OK DIsregard the last message after I acknowledged the error message I previously mentioned I did notice a text file created in my c drive called combo fix which I am assuming is the log... here is it ....
ComboFix 10-01-04.01 - Ron 01/07/2010 12:11:25.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.459 [GMT -5:00]
Running from: c:\aol downloads\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Ron\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Security 2010.lnk
c:\documents and settings\Ron\Desktop\Internet Security 2010.lnk
c:\documents and settings\Ron\Start Menu\Internet Security 2010.lnk
c:\program files\InternetSecurity2010
c:\program files\InternetSecurity2010\IS2010.exe
c:\windows\system32\41.exe
c:\windows\system32\helper32.dll
.
---- Previous Run -------
.
c:\documents and settings\All Users\Application Data\Macromedia\SwUpdate\swUPdate.dll
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\Ron\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Security 2010.lnk
c:\documents and settings\Ron\Desktop\Internet Security 2010.lnk
c:\documents and settings\Ron\Start Menu\Internet Security 2010.lnk
c:\program files\InternetSecurity2010\IS2010.exe
c:\windows\Fonts\acrsec.fon
c:\windows\kb913800.exe
c:\windows\system32\11478.exe
c:\windows\system32\15724.exe
c:\windows\system32\18467.exe
c:\windows\system32\19169.exe
c:\windows\system32\26500.exe
c:\windows\system32\41.exe
c:\windows\system32\6334.exe
c:\windows\system32\AutoRun.inf
c:\windows\system32\AVSredirect.dll
c:\windows\system32\ccrpTmr6.dll
c:\windows\system32\hawupula.dll
c:\windows\system32\helper32.dll
c:\windows\system32\jefaduku.dll
c:\windows\system32\logon.exe
c:\windows\system32\mapopabe.dll
c:\windows\system32\mifolole.dll
c:\windows\system32\pamepusu.dll
c:\windows\system32\pujojiwu.dll
c:\windows\system32\sefewana.dll
c:\windows\system32\tehisuvo.dll
c:\windows\system32\vetaweyo.dll
c:\windows\Tasks\jkzjihhd.job
.
((((((((((((((((((((((((( Files Created from 2009-12-07 to 2010-01-07 )))))))))))))))))))))))))))))))
.
2010-01-07 17:25 . 2010-01-07 17:25 1116672 ----a-w- c:\windows\system32\IS15.exe
2010-01-07 17:25 . 2010-01-07 17:25 16896 ----a-w- c:\windows\system32\helper32.dll
2010-01-07 17:09 . 2010-01-07 17:09 -------- d-----w- c:\program files\Trend Micro
2010-01-07 12:13 . 1601-01-01 00:03 29696 --sha-w- c:\windows\system32\winlogon32.exe
2010-01-07 12:13 . 1601-01-01 00:03 29696 --sha-w- c:\windows\system32\smss32.exe
2010-01-06 21:58 . 2010-01-06 21:58 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-12-30 19:39 . 2009-12-30 19:39 -------- d-----w- c:\documents and settings\Ron\Application Data\SharePod
2009-12-30 19:18 . 2009-12-30 19:18 59904 ----a-w- c:\windows\system32\ZLIB1.DLL
2009-12-30 16:23 . 2009-12-30 16:23 -------- d-----w- c:\documents and settings\Ron\Application Data\Facebook
2009-12-27 19:36 . 2009-12-30 18:25 -------- d-----w- c:\documents and settings\Ron\Application Data\Apple Computer
2009-12-27 19:34 . 2010-01-07 15:39 -------- d-----w- c:\program files\iTunes
2009-12-27 19:34 . 2009-12-27 19:35 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-12-27 19:33 . 2010-01-04 17:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-12-27 19:33 . 2009-12-27 19:33 -------- d-----w- c:\documents and settings\Ron\Local Settings\Application Data\Apple
2009-12-27 19:33 . 2009-12-27 19:33 -------- d-----w- c:\program files\Apple Software Update
2009-12-27 19:32 . 2010-01-04 17:49 -------- d-----w- c:\program files\Common Files\Apple
2009-12-27 19:32 . 2009-12-27 19:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-12-27 19:32 . 2009-12-27 19:47 -------- d-----w- c:\documents and settings\Ron\Local Settings\Application Data\Apple Computer
2009-12-22 20:25 . 2009-12-22 20:25 -------- d-----w- c:\program files\NCH Software
2009-12-22 20:23 . 2009-12-22 20:23 -------- d-----w- c:\documents and settings\All Users\Application Data\NCH Swift Sound
2009-12-22 20:23 . 2009-12-22 20:23 -------- d-----w- c:\program files\NCH Swift Sound
2009-12-22 20:23 . 2009-12-22 20:23 -------- d-----w- c:\documents and settings\Ron\Application Data\NCH Swift Sound
2009-12-22 01:53 . 2009-12-22 01:53 -------- d-----w- c:\program files\MP4Cam2AVI_v2.83
