Here's the Combofix log. Thanks
ComboFix 09-12-02.05 - Mark Jeffords 12/02/2009 22:50.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.511.148 [GMT -5:00]
Running from: c:\documents and settings\Mark Jeffords\Desktop\Combo-Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Lauren Jeffords\Local Settings\Application Data\jqonsj
c:\documents and settings\Lauren Jeffords\Local Settings\Application Data\jqonsj\amwxsysguard.exe
c:\program files\Internet Explorer\msimg32.dll
c:\program files\PlaySushi\PSTExt.dll
c:\windows\desktop
c:\windows\desktop\Diva Starz(TM) CD-ROM.lnk
c:\windows\Downloaded Program Files\RdxIE.dll
c:\windows\system32\lsp.dll
c:\windows\system32\mydll.dll
.
((((((((((((((((((((((((( Files Created from 2009-11-03 to 2009-12-03 )))))))))))))))))))))))))))))))
.
2009-12-01 00:41 . 2009-12-01 00:41 -------- d-----w- c:\documents and settings\Alisa Jeffords\Application Data\Malwarebytes
2009-11-30 21:13 . 2009-11-30 21:13 -------- d-----w- c:\documents and settings\Lauren Jeffords\Application Data\Leadertech
2009-11-30 21:06 . 2009-11-30 21:06 -------- d-----w- c:\documents and settings\Lauren Jeffords\Application Data\Malwarebytes
2009-11-30 20:28 . 2009-11-30 20:28 -------- d-----w- c:\documents and settings\Hannah Jeffords\Application Data\Malwarebytes
2009-11-30 11:56 . 2009-11-30 11:56 -------- d-----w- c:\documents and settings\Ashley Jeffords\Application Data\Malwarebytes
2009-11-30 02:32 . 2009-11-30 02:32 -------- d-----w- c:\documents and settings\Mark Jeffords\Application Data\Malwarebytes
2009-11-30 02:32 . 2009-09-10 19:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-30 02:32 . 2009-11-30 02:32 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-30 02:32 . 2009-11-30 02:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-11-30 02:32 . 2009-09-10 19:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-29 18:40 . 2004-09-08 03:13 24520 ----a-w- c:\documents and settings\Administrator.JEFFORDS1\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-29 17:18 . 2009-11-29 17:18 -------- d-----w- c:\program files\Trend Micro
2009-11-13 01:25 . 2008-04-17 18:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-11-13 01:24 . 2009-11-13 01:24 -------- d-----w- c:\program files\iPod
2009-11-13 01:23 . 2009-11-13 01:25 -------- d-----w- c:\program files\iTunes
2009-11-13 01:13 . 2009-11-13 01:13 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-03 04:22 . 2009-10-29 01:42 -------- d-----w- c:\program files\PlaySushi
2009-12-03 01:53 . 2004-09-08 03:02 288 ----a-w- c:\windows\system32\DVCStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
2009-12-03 01:53 . 2004-09-08 03:02 288 ----a-w- c:\windows\system32\DVCState-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
2009-11-29 18:26 . 2004-09-08 03:06 10344 ----a-w- c:\windows\system32\drivers\symlcbrd.sys
2009-11-29 00:51 . 2009-10-29 01:44 -------- d-----w- c:\program files\qhaqan
2009-11-13 01:23 . 2008-12-25 16:57 -------- d-----w- c:\program files\Common Files\Apple
2009-11-04 21:45 . 2005-02-22 20:54 -------- d-----w- c:\documents and settings\Ashley Jeffords\Application Data\AdobeUM
2009-11-03 12:25 . 2008-05-01 01:47 -------- d-----w- c:\documents and settings\Lauren Jeffords\Application Data\U3
2009-11-01 02:02 . 2009-10-29 22:43 -------- d-----w- c:\documents and settings\Mark Jeffords\Application Data\U3
2009-10-30 00:04 . 2004-09-08 03:06 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-10-29 23:31 . 2009-10-29 23:31 46640 ----a-w- c:\windows\system32\msln.exe
2009-10-29 19:49 . 2009-10-29 19:49 -------- d-----w- c:\program files\MSN Toolbar Installer
2009-10-28 00:16 . 2008-01-19 14:32 -------- d-----w- c:\documents and settings\Lauren Jeffords\Application Data\FrostWire
2009-10-27 23:45 . 2009-10-27 23:45 43824 ---ha-w- c:\windows\system32\mlfcache.dat
