I could not find c:\documents and settings\annette gagnon.annette-shnkr5u\local settings\application data\ajlmmsjvd.exe but i did find it in the _OTMoveIt/moved files is that a good thing? I tried to put it on that site but it wouldn't load up, I did the other scan though and here it is
ComboFix 08-05-15.3 - Annette Gagnon 2008-05-16 21:44:54.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.155 [GMT -7:00]
Running from: C:\Documents and Settings\Annette Gagnon.ANNETTE-SHNKR5U\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Annette Gagnon.ANNETTE-SHNKR5U\Application Data\FunWebProducts
C:\Documents and Settings\Annette Gagnon.ANNETTE-SHNKR5U\Application Data\MessengerSkinner
C:\Documents and Settings\Annette Gagnon.ANNETTE-SHNKR5U\Application Data\MessengerSkinner\Userdata\languages_v2.xml
C:\Documents and Settings\Annette Gagnon.ANNETTE-SHNKR5U\Local Settings\Application Data\ajlmmsjvd.dat
c:\Documents and Settings\Annette Gagnon.ANNETTE-SHNKR5U\Local Settings\Application Data\ajlmmsjvd_nav.dat
C:\Documents and Settings\Annette Gagnon.ANNETTE-SHNKR5U\Local Settings\Application Data\ajlmmsjvd_navps.dat
C:\Documents and Settings\Annette Gagnon.ANNETTE-SHNKR5U\Local Settings\Application Data\kqxnsedb.dat
C:\Documents and Settings\Annette Gagnon.ANNETTE-SHNKR5U\Local Settings\Application Data\kqxnsedb_nav.dat
C:\Documents and Settings\Annette Gagnon.ANNETTE-SHNKR5U\Local Settings\Application Data\kqxnsedb_navps.dat
C:\Documents and Settings\Annette Gagnon.ANNETTE-SHNKR5U\Start Menu\Programs\MessengerSkinner
C:\Documents and Settings\Annette Gagnon.ANNETTE-SHNKR5U\Start Menu\Programs\MessengerSkinner\MessengerSkinner.lnk
C:\Documents and Settings\Annette Gagnon\Application Data\FunWebProducts
C:\Documents and Settings\Annette Gagnon\Application Data\FunWebProducts\Data\Annette Gagnon\wffavs.dat
C:\WINDOWS\system32\rxbuwscvp.dat
C:\WINDOWS\system32\rxbuwscvp_navtmp.dat
.
((((((((((((((((((((((((( Files Created from 2008-04-17 to 2008-05-17 )))))))))))))))))))))))))))))))
.
2008-05-16 15:35 . 2008-05-16 15:35 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-16 15:35 . 2008-05-16 15:35 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Kaspersky Lab
2008-05-16 06:16 . 2008-05-16 06:16 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-16 06:16 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-16 06:16 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-05-15 06:19 . 2008-05-15 06:19 <DIR> d-------- C:\_OTMoveIt
2008-05-14 15:44 . 2008-05-14 15:44 <DIR> d-------- C:\Deckard
2008-05-12 18:11 . 2008-05-12 18:12 <DIR> d-------- C:\Program Files\Panda Security
2008-05-12 18:01 . 2008-05-12 18:01 <DIR> d-------- C:\Documents and Settings\Administrator.ANNETTE-SHNKR5U
2008-05-12 18:01 . 2008-05-16 21:44 1,024 --ah----- C:\Documents and Settings\Administrator.ANNETTE-SHNKR5U\NTUSER.DAT.LOG
2008-05-09 23:17 . 2008-05-14 17:52 <DIR> d--h----- C:\$AVG8.VAULT$
2008-05-09 22:30 . 2008-04-13 17:11 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2008-05-09 22:30 . 2008-04-13 17:11 21,504 --a--c--- C:\WINDOWS\system32\dllcache\hidserv.dll
