ok, turned off system restore and ran combofix,mbam,hijack: results as shown:ComboFix 10-01-12.05 - Compaq_Owner 01/13/2010 9:01.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.503.108 [GMT -8:00]
Running from: c:\documents and settings\Compaq_Owner\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.((((((((((((((((((((((((( Files Created from 2009-12-13 to 2010-01-13
.2010-01-12 19:12 . 2009-11-21 15:51 471552 ------w- c:\windows\system32\dllcache\aclayers.dll
2010-01-12 00:09 . 2010-01-12 00:09 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\Malwarebytes
2010-01-12 00:09 . 2010-01-08 00:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-12 00:08 . 2010-01-12 00:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-12 00:08 . 2010-01-08 00:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-12 00:08 . 2010-01-12 00:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-11 19:42 . 2010-01-11 19:42 -------- d-----w- c:\program files\VirtualDJ
2010-01-11 19:34 . 2010-01-11 19:48 -------- d-----w- c:\program files\MagicISO
2010-01-11 18:43 . 2010-01-11 19:12 -------- d-----w- c:\documents and settings\Compaq_Owner\.ultramixer
2010-01-11 18:42 . 2010-01-11 19:48 -------- d-----w- c:\program files\UltraMixer
2010-01-11 17:51 . 2010-01-11 17:51 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2010-01-11 17:47 . 2010-01-11 23:20 -------- d-----w- c:\windows\Internet Logs
2010-01-09 19:04 . 2010-01-09 19:04 -------- d-sh--w- c:\documents and settings\Compaq_Owner\IECompatCache
2010-01-09 19:00 . 2010-01-09 19:00 -------- d-sh--w- c:\documents and settings\Compaq_Owner\PrivacIE
2010-01-09 18:58 . 2010-01-09 18:58 -------- d-sh--w- c:\documents and settings\Compaq_Owner\IETldCache
2010-01-09 18:53 . 2010-01-09 18:53 -------- d-----w- c:\windows\ie8updates
2010-01-09 18:47 . 2010-01-09 18:50 -------- dc-h--w- c:\windows\ie8
2010-01-09 18:42 . 2009-10-29 07:45 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2010-01-09 18:42 . 2009-10-29 07:45 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll
2010-01-09 18:42 . 2009-10-02 04:44 92160 ------w- c:\windows\system32\dllcache\iecompat.dll
2010-01-08 20:05 . 2010-01-08 20:23 -------- d-----w- c:\program files\DICO
2010-01-08 19:51 . 2003-12-01 17:42 31787 ----a-w- c:\windows\system32\drivers\FADVR800.sys
2010-01-08 18:50 . 2008-06-13 11:05 272128 ------w- c:\windows\system32\dllcache\bthport.sys
2010-01-08 18:49 . 2009-03-06 14:22 284160 ------w- c:\windows\system32\dllcache\pdh.dll
2010-01-08 18:49 . 2009-02-09 12:10 401408 ------w- c:\windows\system32\dllcache\rpcss.dll
2010-01-08 18:49 . 2009-02-06 11:11 110592 ------w- c:\windows\system32\dllcache\services.exe
2010-01-08 18:49 . 2009-02-09 12:10 473600 ------w- c:\windows\system32\dllcache\fastprox.dll
2010-01-08 18:49 . 2009-02-06 10:10 227840 ------w- c:\windows\system32\dllcache\wmiprvse.exe
2010-01-08 18:49 . 2009-06-25 08:25 730112 ------w- c:\windows\system32\dllcache\lsasrv.dll
2010-01-08 18:49 . 2009-02-09 12:10 617472 ------w- c:\windows\system32\dllcache\advapi32.dll
2010-01-08 18:49 . 2009-02-09 12:10 453120 ------w- c:\windows\system32\dllcache\wmiprvsd.dll
2010-01-08 18:49 . 2009-02-09 12:10 714752 ------w- c:\windows\system32\dllcache\ntdll.dll
2010-01-08 18:48 . 2008-05-08 14:02 203136 ------w- c:\windows\system32\dllcache\rmcast.sys
2010-01-08 18:48 . 2008-10-24 11:21 455296 ------w- c:\windows\system32\dllcache\mrxsmb.sys
2010-01-08 18:48 . 2008-12-11 10:57 333952 ------w- c:\windows\system32\dllcache\srv.sys
2010-01-08 18:48 . 2009-07-10 13:27 1315328 ------w- c:\windows\system32\dllcache\msoe.dll
2010-01-08 18:48 . 2008-04-11 19:04 691712 ------w- c:\windows\system32\dllcache\inetcomm.dll
2010-01-08 18:47 . 2010-01-09 19:19 364949 ----a-w- c:\windows\system32\drivers\BT848.sys
2010-01-08 18:46 . 2009-08-04 15:13 2145280 ------w- c:\windows\system32\dllcache\ntkrnlmp.exe
2010-01-08 18:46 . 2009-08-04 14:20 2023936 ------w- c:\windows\system32\dllcache\ntkrpamp.exe
