Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.651 [GMT -8:00]
Running from: c:\documents and settings\davis family\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1368 [VPS 100117-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\documents and settings\davis family\Application Data\.#
c:\windows\kb913800.exe
c:\windows\system32\config\systemprofile\Application Data\alot
.
((((((((((((((((((((((((( Files Created from 2009-12-18 to 2010-01-18 )))))))))))))))))))))))))))))))
.
2010-01-17 21:50 . 2010-01-17 21:50 388096 ----a-r- c:\documents and settings\davis family\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2010-01-16 00:37 . 2010-01-16 01:52 -------- d-----w- c:\program files\Electronic Arts
2010-01-13 21:02 . 2010-01-13 21:02 -------- d-----w- c:\program files\JavaFX
2010-01-13 21:01 . 2010-01-13 21:01 -------- d-----w- c:\program files\Sun
2010-01-13 20:44 . 2010-01-14 16:08 -------- d-----w- c:\program files\Reimage
2010-01-13 20:20 . 2010-01-13 20:20 -------- d-----w- c:\program files\HoverIP
2010-01-13 17:54 . 2010-01-13 17:54 -------- d-----w- c:\program files\Trend Micro
2010-01-13 17:43 . 2010-01-13 17:43 -------- d-----w- c:\program files\TrendMicro
2010-01-13 02:56 . 2010-01-13 02:56 -------- d-sh--w- c:\documents and settings\LocalService\IECompatCache
2010-01-13 02:56 . 2010-01-13 02:56 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Threat Expert
2010-01-13 02:56 . 2010-01-13 02:56 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\BakuganBay
2010-01-13 01:52 . 2010-01-13 01:52 -------- d-----w- c:\documents and settings\davis family\Local Settings\Application Data\Threat Expert
2010-01-12 23:50 . 2010-01-12 23:50 -------- d-----w- c:\program files\CleanUp!
2010-01-12 00:54 . 2009-11-24 23:49 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-01-12 00:54 . 2009-11-24 23:48 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-01-12 00:54 . 2009-11-24 23:47 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-01-12 00:54 . 2009-11-24 23:51 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-01-12 00:54 . 2009-11-24 23:50 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-01-12 00:54 . 2009-11-24 23:50 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-01-12 00:54 . 2009-11-24 23:50 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-01-12 00:54 . 2009-11-24 23:47 97480 ----a-w- c:\windows\system32\AvastSS.scr
2010-01-12 00:54 . 2009-11-24 23:54 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2010-01-12 00:54 . 2010-01-12 00:54 -------- d-----w- c:\program files\Alwil Software
2010-01-12 00:17 . 2010-01-12 00:18 -------- d-----w- c:\program files\ERUNT
2010-01-11 20:25 . 2010-01-11 20:25 -------- d-----w- c:\program files\Windows Live SkyDrive
2010-01-09 17:45 . 2010-01-12 23:51 -------- d-----w- C:\found.001
2010-01-05 23:58 . 2010-01-05 23:58 5061520 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-04 23:13 . 2010-01-04 23:13 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2010-01-04 20:26 . 2010-01-04 20:26 -------- d-----w- c:\program files\Sims2Pack Clean Installer
2010-01-03 20:44 . 2010-01-03 20:46 -------- d-----w- c:\documents and settings\davis family\Application Data\Virtual City
2010-01-03 20:36 . 2010-01-03 20:36 -------- d-----w- c:\documents and settings\davis family\Application Data\MysteryStudio
2010-01-03 05:13 . 2010-01-03 05:14 -------- d-----w- c:\program files\Virtual City
2010-01-03 05:06 . 2010-01-03 05:06 -------- d-----w- c:\program files\Fashion Assistant
2010-01-03 05:04 . 2010-01-03 05:05 -------- d-----w- c:\program files\Gotcha - Celebrity Secrets
2010-01-02 20:41 . 2010-01-02 20:41 -------- d-----w- c:\documents and settings\davis family\Application Data\Home Sweet Home
2010-01-01 21:41 . 2010-01-01 21:41 -------- d-----w- c:\program files\The Mirror Mysteries
2010-01-01 21:36 . 2010-01-01 21:36 1604302 ----a-w- c:\documents and settings\All Users\Application Data\BigFishGamesCache\GameManager\GameDB\F5300T1L1\setup_gF5300T1L1_d740504578_l1_s1.exe
2009-12-26 23:46 . 2009-12-26 23:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Fenomen Games
2009-12-26 23:26 . 2009-12-26 23:26 -------- d-----w- c:\documents and settings\davis family\Saved Games
