Hi, LDTate!
Here is my ComboFix log.
ComboFix 09-01-13.04 - Owner 2009-01-15 8:08:12.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.447.78 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComFix.exe
AV: avast! antivirus 4.8.1296 [VPS 090115-0] *On-access scanning disabled* (Updated)
AV: Spy Sweeper with AntiVirus *On-access scanning disabled* (Updated)
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2008-12-15 to 2009-01-15 )))))))))))))))))))))))))))))))
.
2009-01-14 15:27 . 2009-01-14 15:27 d——– c:\documents and settings\All Users.WINDOWS\Application Data\1035B
2009-01-13 14:48 . 2009-01-13 14:48 d——– c:\documents and settings\All Users.WINDOWS\Application Data\18232
2009-01-13 14:22 . 2009-01-13 14:23 d——– C:\ComboFix1
2009-01-13 13:25 . 2009-01-13 13:25 d——– C:\ComFx
2009-01-12 20:23 . 2008-11-07 14:23 32,000 –a—— c:\windows\system32\drivers\usbaapl.sys
2009-01-11 12:51 . 2009-01-11 12:51 d——– c:\documents and settings\All Users.WINDOWS\Application Data\17186
2009-01-11 10:10 . 2009-01-11 10:10 d——– c:\documents and settings\mike\Application Data\Apple Computer
2009-01-10 22:08 . 2009-01-10 22:08 16,832 –a—— c:\windows\system32\amcompat.tlb
2009-01-10 22:00 . 2009-01-10 22:00 d——– c:\documents and settings\All Users.WINDOWS\Application Data\26CB
2009-01-10 13:24 . 2004-08-03 13:33 4,190,352 –a—— c:\windows\system32\dllcache\luna.mst
2009-01-10 13:23 . 2004-08-03 15:56 3,166,208 –a—— c:\windows\system32\dllcache\msgr3en.dll
2009-01-10 13:22 . 2007-03-21 13:34 2,068,480 –a—— c:\windows\system32\dllcache\cdosys.dll
2009-01-10 13:21 . 2007-04-18 08:14 2,854,400 –a—— c:\windows\system32\dllcache\msi.dll
2009-01-10 13:20 . 2007-10-25 19:34 8,460,288 –a—— c:\windows\system32\dllcache\shell32.dll
2009-01-10 13:19 . 2008-09-15 04:17 1,846,912 –a—— c:\windows\system32\win32k.sys
2009-01-10 13:18 . 2008-08-14 01:57 2,185,984 –a—— c:\windows\system32\ntoskrnl.exe
2009-01-10 13:18 . 2008-08-14 01:57 2,185,984 –a—— c:\windows\system32\dllcache\ntoskrnl.exe
2009-01-10 13:18 . 2008-08-14 01:18 2,062,976 –a—— c:\windows\system32\ntkrnlpa.exe
2009-01-10 13:18 . 2008-08-14 01:18 2,062,976 –a—— c:\windows\system32\dllcache\ntkrnlpa.exe
2009-01-10 12:30 . 2009-01-10 12:30 d——– c:\documents and settings\All Users.WINDOWS\Application Data\1B290
2009-01-09 07:40 . 2009-01-09 07:40 d——– c:\documents and settings\All Users.WINDOWS\Application Data\22280
2009-01-08 21:05 . 2009-01-13 18:28 34 –a—— c:\documents and settings\mike\jagex_runescape_preferences.dat
2009-01-08 20:50 . 2009-01-08 20:50 d——– c:\documents and settings\mike\Application Data\Yahoo!
