FYI - Before I run ComboFix it gives me this warning:
ComboFix has detected the following real time scanner(s) to be active:
antivirus: CyberDefender Internet Security
I can't locate this program anywhere to disable (or get rid of) it.
ComboFix 09-10-13.01 - louish 10/13/2009 13:30.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1461 [GMT -7:00]
Running from: c:\documents and settings\louish\Desktop\Combo-Fix.exe
AV: CyberDefender Internet Security *On-access scanning enabled* (Updated) {D7B67E25-9B99-48A7-89AB-E3D8D7716279}
AV: F-Secure Anti-Virus 2010 10.00 *On-access scanning disabled* (Updated) {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\louish\LOCALS~1\Temp\catchme.dll
c:\documents and settings\louish\Local Settings\temp\catchme.dll
c:\windows\system32\Cache
.
((((((((((((((((((((((((( Files Created from 2009-09-13 to 2009-10-13 )))))))))))))))))))))))))))))))
.
2009-10-12 17:17 . 2009-10-12 17:32 33920 ----a-w- c:\windows\system32\drivers\fsbts.sys
2009-10-12 17:17 . 2009-07-09 09:33 80000 ----a-w- c:\windows\system32\drivers\fsdfw.sys
2009-10-12 17:16 . 2009-10-12 18:08 -------- d-----w- c:\program files\F-Secure
2009-10-12 17:14 . 2009-10-12 17:17 -------- d-----w- c:\documents and settings\All Users\Application Data\f-secure
2009-10-12 14:22 . 2009-10-12 14:22 -------- d-----w- c:\program files\Java
2009-10-11 23:48 . 2009-07-19 13:32 6067200 -c----w- c:\windows\system32\dllcache\ieframe.dll
2009-10-11 23:48 . 2009-06-29 16:12 52224 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-10-11 23:48 . 2009-06-29 16:12 459264 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2009-10-11 23:48 . 2009-06-29 16:12 268288 -c----w- c:\windows\system32\dllcache\iertutil.dll
2009-10-11 23:48 . 2009-06-29 16:12 63488 -c----w- c:\windows\system32\dllcache\icardie.dll
2009-10-11 23:48 . 2009-06-29 16:12 380928 -c----w- c:\windows\system32\dllcache\ieapfltr.dll
2009-10-11 23:48 . 2009-06-29 11:07 13824 -c----w- c:\windows\system32\dllcache\ieudinit.exe
2009-10-11 21:37 . 2005-07-08 21:19 666 ----a-w- c:\windows\speed.reg
2009-10-11 19:17 . 2009-10-11 19:17 -------- d-----w- c:\program files\Common Files\Zeepe Framework 7
2009-10-11 17:07 . 2009-10-11 17:07 -------- d-----w- c:\windows\system32\vmm32
2009-10-11 16:13 . 2001-08-18 05:36 23040 -c--a-w- c:\windows\system32\dllcache\xrxwbtmp.dll
2009-10-11 16:13 . 2001-08-18 05:37 27648 -c--a-w- c:\windows\system32\dllcache\xrxftplt.exe
2009-10-11 16:13 . 2001-08-18 05:37 4608 -c--a-w- c:\windows\system32\dllcache\xrxflnch.exe
2009-10-11 16:13 . 2001-08-18 05:37 99865 -c--a-w- c:\windows\system32\dllcache\xlog.exe
2009-10-11 16:13 . 2001-08-17 19:11 16970 -c--a-w- c:\windows\system32\dllcache\xem336n5.sys
2009-10-11 16:11 . 2004-08-04 05:29 11775 -c--a-w- c:\windows\system32\dllcache\wadv05nt.sys
2009-10-11 16:10 . 2001-08-17 20:28 793598 -c--a-w- c:\windows\system32\dllcache\usr1806.sys
2009-10-11 16:09 . 2001-08-17 21:56 440576 -c--a-w- c:\windows\system32\dllcache\tridkb.dll
2009-10-11 16:08 . 2001-08-17 21:56 172768 -c--a-w- c:\windows\system32\dllcache\t2r4disp.dll
2009-10-11 16:07 . 2001-08-17 19:51 37040 -c--a-w- c:\windows\system32\dllcache\sonypi.sys
2009-10-11 16:06 . 2001-08-18 05:36 238592 -c--a-w- c:\windows\system32\dllcache\sisgrv.dll
2009-10-11 16:05 . 2001-08-17 20:51 16640 -c--a-w- c:\windows\system32\dllcache\scmstcs.sys