2009-10-27 21:54 . 2009-10-27 21:54 -------- d-----w- c:\documents and settings\Hannah Jeffords\Application Data\AdobeUM
2009-10-27 15:42 . 2009-10-27 15:42 188928 ----a-w- c:\documents and settings\Alisa Jeffords\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@playsushi.com\components\PlaySushiFF.dll
2009-10-27 02:50 . 2004-10-24 19:39 -------- d-----w- c:\documents and settings\Mark Jeffords\Application Data\AdobeUM
2009-10-24 13:36 . 2009-06-02 14:35 -------- d-----w- c:\documents and settings\Ashley Jeffords\Application Data\Apple Computer
2009-10-19 21:39 . 2005-03-05 22:36 -------- d-----w- c:\documents and settings\Alisa Jeffords\Application Data\AdobeUM
2009-10-15 18:40 . 2008-12-25 17:01 -------- d-----w- c:\documents and settings\Lauren Jeffords\Application Data\Apple Computer
2009-10-15 18:32 . 2009-10-15 18:31 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-10-15 18:29 . 2009-10-15 18:29 -------- d-----w- c:\program files\QuickTime
2009-10-14 20:49 . 2005-01-20 00:07 -------- d-----w- c:\documents and settings\Lauren Jeffords\Application Data\AdobeUM
2009-09-25 05:49 . 2006-06-23 16:33 668672 ----a-w- c:\windows\system32\wininet.dll
2009-09-25 05:48 . 2004-08-04 07:56 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-09-11 14:33 . 2002-08-29 10:00 133632 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 20:45 . 2004-03-30 01:48 58880 ----a-w- c:\windows\system32\msasn1.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"MoneyAgent"="c:\program files\Microsoft Money\System\mnyexpr.exe" [2003-06-18 200704]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER" [X]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-11-03 4800512]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-11 53248]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184]
"CTSysVol"="c:\program files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe" [2002-10-29 49152]
"CTDVDDet"="c:\program files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE" [2002-09-30 45056]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-12 290816]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-03-15 122933]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"mmtask"="c:\program files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2004-04-19 53248]
"MMTray"="c:\program files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe" [2004-04-19 131072]
"HPDJ Taskbar Utility"="c:\windows\System32\spool\drivers\w32x86\3\hpztsb11.exe" [2004-04-06 172032]
"HPHUPD06"="c:\program files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2004-06-07 49152]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"HPHmon06"="c:\windows\System32\hphmon06.exe" [2004-06-07 659456]
"HostManager"="c:\program files\Common Files\AOL\1107989059\ee\AOLSoftware.exe" [2006-09-26 50736]
"AOLDialer"="c:\program files\Common Files\AOL\ACS\AOLDial.exe" [2006-10-23 71216]
"Pure Networks Port Magic"="c:\progra~1\PURENE~1\PORTMA~1\PortAOL.exe" [2004-04-05 99480]
"PaperPort PTD"="c:\program files\Scansoft\PaperPort\pptd40nt.exe" [2002-09-23 45108]
"IndexSearch"="c:\program files\Scansoft\PaperPort\IndexSearch.exe" [2002-09-23 36864]
"OneTouch Monitor"="c:\program files\Visioneer OneTouch\OneTouchMon.exe" [2003-08-18 98304]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"CTHelper"="CTHELPER.EXE" - c:\windows\SYSTEM32\CTHELPER.EXE [2003-02-20 28672]
"AsioReg"="CTASIO.DLL" - c:\windows\SYSTEM32\CTASIO.DLL [2003-02-20 110592]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1107989059\\EE\\aolsoftware.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\America Online 9.0a\\waol.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\BearShare Applications\\BearShare\\BearShare.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2/22/2007 5:11 PM 24652]
S3 lsscdbhk;lsscdbhk;\??\c:\docume~1\ASHLEY~1\LOCALS~1\Temp\lsscdbhk.sys --> c:\docume~1\ASHLEY~1\LOCALS~1\Temp\lsscdbhk.sys [?]