2009-12-10 18:24 . 2007-05-17 22:30 318976 ----a-w- c:\windows\system32\avisynth.dll
2009-12-10 18:24 . 2004-02-22 15:11 719872 ----a-w- c:\windows\system32\devil.dll
2009-12-10 18:10 . 2001-08-18 03:36 5632 ----a-w- c:\windows\system32\ptpusb.dll
2009-12-10 18:10 . 2008-04-14 01:12 159232 ----a-w- c:\windows\system32\ptpusd.dll
2009-12-10 17:59 . 2009-12-10 17:59 -------- d-----w- c:\program files\Flip Video
2009-12-10 16:47 . 2009-12-10 16:47 -------- d-----w- c:\program files\3ivx
2009-12-10 16:46 . 2009-12-10 16:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Flip Video
2009-12-09 17:13 . 2004-01-25 05:00 70656 ----a-w- c:\windows\system32\yv12vfw.dll
2009-12-09 17:13 . 2004-01-25 05:00 70656 ----a-w- c:\windows\system32\i420vfw.dll
2009-12-09 17:12 . 2008-03-16 12:30 216064 --sh--r- c:\windows\system32\nbDX.dll
2009-12-09 17:12 . 2007-02-21 10:47 31232 --sh--r- c:\windows\system32\msfDX.dll
2009-12-09 17:12 . 2006-05-03 09:06 163328 --sh--r- c:\windows\system32\flvDX.dll
2009-12-09 17:12 . 2009-12-09 17:12 -------- d-----w- c:\program files\eRightSoft
2009-12-09 16:19 . 2009-12-09 16:19 -------- d-----w- c:\documents and settings\Ron\Application Data\AVS4YOU
2009-12-09 16:19 . 2009-12-09 16:19 -------- d-----w- c:\documents and settings\All Users\Application Data\AVS4YOU
2009-12-09 16:04 . 2009-12-09 16:22 -------- d-----w- c:\program files\Common Files\AVSMedia
2009-12-09 16:04 . 2009-12-09 16:22 -------- d-----w- c:\program files\AVS4YOU
2009-12-09 16:04 . 2008-08-13 15:22 24576 ----a-w- c:\windows\system32\msxml3a.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-07 17:25 . 2010-01-07 17:25 0 ----a-w- c:\windows\system32\41.exe
2010-01-07 16:28 . 2009-03-24 23:25 -------- d-----w- c:\program files\Windows Live Safety Center
2010-01-07 12:13 . 2008-11-28 13:38 -------- d-----w- c:\program files\LogMeIn
2010-01-06 21:14 . 2007-01-26 13:48 -------- d-----w- c:\program files\FTP Commander
2010-01-04 17:50 . 2007-01-17 06:42 -------- d-----w- c:\program files\QuickTime
2010-01-04 14:40 . 2007-01-22 15:57 3350 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-12-31 13:34 . 2009-12-07 13:25 862040 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-12-31 13:33 . 2009-12-07 13:25 206944 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-12-31 13:33 . 2009-12-07 13:25 390288 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
2009-12-31 13:33 . 2009-12-07 13:25 537576 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\aawapi.dll
2009-12-31 13:33 . 2009-12-07 13:25 370744 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2009-12-31 13:33 . 2009-12-07 13:25 194104 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Savapibridge.dll
2009-12-31 13:30 . 2009-12-07 13:24 6296864 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2009-12-31 13:29 . 2009-12-07 13:24 933120 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-12-31 13:29 . 2009-12-07 13:24 816272 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-12-31 13:29 . 2009-12-07 13:24 822904 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-12-31 13:29 . 2009-12-07 13:24 1643272 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-12-31 13:28 . 2009-12-07 13:24 788880 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-12-31 13:28 . 2009-12-07 13:24 1181328 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-12-30 19:02 . 2007-01-17 06:57 108920 -c--a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-30 18:54 . 2007-01-17 06:38 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-30 18:45 . 2007-01-22 15:57 -------- d-----w- c:\documents and settings\Ron\Application Data\Corel
2009-12-30 18:45 . 2007-01-17 06:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Corel
2009-12-30 18:45 . 2007-01-17 06:40 -------- d-----w- c:\program files\Corel
2009-12-30 18:42 . 2007-01-22 20:25 -------- d-----w- c:\documents and settings\Ron\Application Data\Ulead Systems
2009-12-30 18:42 . 2007-01-22 16:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Ulead Systems
2009-12-30 18:42 . 2007-01-17 06:40 -------- d-----w- c:\program files\Common Files\Corel
2009-12-30 18:38 . 2007-01-22 16:10 -------- d-----w- c:\program files\Common Files\Ulead Systems
2009-12-30 16:23 . 2009-12-30 16:23 50354 ----a-w- c:\documents and settings\Ron\Application Data\Facebook\uninstall.exe