2009-10-11 16:04 . 2001-08-18 05:36 9216 -c--a-w- c:\windows\system32\dllcache\rsmgrstr.dll
2009-10-11 16:03 . 2001-08-17 20:53 17792 -c--a-w- c:\windows\system32\dllcache\ppa.sys
2009-10-11 16:02 . 2001-08-18 05:36 41984 -c--a-w- c:\windows\system32\dllcache\ovui2rc.dll
2009-10-11 16:01 . 2001-08-17 20:53 7552 -c--a-w- c:\windows\system32\dllcache\nsmmc.sys
2009-10-11 16:00 . 2001-08-17 19:50 103296 -c--a-w- c:\windows\system32\dllcache\mtxvideo.sys
2009-10-11 16:00 . 2001-08-17 20:48 12416 -c--a-w- c:\windows\system32\dllcache\msriffwv.sys
2009-10-11 16:00 . 2001-08-17 21:00 2944 -c--a-w- c:\windows\system32\dllcache\msmpu401.sys
2009-10-11 16:00 . 2001-08-17 21:02 35200 -c--a-w- c:\windows\system32\dllcache\msgame.sys
2009-10-11 16:00 . 2001-08-17 20:48 6016 -c--a-w- c:\windows\system32\dllcache\msfsio.sys
2009-10-11 16:00 . 2001-08-17 20:57 16128 -c--a-w- c:\windows\system32\dllcache\modemcsa.sys
2009-10-11 15:58 . 2001-08-17 19:11 25065 -c--a-w- c:\windows\system32\dllcache\lmndis3.sys
2009-10-11 15:58 . 2001-08-17 20:51 15744 -c--a-w- c:\windows\system32\dllcache\lit220p.sys
2009-10-11 15:58 . 2001-08-17 19:12 26442 -c--a-w- c:\windows\system32\dllcache\lanepic5.sys
2009-10-11 15:58 . 2001-08-17 19:12 19016 -c--a-w- c:\windows\system32\dllcache\ktc111.sys
2009-10-11 15:58 . 2001-08-18 05:36 37376 -c--a-w- c:\windows\system32\dllcache\kousd.dll
2009-10-11 15:58 . 2001-08-18 05:36 8192 -c--a-w- c:\windows\system32\dllcache\kbdkor.dll
2009-10-11 15:58 . 2001-08-18 05:36 8704 -c--a-w- c:\windows\system32\dllcache\kbdjpn.dll
2009-10-11 15:58 . 2001-08-17 21:55 5632 -c--a-w- c:\windows\system32\dllcache\kbd103.dll
2009-10-11 15:58 . 2001-08-17 21:55 6144 -c--a-w- c:\windows\system32\dllcache\kbd101c.dll
2009-10-11 15:58 . 2001-08-17 21:55 6144 -c--a-w- c:\windows\system32\dllcache\kbd101b.dll
2009-10-11 15:58 . 2001-08-17 20:49 26624 -c--a-w- c:\windows\system32\dllcache\irstusb.sys
2009-10-11 15:56 . 2001-08-17 21:05 141056 -c--a-w- c:\windows\system32\dllcache\icam3.sys
2009-10-11 15:55 . 2001-08-17 20:28 67167 -c--a-w- c:\windows\system32\dllcache\hsf_bsc2.sys
2009-10-11 15:54 . 2001-08-17 21:56 470144 -c--a-w- c:\windows\system32\dllcache\g200d.dll
2009-10-11 15:53 . 2001-08-17 20:28 347550 -c--a-w- c:\windows\system32\dllcache\es56tpi.sys
2009-10-11 15:52 . 2001-08-17 19:11 29696 -c--a-w- c:\windows\system32\dllcache\dm9pci5.sys
2009-10-11 15:51 . 2001-08-17 19:19 3584 -c--a-w- c:\windows\system32\dllcache\cwcosnt5.sys
2009-10-11 15:50 . 2001-08-17 20:51 13824 -c--a-w- c:\windows\system32\dllcache\bulltlp3.sys
2009-10-11 15:49 . 2004-08-04 05:31 36224 -c--a-w- c:\windows\system32\dllcache\an983.sys
2009-10-10 19:40 . 2009-10-10 19:40 -------- d-----w- c:\program files\AOL Toolbar
2009-10-10 19:18 . 2009-10-10 19:18 -------- d-----w- c:\program files\Common Files\Software Update Utility
2009-10-10 19:18 . 2003-01-10 21:13 33588 ----a-r- c:\windows\system32\drivers\wanatw4.sys
2009-10-10 19:17 . 2009-10-11 15:21 -------- d-----w- c:\program files\AOL 9.1
2009-10-09 21:03 . 2009-10-09 21:03 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\AOL
2009-10-09 05:01 . 2009-06-29 08:33 2452872 -c----w- c:\windows\system32\dllcache\ieapfltr.dat
2009-10-08 20:43 . 2009-10-08 20:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-10-08 20:43 . 2009-10-08 20:43 -------- d-----w- c:\program files\Viewpoint
2009-10-08 18:51 . 2009-10-09 19:00 65 ----a-w- c:\windows\system32\BD7020.dat
