Hi Gringo,
Thanks for your help. I am only on this computer twice a week, so sorry for the delay. I ran combofix with the cfscript and it seemed to work. below is the log file and the computer seems to be running better and the redirect problem is gone. I currently have no AV protection though. Is it safe to put that back on, and what would you recommend? I would prefer a free on is possible. Are there more steps?
Thanks.
david
ComboFix 11-10-20.05 - Bduggan 10/20/2011 10:13:32.4.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2037.1282 [GMT -5:00]
Running from: c:\documents and settings\Bduggan\My Documents\Downloads\ComboFix.exe
Command switches used :: c:\documents and settings\Bduggan\Desktop\cfscript.txt
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
FILE ::
"c:\windows\system32\c_15646.nl_"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-1344\20252d6e001ae3774b425e81ba09b666\Fcntl.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-1344\2076671ee5d0a5323570c92c74abac6f\Process.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-1344\23ae7fb85999872530b5a5d4d67a4f44\Registry.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-1344\23fe5d76b9491fa255db2281ac7687d5\Service.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-1344\2d2847f7dd2a1fddd0fdb79d9d64ba93\List.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-1344\6a834a555edd63cb8706466e7c1666f2\Hostname.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-1344\7020d50af327e3fc94b98242c307fc81\Cwd.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-1344\7dd16cc839f33995d1a58e2773aa29b8\WinError.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-1344\855297e7b4b860331fdbdd53426f5e15\Dumper.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-1344\86351894c58e4804ca004825fea78bbb\Encode.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-1344\a7c0cce4e1ac2c1f6d3e71bbe3c9bdd3\Socket.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-1344\b7b4505cb0a127c242f14d779e410e03\POSIX.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-1344\c3da4aa4c02db51c7f94d5eaf2438023\OLE.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-1344\f48694173221cfa9bad4275e2389b498\Win32.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-1344\perl510.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\14d02158d1dc4c498d1acd9638684120\Name.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\194ac47433b8bc54b2df1d99c554a72e\EV.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\20252d6e001ae3774b425e81ba09b666\Fcntl.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\2076671ee5d0a5323570c92c74abac6f\Process.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\23ae7fb85999872530b5a5d4d67a4f44\Registry.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\2d2847f7dd2a1fddd0fdb79d9d64ba93\List.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\2f0807b0946b0fe6a4923ffadf1218fc\vxs.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\461090bfc26706cc26ffa02662c1592c\Syck.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\48a4e6ef370984d8d9ce53660d66a7a5\Unicode.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\4e3813a1edb6903dcc223941e51f7e18\Parser.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\52831fecbfbbfee1a05b91977e499808\File.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\542ba247eebc159476ad07ad6bd76209\XS.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\5f6960e0234e0b14396e4c82a1f56c8f\HiRes.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\62aa3b09ac39e34fd76505142c94e975\Storable.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\64aa79000ff318c6735dfd0191e3b022\Scale.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\6a834a555edd63cb8706466e7c1666f2\Hostname.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\6c1da131f436ce35edb0690f338bdad8\File.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\6c25de79371a4db1d7e8eff0d11d5337\Base64.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\6eca2cf2961ac400050de852a1cbef9b\Byte.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\7020d50af327e3fc94b98242c307fc81\Cwd.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\76c0175b78e6f49c7544e19221d4457d\IO.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\7dd16cc839f33995d1a58e2773aa29b8\WinError.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\8245460bbc088712019f4f3ab3a844ff\icudt46.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\8245460bbc088712019f4f3ab3a844ff\icuin46.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\8245460bbc088712019f4f3ab3a844ff\icuuc46.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\8245460bbc088712019f4f3ab3a844ff\SQLite.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\855297e7b4b860331fdbdd53426f5e15\Dumper.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\86351894c58e4804ca004825fea78bbb\Encode.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\8f8bffaa9136789fd266c59519e6a452\encoding.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\90198bd2c008178752393a8740fa6369\XS.