2008-05-09 22:13 . 2008-05-09 22:13 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-09 22:01 . 2008-05-16 06:13 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-05-09 22:01 . 2008-05-09 22:01 <DIR> d-------- C:\Program Files\AVG
2008-05-09 22:01 . 2008-05-09 22:01 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\avg8
2008-05-09 22:01 . 2008-05-09 22:01 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-05-09 22:01 . 2008-05-09 22:01 75,272 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-05-09 22:01 . 2008-05-09 22:01 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-05-09 21:34 . 2008-05-09 21:34 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-05-09 21:34 . 2008-05-09 21:34 <DIR> d-------- C:\WINDOWS\system32\en
2008-05-09 21:34 . 2008-05-09 21:34 <DIR> d-------- C:\WINDOWS\l2schemas
2008-05-09 21:13 . 2008-04-13 17:12 1,306,624 -----c--- C:\WINDOWS\system32\dllcache\msxml6.dll
2008-05-09 21:12 . 2008-04-13 17:11 650,752 --------- C:\WINDOWS\system32\dot3ui.dll
2008-05-09 21:11 . 2008-04-13 17:11 136,192 --------- C:\WINDOWS\system32\aaclient.dll
2008-05-09 18:17 . 2008-05-09 18:17 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\SUPERAntiSpyware.com
2008-05-09 18:16 . 2008-05-09 21:58 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-05-09 18:16 . 2008-05-09 21:58 <DIR> d-------- C:\Documents and Settings\Annette Gagnon.ANNETTE-SHNKR5U\Application Data\SUPERAntiSpyware.com
2008-05-09 16:29 . 2008-05-09 16:29 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-05-09 16:29 . 2008-05-09 16:29 <DIR> d-------- C:\Documents and Settings\Annette Gagnon.ANNETTE-SHNKR5U\Application Data\Malwarebytes
2008-05-09 16:29 . 2008-05-09 16:29 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes
2008-05-09 16:19 . 2008-05-16 21:44 1,024 --ah----- C:\WINDOWS\system32\config\systemprofile\ntuser.dat.LOG
2008-05-06 16:44 . 2008-05-06 16:44 <DIR> d-------- C:\Documents and Settings\Annette Gagnon.ANNETTE-SHNKR5U\Application Data\Application Data
2008-05-06 16:44 . 2008-05-06 16:44 <DIR> d-------- C:\Documents and Settings\Annette Gagnon.ANNETTE-SHNKR5U\Annette Gagnon.ANNETTE-SHNKR5U
2008-05-04 17:43 . 2008-05-16 21:56 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-05-04 17:43 . 2008-05-04 17:43 1,409 --a------ C:\WINDOWS\QTFont.for
2008-05-04 17:17 . 2008-05-04 17:17 <DIR> d-------- C:\Application Data
2008-05-03 16:57 . 2008-05-03 19:26 <DIR> d-------- C:\Documents and Settings\Annette Gagnon.ANNETTE-SHNKR5U\Application Data\Apple Computer
2008-05-03 16:56 . 2008-05-03 16:57 <DIR> d-------- C:\Program Files\iTunes
2008-05-03 16:56 . 2008-05-03 16:56 <DIR> d-------- C:\Program Files\iPod
2008-05-03 16:54 . 2008-05-03 16:55 <DIR> d-------- C:\Program Files\QuickTime
2008-05-03 16:54 . 2008-05-03 16:56 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Apple Computer
2008-05-03 16:53 . 2008-05-03 16:53 <DIR> d-------- C:\Program Files\Common Files\Apple
2008-05-03 16:53 . 2008-05-03 16:54 <DIR> d-------- C:\Program Files\Apple Software Update
2008-05-03 16:53 . 2008-05-03 16:53 <DIR> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Apple
2008-04-30 16:37 . 2008-04-30 16:37 <DIR> d-------- C:\Program Files\ReflexiveArcade
