combofix did run fully, unfortunately, I closed the logfile without saving. Here is a created text file, combofix.txt. Hope it helps.
OTL would not run fully but did create this file.
I responded to your question in my last post. Still multiple BSOD's, Java problems not much in virus detection but the system seems more unstable.
Combofix found and deleted catchme.dll in two places.
OTL logfile created on: 8/28/2009 12:31:32 PM - Run 3
OTL by OldTimer - Version 3.0.10.7 Folder = C:\Documents and Settings\Bill & Kathy\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1022.07 Mb Total Physical Memory | 568.86 Mb Available Physical Memory | 55.66% Memory free
2.40 Gb Paging File | 2.10 Gb Available in Paging File | 87.22% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.79 Gb Total Space | 54.23 Gb Free Space | 77.70% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: OAKLEY
Current User Name: Bill & Kathy
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2006/06/07 17:03:20 | 00,409,600 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\System32\Ati2evxx.exe
PRC - [2005/03/22 17:20:44 | 00,339,968 | —- | M] (SigmaTel, Inc.) – C:\WINDOWS\stsystra.exe
PRC - [2005/06/10 10:44:02 | 00,081,920 | —- | M] (InstallShield Software Corporation) – C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
PRC - [2007/06/28 19:02:08 | 00,198,184 | —- | M] (SupportSoft, Inc.) – C:\Program Files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe
PRC - [2005/09/29 14:01:14 | 00,067,584 | —- | M] (Microsoft Corporation) – C:\WINDOWS\ehome\ehtray.exe
PRC - [2006/05/03 03:12:00 | 00,098,304 | —- | M] () – C:\Program Files\Dell\Media Experience\DMXLauncher.exe
PRC - [2005/09/08 05:20:00 | 00,122,940 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\DLA\DLACTRLW.EXE
PRC - [2006/01/02 17:41:22 | 00,045,056 | —- | M] (ATI Technologies Inc.) – C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
PRC - [2009/05/14 15:47:08 | 02,029,640 | —- | M] (ESET) – C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
PRC - [2003/10/29 02:06:00 | 00,024,576 | R— | M] (BVRP Software) – C:\Program Files\Digital Line Detect\DLG.exe
PRC - [2006/10/09 16:16:56 | 00,237,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\eHome\ehRecvr.exe
PRC - [2005/08/05 13:56:32 | 00,102,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\eHome\ehSched.exe
PRC - [2009/05/14 15:47:54 | 00,731,840 | —- | M] (ESET) – C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
PRC - [2001/08/09 02:01:00 | 00,090,112 | —- | M] (SEIKO EPSON CORPORATION) – C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
PRC - [2009/01/26 18:13:52 | 00,303,104 | —- | M] (Motive Communications, Inc.) – C:\Program Files\Common Files\Motive\McciCMService.exe
PRC - [2005/08/05 13:27:08 | 00,099,328 | —- | M] (Microsoft Corporation) – C:\WINDOWS\ehome\mcrdsvc.exe
PRC - [2008/04/13 20:12:41 | 00,013,824 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\wscntfy.exe
PRC - [2005/08/05 13:56:28 | 00,046,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\eHome\ehmsas.exe
PRC - [2006/01/02 17:41:22 | 00,045,056 | —- | M] (ATI Technologies Inc.) – C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
PRC - [2008/04/13 20:12:19 | 01,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2009/08/24 17:42:02 | 00,514,048 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Bill & Kathy\Desktop\OTL.exe
========== Win32 Services (SafeList) ==========
SRV - [2008/07/25 11:16:40 | 00,034,312 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe – (aspnet_state [On_Demand | Stopped])
SRV - [2006/06/07 17:03:20 | 00,409,600 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\System32\Ati2evxx.exe – (Ati HotKey Poller [Auto | Running])
SRV - [2006/07/28 17:47:00 | 00,520,192 | —- | M] () – C:\WINDOWS\System32\ati2sgag.exe – (ATI Smart [Auto | Stopped])
SRV - [2008/07/25 11:17:02 | 00,069,632 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2007/03/07 15:47:46 | 00,076,848 | —- | M] () – C:\Program Files\DellSupport\brkrsvc.exe – (DSBrokerService [On_Demand | Stopped])
SRV - [2006/10/09 16:16:56 | 00,237,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\eHome\ehRecvr.exe – (ehRecvr [Auto | Running])
SRV - [2005/08/05 13:56:32 | 00,102,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\eHome\ehSched.exe – (ehSched [Auto | Running])
SRV - [2009/05/14 15:54:22 | 00,020,680 | —- | M] (ESET) – C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe – (EhttpSrv [On_Demand | Stopped])
SRV - [2009/05/14 15:47:54 | 00,731,840 | —- | M] (ESET) – C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe – (ekrn [Auto | Running])
SRV - [2001/08/09 02:01:00 | 00,090,112 | —- | M] (SEIKO EPSON CORPORATION) – C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe – (EPSONStatusAgent2 [Auto | Running])
SRV - [2008/07/29 21:10:04 | 00,046,104 | —- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe – (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2009/04/02 19:22:10 | 00,133,104 | —- | M] (Google Inc.) – C:\Program Files\Google\Update\GoogleUpdate.exe – (gupdate1c9b3e9dfcb5276 [Auto | Stopped])
SRV - [2009/04/02 19:20:46 | 00,183,280 | —- | M] (Google) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe – (gusvc [Auto | Stopped])
SRV - [2008/04/13 20:12:02 | 00,038,400 | —- | M] (Microsoft Corporation) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll – (helpsvc [Auto | Running])
SRV - [2008/07/29 19:24:50 | 00,881,664 | —- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe – (idsvc [Unknown | Stopped])
SRV - [2009/08/15 00:03:21 | 00,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe – (JavaQuickStarterService [Auto | Stopped])
SRV - [2009/07/04 14:03:33 | 01,029,456 | —- | M] (Lavasoft) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe – (Lavasoft Ad-Aware Service [Auto | Stopped])
SRV - [2009/01/26 18:13:52 | 00,303,104 | —- | M] (Motive Communications, Inc.) – C:\Program Files\Common Files\Motive\McciCMService.exe – (McciCMService [Auto | Running])
