Here's the log.
ComboFix 13-02-18.02 - Ally 02/19/2013 21:31:41.3.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3071.2498 [GMT -5:00]
Running from: c:\documents and settings\Ally\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Ally\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
FILE ::
"C:\cmdinstall.exe"
"c:\windows\system32\GameMon.des -service"
"c:\windows\System32\guard32.dll"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Ally\Local Settings\Application Data\COMODO
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\chrome_shutdown_ms.txt
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Archived History-journal
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Archived History
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Cache\data_0
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Cache\data_1
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Cache\data_2
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Cache\data_3
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Cache\f_000001
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Cache\f_000002
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Cache\f_000003
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Cache\f_000004
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Cache\f_000005
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Cache\index
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Cookies-journal
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Cookies
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Current Session
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Current Tabs
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Extension State\000003.log
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Extension State\CURRENT
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Extension State\LOCK
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Extension State\LOG
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Extension State\MANIFEST-000002
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Extensions\bdngekjahnmlkinegnhdmmbcfnmbclnn\0.2_0\_locales\en\messages.json
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Extensions\bdngekjahnmlkinegnhdmmbcfnmbclnn\0.2_0\_locales\ru\messages.json
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Extensions\bdngekjahnmlkinegnhdmmbcfnmbclnn\0.2_0\_locales\uk\messages.json
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Extensions\bdngekjahnmlkinegnhdmmbcfnmbclnn\0.2_0\icon.png
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Extensions\bdngekjahnmlkinegnhdmmbcfnmbclnn\0.2_0\icon_16.png
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Extensions\bdngekjahnmlkinegnhdmmbcfnmbclnn\0.2_0\icon_48.png
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Extensions\bdngekjahnmlkinegnhdmmbcfnmbclnn\0.2_0\main.js
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Extensions\bdngekjahnmlkinegnhdmmbcfnmbclnn\0.2_0\manifest.json
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Extensions\bdngekjahnmlkinegnhdmmbcfnmbclnn\0.2_0\options.css
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Extensions\bdngekjahnmlkinegnhdmmbcfnmbclnn\0.2_0\options.html
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Extensions\bdngekjahnmlkinegnhdmmbcfnmbclnn\0.2_0\options.js
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Extensions\mcmdgbiocnkpnaccjkailibfgepaccgf\0.1_0\_locales\en\messages.json
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Extensions\mcmdgbiocnkpnaccjkailibfgepaccgf\0.1_0\_locales\ru\messages.json
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Extensions\mcmdgbiocnkpnaccjkailibfgepaccgf\0.1_0\_locales\uk\messages.json
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Extensions\mcmdgbiocnkpnaccjkailibfgepaccgf\0.1_0\browser_action.html
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Extensions\mcmdgbiocnkpnaccjkailibfgepaccgf\0.1_0\css\browser_action.css
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Extensions\mcmdgbiocnkpnaccjkailibfgepaccgf\0.1_0\css\options.css
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Extensions\mcmdgbiocnkpnaccjkailibfgepaccgf\0.1_0\css\reset.css
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Extensions\mcmdgbiocnkpnaccjkailibfgepaccgf\0.1_0\icons\default_services\facebook.png
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Extensions\mcmdgbiocnkpnaccjkailibfgepaccgf\0.1_0\icons\default_services\linkedin.png
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Extensions\mcmdgbiocnkpnaccjkailibfgepaccgf\0.1_0\icons\default_services\twitter.png
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Extensions\mcmdgbiocnkpnaccjkailibfgepaccgf\0.1_0\icons\extension_icon_settings.png
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Extensions\mcmdgbiocnkpnaccjkailibfgepaccgf\0.1_0\icons\logo.png
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Extensions\mcmdgbiocnkpnaccjkailibfgepaccgf\0.1_0\icons\popup_menu_title.png
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Extensions\mcmdgbiocnkpnaccjkailibfgepaccgf\0.1_0\icons\toolbar_icon_active.png
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Extensions\mcmdgbiocnkpnaccjkailibfgepaccgf\0.1_0\icons\toolbar_icon_inactive.png
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Extensions\mcmdgbiocnkpnaccjkailibfgepaccgf\0.1_0\js\background.js
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Extensions\mcmdgbiocnkpnaccjkailibfgepaccgf\0.1_0\js\browser_action.js
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Extensions\mcmdgbiocnkpnaccjkailibfgepaccgf\0.1_0\js\options.js
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Extensions\mcmdgbiocnkpnaccjkailibfgepaccgf\0.1_0\js\utils.js
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Extensions\mcmdgbiocnkpnaccjkailibfgepaccgf\0.1_0\manifest.json
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Extensions\mcmdgbiocnkpnaccjkailibfgepaccgf\0.1_0\options.html
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Favicons-journal
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Favicons
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\History-journal
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\History Index 2013-02-journal
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\History Index 2013-02
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\History Provider Cache
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\History
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Login Data-journal
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Login Data
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Managed Mode Settings
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Network Action Predictor-journal
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Network Action Predictor
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Preferences
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Shortcuts-journal
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Shortcuts
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\User StyleSheets\Custom.css
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Visited Links
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Web Data-journal
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Default\Web Data
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\First Run
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Local State
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Safe Browsing Cookies-journal
c:\documents and settings\Ally\Local Settings\Application Data\COMODO\Dragon\User Data\Safe Browsing Cookies
c:\documents and settings\LocalService\Local Settings\Application Data\COMODO
c:\documents and settings\LocalService\Local Settings\Application Data\COMODO\Dragon\User Data\Local State
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_npggsvc
.
