The computer is running fine with intermittent times of random slow speed.
ComboFix 09-11-05.05 - Alyssa 11/06/2009 10:36.1.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1022.627 [GMT -5:00]
Running from: c:\documents and settings\Alyssa\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1356 [VPS 091106-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\hesanebo.dll
c:\windows\system32\logon.exe
c:\windows\system32\yulugezu.dll
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-10-06 to 2009-11-06 )))))))))))))))))))))))))))))))
.
2009-11-06 07:06 . 2009-11-06 07:06 -------- d-----w- c:\program files\Microsoft Reader
2009-11-06 07:06 . 2003-06-05 22:15 57436 ----a-w- c:\windows\DASShp.dll
2009-11-05 22:15 . 2009-11-05 22:15 -------- d-----w- c:\program files\Trend Micro
2009-11-05 22:01 . 2009-11-05 22:01 -------- d-----w- c:\documents and settings\Alyssa\Application Data\Malwarebytes
2009-11-05 21:39 . 2009-09-15 11:54 52368 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-05 21:39 . 2009-09-15 11:54 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-05 21:39 . 2009-09-15 11:53 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-11-05 21:39 . 2009-09-15 11:53 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-11-05 21:39 . 2009-09-15 11:55 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-05 21:39 . 2009-09-15 11:56 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-11-05 21:39 . 2009-09-15 11:56 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-11-05 21:39 . 2009-09-15 11:55 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-05 21:38 . 2009-09-15 11:59 1279968 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-05 21:38 . 2009-11-05 21:38 -------- d-----w- c:\program files\Alwil Software
2009-11-05 21:27 . 2009-11-05 21:27 -------- d-----w- c:\documents and settings\Alyssa\Local Settings\Application Data\Threat Expert
2009-11-05 20:51 . 2009-11-05 20:44 15880 ----a-w- c:\windows\system32\lsdelete.exe
2009-11-05 20:45 . 2009-11-05 20:45 -------- dc----w- c:\windows\system32\DRVSTORE
2009-11-05 20:45 . 2009-09-23 12:55 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-11-05 20:43 . 2009-11-05 20:43 5908024 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2009-11-05 20:43 . 2009-11-05 20:43 327000 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-11-05 20:43 . 2009-11-05 20:43 87496 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-11-05 20:43 . 2009-11-05 20:43 933120 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-11-05 20:43 . 2009-11-05 20:43 640608 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2009-11-05 20:42 . 2009-11-05 20:42 815760 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-11-05 20:42 . 2009-11-05 20:42 822904 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-11-05 20:42 . 2009-11-05 20:42 1638104 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-11-05 20:42 . 2009-11-05 20:42 788368 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-11-05 20:42 . 2009-11-05 20:42 1179232 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-11-05 20:40 . 2009-11-05 20:40 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2009-11-05 20:40 . 2009-10-03 08:15 2924848 -c--a-w- c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}\Ad-AwareInstallation.exe
2009-11-05 20:40 . 2009-11-05 20:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-11-05 20:40 . 2009-11-05 20:40 -------- d-----w- c:\program files\Lavasoft