SRV - [2005/08/05 13:27:08 | 00,099,328 | —- | M] (Microsoft Corporation) – C:\WINDOWS\ehome\mcrdsvc.exe – (McrdSvc [Auto | Running])
SRV - [2003/06/20 03:25:00 | 00,322,120 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe – (MDM [Auto | Stopped])
SRV - [2004/08/10 04:11:50 | 00,085,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mhn.dll – (MHN [On_Demand | Stopped])
SRV - [2004/11/19 11:26:40 | 00,147,456 | —- | M] (Intel® Corporation) – C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe – (NetSvc [On_Demand | Stopped])
SRV - [2008/07/29 19:16:38 | 00,132,096 | —- | M] (Microsoft Corporation) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe – (NetTcpPortSharing [Disabled | Stopped])
SRV - [2006/10/18 20:05:24 | 00,913,408 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\WMPNetwk.exe – (WMPNetworkSvc [Auto | Stopped])
========== Driver Services (SafeList) ==========
DRV - [2001/08/17 13:51:56 | 00,005,248 | —- | M] (Acer Laboratories Inc.) – C:\WINDOWS\system32\DRIVERS\aliide.sys – (AliIde [Disabled | Stopped])
DRV - [2008/04/13 14:36:39 | 00,043,008 | —- | M] (Advanced Micro Devices, Inc.) – C:\WINDOWS\system32\DRIVERS\amdagp.sys – (amdagp [Disabled | Stopped])
DRV - [2001/08/17 13:52:00 | 00,026,496 | —- | M] (Advanced System Products, Inc.) – C:\WINDOWS\system32\DRIVERS\asc.sys – (asc [Disabled | Stopped])
DRV - [2001/08/17 13:51:58 | 00,014,848 | —- | M] (Advanced System Products, Inc.) – C:\WINDOWS\system32\DRIVERS\asc3550.sys – (asc3550 [Disabled | Stopped])
DRV - [2006/08/17 23:57:14 | 00,008,552 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\System32\drivers\asctrm.sys – (ASCTRM [Auto | Running])
DRV - [2006/06/07 17:08:58 | 01,580,544 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\System32\DRIVERS\ati2mtag.sys – (ati2mtag [On_Demand | Running])
DRV - File not found – – (catchme [On_Demand | Running])
DRV - [2001/08/17 13:51:54 | 00,006,656 | —- | M] (CMD Technology, Inc.) – C:\WINDOWS\system32\DRIVERS\cmdide.sys – (CmdIde [Disabled | Stopped])
DRV - [2001/08/17 13:52:16 | 00,179,584 | —- | M] (Mylex Corporation) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys – (dac2w2k [Disabled | Stopped])
DRV - [2005/09/08 05:20:00 | 00,025,628 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\DLA\DLABOIOM.SYS – (DLABOIOM [Auto | Running])
DRV - [2005/08/25 12:16:52 | 00,005,628 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\Drivers\DLACDBHM.SYS – (DLACDBHM [System | Running])
DRV - [2005/09/08 05:20:00 | 00,002,496 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\DLA\DLADResN.SYS – (DLADResN [Auto | Running])
DRV - [2005/09/08 05:20:00 | 00,086,524 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\DLA\DLAIFS_M.SYS – (DLAIFS_M [Auto | Running])
DRV - [2005/09/08 05:20:00 | 00,014,684 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\DLA\DLAOPIOM.SYS – (DLAOPIOM [Auto | Running])
DRV - [2005/09/08 05:20:00 | 00,006,364 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\DLA\DLAPoolM.SYS – (DLAPoolM [Auto | Running])
DRV - [2005/08/25 12:16:16 | 00,022,684 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\Drivers\DLARTL_N.SYS – (DLARTL_N [System | Running])
DRV - [2005/09/08 05:20:00 | 00,094,332 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\DLA\DLAUDFAM.SYS – (DLAUDFAM [Auto | Running])
DRV - [2005/09/08 05:20:00 | 00,087,036 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\DLA\DLAUDF_M.SYS – (DLAUDF_M [Auto | Running])
DRV - [2005/09/12 03:30:00 | 00,089,264 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\Drivers\DRVMCDB.SYS – (DRVMCDB [Boot | Running])
DRV - [2005/08/12 05:20:00 | 00,040,544 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\Drivers\DRVNDDM.SYS – (DRVNDDM [Auto | Running])
DRV - [2006/10/05 16:07:28 | 00,004,736 | —- | M] (Gteko Ltd.) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys – (DSproct [On_Demand | Stopped])
DRV - [2007/02/25 12:10:48 | 00,005,376 | –S- | M] (Gteko Ltd.) – C:\WINDOWS\System32\DRIVERS\dsunidrv.sys – (dsunidrv [Auto | Running])
DRV - [2006/10/31 14:15:16 | 00,165,752 | —- | M] (Intel Corporation) – C:\WINDOWS\System32\DRIVERS\e100b325.sys – (E100B [On_Demand | Running])
DRV - [2009/05/14 15:41:10 | 00,114,472 | —- | M] (ESET) – C:\WINDOWS\System32\DRIVERS\eamon.sys – (eamon [Auto | Running])
DRV - [2009/05/14 15:47:14 | 00,107,256 | —- | M] (ESET) – C:\WINDOWS\System32\DRIVERS\ehdrv.sys – (ehdrv [System | Running])
DRV - [2009/05/14 15:49:32 | 00,094,360 | —- | M] (ESET) – C:\WINDOWS\System32\DRIVERS\epfwtdir.sys – (epfwtdir [System | Running])
DRV - [2008/04/13 12:36:05 | 00,144,384 | —- | M] (Windows ® Server 2003 DDK provider) – C:\WINDOWS\System32\DRIVERS\HDAudBus.sys – (HDAudBus [On_Demand | Running])
DRV - [2003/11/17 21:59:20 | 00,212,224 | —- | M] (Conexant Systems, Inc.) – C:\WINDOWS\System32\DRIVERS\HSFHWBS2.sys – (HSFHWBS2 [On_Demand | Running])
DRV - [2003/11/17 21:56:26 | 01,042,432 | —- | M] (Conexant Systems, Inc.) – C:\WINDOWS\System32\DRIVERS\HSF_DP.sys – (HSF_DP [On_Demand | Running])
DRV - [2009/08/13 20:04:41 | 00,045,344 | —- | M] () – C:\WINDOWS\System32\drivers\krjbecd.sys – (krjbecd [Boot | Stopped])
DRV - [2009/04/25 14:02:27 | 00,064,160 | —- | M] (Lavasoft AB) – C:\WINDOWS\system32\DRIVERS\Lbd.sys – (Lbd [Boot | Running])
DRV - [2003/04/09 18:48:08 | 00,011,043 | —- | M] (Conexant) – C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys – (mdmxsdk [Auto | Running])
DRV - [2001/08/17 13:57:38 | 00,016,128 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\MODEMCSA.sys – (MODEMCSA [On_Demand | Running])
DRV - [2001/08/17 13:52:12 | 00,017,280 | —- | M] (American Megatrends Inc.) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys – (mraid35x [Disabled | Stopped])
DRV - [2009/01/26 18:13:41 | 00,021,248 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) – C:\Program Files\Common Files\Motive\MREMP50.sys – (MREMP50 [On_Demand | Stopped])
