OK, here's the log:
ComboFix 09-08-30.01 - Kyle 08/30/2009 18:04.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.569 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
* Created a new restore point
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}
c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.dat
c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.exe
c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.lan
c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.msi
c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.par
c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\Ad-AwareAE.res
c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\instance.dat
c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}\mia.lib
c:\windows\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb
c:\windows\Fonts\WPHV07NB.TTF
c:\windows\Installer\WMEncoder.msi
c:\windows\jestertb.dll
c:\windows\run.log
c:\windows\system32\bszip.dll
c:\windows\system32\drivers\UACyvtndpmuje.sys
c:\windows\system32\UACbrqlrulhhb.dll
c:\windows\system32\UACdqvdksrrjk.dll
c:\windows\system32\UACebxnyymnmo.dat
c:\windows\system32\uacinit.dll
c:\windows\system32\UACjtmxewpipx.dll
c:\windows\system32\UACkakjqfopvo.dll
c:\windows\system32\UACwdrexpkela.db
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_UACd.sys
——-\Legacy_UACd.sys
((((((((((((((((((((((((( Files Created from 2009-07-28 to 2009-08-30 )))))))))))))))))))))))))))))))
.
2009-08-30 20:20 . 2009-08-30 20:20 ——– d—–w- c:\program files\Common Files\LightScribe
2009-08-30 20:10 . 2009-08-30 20:10 ——– d—–w- c:\documents and settings\Kyle\Application Data\Acoustica
2009-08-30 20:09 . 2009-08-30 20:12 ——– d—–w- c:\program files\Acoustica CD Label Maker
2009-08-27 18:19 . 2009-08-27 18:19 ——– d—–w- c:\documents and settings\LocalService\Application Data\McAfee
2009-08-22 13:13 . 2009-08-22 13:13 ——– d—–w- c:\documents and settings\Amy Kay Ollila\Application Data\McAfee
2009-08-20 00:13 . 2009-07-03 14:49 15688 —-a-w- c:\windows\system32\lsdelete.exe
2009-08-19 19:19 . 2009-07-03 14:49 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys
2009-08-19 19:17 . 2009-08-19 19:19 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-08-19 19:17 . 2009-08-19 19:17 ——– d—–w- c:\program files\Lavasoft
2009-08-19 18:49 . 2009-08-19 18:49 ——– d—–w- c:\documents and settings\All Users\Application Data\TEMP
2009-08-19 18:49 . 2009-08-19 18:49 ——– d—–w- c:\program files\Ace Utilities
2009-08-19 18:19 . 2009-08-03 18:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-19 18:19 . 2009-08-03 18:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-19 17:36 . 2009-08-19 17:36 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2009-08-18 08:04 . 2009-08-18 08:04 ——– d-sh–w- c:\documents and settings\Kyle\IECompatCache
2009-08-18 01:28 . 2009-08-18 01:28 ——– d—–w- c:\documents and settings\Kyle\Application Data\McAfee
2009-08-18 01:28 . 2009-08-18 01:28 127 —-a-w- c:\documents and settings\Kyle\Local Settings\Application Data\fusioncache.dat
2009-08-17 17:31 . 2009-08-17 17:32 ——– d—–w- c:\program files\AVI MPEG RM WMV Joiner
2009-08-17 04:24 . 2009-08-17 04:24 82632 —-a-w- c:\documents and settings\Amy Kay Ollila\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-15 23:02 . 2009-08-15 23:02 ——– d—–w- c:\windows\system32\XPSViewer