2009-10-08 18:50 . 2003-11-29 01:57 0 ----a-w- c:\windows\brdfxspd.dat
2009-10-08 17:42 . 2009-10-09 18:45 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters(2)
2009-10-08 16:25 . 2009-10-08 16:25 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\F-Secure
2009-10-08 16:23 . 2009-10-12 17:16 -------- d-----w- c:\documents and settings\All Users\Application Data\fssg
2009-10-08 03:16 . 2008-09-10 01:14 1307648 -c----w- c:\windows\system32\dllcache\msxml6.dll
2009-10-08 03:16 . 2008-04-13 17:27 79872 -c----w- c:\windows\system32\dllcache\msxml6r.dll
2009-10-08 02:48 . 2009-10-11 18:33 -------- d-----w- c:\documents and settings\louish\Local Settings\Application Data\Deployment
2009-10-08 02:36 . 2009-03-06 14:22 284160 -c----w- c:\windows\system32\dllcache\pdh.dll
2009-10-08 02:36 . 2009-02-09 12:10 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2009-10-08 02:36 . 2009-02-09 12:10 617472 -c----w- c:\windows\system32\dllcache\advapi32.dll
2009-10-08 02:36 . 2009-02-09 12:10 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2009-10-08 02:36 . 2009-02-09 12:10 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2009-10-08 02:36 . 2009-02-06 11:11 110592 -c----w- c:\windows\system32\dllcache\services.exe
2009-10-08 02:36 . 2009-02-06 10:10 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2009-10-08 02:36 . 2009-02-09 12:10 714752 -c----w- c:\windows\system32\dllcache\ntdll.dll
2009-10-08 02:36 . 2009-02-06 11:06 2145280 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-10-08 02:36 . 2009-02-06 11:08 2189056 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-10-08 02:36 . 2009-02-06 10:32 2023936 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-10-08 02:34 . 2008-10-24 11:21 455296 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2009-10-08 02:29 . 2009-05-21 18:46 268288 -c----w- c:\windows\system32\dllcache\httpext.dll
2009-10-08 02:22 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2009-10-08 02:22 . 2008-12-11 10:57 333952 -c----w- c:\windows\system32\dllcache\srv.sys
2009-10-08 02:22 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2009-10-08 02:22 . 2008-04-11 19:04 691712 -c----w- c:\windows\system32\dllcache\inetcomm.dll
2009-10-08 02:21 . 2008-10-15 16:34 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2009-10-08 02:20 . 2008-04-21 12:08 215552 -c----w- c:\windows\system32\dllcache\wordpad.exe
2009-10-07 22:56 . 2007-05-18 17:45 172032 ----a-w- c:\windows\system32\igfxres.dll
2009-10-07 21:59 . 2004-08-04 10:00 14848 -c--a-w- c:\windows\system32\dllcache\register.exe
2009-10-07 21:58 . 2008-04-14 00:09 81976 -c--a-w- c:\windows\system32\dllcache\imjpdct.dll
2009-10-07 21:53 . 2004-08-04 10:00 16384 -c--a-w- c:\windows\system32\dllcache\isignup.exe
2009-10-07 21:50 . 2004-08-04 10:00 7680 -c--a-w- c:\windows\system32\dllcache\inetmgr.exe
2009-10-07 21:35 . 2004-08-04 10:00 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
2009-10-07 21:35 . 2004-08-04 10:00 24661 ----a-w- c:\windows\system32\spxcoins.dll
2009-10-07 21:35 . 2004-08-04 10:00 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
2009-10-07 21:35 . 2004-08-04 10:00 13312 ----a-w- c:\windows\system32\irclass.dll
2009-10-07 17:45 . 2009-10-13 02:36 -------- d-----w- c:\program files\Roxio
2009-10-07 14:23 . 2009-10-07 14:23 -------- d-----w- c:\windows\dell
2009-10-06 21:26 . 2007-07-24 22:58 95616 ----a-w- c:\windows\junction.exe
