open a new tab. I'm going to try & re-start & see if that helps. Thanks again for all your help.
ComboFix 09-11-20.04 - Darla Kelly 11/21/2009 9:23.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.502.229 [GMT -6:00]
Running from: c:\documents and settings\Darla Kelly\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Darla Kelly\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FILE ::
"c:\documents and settings\Darla Kelly\Shared\Cinema Bizarre - How does it feel.wma"
"c:\documents and settings\Darla Kelly\Shared\What They Goin do lil jon.wma"
"c:\documents and settings\Laycie Kelly\Incomplete\Preview-T-4335426-Eighties classic (lambert).wma"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Darla Kelly\Shared\Cinema Bizarre - How does it feel.wma
c:\documents and settings\Darla Kelly\Shared\What They Goin do lil jon.wma
c:\documents and settings\Laycie Kelly\Incomplete\Preview-T-4335426-Eighties classic (lambert).wma
.
((((((((((((((((((((((((( Files Created from 2009-10-21 to 2009-11-21 )))))))))))))))))))))))))))))))
.
2009-11-19 04:32 . 2009-11-19 04:32 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-11-18 02:50 . 2009-11-10 04:42 4026136 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2009-11-18 02:50 . 2009-11-10 04:42 2016536 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtray.exe
2009-11-18 02:50 . 2009-11-10 04:42 1257240 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgfrw.exe
2009-11-18 02:50 . 2009-10-22 04:04 600344 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgnsx.exe
2009-11-18 02:50 . 2009-11-10 04:42 3963672 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2009-11-18 02:50 . 2009-10-24 20:11 496920 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgchjwx.dll
2009-11-09 00:58 . 2009-11-10 01:01 -------- d-----w- c:\documents and settings\Darla Kelly\.SunDownloadManager
2009-11-07 00:35 . 2009-11-07 00:35 -------- d-----w- c:\program files\Trend Micro
2009-11-01 01:19 . 2009-10-31 02:50 15880 ----a-w- c:\windows\system32\lsdelete.exe
2009-10-31 19:30 . 2009-10-31 19:30 -------- d-----w- c:\documents and settings\Darla Kelly\Application Data\Malwarebytes
2009-10-31 19:28 . 2009-09-10 19:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-31 19:28 . 2009-10-31 19:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-10-31 19:28 . 2009-09-10 19:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-31 19:28 . 2009-11-07 00:33 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-31 17:00 . 2009-10-31 17:00 -------- d-sh--w- c:\documents and settings\Brayden Kelly\IETldCache
2009-10-31 02:53 . 2009-10-31 02:51 93360 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2009-10-31 02:51 . 2009-10-31 02:51 93360 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\SBREDrv.sys
2009-10-31 02:50 . 2009-10-31 02:50 554280 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\sbap.dll
2009-10-31 02:50 . 2009-10-31 02:50 15880 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-10-31 02:50 . 2009-10-31 02:50 212480 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\VipreBridge.dll
2009-10-31 02:50 . 2009-10-31 02:50 283944 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Vipre.dll
2009-10-31 02:49 . 2009-10-31 02:49 1223976 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\SBTE.dll
2009-10-31 02:49 . 2009-10-31 02:49 242984 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\SBRE.dll
2009-10-31 02:49 . 2009-10-31 02:49 5908024 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2009-10-31 01:46 . 2009-09-18 17:27 1119488 ----a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-10-24 20:14 . 2009-10-24 20:13 360584 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtdix.sys
2009-10-24 20:07 . 2009-10-24 20:06 610072 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgiproxy.exe
2009-10-24 20:07 . 2009-10-22 04:04 798488 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avginet.dll
2009-10-24 02:26 . 2009-11-10 01:21 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-24 02:21 . 2009-10-24 02:21 152576 ----a-w- c:\documents and settings\Darla Kelly\Application Data\Sun\Java\jre1.6.0_15\lzma.dll