2009-12-20 16:59 . 2007-11-14 14:51 130958 -c--a-w- c:\windows\hpoins12.dat
2009-12-18 15:19 . 2007-12-16 16:31 -------- d-----w- c:\documents and settings\Ron\Application Data\Image Zone Express
2009-12-17 06:50 . 2009-12-17 06:50 847040 ----a-w- c:\documents and settings\Ron\Application Data\Facebook\axfbootloader.dll
2009-12-17 06:49 . 2009-12-17 06:49 5562368 ----a-w- c:\documents and settings\Ron\Application Data\Facebook\npfbplugin_1_0_0.dll
2009-12-09 17:33 . 2009-01-15 20:14 -------- d-----w- c:\program files\Active Images Express
2009-12-09 17:32 . 2009-03-21 14:28 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-09 17:31 . 2009-12-08 02:35 -------- d-----w- c:\program files\AviSynth 2.5
2009-12-08 10:19 . 2009-12-02 16:39 589776 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-12-08 02:35 . 2009-12-08 02:35 -------- d-----w- c:\program files\Red Kawa
2009-12-08 02:25 . 2009-12-02 16:26 2516 --sha-w- c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
2009-12-08 02:25 . 2009-12-02 16:26 2516 --sha-w- c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
2009-12-08 00:52 . 2009-12-02 16:26 88 --sh--r- c:\documents and settings\All Users\Application Data\55AF9A5A34.sys
2009-12-08 00:52 . 2009-12-02 16:26 88 --sh--r- c:\documents and settings\All Users\Application Data\55AF9A5A34.sys
2009-12-07 13:25 . 2009-12-07 13:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-12-07 13:25 . 2009-12-07 15:13 15880 ----a-w- c:\windows\system32\lsdelete.exe
2009-12-07 13:25 . 2009-12-07 13:25 15880 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-12-07 13:25 . 2009-12-07 13:25 163728 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-12-07 13:24 . 2009-12-07 13:24 327000 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-12-07 13:24 . 2009-12-07 13:24 87496 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-12-07 13:24 . 2009-12-07 13:24 641632 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2009-12-07 13:14 . 2009-12-07 13:14 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2009-12-07 13:14 . 2007-01-22 15:53 -------- d-----w- c:\program files\Lavasoft
2009-12-02 16:49 . 2009-12-02 16:49 -------- d-----w- c:\program files\iSofter
2009-12-02 16:09 . 2009-12-02 16:09 -------- d-----w- c:\program files\Windows Media Components
2009-12-02 15:13 . 2009-12-02 15:13 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-12-02 15:13 . 2009-12-02 15:13 -------- d-----w- c:\program files\NOS
2009-12-02 14:38 . 2009-12-02 14:38 -------- d-----w- c:\program files\DVD Decrypter
2009-11-24 13:55 . 2009-11-24 13:55 -------- d-----w- c:\program files\MP3Gain
2009-11-19 16:14 . 2009-11-19 16:14 4732800 ----a-w- c:\documents and settings\All Users\Application Data\Flip Video\FlipShare\Updates\FirmwareExec_Windows_en-US_83.06_83.07\FlipVideoFWUpdate.exe
2009-10-29 07:45 . 2005-08-16 09:18 916480 ------w- c:\windows\system32\wininet.dll
2009-10-26 14:21 . 2008-12-07 14:59 4045527 -c--a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-10-21 05:38 . 2005-08-16 09:18 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2005-08-16 09:18 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 04:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2005-08-16 09:18 270336 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2005-08-16 09:18 149504 ----a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2005-08-16 09:18 79872 ----a-w- c:\windows\system32\raschap.dll
2007-01-22 15:57 . 2007-01-22 15:57 88 -csh--r- c:\windows\system32\6B6B789376.sys
1601-01-01 00:03 . 1601-01-01 00:03 61440 --sha-w- c:\windows\system32\fetepaze.dll
2006-05-03 09:06 . 2009-12-09 17:12 163328 --sh--r- c:\windows\system32\flvDX.dll
1601-01-01 00:03 . 1601-01-01 00:03 51712 --sha-w- c:\windows\system32\jarizasu.dll
2007-02-21 10:47 . 2009-12-09 17:12 31232 --sh--r- c:\windows\system32\msfDX.dll
2008-03-16 12:30 . 2009-12-09 17:12 216064 --sh--r- c:\windows\system32\nbDX.dll
1601-01-01 00:03 . 2010-01-07 12:13 29696 --sha-w- c:\windows\system32\smss32.exe
1601-01-01 00:03 . 1601-01-01 00:03 29696 --sha-w- c:\windows\system32\tijayefe.exe
1601-01-01 00:03 . 2010-01-07 12:13 29696 --sha-w- c:\windows\system32\winlogon32.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1724f44f-abc3-4aac-bf02-67194d09bf10}]
