Here are the latest logs:
ComboFix 09-01-19.01 - larryb 2009-01-19 13:10:55.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.451 [GMT -5:00]
Running from: c:\documents and settings\larryb\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\larryb\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1296 [VPS 090118-0] *On-access scanning disabled* (Updated)
AV: BitDefender Antivirus *On-access scanning enabled* (Updated)
FW: BitDefender Firewall *disabled*
* Created a new restore point
FILE ::
c:\windows\Tasks\uaevfwsi.job
c:\windows\ubuyosegefimif.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Webroot
c:\documents and settings\All Users\Application Data\Webroot\Database\WRConsumerService.db
c:\documents and settings\All Users\Application Data\Webroot\Logs\WRConsumerService.exe_000021.log
c:\documents and settings\All Users\Application Data\Webroot\Logs\WRConsumerService.exe_000022.log
c:\documents and settings\All Users\Application Data\Webroot\Logs\WRConsumerService.exe_000023.log
c:\documents and settings\All Users\Application Data\Webroot\Logs\WRConsumerService.exe_000024.log
c:\documents and settings\All Users\Application Data\Webroot\Logs\WRConsumerService.exe_000025.log
c:\documents and settings\All Users\Application Data\Webroot\Logs\WRConsumerService.exe_000026.log
c:\documents and settings\All Users\Application Data\Webroot\Logs\WRConsumerService.exe_000027.log
c:\documents and settings\All Users\Application Data\Webroot\Logs\WRConsumerService.exe_000028.log
c:\documents and settings\All Users\Application Data\Webroot\Logs\WRConsumerService.exe_000029.log
c:\documents and settings\All Users\Application Data\Webroot\Logs\WRConsumerService.exe_000030.log
c:\documents and settings\All Users\Application Data\Webroot\Logs\WRConsumerService.exe_000031.log
c:\documents and settings\All Users\Application Data\Webroot\Logs\WRConsumerService.exe_000032.log
c:\documents and settings\All Users\Application Data\Webroot\Logs\WRConsumerService.exe_000033.log
c:\documents and settings\All Users\Application Data\Webroot\Logs\WRConsumerService.exe_000034.log
c:\documents and settings\All Users\Application Data\Webroot\Logs\WRConsumerService.exe_000035.log
c:\documents and settings\All Users\Application Data\Webroot\Logs\WRConsumerService.exe_000036.log
c:\documents and settings\All Users\Application Data\Webroot\Logs\WRConsumerService.exe_000037.log
c:\documents and settings\All Users\Application Data\Webroot\Logs\WRConsumerService.exe_000038.log
c:\documents and settings\All Users\Application Data\Webroot\Logs\WRConsumerService.exe_000039.log
c:\documents and settings\All Users\Application Data\Webroot\Logs\WRConsumerService.exe_000040.log
c:\documents and settings\All Users\Application Data\Webroot\Logs\WRConsumerService.exe_000041.log
c:\documents and settings\All Users\Application Data\Webroot\Logs\WRConsumerService.exe_000042.log
c:\documents and settings\All Users\Application Data\Webroot\Logs\WRConsumerService.exe_000043.log
c:\documents and settings\All Users\Application Data\Webroot\Logs\WRConsumerService.exe_000044.log
c:\documents and settings\All Users\Application Data\Webroot\Logs\WRConsumerService.exe_000045.log
c:\documents and settings\All Users\Application Data\Webroot\Logs\WRConsumerService.exe_000046.log
c:\documents and settings\All Users\Application Data\Webroot\Logs\WRConsumerService.exe_000047.log
c:\documents and settings\All Users\Application Data\Webroot\Logs\WRConsumerService.exe_000048.log
c:\documents and settings\All Users\Application Data\Webroot\Logs\WRConsumerService.exe_000049.log
c:\documents and settings\All Users\Application Data\Webroot\Logs\WRConsumerService.exe_000050.log
c:\documents and settings\All Users\Application Data\Webroot\Logs\WRConsumerService.exe_000051.log
c:\documents and settings\All Users\Application Data\Webroot\Logs\WRConsumerService.exe_000052.log
c:\documents and settings\All Users\Application Data\Webroot\Logs\WRConsumerService.exe_000053.log
c:\documents and settings\All Users\Application Data\Webroot\Logs\WRConsumerService.exe_000054.log
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\install.dat
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Plugins.cfg
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Plugins.mst
