Hi,
Many thanks for getting back to me so quickly .
I (a) ran ComboFix. It seemed to run ok and rebooted my computer, but failed to produce a ComboFix.txt file. Instead it seemed to produced a shortcut in c: called 'ComboFix' that pointed to my MyComputer.
So (

I renamed the executablee ComboFix.exe as 'Richard.exe', and ran it again. It seemed to run ok, did not reboot my compuer, but did produce a ComboFix.txt file.
I realised afterwards that I should not have done (

without you telling me to, so I hope I have not meseed things up.
Many thanks for your continued help,
Richard
***
ComboFix 09-06-11.06 - richard 12/06/2009 17:12.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3582.2940 [GMT 1:00]
Running from: c:\documents and settings\richard\Desktop\Richard.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: Online Armor Firewall *disabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
Infected copy of c:\windows\system32\ws2_32.dll was found and disinfected
Restored copy from - c:\system volume information\_restore{78DCF30B-FBF4-404D-8DCE-EF333CC52824}\RP193\A0062578.dll
.
((((((((((((((((((((((((( Files Created from 2009-05-12 to 2009-06-12 )))))))))))))))))))))))))))))))
.
2009-06-12 15:55 . 2009-06-12 16:00 -------- dcs---w- C:\ComboFix.t.x
2009-06-10 08:23 . 2009-04-30 21:22 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-06-10 08:23 . 2009-04-30 21:22 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-05 07:58 . 2009-06-05 07:58 -------- dc----w- c:\program files\Common Files\Jumping Bytes
2009-06-05 07:54 . 2009-06-05 07:54 -------- dc----w- c:\documents and settings\LocalService\Bluetooth Software
2009-06-03 10:23 . 2009-06-03 10:23 -------- dc----w- c:\program files\R
2009-06-01 12:00 . 2009-06-04 14:33 -------- dc----w- c:\program files\Stata8_2
2009-05-31 19:52 . 2009-05-31 19:52 -------- dc----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-05-31 17:32 . 2009-05-31 17:32 -------- dc----w- c:\documents and settings\richard\Application Data\OnlineArmor
2009-05-31 17:32 . 2009-05-31 17:32 -------- dc----w- c:\documents and settings\All Users\Application Data\OnlineArmor
2009-05-31 17:32 . 2009-04-28 04:38 29776 -c--a-w- c:\windows\system32\drivers\OAnet.sys
2009-05-31 17:32 . 2009-04-28 04:02 31824 -c--a-w- c:\windows\system32\drivers\OAmon.sys
2009-05-31 17:32 . 2009-04-28 04:01 198224 -c--a-w- c:\windows\system32\drivers\OADriver.sys
2009-05-31 17:32 . 2009-05-31 17:53 -------- dc----w- c:\program files\Online Armor
2009-05-31 14:54 . 2009-05-31 14:54 -------- dc----w- c:\documents and settings\All Users\Application Data\TEMP
2009-05-31 14:53 . 2009-05-31 17:48 -------- dc----w- c:\program files\SpywareBlaster
2009-05-31 14:53 . 2009-05-31 14:53 -------- dc----w- c:\documents and settings\All Users\Application Data\SiteAdvisor
2009-05-31 14:52 . 2009-05-31 14:52 -------- dc----w- c:\documents and settings\LocalService\Application Data\SACore
2009-05-31 14:52 . 2009-05-31 14:52 -------- dc----w- c:\program files\Common Files\McAfee
2009-05-31 14:52 . 2009-05-31 14:52 -------- dc----w- c:\windows\system32\config\systemprofile\Application Data\SACore
2009-05-31 14:52 . 2009-05-31 17:51 -------- dc----w- c:\program files\McAfee
2009-05-31 14:52 . 2009-05-31 14:52 -------- dc----w- c:\documents and settings\All Users\Application Data\McAfee
2009-05-31 14:30 . 2009-03-30 09:33 96104 -c--a-w- c:\windows\system32\drivers\avipbb.sys
2009-05-31 14:30 . 2009-02-13 11:29 22360 -c--a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-05-31 14:30 . 2009-02-13 11:17 45416 -c--a-w- c:\windows\system32\drivers\avgntdd.sys
2009-05-31 14:30 . 2009-05-31 14:30 -------- dc----w- c:\program files\Avira
2009-05-31 14:30 . 2009-05-31 14:30 -------- dc----w- c:\documents and settings\All Users\Application Data\Avira
2009-05-31 13:30 . 2009-05-31 13:44 -------- dc----w- c:\program files\Browser Hijack Recover
2009-05-31 12:41 . 2009-05-31 13:43 218736 -c--a-w- c:\documents and settings\richard\Application Data\HouseCall 6.6\patch.exe
2009-05-31 12:41 . 2009-05-31 13:43 189968 -c--a-w- c:\documents and settings\richard\Application Data\HouseCall 6.6\ciussi32.dll