2009-08-15 23:02 . 2009-08-15 23:02 ——– d—–w- c:\program files\MSBuild
2009-08-15 23:02 . 2009-08-15 23:02 ——– d—–w- c:\program files\Reference Assemblies
2009-08-15 23:00 . 2008-07-06 12:06 89088 ——w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-15 23:00 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2009-08-15 23:00 . 2008-07-06 10:50 597504 ——w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-15 23:00 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2009-08-15 23:00 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-15 23:00 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2009-08-15 23:00 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-15 23:00 . 2009-08-15 23:01 ——– d—–w- C:\deb76f555261a90c7710e8acc3d6b5
2009-08-14 06:53 . 2009-08-14 06:53 ——– d—–w- c:\documents and settings\Kyle\Local Settings\Application Data\My Games
2009-08-14 05:13 . 2009-08-14 05:13 ——– d—–w- c:\program files\Firaxis Games
2009-08-11 20:58 . 2009-07-10 13:27 1315328 ——w- c:\windows\system32\dllcache\msoe.dll
2009-08-10 03:20 . 2009-08-11 09:07 ——– d—–w- c:\documents and settings\Kyle\Application Data\Family Project
2009-08-10 03:20 . 2009-08-10 03:19 695578 —-a-w- c:\documents and settings\Kyle\Application Data\Family Project\unins000.exe
2009-08-10 03:20 . 2009-08-08 06:54 647168 —-a-w- c:\documents and settings\Kyle\Application Data\Family Project\FAMILY.exe
2009-08-06 13:52 . 2009-08-06 13:52 152576 —-a-w- c:\documents and settings\Kyle\Application Data\Sun\Java\jre1.6.0_15\lzma.dll
2009-08-05 09:01 . 2009-08-05 09:01 204800 ——w- c:\windows\system32\dllcache\mswebdvd.dll
2009-08-03 04:18 . 2009-08-03 04:19 127872 —-a-w- c:\documents and settings\Kyle\Application Data\Move Networks\uninstall.exe
2009-08-03 04:18 . 2009-08-13 05:45 ——– d—–w- c:\documents and settings\Kyle\Application Data\Move Networks
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-24 22:04 . 2009-07-06 20:13 ——– d—–w- c:\documents and settings\Kyle\Application Data\ATI MMC
2009-08-24 21:01 . 2009-07-06 20:11 ——– d—–w- c:\documents and settings\All Users\Application Data\ATI MMC
2009-08-24 09:03 . 2009-03-09 22:33 ——– d—–w- c:\documents and settings\Kyle\Application Data\uTorrent
2009-08-20 00:38 . 2009-03-09 22:32 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-19 08:49 . 2009-04-23 17:29 ——– d—–w- c:\program files\C-Force
2009-08-18 19:03 . 2009-04-23 17:29 249856 ——w- c:\windows\Setup1.exe
2009-08-18 19:03 . 2009-04-23 17:29 73216 —-a-w- c:\windows\ST6UNST.EXE
2009-08-18 17:50 . 2009-08-18 17:50 784423 —-a-w- c:\windows\system32\xa.tmp
2009-08-18 05:36 . 2009-03-29 17:58 ——– d—–w- c:\documents and settings\All Users\Application Data\Rosetta Stone
2009-08-18 01:28 . 2009-07-19 23:03 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2009-08-18 01:28 . 2009-03-11 00:08 82632 —-a-w- c:\documents and settings\Kyle\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-14 06:04 . 2005-07-27 13:29 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-08-06 13:53 . 2005-07-27 13:26 ——– d—–w- c:\program files\Java
2009-08-05 09:01 . 2004-08-10 17:51 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-08-03 04:19 . 2009-06-16 06:35 4183416 —-a-w- c:\documents and settings\Kyle\Application Data\Move Networks\plugins\npqmp071503000010.dll
2009-07-31 03:24 . 2009-07-27 04:40 ——– d—–w- c:\program files\sische
