There seems to be none of that constant disk caching anymore. At least when I'm not running ComboFix.

I do have one glitch that's been going on for while. When I send mail in Outlook Express on my IMAP account, it doesn't copy the mail to the sent folder even though that option is checked in the configuration settings. I deleted the email account, the sent items.dbx file, and reinstalled the account, and it didn't correct the problem.
Thanks for your assistance.
The ComboFix report follows.
ComboFix 11-09-12.03 - Alin 09/12/2011 14:47:52.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.510.310 [GMT -7:00]
Running from: c:\documents and settings\Alin\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Alin\Desktop\CFScript.txt
AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system\oeminfo.ini
c:\windows\system32\gotomon.log
.
.
((((((((((((((((((((((((( Files Created from 2011-08-12 to 2011-09-12 )))))))))))))))))))))))))))))))
.
.
2011-09-12 19:49 . 2011-09-12 20:18 -------- d-----w- C:\OE backup
2011-09-11 01:07 . 2001-08-18 05:36 7168 -c--a-w- c:\windows\system32\dllcache\EXCH_snprfdll.dll
2011-09-11 01:07 . 2001-08-18 05:36 12288 -c--a-w- c:\windows\system32\dllcache\EXCH_smtpctrs.dll
2011-09-11 01:07 . 2001-08-18 05:36 26112 -c--a-w- c:\windows\system32\dllcache\EXCH_seos.dll
2011-09-11 01:07 . 2001-08-18 05:36 57856 -c--a-w- c:\windows\system32\dllcache\EXCH_scripto.dll
2011-09-11 01:07 . 2001-08-18 05:36 23040 -c--a-w- c:\windows\system32\dllcache\EXCH_regtrace.exe
2011-09-11 01:07 . 2001-08-18 05:36 38912 -c--a-w- c:\windows\system32\dllcache\EXCH_ntfsdrv.dll
2011-09-11 01:05 . 2004-08-12 13:19 7680 -c--a-w- c:\windows\system32\dllcache\ftpctrs2.dll
2011-09-11 01:04 . 2004-08-12 13:17 108544 -c--a-w- c:\windows\system32\dllcache\appconf.dll
2011-09-11 00:46 . 2004-08-12 13:29 24661 ----a-w- c:\windows\system32\spxcoins.dll
2011-09-11 00:46 . 2004-08-12 13:20 13312 ----a-w- c:\windows\system32\irclass.dll
2011-09-11 00:46 . 2004-08-12 13:20 13753 ----a-r- c:\windows\SETFE.tmp
2011-09-11 00:46 . 2004-08-12 13:25 1086058 ----a-r- c:\windows\SETF2.tmp
2011-09-11 00:46 . 2004-08-12 13:29 1042903 ----a-r- c:\windows\SETEF.tmp
2011-09-11 00:21 . 2004-08-12 13:20 16384 ----a-w- c:\program files\Internet Explorer\Connection Wizard\isignup.exe
2011-09-11 00:04 . 2004-08-12 13:20 13753 ----a-r- c:\windows\SET180.tmp
2011-09-11 00:04 . 2004-08-12 13:25 1086058 ----a-r- c:\windows\SET174.tmp
2011-09-11 00:03 . 2004-08-12 13:29 1042903 ----a-r- c:\windows\SET171.tmp
2011-09-11 00:03 . 2011-09-11 00:03 -------- d-s---w- c:\windows\system32\config\systemprofile\History
2011-09-10 16:52 . 2011-09-10 16:52 -------- d-----w- c:\windows\dell
2011-09-10 03:34 . 2005-07-20 01:26 61440 ----a-w- c:\windows\system32\iAlmCoIn_v4363.dll