2009-05-31 12:41 . 2009-05-31 13:43 170512 -c--a-w- c:\documents and settings\richard\Application Data\HouseCall 6.6\PATCHW32.DLL
2009-05-31 12:41 . 2009-05-31 13:43 1267320 -c--a-w- c:\documents and settings\richard\Application Data\HouseCall 6.6\TmUpdate.dll
2009-05-31 12:40 . 2009-05-31 13:43 832776 -c--a-w- c:\documents and settings\richard\Application Data\HouseCall 6.6\lea.dll
2009-05-31 12:40 . 2009-05-31 13:43 61440 -c--a-w- c:\documents and settings\richard\Application Data\HouseCall 6.6\Toolkit.dll
2009-05-31 12:40 . 2009-05-31 13:43 439560 -c--a-w- c:\documents and settings\richard\Application Data\HouseCall 6.6\jlea.dll
2009-05-31 12:40 . 2009-05-31 13:43 42320 -c--a-w- c:\documents and settings\richard\Application Data\HouseCall 6.6\dsvout.dll
2009-05-31 12:40 . 2009-05-31 13:43 183356 -c--a-w- c:\documents and settings\richard\Application Data\HouseCall 6.6\Uninstaller.exe
2009-05-31 12:40 . 2009-05-31 13:43 -------- dc----w- c:\documents and settings\richard\Application Data\HouseCall 6.6
2009-05-30 14:22 . 2009-06-10 08:32 -------- dc----w- c:\documents and settings\richard\Application Data\Spotify
2009-05-30 14:22 . 2009-05-30 14:23 -------- dc----w- c:\documents and settings\richard\Local Settings\Application Data\Spotify
2009-05-30 14:22 . 2009-05-30 14:22 -------- dc----w- c:\program files\Spotify
2009-05-29 22:32 . 2009-06-06 21:11 -------- dc----w- c:\temp\admin
2009-05-29 13:57 . 2008-08-27 07:59 1209616 -c--a-w- c:\windows\system32\nipplib.dll
2009-05-29 13:57 . 2008-08-25 13:29 36864 -c--a-w- c:\windows\system32\icapture.exe
2009-05-29 13:57 . 2008-08-25 13:29 34671 -c--a-w- c:\windows\system32\drivers\nipplpt.sys
2009-05-29 13:57 . 2008-08-25 13:28 49152 -c--a-w- c:\windows\system32\nipplpte.exe
2009-05-29 13:57 . 2008-08-25 13:28 45056 -c--a-w- c:\windows\system32\iprntlgn.exe
2009-05-29 13:57 . 2008-08-25 13:27 40960 -c--a-w- c:\windows\system32\iprntctl.exe
2009-05-29 13:57 . 2008-08-25 13:27 61440 -c--a-w- c:\windows\system32\iprntcmd.exe
2009-05-29 13:57 . 2008-08-25 13:27 40960 -c--a-w- c:\windows\system32\iprntcfg.exe
2009-05-29 13:57 . 2008-08-25 13:27 32768 -c--a-w- c:\windows\system32\nipplgex.dll
2009-05-29 13:57 . 2008-08-25 13:26 53248 -c--a-w- c:\windows\system32\nippcl32.dll
2009-05-29 13:57 . 2008-08-25 13:24 110592 -c--a-w- c:\windows\system32\nippnt.dll
2009-05-29 13:57 . 2008-08-25 13:23 69632 -c--a-w- c:\windows\system32\nipp95.dll
2009-05-28 14:49 . 2009-03-24 15:08 55640 -c--a-w- c:\windows\system32\drivers\avgntflt.sys
2009-05-28 13:46 . 2009-05-28 13:46 -------- dc----w- c:\documents and settings\richard\Application Data\Malwarebytes
2009-05-28 13:46 . 2009-05-26 12:20 40160 -c--a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-28 13:45 . 2009-05-28 13:46 -------- dc----w- c:\program files\Malwarebytes' Anti-Malware
2009-05-28 13:45 . 2009-05-28 13:45 -------- dc----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-28 13:45 . 2009-05-26 12:19 19096 -c--a-w- c:\windows\system32\drivers\mbam.sys
2009-05-28 13:02 . 2009-05-28 13:03 -------- dc----w- c:\documents and settings\richard\Local Settings\Application Data\Deployment
2009-05-27 21:46 . 2009-05-27 22:14 -------- dc----w- c:\program files\EqPlot
2009-05-25 14:01 . 2009-05-25 14:02 2514315 -c--a-w- c:\temp\winscp419setup.exe
2009-05-24 21:09 . 2009-05-24 21:09 -------- dc----w- C:\spoolerlogs
2009-05-23 13:43 . 2009-05-23 13:43 -------- dcsh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-05-23 11:30 . 2009-05-25 15:55 -------- dc----w- c:\temp\2v473cr2_test
2009-05-23 07:33 . 2009-05-23 16:50 -------- dc----w- c:\temp\vX.xx_2
2009-05-23 07:33 . 2009-05-23 07:33 -------- dc----w- c:\temp\vX.xx
2009-05-22 15:16 . 2009-05-22 15:16 -------- dc----w- c:\temp\2v473Cr2
2009-05-22 09:43 . 2009-05-27 22:21 -------- dc----w- c:\temp\HPC
2009-05-21 10:48 . 2009-05-21 10:48 -------- dc----w- c:\program files\WinSCP
2009-05-21 08:56 . 2009-05-21 08:56 -------- dc----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-05-20 08:35 . 2009-05-20 08:35 152576 -c--a-w- c:\documents and settings\richard\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-05-20 08:26 . 2009-05-20 08:26 162768 -c--a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-05-20 08:21 . 2009-05-20 08:24 12337480 -c--a-w- c:\documents and settings\All Users\Application Data\Birdstep Technology\EasyConnect\Update\3UK_2.7.0.77_AUP_ZTE.exe