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\9076f6dacaea506ecfb169822b132706\MD5.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\92d2aa3f2974636beefdb4636326e9c4\Scan.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\a33551806ec091669b28f0334ef049cc\DBI.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\a7c0cce4e1ac2c1f6d3e71bbe3c9bdd3\Socket.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\b7b4505cb0a127c242f14d779e410e03\POSIX.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\c06adade199b7f380d57181669fb22c1\Util.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\c3da4aa4c02db51c7f94d5eaf2438023\OLE.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\c8b0e39733c3e73e232a64a5c305ca76\API.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\e1ea0dbaf8a3ac5d1f0be83f219f8571\FastCalc.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\e775fca35641b4340ecf5cdba1fc6f62\Expat.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\ea4a4f99088551dd603ccfbabfaf3932\XSAccessor.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\f48694173221cfa9bad4275e2389b498\Win32.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\fc665959964b1312aee9d476290accdc\SHA1.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\fc8b9fd242032de837413f14e26ce21c\Zlib.dll
c:\docume~1\Bduggan\LOCALS~1\Temp\pdk-Bduggan-3948\perl510.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-1344\20252d6e001ae3774b425e81ba09b666\Fcntl.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-1344\2076671ee5d0a5323570c92c74abac6f\Process.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-1344\23ae7fb85999872530b5a5d4d67a4f44\Registry.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-1344\23fe5d76b9491fa255db2281ac7687d5\Service.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-1344\2d2847f7dd2a1fddd0fdb79d9d64ba93\List.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-1344\6a834a555edd63cb8706466e7c1666f2\Hostname.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-1344\7020d50af327e3fc94b98242c307fc81\Cwd.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-1344\7dd16cc839f33995d1a58e2773aa29b8\WinError.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-1344\855297e7b4b860331fdbdd53426f5e15\Dumper.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-1344\86351894c58e4804ca004825fea78bbb\Encode.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-1344\a7c0cce4e1ac2c1f6d3e71bbe3c9bdd3\Socket.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-1344\b7b4505cb0a127c242f14d779e410e03\POSIX.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-1344\c3da4aa4c02db51c7f94d5eaf2438023\OLE.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-1344\f48694173221cfa9bad4275e2389b498\Win32.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-1344\perl510.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\14d02158d1dc4c498d1acd9638684120\Name.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\194ac47433b8bc54b2df1d99c554a72e\EV.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\20252d6e001ae3774b425e81ba09b666\Fcntl.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\2076671ee5d0a5323570c92c74abac6f\Process.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\23ae7fb85999872530b5a5d4d67a4f44\Registry.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\2d2847f7dd2a1fddd0fdb79d9d64ba93\List.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\2f0807b0946b0fe6a4923ffadf1218fc\vxs.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\461090bfc26706cc26ffa02662c1592c\Syck.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\48a4e6ef370984d8d9ce53660d66a7a5\Unicode.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\4e3813a1edb6903dcc223941e51f7e18\Parser.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\52831fecbfbbfee1a05b91977e499808\File.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\542ba247eebc159476ad07ad6bd76209\XS.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\5f6960e0234e0b14396e4c82a1f56c8f\HiRes.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\62aa3b09ac39e34fd76505142c94e975\Storable.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\64aa79000ff318c6735dfd0191e3b022\Scale.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\6a834a555edd63cb8706466e7c1666f2\Hostname.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\6c1da131f436ce35edb0690f338bdad8\File.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\6c25de79371a4db1d7e8eff0d11d5337\Base64.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\6eca2cf2961ac400050de852a1cbef9b\Byte.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\7020d50af327e3fc94b98242c307fc81\Cwd.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\76c0175b78e6f49c7544e19221d4457d\IO.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\7dd16cc839f33995d1a58e2773aa29b8\WinError.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\8245460bbc088712019f4f3ab3a844ff\icudt46.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\8245460bbc088712019f4f3ab3a844ff\icuin46.