2009-01-08 20:48 . 2009-01-08 20:48 d——– c:\documents and settings\mike\Application Data\Webroot
2009-01-08 20:43 . 2009-01-13 14:39 d——– c:\documents and settings\mike
2009-01-08 20:38 . 2009-01-08 20:38 d——– c:\documents and settings\NetworkService.NT AUTHORITY\Application Data\Webroot
2009-01-08 20:38 . 2009-01-08 20:38 d——– c:\documents and settings\Administrator.OWNER-9BCB8A677
2009-01-08 18:06 . 2009-01-08 18:06 d——– c:\documents and settings\All Users.WINDOWS\Application Data\25186
2009-01-08 17:24 . 2009-01-08 17:24 d——– c:\documents and settings\All Users.WINDOWS\Application Data\7242
2009-01-07 18:55 . 2009-01-07 18:55 d——– c:\documents and settings\All Users.WINDOWS\Application Data\36213
2009-01-07 13:55 . 2009-01-07 13:55 d——– c:\documents and settings\All Users.WINDOWS\Application Data\EscapeTheMuseum
2009-01-07 13:49 . 2009-01-14 14:46 d——– c:\program files\RealArcade
2009-01-06 19:49 . 2009-01-06 19:49 d——– c:\documents and settings\All Users.WINDOWS\Application Data\10290
2009-01-06 14:18 . 2009-01-06 14:18 d——– c:\windows\system32\config\systemprofile\Application Data\PC Tools
2009-01-06 06:03 . 2009-01-06 06:03 d——– c:\documents and settings\All Users.WINDOWS\Application Data\1936B
2009-01-05 21:33 . 2009-01-05 21:33 d——– c:\documents and settings\All Users.WINDOWS\Application Data\4232
2009-01-05 19:33 . 2009-01-05 19:33 d——– c:\program files\Alwil Software
2009-01-05 19:16 . 2009-01-05 19:16 d——– c:\documents and settings\All Users.WINDOWS\Application Data\32148
2009-01-05 17:25 . 2009-01-05 17:25 d——– c:\documents and settings\All Users.WINDOWS\Application Data\20290
2009-01-05 12:18 . 2009-01-15 04:14 d——– c:\program files\Spyware Doctor
2009-01-05 12:18 . 2009-01-05 12:18 d——– c:\documents and settings\Owner\Application Data\PC Tools
2009-01-05 12:18 . 2005-09-23 07:29 626,688 –a—— c:\windows\system32\msvcr80.dll
2009-01-05 12:18 . 2009-01-06 14:53 81,288 –a—— c:\windows\system32\drivers\iksyssec.sys
2009-01-05 12:18 . 2009-01-06 14:53 66,952 –a—— c:\windows\system32\drivers\iksysflt.sys
2009-01-05 12:18 . 2009-01-06 14:53 40,840 –a—— c:\windows\system32\drivers\ikfilesec.sys
2009-01-05 12:18 . 2008-06-02 15:19 29,576 –a—— c:\windows\system32\drivers\kcom.sys
2009-01-05 12:12 . 2006-10-04 18:42 2,560 ——— c:\windows\system32\drivers\cdralw2k.sys
2009-01-05 12:12 . 2006-10-04 18:42 2,432 ——— c:\windows\system32\drivers\cdr4_xp.sys
2009-01-05 12:11 . 2009-01-06 14:14 d——– c:\program files\Picasa2
2009-01-05 12:10 . 2009-01-05 12:10 d——– c:\windows\system32\runtime
2009-01-05 09:04 . 2009-01-05 09:04 d——– c:\documents and settings\All Users.WINDOWS\Application Data\2EEA
2009-01-05 06:48 . 2009-01-05 06:48 d——– c:\documents and settings\All Users.WINDOWS\Application Data\2E138
2009-01-04 17:56 . 2009-01-04 17:56 d——– c:\documents and settings\All Users.WINDOWS\Application Data\A148
2009-01-01 10:39 . 2009-01-01 10:39 d——– c:\documents and settings\All Users.WINDOWS\Application Data\25D
2008-12-31 23:32 . 2008-12-31 23:32 d——– c:\documents and settings\All Users.WINDOWS\Application Data\14261
2008-12-31 09:23 . 2008-12-31 09:23 d——– c:\documents and settings\All Users.WINDOWS\Application Data\294E
2008-12-30 08:52 . 2008-12-30 08:52 d——– c:\documents and settings\Guest\Application Data\AOL
2008-12-29 22:46 . 2008-12-29 22:46 d——– c:\documents and settings\All Users.WINDOWS\Application Data\16100
2008-12-26 05:56 . 2008-12-26 05:56 d——– c:\documents and settings\Guest\Application Data\Apple Computer
2008-12-25 07:38 . 2008-12-25 07:38 d——– c:\documents and settings\All Users.WINDOWS\Application Data\C222