2010-01-08 18:46 . 2009-08-04 14:20 2066048 ------w- c:\windows\system32\dllcache\ntkrnlpa.exe
2010-01-08 18:46 . 2008-10-15 16:34 337408 ------w- c:\windows\system32\dllcache\netapi32.dll
2010-01-08 18:31 . 2010-01-08 18:31 -------- d-----w- c:\windows\system32\scripting
2010-01-08 18:31 . 2010-01-08 18:31 -------- d-----w- c:\windows\l2schemas
2010-01-08 18:31 . 2010-01-08 18:31 -------- d-----w- c:\windows\system32\en
2010-01-08 18:31 . 2010-01-08 18:31 -------- d-----w- c:\windows\system32\bits
2010-01-08 18:18 . 2010-01-08 18:18 -------- d-----w- c:\windows\EHome
2010-01-08 00:36 . 2010-01-08 00:36 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2010-01-07 19:16 . 2010-01-07 19:20 -------- d-----w- C:\Monitor1
2010-01-07 18:18 . 2010-01-07 18:18 -------- d-----w- c:\documents and settings\LocalService\Application Data\NCH Software
2010-01-07 18:12 . 2008-04-13 18:39 5504 ----a-w- c:\windows\system32\drivers\mstee.sys
2010-01-07 18:12 . 2008-04-13 18:46 10880 ----a-w- c:\windows\system32\drivers\ndisip.sys
2010-01-07 18:12 . 2008-04-13 18:46 15232 ----a-w- c:\windows\system32\drivers\streamip.sys
2010-01-07 18:12 . 2008-04-13 18:46 11136 ----a-w- c:\windows\system32\drivers\slip.sys
2010-01-07 18:12 . 2008-04-13 18:46 19200 ----a-w- c:\windows\system32\drivers\wstcodec.sys
2010-01-07 18:12 . 2008-04-13 18:46 85248 ----a-w- c:\windows\system32\drivers\nabtsfec.sys
2010-01-07 18:11 . 2008-04-13 18:46 17024 ----a-w- c:\windows\system32\drivers\ccdecode.sys
2010-01-07 18:10 . 2008-04-14 00:12 53760 ----a-w- c:\windows\system32\vfwwdm32.dll
2010-01-07 18:10 . 2008-04-14 00:12 53760 ----a-w- c:\windows\system32\dllcache\vfwwdm32.dll
2010-01-07 17:51 . 2010-01-08 19:52 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\NCH Software
2010-01-05 00:43 . 2010-01-05 04:42 -------- d-----w- C:\Photoshop_cs3
2010-01-04 21:26 . 2010-01-04 21:26 -------- d-----w- c:\program files\Bonjour
2010-01-04 21:15 . 2010-01-04 21:15 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2010-01-04 21:08 . 2010-01-04 21:08 -------- d-----w- C:\Adobe CS3
2010-01-04 18:36 . 2010-01-04 18:36 -------- d-----w- C:\Adobe Reader 9 Installer
2010-01-04 18:20 . 2008-05-28 23:03 37176 ----a-w- c:\documents and settings\Compaq_Owner\Application Data\Macromedia\Flash Player\
http://www.macromedia.com\bin\airapp...pinstaller.exe
2010-01-04 18:18 . 2010-01-04 18:18 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-01-04 18:18 . 2010-01-04 18:18 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-01-04 18:18 . 2010-01-04 18:18 -------- d-----w- c:\program files\NOS
2010-01-04 17:21 . 2010-01-04 17:21 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\Uniblue
2009-12-31 22:39 . 2009-11-25 21:01 1230080 ----a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-12-31 22:26 . 2009-12-31 22:26 -------- d-----w- C:\$AVG
2009-12-31 22:26 . 2009-12-31 22:26 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-12-31 22:26 . 2009-12-31 22:26 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-12-31 22:26 . 2009-12-31 22:26 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-12-31 22:25 . 2009-12-31 22:25 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-12-31 22:25 . 2010-01-13 16:57 -------- d-----w- c:\windows\system32\drivers\Avg
2009-12-31 22:25 . 2009-12-31 22:39 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-12-31 22:25 . 2009-12-31 22:25 -------- d-----w- c:\program files\AVG
2009-12-31 22:25 . 2010-01-11 23:19 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2009-12-31 18:53 . 2009-12-31 18:53 -------- d-----w- c:\windows\system32\XPSViewer
2009-12-31 18:53 . 2009-12-31 18:53 -------- d-----w- c:\program files\MSBuild
2009-12-31 18:53 . 2009-12-31 18:53 -------- d-----w- c:\program files\Reference Assemblies
2009-12-31 18:53 . 2008-07-06 12:06 89088 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpi pelineprintproc.dll
2009-12-31 18:52 . 2008-07-06 12:06 89088 ------w- c:\windows\system32\dllcache\filterpipelineprintpr oc.dll