1601-01-01 00:03 51712 --sha-w- c:\windows\system32\jarizasu.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Internet Security 2010"="c:\program files\InternetSecurity2010\IS2010.exe" [BU]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-07-24 63048]
"smss32.exe"="c:\windows\system32\smss32.exe" [1601-01-01 29696]
"tihiwalavo"="pamepusu.dll" [BU]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{3090f905-4848-4473-ab46-7fcbde3488fa}"= "c:\windows\system32\sokogufe.dll" [BU]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"masebagey"= {3090f905-4848-4473-ab46-7fcbde3488fa} - c:\windows\system32\sokogufe.dll [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\system32\winlogon32.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2009-10-02 12:08 87352 ----a-w- c:\windows\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Event Reminder.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^EZ-DUB Finder.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\EZ-DUB Finder.lnk
backup=c:\windows\pss\EZ-DUB Finder.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^Ron^Start Menu^Programs^Startup^Event Reminder.lnk]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLSPScheduler
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OASClnt
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sscRun
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Fast Start]
2009-02-11 16:25 50472 ----a-w- c:\program files\AOL 9.5a\aol.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
2006-10-23 12:50 71216 ----a-r- c:\program files\Common Files\AOL\acs\AOLDial.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMXLauncher]
2005-10-05 08:12 94208 ----a-w- c:\program files\Dell\Media Experience\DMXLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
2005-09-29 19:01 67584 -c--a-w- c:\windows\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
2008-11-06 17:33 41264 ----a-w- c:\program files\Common Files\AOL\1237209216\ee\aolsoftware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2006-07-21 21:50 86016 -c--a-w- c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2006-12-11 02:52 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
2006-07-06 12:15 151552 -c--a-w- c:\program files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2006-07-21 21:48 98304 -c--a-w- c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2005-08-11 21:30 249856 -c--a-w- c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2005-08-11 21:30 81920 -c--a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LifeCam]
2007-05-17 21:45 279912 ----a-w- c:\program files\Microsoft LifeCam\LifeExp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2006-07-21 21:47 81920 -c--a-w- c:\windows\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-11 04:08 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
2006-07-24 15:20 282624 -c--a-w- c:\windows\stsystra.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Simple Star PhotoShow Media Manager]
2006-01-13 21:22 233472 -c--a-w- c:\progra~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\smss32.exe]
1601-01-01 00:03 29696 --sha-w- c:\windows\system32\smss32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-08-30 16:49 149280 -c--a-w- c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VX1000]
2007-04-10 21:46 709992 ----a-w- c:\windows\vVX1000.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"sdCoreService"=2 (0x2)
"sdAuxService"=2 (0x2)
"MpfService"=2 (0x2)
"MDM"=2 (0x2)
"idsvc"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\FlexiSIGN-PRO 7.0v2\\Program\\App.exe"=
"c:\\Program Files\\FlexiSIGN-PRO 7.0v2\\Program\\App2.exe"=
"c:\\Program Files\\FTP Commander\\ftpcomm.exe"=
"c:\\Program Files\\CoffeeCup Software\\Coffee.exe"=
"c:\\Program Files\\Shareaza\\Shareaza.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Common Files\\AOL\\1237209216\\ee\\aolsoftware.exe"=
"c:\\Program Files\\AOL 9.5\\waol.exe"=
"c:\\Program Files\\AOL 9.5\\shellmon.exe"=
"c:\\Program Files\\AOL 9.5\\shellrestart.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\AOL 9.5a\\waol.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Lavasoft\\Ad-Aware\\Ad-AwareAdmin.exe"=