2009-05-20 08:17 . 2009-05-20 08:17 -------- dc----w- c:\documents and settings\richard\Application Data\Birdstep Technology
2009-05-20 08:17 . 2009-05-20 08:17 -------- dc----w- c:\documents and settings\All Users\Application Data\Birdstep Technology
2009-05-20 08:16 . 2007-05-28 17:00 10240 -c----w- c:\windows\system32\drivers\mdvrmng.sys
2009-05-20 08:16 . 2009-05-20 08:16 -------- dc----w- c:\program files\ZTE_MF6X6_USB_MODEM_1.2050.0.6
2009-05-20 08:16 . 2009-05-20 08:16 -------- dc----w- c:\program files\3
2009-05-20 07:38 . 2009-05-20 07:39 -------- dc----w- c:\program files\BBC iPlayer Desktop
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-12 16:03 . 2008-11-19 13:52 -------- dc----w- c:\documents and settings\richard\Application Data\Skype
2009-06-12 16:03 . 2008-11-19 13:53 -------- dc----w- c:\documents and settings\richard\Application Data\skypePM
2009-06-12 13:11 . 2008-11-19 17:19 -------- dc----w- c:\documents and settings\richard\Application Data\EndNote
2009-06-12 08:03 . 2008-11-12 18:15 269393 -c--a-w- c:\windows\system32\nvModes.dat
2009-06-11 15:30 . 2008-11-19 13:07 -------- dc----w- c:\program files\Google
2009-06-11 07:42 . 2008-11-18 14:46 -------- dc----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-06-09 11:14 . 2008-11-19 15:28 -------- dc----w- c:\documents and settings\richard\Application Data\TextPad
2009-06-06 21:11 . 2008-11-22 21:03 -------- dc----w- c:\documents and settings\richard\Application Data\LimeWire
2009-06-05 07:59 . 2008-11-19 23:09 -------- dc----w- c:\documents and settings\richard\Application Data\Mobile Master
2009-06-05 07:58 . 2008-11-19 23:09 -------- dc----w- c:\program files\Mobile Master
2009-06-05 07:55 . 2008-11-19 23:05 -------- dc----w- c:\documents and settings\All Users\Application Data\PC Suite
2009-05-31 14:46 . 2008-11-22 21:01 -------- dc----w- c:\program files\Java
2009-05-31 12:37 . 2008-11-22 21:26 -------- dc----w- c:\documents and settings\richard\Application Data\uTorrent
2009-05-28 16:29 . 2009-03-06 21:07 -------- dc----w- c:\program files\Easy DVD Player
2009-05-28 16:27 . 2008-11-19 15:41 -------- dc----w- c:\program files\SmartDraw
2009-05-28 12:51 . 2008-11-12 18:26 69232 -c--a-w- c:\documents and settings\richard\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-25 18:35 . 2009-02-18 23:43 -------- dc----w- c:\program files\StartKiller
2009-05-25 18:32 . 2008-11-12 17:18 -------- dc-h--w- c:\program files\InstallShield Installation Information
2009-05-25 18:32 . 2008-11-25 12:21 -------- dc----w- c:\program files\Doom 3
2009-05-17 22:52 . 2008-11-12 17:39 1324 -c--a-w- c:\windows\system32\d3d9caps.dat
2009-05-13 05:15 . 2008-04-14 04:00 915456 -c--a-w- c:\windows\system32\wininet.dll
2009-05-12 20:08 . 2009-05-12 20:08 -------- dc----w- c:\program files\WinDirStat
2009-05-10 21:18 . 2009-05-10 21:16 -------- dc----w- c:\program files\NetLogo 4.0.4
2009-05-10 21:16 . 2009-05-10 21:16 -------- dc-h--w- c:\program files\Zero G Registry
2009-05-10 20:28 . 2009-05-10 20:28 -------- dc----w- c:\program files\GomEncoder
2009-05-10 20:28 . 2009-05-10 20:28 -------- dc----w- c:\program files\CoreAAC
2009-05-10 19:51 . 2009-05-10 19:51 -------- dc----w- c:\documents and settings\richard\Application Data\BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1
2009-05-10 19:51 . 2009-05-10 19:51 -------- dc----w- c:\program files\Common Files\Adobe AIR
2009-05-10 19:50 . 2008-11-19 21:52 -------- dc----w- c:\program files\Kontiki
2009-05-10 19:50 . 2009-05-10 19:51 38208 -c--a-w- c:\documents and settings\richard\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-05-10 14:58 . 2008-11-19 16:36 -------- dc----w- c:\program files\DesignWorkshop Lite
2009-05-08 23:49 . 2009-03-06 21:31 -------- dc----w- c:\program files\WinX DVD Player 3.0
2009-05-07 15:32 . 2008-04-14 04:00 345600 -c--a-w- c:\windows\system32\localspl.dll
2009-05-02 09:48 . 2008-11-18 14:50 -------- dc----w- c:\program files\Microsoft Works
2009-05-02 09:37 . 2009-03-03 21:23 -------- dc----w- c:\program files\DeskSpace
