKUTIL;i:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 4:55 PM 67664]
R1 sbaphd;sbaphd;i:\windows\system32\drivers\sbaphd.sys [8/28/2012 2:20 PM 21240]
R2 !SASCORE;SAS Core Service;i:\program files\SUPERAntiSpyware\SASCore.exe [8/11/2011 6:38 PM 116608]
R2 Ad-Aware Service;Ad-Aware Service;i:\program files\Ad-Aware Antivirus\AdAwareService.exe [7/12/2012 6:32 PM 1239952]
R2 AdobeActiveFileMonitor10.0;Adobe Active File Monitor V10;i:\program files\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe [9/14/2011 10:06 PM 169624]
R2 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service;i:\windows\system32\IPROSetMonitor.exe [3/12/2012 10:57 AM 133280]
R2 MBAMService;MBAMService;i:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [8/21/2012 1:29 PM 655944]
R2 nvUpdatusService;NVIDIA Update Service Daemon;i:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [8/18/2012 12:27 PM 2458944]
R2 PCPitstop Scheduling;PCPitstop Scheduling;i:\program files\PCPitstop\PCPitstopScheduleService.exe [5/30/2012 9:23 AM 86016]
R2 sbapifs;sbapifs;i:\windows\system32\drivers\sbapifs.sys [8/28/2012 2:20 PM 77816]
R3 MBAMProtector;MBAMProtector;i:\windows\system32\drivers\mbam.sys [8/21/2012 1:29 PM 22344]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;i:\windows\system32\drivers\nvhda32.sys [8/18/2012 12:26 PM 123584]
S1 SBRE;SBRE;i:\windows\system32\drivers\SBREDrv.sys [10/26/2011 2:23 PM 101112]
S2 gupdate;Google Update Service (gupdate);i:\program files\Google\Update\GoogleUpdate.exe [6/27/2012 5:02 PM 136176]
S2 SBAMSvc;Ad-Aware;i:\program files\Ad-Aware Antivirus\SBAMSvc.exe [12/19/2011 1:20 PM 3289032]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;i:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [5/29/2012 11:08 AM 250056]
S3 cpuz134;cpuz134;\??\i:\docume~1\Weston\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys --> i:\docume~1\Weston\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys [?]
S3 gupdatem;Google Update Service (gupdatem);i:\program files\Google\Update\GoogleUpdate.exe [6/27/2012 5:02 PM 136176]
S3 MozillaMaintenance;Mozilla Maintenance Service;i:\program files\Mozilla Maintenance Service\maintenanceservice.exe [5/28/2012 6:32 PM 114144]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
.
2012-08-28 i:\windows\Tasks\Ad-Aware Antivirus Scheduled Scan.job
- i:\progra~1\AD-AWA~1\AdAwareLauncher.exe [2012-07-12 23:32]
.
2012-09-01 i:\windows\Tasks\Adobe Flash Player Updater.job
- i:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-29 13:02]
.
2012-09-01 i:\windows\Tasks\AdobeAAMUpdater-1.0-WMAYNARD-Anna.job
- i:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2012-07-15 11:09]
.
2012-09-01 i:\windows\Tasks\AdobeAAMUpdater-1.0-WMAYNARD-Weston.job
- i:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2012-07-15 11:09]
.
2012-08-26 i:\windows\Tasks\AppleSoftwareUpdate.job
- i:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 22:57]
.
2012-09-01 i:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- i:\program files\Google\Update\GoogleUpdate.exe [2012-06-27 22:02]
.
2012-09-01 i:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- i:\program files\Google\Update\GoogleUpdate.exe [2012-06-27 22:02]
.
2012-08-31 i:\windows\Tasks\ParetoLogic Registration3.job
- i:\program files\Common Files\ParetoLogic\UUS3\UUS3.dll [2012-06-27 21:06]
.
2012-09-01 i:\windows\Tasks\ParetoLogic Update Version3 Startup Task.job
- i:\program files\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe [2012-06-27 21:06]
.
2012-08-27 i:\windows\Tasks\ParetoLogic Update Version3.job
- i:\program files\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe [2012-06-27 21:06]
.
2012-09-01 i:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-2052111302-1563985344-839522115-1004.job
- i:\program files\Real\RealUpgrade\realupgrade.exe [2012-06-21 17:00]
.
2012-09-01 i:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-2052111302-1563985344-839522115-1007.job
- i:\program files\Real\RealUpgrade\realupgrade.exe [2012-06-21 17:00]
.
2012-09-01 i:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-2052111302-1563985344-839522115-1004.job
- i:\program files\Real\RealUpgrade\realupgrade.exe [2012-06-21 17:00]
.
2012-08-30 i:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-2052111302-1563985344-839522115-1007.job
- i:\program files\Real\RealUpgrade\realupgrade.exe [2012-06-21 17:00]
.
2012-08-29 i:\windows\Tasks\RegCure Pro.job
- i:\program files\ParetoLogic\RegCure Pro\RegCurePro.exe [2011-12-21 22:07]
.
2012-08-31 i:\windows\Tasks\Reimage Reminder.job
- i:\program files\Reimage\Reimage Repair\ReimageReminder.exe [2012-08-02 12:30]
.
2012-09-01 i:\windows\Tasks\User_Feed_Synchronization-{712E1E74-77AA-4035-8CC1-528433DE115F}.job
- i:\windows\system32\msfeedssync.exe [2009-03-08 09:31]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://xfinity.comcast.net/uInternet Settings,ProxyOverride = <local>
IE: E&xport to Microsoft Excel - i:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - i:\documents and settings\Weston\Application Data\Mozilla\Firefox\Profiles\8qvw9xu9.default\
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2012-09-01 17:07
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2052111302-1563985344-839522115-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(740)
i:\program files\SUPERAntiSpyware\SASWINLO.DLL
i:\windows\system32\WININET.dll
.
Completion time: 2012-09-01 17:11:06
ComboFix-quarantined-files.txt 2012-09-01 22:11
.
Pre-Run: 929,363,927,040 bytes free
Post-Run: 930,821,726,208 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 7AA0A7146CAF60B25C2FC256169C5DA0