2009-12-26 22:50 . 2009-12-22 00:14 73728 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\jojos-fashion-show-3\game\zlib1.dll
2009-12-26 22:50 . 2009-12-22 00:14 32768 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\jojos-fashion-show-3\game\vorbisfile.dll
2009-12-26 22:50 . 2009-12-22 00:14 24576 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\jojos-fashion-show-3\game\ogg.dll
2009-12-26 22:50 . 2009-12-22 00:14 196608 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\jojos-fashion-show-3\game\smpeg.dll
2009-12-26 22:50 . 2009-12-22 00:14 1101824 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\jojos-fashion-show-3\game\vorbis.dll
2009-12-26 22:50 . 2009-12-22 00:14 169443 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\jojos-fashion-show-3\game\jpeg.dll
2009-12-26 22:50 . 2009-12-22 00:14 114688 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\jojos-fashion-show-3\game\libpng13.dll
2009-12-26 22:49 . 2009-12-22 00:30 3182592 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\jojos-fashion-show-3\game\Jojos3.exe
2009-12-26 22:49 . 2009-12-22 00:14 86016 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\jojos-fashion-show-3\game\iWinFlash.dll
2009-12-26 22:49 . 2009-12-22 00:14 8421376 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\jojos-fashion-show-3\game\icudt38.dll
2009-12-26 22:49 . 2009-12-22 00:14 397312 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\jojos-fashion-show-3\game\FlashPlayerControl.dll
2009-12-26 22:48 . 2009-12-22 00:13 8667136 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\jojos-fashion-show-3\game\Awesomium.dll
2009-12-26 22:48 . 2009-12-22 00:13 581632 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\jojos-fashion-show-3\game\audiere.dll
2009-12-26 22:48 . 2009-06-12 23:23 57344 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\jojos-fashion-show-3\pfinstall.dll
2009-12-26 22:48 . 2009-12-22 00:30 1732608 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\jojos-fashion-show-3\Jojos3.exe
2009-12-26 22:48 . 2007-11-21 11:38 161344 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\jojos-fashion-show-3\UNWISE.EXE
2009-12-26 17:08 . 2009-12-26 17:08 47344 ---ha-w- c:\windows\system32\mlfcache.dat
2009-12-25 17:59 . 2009-05-18 22:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-12-25 17:59 . 2008-04-17 21:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-12-25 17:58 . 2009-12-25 17:58 -------- d-----w- c:\program files\iPod
2009-12-25 17:57 . 2009-12-25 17:59 -------- d-----w- c:\program files\iTunes
2009-12-25 17:57 . 2009-12-25 17:59 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-12-25 17:56 . 2009-12-25 17:56 -------- d-----w- c:\program files\Bonjour
2009-12-25 17:53 . 2009-12-25 17:53 -------- d-----w- c:\documents and settings\davis family\Local Settings\Application Data\Apple
2009-12-25 17:53 . 2009-12-25 17:53 -------- d-----w- c:\program files\Apple Software Update
2009-12-25 17:53 . 2009-08-29 03:42 40448 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-12-25 17:53 . 2009-08-29 03:42 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-12-25 17:52 . 2009-12-25 17:58 -------- d-----w- c:\program files\Common Files\Apple
2009-12-25 17:52 . 2009-12-25 17:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-12-22 16:57 . 2009-12-22 16:59 24438056 ----a-w- c:\documents and settings\davis family\Application Data\IMVUClient\installer\SetupImvu_update.exe
2009-12-21 19:36 . 2009-12-21 19:36 92192 ----a-w- c:\documents and settings\davis family\Application Data\IMVUClient\IMVUupdater.exe
2009-12-21 19:36 . 2009-12-21 19:36 52992 ----a-w- c:\documents and settings\davis family\Application Data\IMVUClient\IMVUClient.exe
2009-12-21 19:36 . 2009-12-21 19:36 21760 ----a-w- c:\documents and settings\davis family\Application Data\IMVUClient\IMVUQualityAgent.exe
2009-12-21 19:33 . 2009-12-21 19:33 121856 ----a-w- c:\documents and settings\davis family\Application Data\IMVUClient\WriteMiniDump.exe
2009-12-21 19:31 . 2009-12-21 19:31 1222144 ----a-w- c:\documents and settings\davis family\Application Data\IMVUClient\SceneWindow.dll
2009-12-21 19:31 . 2009-12-21 19:31 45568 ----a-w- c:\documents and settings\davis family\Application Data\IMVUClient\ui\plugins\npvivoxproxy.dll