2008-12-24 21:24 . 2008-12-24 21:24 d——– c:\documents and settings\Guest\.jagex_cache_32
2008-12-24 21:24 . 2009-01-03 13:51 31 –a—— c:\documents and settings\Guest\jagex_runescape_preferences.dat
2008-12-24 17:42 . 2008-12-24 17:42 d——– c:\documents and settings\All Users.WINDOWS\Application Data\29213
2008-12-24 16:46 . 2008-12-24 16:46 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-24 16:46 . 2008-12-24 16:46 d——– c:\documents and settings\Owner\Application Data\Malwarebytes
2008-12-24 16:46 . 2008-12-24 16:46 d——– c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2008-12-24 16:46 . 2008-12-03 19:52 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-24 16:46 . 2008-12-03 19:52 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-12-24 07:57 . 2008-12-24 07:57 d——– c:\documents and settings\All Users.WINDOWS\Application Data\2F232
2008-12-24 00:11 . 2008-12-24 00:11 d——– c:\documents and settings\All Users.WINDOWS\Application Data\333A9
2008-12-23 10:03 . 2008-12-23 10:03 d——– c:\documents and settings\All Users.WINDOWS\Application Data\3833C
2008-12-23 08:30 . 2008-12-23 08:30 d——– c:\temp\google
2008-12-23 08:16 . 2008-12-23 08:19 73,728 –a—— c:\windows\system32\javacpl.cpl
2008-12-22 13:00 . 2008-12-22 13:00 d——– C:\Google
2008-12-22 12:59 . 2008-12-22 12:59 d——– C:\CyberLink PowerDVD
2008-12-22 12:54 . 2008-12-22 12:54 d——– c:\documents and settings\All Users.WINDOWS\Application Data\11157
2008-12-22 12:38 . 2008-12-22 12:38 d——– c:\documents and settings\All Users.WINDOWS\Application Data\137A
2008-12-22 09:36 . 2008-12-22 09:36 d——– c:\documents and settings\Guest\Application Data\Yahoo!
2008-12-22 09:33 . 2008-12-22 09:33 d——– c:\documents and settings\Guest\Application Data\Webroot
2008-12-22 09:31 . 2009-01-05 13:22 d——– c:\documents and settings\Guest
2008-12-20 19:36 . 2008-12-22 10:01 d——– C:\.jagex_cache_32
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-15 12:10 ——— d—a-w c:\documents and settings\All Users.WINDOWS\Application Data\TEMP
2009-01-15 11:09 ——— d—–w c:\documents and settings\All Users.WINDOWS\Application Data\Google Updater
2009-01-13 05:04 31 —-a-w c:\documents and settings\Owner\jagex_runescape_preferences.dat
2009-01-13 04:29 ——— d—–w c:\program files\Apple Software Update
2009-01-11 02:37 ——— d—–w c:\program files\Common Files\Wise Installation Wizard
2009-01-05 20:16 ——— d—–w c:\program files\Google
2009-01-01 19:06 ——— d—–w c:\program files\Trend Micro
2008-12-25 01:05 ——— d—–w c:\program files\My.Freeze.com Toolbar with NetAssistant
2008-12-24 09:10 ——— d—–w c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft Help
2008-12-23 19:09 ——— d—–w c:\documents and settings\Owner\Application Data\OOo-dev2
2008-12-23 15:30 ——— d—–w c:\program files\Java
2008-12-09 18:14 ——— d—–w c:\documents and settings\All Users.WINDOWS\Application Data\1933C
2008-12-09 17:34 ——— d—–w c:\documents and settings\All Users.WINDOWS\Application Data\93A9
2008-12-09 02:25 ——— d—–w c:\documents and settings\All Users.WINDOWS\Application Data\CF
2008-12-06 07:53 ——— d—–w c:\documents and settings\All Users.WINDOWS\Application Data\F251
2008-12-03 05:59 ——— d—–w c:\documents and settings\Owner\Application Data\LimeWire
2008-12-01 22:32 ——— d—–w c:\program files\Acoustica Shared Effects
2008-12-01 14:46 ——— d—–w c:\documents and settings\All Users.WINDOWS\Application Data\70
2008-12-01 06:33 ——— d—–w c:\program files\LimeWire
2008-12-01 05:38 ——— d—–w c:\documents and settings\All Users.WINDOWS\Application Data\21F