DRV - [2009/01/26 18:13:39 | 00,020,096 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) – C:\Program Files\Common Files\Motive\MRESP50.sys – (MRESP50 [On_Demand | Stopped])
DRV - [2004/08/03 22:29:56 | 01,897,408 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\System32\DRIVERS\nv4_mini.sys – (nv [On_Demand | Stopped])
DRV - [2004/04/08 04:46:50 | 00,054,272 | —- | M] (Protection Technology) – C:\WINDOWS\System32\drivers\prodrv06.sys – (prodrv06 [System | Running])
DRV - [2004/04/08 06:06:08 | 00,070,400 | —- | M] (Protection Technology) – C:\WINDOWS\System32\drivers\prohlp02.sys – (prohlp02 [Boot | Running])
DRV - [2003/09/06 08:22:08 | 00,006,944 | —- | M] (Protection Technology) – C:\WINDOWS\System32\drivers\prosync1.sys – (prosync1 [Boot | Running])
DRV - [2004/08/10 05:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.) – C:\WINDOWS\System32\DRIVERS\ptilink.sys – (Ptilink [On_Demand | Running])
DRV - [2005/04/25 02:03:00 | 00,020,640 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\Drivers\PxHelp20.sys – (PxHelp20 [Boot | Running])
DRV - [2001/08/17 13:52:20 | 00,040,320 | —- | M] (QLogic Corporation) – C:\WINDOWS\system32\DRIVERS\ql1080.sys – (ql1080 [Disabled | Stopped])
DRV - [2001/08/17 13:52:20 | 00,045,312 | —- | M] (QLogic Corporation) – C:\WINDOWS\system32\DRIVERS\ql12160.sys – (ql12160 [Disabled | Stopped])
DRV - [2001/08/17 13:52:18 | 00,049,024 | —- | M] (QLogic Corporation) – C:\WINDOWS\system32\DRIVERS\ql1280.sys – (ql1280 [Disabled | Stopped])
DRV - [2007/11/13 06:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\WINDOWS\System32\DRIVERS\secdrv.sys – (Secdrv [On_Demand | Stopped])
DRV - [2003/12/01 11:20:52 | 00,004,832 | —- | M] (Protection Technology) – C:\WINDOWS\System32\drivers\sfhlp01.sys – (sfhlp01 [Boot | Running])
DRV - [2008/04/13 14:36:39 | 00,040,960 | —- | M] (Silicon Integrated Systems Corporation) – C:\WINDOWS\system32\DRIVERS\sisagp.sys – (sisagp [Disabled | Stopped])
DRV - [2001/08/17 14:56:16 | 00,007,552 | —- | M] (Sony Corporation) – C:\WINDOWS\System32\DRIVERS\SONYPVU1.SYS – (SONYPVU1 [On_Demand | Stopped])
DRV - [2001/08/17 14:07:44 | 00,019,072 | —- | M] (Adaptec, Inc.) – C:\WINDOWS\system32\DRIVERS\sparrow.sys – (Sparrow [Disabled | Stopped])
DRV - [2005/11/16 15:36:00 | 01,047,816 | —- | M] (SigmaTel, Inc.) – C:\WINDOWS\System32\drivers\sthda.sys – (STHDA [On_Demand | Running])
DRV - [2001/08/17 14:07:34 | 00,016,256 | —- | M] (Symbios Logic Inc.) – C:\WINDOWS\system32\DRIVERS\symc810.sys – (symc810 [Disabled | Stopped])
DRV - [2001/08/17 14:07:36 | 00,032,640 | —- | M] (LSI Logic) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys – (symc8xx [Disabled | Stopped])
DRV - [2001/08/17 14:07:40 | 00,028,384 | —- | M] (LSI Logic) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys – (sym_hi [Disabled | Stopped])
DRV - [2001/08/17 14:07:42 | 00,030,688 | —- | M] (LSI Logic) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys – (sym_u3 [Disabled | Stopped])
DRV - [2008/04/21 20:25:44 | 00,023,600 | —- | M] (EnTech Taiwan) – C:\WINDOWS\System32\DRIVERS\TVICHW32.SYS – (TVICHW32 [On_Demand | Stopped])
DRV - [2001/08/17 13:52:22 | 00,036,736 | —- | M] (Promise Technology, Inc.) – C:\WINDOWS\system32\DRIVERS\ultra.sys – (ultra [Disabled | Stopped])
DRV - [2003/11/17 21:58:02 | 00,680,704 | —- | M] (Conexant Systems, Inc.) – C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys – (winachsf [On_Demand | Running])
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://hometab.bellsouth.net/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/08/07 03:01:09 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/08/15 00:03:21 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird
O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe ()
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKLM..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe (Microsoft Corporation)
O4 - HKLM..\Run: [HelpCenter4.1] C:\Program Files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [ISUSPM Startup] C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe (McAfee, Inc.)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\System32\spool\drivers\w32x86\3\E_SRCV02.EXE (SEIKO EPSON CORPORATION)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Bill & Kathy\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe ()
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe ()
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: musicmatch.com ([online] https in Trusted sites)
O15 - HKLM\..Trusted Domains: 2 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED}
http://help.bellsouth.net/sdccommon/download/tgctlcm.cab (Reg Error: Key error.)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089}
http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab (Trend Micro ActiveX Scan Agent 6.6)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc3.cab (Office Update Installation Engine)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0}
http://photos.walmart.com/WalmartActivia.cab (Snapfish Activia)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.microsoft.com/microsoftupdat…b?1157589360759 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A}
http://webaccess.goodwillsavannahga.org/msrdp.cab (Microsoft RDP Client Control (redist))
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}
http://java.sun.com/update/1.4.2/jinstall-…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941}
http://plugin.driveragent.com/files/driveragent.cab (Driver Agent ActiveX Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 192.168.1.254
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 04:43:04 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
========== Files/Folders - Created Within 30 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[2009/08/28 12:27:30 | 00,000,000 | —D | C] – C:\WINDOWS\temp
[2009/08/28 12:26:31 | 00,019,968 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\linkinfo.dll