2009-05-02 09:31 . 2009-04-11 22:11 -------- dc----w- c:\program files\Starcraft Shareware(ED)
2009-05-01 21:32 . 2009-05-01 21:32 -------- dc----w- c:\program files\Common Files\PCSuite
2009-05-01 21:32 . 2009-05-01 21:32 -------- dc----w- c:\program files\Common Files\Nokia
2009-05-01 21:32 . 2008-11-19 23:03 -------- dc----w- c:\program files\Nokia
2009-05-01 21:31 . 2009-05-01 21:31 -------- dc----w- c:\program files\PC Connectivity Solution
2009-05-01 21:30 . 2008-11-19 23:02 -------- dc----w- c:\documents and settings\All Users\Application Data\Installations
2009-05-01 21:30 . 2009-05-01 21:30 8192 -c--a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstCCD.exe
2009-05-01 21:30 . 2009-05-01 21:30 61440 -c--a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-05-01 21:30 . 2009-05-01 21:30 10240 -c--a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Installer\CommonCustomActions\UninstPCS.exe
2009-05-01 21:29 . 2009-05-01 21:30 34396584 -c--a-w- c:\documents and settings\All Users\Application Data\Installations\{7694EC32-CB0E-4B35-9088-7B320CB1F4FE}\Nokia_PC_Suite_7_1_26_0_eng.exe
2009-04-24 12:39 . 2009-04-24 12:39 -------- dc----w- c:\program files\Common Files\Skype
2009-04-24 12:39 . 2009-04-24 12:39 -------- dc----r- c:\program files\Skype
2009-04-24 12:39 . 2008-11-19 13:52 -------- dc----w- c:\documents and settings\All Users\Application Data\Skype
2009-04-17 12:26 . 2008-04-14 04:00 1847168 -c--a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2008-04-14 04:00 585216 -c--a-w- c:\windows\system32\rpcrt4.dll
2009-03-16 13:18 . 2009-04-01 21:40 69448 -c--a-w- c:\windows\system32\XAPOFX1_3.dll
2009-03-16 13:18 . 2009-04-01 21:40 517448 -c--a-w- c:\windows\system32\XAudio2_4.dll
2009-03-16 13:18 . 2009-04-01 21:40 235352 -c--a-w- c:\windows\system32\xactengine3_4.dll
2009-03-16 13:18 . 2009-04-01 21:40 22360 -c--a-w- c:\windows\system32\X3DAudio1_6.dll
2009-03-01 21:49 . 2009-03-01 21:49 122880 -c--a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-05-31_14.22.04 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-07 01:19 . 2007-11-07 01:19 54272 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_ecc42bd1\vcomp90.dll
+ 2009-06-12 16:00 . 2009-06-12 16:00 16384 c:\windows\Temp\Perflib_Perfdata_4b8.dat
+ 2008-04-14 04:00 . 2009-06-12 16:05 65482 c:\windows\system32\perfc009.dat
+ 2008-04-14 04:00 . 2009-04-30 21:22 25600 c:\windows\system32\jsproxy.dll
- 2008-04-14 04:00 . 2009-03-08 03:33 25600 c:\windows\system32\jsproxy.dll
+ 2009-05-31 14:30 . 2009-06-09 16:03 28520 c:\windows\system32\drivers\ssmdrv.sys
+ 2008-04-14 04:00 . 2009-04-30 21:22 25600 c:\windows\system32\dllcache\jsproxy.dll
- 2008-04-14 04:00 . 2009-03-08 03:33 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2008-11-18 14:50 . 2009-06-11 07:42 35088 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
- 2008-11-18 14:50 . 2009-05-28 14:33 35088 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
+ 2008-11-18 14:50 . 2009-06-11 07:42 18704 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
- 2008-11-18 14:50 . 2009-05-28 14:33 18704 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
- 2008-11-18 14:50 . 2009-05-28 14:33 20240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
+ 2008-11-18 14:50 . 2009-06-11 07:42 20240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
+ 2008-11-18 14:15 . 2009-06-11 07:42 90112 c:\windows\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\xlicons.exe
- 2008-11-18 14:15 . 2009-05-29 10:23 90112 c:\windows\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\xlicons.exe
- 2008-11-18 14:15 . 2009-05-29 10:23 45056 c:\windows\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\wordicon.exe
+ 2008-11-18 14:15 . 2009-06-11 07:42 45056 c:\windows\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\wordicon.exe
+ 2008-11-18 14:15 . 2009-06-11 07:42 22528 c:\windows\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\unbndico.exe
- 2008-11-18 14:15 . 2009-05-29 10:23 22528 c:\windows\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\unbndico.exe
+ 2008-11-18 14:15 . 2009-06-11 07:42 30720 c:\windows\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\pptico.exe
