Thanks for all the help so far. Computer seems to be running very smoothly now. Here is ComboFix log:
ComboFix 10-06-10.03 - Administrator 06/11/2010 0:24.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3063.2723 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
ADS - explorer.exe: deleted 88 bytes in 2 streams.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\AVSredirect.dll
.
((((((((((((((((((((((((( Files Created from 2010-05-11 to 2010-06-11 )))))))))))))))))))))))))))))))
.
2010-06-10 05:21 . 2010-06-10 05:21 721904 —-a-w- c:\windows\system32\drivers\sptd.sys
2010-06-10 05:20 . 2009-03-02 18:00 95592 —-a-w- c:\windows\system32\drivers\StarPortLite.sys
2010-06-10 05:08 . 2010-06-10 05:08 158192 ——w- c:\windows\system32\pxwma.dll
2010-06-10 03:36 . 2010-06-10 03:36 ——– d—–w- c:\documents and settings\Administrator\Application Data\ElevatedDiagnostics
2010-06-09 22:28 . 2010-06-09 22:28 ——– d—–w- c:\program files\ESET
2010-06-09 19:36 . 2010-06-09 19:36 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-06-09 19:36 . 2010-04-29 19:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-09 19:36 . 2010-06-09 19:36 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-06-09 19:36 . 2010-06-09 19:36 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-09 19:36 . 2010-04-29 19:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-06-09 05:12 . 2010-05-06 10:41 743424 -c—-w- c:\windows\system32\dllcache\iedvtool.dll
2010-06-09 02:48 . 2010-06-09 02:48 388096 —-a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-06-09 02:48 . 2010-06-09 02:48 ——– d—–w- c:\program files\Trend Micro
2010-06-08 01:49 . 2010-06-08 01:49 63488 —-a-w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-06-08 01:49 . 2010-06-08 01:49 52224 —-a-w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-06-08 01:49 . 2010-06-08 01:49 117760 —-a-w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-06-08 01:48 . 2010-06-08 01:48 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-06-08 01:48 . 2010-06-08 01:48 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-06-07 01:28 . 2010-06-07 01:28 ——– d–h–w- c:\windows\system32\GroupPolicy
2010-06-06 22:35 . 2010-06-06 22:35 ——– d—–w- c:\documents and settings\Administrator\Application Data\IObit
2010-06-06 22:35 . 2010-06-06 22:35 ——– d—–w- c:\program files\IObit
2010-06-06 20:16 . 2010-06-06 20:16 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Netscape
2010-06-06 20:16 . 2010-06-06 20:16 ——– d—–w- c:\documents and settings\Administrator\Application Data\Netscape
2010-06-06 20:16 . 2010-06-06 20:16 ——– d—–w- c:\program files\Netscape
2010-06-04 01:09 . 2008-10-15 09:09 ——– d—–w- C:\xpadder_gamepad_profiler
2010-06-02 21:42 . 2010-06-02 21:42 ——– d—–w- c:\program files\Common Files\Gibinsoft Shared
2010-06-02 21:42 . 2010-06-02 21:42 ——– d—–w- c:\program files\GiPo@Utilities
2010-06-02 18:06 . 2010-06-02 18:06 ——– d—–w- c:\program files\RocketDock
2010-06-02 15:15 . 2010-06-02 16:30 ——– d—–w- c:\documents and settings\Administrator\Application Data\Dexpot
2010-06-02 14:32 . 2010-06-02 14:32 ——– d—–w- c:\documents and settings\Administrator\Application Data\maComfort
2010-06-02 14:32 . 2010-06-02 17:15 ——– d—–w- c:\program files\maComfort
2010-06-02 04:27 . 2010-06-02 04:47 ——– d—–w- c:\documents and settings\Administrator\Application Data\Auslogics
2010-06-02 03:15 . 2010-06-02 04:33 ——– d—–w- C:\shman
2010-06-02 02:15 . 2010-06-10 05:49 ——– d—–w- c:\program files\Auslogics
2010-05-30 14:26 . 2010-05-30 14:26 ——– d—–w- c:\windows\Downloaded Installations
2010-05-30 00:32 . 2010-05-30 00:34 ——– d—–w- c:\documents and settings\Administrator\Application Data\EstSoft
2010-05-30 00:32 . 2010-05-30 00:42 ——– d—–w- c:\program files\ESTsoft