2008-04-30 16:37 . 2008-05-09 18:01 <DIR> d-------- C:\Program Files\Cubis Gold 2
2008-04-28 17:46 . 2008-04-28 17:46 <DIR> d-------- C:\Program Files\IncrediGames
2008-04-28 17:46 . 2008-04-28 17:46 <DIR> d-------- C:\Program Files\Common Files\Oberon Media
2008-04-19 17:50 . 2008-04-20 17:08 <DIR> dr-h----- C:\Documents and Settings\Annette Gagnon.ANNETTE-SHNKR5U\Application Data\CrystalSpace
2008-04-18 16:53 . 2008-04-18 17:30 <DIR> d-------- C:\Program Files\JoWood
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-16 22:33 --------- d-----w C:\Program Files\MSN Messenger
2008-05-13 03:16 --------- d-----w C:\Program Files\Game XP
2008-05-10 04:58 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-05-09 23:02 --------- d-----w C:\Program Files\LimeWire
2008-05-09 04:15 --------- d-----w C:\Documents and Settings\Annette Gagnon.ANNETTE-SHNKR5U\Application Data\Azureus
2008-05-05 01:02 --------- d-----w C:\Program Files\Azureus
2008-05-01 01:16 --------- d---a-w C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2008-04-29 01:42 --------- d-----w C:\Program Files\Magentic
2008-04-28 01:12 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-27 23:26 --------- d-----w C:\Program Files\Davincis Secret
2008-04-20 01:58 --------- d-----w C:\Program Files\Mystery Case Files - Prime Suspects
2008-04-17 00:56 --------- dc----w C:\Program Files\Common Files\WindowsLiveInstaller
2008-04-17 00:56 --------- d-----w C:\Program Files\Sony Online Entertainment
2008-04-17 00:56 --------- d-----w C:\Program Files\QuickTax 2007
2008-04-17 00:56 --------- d-----w C:\Program Files\iWin
2008-04-17 00:56 --------- d-----w C:\Program Files\Common Files\AnswerWorks 4.0
2008-04-17 00:56 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Kiwee Toolbar
2008-04-17 00:53 --------- d-----w C:\Program Files\Skype
2008-04-17 00:53 --------- d-----w C:\Program Files\Nancy Drew
2008-04-17 00:53 --------- d-----w C:\Program Files\Mystery Case Files - Prime Suspects(2)
2008-04-17 00:53 --------- d-----w C:\Program Files\Kiwee Toolbar
2008-04-17 00:53 --------- d-----w C:\Program Files\Common Files\Skype
2008-04-17 00:53 --------- d-----w C:\Documents and Settings\Annette Gagnon.ANNETTE-SHNKR5U\Application Data\Skype
2008-04-17 00:53 --------- d-----w C:\Documents and Settings\Annette Gagnon.ANNETTE-SHNKR5U\Application Data\InstallShield
2008-04-17 00:53 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Skype
2008-04-17 00:52 --------- d-----w C:\Program Files\Yahoo!
2008-04-17 00:52 --------- d-----w C:\Program Files\Trillian
2008-04-17 00:51 --------- d-----w C:\Program Files\DivX
2008-04-17 00:50 --------- d-----w C:\Program Files\RealArcade
2008-04-17 00:50 --------- d-----w C:\Program Files\Java
2008-04-17 00:49 --------- d-----w C:\Program Files\ArcSoft
2008-04-16 23:32 --------- d-----w C:\Program Files\PC Drivers HeadQuarters
2008-04-14 12:42 985,088 ----a-w C:\WINDOWS\system32\setupapi.dll
2008-04-14 12:42 11,264 ------w C:\WINDOWS\system32\spnpinst.exe
2008-04-14 12:41 423,936 ----a-w C:\WINDOWS\system32\licdll.dll
2008-04-14 00:25 1,804 ----a-w C:\WINDOWS\system32\dcache.bin