2009-10-24 00:06 . 2009-10-24 00:04 877848 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.exe
2009-10-24 00:06 . 2009-10-24 20:06 1657112 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-21 15:40 . 2009-04-06 23:06 256 ----a-w- c:\windows\system32\pool.bin
2009-11-19 03:11 . 2009-10-22 03:32 862040 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-11-19 03:10 . 2009-10-22 03:32 206944 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-11-19 03:10 . 2009-10-22 03:32 390288 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
2009-11-19 03:10 . 2009-10-22 03:32 537576 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\aawapi.dll
2009-11-19 03:10 . 2009-10-22 03:32 370744 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2009-11-19 03:10 . 2009-10-22 03:32 163728 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-11-19 03:10 . 2009-10-22 03:32 194104 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Savapibridge.dll
2009-11-19 03:10 . 2009-10-22 03:29 327000 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-11-19 03:10 . 2009-10-22 03:29 87496 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-11-19 03:10 . 2009-10-22 03:29 933632 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-11-19 03:10 . 2009-10-22 03:28 641632 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2009-11-19 03:09 . 2009-10-22 03:28 815760 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-11-19 03:09 . 2009-10-22 03:28 822904 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-11-19 03:09 . 2009-10-22 03:28 1638640 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-11-19 03:09 . 2009-10-22 03:28 788880 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-11-19 03:09 . 2009-10-22 03:27 1184912 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-11-10 04:42 . 2009-10-22 04:06 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-11-10 03:01 . 2007-06-26 03:04 -------- d-----w- c:\documents and settings\Darla Kelly\Application Data\LimeWire
2009-11-10 01:21 . 2005-02-05 08:39 -------- d-----w- c:\program files\Java
2009-11-07 00:34 . 2005-09-26 04:03 -------- d-----w- c:\documents and settings\Darla Kelly\Application Data\Lavasoft
2009-11-07 00:34 . 2007-03-18 03:16 -------- d-----w- c:\program files\Lavasoft
2009-10-31 17:19 . 2006-10-28 15:06 104752 -c--a-w- c:\documents and settings\Brayden Kelly\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-31 17:18 . 2007-10-02 02:04 -------- d-----w- c:\documents and settings\Brayden Kelly\Application Data\Apple Computer
2009-10-31 01:46 . 2009-10-22 04:04 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-10-22 04:06 . 2009-10-22 04:06 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-10-22 04:06 . 2009-10-22 04:06 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-10-22 04:06 . 2009-10-22 04:06 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-10-22 04:04 . 2009-10-22 04:04 -------- d-----w- c:\program files\AVG
2009-10-22 04:04 . 2009-10-22 04:04 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2009-10-22 03:36 . 2006-07-29 22:52 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-10-22 03:20 . 2009-10-22 03:20 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2009-10-22 03:17 . 2009-10-22 03:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-10-03 08:15 . 2009-10-22 03:20 2924848 -c--a-w- c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}\Ad-AwareInstallation.exe
2009-09-23 12:55 . 2009-10-22 03:32 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-09-18 20:54 . 2005-02-12 19:42 104752 -c--a-w- c:\documents and settings\Darla Kelly\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-11 14:18 . 2004-08-04 11:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-09 02:43 . 2009-09-09 02:43 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.0.70\SetupAdmin.exe
2009-09-09 01:50 . 2003-12-06 04:11 348160 ----a-w- c:\windows\system32\msvcr71.dll
2009-09-04 21:28 . 2008-03-19 23:40 488968 ----a-w- c:\documents and settings\Darla Kelly\Application Data\Real\Update\setup\setup.exe