2009-11-05 20:39 . 2009-09-10 19:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-05 20:39 . 2009-11-05 20:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-11-05 20:39 . 2009-09-10 19:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-05 20:39 . 2009-11-05 23:32 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-05 20:26 . 2009-05-07 07:04 157712 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2009-11-05 18:01 . 2009-11-05 18:01 -------- d-----w- c:\program files\Mad Scientist Productions
2009-11-05 17:54 . 2009-11-05 17:54 -------- d-----w- C:\ProgramData
2009-11-05 17:54 . 2009-11-05 17:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Electronic Arts
2009-11-05 17:50 . 2009-11-05 17:50 10134 ----a-r- c:\documents and settings\Alyssa\Application Data\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
2009-11-05 17:50 . 2009-11-05 17:50 -------- d-----w- c:\program files\Microsoft WSE
2009-11-05 17:50 . 2008-09-04 18:17 447752 ----a-r- c:\windows\system32\vp6vfw.dll
2009-11-05 17:47 . 2006-09-28 21:05 2414360 ----a-w- c:\windows\system32\d3dx9_31.dll
2009-11-05 17:47 . 2009-11-05 17:47 -------- d-----w- c:\windows\Logs
2009-11-05 17:37 . 2009-11-05 17:51 -------- d-----w- c:\program files\Electronic Arts
2009-11-05 17:17 . 2009-11-05 17:17 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-11-05 17:17 . 2009-11-05 17:24 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-11-05 17:16 . 2009-11-05 17:36 -------- d-----w- c:\documents and settings\Alyssa\Application Data\DAEMON Tools Lite
2009-11-05 17:16 . 2009-11-05 17:16 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2009-11-05 07:39 . 2004-08-04 03:58 14848 ----a-w- c:\windows\system32\drivers\kbdhid.sys
2009-11-05 07:39 . 2004-08-04 03:58 14848 ----a-w- c:\windows\system32\dllcache\kbdhid.sys
2009-11-05 07:39 . 2004-08-04 04:08 31616 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2009-11-05 07:39 . 2004-08-04 04:08 31616 ----a-w- c:\windows\system32\dllcache\usbccgp.sys
2009-11-05 04:16 . 2009-11-05 04:16 -------- d-sh--w- c:\documents and settings\Liz\IECompatCache
2009-11-05 03:05 . 2009-11-05 03:05 -------- d-sh--w- c:\documents and settings\Liz\PrivacIE
2009-11-05 02:52 . 2009-11-05 02:52 -------- d-sh--w- c:\documents and settings\Liz\IETldCache
2009-11-04 17:44 . 2009-09-23 21:37 34112 ----a-w- c:\documents and settings\Alyssa\Application Data\Flock\Browser\Profiles\8ngju884.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg_bootstrap.exe
2009-11-04 17:44 . 2009-09-23 21:37 32448 ----a-w- c:\documents and settings\Alyssa\Application Data\Flock\Browser\Profiles\8ngju884.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
2009-11-04 17:44 . 2009-09-23 21:37 22352 ----a-w- c:\documents and settings\Alyssa\Application Data\Flock\Browser\Profiles\8ngju884.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg.exe
2009-11-04 17:44 . 2009-07-01 19:45 52224 ----a-w- c:\documents and settings\Alyssa\Application Data\Flock\Browser\Profiles\8ngju884.default\extensions\{ad605904-0ba5-4d5c-8725-5adbc8912667}\components\FFExternalAlert.dll
2009-11-04 17:44 . 2009-07-01 19:45 114688 ----a-w- c:\documents and settings\Alyssa\Application Data\Flock\Browser\Profiles\8ngju884.default\extensions\{ad605904-0ba5-4d5c-8725-5adbc8912667}\components\npmozax.dll
2009-11-04 17:43 . 2009-11-04 17:43 -------- d-----w- c:\documents and settings\Alyssa\Local Settings\Application Data\Flock
2009-11-04 17:43 . 2009-11-04 17:43 -------- d-----w- c:\documents and settings\Alyssa\Application Data\Flock
2009-11-04 17:43 . 2009-11-06 15:14 -------- d-----w- c:\program files\Flock
2009-11-04 17:35 . 2009-11-04 17:35 -------- d-sh--w- c:\documents and settings\Alyssa\IECompatCache