2008-04-14 00:16 329,728 ----a-w C:\WINDOWS\system32\netsetup.exe
2008-04-14 00:13 92,424 ----a-w C:\WINDOWS\system32\rdpdd.dll
2008-04-14 00:13 87,176 ----a-w C:\WINDOWS\system32\rdpwsx.dll
2008-04-14 00:13 40,840 ----a-w C:\WINDOWS\system32\drivers\termdd.sys
2008-04-14 00:13 21,896 ----a-w C:\WINDOWS\system32\drivers\tdtcp.sys
2008-04-14 00:13 139,656 ----a-w C:\WINDOWS\system32\drivers\rdpwd.sys
2008-04-14 00:13 12,168 ----a-w C:\WINDOWS\system32\tsddd.dll
2008-04-14 00:13 12,040 ----a-w C:\WINDOWS\system32\drivers\tdpipe.sys
2008-04-14 00:11 997,376 ----a-w C:\WINDOWS\system32\msgina.dll
2008-04-14 00:10 53,279 ----a-w C:\WINDOWS\system32\odbcji32.dll
2008-04-14 00:10 4,126 ----a-w C:\WINDOWS\system32\msdxmlc.dll
2008-04-14 00:10 3,584 ----a-w C:\WINDOWS\system32\msafd.dll
2008-04-13 19:30 1,845,632 ----a-w C:\WINDOWS\system32\win32k.sys
2008-04-13 19:28 175,744 ----a-w C:\WINDOWS\system32\drivers\rdbss.sys
2008-04-13 19:27 2,188,928 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-04-13 19:21 162,816 ----a-w C:\WINDOWS\system32\drivers\netbt.sys
2008-04-13 19:20 91,520 ----a-w C:\WINDOWS\system32\drivers\ndiswan.sys
2008-04-13 19:20 361,344 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-04-13 19:20 182,656 ----a-w C:\WINDOWS\system32\drivers\ndis.sys
2008-04-13 19:19 75,264 ----a-w C:\WINDOWS\system32\drivers\ipsec.sys
2008-04-13 19:19 51,328 ----a-w C:\WINDOWS\system32\drivers\rasl2tp.sys
2008-04-13 19:19 48,384 ----a-w C:\WINDOWS\system32\drivers\raspptp.sys
2008-04-13 19:19 146,048 ----a-w C:\WINDOWS\system32\drivers\portcls.sys
2008-04-13 19:19 138,112 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-04-13 19:18 52,480 ----a-w C:\WINDOWS\system32\drivers\i8042prt.sys
2008-04-13 19:17 83,072 ----a-w C:\WINDOWS\system32\drivers\wdmaud.sys
2008-04-13 19:17 456,576 ----a-w C:\WINDOWS\system32\drivers\mrxsmb.sys
2008-04-13 19:17 105,344 ----a-w C:\WINDOWS\system32\drivers\mup.sys
2008-04-13 19:16 49,536 ----a-w C:\WINDOWS\system32\drivers\classpnp.sys
2008-04-13 19:16 141,056 ----a-w C:\WINDOWS\system32\drivers\ks.sys
2008-04-13 19:15 64,512 ----a-w C:\WINDOWS\system32\drivers\serial.sys
2008-04-13 19:15 60,800 ----a-w C:\WINDOWS\system32\drivers\sysaudio.sys
2008-04-13 19:15 574,976 ----a-w C:\WINDOWS\system32\drivers\ntfs.sys
2008-04-13 19:15 334,848 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-04-13 19:14 63,744 ----a-w C:\WINDOWS\system32\drivers\cdfs.sys
2008-04-13 19:14 143,744 ----a-w C:\WINDOWS\system32\drivers\fastfat.sys
2008-04-13 19:00 30,080 ----a-w C:\WINDOWS\system32\drivers\modem.sys
2008-04-13 19:00 225,664 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-04-13 19:00 19,072 ----a-w C:\WINDOWS\system32\drivers\tdi.sys
2008-04-13 18:57 41,472 ----a-w C:\WINDOWS\system32\drivers\raspppoe.sys
2008-04-13 18:57 40,576 ----a-w C:\WINDOWS\system32\drivers\ndproxy.sys
2008-04-13 18:57 34,560 ----a-w C:\WINDOWS\system32\drivers\wanarp.sys
2008-04-13 18:57 20,864 ----a-w C:\WINDOWS\system32\drivers\ipinip.sys
2008-04-13 18:57 152,832 ----a-w C:\WINDOWS\system32\drivers\ipnat.sys
2008-04-13 18:57 14,336 ----a-w C:\WINDOWS\system32\drivers\asyncmac.sys