"c:\\Program Files\\LogMeIn\\x86\\LogMeInSystray.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [12/7/2009 8:25 AM 64288]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [9/24/2009 6:17 AM 1181328]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [7/24/2008 6:46 PM 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [11/28/2008 8:38 AM 47640]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2010-01-07 c:\windows\Tasks\Ad-Aware Update (Daily 1).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 13:29]
2010-01-07 c:\windows\Tasks\Ad-Aware Update (Daily 2).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 13:29]
2010-01-07 c:\windows\Tasks\Ad-Aware Update (Daily 3).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 13:29]
2010-01-07 c:\windows\Tasks\Ad-Aware Update (Daily 4).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 13:29]
2010-01-07 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-10-01 13:29]
2009-12-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.aol.com
IE: &AOL Toolbar Search - c:\documents and settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
TCP: {C6BAEE2B-FB7C-4984-A02B-0A364CE90E18} = 193.104.110.38,4.2.2.1,71.250.0.12 71.242.0.12
DPF: {B7039D87-D648-4431-BA87-C3A04E6111DA} - hxxps://208.73.37.77:4643/vz/ssh/wodTelnetDLX.cab
FF - ProfilePath - c:\documents and settings\Ron\Application Data\Mozilla\Firefox\Profiles\fwpw46wg.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/
FF - plugin: c:\documents and settings\Ron\Application Data\Facebook\npfbplugin_1_0_0.dll
FF - plugin: c:\documents and settings\Ron\Application Data\Mozilla\Firefox\Profiles\fwpw46wg.default\extensions\
[email protected]\plugins\npRACtrl.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np_IEGetPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-mcmscsvc
SafeBoot-MCODS
MSConfigStartUp-Custom Skin Clock - c:\program files\Custom Skin Clock\Clock.exe
MSConfigStartUp-EPSON Stylus C84 Series - c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2D1.EXE
MSConfigStartUp-Google Desktop Search - c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
MSConfigStartUp-Malwarebytes Anti-Malware (reboot) - c:\program files\Malwarebytes' Anti-Malware\mbam.exe
MSConfigStartUp-popovonat - c:\windows\system32\sokogufe.dll
AddRemove-Crime Scenes SmartShapes(r) Solution - c:\aol downloads\Viseo 2000\Install\bin\Program Files\Visio\DeIsL1.isu
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-07 12:25
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1540886547-1961150650-1237119731-1006\Software\MusicMatch, Inc.\Musicmatch for WMP]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\BVRP Software\Modem Helper]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\BVRP Software, Inc\Digital Line Detect]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\BVRP Software, Inc\NetWaiting]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Microsoft\Advanced INF Setup\IEHomePageInfo\RegBackup]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\Microsoft\MediaPlayer\MLS]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Microsoft\MediaPlayer\services]
@DACL=(02 0000)
@SACL=
"NoServices"=dword:00000000
"ServiceExtra"="\"Partner=Dell&MachineID=CG88DC1\""
[HKEY_LOCAL_MACHINE\software\Symantec\CCPD-LC]
@DACL=(02 0000)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(776)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
- - - - - - - > 'explorer.exe'(296)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\AOL\ACS\AOLAcsd.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Flip Video\FlipShare\FlipShareService.exe
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\LogMeIn\x86\RaMaint.exe
c:\program files\LogMeIn\x86\LogMeIn.exe
c:\program files\LogMeIn\x86\LMIGuardian.exe
c:\program files\LogMeIn\x86\LMIGuardian.exe
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\program files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
.
**************************************************************************
.
Completion time: 2010-01-07 12:36:08 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-07 17:36
Pre-Run: 204,526,497,792 bytes free
Post-Run: 204,263,866,368 bytes free
- - End Of File - - B161D956FA75DDFBA1E9E65A5786250C