S3 MMCD;MMCD;\??\c:\docume~1\ALISAJ~1\LOCALS~1\Temp\MMCD.SYS --> c:\docume~1\ALISAJ~1\LOCALS~1\Temp\MMCD.SYS [?]
S3 NwudfRd;NwudfRd;\??\c:\docume~1\HANNAH~1\LOCALS~1\Temp\NwudfRd.sys --> c:\docume~1\HANNAH~1\LOCALS~1\Temp\NwudfRd.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2009-12-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2009-12-02 c:\windows\Tasks\HP Usg Daily FY04.job
- c:\program files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\pexpress\hphped06.exe [2004-06-07 04:53]
2009-09-18 c:\windows\Tasks\Norton Security Scan.job
- c:\program files\Norton Security Scan\Nss.exe [2007-04-20 03:42]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.aol.com/
mStart Page = hxxp://www.dell4me.com/myway
uInternet Connection Wizard,ShellNext = "c:\program files\MSN Gaming Zone\Windows\CHKRZM.EXE"
uInternet Settings,ProxyOverride =
uInternet Settings,ProxyServer = http=127.0.0.1:5555
IE: &AOL Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: {{EBD24BD3-E272-4FA3-A8BA-C5D709757CAB} - {EBD24BD3-E272-4FA3-A8BA-C5D709757CAB} - c:\program files\PlaySushi\PSText.dll
DPF: {6632A7E9-FE1F-43D2-A04A-A15951ED63E0} - hxxp://mediaplayer.walmart.com/installer/install.cab
DPF: {F91AB7B8-EE67-42AF-A5AA-8E232C396A04} - hxxps://www.creditcommander.com/cabs/htmlprint.cab
FF - ProfilePath - c:\documents and settings\Mark Jeffords\Application Data\Mozilla\Firefox\Profiles\q3idopo5.default\
FF - component: c:\program files\BearShare Applications\Personalization\FF_v1047\components\BearSharePersonalizationFF_v1047.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
- - - - ORPHANS REMOVED - - - -
AddRemove-BearShare - c:\program files\BearShare Applications\BearShare\UninstallSurvey.exe c:\progra~1\BEARSH~1\BEARSH~1\UNWISE.EXE
AddRemove-Playsushi - c:\program files\PlaySushi\psuninst.exe
AddRemove-RealPlayer 6.0 - c:\program files\Common Files\Real\Update\\rnuninst.exe RealNetworks|RealPlayer|6.0
AddRemove-RegPowerClean2007_is1 - c:\program files\Winferno\RegistryPowerCleaner\unins000.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-02 23:25
Windows 5.1.2600 Service Pack 2 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
scan completed successfully
hȋdden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\.mfp]
@DACL=(02 0000)
@="MacromediaFlashPaper.MacromediaFlashPaper"
"Content Type"="application/x-shockwave-flash"
[HKEY_LOCAL_MACHINE\software\Classes\.sol]
@DACL=(02 0000)
"Content Type"="text/plain"
[HKEY_LOCAL_MACHINE\software\Classes\.sor]
@DACL=(02 0000)
"Content Type"="text/plain"
.