2008-11-28 16:44 ——— d—–w c:\documents and settings\All Users.WINDOWS\Application Data\31251
2008-11-27 23:29 ——— d—–w c:\documents and settings\All Users.WINDOWS\Application Data\2A213
2008-11-24 17:15 ——— d—–w c:\program files\Microsoft ActiveSync
2008-11-21 14:36 ——— d—–w c:\program files\Master of Defense
2008-11-21 14:35 ——— d—–w c:\program files\Mahjong Mania Deluxe
2008-11-19 12:55 ——— d—–w c:\program files\Acoustica Mixcraft 4
2008-03-03 16:40 0 —-a-w c:\program files\temp01
2007-08-05 07:05 774,144 —-a-w c:\program files\RngInterstitial.dll
2007-03-22 07:04 496 —-a-w c:\program files\Common Files\qufax
2007-03-01 14:53 142 —-a-w c:\program files\Common Files\rtenem.html
2008-12-18 21:50 122,880 —-a-w c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2007-12-23 19:36 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012007122320071224\index.dat
.
((((((((((((((((((((((((((((( snapshot@2009-01-11_10.20.11.29 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-01-11 16:35:31 315,392 —-a-w c:\windows\.jagex_cache_32\runescape\jogl.dll
+ 2009-01-14 00:45:49 315,392 —-a-w c:\windows\.jagex_cache_32\runescape\jogl.dll
- 2009-01-11 16:35:32 20,480 —-a-w c:\windows\.jagex_cache_32\runescape\jogl_awt.dll
+ 2009-01-14 00:45:50 20,480 —-a-w c:\windows\.jagex_cache_32\runescape\jogl_awt.dll
+ 2009-01-13 04:29:49 27,136 —-a-r c:\windows\Installer\{6956856F-B6B3-4BE0-BA0B-8F495BE32033}\AppleSoftwareUpdateIco.exe
- 2000-08-31 16:00:00 28,672 —-a-w c:\windows\NIRCMD.exe
+ 2000-08-31 16:00:00 29,696 —-a-w c:\windows\NIRCMD.exe
- 2009-01-10 02:18:34 16,384 –sha-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-01-12 08:06:39 16,384 –sha-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-01-10 02:18:34 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-01-12 08:06:39 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-01-10 02:18:34 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-01-12 08:06:39 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-11-07 22:23:30 32,000 -c–a-w c:\windows\system32\DRVSTORE\usbaapl_246F92BBD6449C86FC3F3F28C40D59AC1F69C558\usbaapl.sys
+ 2004-08-03 22:08:48 26,496 —-a-w c:\windows\system32\ReinstallBackups\
0004\DriverFiles\i386\USBSTOR.SYS
+ 2009-01-14 23:24:48 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_4f0.dat
+ 2009-01-14 23:24:42 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_640.dat
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—-a-w 61,440 2005-02-03 00:44:24 c:\hp\KBD\bak\KBD.EXE
—-a-w 61,440 2003-02-12 03:02:48 c:\hp\KBD\kbd.exe
—-a-w 1,343,488 2006-04-07 22:02:24 c:\program files\AWS\WeatherBug\bak\Weather.exe
—-a-r 1,654,784 2007-06-14 17:28:32 c:\program files\AWS\WeatherBug\Weather.exe
—-a-w 180,269 2004-08-12 03:52:37 c:\program files\Common Files\Real\Update_OB\bak\realsched.exe
—-a-w 120,320 2006-07-16 21:01:46 c:\program files\Google\Google Desktop Search\bak\GoogleDesktop.exe
—-a-w 29,744 2008-12-18 21:50:02 c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
—-a-w 49,152 2005-05-12 07:12:54 c:\program files\HP\HP Software Update\bak\HPWuSchd2.exe
—-a-w 49,152 2005-05-12 06:12:54 c:\program files\HP\HP Software Update\hpwuSchd2.exe
—-a-w 49,152 2004-06-08 01:53:26 c:\program files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\bak\hphupd06.exe
—-a-w 49,152 2004-06-08 01:53:26 c:\program files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
—-a-w 286,720 2004-04-22 01:28:18 c:\program files\iTunes\bak\iTunesHelper.exe
—-a-w 267,048 2007-11-15 21:11:04 c:\program files\iTunes\iTunesHelper.exe