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01012009093345.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01012009151522.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01022009154636.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01032009185329.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01032009213138.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01032009214544.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01042009095750.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01052009174739.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01062009171654.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01062009172332.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01062009174425.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01062009181435.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01062009212930.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01062009213811.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01062009214338.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01062009220054.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01062009220616.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01062009222517.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01062009224211.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01072009171223.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01072009171633.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01072009180220.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01072009180925.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01072009182704.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01072009183829.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01072009185305.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01072009185749.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01072009190401.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01072009191117.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01072009203809.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01072009204459.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01072009205410.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01072009210721.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01072009211257.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01072009213310.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01072009213743.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01082009165012.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-01092009212642.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-12312008232525.xml
c:\documents and settings\All Users\Application Data\Webroot\Spy Sweeper\Reports\ml-12312008233652.xml
c:\documents and settings\larryb\Application Data\Webroot
c:\documents and settings\me\Application Data\Webroot
c:\program files\Webroot
c:\program files\Webroot\WebrootSecurity\Backup\CtxMenu_1_0_0_10.dll
c:\program files\Webroot\WebrootSecurity\Backup\dbconfig.mdb
c:\program files\Webroot\WebrootSecurity\Backup\error.htm
c:\program files\Webroot\WebrootSecurity\Backup\gdiplus.dll
c:\program files\Webroot\WebrootSecurity\Backup\HLSC10.dll
c:\program files\Webroot\WebrootSecurity\Backup\images\32bit.ico
c:\program files\Webroot\WebrootSecurity\Backup\images\8bit_blue.ico
c:\program files\Webroot\WebrootSecurity\Backup\images\8bit_gray.ico
c:\program files\Webroot\WebrootSecurity\Backup\images\AgentHeader.jpg
c:\program files\Webroot\WebrootSecurity\Backup\images\ClassicViewLogo.jpg
c:\program files\Webroot\WebrootSecurity\Backup\images\ctxmenu.bmp
c:\program files\Webroot\WebrootSecurity\Backup\images\curve.gif
c:\program files\Webroot\WebrootSecurity\Backup\images\gray32bit.ico
c:\program files\Webroot\WebrootSecurity\Backup\images\localbackup.ico
c:\program files\Webroot\WebrootSecurity\Backup\images\localbackup_failed.ico
c:\program files\Webroot\WebrootSecurity\Backup\images\localbackup_gray.ico
c:\program files\Webroot\WebrootSecurity\Backup\images\LocalBackupBackground.jpg
c:\program files\Webroot\WebrootSecurity\Backup\images\MessageScreen.jpg
c:\program files\Webroot\WebrootSecurity\Backup\images\Refresh.png
c:\program files\Webroot\WebrootSecurity\Backup\images\SOS.ico
c:\program files\Webroot\WebrootSecurity\Backup\images\SOSico.ico
c:\program files\Webroot\WebrootSecurity\Backup\images\Thumbs.db