- 2008-11-18 14:15 . 2009-05-29 10:23 30720 c:\windows\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\pptico.exe
+ 2008-11-18 14:15 . 2009-06-11 07:42 16384 c:\windows\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\PEicons.exe
- 2008-11-18 14:15 . 2009-05-29 10:23 16384 c:\windows\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\PEicons.exe
- 2008-11-18 14:15 . 2009-05-29 10:23 34304 c:\windows\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\misc.exe
+ 2008-11-18 14:15 . 2009-06-11 07:42 34304 c:\windows\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\misc.exe
+ 2009-06-05 07:58 . 2009-06-05 07:58 31430 c:\windows\Installer\{5F0E82C8-CB7F-4896-884D-ECD2D876AEB8}\controlPanelIcon.exe
+ 2009-04-02 13:23 . 2009-04-02 13:23 10104 c:\windows\Installer\$PatchCache$\Managed\
00002109030000000000000000F01FEC\12.0.6425\XLCALL32.DLL
+ 2009-04-03 17:01 . 2009-04-03 17:01 71504 c:\windows\Installer\$PatchCache$\Managed\
00002109030000000000000000F01FEC\12.0.6425\XL12CNVP.DLL
+ 2009-04-03 16:57 . 2009-04-03 16:57 21320 c:\windows\Installer\$PatchCache$\Managed\
00002109030000000000000000F01FEC\12.0.6425\WRD12EXE.EXE
+ 2009-06-11 07:41 . 2009-03-08 03:33 12288 c:\windows\ie8updates\KB969897-IE8\xpshims.dll
+ 2009-06-11 07:41 . 2009-03-08 03:33 25600 c:\windows\ie8updates\KB969897-IE8\jsproxy.dll
+ 2008-11-18 14:15 . 2009-06-11 07:42 3584 c:\windows\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\opwicon.exe
- 2008-11-18 14:15 . 2009-05-29 10:23 3584 c:\windows\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\opwicon.exe
+ 2008-11-18 14:15 . 2009-06-11 07:42 8192 c:\windows\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\mspicons.exe
- 2008-11-18 14:15 . 2009-05-29 10:23 8192 c:\windows\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\mspicons.exe
- 2008-11-18 14:15 . 2009-05-29 10:23 2560 c:\windows\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\cagicon.exe
+ 2008-11-18 14:15 . 2009-06-11 07:42 2560 c:\windows\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\cagicon.exe
+ 2008-07-29 07:05 . 2008-07-29 07:05 161784 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_d01483b2\atl90.dll
+ 2008-04-14 04:00 . 2009-06-12 16:05 426638 c:\windows\system32\perfh009.dat
+ 2008-04-14 04:00 . 2009-04-30 21:22 385536 c:\windows\system32\iedkcs32.dll
- 2008-04-14 04:00 . 2009-03-08 03:32 173056 c:\windows\system32\ie4uinit.exe
+ 2008-04-14 04:00 . 2009-04-30 11:21 173056 c:\windows\system32\ie4uinit.exe
- 2008-11-12 15:14 . 2009-05-28 12:51 267800 c:\windows\system32\FNTCACHE.DAT
+ 2008-11-12 15:14 . 2009-06-11 07:44 267800 c:\windows\system32\FNTCACHE.DAT
+ 2008-04-14 04:00 . 2009-05-13 05:15 915456 c:\windows\system32\dllcache\wininet.dll
+ 2008-04-14 04:00 . 2009-04-15 14:51 585216 c:\windows\system32\dllcache\rpcrt4.dll
+ 2008-04-14 04:00 . 2009-05-07 15:32 345600 c:\windows\system32\dllcache\localspl.dll
+ 2008-04-14 04:00 . 2009-04-30 21:22 385536 c:\windows\system32\dllcache\iedkcs32.dll
+ 2008-04-14 04:00 . 2009-04-30 11:21 173056 c:\windows\system32\dllcache\ie4uinit.exe
- 2008-04-14 04:00 . 2009-03-08 03:32 173056 c:\windows\system32\dllcache\ie4uinit.exe
- 2009-05-28 14:32 . 2009-05-28 14:32 217864 c:\windows\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
+ 2009-06-02 16:29 . 2009-06-02 16:29 217864 c:\windows\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
- 2008-11-18 14:50 . 2009-05-28 14:33 888080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
+ 2008-11-18 14:50 . 2009-06-11 07:42 888080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
+ 2008-11-18 14:50 . 2009-06-11 07:42 272648 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
- 2008-11-18 14:50 . 2009-05-28 14:33 272648 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
+ 2008-11-18 14:50 . 2009-06-11 07:42 922384 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
- 2008-11-18 14:50 . 2009-05-28 14:33 922384 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
- 2008-11-18 14:50 . 2009-05-28 14:33 845584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
+ 2008-11-18 14:50 . 2009-06-11 07:42 845584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
+ 2008-11-18 14:50 . 2009-06-11 07:42 217864 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