2008-04-13 18:57 10,112 ----a-w C:\WINDOWS\system32\drivers\ndistapi.sys
2008-04-13 18:56 88,320 ----a-w C:\WINDOWS\system32\drivers\nwlnkipx.sys
2008-04-13 18:56 69,120 ----a-w C:\WINDOWS\system32\drivers\psched.sys
2008-04-13 18:56 35,072 ----a-w C:\WINDOWS\system32\drivers\msgpc.sys
2008-04-13 18:56 34,688 ----a-w C:\WINDOWS\system32\drivers\netbios.sys
2008-04-13 18:56 30,592 ----a-w C:\WINDOWS\system32\drivers\rndismp.sys
2008-04-13 18:56 30,592 ------w C:\WINDOWS\system32\drivers\rndismpx.sys
2008-04-13 18:56 12,800 ----a-w C:\WINDOWS\system32\drivers\usb8023.sys
2008-04-13 18:56 12,800 ------w C:\WINDOWS\system32\drivers\usb8023x.sys
2008-04-13 18:56 12,288 ------w C:\WINDOWS\system32\drivers\tunmp.sys
2008-04-13 18:55 202,624 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-04-13 18:55 14,592 ----a-w C:\WINDOWS\system32\drivers\ndisuio.sys
2008-04-13 18:54 11,264 ----a-w C:\WINDOWS\system32\drivers\irenum.sys
2008-04-13 18:53 71,552 ----a-w C:\WINDOWS\system32\drivers\bridge.sys
2008-04-13 18:53 40,320 ----a-w C:\WINDOWS\system32\drivers\nmnt.sys
2008-04-13 18:53 36,608 ------w C:\WINDOWS\system32\drivers\ip6fw.sys
2008-04-13 18:53 264,832 ------w C:\WINDOWS\system32\drivers\http.sys
2008-04-13 18:51 61,824 ----a-w C:\WINDOWS\system32\drivers\nic1394.sys
2008-04-13 18:51 60,800 ----a-w C:\WINDOWS\system32\drivers\arp1394.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6638A9DE-0745-4292-8A2E-AE530E7B9B3F}]
2007-10-31 17:10 296256 --a------ C:\Program Files\Kiwee Toolbar\KiweeIEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{6638A9DE-0745-4292-8A2E-AE530E7B9B3F}"= "C:\Program Files\Kiwee Toolbar\KiweeIEToolbar.dll" [2007-10-31 17:10 296256]
[HKEY_CLASSES_ROOT\clsid\{6638a9de-0745-4292-8a2e-ae530e7b9b3f}]
[HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{259EEB17-79AA-44DF-8410-8E55F82A902A}]
[HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{6638A9DE-0745-4292-8A2E-AE530E7B9B3F}"= C:\Program Files\Kiwee Toolbar\KiweeIEToolbar.dll [2007-10-31 17:10 296256]
[HKEY_CLASSES_ROOT\clsid\{6638a9de-0745-4292-8a2e-ae530e7b9b3f}]
[HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar.1]
[HKEY_CLASSES_ROOT\TypeLib\{259EEB17-79AA-44DF-8410-8E55F82A902A}]
[HKEY_CLASSES_ROOT\KiweeIEToolbar.KiweeToolbar]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 17:12 15360]
"MsnMsgr"="~C:\Program Files\MSN Messenger\MsnMsgr.exe" [ ]
"SweetIM"="C:\Program Files\Macrogaming\SweetIM\SweetIM.exe" [2008-01-02 21:15 103712]
"IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2008-01-17 12:08 214456]
"Magentic"="C:\PROGRA~1\Magentic\bin\Magentic.exe" [2008-03-09 11:00 480648]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 20:05 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2005-01-08 09:17 102491]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-01-08 09:16 692315]
"AzMixerSel"="C:\Program Files\Realtek\InstallShield\AzMixerSel.exe" [2005-06-11 05:51 53248]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 17:07 61952 C:\WINDOWS\system32\HdAShCut.exe]
"EPM-DM"="c:\acer\epm\epm-dm.exe" [2005-08-11 19:21 200704]