2009-12-31 18:52 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-12-31 18:52 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-12-31 18:52 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-12-31 18:52 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfil terpipelinesvc.exe
2009-12-31 18:52 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\dllcache\printfilterpipelinesv c.exe
2009-12-31 18:52 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-12-31 18:52 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\dllcache\xpssvcs.dll
2009-12-31 18:50 . 2009-12-31 18:50 -------- d-----w- c:\program files\MSXML 6.0
2009-12-31 18:25 . 2007-02-21 00:04 190696 ----a-w- c:\windows\system32\NPSWF32_FlashUtil.exe
2009-12-31 18:25 . 2007-02-21 00:04 2463976 ----a-w- c:\windows\system32\NPSWF32.dll
2009-12-31 17:42 . 2009-12-31 17:42 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-12-31 17:40 . 2009-12-31 17:51 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\DAEMON Tools Lite
2009-12-31 17:40 . 2009-12-31 17:40 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2009-12-30 23:46 . 2009-12-30 23:46 111144 ----a-w- C:\GDIPFONTCACHEV1.DAT
2009-12-30 23:46 . 2009-12-30 23:46 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet
2009-12-30 22:31 . 2009-12-30 22:31 -------- d-----w- c:\program files\Adobe Media Player
2009-12-30 22:28 . 2009-12-30 22:28 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-12-29 23:01 . 2009-12-29 23:01 -------- d-----w- c:\documents and settings\Compaq_Owner\Local Settings\Application Data\xddvev
2009-12-28 21:36 . 2009-12-28 21:36 -------- d-----w- C:\audio
2009-12-28 19:12 . 2009-12-28 19:12 -------- d-----w- c:\program files\ASIO4ALL v2
2009-12-28 19:10 . 2006-06-20 08:56 225280 ----a-w- c:\windows\system32\rewire.dll
2009-12-28 19:10 . 2009-12-28 19:10 -------- d-----w- c:\program files\VstPlugins
2009-12-28 19:10 . 2009-12-28 19:10 -------- d-----w- c:\program files\Outsim
2009-12-28 19:07 . 2009-12-28 19:31 -------- d-----w- c:\program files\Image-Line
2009-12-28 18:38 . 2009-12-28 18:38 -------- d-----w- c:\program files\uTorrent
Find3M Report
.2010-01-13 17:06 . 2008-07-28 22:01 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\uTorrent
2010-01-13 16:47 . 2008-07-28 23:05 111912 -c--a-w- c:\documents and settings\Compaq_Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-13 01:02 . 2008-08-23 18:44 7444 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2008\qbbackup.sys
2010-01-08 23:22 . 2009-03-10 16:45 -------- d-----w- c:\program files\NCH Software
2010-01-08 19:52 . 2009-11-23 22:11 -------- d-----w- c:\documents and settings\All Users\Application Data\NCH Software
2010-01-08 18:34 . 2005-01-27 05:13 83187 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-01-08 18:33 . 2010-01-08 18:33 45056 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\uninstallUI\eHelpSet up.exe
2010-01-08 18:33 . 2010-01-08 18:33 44032 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Scripts\devcon.exe
2010-01-08 01:12 . 2009-03-10 16:44 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\NCH Swift Sound
2010-01-08 00:58 . 2009-03-10 16:45 -------- d-----w- c:\documents and settings\All Users\Application Data\NCH Swift Sound
2010-01-04 21:26 . 2005-09-15 19:22 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-31 22:58 . 2002-01-11 03:13 -------- d-----w- c:\program files\QuickTime
2009-12-31 18:06 . 2002-01-11 03:13 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-31 18:03 . 2009-03-16 04:31 -------- d-----w- c:\program files\McAfee
2009-12-31 18:03 . 2008-06-28 17:59 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-12-29 22:18 . 2008-07-02 22:34 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\AdobeUM
2009-11-24 00:22 . 2009-11-24 00:18 -------- d-----w- c:\program files\Invoice2go 4.0