- 2008-11-18 14:50 . 2009-05-28 14:33 217864 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
+ 2008-11-18 14:50 . 2009-06-11 07:42 184080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
- 2008-11-18 14:50 . 2009-05-28 14:33 184080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
+ 2008-11-18 14:50 . 2009-06-11 07:42 159504 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
- 2008-11-18 14:50 . 2009-05-28 14:33 159504 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
- 2008-11-18 14:15 . 2009-05-29 10:23 114688 c:\windows\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\outicon.exe
+ 2008-11-18 14:15 . 2009-06-11 07:42 114688 c:\windows\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\outicon.exe
+ 2008-11-18 14:15 . 2009-06-11 07:42 167936 c:\windows\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\accicons.exe
- 2008-11-18 14:15 . 2009-05-29 10:23 167936 c:\windows\Installer\{90110409-6000-11D3-8CFE-0050048383C9}\accicons.exe
+ 2009-04-03 17:11 . 2009-04-03 17:11 408424 c:\windows\Installer\$PatchCache$\Managed\
00002109030000000000000000F01FEC\12.0.6425\WINWORD.EXE
+ 2009-06-11 07:41 . 2009-03-08 03:34 914944 c:\windows\ie8updates\KB969897-IE8\wininet.dll
+ 2009-06-11 07:41 . 2008-07-09 07:38 382840 c:\windows\ie8updates\KB969897-IE8\spuninst\updspapi.dll
+ 2009-06-11 07:41 . 2007-11-30 12:39 231288 c:\windows\ie8updates\KB969897-IE8\spuninst\spuninst.exe
+ 2009-06-11 07:41 . 2009-03-08 03:33 246784 c:\windows\ie8updates\KB969897-IE8\ieproxy.dll
+ 2009-06-11 07:41 . 2009-03-08 13:09 391536 c:\windows\ie8updates\KB969897-IE8\iedkcs32.dll
+ 2009-06-11 07:41 . 2009-03-08 03:32 173056 c:\windows\ie8updates\KB969897-IE8\ie4uinit.exe
+ 2008-04-14 04:00 . 2009-04-30 21:22 1207808 c:\windows\system32\urlmon.dll
+ 2008-04-14 04:00 . 2009-05-13 05:15 5936128 c:\windows\system32\mshtml.dll
+ 2007-08-13 18:34 . 2009-04-30 21:22 1985024 c:\windows\system32\iertutil.dll
- 2007-08-13 18:34 . 2009-03-08 03:32 1985024 c:\windows\system32\iertutil.dll
+ 2008-04-14 04:00 . 2009-04-17 12:26 1847168 c:\windows\system32\dllcache\win32k.sys
+ 2008-04-14 04:00 . 2009-04-30 21:22 1207808 c:\windows\system32\dllcache\urlmon.dll
+ 2008-04-14 04:00 . 2009-05-13 05:15 5936128 c:\windows\system32\dllcache\mshtml.dll
+ 2008-11-19 13:13 . 2009-04-30 21:22 1985024 c:\windows\system32\dllcache\iertutil.dll
- 2008-11-19 13:13 . 2009-03-08 03:32 1985024 c:\windows\system32\dllcache\iertutil.dll
+ 2008-11-18 14:50 . 2009-06-11 07:42 1172240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
- 2008-11-18 14:50 . 2009-05-28 14:33 1172240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
+ 2008-11-18 14:50 . 2009-06-11 07:42 1165584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
- 2008-11-18 14:50 . 2009-05-28 14:33 1165584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
+ 2009-04-03 16:57 . 2009-04-03 16:57 4671320 c:\windows\Installer\$PatchCache$\Managed\
00002109030000000000000000F01FEC\12.0.6425\WRD12CNV.DLL
+ 2009-06-11 07:41 . 2009-03-08 03:34 1206784 c:\windows\ie8updates\KB969897-IE8\urlmon.dll
+ 2009-06-11 07:41 . 2009-03-08 03:41 5937152 c:\windows\ie8updates\KB969897-IE8\mshtml.dll
+ 2009-06-11 07:41 . 2009-03-08 03:32 1985024 c:\windows\ie8updates\KB969897-IE8\iertutil.dll
+ 2008-11-19 13:12 . 2009-06-01 16:51 23635392 c:\windows\system32\MRT.exe
+ 2007-08-13 18:54 . 2009-04-30 21:22 11064832 c:\windows\system32\ieframe.dll
+ 2008-11-19 13:13 . 2009-04-30 21:22 11064832 c:\windows\system32\dllcache\ieframe.dll
+ 2009-04-03 17:01 . 2009-04-03 17:01 15108448 c:\windows\Installer\$PatchCache$\Managed\
00002109030000000000000000F01FEC\12.0.6425\XL12CNV.EXE
+ 2009-04-03 17:11 . 2009-04-03 17:11 17740136 c:\windows\Installer\$PatchCache$\Managed\
00002109030000000000000000F01FEC\12.0.6425\WWLIB.DLL
+ 2009-04-03 17:11 . 2009-04-03 17:11 18330984 c:\windows\Installer\$PatchCache$\Managed\
00002109030000000000000000F01FEC\12.0.6425\EXCEL.EXE