2009-12-21 19:31 . 2009-12-21 19:31 54784 ----a-w- c:\documents and settings\davis family\Application Data\IMVUClient\ui\plugins\nphwndproxy.dll
2009-12-21 19:31 . 2009-12-21 19:31 16896 ----a-w- c:\documents and settings\davis family\Application Data\IMVUClient\MemoryHook.dll
2009-12-21 19:30 . 2009-12-21 19:30 320000 ----a-w- c:\documents and settings\davis family\Application Data\IMVUClient\cal3d.dll
2009-12-21 19:29 . 2009-12-21 19:29 198656 ----a-w- c:\documents and settings\davis family\Application Data\IMVUClient\boost_python.dll
2009-12-21 19:29 . 2009-12-21 19:29 29184 ----a-w- c:\documents and settings\davis family\Application Data\IMVUClient\CallStack.dll
2009-12-21 19:29 . 2009-12-21 19:29 260096 ----a-w- c:\documents and settings\davis family\Application Data\IMVUClient\audiere.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-18 01:23 . 2009-10-04 14:07 -------- d-----w- c:\program files\BakuganBay
2010-01-18 01:23 . 2009-07-06 23:31 -------- d-----w- c:\program files\DAP
2010-01-18 00:52 . 2009-07-06 23:31 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-01-17 01:54 . 2009-07-10 18:44 10718 ----a-w- c:\documents and settings\davis family\Application Data\wklnhst.dat
2010-01-16 01:53 . 2009-07-06 22:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Electronic Arts
2010-01-16 00:37 . 2009-07-06 18:27 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-14 16:10 . 2009-07-06 18:35 63104 ----a-w- c:\documents and settings\davis family\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-13 20:55 . 2009-07-07 21:33 -------- d-----w- c:\program files\Java
2010-01-12 00:19 . 2009-07-06 21:31 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-10 18:04 . 2009-08-05 22:49 -------- d-----w- c:\documents and settings\davis family\Application Data\LimeWire
2010-01-08 00:07 . 2009-07-06 21:31 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-08 00:07 . 2009-07-06 21:31 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-04 16:40 . 2009-12-18 17:16 -------- d-----w- c:\documents and settings\davis family\Application Data\IMVU
2010-01-01 23:58 . 2009-12-15 02:30 -------- d-----w- c:\program files\InterActual
2010-01-01 23:56 . 2009-07-06 18:44 -------- d-----w- c:\program files\Google
2010-01-01 22:43 . 2009-07-19 04:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Sandlot Games
2010-01-01 22:42 . 2009-07-17 21:19 -------- d-----w- c:\documents and settings\All Users\Application Data\BigFishGamesCache
2009-12-27 03:11 . 2009-07-19 04:27 -------- d-----w- c:\documents and settings\davis family\Application Data\PlayFirst
2009-12-27 03:11 . 2009-07-19 04:27 -------- d-----w- c:\documents and settings\All Users\Application Data\PlayFirst
2009-12-25 18:14 . 2009-10-11 16:30 -------- d-----w- c:\documents and settings\davis family\Application Data\Apple Computer
2009-12-25 17:57 . 2009-10-08 20:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-12-25 17:55 . 2009-10-08 20:13 -------- d-----w- c:\program files\QuickTime
2009-12-22 16:59 . 2009-12-18 17:16 76774 ----a-w- c:\documents and settings\davis family\Application Data\IMVUClient\Uninstall.exe
2009-12-22 16:59 . 2009-12-18 17:16 -------- d-----w- c:\documents and settings\davis family\Application Data\IMVUClient
2009-12-17 18:05 . 2009-12-17 18:05 7491728 ----a-w- c:\documents and settings\davis family\Application Data\IMVUClient\1VivoxVoice.exe
2009-12-17 18:05 . 2009-12-17 18:05 4924048 ----a-w- c:\documents and settings\davis family\Application Data\IMVUClient\vivoxsdk.dll
2009-12-17 18:05 . 2009-12-17 18:05 353424 ----a-w- c:\documents and settings\davis family\Application Data\IMVUClient\npvivoxvoiceplugin.dll
2009-12-17 18:05 . 2009-12-17 18:05 330896 ----a-w- c:\documents and settings\davis family\Application Data\IMVUClient\libsndfile-1.dll
2009-12-17 18:05 . 2009-12-17 18:05 275088 ----a-w- c:\documents and settings\davis family\Application Data\IMVUClient\vivoxoal.dll
2009-12-17 18:05 . 2009-12-17 18:05 246416 ----a-w- c:\documents and settings\davis family\Application Data\IMVUClient\ortp.dll
2009-12-17 18:05 . 2009-12-17 18:05 1034896 ----a-w- c:\documents and settings\davis family\Application Data\IMVUClient\dbghelp.dll
2009-12-15 14:39 . 2009-09-06 16:55 -------- d-----w- c:\program files\Blockland
2009-12-14 17:51 . 2009-12-06 19:56 -------- d-----w- c:\program files\SBC Yahoo!