[2009/08/28 12:20:20 | 00,229,376 | —- | C] () – C:\WINDOWS\PEV.exe
[2009/08/28 12:20:20 | 00,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2009/08/28 12:20:20 | 00,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2009/08/28 12:20:20 | 00,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2009/08/28 12:20:20 | 00,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2009/08/28 12:20:20 | 00,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2009/08/28 12:20:20 | 00,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2009/08/28 12:20:20 | 00,031,232 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2009/08/28 12:20:13 | 00,000,000 | –SD | C] – C:\ComboFix
[2009/08/28 12:20:09 | 00,000,000 | —D | C] – C:\Qoobox
[2009/08/28 12:19:26 | 03,187,017 | R— | C] () – C:\Documents and Settings\Bill & Kathy\Desktop\ComboFix.exe
[2009/08/27 21:07:48 | 00,000,000 | –SD | C] – C:\Combo-Fix
[2009/08/27 20:24:18 | 01,614,848 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\sfcfiles.dll
[2009/08/27 20:24:18 | 00,574,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ntfs.sys
[2009/08/27 20:24:18 | 00,435,200 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ntmssvc.dll
[2009/08/27 20:24:18 | 00,253,952 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\es.dll
[2009/08/27 20:24:18 | 00,249,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\tapisrv.dll
[2009/08/27 20:24:18 | 00,245,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\mswsock.dll
[2009/08/27 20:24:18 | 00,198,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\netman.dll
[2009/08/27 20:24:18 | 00,192,512 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\schedsvc.dll
[2009/08/27 20:24:18 | 00,185,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\upnphost.dll
[2009/08/27 20:24:18 | 00,171,008 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\srsvc.dll
[2009/08/27 20:24:18 | 00,135,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\shsvcs.dll
[2009/08/27 20:24:18 | 00,129,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\xmlprov.dll
[2009/08/27 20:24:18 | 00,088,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\rasauto.dll
[2009/08/27 20:24:18 | 00,077,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\browser.dll
[2009/08/27 20:24:18 | 00,071,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ssdpsrv.dll
[2009/08/27 20:24:18 | 00,062,464 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\cryptsvc.dll
[2009/08/27 20:24:18 | 00,059,904 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\regsvc.dll
[2009/08/27 20:24:18 | 00,027,136 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\mspmsnsv.dll
[2009/08/27 20:24:18 | 00,013,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\wscntfy.exe
[2009/08/27 20:24:17 | 03,597,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\mshtml.dll
[2009/08/27 20:24:17 | 02,145,280 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ntoskrnl.exe
[2009/08/27 20:24:17 | 02,023,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ntkrnlpa.exe
[2009/08/27 20:24:17 | 01,033,728 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\explorer.exe
[2009/08/27 20:24:17 | 00,989,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\kernel32.dll
[2009/08/27 20:24:17 | 00,927,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\mfc40u.dll
[2009/08/27 20:24:17 | 00,792,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\comres.dll
[2009/08/27 20:24:17 | 00,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\comctl32.dll
[2009/08/27 20:24:17 | 00,409,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\qmgr.dll
[2009/08/27 20:24:17 | 00,407,040 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\netlogon.dll
[2009/08/27 20:24:17 | 00,401,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\rpcss.dll
[2009/08/27 20:24:17 | 00,295,424 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\termsrv.dll
[2009/08/27 20:24:17 | 00,182,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ndis.sys
[2009/08/27 20:24:17 | 00,181,248 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\scecli.dll
[2009/08/27 20:24:17 | 00,142,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\aec.sys
[2009/08/27 20:24:17 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\services.exe
[2009/08/27 20:24:17 | 00,110,080 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\imm32.dll
[2009/08/27 20:24:17 | 00,057,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\spoolsv.exe
[2009/08/27 20:24:17 | 00,056,320 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\eventlog.dll
[2009/08/27 20:24:17 | 00,051,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\wuauclt.exe
[2009/08/27 20:24:17 | 00,036,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ip6fw.sys
[2009/08/27 20:24:17 | 00,033,792 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\msgsvc.dll
[2009/08/27 20:24:17 | 00,026,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\userinit.exe
[2009/08/27 20:24:17 | 00,024,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\kbdclass.sys
[2009/08/27 20:24:17 | 00,022,016 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\lpk.dll
[2009/08/27 20:24:17 | 00,017,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\powrprof.dll
[2009/08/27 20:24:17 | 00,015,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ctfmon.exe
[2009/08/27 20:24:17 | 00,014,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\asyncmac.sys
[2009/08/27 20:24:17 | 00,013,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\lsass.exe
[2009/08/27 20:24:17 | 00,011,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\acpiec.sys
[2009/08/27 20:24:17 | 00,005,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\sfc.dll
[2009/08/27 20:24:17 | 00,004,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\beep.sys
[2009/08/27 20:24:17 | 00,002,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\null.sys
[2009/08/27 20:24:16 | 00,827,392 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\wininet.dll