+ 2009-06-11 07:41 . 2009-03-08 03:39 11063808 c:\windows\ie8updates\KB969897-IE8\ieframe.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2008-01-16 17:52 80384 -c--a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2008-01-16 17:52 80384 -c--a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2008-01-16 17:52 80384 -c--a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2008-01-16 17:52 80384 -c--a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2008-01-16 17:52 80384 -c--a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2008-01-16 17:52 80384 -c--a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2008-01-16 17:52 80384 -c--a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2008-01-16 17:52 80384 -c--a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2008-01-16 17:52 80384 -c--a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@="{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}"
[HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]
2007-04-16 23:13 721408 -c--a-w- c:\program files\Fingerprint Reader Suite\farchns.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@="{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}"
[HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]
2007-04-16 23:13 721408 -c--a-w- c:\program files\Fingerprint Reader Suite\farchns.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"SpeedswitchXP"="c:\program files\SpeedswitchXP\SpeedswitchXP.exe" [2006-07-14 626688]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-11-20 68856]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-03-20 1312256]
"Google Update"="c:\documents and settings\richard\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-05-31 133104]
"MMAgent"="c:\program files\Mobile Master\MMAgent.exe" [2009-05-27 1355776]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-04-16 24264488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"OEM04Mon.exe"="c:\windows\OEM04Mon.exe" [2007-06-11 36864]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-08-01 8466432]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"iPrint Tray"="c:\windows\system32\iprntctl.exe" [2008-08-25 40960]
"iPrint Event Monitor"="c:\windows\system32\iprntlgn.exe" [2008-08-25 45056]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"@OnlineArmor GUI"="c:\program files\Online Armor\oaui.exe" [2009-04-28 2045128]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-06-11 30192]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2007-08-01 1626112]
"NVHotkey"="nvHotkey.dll" - c:\windows\system32\nvhotkey.dll [2007-08-01 67584]
"NvMediaCenter"="NvMCTray.dll" - c:\windows\system32\nvmctray.dll [2007-08-01 81920]
"NWTRAY"="NWTRAY.EXE" - c:\windows\system32\nwtray.exe [2002-03-12 28672]
"Run StartupMonitor"="StartupMonitor.exe" - c:\windows\StartupMonitor.exe [2000-05-20 86016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]
c:\documents and settings\richard\Start Menu\Programs\Startup\
Shortcut to map_h.bat.lnk - c:\users\rw\programs\startup\map_h.bat [2008-11-8 37]
TextPad.lnk - c:\program files\TextPad 4\TextPad.exe [2008-11-19 1900544]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe [2003-5-15 217193]
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-5-24 622653]
Novell iFolder.lnk - c:\program files\Novell\iFolder\trayapp.exe [2009-1-6 266317]
Update Agent.lnk - c:\program files\3\3Connect\AutoUpdateSrv.exe [2009-5-20 670256]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"CompatibleRUPSecurity"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= "c:\progra~1\ONLINE~2\oaevent.dll" [2009-04-28 335048]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2007-04-16 23:04 86528 -c--a-w- c:\windows\system32\psqlpwd.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwv1_0
Notification Packages REG_MULTI_SZ scecli psqlpwd
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Novell\\GroupWise\\grpwise.exe"=
"c:\\Novell\\GroupWise\\notify.exe"=
"c:\\Program Files\\Microsoft Office\\Office10\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office10\\WINWORD.EXE"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 NifFltr;NifFltr;c:\windows\system32\drivers\niffltr.sys [06/01/2009 10:53 25300]
R1 nipplpt2;Novell iCapture Lpt Redirector 2;c:\windows\system32\drivers\nipplpt.sys [29/05/2009 14:57 34671]
R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [31/05/2009 18:32 198224]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [31/05/2009 18:32 31824]