c:\program files\Webroot\WebrootSecurity\Backup\images\WaitAjaxBig.gif
c:\program files\Webroot\WebrootSecurity\Backup\images\WaitAjaxSmall.gif
c:\program files\Webroot\WebrootSecurity\Backup\images\Webroot_Wizard\Background.jpg
c:\program files\Webroot\WebrootSecurity\Backup\images\Webroot_Wizard\BackupLocally_Active.gif
c:\program files\Webroot\WebrootSecurity\Backup\images\Webroot_Wizard\BackupLocally_Normal.gif
c:\program files\Webroot\WebrootSecurity\Backup\images\Webroot_Wizard\BackupOnline_Active.gif
c:\program files\Webroot\WebrootSecurity\Backup\images\Webroot_Wizard\BackupOnline_Normal.gif
c:\program files\Webroot\WebrootSecurity\Backup\images\Webroot_Wizard\ChangePassword_Active.gif
c:\program files\Webroot\WebrootSecurity\Backup\images\Webroot_Wizard\ChangePassword_Normal.gif
c:\program files\Webroot\WebrootSecurity\Backup\images\Webroot_Wizard\Close_Active.jpg
c:\program files\Webroot\WebrootSecurity\Backup\images\Webroot_Wizard\Close_Normal.jpg
c:\program files\Webroot\WebrootSecurity\Backup\images\Webroot_Wizard\Help_Active.gif
c:\program files\Webroot\WebrootSecurity\Backup\images\Webroot_Wizard\Help_Normal.gif
c:\program files\Webroot\WebrootSecurity\Backup\images\Webroot_Wizard\RestoreLocally_Active.gif
c:\program files\Webroot\WebrootSecurity\Backup\images\Webroot_Wizard\RestoreLocally_Normal.gif
c:\program files\Webroot\WebrootSecurity\Backup\images\Webroot_Wizard\RestoreOnline_Active.gif
c:\program files\Webroot\WebrootSecurity\Backup\images\Webroot_Wizard\RestoreOnline_Normal.gif
c:\program files\Webroot\WebrootSecurity\Backup\images\Webroot_Wizard\SwitchUser_Active.gif
c:\program files\Webroot\WebrootSecurity\Backup\images\Webroot_Wizard\SwitchUser_Normal.gif
c:\program files\Webroot\WebrootSecurity\Backup\images\Webroot_Wizard\Thumbs.db
c:\program files\Webroot\WebrootSecurity\Backup\images\Webroot_Wizard\Wizard_Background.jpg
c:\program files\Webroot\WebrootSecurity\Backup\images\Webroot_Wizard\WizardButton_Active.png
c:\program files\Webroot\WebrootSecurity\Backup\images\Webroot_Wizard\WizardButton_Disabled.png
c:\program files\Webroot\WebrootSecurity\Backup\images\Webroot_Wizard\WizardButton_Normal.png
c:\program files\Webroot\WebrootSecurity\Backup\images\Wizards\Active.png
c:\program files\Webroot\WebrootSecurity\Backup\images\Wizards\AdvancedButton_Active.jpg
c:\program files\Webroot\WebrootSecurity\Backup\images\Wizards\AdvancedButton_Normal.jpg
c:\program files\Webroot\WebrootSecurity\Backup\images\Wizards\Background.jpg
c:\program files\Webroot\WebrootSecurity\Backup\images\Wizards\Cancel_Active.png
c:\program files\Webroot\WebrootSecurity\Backup\images\Wizards\Cancel_Normal.png
c:\program files\Webroot\WebrootSecurity\Backup\images\Wizards\ClassicViewButton_Active.jpg
c:\program files\Webroot\WebrootSecurity\Backup\images\Wizards\ClassicViewButton_Normal.jpg
c:\program files\Webroot\WebrootSecurity\Backup\images\Wizards\Finish_Active.png
c:\program files\Webroot\WebrootSecurity\Backup\images\Wizards\Finish_Normal.png
c:\program files\Webroot\WebrootSecurity\Backup\images\Wizards\LaunchForm_Background.png
c:\program files\Webroot\WebrootSecurity\Backup\images\Wizards\LaunchForm_Close_Active.gif
c:\program files\Webroot\WebrootSecurity\Backup\images\Wizards\LaunchForm_Close_Normal.gif
c:\program files\Webroot\WebrootSecurity\Backup\images\Wizards\LaunchForm_Logo.png
c:\program files\Webroot\WebrootSecurity\Backup\images\Wizards\LocalBackup_Active.png
c:\program files\Webroot\WebrootSecurity\Backup\images\Wizards\LocalBackup_Normal.png
c:\program files\Webroot\WebrootSecurity\Backup\images\Wizards\LocalRestore_Active.png
c:\program files\Webroot\WebrootSecurity\Backup\images\Wizards\LocalRestore_Normal.png
c:\program files\Webroot\WebrootSecurity\Backup\images\Wizards\Logo.png
c:\program files\Webroot\WebrootSecurity\Backup\images\Wizards\MessageField_Active.png
c:\program files\Webroot\WebrootSecurity\Backup\images\Wizards\MessageField_Normal.png
c:\program files\Webroot\WebrootSecurity\Backup\images\Wizards\Next_Active.png
c:\program files\Webroot\WebrootSecurity\Backup\images\Wizards\Next_Normal.png
c:\program files\Webroot\WebrootSecurity\Backup\images\Wizards\Normal.png
c:\program files\Webroot\WebrootSecurity\Backup\images\Wizards\OnlineBackup_Active.png
c:\program files\Webroot\WebrootSecurity\Backup\images\Wizards\OnlineBackup_Normal.png