[2009/08/27 20:24:16 | 00,578,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\user32.dll
[2009/08/27 20:24:16 | 00,507,904 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\winlogon.exe
[2009/08/27 20:24:16 | 00,361,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\tcpip.sys
[2009/08/27 20:24:16 | 00,082,432 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\ws2_32.dll
[2009/08/27 20:24:16 | 00,014,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cache\svchost.exe
[2009/08/27 20:24:16 | 00,000,000 | —D | C] – C:\WINDOWS\System32\dllcache\cache
[2009/08/24 17:41:01 | 00,514,048 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Bill & Kathy\Desktop\OTL.exe
[2009/08/23 17:16:24 | 00,000,000 | —D | C] – C:\Documents and Settings\Bill & Kathy\Local Settings\Application Data\Deployment
[2009/08/22 17:37:27 | 00,002,812 | —- | C] () – C:\dds.zip
[2009/08/22 17:33:42 | 00,359,932 | —- | C] () – C:\Documents and Settings\Bill & Kathy\Desktop\dds.scr
[2009/08/21 22:36:23 | 36,065,792 | —- | C] () – C:\Documents and Settings\Bill & Kathy\My Documents\eav_nt32_enu.msi
[2009/08/21 21:29:11 | 00,000,000 | —D | C] – C:\Documents and Settings\Bill & Kathy\Application Data\ESET
[2009/08/21 21:28:16 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\ESET
[2009/08/21 19:16:26 | 00,000,000 | —- | C] () – C:\Documents and Settings\Bill & Kathy\Desktop\settings.dat
[2009/08/21 19:15:35 | 00,472,064 | —- | C] ( ) – C:\Documents and Settings\Bill & Kathy\Desktop\RootRepeal.exe
[2009/08/21 18:48:06 | 00,000,767 | —- | C] () – C:\Documents and Settings\Bill & Kathy\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/08/21 18:48:00 | 00,000,611 | —- | C] () – C:\Documents and Settings\Bill & Kathy\Desktop\NTREGOPT.lnk
[2009/08/21 18:48:00 | 00,000,592 | —- | C] () – C:\Documents and Settings\Bill & Kathy\Desktop\ERUNT.lnk
[2009/08/21 18:47:59 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2009/08/21 18:47:13 | 00,791,393 | —- | C] (Lars Hederer ) – C:\Documents and Settings\Bill & Kathy\Desktop\erunt-setup.exe
[2009/08/21 17:53:52 | 00,000,000 | -HSD | C] – C:\found.000
[2009/08/19 18:59:46 | 00,000,209 | —- | C] () – C:\Boot.bak
[2009/08/19 18:59:43 | 00,260,272 | —- | C] () – C:\cmldr
[2009/08/19 18:59:42 | 00,000,000 | RHSD | C] – C:\cmdcons
[2009/08/19 18:55:16 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/08/18 20:35:38 | 00,000,000 | —D | C] – C:\Program Files\AskBarDis
[2009/08/18 20:35:35 | 00,000,700 | —- | C] () – C:\Documents and Settings\Bill & Kathy\Desktop\Glary Registry Repair.lnk
[2009/08/18 20:35:35 | 00,000,232 | —- | C] () – C:\Documents and Settings\Bill & Kathy\Desktop\Glary Utilities Freeware.url
[2009/08/18 20:35:35 | 00,000,000 | —D | C] – C:\Documents and Settings\Bill & Kathy\Application Data\GlarySoft
[2009/08/18 20:35:34 | 00,000,000 | —D | C] – C:\Program Files\Glary Registry Repair
[2009/08/18 20:11:55 | 00,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2009/08/18 18:01:55 | 00,288,768 | —- | C] () – C:\Documents and Settings\Bill & Kathy\Desktop\0pqrt3zy.exe
[2009/08/17 19:09:24 | 00,000,250 | —- | C] () – C:\WINDOWS\gmer.ini
[2009/08/17 19:09:23 | 00,573,440 | —- | C] () – C:\WINDOWS\gmer.exe
[2009/08/17 19:09:23 | 00,565,311 | —- | C] () – C:\WINDOWS\gmer.dll
[2009/08/17 19:09:23 | 00,068,961 | —- | C] (GMER) – C:\WINDOWS\System32\drivers\gmer.sys
[2009/08/17 19:09:23 | 00,000,080 | —- | C] () – C:\WINDOWS\gmer_uninstall.cmd
[2009/08/15 08:28:10 | 00,001,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
[2009/08/15 08:28:10 | 00,000,893 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\EPSON Status Monitor 3 Environment Check 2.lnk
[2009/08/15 08:28:10 | 00,000,493 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
[2009/08/15 00:11:27 | 00,000,036 | —- | C] () – C:\Documents and Settings\Bill & Kathy\Local Settings\Application Data\housecall.guid.cache
[2009/08/15 00:03:35 | 00,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2009/08/15 00:03:35 | 00,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2009/08/15 00:03:35 | 00,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2009/08/15 00:03:35 | 00,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2009/08/14 20:04:08 | 00,000,000 | —D | C] – C:\SAV32CLI
[2009/08/14 19:43:29 | 00,001,734 | —- | C] () – C:\Documents and Settings\Bill & Kathy\Desktop\HijackThis.lnk
[2009/08/14 19:43:28 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/08/13 20:23:21 | 00,000,000 | —D | C] – C:\Documents and Settings\Bill & Kathy\Application Data\Malwarebytes
[2009/08/13 20:23:19 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/08/13 20:23:16 | 00,038,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/08/13 20:23:15 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/08/13 20:23:14 | 00,019,096 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/08/13 20:23:14 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/08/13 20:04:41 | 00,045,344 | —- | C] () – C:\WINDOWS\System32\drivers\krjbecd.sys
[2009/08/12 19:16:54 | 00,128,512 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\dhtmled.ocx
[2009/08/12 19:16:27 | 01,315,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msoe.dll
[2009/08/07 22:11:00 | 00,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2009/08/07 22:11:00 | 00,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2009/08/06 20:10:52 | 01,089,593 | —- | C] () – C:\WINDOWS\System32\dllcache\ntprint.cat
[2009/08/06 03:05:29 | 00,000,000 | —D | C] – C:\WINDOWS\System32\XPSViewer
[2009/08/06 03:05:24 | 00,000,000 | —D | C] – C:\Program Files\MSBuild
[2009/08/06 03:05:15 | 00,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2009/08/06 03:04:38 | 01,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpssvcs.dll
[2009/08/06 03:04:38 | 01,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2009/08/06 03:04:38 | 00,597,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2009/08/06 03:04:38 | 00,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpsshhdr.dll