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\8245460bbc088712019f4f3ab3a844ff\icuuc46.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\8245460bbc088712019f4f3ab3a844ff\SQLite.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\855297e7b4b860331fdbdd53426f5e15\Dumper.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\86351894c58e4804ca004825fea78bbb\Encode.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\8f8bffaa9136789fd266c59519e6a452\encoding.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\90198bd2c008178752393a8740fa6369\XS.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\9076f6dacaea506ecfb169822b132706\MD5.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\92d2aa3f2974636beefdb4636326e9c4\Scan.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\a33551806ec091669b28f0334ef049cc\DBI.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\a7c0cce4e1ac2c1f6d3e71bbe3c9bdd3\Socket.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\b7b4505cb0a127c242f14d779e410e03\POSIX.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\c06adade199b7f380d57181669fb22c1\Util.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\c3da4aa4c02db51c7f94d5eaf2438023\OLE.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\c8b0e39733c3e73e232a64a5c305ca76\API.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\e1ea0dbaf8a3ac5d1f0be83f219f8571\FastCalc.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\e775fca35641b4340ecf5cdba1fc6f62\Expat.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\ea4a4f99088551dd603ccfbabfaf3932\XSAccessor.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\f48694173221cfa9bad4275e2389b498\Win32.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\fc665959964b1312aee9d476290accdc\SHA1.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\fc8b9fd242032de837413f14e26ce21c\Zlib.dll
c:\documents and settings\Bduggan\Local Settings\temp\pdk-Bduggan-3948\perl510.dll
.
.
((((((((((((((((((((((((( Files Created from 2011-09-20 to 2011-10-20 )))))))))))))))))))))))))))))))
.
.
2011-10-18 20:05 . 2011-10-18 20:07 -------- d-----w- c:\program files\iTunes
2011-10-18 00:44 . 2011-10-18 00:44 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2011-10-17 14:48 . 2011-10-17 14:48 -------- d-----w- c:\program files\Bonjour
2011-10-16 19:25 . 2011-10-16 19:25 -------- d-sh--w- c:\windows\system32\config\systemprofile\PrivacIE
2011-10-13 14:28 . 2011-10-13 14:28 -------- d-----w- c:\documents and settings\Bduggan\Application Data\SUPERAntiSpyware.com
2011-10-13 14:27 . 2011-10-18 14:43 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-10-13 14:27 . 2011-10-13 14:27 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2011-10-11 22:15 . 2011-10-11 22:16 -------- d-----w- c:\program files\Maware
2011-10-11 22:07 . 2011-10-11 22:17 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-10-11 21:46 . 2011-08-31 22:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-10-05 14:10 . 2011-10-05 14:10 56200 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F696CEB8-CBEA-4C6B-B654-9D5361D81FA1}\offreg.dll
2011-10-05 14:10 . 2011-09-12 23:14 7269712 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{F696CEB8-CBEA-4C6B-B654-9D5361D81FA1}\mpengine.dll
2011-09-20 20:42 . 2011-09-20 20:42 -------- d-----w- c:\program files\DVD Decrypter
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-11 22:18 . 2008-05-27 03:18 441856 ----a-w- c:\windows\system32\SearchIndexer.exe
2011-10-11 20:20 . 2011-04-18 18:18 165648 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2011-09-26 16:41 . 2008-07-30 00:59 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 16:41 . 2004-08-11 22:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-26 16:41 . 2004-08-11 22:00 20480 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-12 23:14 . 2011-09-10 08:25 7269712 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-09-09 09:12 . 2004-08-11 22:00 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-08 21:54 . 2011-09-08 21:54 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-09-08 20:20 . 2004-08-11 22:00 44544 ----a-w- c:\windows\system32\drivers\fips.sys
2011-09-06 14:24 . 2011-06-28 11:48 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-06 13:20 . 2004-08-11 22:00 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-08-31 04:05 . 2011-08-31 04:05 83816 ----a-w- c:\windows\system32\dns-sd.exe
2011-08-31 04:05 . 2011-08-31 04:05 73064 ----a-w- c:\windows\system32\dnssd.dll
2011-08-22 23:48 . 2004-08-11 22:00 916480 ----a-w- c:\windows\system32\wininet.dll
2011-08-22 23:48 . 2004-08-11 22:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-08-22 23:48 . 2004-08-11 22:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-08-22 11:56 . 2004-08-11 22:00 385024 ----a-w- c:\windows\system32\html.iec
2011-08-17 13:49 . 2004-08-11 22:00 138496 ----a-w- c:\windows\system32\drivers\afd.sys
2011-08-11 18:49 . 2011-08-11 18:36 232512 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
.