2009-10-06 15:04 . 2009-10-12 14:22 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-06 00:18 . 2009-10-06 00:19 -------- d-----w- C:\Combo-Fix8085C
2009-10-05 21:36 . 2009-10-05 21:36 -------- d-----w- C:\My Shared Folder
2009-10-05 21:36 . 2009-10-05 21:36 -------- d-----w- c:\documents and settings\louish\Application Data\Kazaa Lite
2009-10-05 21:36 . 2009-10-05 21:50 -------- d-----w- c:\program files\LimeWire
2009-10-05 20:21 . 2009-10-05 21:36 -------- d-----w- C:\Combo-Fix
2009-10-05 16:53 . 2009-10-05 16:53 11952 ----a-w- c:\windows\system32\avgrsstx(2).dll
2009-10-05 16:53 . 2009-10-05 16:57 -------- d-----w- c:\windows\system32\drivers\Avg(2)
2009-10-05 16:52 . 2009-10-05 21:36 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-10-05 16:52 . 2009-10-05 16:52 -------- d-----w- c:\program files\AVG
2009-10-05 16:52 . 2009-10-05 21:35 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-10-05 14:42 . 2009-10-05 14:42 -------- d-----w- c:\program files\Trend Micro
2009-10-04 19:31 . 2009-10-04 19:31 -------- d-----w- C:\GHOSTS_OF_GIRLFRIENDS_PAST
2009-10-04 18:08 . 2009-09-10 21:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-04 18:08 . 2009-09-10 21:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-04 18:08 . 2009-10-04 18:08 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-04 01:05 . 2009-10-04 01:12 -------- d-----w- c:\windows\BDOSCAN8
2009-10-04 00:16 . 2009-10-04 18:38 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-10-02 17:46 . 2009-10-01 17:29 195440 ----a-w- c:\windows\system32\MpSigStub.exe
2009-10-01 20:43 . 2009-10-01 20:43 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-10-01 20:43 . 2009-10-01 20:43 -------- d-----w- c:\documents and settings\louish\Application Data\SUPERAntiSpyware.com
2009-10-01 20:07 . 2009-10-01 20:07 129 ----a-w- c:\documents and settings\louish\Local Settings\Application Data\fusioncache.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-13 20:05 . 2008-10-30 21:13 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-13 16:46 . 2007-12-14 02:09 -------- d-----w- c:\program files\Paint Shop Pro 5
2009-10-13 15:36 . 2009-10-13 15:36 -------- d-----w- c:\documents and settings\louish\Application Data\Regensoft
2009-10-13 15:35 . 2009-10-13 15:35 -------- d-----w- c:\documents and settings\louish\Application Data\Red Kawa
2009-10-13 15:29 . 2009-10-13 15:29 -------- d-----w- c:\program files\Regensoft
2009-10-13 15:29 . 2008-05-12 20:24 -------- d-----w- c:\program files\Red Kawa
2009-10-13 15:20 . 2007-12-08 14:30 68648 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-13 04:02 . 2007-12-08 14:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-10-13 04:00 . 2007-12-08 14:21 -------- d-----w- c:\program files\Microsoft Works
2009-10-13 03:15 . 2007-12-19 21:28 -------- d-----w- c:\documents and settings\louish\Application Data\Roxio
2009-10-13 02:38 . 2007-12-08 14:17 -------- d-----w- c:\program files\Common Files\Roxio Shared
2009-10-12 16:34 . 2007-12-08 14:24 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-10-12 15:36 . 2007-12-12 23:42 -------- d-----w- c:\documents and settings\louish\Application Data\Wave Systems Corp
2009-10-11 21:41 . 2009-10-11 21:41 5 ----a-w- c:\windows\system32\drivers\DELL_LAT_D830.MRK
2009-10-11 21:41 . 2007-12-08 13:40 5 -c--a-w- c:\windows\system32\drivers\1028_Dell_LAT_D830.mrk