2009-11-21 15:51 . 2004-08-04 12:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-03 01:02 . 2009-11-03 01:05 816456 ----a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2008\Components\DownloadQB17\Patch\qbpatch2.exe
2009-10-29 07:45 . 2004-08-04 11:00 916480 ------w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2004-08-04 12:00 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-04 12:00 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 11:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
Reg Loading Points
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-11-25 21:01 1230080 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2009-12-28 289584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-04-05 77824]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-26 245760]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwat cher.exe" [2004-10-14 253952]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\UdaterUI.exe" [2006-11-17 136768]
"Persistence"="c:\windows\system32\igfxpers.ex e" [2005-04-05 114688]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-01-01 2033432]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-12-31 22:26 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
2004-03-18 07:10 61952 ----a-w- c:\windows\system32\Hdaudpropshortcut.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-26 23:44 3883856----a-w-c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Intuit\\QuickBooks 2008\\QBDBMgrN.exe"=
"c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"j:\\Raj Khela's PC BACKUP\\My Documents\\utorrent.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\GloballyOpenPorts\List]
"20396:TCP"= 20396:TCP:BitComet 20396 TCP
"20396:UDP"= 20396:UDP:BitComet 20396 UDP
"14672:TCP"= 14672:TCP:BitComet 14672 TCP
"14672:UDP"= 14672:UDP:BitComet 14672 UDP
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [12/31/2009 2:26 PM 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [12/31/2009 2:26 PM 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [12/31/2009 2:25 PM 285392]
R2 BT848;Conexant's BtPCI WDM Video Capture;c:\windows\system32\drivers\BT848.sys [1/8/2010 10:47 AM 364949]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [12/31/2009 9:42 AM 691696]
S2 FADVR800;FADVR800;c:\windows\system32\drivers\FADV R800.sys [1/8/2010 11:51 AM 31787]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.Contents of the 'Scheduled Tasks' folder
2009-12-24 c:\windows\Tasks\Khela Tire Service Ltd. 1221419904.job
- c:\program files\Intuit\QuickBooks 2008\AutoBackupEXE.exe [2008-12-11 18:36]
2010-01-13 c:\windows\Tasks\Khela Tire Service Ltd. 1240417286.job
- c:\program files\Intuit\QuickBooks 2008\AutoBackupEXE.exe [2008-12-11 18:36]
2010-01-13 c:\windows\Tasks\Khela Tire Service Ltd. 1254785729.job
- c:\program files\Intuit\QuickBooks 2008\AutoBackupEXE.exe [2008-12-11 18:36]
2010-01-13 c:\windows\Tasks\User_Feed_Synchronization-{0575B580-0A5B-49B7-857E-C3D85B727FE5}.job
- c:\windows\system32\msfeedssync.exe [2007-08-14 12:31]
2010-01-12 c:\windows\Tasks\{ED4EC287-B9DA-46BB-8D36-CF856FCA7B4D}_RAJ_Compaq_Owner.job
- c:\windows\system32\mobsync.exe [2004-08-04 00:12]
.------- Supplementary Scan -------
.uStart Page = hxxp://www.google.ca/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.micros oft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
.************************************************* *****************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
GMER - Rootkit Detector and Remover
Rootkit scan 2010-01-13 09:09
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
DLLs Loaded Under Running Processes - - - - - - - > 'explorer.exe'(3780)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\program files\Bonjour\mdnsNSP.dll
c:\windows\system32\webcheck.dll
.Completion time: 2010-01-13 09:13:03
ComboFix-quarantined-files.txt 2010-01-13 17:12
ComboFix2.txt 2010-01-11 23:58
Pre-Run: 54,140,817,408 bytes free
Post-Run: 54,109,630,464 bytes free
End Of File - - 7B7CFBF8A3A5E3154D8441AEF7E7E49F
currently scanning with avg.