Completion time: 2009-12-02 23:43
ComboFix-quarantined-files.txt 2009-12-03 04:42
Pre-Run: 106,350,702,592 bytes free
Post-Run: 108,277,817,344 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
- - End Of File - - A1C1E8F05A049126A4E5096921A0AC67
ComboFix 09-12-02.05 - Mark Jeffords 12/02/2009 22:50.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.511.148 [GMT -5:00]
Running from: c:\documents and settings\Mark Jeffords\Desktop\Combo-Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Lauren Jeffords\Local Settings\Application Data\jqonsj
c:\documents and settings\Lauren Jeffords\Local Settings\Application Data\jqonsj\amwxsysguard.exe
c:\program files\Internet Explorer\msimg32.dll
c:\program files\PlaySushi\PSTExt.dll
c:\windows\desktop
c:\windows\desktop\Diva Starz(TM) CD-ROM.lnk
c:\windows\Downloaded Program Files\RdxIE.dll
c:\windows\system32\lsp.dll
c:\windows\system32\mydll.dll
.
((((((((((((((((((((((((( Files Created from 2009-11-03 to 2009-12-03 )))))))))))))))))))))))))))))))
.
2009-12-01 00:41 . 2009-12-01 00:41 -------- d-----w- c:\documents and settings\Alisa Jeffords\Application Data\Malwarebytes
2009-11-30 21:13 . 2009-11-30 21:13 -------- d-----w- c:\documents and settings\Lauren Jeffords\Application Data\Leadertech
2009-11-30 21:06 . 2009-11-30 21:06 -------- d-----w- c:\documents and settings\Lauren Jeffords\Application Data\Malwarebytes
2009-11-30 20:28 . 2009-11-30 20:28 -------- d-----w- c:\documents and settings\Hannah Jeffords\Application Data\Malwarebytes
2009-11-30 11:56 . 2009-11-30 11:56 -------- d-----w- c:\documents and settings\Ashley Jeffords\Application Data\Malwarebytes
2009-11-30 02:32 . 2009-11-30 02:32 -------- d-----w- c:\documents and settings\Mark Jeffords\Application Data\Malwarebytes
2009-11-30 02:32 . 2009-09-10 19:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-30 02:32 . 2009-11-30 02:32 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-30 02:32 . 2009-11-30 02:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-11-30 02:32 . 2009-09-10 19:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-29 18:40 . 2004-09-08 03:13 24520 ----a-w- c:\documents and settings\Administrator.JEFFORDS1\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-29 17:18 . 2009-11-29 17:18 -------- d-----w- c:\program files\Trend Micro
2009-11-13 01:25 . 2008-04-17 18:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-11-13 01:24 . 2009-11-13 01:24 -------- d-----w- c:\program files\iPod
2009-11-13 01:23 . 2009-11-13 01:25 -------- d-----w- c:\program files\iTunes
2009-11-13 01:13 . 2009-11-13 01:13 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-03 04:22 . 2009-10-29 01:42 -------- d-----w- c:\program files\PlaySushi
2009-12-03 01:53 . 2004-09-08 03:02 288 ----a-w- c:\windows\system32\DVCStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
2009-12-03 01:53 . 2004-09-08 03:02 288 ----a-w- c:\windows\system32\DVCState-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
2009-11-29 18:26 . 2004-09-08 03:06 10344 ----a-w- c:\windows\system32\drivers\symlcbrd.sys
2009-11-29 00:51 . 2009-10-29 01:44 -------- d-----w- c:\program files\qhaqan
2009-11-13 01:23 . 2008-12-25 16:57 -------- d-----w- c:\program files\Common Files\Apple
2009-11-04 21:45 . 2005-02-22 20:54 -------- d-----w- c:\documents and settings\Ashley Jeffords\Application Data\AdobeUM
2009-11-03 12:25 . 2008-05-01 01:47 -------- d-----w- c:\documents and settings\Lauren Jeffords\Application Data\U3
2009-11-01 02:02 . 2009-10-29 22:43 -------- d-----w- c:\documents and settings\Mark Jeffords\Application Data\U3
2009-10-30 00:04 . 2004-09-08 03:06 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-10-29 23:31 . 2009-10-29 23:31 46640 ----a-w- c:\windows\system32\msln.exe
2009-10-29 19:49 . 2009-10-29 19:49 -------- d-----w- c:\program files\MSN Toolbar Installer
2009-10-28 00:16 . 2008-01-19 14:32 -------- d-----w- c:\documents and settings\Lauren Jeffords\Application Data\FrostWire