2009-10-11 21:37 . 2007-12-08 14:02 -------- d-----w- c:\program files\Dell
2009-10-11 19:17 . 2007-12-08 14:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Novatel Wireless
2009-10-10 19:44 . 2007-12-14 01:46 -------- d-----w- c:\program files\Common Files\aol
2009-10-10 19:19 . 2007-12-14 01:48 -------- d-----w- c:\documents and settings\louish\Application Data\AOL
2009-10-10 19:19 . 2007-12-14 01:46 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL
2009-10-10 19:17 . 2009-10-09 18:42 -------- d-----w- c:\program files\Common Files\aolshare
2009-10-09 20:45 . 2007-12-14 01:30 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL Downloads
2009-10-07 21:51 . 2004-08-11 23:12 27904 -c--a-w- c:\windows\system32\emptyregdb.dat
2009-10-07 15:40 . 2008-10-22 04:02 -------- d-----w- c:\program files\CCleaner
2009-10-06 17:58 . 2007-12-12 23:21 -------- d-----w- c:\documents and settings\Default User\Application Data\Wave Systems Corp
2009-10-06 05:17 . 2008-05-09 18:35 -------- d-----w- c:\program files\MP3 Rocket
2009-10-05 21:36 . 2007-12-17 18:26 -------- d-----w- c:\documents and settings\louish\Application Data\LimeWire
2009-10-04 19:25 . 2009-09-02 14:26 -------- d-----w- c:\program files\DVD Decrypter
2009-10-02 16:01 . 2007-12-12 23:21 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Wave Systems Corp
2009-10-01 18:40 . 2008-10-22 02:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-09-17 14:58 . 2008-09-03 02:36 -------- d-----w- c:\documents and settings\louish\Application Data\Move Networks
2009-09-16 17:26 . 2008-08-18 15:44 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-12 05:12 . 2009-09-06 21:53 -------- d-----w- c:\program files\Verizon
2009-09-12 05:11 . 2008-10-22 21:47 -------- d-----w- c:\program files\Speeditup Free
2009-09-12 05:11 . 2009-09-09 03:25 -------- d-----w- c:\program files\Advanced PC Tweaker
2009-09-12 05:10 . 2009-09-12 05:10 -------- d-----w- c:\documents and settings\All Users\Application Data\CopyTransControlCenter
2009-09-09 18:38 . 2009-09-09 18:38 -------- d-----w- c:\documents and settings\All Users\Application Data\WindSolutions
2009-09-09 18:38 . 2009-09-09 18:38 -------- d-----w- c:\documents and settings\louish\Application Data\WindSolutions
2009-09-06 22:02 . 2009-09-06 21:55 -------- d-----w- c:\documents and settings\louish\Application Data\Verizon
2009-09-03 01:34 . 2009-09-03 01:34 -------- d-----w- c:\documents and settings\All Users\Application Data\SlySoft
2009-08-21 17:07 . 2009-08-21 17:07 -------- d-----w- c:\program files\MSBuild
2009-08-21 17:06 . 2009-08-21 17:06 -------- d-----w- c:\program files\Reference Assemblies
2009-08-05 09:01 . 2004-08-04 10:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-29 04:37 . 2004-08-04 10:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-07-29 04:37 . 2004-08-04 10:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-07-17 19:01 . 2004-08-04 10:00 58880 ----a-w- c:\windows\system32\atl(2).dll
2009-07-17 18:55 . 2004-08-04 10:00 58880 ----a-w- c:\windows\system32\atl.dll
2001-12-04 00:09 . 2009-03-16 22:03 90112 ----a-w- c:\program files\internet explorer\plugins\DjVuControl.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{631ac2d4-57b3-42b0-a148-da33b462c1a3}"= "c:\program files\Absolutist_Games\tbAbso.dll" [2007-08-01 1391640]
[HKEY_CLASSES_ROOT\clsid\{631ac2d4-57b3-42b0-a148-da33b462c1a3}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{631ac2d4-57b3-42b0-a148-da33b462c1a3}]