2009-12-14 17:49 . 2009-10-08 20:10 -------- d-----w- c:\program files\Common Files\ArcSoft
2009-12-14 17:49 . 2009-10-08 20:10 -------- d-----w- c:\program files\ArcSoft
2009-12-14 17:48 . 2009-10-08 20:11 720 ----a-w- c:\documents and settings\All Users\Application Data\ArcSoft\kodak-printcreations-22-080812-oem\acforall.dll
2009-12-14 16:23 . 2009-07-06 23:33 95744 ----a-w- c:\documents and settings\All Users\Application Data\SpeedBit\DAP\SDCondition.dll
2009-12-11 02:19 . 2009-09-14 22:32 1 ----a-w- c:\documents and settings\davis family\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-12-10 17:37 . 2009-07-07 00:58 -------- d-----w- c:\program files\Mad Scientist Productions
2009-12-07 16:44 . 2009-07-06 17:12 -------- d-----w- c:\program files\RGB
2009-12-04 19:52 . 2009-12-04 19:52 -------- d-----w- c:\documents and settings\davis family\Application Data\Namco
2009-12-04 19:52 . 2009-12-04 19:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Namco
2009-12-03 17:17 . 2009-12-03 17:17 4096 ----a-w- c:\windows\d3dx.dat
2009-12-03 16:49 . 2009-12-03 16:47 -------- d-----w- c:\documents and settings\davis family\Application Data\Playfirst JanesZOO
2009-12-01 23:58 . 2009-12-01 23:58 7490192 ----a-w- c:\documents and settings\davis family\Application Data\IMVUClient\ui\plugins\VivoxVoiceManager.exe
2009-12-01 23:58 . 2009-12-01 23:58 5005968 ----a-w- c:\documents and settings\davis family\Application Data\IMVUClient\ui\plugins\vivoxsdk.dll
2009-12-01 23:58 . 2009-12-01 23:58 345744 ----a-w- c:\documents and settings\davis family\Application Data\IMVUClient\ui\plugins\npvivoxvoiceplugin.dll
2009-12-01 23:58 . 2009-12-01 23:58 329872 ----a-w- c:\documents and settings\davis family\Application Data\IMVUClient\ui\plugins\libsndfile-1.dll
2009-12-01 23:58 . 2009-12-01 23:58 283280 ----a-w- c:\documents and settings\davis family\Application Data\IMVUClient\ui\plugins\vivoxoal.dll
2009-12-01 23:58 . 2009-12-01 23:58 246416 ----a-w- c:\documents and settings\davis family\Application Data\IMVUClient\ui\plugins\ortp.dll
2009-12-01 23:58 . 2009-12-01 23:58 184832 ----a-w- c:\documents and settings\davis family\Application Data\IMVUClient\ui\plugins\ssleay32.dll
2009-12-01 23:58 . 2009-12-01 23:58 1034896 ----a-w- c:\documents and settings\davis family\Application Data\IMVUClient\ui\plugins\DbgHelp.dll
2009-12-01 23:58 . 2009-12-01 23:58 1006080 ----a-w- c:\documents and settings\davis family\Application Data\IMVUClient\ui\plugins\libeay32.dll
2009-12-01 02:38 . 2009-12-01 02:38 1006080 ----a-w- c:\documents and settings\davis family\Application Data\IMVUClient\libeay32.dll
2009-12-01 02:38 . 2009-12-01 02:38 184832 ----a-w- c:\documents and settings\davis family\Application Data\IMVUClient\ssleay32.dll
2009-11-28 04:08 . 2009-11-28 04:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Wrinkle-free Games
2009-11-28 03:04 . 2009-11-28 03:03 -------- d-----w- c:\program files\Paradise Beach
2009-11-28 02:56 . 2009-11-28 02:56 -------- d-----w- c:\program files\Hotel Dash - Suite Success
2009-11-21 15:51 . 2004-08-10 11:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-13 01:07 . 2009-11-13 01:07 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-11-12 23:27 . 2009-11-12 23:27 3771296 ----a-w- c:\documents and settings\davis family\Application Data\IMVUClient\ui\plugins\NPSWF32.dll
2009-11-08 15:49 . 2009-10-01 02:24 573440 -c--a-w- c:\documents and settings\All Users\Application Data\Nanovor\Utils\ConsoleDeviceInterface.exe
2009-11-08 15:49 . 2009-08-20 20:43 11497040 ----a-w- c:\documents and settings\All Users\Application Data\Nanovor\Nanovor.exe
2009-11-08 15:49 . 2009-08-14 19:48 108 -c--a-w- c:\documents and settings\All Users\Application Data\Nanovor\Nanovor.bat
2009-11-08 15:45 . 2009-09-17 23:12 5940864 -c--a-w- c:\documents and settings\All Users\Application Data\Nanovor\evolver.exe
2009-10-29 07:45 . 2006-03-04 03:33 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-25 22:25 . 2009-10-25 22:25 9158 -c--a-r- c:\documents and settings\davis family\Application Data\Microsoft\Installer\{89DE67AD-08B8-4699-A55D-CA5C0AF82BF3}\ARPPRODUCTICON.exe