—-a-w 32,881 2004-08-12 02:36:13 c:\program files\Java\j2re1.4.2_03\bin\bak\jusched.exe
—-a-w 49,263 2006-10-12 11:10:54 c:\program files\Java\jre1.5.0_09\bin\bak\jusched.exe
—-a-w 32,768 2007-01-20 15:18:47 c:\program files\Logitech\Desktop Messenger\8876480\Program\bak\LogitechDesktopMessenger.exe
—-a-w 1,207,080 2006-06-21 06:36:22 c:\program files\Microsoft ActiveSync\bak\wcescomm.exe
—-a-w 1,207,080 2006-06-21 06:36:22 c:\program files\Microsoft ActiveSync\wcescomm.exe
—-a-w 53,248 2005-07-19 18:05:32 c:\program files\MUSICMATCH\Musicmatch Jukebox\bak\mmtask.exe
—-a-w 135,168 2005-07-19 18:05:32 c:\program files\MUSICMATCH\Musicmatch Jukebox\bak\mm_tray.exe
—-a-w 98,304 2004-08-12 04:08:01 c:\program files\QuickTime\bak\qttask.exe
—-a-w 286,720 2007-11-15 07:43:10 c:\program files\QuickTime\QTTask.exe
—-a-w 3,096,576 2005-12-08 21:55:10 c:\program files\Yahoo!\Messenger\bak\ypager.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{E38FA08E-F56A-4169-ABF5-5C71E3C153A1}"= "c:\program files\My.Freeze.com Toolbar with NetAssistant\NetAssistant.dll" [2008-10-01 253048]
[HKEY_CLASSES_ROOT\clsid\{e38fa08e-f56a-4169-abf5-5c71e3c153a1}]
[HKEY_CLASSES_ROOT\NetAssistant.NetAssistantBHO.1]
[HKEY_CLASSES_ROOT\TypeLib\{1E8FC16F-4C51-49C4-BC9B-4FC24BDDCEE7}]
[HKEY_CLASSES_ROOT\NetAssistant.NetAssistantBHO]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E38FA08E-F56A-4169-ABF5-5C71E3C153A1}]
2008-10-01 12:02 253048 –a—— c:\program files\My.Freeze.com Toolbar with NetAssistant\NetAssistant.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D0523BB4-21E7-11DD-9AB7-415B56D89593}"= "c:\program files\My.Freeze.com Toolbar with NetAssistant\freeze_us.dll" [2008-10-01 1916024]
[HKEY_CLASSES_ROOT\clsid\{d0523bb4-21e7-11dd-9ab7-415b56d89593}]
[HKEY_CLASSES_ROOT\TBSB00001.TBSB00001.3]
[HKEY_CLASSES_ROOT\TypeLib\{77AA25E8-6083-4949-A831-9CB11861DC10}]
[HKEY_CLASSES_ROOT\TBSB00001.TBSB00001]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D0523BB4-21E7-11DD-9AB7-415B56D89593}"= "c:\program files\My.Freeze.com Toolbar with NetAssistant\freeze_us.dll" [2008-10-01 1916024]
[HKEY_CLASSES_ROOT\clsid\{d0523bb4-21e7-11dd-9ab7-415b56d89593}]
[HKEY_CLASSES_ROOT\TBSB00001.TBSB00001.3]
[HKEY_CLASSES_ROOT\TypeLib\{77AA25E8-6083-4949-A831-9CB11861DC10}]
[HKEY_CLASSES_ROOT\TBSB00001.TBSB00001]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2006-10-24 4662776]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-06-20 1207080]
"VibeFireAlerts"="c:\program files\W3i\VibeFire\VibeFire.exe" [2008-10-21 552960]
"AROReminder"="c:\program files\Advanced Registry Optimizer\aro.exe" [2008-04-09 2084480]
"BearShare"="c:\program files\BearShare Applications\BearShare\BearShare.exe" [2008-11-19 13137336]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-16 68856]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2007-03-21 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 49152]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-12-06 69216]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 54832]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-11-14 286720]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-11-15 267048]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-12-18 29744]
"G2"="c:\program files\GamingSquared\Gaming2\G2.exe" [2008-03-03 1215664]
"HostManager"="c:\program files\Common Files\AOL\1221064064\ee\AOLSoftware.exe" [2006-09-25 50736]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"Synchronization Manager"="c:\windows\system32\mobsync.exe" [2004-08-03 143360]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-23 136600]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2009-01-06 1168264]