[2009/08/06 03:04:38 | 00,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2009/08/06 03:04:38 | 00,117,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\prntvpt.dll
[2009/08/06 03:04:38 | 00,089,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2009/08/06 03:04:37 | 00,000,000 | —D | C] – C:\2aa286fd5e5fe8c08b1513
[2009/08/06 03:04:13 | 00,000,000 | —D | C] – C:\WINDOWS\SxsCaPendDel
[2008/07/24 19:30:41 | 00,000,030 | —- | C] () – C:\WINDOWS\capture.ini
[2008/07/24 19:28:56 | 00,000,579 | —- | C] () – C:\WINDOWS\addrbook.ini
[2008/07/24 19:27:52 | 00,000,102 | —- | C] () – C:\WINDOWS\dvr2.ini
[2007/12/11 20:56:35 | 00,000,917 | —- | C] () – C:\WINDOWS\ARCADE2.INI
[2007/08/11 11:01:31 | 00,000,052 | —- | C] () – C:\WINDOWS\rblky.sys
[2006/10/02 20:47:01 | 00,000,088 | RHS- | C] () – C:\WINDOWS\System32\FB24DE712C.sys
[2006/10/02 20:47:00 | 00,003,350 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2006/09/04 15:04:18 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/08/26 12:38:55 | 00,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2006/08/26 12:35:48 | 00,040,448 | —- | C] () – C:\WINDOWS\System32\BJAXSecurityManager.dll
[2006/08/26 12:35:47 | 00,086,016 | —- | C] () – C:\WINDOWS\System32\BJInstaller.dll
[2006/08/18 00:11:31 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/08/17 23:30:58 | 00,000,392 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/11/10 08:56:34 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/08/31 12:11:14 | 00,000,442 | —- | C] () – C:\WINDOWS\System32\dlcfplc.ini
[2005/08/16 04:37:24 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/08/16 04:18:43 | 00,000,651 | —- | C] () – C:\WINDOWS\win.ini
[2005/08/16 04:18:41 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[2005/08/05 14:01:54 | 00,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
========== Files - Modified Within 30 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[2009/08/28 12:27:28 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/08/28 12:26:12 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2009/08/28 12:19:58 | 03,187,017 | R— | M] () – C:\Documents and Settings\Bill & Kathy\Desktop\ComboFix.exe
[2009/08/28 12:14:18 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/08/28 12:13:56 | 00,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2009/08/28 12:13:35 | 00,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2009/08/28 12:13:32 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/08/28 12:13:29 | 10,717,96224 | -HS- | M] () – C:\hiberfil.sys
[2009/08/28 11:55:00 | 00,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2009/08/24 17:42:02 | 00,514,048 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Bill & Kathy\Desktop\OTL.exe
[2009/08/24 14:03:16 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/08/23 10:55:41 | 00,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2009/08/23 03:09:13 | 00,229,376 | —- | M] () – C:\WINDOWS\PEV.exe
[2009/08/22 23:41:01 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/08/22 17:37:48 | 00,002,812 | —- | M] () – C:\dds.zip
[2009/08/22 17:33:52 | 00,359,932 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Desktop\dds.scr
[2009/08/21 22:36:35 | 36,065,792 | —- | M] () – C:\Documents and Settings\Bill & Kathy\My Documents\eav_nt32_enu.msi
[2009/08/21 19:16:26 | 00,000,000 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Desktop\settings.dat
[2009/08/21 19:15:38 | 00,472,064 | —- | M] ( ) – C:\Documents and Settings\Bill & Kathy\Desktop\RootRepeal.exe
[2009/08/21 18:48:06 | 00,000,767 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/08/21 18:48:00 | 00,000,611 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Desktop\NTREGOPT.lnk
[2009/08/21 18:48:00 | 00,000,592 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Desktop\ERUNT.lnk
[2009/08/21 18:47:20 | 00,791,393 | —- | M] (Lars Hederer ) – C:\Documents and Settings\Bill & Kathy\Desktop\erunt-setup.exe
[2009/08/19 19:19:18 | 00,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/08/19 18:59:46 | 00,000,279 | -HS- | M] () – C:\boot.ini
[2009/08/18 20:41:44 | 00,000,232 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Desktop\Glary Utilities Freeware.url
[2009/08/18 20:35:35 | 00,000,700 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Desktop\Glary Registry Repair.lnk
[2009/08/18 20:28:52 | 00,001,475 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Desktop\Windows Explorer.lnk
[2009/08/18 20:11:55 | 00,000,000 | —- | M] () – C:\WINDOWS\iPlayer.INI
[2009/08/18 18:01:55 | 00,288,768 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Desktop\0pqrt3zy.exe
[2009/08/17 19:12:04 | 00,000,250 | —- | M] () – C:\WINDOWS\gmer.ini
[2009/08/17 19:09:23 | 00,565,311 | —- | M] () – C:\WINDOWS\gmer.dll
[2009/08/17 19:09:23 | 00,068,961 | —- | M] (GMER) – C:\WINDOWS\System32\drivers\gmer.sys
[2009/08/17 19:09:23 | 00,000,080 | —- | M] () – C:\WINDOWS\gmer_uninstall.cmd
[2009/08/17 19:06:36 | 00,573,440 | —- | M] () – C:\WINDOWS\gmer.exe
[2009/08/15 08:28:01 | 00,000,651 | —- | M] () – C:\WINDOWS\win.ini
[2009/08/15 08:28:01 | 00,000,209 | —- | M] () – C:\Boot.bak
[2009/08/15 00:11:27 | 00,000,036 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Local Settings\Application Data\housecall.guid.cache
[2009/08/15 00:03:21 | 00,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deploytk.dll
[2009/08/15 00:03:21 | 00,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2009/08/15 00:03:21 | 00,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2009/08/15 00:03:21 | 00,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2009/08/15 00:03:21 | 00,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2009/08/14 22:23:46 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/08/14 19:43:29 | 00,001,734 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Desktop\HijackThis.lnk
[2009/08/13 20:04:41 | 00,045,344 | —- | M] () – C:\WINDOWS\System32\drivers\krjbecd.sys