.
((((((((((((((((((((((((((((( SnapShot_2011-10-18_14.54.16 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-07-18 16:01 . 2011-10-18 14:48 81920 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-07-18 16:01 . 2011-10-20 15:26 81920 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-07-18 16:01 . 2011-10-18 14:48 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-07-18 16:01 . 2011-10-20 15:26 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-07-18 16:01 . 2011-10-20 15:26 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2008-07-18 16:01 . 2011-10-18 14:48 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2011-10-18 20:07 . 2011-10-18 20:07 380928 c:\windows\Installer\{29ED20C9-5E15-4969-9279-25BF3727A3DA}\iTunesIco.exe
- 2011-10-17 14:57 . 2011-10-17 14:57 380928 c:\windows\Installer\{29ED20C9-5E15-4969-9279-25BF3727A3DA}\iTunesIco.exe
+ 2011-10-18 20:07 . 2011-10-18 20:07 5235200 c:\windows\Installer\89cbb1.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"RemoteHelper"="c:\program files\Remote HD\Remote Helper\RemoteHelper.exe" [2011-02-14 586752]
"Push Client"="c:\documents and settings\Bduggan\Local Settings\Application Data\ATT Connect\Participant\pull.exe" [2008-12-29 918768]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-10-12 4615552]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-07-17 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-07-17 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-07-17 138008]
"RTHDCPL"="RTHDCPL.EXE" [2007-07-17 16132608]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2007-09-17 124200]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2008-02-28 17920]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"Tracker"="c:\program files\MySoftware\MyInvoices\tracker.exe" [2006-12-22 114688]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2010-03-12 49208]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2011-05-27 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-10-15 623992]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2011-07-05 421888]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-10-09 421736]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start
http://www.avg.com/ww.special-uninstallation-feedback-appf?lic=NFVXV1UtV0JEWEMtVllGTjMtUURKTUgtNDJBT0EtSzZIVTk&inst=NzctNzE2NzE2MzQ2LVNUMTJGT0krMS1ERFQrMC1FVUxBKzEtU1QxMkZBUFArMQ&prod=90&ver=2012.0.1796&mid=81907d74cea047d1b86cd1544f7a57ec-c867b1d26da29d6fde8aeb42503fe637d4fd75e4" [?]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"LabelMaker2.0"="c:\program files\Common Files\MySoftware\regdll.dll" [2006-08-03 94208]
.
c:\documents and settings\Bduggan\Start Menu\Programs\Startup\
ZvRemote.lnk - c:\program files\ZeeVee\ZvRemote\ZvRemote.exe [2009-9-21 1565944]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-6-21 24576]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-4 258048]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-4 53248]
Newsflash.lnk - c:\program files\Common Files\MySoftware\Newsflsh.exe [2008-7-24 233472]
Squeezebox Server Tray Tool.lnk - c:\program files\Squeezebox\SqueezeTray.exe [2011-8-2 2162775]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-06-22 02:54 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2011-08-02 07:33 4910912 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
2010-07-27 16:17 30192 ----a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\RTI\\Integration Designer\\idesign.exe"=