2009-09-04 21:03 . 2004-08-04 11:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 08:08 . 2004-08-04 11:00 916480 ------w- c:\windows\system32\wininet.dll
2009-08-29 00:42 . 2009-07-29 01:46 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-08-29 00:42 . 2007-10-02 01:59 40448 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-08-26 08:00 . 2004-08-04 11:00 247326 ----a-w- c:\windows\system32\strmdll.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-11-08_22.34.09 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-11-21 15:01 . 2009-11-21 15:01 16384 c:\windows\Temp\Perflib_Perfdata_7e0.dat
- 2005-02-11 00:38 . 2009-10-31 02:56 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2005-02-11 00:38 . 2009-11-19 03:12 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2005-02-11 00:38 . 2009-11-19 03:12 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\index.dat
- 2005-02-11 00:38 . 2009-10-31 02:56 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-11-19 03:01 . 2009-11-19 03:12 16384 c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\index.dat
+ 2005-02-05 08:41 . 2009-11-18 04:42 45056 c:\windows\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\wordicon.exe
- 2005-02-05 08:41 . 2009-10-16 02:29 45056 c:\windows\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\wordicon.exe
+ 2005-02-05 08:41 . 2009-11-18 04:42 22528 c:\windows\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\unbndico.exe
- 2005-02-05 08:41 . 2009-10-16 02:29 22528 c:\windows\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\unbndico.exe
- 2005-02-05 08:41 . 2009-10-16 02:29 16384 c:\windows\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\PEicons.exe
+ 2005-02-05 08:41 . 2009-11-18 04:42 16384 c:\windows\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\PEicons.exe
+ 2005-02-05 08:41 . 2009-11-18 04:42 34304 c:\windows\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\misc.exe
- 2005-02-05 08:41 . 2009-10-16 02:29 34304 c:\windows\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\misc.exe
+ 2005-02-05 08:41 . 2009-11-18 04:42 3584 c:\windows\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\opwicon.exe
- 2005-02-05 08:41 . 2009-10-16 02:29 3584 c:\windows\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\opwicon.exe
+ 2005-02-05 08:41 . 2009-11-18 04:42 8192 c:\windows\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\mspicons.exe
- 2005-02-05 08:41 . 2009-10-16 02:29 8192 c:\windows\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\mspicons.exe
- 2005-02-05 08:41 . 2009-10-16 02:29 2560 c:\windows\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\cagicon.exe
+ 2005-02-05 08:41 . 2009-11-18 04:42 2560 c:\windows\Installer\{911B0409-6000-11D3-8CFE-0050048383C9}\cagicon.exe
- 2009-10-24 02:26 . 2009-10-24 02:25 149280 c:\windows\SYSTEM32\javaws.exe
+ 2009-11-10 01:22 . 2009-11-10 01:21 149280 c:\windows\SYSTEM32\javaws.exe
- 2009-10-24 02:26 . 2009-10-24 02:25 145184 c:\windows\SYSTEM32\javaw.exe
+ 2009-11-10 01:22 . 2009-11-10 01:21 145184 c:\windows\SYSTEM32\javaw.exe
- 2009-10-24 02:26 . 2009-10-24 02:25 145184 c:\windows\SYSTEM32\java.exe
+ 2009-11-10 01:22 . 2009-11-10 01:21 145184 c:\windows\SYSTEM32\java.exe
- 2004-08-10 19:08 . 2009-09-17 18:59 341032 c:\windows\SYSTEM32\FNTCACHE.DAT
+ 2004-08-10 19:08 . 2009-11-19 01:11 341032 c:\windows\SYSTEM32\FNTCACHE.DAT
+ 2009-07-10 04:13 . 2009-11-19 03:12 245760 c:\windows\SYSTEM32\CONFIG\systemprofile\IETldCache\index.dat
- 2009-07-10 04:13 . 2009-10-31 02:56 245760 c:\windows\SYSTEM32\CONFIG\systemprofile\IETldCache\index.dat
+ 2004-08-04 11:00 . 2009-08-14 13:21 1850624 c:\windows\SYSTEM32\win32k.sys
+ 2008-10-15 02:33 . 2009-08-14 13:21 1850624 c:\windows\SYSTEM32\DLLCACHE\win32k.sys
+ 2009-09-30 21:11 . 2009-09-30 21:11 8409088 c:\windows\Installer\5db1b5.msp
+ 2009-11-10 01:21 . 2009-11-10 01:21 1757696 c:\windows\Installer\2fb50f.msi