2011-09-10 03:07 . 2011-09-10 03:07 -------- d-----w- c:\program files\ESET
2011-09-10 03:06 . 2011-09-10 03:07 -------- d-----w- C:\Eset online scan
2011-09-01 19:35 . 2011-09-01 20:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2011-09-01 19:35 . 2011-09-01 19:43 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-09-01 03:12 . 2011-09-01 03:12 -------- d-----w- c:\documents and settings\Alin\Application Data\Malwarebytes
2011-09-01 03:11 . 2011-07-07 02:52 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-09-01 03:11 . 2011-09-01 03:11 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-09-01 03:11 . 2011-07-07 02:52 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-09-01 03:11 . 2011-09-01 03:11 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-08-21 01:34 . 2011-09-10 06:33 -------- d-----w- c:\program files\Mozilla Firefox 6
2011-08-20 22:40 . 2011-08-20 22:40 -------- d-----w- C:\Appliances
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-11 16:57 . 2011-08-11 16:57 1409 ----a-w- c:\windows\QTFont.for
2011-06-29 05:35 . 2010-03-28 03:26 66616 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-06-29 05:35 . 2010-03-28 03:26 138192 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-01-25 18:58 . 2010-07-28 18:51 462848 ----a-w- c:\program files\mozilla firefox\plugins\ractrlkeyhook.dll
2010-03-27 00:24 . 2005-01-14 01:56 67688 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2010-03-27 00:24 . 2005-01-14 01:56 54368 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2010-03-27 00:24 . 2006-12-21 23:47 34944 ----a-w- c:\program files\mozilla firefox\components\myspell.dll
2010-03-27 00:24 . 2006-12-21 23:47 46712 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll
2010-03-27 00:24 . 2005-01-14 01:56 172136 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-09-12_15.13.03 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-29 06:42 . 2009-06-29 06:42 91656 c:\windows\WinSxS\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.1.0_x-ww_2a41bceb\msxml4r.dll
+ 2004-08-12 13:32 . 2009-06-25 08:44 59392 c:\windows\SYSTEM32\wdigest.dll
+ 2004-08-12 13:28 . 2009-06-25 08:44 56320 c:\windows\SYSTEM32\secur32.dll
+ 2004-08-12 13:22 . 2009-06-25 18:36 48640 c:\windows\SYSTEM32\mqupgrd.dll
- 2004-08-12 13:22 . 2004-08-12 13:22 48640 c:\windows\SYSTEM32\mqupgrd.dll
- 2004-08-12 13:22 . 2004-08-12 13:22 95744 c:\windows\SYSTEM32\mqsec.dll
+ 2004-08-12 13:22 . 2009-06-25 18:36 95744 c:\windows\SYSTEM32\mqsec.dll
+ 2004-08-12 13:22 . 2009-06-25 18:36 16896 c:\windows\SYSTEM32\mqise.dll
- 2004-08-12 13:22 . 2004-08-12 13:22 16896 c:\windows\SYSTEM32\mqise.dll
- 2004-08-12 13:22 . 2004-08-12 13:22 47104 c:\windows\SYSTEM32\mqdscli.dll
+ 2004-08-12 13:22 . 2009-06-25 18:36 47104 c:\windows\SYSTEM32\mqdscli.dll