R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [31/05/2009 18:32 29776]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [31/05/2009 15:30 108289]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [31/05/2009 15:52 210216]
R2 mdvrmng;Mobile IP Route Manager;c:\windows\system32\drivers\mdvrmng.sys [20/05/2009 09:16 10240]
R2 OAcat;Online Armor Helper Service;c:\program files\Online Armor\oacat.exe [31/05/2009 18:32 361672]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 20:19 13592]
R2 wwEngineSvc;Window Washer Engine;c:\program files\Webroot\Washer\WasherSvc.exe [27/01/2009 18:49 598856]
R3 OEM04Afx;Provides a software interface to control audio effects of OEM004 camera.;c:\windows\system32\drivers\OEM04Afx.sys [12/11/2008 18:16 141376]
R3 OEM04Vfx;Creative Camera OEM004 Video VFX Driver;c:\windows\system32\drivers\OEM04Vfx.sys [12/11/2008 18:16 7424]
R3 OEM04Vid;Creative Camera OEM004 Driver;c:\windows\system32\drivers\OEM04Vid.sys [12/11/2008 18:16 234720]
S2 SvcOnlineArmor;Online Armor;c:\program files\Online Armor\oasrv.exe [31/05/2009 18:32 3052744]
S3 GoogleDesktopManager-092308-165331;Google Desktop Manager 5.8.809.23506;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [11/06/2009 16:30 30192]
S3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter.sys [22/08/2008 19:56 7680]
S3 vcache;vcache;c:\windows\system32\drivers\vcache.sys [25/03/2009 21:19 46992]
S3 vfilter;vfilter;c:\windows\system32\drivers\vfilter.sys [25/03/2009 21:19 28944]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-06-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-789336058-2025429265-1801674531-1003.job
- c:\documents and settings\richard\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-31 18:28]
2009-06-12 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
2009-06-12 c:\windows\Tasks\User_Feed_Synchronization-{E2E50640-E066-4CA5-A1AF-82FBD09C7F42}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 03:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.bbcnews.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MI69DF~1\Office12\EXCEL.EXE/3000
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} - hxxps://moneymanager.egg.com/Pinsafe/accounttracking.cab
DPF: {EAC139A9-D22D-4C29-8D1C-252BE63750F9} - hxxp://www.cooliris.com/shared/plinstll.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-06-12 17:14
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-789336058-2025429265-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{280DF7DA-9B6D-694A-22F7-119678CD0601}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"abhinbmdlmeocdgkkcnpnpcjnnggjfnked"=hex:6a,61,67,68,62,69,70,61,62,6f,65,63,
6b,62,62,67,63,62,64,6c,00,53
"panjppohkhbfhaciifpnjnldjjikmifp"=hex:69,61,6c,68,70,6a,67,6c,6a,69,61,70,6d,
6b,6c,68,61,66,00,00
"abhinbmdlmeocdgkkcnpnpcjnnggifahbb"=hex:69,61,69,68,6f,67,6c,66,6b,62,6e,61,
6c,70,64,6f,6c,61,00,00
"panjppohkhbfhaciifpnjnldjjjkjioo"=hex:69,61,69,68,6f,67,6c,66,6b,62,6e,61,6c,
70,64,6f,6c,61,00,00
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(544)
c:\windows\system32\psqlpwd.dll
c:\program files\Fingerprint Reader Suite\homefus2.dll
c:\program files\Fingerprint Reader Suite\infra.dll
c:\program files\Fingerprint Reader Suite\homepass.dll
c:\program files\Fingerprint Reader Suite\bio.dll
c:\program files\Fingerprint Reader Suite\remote.dll
c:\program files\Fingerprint Reader Suite\crypto.dll
- - - - - - - > 'lsass.exe'(600)
c:\windows\system32\psqlpwd.dll
c:\program files\Fingerprint Reader Suite\homefus2.dll
c:\program files\Fingerprint Reader Suite\infra.dll
- - - - - - - > 'Explorer.exe'(3296)
c:\windows\system32\WININET.dll
c:\program files\McAfee\SiteAdvisor\saHook.dll
c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
c:\program files\TortoiseSVN\bin\TortoiseStub.dll
c:\program files\Fingerprint Reader Suite\farchns.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
c:\program files\Fingerprint Reader Suite\infra.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-06-12 17:16
ComboFix-quarantined-files.txt 2009-06-12 16:16
Pre-Run: 49,876,729,856 bytes free
Post-Run: 49,393,549,312 bytes free
464 --- E O F --- 2009-06-11 07:42