2009-10-21 05:38 . 2004-08-10 11:00 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-10 11:00 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-10 11:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-27 4351216]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-07-06 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BDARemote.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PalTalk.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^davis family^Start Menu^Programs^Startup^IMVU.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^davis family^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoboForm
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-09-04 19:08 935288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-10-03 11:08 35696 -c--a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 3]
2009-11-20 21:51 2335880 ----a-w- c:\program files\IObit\Advanced SystemCare 3\AWC.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATICCC]
2006-09-25 16:12 90112 -c--a-w- c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ------w- c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DownloadAccelerator]
2009-11-03 16:11 2803200 ----a-w- c:\program files\DAP\DAP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EA Core]
2009-03-28 21:11 3325952 ----a-w- c:\program files\Electronic Arts\EADM\Core.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
2005-08-05 20:56 64512 -c--a-w- c:\windows\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus CX4800 Series]
2005-02-02 03:00 98304 -c--a-w- c:\windows\system32\spool\drivers\w32x86\3\E_FATIADA.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-11-13 00:33 141600 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ------w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-11 07:08 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Search Protection]
2009-02-23 13:05 111856 ----a-w- c:\program files\Yahoo!\Search Protection\SearchProtection.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
2006-07-27 21:19 282624 ----a-w- c:\windows\stsystra.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartRAM]
2009-02-19 22:23 202064 ----a-w- c:\program files\IObit\Advanced SystemCare 3\Sup_SmartRAM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-07-07 21:33 148888 -c--a-w- c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-07-06 18:56 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YSearchProtection]
2009-02-23 13:05 111856 ----a-w- c:\program files\Yahoo!\Search Protection\SearchProtection.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\bfgclient\\bfggameservices.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Microsoft Games\\Zoo Tycoon 2\\zt.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\ATI Technologies\\ATI.ACE\\CLI.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [1/11/2010 4:54 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [1/11/2010 4:54 PM 20560]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [10/14/2009 6:30 PM 133104]
S3 cpuz128;cpuz128;\??\c:\docume~1\DAVISF~1\LOCALS~1\Temp\cpuz_x32.sys --> c:\docume~1\DAVISF~1\LOCALS~1\Temp\cpuz_x32.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2010-01-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 20:34]
2010-01-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-15 02:30]
2010-01-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-15 02:30]
2010-01-11 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2009-08-04 16:22]
2010-01-18 c:\windows\Tasks\User_Feed_Synchronization-{D3F37C4D-777B-454D-BE68-24D0A7B22B94}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 11:31]
.
.
------- Supplementary Scan -------
.
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\davis family\Start Menu\Programs\IMVU\Run IMVU.lnk
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: {75A6AEA3-F26E-4608-AE9B-8DA78C87576E} - hxxps://kingsisle.hs.llnwd.net/e1/static/themes/wizard101A/activex/Wizard101GameLauncher.CAB
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{0BB39A79-CB69-4721-8C1F-81E25AABB621} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
MSConfigStartUp-ReimageFTP - c:\program files\Reimage\Reimage Repair\ReiFTPWatchDog.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-17 17:33
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,1c,ac,aa,3c,de,fc,9b,4f,a8,61,52,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,1c,ac,aa,3c,de,fc,9b,4f,a8,61,52,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(712)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2010-01-17 17:37:13
ComboFix-quarantined-files.txt 2010-01-18 01:36
Pre-Run: 114,085,036,032 bytes free
Post-Run: 114,095,726,592 bytes free
- - End Of File - - 250B5D3A8433650F5DEBD33C986C4C4D