- 2004-08-12 13:22 . 2004-08-12 13:22 19968 c:\windows\SYSTEM32\mqbkup.exe
+ 2004-08-12 13:22 . 2009-06-22 11:49 19968 c:\windows\SYSTEM32\mqbkup.exe
+ 2004-08-12 13:22 . 2009-06-22 11:48 91776 c:\windows\SYSTEM32\DRIVERS\mqac.sys
+ 2004-08-12 13:20 . 2009-06-22 11:34 92544 c:\windows\SYSTEM32\DRIVERS\ksecdd.sys
+ 2004-08-12 13:32 . 2009-06-25 08:44 59392 c:\windows\SYSTEM32\DLLCACHE\wdigest.dll
+ 2004-08-12 13:28 . 2009-06-25 08:44 56320 c:\windows\SYSTEM32\DLLCACHE\secur32.dll
- 2004-08-12 13:22 . 2004-08-12 13:22 48640 c:\windows\SYSTEM32\DLLCACHE\mqupgrd.dll
+ 2004-08-12 13:22 . 2009-06-25 18:36 48640 c:\windows\SYSTEM32\DLLCACHE\mqupgrd.dll
- 2004-08-12 13:22 . 2004-08-12 13:22 95744 c:\windows\SYSTEM32\DLLCACHE\mqsec.dll
+ 2004-08-12 13:22 . 2009-06-25 18:36 95744 c:\windows\SYSTEM32\DLLCACHE\mqsec.dll
- 2004-08-12 13:22 . 2004-08-12 13:22 16896 c:\windows\SYSTEM32\DLLCACHE\mqise.dll
+ 2004-08-12 13:22 . 2009-06-25 18:36 16896 c:\windows\SYSTEM32\DLLCACHE\mqise.dll
- 2004-08-12 13:22 . 2004-08-12 13:22 47104 c:\windows\SYSTEM32\DLLCACHE\mqdscli.dll
+ 2004-08-12 13:22 . 2009-06-25 18:36 47104 c:\windows\SYSTEM32\DLLCACHE\mqdscli.dll
- 2004-08-12 13:22 . 2004-08-12 13:22 19968 c:\windows\SYSTEM32\DLLCACHE\mqbkup.exe
+ 2004-08-12 13:22 . 2009-06-22 11:49 19968 c:\windows\SYSTEM32\DLLCACHE\mqbkup.exe
+ 2004-08-12 13:22 . 2009-06-22 11:48 91776 c:\windows\SYSTEM32\DLLCACHE\mqac.sys
+ 2004-08-12 13:20 . 2009-06-22 11:34 92544 c:\windows\SYSTEM32\DLLCACHE\ksecdd.sys
+ 2011-09-12 20:47 . 2011-09-12 20:47 32768 c:\windows\Installer\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}\icon.exe
+ 2011-09-12 20:47 . 2011-09-12 20:47 32768 c:\windows\Installer\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}\icon.exe
+ 2011-09-12 20:48 . 2008-07-08 13:02 17272 c:\windows\ie8updates\KB971961-IE8\spmsg.dll
+ 2011-09-12 20:48 . 2008-07-08 13:02 26488 c:\windows\ie8updates\KB971961-IE8\spcustom.dll
+ 2004-08-12 13:22 . 2009-06-22 11:49 4608 c:\windows\SYSTEM32\mqsvc.exe
- 2004-08-12 13:22 . 2004-08-12 13:22 4608 c:\windows\SYSTEM32\mqsvc.exe
+ 2004-08-12 13:22 . 2009-06-22 11:49 4608 c:\windows\SYSTEM32\DLLCACHE\mqsvc.exe
- 2004-08-12 13:22 . 2004-08-12 13:22 4608 c:\windows\SYSTEM32\DLLCACHE\mqsvc.exe
+ 2004-08-12 13:23 . 2009-06-25 18:36 169472 c:\windows\SYSTEM32\Setup\msmqocm.dll
+ 2004-08-12 13:27 . 2009-06-25 08:44 168448 c:\windows\SYSTEM32\schannel.dll
+ 2004-08-12 13:24 . 2008-10-15 16:57 332800 c:\windows\SYSTEM32\netapi32.dll
+ 2004-08-12 13:23 . 2009-08-05 09:11 204800 c:\windows\SYSTEM32\mswebdvd.dll
+ 2004-08-12 13:23 . 2009-09-11 14:33 133632 c:\windows\SYSTEM32\msv1_0.dll
- 2004-08-12 13:22 . 2004-08-12 13:22 471552 c:\windows\SYSTEM32\mqutil.dll
+ 2004-08-12 13:22 . 2009-06-25 18:36 471552 c:\windows\SYSTEM32\mqutil.dll
- 2004-08-12 13:22 . 2004-08-12 13:22 186880 c:\windows\SYSTEM32\mqtrig.dll
