Second half of Combofix log.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Note empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Sidebar”=“c:\program files\Windows Sidebar\sidebar.exe” [2009-04-11 1233920]
“ehTray.exe”=“c:\windows\ehome\ehTray.exe” [2008-01-21 125952]
“WMPNSCFG”=“c:\program files\Windows Media Player\WMPNSCFG.exe” [2008-01-21 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“Windows Defender”=“c:\program files\Windows Defender\MSASCui.exe” [2008-01-21 1008184]
“Apoint”=“c:\program files\DellTPad\Apoint.exe” [2008-09-04 200704]
“IgfxTray”=“c:\windows\system32\igfxtray.exe” [2008-12-09 150040]
“HotKeysCmds”=“c:\windows\system32\hkcmd.exe” [2008-12-09 178712]
“Persistence”=“c:\windows\system32\igfxpers.exe” [2008-12-09 154136]
“Broadcom Wireless Manager UI”=“c:\windows\system32\WLTRAY.exe” [2008-12-22 3810304]
“IAAnotif”=“c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe” [2008-05-07 178712]
“dellsupportcenter”=“c:\program files\Dell Support Center\bin\sprtcmd.exe” [2009-06-03 206064]
“avast!”=“c:\progra~1\ALWILS~1\Avast4\ashDisp.exe” [2009-11-24 81000]
“PDVDDXSrv”=“c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe” [2009-04-02 128232]
“SysTrayApp”=“c:\program files\IDT\WDM\sttray.exe” [2008-12-15 483420]
“Adobe Reader Speed Launcher”=“c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe” [2009-12-22 35760]
“Adobe ARM”=“c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe” [2009-12-11 948672]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup
Dell Remote Access.lnk - c:\windows\Installer{F66A31D9-7831-4FBA-BA02-C411C0047CC5}\NewShortcut4_F66A31D978314FBABA02C411C0047CC5.exe [2009-4-25 53248]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“EnableUIADesktopToggle”= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2009-04-25 13:07 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@=“Driver”
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@=“Service”
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
“VistaSp2”=hex(b):ba,5e,ca,3d,af,53,ca,01
R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [6/1/2009 7:48 AM 114768]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\AEstSrv.exe [4/25/2009 9:28 AM 81920]
R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [6/1/2009 7:48 AM 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [6/1/2009 7:48 AM 53328]
R2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [12/18/2008 12:05 PM 155648]
S2 SftService;SoftThinks Agent Service;“c:\windows\sminst\sftservice.EXE” → c:\windows\sminst\sftservice.EXE [?]
S2 yksvc;Marvell Yukon Service;RUNDLL32.EXE ykx32coinst,serviceStartProc → RUNDLL32.EXE ykx32coinst,serviceStartProc [?]
S3 PCD5SRVC{3F6A8B78-EC003E00-05040104};PCD5SRVC{3F6A8B78-EC003E00-05040104} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms [11/4/2008 5:16 PM 22904]
— Other Services/Drivers In Memory —
Deregistered - SASENUM
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the ‘Scheduled Tasks’ folder
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - (no file)
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-18 20:29
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PCD5SRVC{3F6A8B78-EC003E00-05040104}]
“ImagePath”=“??\c:\progra~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms”
.
Completion time: 2010-02-18 20:32:04
ComboFix-quarantined-files.txt 2010-02-19 02:32
Pre-Run: 90,708,385,792 bytes free
Post-Run: 90,655,232,000 bytes free
-
- End Of File - - 5641BDFAB7B84067BD1808AADF34DFCF