2010-05-29 20:29 . 2010-05-29 20:29 ——– d—–w- c:\documents and settings\All Users\Application Data\Innovative Solutions
2010-05-29 20:29 . 2010-05-29 20:29 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Innovative Solutions
2010-05-29 20:29 . 2010-05-29 20:29 ——– d—–w- c:\program files\Innovative Solutions
2010-05-29 14:10 . 2010-05-29 14:10 ——– d—–w- c:\documents and settings\All Users\Application Data\NCH Software
2010-05-29 14:10 . 2010-05-29 14:10 ——– d—–w- c:\documents and settings\Administrator\Application Data\NCH Software
2010-05-29 14:10 . 2010-05-29 14:10 ——– d—–w- c:\program files\NCH Software
2010-05-29 13:29 . 2010-05-29 13:55 ——– d—–w- c:\program files\VLMC
2010-05-29 11:40 . 2010-05-29 11:40 ——– d—–w- c:\program files\Sonic Foundry
2010-05-29 11:39 . 2010-05-29 11:51 ——– d—–w- c:\program files\DebugMode
2010-05-29 10:33 . 2004-02-22 14:11 719872 —-a-w- c:\windows\system32\devil.dll
2010-05-29 10:33 . 2009-09-27 13:39 369152 —-a-w- c:\windows\system32\avisynth.dll
2010-05-29 10:33 . 2004-01-25 04:00 70656 —-a-w- c:\windows\system32\yv12vfw.dll
2010-05-29 10:33 . 2004-01-25 04:00 70656 —-a-w- c:\windows\system32\i420vfw.dll
2010-05-29 10:33 . 2010-05-29 10:33 ——– d—–w- c:\program files\AviSynth 2.5
2010-05-29 10:32 . 2008-03-16 12:30 216064 –sh–r- c:\windows\system32\nbDX.dll
2010-05-29 10:32 . 2007-02-21 10:47 31232 –sh–r- c:\windows\system32\msfDX.dll
2010-05-29 10:32 . 2006-05-03 09:06 163328 –sh–r- c:\windows\system32\flvDX.dll
2010-05-29 10:32 . 2010-05-29 10:32 ——– d—–w- c:\program files\eRightSoft
2010-05-23 07:30 . 2010-05-23 07:30 503808 —-a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-2fbeba8c-n\msvcp71.dll
2010-05-23 07:29 . 2010-05-23 07:29 499712 —-a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-2fbeba8c-n\jmc.dll
2010-05-23 07:29 . 2010-05-23 07:29 12800 —-a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-4094cbbe-n\decora-d3d.dll
2010-05-23 07:29 . 2010-05-23 07:29 61440 —-a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-4094cbbe-n\decora-sse.dll
2010-05-23 07:29 . 2010-05-23 07:29 348160 —-a-w- c:\documents and settings\Administrator\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-2fbeba8c-n\msvcr71.dll
2010-05-18 02:33 . 2010-05-18 02:34 ——– d—–w- c:\program files\MPC HomeCinema
2010-05-18 00:47 . 2010-05-18 00:47 ——– d—–w- c:\program files\Xvid
2010-05-18 00:47 . 2009-06-07 20:24 180224 —-a-w- c:\windows\system32\xvidvfw.dll
2010-05-18 00:47 . 2009-06-07 20:16 819200 —-a-w- c:\windows\system32\xvidcore.dll
2010-05-18 00:36 . 2010-05-18 00:36 ——– d—–w- c:\program files\XP Codec Pack
2010-05-18 00:22 . 2010-05-18 00:22 ——– d—–w- c:\documents and settings\Administrator\Application Data\Media Player Classic
2010-05-18 00:12 . 2010-05-18 00:12 ——– d—–w- c:\program files\Haali
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-11 03:09 . 2009-11-20 16:08 1 —-a-w- c:\documents and settings\Administrator\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-06-10 23:41 . 2009-11-19 08:40 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-06-10 07:57 . 2009-12-17 08:06 ——– d—–w- c:\program files\Oldgames
2010-06-09 13:56 . 2009-11-19 16:45 ——– d—–w- c:\documents and settings\Administrator\Application Data\BitTorrent
2010-06-08 01:48 . 2009-12-20 21:06 ——– d—–w- c:\documents and settings\Administrator\Application Data\SUPERAntiSpyware.com
2010-06-05 17:57 . 2009-11-18 22:41 ——– d—–w- c:\program files\IrfanView
2010-06-04 09:09 . 2004-08-04 10:00 1033728 —-a-w- c:\windows\explorer.exe
2010-06-03 20:44 . 2004-08-04 10:00 218624 —-a-w- c:\windows\system32\uxtheme.dll
2010-06-03 14:10 . 2009-11-27 22:06 2316 —-a-w- c:\documents and settings\All Users\Application Data\xml9F.tmp
2010-06-03 14:10 . 2010-05-25 23:03 13757 —-a-w- c:\documents and settings\All Users\Application Data\xml31.tmp