+ 2004-08-12 13:22 . 2009-06-25 18:36 186880 c:\windows\SYSTEM32\mqtrig.dll
+ 2004-08-12 13:22 . 2009-06-22 11:49 117248 c:\windows\SYSTEM32\mqtgsvc.exe
- 2004-08-12 13:22 . 2004-08-12 13:22 117248 c:\windows\SYSTEM32\mqtgsvc.exe
+ 2004-08-12 13:22 . 2009-06-25 18:36 517120 c:\windows\SYSTEM32\mqsnap.dll
- 2004-08-12 13:22 . 2004-08-12 13:22 123392 c:\windows\SYSTEM32\mqrtdep.dll
+ 2004-08-12 13:22 . 2009-06-25 18:36 123392 c:\windows\SYSTEM32\mqrtdep.dll
- 2004-08-12 13:22 . 2004-08-12 13:22 177152 c:\windows\SYSTEM32\mqrt.dll
+ 2004-08-12 13:22 . 2009-06-25 18:36 177152 c:\windows\SYSTEM32\mqrt.dll
+ 2004-08-12 13:22 . 2009-06-25 18:36 661504 c:\windows\SYSTEM32\mqqm.dll
- 2004-08-12 13:22 . 2004-08-12 13:22 225280 c:\windows\SYSTEM32\mqoa.dll
+ 2004-08-12 13:22 . 2009-06-25 18:36 225280 c:\windows\SYSTEM32\mqoa.dll
+ 2004-08-12 13:22 . 2009-06-25 18:36 138240 c:\windows\SYSTEM32\mqad.dll
- 2004-08-12 13:22 . 2004-08-12 13:22 138240 c:\windows\SYSTEM32\mqad.dll
+ 2004-08-12 13:21 . 2009-06-25 08:44 724480 c:\windows\SYSTEM32\lsasrv.dll
+ 2004-08-12 13:20 . 2009-06-25 08:44 298496 c:\windows\SYSTEM32\kerberos.dll
- 2004-08-12 13:20 . 2009-03-08 11:33 726528 c:\windows\SYSTEM32\jscript.dll
+ 2004-08-12 13:20 . 2009-06-22 06:44 726528 c:\windows\SYSTEM32\jscript.dll
+ 2004-08-12 13:19 . 2008-10-23 13:01 283648 c:\windows\SYSTEM32\gdi32.dll
+ 2004-08-04 11:00 . 2008-04-21 10:02 215552 c:\windows\SYSTEM32\DLLCACHE\wordpad.exe
+ 2004-08-12 13:27 . 2009-06-25 08:44 168448 c:\windows\SYSTEM32\DLLCACHE\schannel.dll
+ 2004-08-12 13:24 . 2008-10-15 16:57 332800 c:\windows\SYSTEM32\DLLCACHE\netapi32.dll
+ 2004-08-12 13:23 . 2009-08-05 09:11 204800 c:\windows\SYSTEM32\DLLCACHE\mswebdvd.dll
+ 2004-08-12 13:23 . 2009-09-11 14:33 133632 c:\windows\SYSTEM32\DLLCACHE\msv1_0.dll
+ 2004-08-12 13:23 . 2009-06-25 18:36 169472 c:\windows\SYSTEM32\DLLCACHE\msmqocm.dll
+ 2004-08-12 13:22 . 2009-06-25 18:36 471552 c:\windows\SYSTEM32\DLLCACHE\mqutil.dll
- 2004-08-12 13:22 . 2004-08-12 13:22 471552 c:\windows\SYSTEM32\DLLCACHE\mqutil.dll
- 2004-08-12 13:22 . 2004-08-12 13:22 186880 c:\windows\SYSTEM32\DLLCACHE\mqtrig.dll
+ 2004-08-12 13:22 . 2009-06-25 18:36 186880 c:\windows\SYSTEM32\DLLCACHE\mqtrig.dll
+ 2004-08-12 13:22 . 2009-06-22 11:49 117248 c:\windows\SYSTEM32\DLLCACHE\mqtgsvc.exe
- 2004-08-12 13:22 . 2004-08-12 13:22 117248 c:\windows\SYSTEM32\DLLCACHE\mqtgsvc.exe
+ 2004-08-12 13:22 . 2009-06-25 18:36 517120 c:\windows\SYSTEM32\DLLCACHE\mqsnap.dll
- 2004-08-12 13:22 . 2004-08-12 13:22 123392 c:\windows\SYSTEM32\DLLCACHE\mqrtdep.dll
+ 2004-08-12 13:22 . 2009-06-25 18:36 123392 c:\windows\SYSTEM32\DLLCACHE\mqrtdep.dll
- 2004-08-12 13:22 . 2004-08-12 13:22 177152 c:\windows\SYSTEM32\DLLCACHE\mqrt.dll
+ 2004-08-12 13:22 . 2009-06-25 18:36 177152 c:\windows\SYSTEM32\DLLCACHE\mqrt.dll