[2009/08/11 17:20:37 | 00,003,350 | -HS- | M] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2009/08/11 17:20:33 | 00,000,088 | RHS- | M] () – C:\WINDOWS\System32\FB24DE712C.sys
[2009/08/11 17:19:58 | 00,069,328 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/08/08 12:56:06 | 00,011,776 | —- | M] () – C:\Documents and Settings\Bill & Kathy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/07 22:11:00 | 00,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2009/08/06 03:17:11 | 00,266,208 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/08/06 03:09:26 | 00,503,304 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/08/06 03:09:26 | 00,442,466 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/08/06 03:09:26 | 00,071,732 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/08/05 05:01:48 | 00,204,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mswebdvd.dll
[2009/08/05 05:01:48 | 00,204,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mswebdvd.dll
[2009/08/03 13:36:28 | 00,038,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/08/03 13:36:06 | 00,019,096 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/07/29 17:49:16 | 24,281,536 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
========== Alternate Data Streams ==========
@Alternate Data Stream - 88 bytes -> C:\Documents and Settings\Bill & Kathy\My Documents\dds.txt.txt:SummaryInformation
@Alternate Data Stream - 135 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:40088782
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CB0AACC9
< End of report >
ComboFix 09-08-27.A3 - Bill & Kathy 08/28/2009 12:21.6.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.634 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\BILL&K;~1\LOCALS~1\Temp\catchme.dll
c:\documents and settings\Bill & Kathy\Local Settings\Temp\catchme.dll
.
((((((((((((((((((((((((( Files Created from 2009-07-28 to 2009-08-28 )))))))))))))))))))))))))))))))
.
2009-08-19 00:35 . 2009-08-21 10:14 ——– d—–w- c:\program files\AskBarDis
2009-08-19 00:35 . 2009-08-19 00:35 ——– d—–w- c:\documents and settings\Bill & Kathy\Application Data\GlarySoft
2009-08-19 00:35 . 2009-08-19 00:35 ——– d—–w- c:\program files\Glary Registry Repair
2009-08-15 02:24 . 2009-08-15 02:24 3942047 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-08-15 01:18 . 2009-08-15 03:59 152576 —-a-w- c:\documents and settings\Bill & Kathy\Application Data\Sun\Java\jre1.6.0_15\lzma.dll
2009-08-15 00:04 . 2009-08-15 00:04 ——– d—–w- C:\SAV32CLI
2009-08-14 23:43 . 2009-08-14 23:43 ——– d—–w- c:\program files\Trend Micro
2009-08-14 00:23 . 2009-08-14 00:23 ——– d—–w- c:\documents and settings\Bill & Kathy\Application Data\Malwarebytes
2009-08-14 00:23 . 2009-08-03 17:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-14 00:23 . 2009-08-14 00:23 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-14 00:23 . 2009-08-15 02:24 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-14 00:23 . 2009-08-03 17:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-14 00:04 . 2009-08-14 00:04 45344 —-a-w- c:\windows\system32\drivers\krjbecd.sys
2009-08-12 23:16 . 2009-07-10 13:27 1315328 ——w- c:\windows\system32\dllcache\msoe.dll
2009-08-06 07:05 . 2009-08-06 07:05 ——– d—–w- c:\windows\system32\XPSViewer
2009-08-06 07:05 . 2009-08-06 07:05 ——– d—–w- c:\program files\MSBuild
2009-08-06 07:05 . 2009-08-06 07:05 ——– d—–w- c:\program files\Reference Assemblies
2009-08-06 07:04 . 2008-07-06 12:06 89088 ——w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-06 07:04 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2009-08-06 07:04 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-06 07:04 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2009-08-06 07:04 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-06 07:04 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2009-08-06 07:04 . 2008-07-06 10:50 597504 ——w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-06 07:04 . 2009-08-06 07:05 ——– d—–w- C:\2aa286fd5e5fe8c08b1513
2009-08-06 07:04 . 2009-08-06 07:17 ——– d—–w- c:\windows\SxsCaPendDel
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-27 18:19 . 2009-04-02 23:20 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2009-08-22 21:37 . 2009-08-22 21:37 2812 —-a-w- C:\dds.zip
2009-08-22 02:37 . 2009-08-22 01:28 ——– d—–w- c:\documents and settings\All Users\Application Data\ESET
2009-08-22 02:37 . 2006-08-26 18:29 ——– d—–w- c:\program files\ESET
2009-08-22 01:29 . 2009-08-22 01:29 ——– d—–w- c:\documents and settings\Bill & Kathy\Application Data\ESET
2009-08-21 22:48 . 2009-08-21 22:47 ——– d—–w- c:\program files\ERUNT
2009-08-19 00:16 . 2006-09-07 03:05 ——– d—–w- c:\program files\Windows Media Connect 2
2009-08-15 04:03 . 2009-02-11 23:55 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-08-15 04:03 . 2006-08-18 03:48 ——– d—–w- c:\program files\Java
2009-08-15 03:13 . 2006-12-25 18:58 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-11 23:29 . 2006-08-26 21:24 ——– d—–w- c:\program files\PartyGaming
2009-08-11 21:20 . 2006-10-03 00:47 3350 –sha-w- c:\windows\system32\KGyGaAvL.sys
2009-08-11 21:20 . 2006-10-03 00:47 88 –sh–r- c:\windows\system32\FB24DE712C.sys
2009-08-11 21:19 . 2006-08-25 01:46 69328 —-a-w- c:\documents and settings\Bill & Kathy\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-06 07:17 . 2009-06-13 16:28 ——– d—–w- c:\program files\Microsoft Silverlight
2009-08-05 09:01 . 2005-08-16 08:18 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-07-23 14:07 . 2006-08-26 18:20 ——– d—–w- c:\documents and settings\Bill & Kathy\Application Data\AdobeUM
2009-07-17 19:01 . 2005-08-16 08:18 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-14 03:43 . 2005-08-16 08:19 286208 —-a-w- c:\windows\system32\wmpdxm.dll
2009-07-11 18:06 . 2009-06-20 18:03 25440 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\savapibridge.dll