2009-11-04 17:34 . 2009-11-04 17:34 -------- d-sh--w- c:\documents and settings\Alyssa\PrivacIE
2009-11-04 17:33 . 2009-11-04 17:33 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-11-04 17:33 . 2009-11-04 17:33 -------- d-sh--w- c:\documents and settings\Alyssa\IETldCache
2009-11-04 17:32 . 2009-10-02 04:44 92160 ------w- c:\windows\system32\dllcache\iecompat.dll
2009-11-04 17:32 . 2009-11-04 17:32 -------- d-----w- c:\windows\ie8updates
2009-11-04 17:31 . 2009-08-29 08:08 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2009-11-04 17:31 . 2009-08-29 08:08 594432 ------w- c:\windows\system32\dllcache\msfeeds.dll
2009-11-04 17:31 . 2009-08-29 08:08 55296 ------w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-11-04 17:31 . 2009-08-29 08:08 1985536 ------w- c:\windows\system32\dllcache\iertutil.dll
2009-11-04 17:31 . 2009-08-29 08:08 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll
2009-11-04 17:31 . 2009-08-29 08:08 11069440 ------w- c:\windows\system32\dllcache\ieframe.dll
2009-11-04 17:31 . 2009-11-04 17:31 -------- dc-h--w- c:\windows\ie8
2009-11-04 17:16 . 2008-02-26 11:59 294912 ------w- c:\windows\system32\dllcache\msctf.dll
2009-11-04 17:15 . 2004-08-04 08:00 25600 ----a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2009-11-04 17:10 . 2009-11-04 17:10 -------- d-----w- c:\program files\Windows Media Connect 2
2009-11-04 17:09 . 2009-11-04 17:10 -------- d-----w- C:\7160f71001ce4df48a54
2009-11-04 17:09 . 2009-11-04 17:10 -------- d-----w- c:\windows\system32\drivers\UMDF
2009-11-04 17:09 . 2009-11-04 17:09 -------- d-----w- c:\windows\system32\LogFiles
2009-11-04 16:43 . 2009-11-04 17:00 -------- d-----w- c:\windows\system32\CatRoot_bak
2009-11-04 05:21 . 2009-11-04 05:21 -------- d-----w- c:\windows\ServicePackFiles
2009-11-04 05:20 . 2009-11-04 05:20 -------- d-----w- c:\program files\MSXML 4.0
2009-11-04 03:20 . 2009-11-04 03:20 -------- d-----w- c:\documents and settings\Liz\Local Settings\Application Data\JollyBear
2009-11-04 03:20 . 2009-11-04 03:20 -------- d-----w- c:\documents and settings\All Users\Application Data\JollyBear
2009-11-04 03:20 . 2009-11-06 06:12 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-11-04 03:02 . 2009-11-04 03:02 -------- d-----w- c:\documents and settings\Liz\Application Data\Enki Games
2009-11-04 02:54 . 2009-11-04 02:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Becky Brogan
2009-11-04 02:46 . 2009-11-04 02:46 -------- d-----w- c:\documents and settings\Liz\Application Data\PlayFirst
2009-11-04 02:46 . 2009-11-04 02:46 -------- d-----w- c:\documents and settings\All Users\Application Data\PlayFirst
2009-11-04 02:46 . 2009-11-04 02:46 -------- d-----w- c:\documents and settings\Liz\Application Data\Big Fish Games
2009-11-04 02:44 . 2009-11-04 02:45 -------- d-----w- c:\program files\Games
2009-11-04 02:43 . 2009-11-04 02:43 -------- d-----w- c:\program files\Big City Adventure - New York
2009-11-04 02:43 . 2009-11-04 02:43 -------- d-----w- c:\windows\Big City Adventure - New York
2009-11-04 02:41 . 2009-11-04 02:43 -------- d-----w- c:\program files\Becky Brogan The Mystery of Meane Manor
2009-11-04 02:41 . 2009-11-04 02:41 -------- d-----w- c:\windows\Becky Brogan The Mystery of Meane Manor
2009-11-04 02:40 . 2009-11-04 02:40 -------- d-----w- c:\program files\Games Hastra
2009-11-04 02:38 . 2008-06-13 13:10 272128 ------w- c:\windows\system32\drivers\bthport.sys
2009-11-04 02:38 . 2008-06-13 13:10 272128 ------w- c:\windows\system32\dllcache\bthport.sys
2009-11-04 02:31 . 2009-03-06 14:44 283648 ------w- c:\windows\system32\dllcache\pdh.dll