"c:\\Program Files\\Qwest\\QuickConnect\\QuickConnect.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Brother\\BRAdmin Professional 3\\discover.exe"=
"c:\\Program Files\\Brother\\BRAdmin Professional 3\\AuditorServer.exe"=
"c:\\Program Files\\Brother\\BRAdmin Professional 3\\bradminv3.exe"=
"c:\\Program Files\\Remote HD\\Remote Helper\\RemoteHelper.exe"=
"c:\\Program Files\\RTI\\Integration Designer\\PCEmu.exe"=
"c:\\Program Files\\Squeezebox\\server\\SqueezeSvr.exe"=
"c:\\WINDOWS\\system32\\mstsc.exe"=
"c:\\Program Files\\Handbrake\\Handbrake.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\EXCEL.EXE"=
"c:\\WINDOWS\\system32\\msfeedssync.exe"=
"c:\\Program Files\\DivX\\DivX Update\\DivXUpdate.exe"=
"c:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe"=
"c:\\Program Files\\DAEMON Tools Lite\\DTLite.exe"=
"c:\\Program Files\\Common Files\\Microsoft Shared\\DW\\DW20.EXE"=
"c:\\WINDOWS\\system32\\HPZinw12.exe"=
"c:\\Program Files\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe"=
"c:\\Program Files\\Trend Micro\\HiJackThis\\HiJackThis.exe"=
"c:\\Documents and Settings\\Bduggan\\Local Settings\\Application Data\\ATT Connect\\Participant\\pull.exe"=
"c:\\Program Files\\Common Files\\MySoftware\\Newsflsh.exe"=
"c:\\Program Files\\Spybot - Search & Destroy\\SDUpdate.exe"=
"c:\\Program Files\\Dell Support Center\\bin\\sprtcmd.exe"=
"c:\\Program Files\\Adobe\\Photoshop Elements 7.0\\PhotoshopElementsEditor.exe"=
"c:\\Documents and Settings\\Bduggan\\Local Settings\\Application Data\\Google\\Update\\GoogleUpdate.exe"=
"c:\\Documents and Settings\\Bduggan\\Local Settings\\Application Data\\Google\\Chrome\\Application\\chrome.exe"=
"c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10w_ActiveX.exe"=
"c:\\Program Files\\Maware\\goddamit.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\WINWORD.EXE"=
"c:\\Program Files\\Common Files\\Adobe\\Updater5\\AdobeUpdater.exe"=
"c:\\Program Files\\SUPERAntiSpyware\\SUPERAntiSpyware.exe"=
"c:\\Program Files\\SUPERAntiSpyware\\SSUpdate.exe"=
"c:\\Program Files\\Squeezebox\\server\\squeezeboxcp.exe"=
"c:\\WINDOWS\\system32\\msiexec.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\HP\\HP Software Update\\hpwucli.exe"=
"c:\\Program Files\\HP\\Product Assistant\\bin\\hprbUpdate.exe"=
"c:\\WINDOWS\\system32\\dwwin.exe"=
"c:\\Program Files\\Common Files\\Apple\\Mobile Device Support\\com.google.ContactSync.client.exe"=
"c:\\Program Files\\Common Files\\Apple\\Mobile Device Support\\MDCrashReportTool.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"9000:TCP"= 9000:TCP:Squeezebox Server 9000 tcp (UI)
"9001:TCP"= 9001:TCP:Squeezebox Server 9001 tcp (UI)
"9002:TCP"= 9002:TCP:Squeezebox Server 9002 tcp (UI)
"9003:TCP"= 9003:TCP:Squeezebox Server 9003 tcp (UI)
"9004:TCP"= 9004:TCP:Squeezebox Server 9004 tcp (UI)
"9005:TCP"= 9005:TCP:Squeezebox Server 9005 tcp (UI)
"9006:TCP"= 9006:TCP:Squeezebox Server 9006 tcp (UI)
"9007:TCP"= 9007:TCP:Squeezebox Server 9007 tcp (UI)
"9008:TCP"= 9008:TCP:Squeezebox Server 9008 tcp (UI)
"9009:TCP"= 9009:TCP:Squeezebox Server 9009 tcp (UI)
"9010:TCP"= 9010:TCP:Squeezebox Server 9010 tcp (UI)
"9100:TCP"= 9100:TCP:Squeezebox Server 9100 tcp (UI)
"8000:TCP"= 8000:TCP:Squeezebox Server 8000 tcp (UI)
"10000:TCP"= 10000:TCP:Squeezebox Server 10000 tcp (UI)
"9090:TCP"= 9090:TCP:Squeezebox Server 9090 tcp (UI)
"3483:UDP"= 3483:UDP:Squeezebox Server 3483 udp
"3483:TCP"= 3483:TCP:Squeezebox Server 3483 tcp
.