2009-10-27 23:45 . 2009-10-27 23:45 43824 ---ha-w- c:\windows\system32\mlfcache.dat
2009-10-27 21:54 . 2009-10-27 21:54 -------- d-----w- c:\documents and settings\Hannah Jeffords\Application Data\AdobeUM
2009-10-27 15:42 . 2009-10-27 15:42 188928 ----a-w- c:\documents and settings\Alisa Jeffords\Application Data\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\textlinks@playsushi.com\components\PlaySushiFF.dll
2009-10-27 02:50 . 2004-10-24 19:39 -------- d-----w- c:\documents and settings\Mark Jeffords\Application Data\AdobeUM
2009-10-24 13:36 . 2009-06-02 14:35 -------- d-----w- c:\documents and settings\Ashley Jeffords\Application Data\Apple Computer
2009-10-19 21:39 . 2005-03-05 22:36 -------- d-----w- c:\documents and settings\Alisa Jeffords\Application Data\AdobeUM
2009-10-15 18:40 . 2008-12-25 17:01 -------- d-----w- c:\documents and settings\Lauren Jeffords\Application Data\Apple Computer
2009-10-15 18:32 . 2009-10-15 18:31 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-10-15 18:29 . 2009-10-15 18:29 -------- d-----w- c:\program files\QuickTime
2009-10-14 20:49 . 2005-01-20 00:07 -------- d-----w- c:\documents and settings\Lauren Jeffords\Application Data\AdobeUM
2009-09-25 05:49 . 2006-06-23 16:33 668672 ----a-w- c:\windows\system32\wininet.dll
2009-09-25 05:48 . 2004-08-04 07:56 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-09-11 14:33 . 2002-08-29 10:00 133632 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 20:45 . 2004-03-30 01:48 58880 ----a-w- c:\windows\system32\msasn1.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"MoneyAgent"="c:\program files\Microsoft Money\System\mnyexpr.exe" [2003-06-18 200704]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER" [X]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-11-03 4800512]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-11 53248]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184]
"CTSysVol"="c:\program files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe" [2002-10-29 49152]
"CTDVDDet"="c:\program files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE" [2002-09-30 45056]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-12 290816]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-03-15 122933]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"mmtask"="c:\program files\MusicMatch\MusicMatch Jukebox\mmtask.exe" [2004-04-19 53248]
"MMTray"="c:\program files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe" [2004-04-19 131072]
"HPDJ Taskbar Utility"="c:\windows\System32\spool\drivers\w32x86\3\hpztsb11.exe" [2004-04-06 172032]
"HPHUPD06"="c:\program files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2004-06-07 49152]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"HPHmon06"="c:\windows\System32\hphmon06.exe" [2004-06-07 659456]
"HostManager"="c:\program files\Common Files\AOL\1107989059\ee\AOLSoftware.exe" [2006-09-26 50736]
"AOLDialer"="c:\program files\Common Files\AOL\ACS\AOLDial.exe" [2006-10-23 71216]
"Pure Networks Port Magic"="c:\progra~1\PURENE~1\PORTMA~1\PortAOL.exe" [2004-04-05 99480]
"PaperPort PTD"="c:\program files\Scansoft\PaperPort\pptd40nt.exe" [2002-09-23 45108]
"IndexSearch"="c:\program files\Scansoft\PaperPort\IndexSearch.exe" [2002-09-23 36864]
"OneTouch Monitor"="c:\program files\Visioneer OneTouch\OneTouchMon.exe" [2003-08-18 98304]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"CTHelper"="CTHELPER.EXE" - c:\windows\SYSTEM32\CTHELPER.EXE [2003-02-20 28672]
"AsioReg"="CTASIO.DLL" - c:\windows\SYSTEM32\CTASIO.DLL [2003-02-20 110592]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1107989059\\EE\\aolsoftware.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\America Online 9.0a\\waol.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\BearShare Applications\\BearShare\\BearShare.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2/22/2007 5:11 PM 24652]
S3 lsscdbhk;lsscdbhk;\??\c:\docume~1\ASHLEY~1\LOCALS~1\Temp\lsscdbhk.sys --> c:\docume~1\ASHLEY~1\LOCALS~1\Temp\lsscdbhk.sys [?]