2009-11-04 02:31 . 2009-02-09 10:20 399360 ------w- c:\windows\system32\dllcache\rpcss.dll
2009-11-04 02:31 . 2009-02-09 10:20 473088 ------w- c:\windows\system32\dllcache\fastprox.dll
2009-11-04 02:31 . 2009-02-09 10:20 453120 ------w- c:\windows\system32\dllcache\wmiprvsd.dll
2009-11-04 02:31 . 2009-02-06 17:14 110592 ------w- c:\windows\system32\dllcache\services.exe
2009-11-04 02:31 . 2009-02-06 16:54 35328 ------w- c:\windows\system32\dllcache\sc.exe
2009-11-04 02:31 . 2009-02-06 16:39 227840 ------w- c:\windows\system32\dllcache\wmiprvse.exe
2009-11-04 02:31 . 2005-07-26 04:39 60416 ------w- c:\windows\system32\dllcache\colbact.dll
2009-11-04 02:31 . 2009-02-09 10:20 714752 ------w- c:\windows\system32\dllcache\ntdll.dll
2009-11-04 02:31 . 2009-02-09 10:20 616960 ------w- c:\windows\system32\dllcache\advapi32.dll
2009-11-04 02:31 . 2009-06-21 22:04 153088 ------w- c:\windows\system32\dllcache\triedit.dll
2009-11-04 02:27 . 2008-05-08 12:28 202752 ------w- c:\windows\system32\dllcache\rmcast.sys
2009-11-04 02:27 . 2008-10-24 11:10 453632 ------w- c:\windows\system32\dllcache\mrxsmb.sys
2009-11-04 02:27 . 2008-12-11 11:57 333184 ------w- c:\windows\system32\dllcache\srv.sys
2009-11-04 02:27 . 2008-05-01 14:30 331776 ------w- c:\windows\system32\dllcache\msadce.dll
2009-11-04 02:27 . 2009-07-10 13:42 1315328 ------w- c:\windows\system32\dllcache\msoe.dll
2009-11-04 02:26 . 2008-04-11 18:50 683520 ------w- c:\windows\system32\dllcache\inetcomm.dll
2009-11-04 02:24 . 2009-08-04 12:51 2185984 ------w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-11-04 02:24 . 2009-08-04 12:49 2142720 ------w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-11-04 02:24 . 2009-08-04 12:02 2062976 ------w- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-11-04 02:24 . 2009-08-04 12:02 2020864 ------w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-11-04 02:23 . 2009-06-05 07:42 655872 ------w- c:\windows\system32\dllcache\mstscax.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-06 09:01 . 2009-11-03 04:30 63848 ----a-w- c:\documents and settings\Alyssa\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-06 07:06 . 2006-02-22 10:54 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-11-03 06:14 . 2006-02-22 11:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-11-03 06:14 . 2006-02-22 11:34 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-11-03 06:08 . 2006-02-22 11:12 -------- d-----w- c:\program files\Hewlett-Packard
2009-11-03 05:48 . 2009-11-03 05:46 61752 ----a-w- c:\documents and settings\Liz\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-03 05:48 . 2009-11-03 05:46 126 ----a-w- c:\documents and settings\Liz\Local Settings\Application Data\fusioncache.dat
2009-11-03 05:47 . 2009-11-03 05:46 1756 --sha-r- c:\windows\system32\drivers\103C_HP_NTBK_HP Pavilion dv8000 (EE944AV)_YN_0Pavi_QCND6111128_E398803002_46_I30A6_SHP_V56.23_BF.08_T060220_WXH2
_L409_M1023_J80_7Intel_8T2400_91.83_#060222_N80861092_(EE944AV)_XMOBILE_CN10_Z_2F
.08Tr14_G10DE01D8.MRK
2009-11-03 05:42 . 2006-02-22 10:54 -------- d-----w- c:\program files\HPQ
2009-11-03 04:24 . 2006-02-22 11:27 -------- d-----w- c:\program files\Synaptics
2009-11-03 04:24 . 2006-02-22 11:24 -------- d-----w- c:\program files\Sonic
2009-11-03 04:23 . 2006-02-22 11:43 -------- d-----w- c:\program files\Quickensetup
2009-11-03 04:23 . 2006-02-22 11:43 -------- d-----w- c:\program files\Quicken
2009-11-03 04:21 . 2006-02-22 11:42 -------- d-----w- c:\program files\muvee Technologies
2009-11-03 04:21 . 2006-02-22 11:42 -------- d-----w- c:\program files\music_now