2009-07-25 10:23 . 2009-03-10 03:06 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-07-20 23:50 . 2009-07-19 23:17 ——– d—–w- c:\program files\McAfee
2009-07-20 23:49 . 2005-07-27 13:49 ——– d—–w- c:\program files\Symantec
2009-07-20 00:11 . 2005-07-27 13:49 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-07-19 23:19 . 2009-07-19 23:17 ——– d—–w- c:\program files\Common Files\McAfee
2009-07-19 23:18 . 2009-07-19 23:18 ——– d—–w- c:\program files\McAfee.com
2009-07-17 19:01 . 2004-08-10 17:50 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-13 15:08 . 2004-08-10 17:51 286720 —-a-w- c:\windows\system32\wmpdxm.dll
2009-07-07 08:01 . 2009-07-07 08:01 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2009-07-07 08:01 . 2009-07-07 08:01 0 —ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-07-06 20:02 . 2009-07-06 19:56 ——– d—–w- c:\program files\ATI Multimedia
2009-07-06 19:57 . 2009-07-06 19:57 ——– d—–w- c:\program files\Common Files\ATI
2009-07-06 18:41 . 2009-07-06 18:41 ——– d—–w- c:\documents and settings\Kyle\Application Data\X10 Commander
2009-07-03 17:09 . 2004-08-10 17:51 915456 —-a-w- c:\windows\system32\wininet.dll
2009-06-25 08:25 . 2004-08-10 17:51 54272 —-a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2004-08-10 17:51 56832 —-a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2004-08-10 17:51 147456 —-a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2004-08-10 17:51 136192 —-a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:25 . 2004-08-10 17:51 730112 —-a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2004-08-10 17:51 301568 —-a-w- c:\windows\system32\kerberos.dll
2009-06-24 11:18 . 2004-08-10 17:51 92928 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:36 . 2004-08-10 17:51 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2004-08-10 17:51 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-16 06:35 . 2009-06-16 06:35 97144 —-a-w- c:\documents and settings\Kyle\Application Data\Move Networks\ie_bin\MovePlayerUpgrade.exe
2009-06-12 12:31 . 2004-08-10 17:51 76288 —-a-w- c:\windows\system32\telnet.exe
2009-06-11 07:44 . 2009-06-11 07:44 10134 —-a-r- c:\documents and settings\Kyle\Application Data\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
2009-06-10 14:19 . 2004-08-10 18:01 2066432 —-a-w- c:\windows\system32\mstscax.dll
2009-06-10 14:13 . 2004-08-10 17:50 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-06-10 06:14 . 2004-08-10 17:51 132096 —-a-w- c:\windows\system32\wkssvc.dll
2009-06-10 02:06 . 2009-06-10 02:06 152576 —-a-w- c:\documents and settings\Kyle\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-05 19:46 . 2009-06-17 22:55 2602720 -c–a-w- c:\documents and settings\All Users\Application Data\{AD1633B8-8F63-40E6-8A96-9AF47AC850E1}\Impulse_setup.exe
2009-06-05 14:57 . 2009-06-17 22:50 523120 -c–a-w- c:\documents and settings\All Users\Application Data\{AD1633B8-8F63-40E6-8A96-9AF47AC850E1}\OFFLINE\86D01CB6\597810BF\7za.exe
2009-06-05 14:56 . 2009-06-17 22:50 616696 -c–a-w- c:\documents and settings\All Users\Application Data\{AD1633B8-8F63-40E6-8A96-9AF47AC850E1}\OFFLINE\86D01CB6\597810BF\7z.dll
2009-06-05 14:55 . 2009-06-17 22:50 356352 -c–a-w- c:\documents and settings\All Users\Application Data\{AD1633B8-8F63-40E6-8A96-9AF47AC850E1}\OFFLINE\86D01CB6\757C30BC\ImpulseNow.exe
2009-06-03 19:09 . 2004-08-10 17:51 1291264 —-a-w- c:\windows\system32\quartz.dll
.