S3 MMCD;MMCD;\??\c:\docume~1\ALISAJ~1\LOCALS~1\Temp\MMCD.SYS --> c:\docume~1\ALISAJ~1\LOCALS~1\Temp\MMCD.SYS [?]
S3 NwudfRd;NwudfRd;\??\c:\docume~1\HANNAH~1\LOCALS~1\Temp\NwudfRd.sys --> c:\docume~1\HANNAH~1\LOCALS~1\Temp\NwudfRd.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2009-12-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2009-12-02 c:\windows\Tasks\HP Usg Daily FY04.job
- c:\program files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\pexpress\hphped06.exe [2004-06-07 04:53]
2009-09-18 c:\windows\Tasks\Norton Security Scan.job
- c:\program files\Norton Security Scan\Nss.exe [2007-04-20 03:42]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.aol.com/
mStart Page = hxxp://www.dell4me.com/myway
uInternet Connection Wizard,ShellNext = "c:\program files\MSN Gaming Zone\Windows\CHKRZM.EXE"
uInternet Settings,ProxyOverride =
uInternet Settings,ProxyServer = http=127.0.0.1:5555
IE: &AOL Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: {{EBD24BD3-E272-4FA3-A8BA-C5D709757CAB} - {EBD24BD3-E272-4FA3-A8BA-C5D709757CAB} - c:\program files\PlaySushi\PSText.dll
DPF: {6632A7E9-FE1F-43D2-A04A-A15951ED63E0} - hxxp://mediaplayer.walmart.com/installer/install.cab
DPF: {F91AB7B8-EE67-42AF-A5AA-8E232C396A04} - hxxps://www.creditcommander.com/cabs/htmlprint.cab
FF - ProfilePath - c:\documents and settings\Mark Jeffords\Application Data\Mozilla\Firefox\Profiles\q3idopo5.default\
FF - component: c:\program files\BearShare Applications\Personalization\FF_v1047\components\BearSharePersonalizationFF_v1047.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
- - - - ORPHANS REMOVED - - - -
AddRemove-BearShare - c:\program files\BearShare Applications\BearShare\UninstallSurvey.exe c:\progra~1\BEARSH~1\BEARSH~1\UNWISE.EXE
AddRemove-Playsushi - c:\program files\PlaySushi\psuninst.exe
AddRemove-RealPlayer 6.0 - c:\program files\Common Files\Real\Update\\rnuninst.exe RealNetworks|RealPlayer|6.0
AddRemove-RegPowerClean2007_is1 - c:\program files\Winferno\RegistryPowerCleaner\unins000.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-02 23:25
Windows 5.1.2600 Service Pack 2 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
scan completed successfully
hȋdden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\.mfp]
@DACL=(02 0000)
@="MacromediaFlashPaper.MacromediaFlashPaper"
"Content Type"="application/x-shockwave-flash"
[HKEY_LOCAL_MACHINE\software\Classes\.sol]
@DACL=(02 0000)
"Content Type"="text/plain"
[HKEY_LOCAL_MACHINE\software\Classes\.sor]
@DACL=(02 0000)
"Content Type"="text/plain"
.
Completion time: 2009-12-02 23:43
ComboFix-quarantined-files.txt 2009-12-03 04:42
Pre-Run: 106,350,702,592 bytes free
Post-Run: 108,277,817,344 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
- - End Of File - - A1C1E8F05A049126A4E5096921A0AC67