2009-07-11 18:06 . 2009-06-20 18:03 1630560 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Resources.dll
2009-07-11 18:06 . 2009-06-20 18:03 2353480 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Ad-Aware.exe
2009-07-11 15:52 . 2009-07-11 15:47 ——– d—–w- c:\program files\ATT-PRT22-WISE
2009-07-11 15:50 . 2009-07-11 15:50 ——– d—–w- c:\program files\att-prt22
2009-07-11 15:50 . 2009-07-11 15:47 ——– d—–w- c:\program files\Common Files\Motive
2009-07-11 15:48 . 2009-07-11 15:48 ——– d—–w- c:\documents and settings\All Users\Application Data\Motive
2009-06-29 16:56 . 2009-06-26 18:50 ——– d—–w- c:\documents and settings\Bill & Kathy\Application Data\U3
2009-06-29 16:12 . 2005-08-16 08:18 827392 ——w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2005-08-16 08:18 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2005-08-16 08:18 17408 —-a-w- c:\windows\system32\corpol.dll
2009-06-25 08:25 . 2005-08-16 08:18 54272 —-a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2005-08-16 08:18 56832 —-a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2005-08-16 08:18 147456 —-a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2005-08-16 08:18 136192 —-a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:25 . 2005-08-16 08:18 730112 —-a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2005-08-16 08:18 301568 —-a-w- c:\windows\system32\kerberos.dll
2009-06-24 11:18 . 2005-08-16 08:18 92928 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-23 00:40 . 2009-06-12 00:49 152576 —-a-w- c:\documents and settings\Bill & Kathy\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-16 14:36 . 2005-08-16 08:18 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2005-08-16 08:18 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-12 12:31 . 2005-08-16 08:18 80896 —-a-w- c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2005-08-16 08:18 76288 —-a-w- c:\windows\system32\telnet.exe
2009-06-10 14:13 . 2005-08-16 08:18 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-06-10 13:19 . 2005-08-16 08:37 2066432 —-a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2005-08-16 08:18 132096 —-a-w- c:\windows\system32\wkssvc.dll
2009-06-03 19:09 . 2005-08-16 08:18 1291264 —-a-w- c:\windows\system32\quartz.dll
2009-05-30 18:04 . 2009-05-30 18:04 15688 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\lsdelete.exe
2009-05-30 18:04 . 2009-04-25 18:10 15688 —-a-w- c:\windows\system32\lsdelete.exe
2007-06-09 17:54 . 2007-06-09 17:54 251 -c–a-w- c:\program files\wt3d.ini
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-07-17 21:20 279944 —-a-w- c:\program files\AskBarDis\bar\bin\askBar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-07-17 279944]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-07-17 279944]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-01 68856]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-15 149280]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-12-11 286720]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2005-07-12 1117184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"HelpCenter4.1"="c:\program files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe" [2007-06-28 198184]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2006-05-03 98304]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-06 344064]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-07-04 520024]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-05-14 2029640]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-03-22 339968]
c:\documents and settings\Bill & Kathy\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-8-17 24576]
EPSON Status Monitor 3 Environment Check 2.lnk - c:\windows\system32\spool\drivers\w32x86\3\E_SRCV02.EXE [2006-8-26 135680]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\networkdvr\\remote.exe"=
"c:\\Program Files\\Enlight\\Virtual Skipper 3\\Vsk3.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [4/25/2009 2:03 PM 64160]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [5/14/2009 3:47 PM 107256]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [5/14/2009 3:49 PM 94360]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [5/14/2009 3:47 PM 731840]
S0 krjbecd;krjbecd;\SystemRoot\\SystemRoot\System32\drivers\krjbecd.sys –> \SystemRoot\\SystemRoot\System32\drivers\krjbecd.sys [?]
S1 9f9a7c46.sys;9f9a7c46.sys;\??\c:\windows\System32\drivers\9f9a7c46.sys –> c:\windows\System32\drivers\9f9a7c46.sys [?]
S2 gupdate1c9b3e9dfcb5276;Google Update Service (gupdate1c9b3e9dfcb5276);c:\program files\Google\Update\GoogleUpdate.exe [4/2/2009 7:22 PM 133104]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 3:06 PM 1029456]
S3 vitra;vitra;c:\windows\system32\drivers\vitra.sys –> c:\windows\system32\drivers\vitra.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2009-08-24 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 18:03]
2009-08-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 19:57]
2009-08-28 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-02-02 23:20]
2009-08-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-02 23:22]
2009-08-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-02 23:22]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://hometab.bellsouth.net/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
Trusted Zone: musicmatch.com\online
.
**************************************************************************
disk not found C:\
please note that you need administrator rights to perform deep scan
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files:
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-847351272-1449424622-3853843411-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Windows\AutorunsDisabled]
"Appinit_Dlls"="c:\\PROGRA~1\\Google\\GOOGLE~1\\GOEC62~1.DLL"
.
Completion time: 2009-08-28 12:27
ComboFix-quarantined-files.txt 2009-08-28 16:27
ComboFix2.txt 2009-08-28 00:26
Pre-Run: 58,240,577,536 bytes free
Post-Run: 58,203,652,096 bytes free
195 — E O F — 2009-08-26 07:00