.
((((((((((((((((((((((((( Files Created from 2013-01-20 to 2013-02-20 )))))))))))))))))))))))))))))))
.
.
2013-02-20 01:39 . 2013-02-20 01:39 8281168 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\BingBar\BBSvc\7.1.391.0oemBingBarSetup-Partner.EXE
2013-02-19 04:01 . 2013-02-19 04:01 -------- d-----w- c:\windows\system32\wbem\Repository
2013-02-18 23:54 . 2013-02-18 23:54 -------- d-----w- C:\_OTL
2013-02-18 23:50 . 2013-02-18 23:50 -------- d-----w- c:\documents and settings\Ally\Application Data\Uninstaller Tool(Comodo Forums)
2013-02-18 04:44 . 2013-02-18 04:44 -------- d-----w- C:\themes
2013-02-18 04:44 . 2013-01-24 22:42 281808 ----a-w- C:\7za.dll
2013-02-18 04:44 . 2013-02-18 04:44 -------- d-----w- C:\cis
2013-02-18 04:44 . 2013-01-24 22:42 3360976 ----a-w- C:\cmdhtml.dll
2013-02-18 04:44 . 2013-01-24 22:42 18980560 ----a-w- C:\cmdinstall.exe
2013-02-18 04:14 . 2013-02-18 04:14 -------- d-----w- c:\program files\NirSoft
2013-02-18 02:33 . 2013-02-18 02:33 -------- d-----w- c:\documents and settings\Ally\Application Data\Malwarebytes
2013-02-18 02:32 . 2013-02-18 02:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2013-02-18 02:32 . 2013-02-18 02:32 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-02-18 02:32 . 2012-12-14 21:49 21104 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-02-17 20:54 . 2013-02-17 20:54 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2013-02-17 06:05 . 2010-09-18 06:53 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2013-02-17 06:02 . 2010-11-02 15:17 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
2013-02-17 06:02 . 2010-08-23 16:12 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2013-02-17 06:01 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2013-02-17 06:00 . 2011-04-21 13:37 105472 -c----w- c:\windows\system32\dllcache\mup.sys
2013-02-17 06:00 . 2012-12-16 12:23 290560 -c----w- c:\windows\system32\dllcache\atmfd.dll
2013-02-17 05:58 . 2012-05-28 18:16 536576 -c----w- c:\windows\system32\dllcache\msado15.dll
2013-02-17 05:57 . 2012-07-04 14:05 139784 -c----w- c:\windows\system32\dllcache\rdpwd.sys
2013-02-17 05:54 . 2012-12-26 20:16 522240 -c----w- c:\windows\system32\dllcache\jsdbgui.dll
2013-02-17 05:54 . 2012-12-26 20:16 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2013-02-17 05:51 . 2011-07-08 14:02 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys
2013-02-17 05:51 . 2012-01-11 19:06 3072 -c----w- c:\windows\system32\dllcache\iacenc.dll
2013-02-17 05:51 . 2012-01-11 19:06 3072 ------w- c:\windows\system32\iacenc.dll
2013-02-17 05:48 . 2010-10-11 14:59 45568 -c----w- c:\windows\system32\dllcache\wab.exe
2013-02-17 02:51 . 2008-04-14 00:12 218624 ----a-w- c:\windows\system32\uxtheme.backup
2013-02-17 02:07 . 2012-10-30 23:51 21256 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2013-02-17 02:07 . 2012-10-30 23:51 361032 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-02-17 02:07 . 2012-10-30 23:51 738504 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-02-17 02:07 . 2012-10-30 23:51 54232 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2013-02-17 02:06 . 2012-10-30 23:51 41224 ----a-w- c:\windows\avastSS.scr
2013-02-17 02:06 . 2012-10-30 23:50 227648 ----a-w- c:\windows\system32\aswBoot.exe
2013-02-17 02:06 . 2013-02-17 02:06 -------- d-----w- c:\program files\AVAST Software
2013-02-17 02:06 . 2013-02-17 02:06 -------- d-----w- c:\documents and settings\All Users\Application Data\AVAST Software
2013-02-17 02:02 . 2013-02-17 02:02 -------- d-----w- c:\program files\Magical Jelly Bean
2013-02-17 01:58 . 2013-02-17 01:58 -------- d-----w- c:\program files\Belarc
2013-02-17 01:58 . 2011-08-09 21:33 3840 ----a-w- c:\windows\system32\drivers\BANTExt.sys