——- Sigcheck ——-
[7] 2008-06-20 10:44 360960 744E57C99232201AE98C49168B918F48 c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[7] 2008-06-20 11:51 361600 9AEFA14BD6B182D61E3119FA5F436D3D c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[7] 2008-06-20 11:59 361600 AD978A1B783B5719720CFF204B666C8E c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 10:45 360320 2A5554FC5B1E04E131230E3CE035C3F9 c:\windows\$NtServicePackUninstall$\tcpip.sys
[7] 2008-04-13 19:20 361344 93EA8D04EC73A85DB02EB8805988F733 c:\windows\$NtUninstallKB951748$\tcpip.sys
[7] 2004-08-04 10:00 359040 9F4B36614A0FC234525BA224957DE55C c:\windows\$NtUninstallKB951748_0$\tcpip.sys
[7] 2008-04-13 19:20 361344 93EA8D04EC73A85DB02EB8805988F733 c:\windows\ServicePackFiles\i386\TCPIP.SYS
[-] 2009-04-23 17:23 361600 D24EA301E2B36C4E975FD216CA85D8E7 c:\windows\system32\dllcache\TCPIP.SYS
[-] 2009-04-23 17:23 361600 D24EA301E2B36C4E975FD216CA85D8E7 c:\windows\system32\drivers\TCPIP.SYS
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Google Update"="c:\documents and settings\Kyle\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-04-26 133104]
"ATI DeviceDetect"="c:\program files\ATI Multimedia\main\ATIDtct.EXE" [2004-07-30 69705]
"ATI Remote Control"="c:\program files\ATI Multimedia\RemCtrl\ATIRW.exe" [2004-07-08 196608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2004-09-13 155648]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 385024]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-13 344064]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-12 290816]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"mmtask"="c:\program files\Musicmatch\Musicmatch Jukebox\mmtask.exe" [2004-09-14 53248]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2005-07-27 26112]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"McAfee Backup"="c:\program files\McAfee\MBK\McAfeeDataBackup.exe" [2007-01-16 4838952]
"MBkLogOnHook"="c:\program files\McAfee\MBK\LogOnHook.exe" [2007-01-08 20480]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
America Online 9.0 Tray Icon.lnk - c:\program files\America Online 9.0\aoltray.exe [2005-7-27 156784]
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng1.exe [2004-12-22 45056]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2005-7-27 24576]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 806912]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-09-07 21:08 110592 —-a-w- c:\program files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone Version 3\\support\\bin\\win\\RosettaStoneLtdServices.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone Version 3\\RosettaStoneVersion3.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Warlords\\Civ4Warlords.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Warlords\\Civ4Warlords_PitBoss.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe"=
"c:\\Program Files\\McAfee\\MBK\\McAfeeDataBackup.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [8/19/2009 2:19 PM 64160]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/3/2009 9:49 AM 1029456]
S3 atinysxx;ATI USB 2.0 TV Audio Crossbar;c:\windows\system32\drivers\atinysxx.sys [3/16/2009 11:24 PM 93696]
S3 atinyvxx;ATI TV WONDER USB2.0 Video & Audio;c:\windows\system32\drivers\atinyvxx.sys [3/16/2009 11:24 PM 185344]
S3 ATITUNEP2;ATI TV WONDER USB2.0 TV Tuner;c:\windows\system32\drivers\atinyuxx.sys [3/16/2009 11:24 PM 75776]
S3 ATIUTD;ATI TV WONDER USB2.0 Device Driver;c:\windows\system32\drivers\ATIUTD.sys [3/16/2009 11:24 PM 38912]
S3 TTDec;ATI TV WONDER USB2.0 Teletext Decoder;c:\windows\system32\drivers\atinyttx.sys [3/16/2009 11:24 PM 13824]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
2009-08-24 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 14:49]
2009-08-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1611299190-930597964-4189443988-1006Core.job
- c:\documents and settings\Kyle\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-04-26 23:58]
2009-08-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1611299190-930597964-4189443988-1006UA.job
- c:\documents and settings\Kyle\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-04-26 23:58]
2009-07-19 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-07-19 18:32]
2009-08-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-07-19 18:32]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-ATI Launchpad - (no file)
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = hxxp://www.dell4me.com/myway
uInternet Settings,ProxyOverride = *.local
uInternet Settings,ProxyServer = 85.131.208.2:3128
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
TCP: {CC036844-2068-4C6F-A8A8-F55F89CC8BFD} = 68.87.77.130
FF - ProfilePath - c:\documents and settings\Kyle\Application Data\Mozilla\Firefox\Profiles\j5xm0jzg.default\
FF - prefs.js: browser.startup.homepage - www.stthomas.edu
FF - plugin: c:\documents and settings\Kyle\Application Data\Move Networks\plugins\npqmp071503000010.dll
FF - plugin: c:\documents and settings\Kyle\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-08-30 18:21
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
McAfee Backup = c:\program files\McAfee\MBK\McAfeeDataBackup.exe?????????????????????????????????????????????????????????????????????????????????
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1040)
c:\windows\system32\Ati2evxx.dll
c:\program files\Intel\Wireless\Bin\LgNotify.dll
.
Completion time: 2009-08-30 18:26
ComboFix-quarantined-files.txt 2009-08-30 23:26
Pre-Run: 1,967,595,520 bytes free
Post-Run: 6,912,602,112 bytes free
280 — E O F — 2009-08-26 06:12