2009-11-03 04:21 . 2006-02-22 11:18 -------- d-----w- c:\program files\MSN Encarta Plus
2009-11-03 04:21 . 2006-02-22 11:18 -------- d-----w- c:\program files\Microsoft Works
2009-11-03 04:20 . 2006-02-22 11:13 -------- d-----w- c:\program files\Microsoft Money 2006
2009-11-03 04:20 . 2006-02-22 10:46 -------- d-----w- c:\program files\microsoft frontpage
2009-11-03 04:20 . 2006-02-22 11:00 -------- d-----w- c:\program files\Java
2009-11-03 04:20 . 2006-02-22 10:56 -------- d-----w- c:\program files\Intel
2009-11-03 04:19 . 2006-02-22 11:07 -------- d-----w- c:\program files\HP
2009-11-03 04:18 . 2006-02-22 11:25 -------- d-----w- c:\program files\Common Files\TiVo Shared
2009-11-03 04:18 . 2006-02-22 10:55 -------- d-----w- c:\program files\CONEXANT
2009-11-03 04:18 . 2006-02-22 11:25 -------- d-----w- c:\program files\Common Files\SureThing Shared
2009-11-03 04:18 . 2006-02-22 11:08 -------- d-----w- c:\program files\Common Files\Sonic Shared
2009-11-03 04:18 . 2006-02-22 11:43 -------- d-----w- c:\program files\Common Files\Palo Alto Software
2009-11-03 04:18 . 2006-02-22 11:42 -------- d-----w- c:\program files\Common Files\muvee Technologies
2009-11-03 04:17 . 2006-02-22 11:47 -------- d-----w- c:\program files\Common Files\LightScribe
2009-11-03 04:17 . 2006-02-22 11:00 -------- d-----w- c:\program files\Common Files\Java
2009-11-03 04:17 . 2006-02-22 11:43 -------- d-----w- c:\program files\Common Files\Intuit
2009-11-03 04:17 . 2006-02-22 10:54 -------- d-----w- c:\program files\Common Files\InstallShield
2009-11-03 04:17 . 2006-02-22 11:07 -------- d-----w- c:\program files\Common Files\HP
2009-11-03 04:15 . 2009-11-03 05:46 -------- d-----w- c:\documents and settings\Liz\Application Data\Intuit
2009-11-03 04:15 . 2009-11-03 04:30 -------- d-----w- c:\documents and settings\Alyssa\Application Data\Intuit
2009-11-03 04:15 . 2006-02-22 11:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Sonic
2009-11-03 04:15 . 2006-02-22 10:46 -------- d-----w- c:\documents and settings\All Users\Application Data\SBSI
2009-11-03 04:15 . 2006-02-22 11:42 -------- d-----w- c:\documents and settings\All Users\Application Data\muvee Technologies
2009-11-03 04:15 . 2006-02-22 11:46 -------- d-----w- c:\documents and settings\All Users\Application Data\HP
2009-11-03 04:15 . 2006-02-22 11:46 -------- d-----w- c:\documents and settings\All Users\Application Data\CyberLink
2009-11-03 04:15 . 2006-02-22 11:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Intuit
2009-11-03 04:15 . 2006-02-22 11:26 -------- d-----w- c:\documents and settings\All Users\Application Data\InstallShield
2009-09-11 14:33 . 2004-08-04 08:00 133632 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 20:45 . 2004-08-04 08:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 08:08 . 2004-08-04 08:00 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-26 08:16 . 2004-08-04 08:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2007-02-12 08:20 . 2009-11-03 04:39 0 --sha-w- c:\windows\SMINST\HPCD.SYS
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-12-15 7331840]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-12-15 86016]
"hpWirelessAssistant"="c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-12-14 507904]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-09-15 81000]
"combofix"="c:\combofix\CF5052.exe" [2009-11-06 388608]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2005-12-15 1519616]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" - c:\windows\system32\CHDAudPropShortcut.exe [2005-11-08 61952]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Wireless Configuration Utility HW.14.lnk - c:\program files\802.11 Wireless LAN\802.11g Wireless USB 2.0 Adapter HW.14 V.1.00\WlanCU.exe [2006-9-12 569344]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Shell"="Explorer.exe logon.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk
backup=c:\windows\pss\HP Photosmart Premier Fast Start.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\WINDOWS\\explorer.exe"=
"c:\\Program Files\\Adobe\\Acrobat 6.0\\Reader\\AcroRd32.exe"=
"c:\\WINDOWS\\system32\\logonui.exe"=
"c:\\WINDOWS\\system32\\winlogon.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [11/5/2009 3:45 PM 64288]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [11/5/2009 4:39 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [11/5/2009 4:39 PM 20560]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [9/24/2009 6:17 AM 1179232]
R3 RTLWUSB;802.11g USB 2.0 WLAN Dongle;c:\windows\system32\drivers\RTL8187.sys [11/3/2009 1:20 AM 169472]
R3 SjyPkt;SjyPkt;c:\windows\system32\drivers\SjyPkt.sys [10/2/2002 9:57 AM 13532]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - MBR
*Deregistered* - mbr
.
Contents of the 'Scheduled Tasks' folder
2009-11-06 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 20:42]
2009-11-06 c:\windows\Tasks\User_Feed_Synchronization-{1C898877-50F0-40ED-9AFF-149ADEDD1193}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 09:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=laptop
uSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=laptop
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=laptop
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
FF - ProfilePath - c:\documents and settings\Alyssa\Application Data\Mozilla\Firefox\Profiles\aucromhz.default\
FF - plugin: c:\documents and settings\Alyssa\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdnupdater2.dll
---- FIREFOX POLICIES ----
FF - user.js: network.protocol-handler.warn-external.dnupdate - falsec:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{472734EA-242A-422B-ADF8-83D1E48CC825} - (no file)
SharedTaskScheduler-{c2da0289-41e9-4410-bb2f-d2ebc8824772} - c:\windows\system32\gorumiba.dll
SSODL-kelizevef-{c2da0289-41e9-4410-bb2f-d2ebc8824772} - c:\windows\system32\gorumiba.dll
AddRemove-HP Game Console - c:\program files\WildTangent\Apps\hpuninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-11-06 10:42
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll iaStor.sys spxc.sys >>UNKNOWN [0x86787938]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\atapi -> 0x867671f8
Warning: possible MBR rootkit infection !
user & kernel MBR OK
Use "Recovery Console" command "fixmbr" to clear infection !
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
iaStor.sys @ 0x0 0x0 bytes
\Driver\iaStor [ IRP_MJ_CREATE ] 0xF186 != 0xF72DD7B0 iaStor.sys
\Driver\iaStor [ IRP_MJ_CLOSE ] 0xF186 != 0xF72DD7B0 iaStor.sys
\Driver\iaStor [ IRP_MJ_DEVICE_CONTROL ] 0x12896 != 0xF72DD7B0 iaStor.sys
\Driver\iaStor [ IRP_MJ_INTERNAL_DEVICE_CONTROL ] 0x12B58 != 0xF72DD7B0 iaStor.sys
\Driver\iaStor [ IRP_MJ_POWER ] 0x17E66 != 0xF72DD7B0 iaStor.sys
\Driver\iaStor [ IRP_MJ_SYSTEM_CONTROL ] 0x17FC6 != 0xF72DD7B0 iaStor.sys
\Driver\iaStor IRP hooks detected !
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\windows\system32\RUNDLL32.EXE
c:\progra~1\HPQ\SHARED\HPQTOA~1.EXE
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-11-06 10:45 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-06 15:45
Pre-Run: 41,001,238,528 bytes free
Post-Run: 40,878,280,704 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - E163E49F73CB8C9C2725B4BEF4B16809