2013-02-17 01:38 . 2013-02-17 01:39 292700 ----a-w- c:\windows\system32\nvdrsdb0.bin
2013-02-17 01:38 . 2013-02-17 01:39 1 ----a-w- c:\windows\system32\nvdrssel.bin
2013-02-17 01:38 . 2013-02-17 01:38 292700 ----a-w- c:\windows\system32\nvdrsdb1.bin
2013-02-17 01:38 . 2013-02-17 01:38 -------- d-----w- c:\program files\NVIDIA Corporation
2013-02-17 01:09 . 2013-02-17 01:10 -------- d-----w- c:\documents and settings\Ally\Local Settings\Application Data\Google
2013-02-17 01:09 . 2013-02-17 01:09 -------- d-----w- c:\program files\Google
2013-02-16 07:45 . 2013-02-17 00:29 -------- d-----w- c:\documents and settings\Ally\Backed up files from the 1TB
2013-02-16 07:20 . 2004-11-17 08:11 9319936 ----a-w- c:\windows\system32\RTLCPL.EXE
2013-02-16 07:20 . 2004-09-07 06:23 156672 ----a-w- c:\windows\system32\RTLCPAPI.dll
2013-02-16 07:20 . 2004-07-16 06:19 70400 ----a-w- c:\windows\system32\drivers\Rtlnicxp.sys
2013-02-16 07:19 . 2004-11-17 11:05 2297664 ----a-w- c:\windows\system32\drivers\ALCXWDM.SYS
2013-02-16 07:19 . 2004-11-17 08:08 16162816 ----a-w- c:\windows\system32\ALSNDMGR.CPL
2013-02-11 00:37 . 2008-04-13 18:45 60032 -c--a-w- c:\windows\system32\dllcache\usbaudio.sys
2013-02-11 00:37 . 2008-04-13 18:45 60032 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2013-02-11 00:37 . 2008-04-14 00:12 91136 ----a-w- c:\windows\system32\kswdmcap.ax
2013-02-11 00:37 . 2008-04-14 00:12 61952 ----a-w- c:\windows\system32\kstvtune.ax
2013-02-11 00:37 . 2008-04-14 00:12 43008 ----a-w- c:\windows\system32\ksxbar.ax
2013-02-11 00:37 . 2008-04-14 00:12 20992 ----a-w- c:\windows\system32\dshowext.ax
2013-02-11 00:37 . 2008-04-14 00:12 53760 -c--a-w- c:\windows\system32\dllcache\vfwwdm32.dll
2013-02-11 00:37 . 2008-04-14 00:12 53760 ----a-w- c:\windows\system32\vfwwdm32.dll
2013-02-11 00:36 . 2008-04-13 18:40 5504 -c--a-w- c:\windows\system32\dllcache\intelide.sys
2013-02-11 00:36 . 2008-04-13 18:40 5504 ----a-w- c:\windows\system32\drivers\intelide.sys
2013-02-11 00:35 . 2008-04-13 18:45 10624 -c--a-w- c:\windows\system32\dllcache\gameenum.sys
2013-02-11 00:35 . 2008-04-13 18:45 10624 ----a-w- c:\windows\system32\drivers\gameenum.sys
2013-01-27 18:53 . 2013-01-27 18:54 -------- d-----w- C:\f12faa67f3615af0b880
2013-01-26 03:55 . 2013-01-26 03:55 552448 -c----w- c:\windows\system32\dllcache\oleaut32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-02-18 05:11 . 2010-03-04 00:54 285256 ----a-w- c:\windows\system32\guard32.dll
2013-01-26 03:55 . 2004-08-04 12:00 552448 ----a-w- c:\windows\system32\oleaut32.dll
2013-01-07 01:19 . 2004-08-04 12:00 2148864 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-01-07 00:37 . 2004-08-03 22:59 2027520 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-01-04 01:20 . 2004-08-04 12:00 1867264 ----a-w- c:\windows\system32\win32k.sys
2013-01-02 06:49 . 2004-08-04 12:00 148992 ----a-w- c:\windows\system32\mpg2splt.ax
2013-01-02 06:49 . 2004-08-04 12:00 1292288 ----a-w- c:\windows\system32\quartz.dll
2012-12-26 20:16 . 2004-08-04 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2012-12-26 20:16 . 2004-08-04 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2012-12-26 20:16 . 2004-08-04 12:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2012-12-24 06:40 . 2004-08-04 12:00 385024 ----a-w- c:\windows\system32\html.iec
2012-12-16 12:23 . 2004-08-04 12:00 290560 ----a-w- c:\windows\system32\atmfd.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-10-30 23:50 121528 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-10-07 323392]
"Aim"="c:\program files\AIM\aim.exe" [2012-05-30 4331392]
"Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2010-01-28 2937528]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"UVS12 Preload"="c:\program files\Corel\Corel VideoStudio 12\uvPL.exe" [2008-06-09 397456]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"PC Pitstop Optimize Scheduler"="c:\program files\PCPitstop\Optimize\PCPOptimize.exe" [2008-03-26 2577120]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2009-03-12 483422]
"SoundMan"="SOUNDMAN.EXE" [2004-11-15 77824]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-10-30 4297136]
"DLCXCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll" [2006-10-16 106496]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\guard32.dll
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone V3\\support\\bin\\win\\RosettaStoneLtdServices.exe"=
"c:\\Program Files\\Rosetta Stone\\Rosetta Stone V3\\RosettaStoneVersion3.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\WINDOWS\\system32\\dlcxcoms.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56294:TCP"= 56294:TCP:Pando Media Booster
"56294:UDP"= 56294:UDP:Pando Media Booster
"<NO NAME>"=
"58422:TCP"= 58422:TCP:Pando Media Booster
"58422:UDP"= 58422:UDP:Pando Media Booster
"58670:TCP"= 58670:TCP:Pando Media Booster
"58670:UDP"= 58670:UDP:Pando Media Booster
"57761:TCP"= 57761:TCP:Pando Media Booster
"57761:UDP"= 57761:UDP:Pando Media Booster
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [5/4/2009 5:58 PM 721904]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2/16/2013 9:07 PM 738504]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2/16/2013 9:07 PM 361032]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2/16/2013 9:07 PM 21256]
R2 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [10/21/2011 3:23 PM 196176]
R2 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\SeaPort.EXE [10/13/2011 5:21 PM 249648]
R2 dlcx_device;dlcx_device;c:\windows\system32\dlcxcoms.exe -service --> c:\windows\system32\dlcxcoms.exe -service [?]
R2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [4/11/2009 3:39 PM 1373480]
R3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [11/29/2009 7:24 PM 47360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-02-17 01:09 1607120 ----a-w- c:\program files\Google\Chrome\Application\24.0.1312.57\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-02-20 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2013-02-17 23:50]
.
2013-02-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-02-17 01:09]
.
2013-02-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-02-17 01:09]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
IE: &Winamp Search - c:\documents and settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
TCP: DhcpNameServer = 209.18.47.61 209.18.47.62
FF - ProfilePath - c:\documents and settings\Ally\Application Data\Mozilla\Firefox\Profiles\iym1yxeh.default\
FF - prefs.js: browser.search.defaulturl -
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2013-02-19 21:44
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCXCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1417001333-287218729-682003330-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
@Denied: (Full) (LocalSystem)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(3824)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Stardock\Object Desktop\IconPackager\iprepair.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\dlcxcoms.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\system32\WTablet\Pen_TabletUser.exe
c:\windows\SOUNDMAN.EXE
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2013-02-19 21:47:19 - machine was rebooted
ComboFix-quarantined-files.txt 2013-02-20 02:47
ComboFix2.txt 2013-02-19 22:08
ComboFix3.txt 2013-02-18 03:22
.
Pre-Run: 305,036,136,448 bytes free
Post-Run: 304,950,747,136 bytes free
.
- - End Of File - - 34B489414C71819A259444F489A30ABA