+ 2005-05-11 22:35 . 2009-11-05 17:36 26768832 c:\windows\SYSTEM32\MRT.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-09-18 1119488]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-09-18 17:27 1119488 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-09-18 1119488]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\ypager.exe" [2005-08-20 3084288]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"MoneyAgent"="c:\program files\Microsoft Money\System\mnyexpr.exe" [2003-06-18 200704]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-02 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-10-12 57344]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592]
"Dell Photo AIO Printer 942"="c:\program files\Dell Photo AIO Printer 942\dlbubmgr.exe" [2004-08-31 294912]
"DellMCM"="c:\program files\Dell Photo AIO Printer 942\memcard.exe" [2004-07-27 262144]
"MediaFace Integration"="c:\program files\Fellowes\MediaFACE 4.0\SetHook.exe" [2003-08-18 53248]
"DXM6Patch_981116"="c:\windows\p_981116.exe" [1998-12-01 497376]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-11-16 127035]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2003-12-06 50688]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-14 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-14 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-14 114688]
"RoxioEngineUtility"="c:\program files\Common Files\Roxio Shared\System\EngUtil.exe" [2003-05-01 65536]
"RoxioDragToDisc"="c:\program files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe" [2003-09-24 868352]
"RoxioAudioCentral"="c:\program files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe" [2003-07-15 319488]
"MimBoot"="c:\progra~1\MUSICM~1\MUSICM~3\mimboot.exe" [2006-01-19 11776]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2008-03-06 236016]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-09-09 198160]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-09 305440]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2009-11-18 2020120]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-11-10 149280]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-02 68856]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
Desktop Manager.lnk - c:\program files\Research In Motion\BlackBerry\DesktopMgr.exe [2008-5-30 1508624]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-10-22 04:06 12464 ----a-w- c:\windows\SYSTEM32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\WINDOWS\\SYSTEM32\\USMT\\migwiz.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 Lbd;Lbd;c:\windows\SYSTEM32\DRIVERS\Lbd.sys [10/21/2009 9:32 PM 64288]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [10/21/2009 10:06 PM 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [10/21/2009 10:06 PM 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [10/21/2009 10:04 PM 285392]
R2 fssfltr;FssFltr;c:\windows\SYSTEM32\DRIVERS\fssfltr_tdi.sys [9/15/2009 9:45 PM 54752]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [9/24/2009 5:17 AM 1184912]
S2 gupdate1ca30ef66b67612;Google Update Service (gupdate1ca30ef66b67612);c:\program files\Google\Update\GoogleUpdate.exe [9/8/2009 7:46 PM 133104]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\Windows Live\Family Safety\fsssvc.exe [8/5/2009 9:48 PM 704864]
.
Contents of the 'Scheduled Tasks' folder
2009-11-21 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 03:09]
2009-05-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 17:34]
2009-09-21 c:\windows\Tasks\Disk Cleanup.job
- c:\windows\SYSTEM32\cleanmgr.exe [2004-08-04 00:12]
2009-11-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-09 01:46]
2009-11-21 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-09 01:46]
2009-09-21 c:\windows\Tasks\Spybot - Search & Destroy.job
- c:\progra~1\SPYBOT~1\SpybotSD.exe [2006-04-22 06:04]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.foxnews.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
Trusted Zone: musicmatch.com\online
DPF: Garmin Communicator Plug-In - hxxps://my.garmin.com/static/m/cab/2.6.4/GarminAxControl.CAB
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-21 09:50
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-11-21 10:02
ComboFix-quarantined-files.txt 2009-11-21 16:02
ComboFix2.txt 2009-11-08 22:48
Pre-Run: 104,437,882,880 bytes free
Post-Run: 104,605,425,664 bytes free
- - End Of File - - BC0EA65D83D5ACE4981D1E7C04EF3938