2010-06-03 14:10 . 2009-11-27 22:06 9521 —-a-w- c:\documents and settings\All Users\Application Data\xml9D.tmp
2010-05-31 07:39 . 2010-03-01 06:32 ——– d—–w- c:\program files\Bible Explorer 4
2010-05-29 22:18 . 2010-01-09 02:48 ——– d—–w- c:\documents and settings\All Users\Application Data\DriverScanner
2010-05-29 22:18 . 2010-01-09 02:48 ——– d—–w- c:\documents and settings\Administrator\Application Data\Uniblue
2010-05-29 15:04 . 2010-03-18 12:46 439816 —-a-w- c:\documents and settings\Administrator\Application Data\Real\Update\setup3.10\setup.exe
2010-05-26 04:50 . 2009-11-19 09:18 ——– d—–w- c:\program files\Common Files\Adobe
2010-05-09 01:33 . 2009-11-18 22:41 ——– d—–w- c:\program files\Google
2010-05-06 23:50 . 2009-11-19 09:48 ——– d—–w- c:\program files\Java
2010-05-06 20:59 . 2010-04-29 04:10 165032 —-a-w- c:\windows\system32\aswBoot.exe
2010-05-06 20:39 . 2010-04-29 04:10 46672 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2010-05-06 20:39 . 2010-04-29 04:10 164048 —-a-w- c:\windows\system32\drivers\aswSP.sys
2010-05-06 20:34 . 2010-04-29 04:10 23376 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2010-05-06 20:33 . 2010-04-29 04:10 100432 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2010-05-06 20:33 . 2010-04-29 04:10 94800 —-a-w- c:\windows\system32\drivers\aswmon.sys
2010-05-06 20:33 . 2010-04-29 04:10 19024 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-05-06 20:33 . 2010-04-29 04:10 28880 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2010-05-06 10:41 . 2006-03-04 03:33 916480 —-a-w- c:\windows\system32\wininet.dll
2010-05-04 16:21 . 2010-05-04 16:21 ——– d—–w- c:\documents and settings\Administrator\Application Data\Unity
2010-05-02 05:22 . 2004-08-04 10:00 1851264 —-a-w- c:\windows\system32\win32k.sys
2010-04-29 04:10 . 2010-04-29 04:10 ——– d—–w- c:\program files\Alwil Software
2010-04-29 04:10 . 2010-04-29 04:10 ——– d—–w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-04-25 19:36 . 2010-04-25 09:35 ——– d—–w- c:\program files\EA SPORTS
2010-04-25 09:38 . 2010-04-25 09:37 ——– d—–w- c:\program files\EACOM
2010-04-25 09:38 . 2008-08-14 19:27 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-04-25 09:38 . 2010-04-25 09:38 474 —-a-w- c:\windows\eReg.dat
2010-04-25 09:11 . 2010-04-24 23:46 ——– d—–w- c:\program files\DOSBox-0.72
2010-04-20 05:30 . 2004-08-04 10:00 285696 —-a-w- c:\windows\system32\atmfd.dll
2010-04-14 16:47 . 2010-04-29 04:10 38848 —-a-w- c:\windows\system32\avastSS.scr
2010-04-12 21:29 . 2010-05-06 23:50 411368 —-a-w- c:\windows\system32\deployJava1.dll
2010-03-15 03:17 . 2006-06-26 06:05 72864 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2006-05-03 09:06 . 2010-05-29 10:32 163328 –sh–r- c:\windows\system32\flvDX.dll
2007-02-21 10:47 . 2010-05-29 10:32 31232 –sh–r- c:\windows\system32\msfDX.dll
2008-03-16 12:30 . 2010-05-29 10:32 216064 –sh–r- c:\windows\system32\nbDX.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-11-18 39408]
"Weather"="c:\program files\AWS\WeatherBug\Weather.exe" [2009-10-20 1693184]
"ftweak_RAMRush"="c:\program files\RAMRush\RAMRush.exe" [2009-09-17 670720]
"ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2009-12-21 1803064]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-05-18 2397424]
"FBackup Scheduler"="c:\program files\Softland\FBackup 4\fbaSched.exe" [2010-05-18 2015056]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTHelper"="CTHELPER.EXE" [2006-12-12 19456]
"CTxfiHlp"="CTXFIHLP.EXE" [2006-12-12 20480]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-12-18 198160]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-05-06 2815192]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite 2010\\RpcAgentSrv.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite 2010\\WNt500x86\\sandra.mui"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite 2010\\WNt500x86\\RpcSandraSrv.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [4/29/2010 12:10 AM 164048]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 2:25 PM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 2:41 PM 67656]