2007-08-01 00:33 1391640 ----a-w- c:\program files\Absolutist_Games\tbAbso.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{631ac2d4-57b3-42b0-a148-da33b462c1a3}"= "c:\program files\Absolutist_Games\tbAbso.dll" [2007-08-01 1391640]
[HKEY_CLASSES_ROOT\clsid\{631ac2d4-57b3-42b0-a148-da33b462c1a3}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{631AC2D4-57B3-42B0-A148-DA33B462C1A3}"= "c:\program files\Absolutist_Games\tbAbso.dll" [2007-08-01 1391640]
[HKEY_CLASSES_ROOT\clsid\{631ac2d4-57b3-42b0-a148-da33b462c1a3}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-17 1392640]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2009-07-23 1181064]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"HostManager"="c:\program files\Common Files\AOL\1255202241\ee\AOLSoftware.exe" [2008-06-24 41824]
"systray"="c:\program files\Dell\Dell Mobile Broadband\systray.exe" [2007-04-13 331851]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-12 149280]
"F-Secure Manager"="c:\program files\F-Secure\Common\FSM32.EXE" [2009-07-09 199264]
"F-Secure TNB"="c:\program files\F-Secure\FSGUI\TNBUtil.exe" [2009-07-09 2349664]
"RoxioEngineUtility"="c:\program files\Common Files\Roxio Shared\System\EngUtil.exe" [2003-05-02 65536]
"RoxioDragToDisc"="c:\program files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe" [2003-07-17 868352]
"RoxioAudioCentral"="c:\program files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe" [2003-07-15 319488]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-05-06 20:59 10792 ----a-w- c:\program files\Citrix\GoToAssist\480\g2awinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\wxvault.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 wvauth
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"WmdmPmSN"=3 (0x3)
"W3SVC"=2 (0x2)
"UPS"=3 (0x3)
"mnmsrvc"=3 (0x3)
"gusvc"=3 (0x3)
"FLEXnet Licensing Service"=3 (0x3)
"Lavasoft Ad-Aware Service"=2 (0x2)
"iPod Service"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\aol\\acs\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\aol\\acs\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\aol\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\Common Files\\aol\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\aol\\System Information\\sinf.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\AOL 9.1\\waol.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"c:\\Program Files\\Common Files\\aol\\1255202241\\ee\\aolsoftware.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
R0 fsbts;fsbts;c:\windows\system32\drivers\fsbts.sys [10/12/2009 10:17 AM 33920]
R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [10/12/2009 10:17 AM 80000]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [10/1/2009 8:31 AM 206256]
R1 F-Secure HIPS;F-Secure HIPS Driver;c:\program files\F-Secure\HIPS\drivers\fshs.sys [10/12/2009 10:16 AM 68064]
R2 ASFIPmon;Broadcom ASF IP and SMBIOS Mailbox Monitor;c:\program files\Broadcom\ASFIPMon\AsfIpMon.exe [12/19/2006 1:21 PM 79432]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [10/1/2009 8:31 AM 348824]
R2 Wave UCSPlus;Wave UCSPlus;c:\windows\system32\dllhost.exe [8/4/2004 3:00 AM 5120]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\F-Secure\Anti-Virus\minifilter\fsgk.sys [10/12/2009 10:16 AM 100984]