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\drivers\dtsoftbus01.sys [8/11/2011 1:36 PM 232512]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011 11:27 AM 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 4:55 PM 67664]
R2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [9/16/2008 1:03 PM 169312]
R2 BRA_Scheduler;Brother BRAdminPro Scheduler;c:\program files\Brother\BRAdmin Professional 3\bratimer.exe [2/23/2011 1:17 PM 73728]
R2 sprtlisten;SupportSoft Listener Service;c:\program files\Common Files\supportsoft\bin\sprtlisten.exe [1/8/2008 12:02 PM 1213728]
S1 MpKsl19ead53b;MpKsl19ead53b;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E55C9D1E-606B-4CD8-923E-E1BCAD03C607}\MpKsl19ead53b.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E55C9D1E-606B-4CD8-923E-E1BCAD03C607}\MpKsl19ead53b.sys [?]
S2 !SASCORE;SAS Core Service;"c:\program files\SUPERAntiSpyware\SASCORE.EXE" --> c:\program files\SUPERAntiSpyware\SASCORE.EXE [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S2 NetFxUpdate_v1.1.4322;Microsoft .NET Framework v1.1.4322 Update;c:\windows\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe [1/15/2007 4:11 PM 73728]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [6/21/2008 9:48 PM 30192]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys --> c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [?]
S3 PCD5SRVC{3F6A8B78-EC003E00-05040000};PCD5SRVC{3F6A8B78-EC003E00-05040000} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms [12/5/2007 4:47 PM 20640]
S3 RTIUSB;RTI USB Driver;c:\windows\system32\drivers\RTIUSB.sys [9/30/2005 4:04 PM 17920]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
S4 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx86.sys --> c:\windows\system32\DRIVERS\avgrkx86.sys [?]
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 22:57]
.
2011-10-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2815802652-1674557370-2013247479-1005Core.job
- c:\documents and settings\Bduggan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-09-08 11:33]
.
2011-10-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2815802652-1674557370-2013247479-1005UA.job
- c:\documents and settings\Bduggan\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-09-08 11:33]
.
2011-10-16 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 20:39]
.
2011-10-20 c:\windows\Tasks\User_Feed_Synchronization-{57D9975E-3717-4641-8C83-A76E830040AC}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 10:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
Trusted Zone: brandmuscle.net
TCP: Interfaces\{CFDD3F3A-BF44-49A8-8D81-2FCB46D954B5}: NameServer = 192.168.254.1,192.168.254.10
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: {46D8BEE7-0B27-4466-ABA2-A5F1E157971C} - hxxp://173.18.253.61/RemoteWeb.cab
DPF: {5FFDFC21-AE40-4C7C-955C-415A1ACE01C8} - hxxp://67.233.224.23:100/VideoViewer.cab
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-10-20 10:28
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\PCD5SRVC{3F6A8B78-EC003E00-05040000}]
"ImagePath"="\??\c:\progra~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(760)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
c:\program files\Citrix\GoToAssist\514\G2AWinLogon.dll
.
- - - - - - - > 'explorer.exe'(2512)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\windows\system32\SearchIndexer.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\RTHDCPL.EXE
c:\program files\HP\Digital Imaging\bin\hpqgalry.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
c:\progra~1\SQUEEZ~1\server\SQUEEZ~3.EXE
c:\windows\system32\msiexec.exe
c:\program files\Microsoft Office\Office12\WINWORD.EXE
.
**************************************************************************
.
Completion time: 2011-10-20 10:34:32 - machine was rebooted
ComboFix-quarantined-files.txt 2011-10-20 15:34
ComboFix2.txt 2011-10-20 15:08
ComboFix3.txt 2011-10-18 15:02
ComboFix4.txt 2011-09-08 20:58
.
Pre-Run: 4,585,517,056 bytes free
Post-Run: 4,556,492,800 bytes free
.
- - End Of File - - 69EF194F7CC67A8AC164C8DB4A7CC807