R1 StarPortLite;StarPort Storage Controller (Lite);c:\windows\system32\drivers\StarPortLite.sys [6/10/2010 1:20 AM 95592]
R1 VBoxDrv;VirtualBox Service;c:\windows\system32\drivers\VBoxDrv.sys [12/11/2009 8:56 PM 123280]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\drivers\VBoxUSBMon.sys [12/11/2009 8:49 PM 41616]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4/29/2010 12:10 AM 19024]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [11/30/2009 1:27 PM 100048]
R3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\drivers\VBoxNetFlt.sys [11/30/2009 1:27 PM 110992]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [6/10/2010 1:21 AM 721904]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1/29/2010 3:17 AM 135664]
S3 SandraAgentSrv;SiSoftware Deployment Agent Service;c:\program files\SiSoftware\SiSoftware Sandra Lite 2010\RpcAgentSrv.exe [11/27/2009 6:02 PM 93336]
.
Contents of the 'Scheduled Tasks' folder
2010-06-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2010-06-08 c:\windows\Tasks\Defraggler Volume C Task.job
- c:\program files\Defraggler\df.exe [2009-12-02 17:37]
2010-06-09 c:\windows\Tasks\Defraggler Volume E Task.job
- c:\program files\Defraggler\df.exe [2009-12-02 17:37]
2010-06-10 c:\windows\Tasks\fba_Productivity Files.job
- c:\program files\Softland\FBackup 4\fbaSchedStarter.exe [2009-11-19 13:01]
2010-06-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 07:17]
2010-06-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 07:17]
2010-06-11 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2010-06-06 16:57]
2010-06-11 c:\windows\Tasks\User_Feed_Synchronization-{E0311074-F1C8-40DA-AE5A-33A049AF1E74}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 09:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://astrocomputers.net/
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\4s87tle8.default\
FF - prefs.js: browser.startup.homepage - hxxp://astrocomputers.net/
FF - prefs.js: browser.search.selectedEngine - GoogleFeed.net
FF - prefs.js: browser.startup.homepage - hxxp://www.google-feed.net/?CID=1&PID=StarBurn
FF - plugin: c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\4s87tle8.default\extensions\[removed]\plugins\npTVUAx.dll
FF - plugin: c:\documents and settings\Administrator\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\Opera\program\plugins\NPQNXWrap.dll
FF - plugin: c:\program files\Opera\program\plugins\npsnpy.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-DriverMax_RESTART - (no file)
HKCU-Run-Cookienator - c:\program files\Cookienator\cookienator.exe
AddRemove-UnityWebPlayer - c:\documents and settings\Administrator\Local Settings\Application Data\Unity\WebPlayer\Uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-06-11 00:30
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTHelper = CTHELPER.EXE?
CTxfiHlp = CTXFIHLP.EXE?
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-1715567821-2146905285-682003330-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ca,b7,4f,25,be,03,af,4c,91,2f,6e,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,d9,cb,c2,14,57,e0,84,4f,80,4d,15,\
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1012)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
Completion time: 2010-06-11 00:33:37
ComboFix-quarantined-files.txt 2010-06-11 04:33
Pre-Run: 123,977,760,768 bytes free
Post-Run: 123,956,060,160 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 286B02AC49187458193459CACC784B50