"SpySweeper"="c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2007-10-01 5367608]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 c:\windows\ALCXMNTR.EXE]
"VTTimer"="VTTimer.exe" [2004-03-26 c:\windows\system32\VTTimer.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 c:\windows\AGRSMMSG.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2007-12-18 8720384]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-08-24 437160]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]
"IE7-11"="advpack.dll" [2008-10-16 c:\windows\system32\advpack.dll]
c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 282624]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Morpheus\\Morpheus.exe"=
"c:\\Program Files\\PopCap Games\\Typer Shark Deluxe\\WinTS.exe"=
"c:\\Program Files\\Yahoo! Games\\Spelvin\\Spelvin_Yahoo.exe"=
"c:\\Program Files\\GameHouse\\WildWords\\wwwords.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\GameHouse\\Combo Chaos\\ComboChaos.exe"=
"c:\\Program Files\\Yahoo! Games\\Word Whomp To Go\\WordWhompToGo.exe"=
"c:\\Program Files\\FreshGames\\Word Mojo Gold\\WordMojoGold.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\1221064064\\ee\\aolsoftware.exe"=
"c:\\Program Files\\AOL 9.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"c:\\Program Files\\AOL 9.0a\\waol.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\BearShare applications\\BearShare\\BearShare.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-01-05 111184]
R4 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};c:\program files\CyberLink\PowerDVD\
000.fcl [2007-12-23 12:09:56 13560]
R4 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-01-05 20560]
R4 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2009-01-06 356920]
R4 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2008-01-17 29744]
— Other Services/Drivers In Memory —
*Deregistered* - mchInjDrv
.
Contents of the 'Scheduled Tasks' folder
2009-01-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2009-01-15 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-01-05 12:07]
2009-01-15 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
2009-01-14 c:\windows\Tasks\PCConfidential.job
- c:\program files\Winferno\PC Confidential\PCConfidential.exe [2008-04-01 14:10]
2009-01-09 c:\windows\Tasks\rpc.job
- c:\program files\Winferno\RegistryPowerCleaner\RegPowerClean.exe [2007-04-12 14:24]
2009-01-15 c:\windows\Tasks\wrSpySweeper_L8B0EAA2945E94C509FCB612134EAB2AA.job
- c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe [2007-10-01 16:40]
2009-01-15 c:\windows\Tasks\wrSpySweeper_L8B0EAA2945E94C509FCB612134EAB2AA.job
- c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe [2007-10-01 16:40]
2009-01-15 c:\windows\Tasks\wrSpySweeper_L8B0EAA2945E94C509FCB612134EAB2AA.job
- c:\","e:\","f:\","g:\","h:\","i:\","J:\" []
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
IE: &Search
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-15 08:20:11
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4c74-92FE-5B863F82066B}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD\
000.fcl"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(696)
c:\windows\system32\WRLogonNTF.dll
.
Completion time: 2009-01-15 8:32:17
ComboFix-quarantined-files.txt 2009-01-15 16:32:05
ComboFix2.txt 2009-01-11 18:41:44
Pre-Run: 13,281,099,776 bytes free
Post-Run: 13,500,190,720 bytes free
344 — E O F — 2009-01-10 22:47:41