R3 FSORSPClient;F-Secure ORSP Client;c:\program files\F-Secure\ORSP Client\fsorsp.exe [10/12/2009 10:16 AM 55904]
R3 NWDellModem;Dell Wireless Mobile Broadband Modem Driver;c:\windows\system32\drivers\nwdelmdm.sys [12/8/2007 6:41 AM 92288]
R3 NWDellPort;Dell Wireless Mobile Broadband Status Port Driver;c:\windows\system32\drivers\nwdelser.sys [12/8/2007 6:41 AM 92288]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
S3 DXEC01;DXEC01;c:\windows\system32\drivers\dxec01.sys [11/2/2006 11:32 AM 97536]
S4 F-Secure Filter;F-Secure File System Filter;c:\program files\F-Secure\Anti-Virus\win2k\fsfilter.sys [10/12/2009 10:16 AM 39776]
S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\F-Secure\Anti-Virus\win2k\fsrec.sys [10/12/2009 10:16 AM 25184]
--- Other Services/Drivers In Memory ---
*Deregistered* - mchInjDrv
.
Contents of the 'Scheduled Tasks' folder
2009-10-09 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 20:34]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.aol.com/?src=toolbaruSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) =
hxxp://www.google.com/search?q=%sIE: &AOL Toolbar Search - c:\documents and settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: c:\program files\F-Secure\FSPS\program\FSLSP.DLL
Trusted Zone: isqft.com\www
FF - ProfilePath - c:\documents and settings\louish\Application Data\Mozilla\Firefox\Profiles\ltpzphx1.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://search.aol.com/aolcom/search?invocationType=tb50ffTB50CLie7&query=FF - prefs.js: browser.search.selectedEngine - AOL Search
FF - prefs.js: browser.startup.homepage -
hxxp://www.aol.com/?ncid=toolbarFF - prefs.js: keyword.URL -
hxxp://search.aol.com/aolcom/search?invocationType=tb50ffTB50CLab&query=FF - plugin: c:\documents and settings\louish\Application Data\Move Networks\plugins\npqmp071500000347.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - hȋdden: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Google Update - c:\documents and settings\louish\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
HKLM-Run-ISUSPM Startup - c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
SafeBoot-mcmscsvc
SafeBoot-MCODS
AddRemove-AOL Toolbar 5.0 - c:\program files\AOL\AOL Toolbar 5.0\uninstall.exe
AddRemove-AOL Toolbar for Firefox - c:\documents and settings\louish\Application Data\Mozilla\Firefox\Profiles\ltpzphx1.default\extensions\{7affbfae-c4e2-4915-8c0f-00fa3ec610a1}\uninstall.exe
**************************************************************************
disk not found C:\
please note that you need administrator rights to perform deep scan
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
scan completed successfully
hȋdden files:
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(988)
c:\windows\system32\wxvault.dll
c:\windows\system32\detoured.dll
c:\program files\Citrix\GoToAssist\480\G2AWinLogon.dll
c:\program files\F-Secure\FSPS\program\FSLSP.DLL
- - - - - - - > 'lsass.exe'(1044)
c:\windows\system32\wxvault.dll
c:\windows\system32\detoured.dll
c:\windows\system32\wvauth.dll
c:\windows\system32\biolsp.dll
c:\program files\F-Secure\FSPS\program\FSLSP.DLL
c:\program files\Bonjour\mdnsNSP.dll
.
Completion time: 2009-10-13 13:39
ComboFix-quarantined-files.txt 2009-10-13 20:38
ComboFix2.txt 2009-10-04 16:43
Pre-Run: 9,465,389,056 bytes free
Post-Run: 9,674,579,968 bytes free
Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
356 --- E O F --- 2009-10-13 14:58