+ 2004-08-12 13:22 . 2009-06-25 18:36 661504 c:\windows\SYSTEM32\DLLCACHE\mqqm.dll
+ 2004-08-12 13:22 . 2009-06-25 18:36 225280 c:\windows\SYSTEM32\DLLCACHE\mqoa.dll
- 2004-08-12 13:22 . 2004-08-12 13:22 225280 c:\windows\SYSTEM32\DLLCACHE\mqoa.dll
+ 2004-08-12 13:22 . 2009-06-25 18:36 138240 c:\windows\SYSTEM32\DLLCACHE\mqad.dll
- 2004-08-12 13:22 . 2004-08-12 13:22 138240 c:\windows\SYSTEM32\DLLCACHE\mqad.dll
+ 2004-08-12 13:21 . 2009-06-25 08:44 724480 c:\windows\SYSTEM32\DLLCACHE\lsasrv.dll
+ 2004-08-12 13:20 . 2009-06-25 08:44 298496 c:\windows\SYSTEM32\DLLCACHE\kerberos.dll
- 2004-08-12 13:20 . 2009-03-08 11:33 726528 c:\windows\SYSTEM32\DLLCACHE\jscript.dll
+ 2004-08-12 13:20 . 2009-06-22 06:44 726528 c:\windows\SYSTEM32\DLLCACHE\jscript.dll
+ 2004-08-12 13:19 . 2008-10-23 13:01 283648 c:\windows\SYSTEM32\DLLCACHE\gdi32.dll
+ 2011-09-12 20:47 . 2011-09-12 20:47 432640 c:\windows\Installer\5efd15.msi
+ 2011-09-12 20:47 . 2011-09-12 20:47 429568 c:\windows\Installer\5efd0e.msi
+ 2011-09-12 20:48 . 2008-07-08 13:02 382840 c:\windows\ie8updates\KB971961-IE8\updspapi.dll
+ 2011-09-12 20:48 . 2008-07-08 13:02 755576 c:\windows\ie8updates\KB971961-IE8\update.exe
+ 2011-09-12 20:48 . 2008-07-08 13:02 231288 c:\windows\ie8updates\KB971961-IE8\spuninst.exe
+ 2010-03-19 02:16 . 2009-03-08 11:33 726528 c:\windows\ie8updates\KB971961-IE8\jscript.dll
- 2010-03-19 02:16 . 2009-03-08 12:33 726528 c:\windows\ie8updates\KB971961-IE8\jscript.dll
- 2009-11-13 20:52 . 2008-07-09 21:08 382840 c:\windows\$hf_mig$\KB955069\update\updspapi.dll
+ 2009-11-13 20:52 . 2008-07-09 20:08 382840 c:\windows\$hf_mig$\KB955069\update\updspapi.dll
+ 2009-07-21 07:03 . 2009-07-21 07:03 1348432 c:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9876.0_x-ww_a621d1d5\msxml4.dll
+ 2008-09-30 23:42 . 2008-09-30 23:42 1286152 c:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9870.0_x-ww_a32d74cf\msxml4.dll
+ 2004-08-12 13:26 . 2010-02-05 18:40 1291264 c:\windows\SYSTEM32\quartz.dll
+ 2009-07-21 07:05 . 2009-07-21 07:05 1348432 c:\windows\SYSTEM32\msxml4.dll
+ 2004-08-12 13:23 . 2008-09-04 16:42 1106944 c:\windows\SYSTEM32\msxml3.dll
+ 2004-08-12 13:26 . 2010-02-05 18:40 1291264 c:\windows\SYSTEM32\DLLCACHE\quartz.dll
+ 2004-08-12 13:23 . 2008-09-04 16:42 1106944 c:\windows\SYSTEM32\DLLCACHE\msxml3.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-05-14 98304]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-05-14 536576]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-11-02 1392640]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-11-04 281768]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-07-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-07-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-07-20 114688]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToMyPC]