"ePowerManagement"="C:\Acer\ePM\ePM.exe" [2005-03-15 10:03 2893824]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-06-07 21:02 94208]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-06-07 20:59 77824]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2005-06-07 21:03 114688]
"RTHDCPL"="RTHDCPL.EXE" [2005-09-22 13:36 14854144 C:\WINDOWS\RTHDCPL.EXE]
"NeroCheck"="C:\WINDOWS\system32\\NeroCheck.exe" [2001-07-09 03:50 155648]
"BrMfcWnd"="C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe" [2006-03-28 16:48 622592]
"SetDefPrt"="C:\Program Files\Brother\Brmfl06a\BrStDvPt.exe" [2005-01-26 19:02 49152]
"ControlCenter3"="C:\Program Files\Brother\ControlCenter3\brctrcen.exe" [2006-04-10 15:58 61440]
"LifeCam"="C:\Program Files\Microsoft LifeCam\LifeExp.exe" [2007-01-12 18:48 275800]
"VX6000"="C:\WINDOWS\vVX6000.exe" [2006-12-19 12:29 994072]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 02:11 132496]
"KiweeHook"="C:\Program Files\Kiwee Toolbar\kwtbaim.exe" [2007-10-31 17:12 62776]
"SweetIM"="C:\Program Files\Macrogaming\SweetIM\SweetIM.exe" [2008-01-02 21:15 103712]
"WildTangent CDA"="C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe" [2005-03-28 18:24 28616]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-05-09 22:01 1177368]
C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 13:05:56 65588]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"C:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImApp.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"C:\\Program Files\\Magentic\\bin\\MgImp.exe"=
"C:\\Program Files\\Magentic\\bin\\Magentic.exe"=
"C:\\Program Files\\Magentic\\bin\\MgApp.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-05-09 22:01]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-05-09 22:01]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-05-09 22:01]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-05-09 22:01]
R2 EpmPsd;Acer EPM Power Scheme Driver;C:\WINDOWS\system32\drivers\epm-psd.sys [2004-07-19 13:10]
R2 EpmShd;Acer EPM System Hardware Driver;C:\WINDOWS\system32\drivers\epm-shd.sys [2005-04-07 18:08]
R2 MSCamSvc;MSCamSvc;"C:\Program Files\Microsoft LifeCam\MSCamS32.exe" [2007-01-04 15:13]
R2 osaio;osaio;C:\WINDOWS\system32\drivers\osaio.sys [2005-06-30 16:58]
R2 osanbm;osanbm;C:\WINDOWS\system32\drivers\osanbm.sys [2005-01-14 15:57]
S3 BrScnUsb;Brother USB Still Image driver;C:\WINDOWS\system32\DRIVERS\BrScnUsb.sys [2004-10-15 13:50]
S3 VX6000;Microsoft LifeCam VX-6000;C:\WINDOWS\system32\DRIVERS\VX6000Xp.sys [2006-12-19 12:29]
.
Contents of the 'Scheduled Tasks' folder
"2008-05-03 23:54:10 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-05-16 21:51:38
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Acer\eManager\anbmServ.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Brother\ControlCenter3\BrccMCtl.exe
C:\PROGRA~1\Magentic\bin\MgApp.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\INCRED~1\bin\ImApp.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-05-16 22:03:36 - machine was rebooted [Annette Gagnon]
ComboFix-quarantined-files.txt 2008-05-17 05:03:25
Pre-Run: 49,155,620,864 bytes free
Post-Run: 49,088,995,328 bytes free
299 --- E O F --- 2008-05-09 04:30:08