2007-06-20 18:09 10536 ----a-w- c:\program files\Citrix\GoToMyPC\G2WinLogon.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\srvF3C]
@="service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\WINDOWS\\SYSTEM32\\FXSCLNT.EXE"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Nero\\Nero\\nero.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Intuit\\QuickBooks 2011\\QBDBMgrN.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\system32\\sessmgr.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"497:UDP"= 497:UDP:Retrospect UDP
"497:TCP"= 497:TCP:Retrospect TCP
"5003:TCP"= 5003:TCP:*:Disabled:FileMaker
"67:UDP"= 67:UDP:DHCP Server
.
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011 9:27 AM 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 2:55 PM 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [8/11/2011 4:38 PM 116608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [3/27/2010 8:26 PM 136360]
R2 QBVSS;QBIDPService;c:\program files\Common Files\Intuit\DataProtect\QBIDPService.exe [6/30/2011 1:25 PM 1248256]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [3/28/2010 9:54 AM 136176]
S2 srvF3C;srvF3C;c:\windows\system32\svchost.exe -k netsvcs [8/12/2004 6:30 AM 14336]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [3/28/2010 9:54 AM 136176]
S3 ZD1211BU(SMC);802.11g Wireless USB2.0 Adapter Driver(SMC);c:\windows\SYSTEM32\DRIVERS\ZD1211BU.sys [8/24/2006 5:44 AM 477696]
S4 Uslsncsvaxn;Uslsncsvaxn;c:\windows\SYSTEM32\ahui.exe [8/12/2004 6:17 AM 98304]
.
Contents of the 'Scheduled Tasks' folder
.
2011-09-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-28 16:53]
.
2011-09-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-28 16:53]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 24.205.224.36 24.205.192.61 68.116.46.115
FF - ProfilePath - c:\documents and settings\Alin\Application Data\Mozilla\Firefox\Profiles\g9arla3k.default\
FF - prefs.js: browser.startup.homepage - about:blank
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-09-12 15:14
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\srvF3C]
"servicedll"="\\?\globalroot\Device\HarddiskVolume2\WINDOWS\Temp\srvF3C.tmp"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(864)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\program files\Citrix\GoToMyPC\G2WinLogon.dll
.
- - - - - - - > 'explorer.exe'(3436)
c:\windows\system32\SynTPFcs.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
.
**************************************************************************
.
Completion time: 2011-09-12 15:20:57 - machine was rebooted
ComboFix-quarantined-files.txt 2011-09-12 22:20
.
Pre-Run: 32,299,270,144 bytes free
Post-Run: 32,448,856,064 bytes free
.
- - End Of File - - 75F3125BF5C0007262314A075F0EC7CA