c:\program files\Webroot\WebrootSecurity\Backup\images\Wizards\OnlineRestore_Active.png
c:\program files\Webroot\WebrootSecurity\Backup\images\Wizards\OnlineRestore_Normal.png
c:\program files\Webroot\WebrootSecurity\Backup\images\Wizards\Prev_Active.png
c:\program files\Webroot\WebrootSecurity\Backup\images\Wizards\Prev_Disable.png
c:\program files\Webroot\WebrootSecurity\Backup\images\Wizards\Prev_Normal.png
c:\program files\Webroot\WebrootSecurity\Backup\images\Wizards\Thumbs.db
c:\program files\Webroot\WebrootSecurity\Backup\Interop.AXUTILITIESLib.dll
c:\program files\Webroot\WebrootSecurity\Backup\Interop.LocalBackupLib.dll
c:\program files\Webroot\WebrootSecurity\Backup\Interop.Shell32.dll
c:\program files\Webroot\WebrootSecurity\Backup\Interop.VSBackupVista.dll
c:\program files\Webroot\WebrootSecurity\Backup\Interop.VSS.dll
c:\program files\Webroot\WebrootSecurity\Backup\Interop.VSS2003.dll
c:\program files\Webroot\WebrootSecurity\Backup\Interop.XceedEncryptionLib.dll
c:\program files\Webroot\WebrootSecurity\Backup\IsExpCmdBld.exe
c:\program files\Webroot\WebrootSecurity\Backup\LiteApi.dll
c:\program files\Webroot\WebrootSecurity\Backup\LocalBackupContainer.dll
c:\program files\Webroot\WebrootSecurity\Backup\Logs\AxUtilities 2008-12-31 23-18-06.log
c:\program files\Webroot\WebrootSecurity\Backup\Logs\BackupEngine 2008-12-31 23-18-09.log
c:\program files\Webroot\WebrootSecurity\Backup\Logs\CtxMenu 2009-01-01 02-34-08.log
c:\program files\Webroot\WebrootSecurity\Backup\Logs\CtxMenu 2009-01-01 13-22-39.log
c:\program files\Webroot\WebrootSecurity\Backup\Logs\CtxMenu 2009-01-01 15-19-34.log
c:\program files\Webroot\WebrootSecurity\Backup\Logs\CtxMenu 2009-01-02 22-40-42.log
c:\program files\Webroot\WebrootSecurity\Backup\Logs\CtxMenu 2009-01-03 20-53-32.log
c:\program files\Webroot\WebrootSecurity\Backup\Logs\CtxMenu 2009-01-03 21-36-27.log
c:\program files\Webroot\WebrootSecurity\Backup\Logs\CtxMenu 2009-01-06 21-50-33.log
c:\program files\Webroot\WebrootSecurity\Backup\Logs\CtxMenu 2009-01-06 22-46-24.log
c:\program files\Webroot\WebrootSecurity\Backup\Logs\CtxMenu 2009-01-07 18-32-54.log
c:\program files\Webroot\WebrootSecurity\Backup\Logs\CtxMenu 2009-01-07 18-43-43.log
c:\program files\Webroot\WebrootSecurity\Backup\Logs\CtxMenu 2009-01-07 19-01-31.log
c:\program files\Webroot\WebrootSecurity\Backup\Logs\CtxMenu 2009-01-07 20-58-43.log
c:\program files\Webroot\WebrootSecurity\Backup\Logs\CtxMenu 2009-01-07 21-30-38.log
c:\program files\Webroot\WebrootSecurity\Backup\Logs\CtxMenu 2009-01-12 21-47-02.log
c:\program files\Webroot\WebrootSecurity\Backup\Logs\CtxMenu 2009-01-18 13-37-51.log
c:\program files\Webroot\WebrootSecurity\Backup\Logs\CtxMenu 2009-01-18 13-55-38.log
c:\program files\Webroot\WebrootSecurity\Backup\Logs\CtxMenu 2009-01-18 18-38-21.log
c:\program files\Webroot\WebrootSecurity\Backup\mgwz.dll
c:\program files\Webroot\WebrootSecurity\Backup\mscomct2.ocx
c:\program files\Webroot\WebrootSecurity\Backup\MSCOMCTL.OCX
c:\program files\Webroot\WebrootSecurity\Backup\mscorsn.dll
c:\program files\Webroot\WebrootSecurity\Backup\msjro.dll
c:\program files\Webroot\WebrootSecurity\Backup\MSSMO.dll
c:\program files\Webroot\WebrootSecurity\Backup\msvcp71.dll
c:\program files\Webroot\WebrootSecurity\Backup\msvcr70.dll
c:\program files\Webroot\WebrootSecurity\Backup\msvcr71d.dll
c:\program files\Webroot\WebrootSecurity\Backup\ntsvc.ocx
c:\program files\Webroot\WebrootSecurity\Backup\OLEGUIDS.TLB
c:\program files\Webroot\WebrootSecurity\Backup\package_meta_data.mdb
c:\program files\Webroot\WebrootSecurity\Backup\Recover.htm
c:\program files\Webroot\WebrootSecurity\Backup\RegisterCOM.bat
c:\program files\Webroot\WebrootSecurity\Backup\RegisterContext.bat
c:\program files\Webroot\WebrootSecurity\Backup\RegisterNET1.1.bat
c:\program files\Webroot\WebrootSecurity\Backup\RegisterNET2.0.bat
c:\program files\Webroot\WebrootSecurity\Backup\RegistryHive.reg
c:\program files\Webroot\WebrootSecurity\Backup\resources\backupReportEmailTemplate.html
c:\program files\Webroot\WebrootSecurity\Backup\resources\emptybg.jpg
c:\program files\Webroot\WebrootSecurity\Backup\resources\homescreen.jpg
c:\program files\Webroot\WebrootSecurity\Backup\resources\sosmessagescreen.jpg
c:\program files\Webroot\WebrootSecurity\Backup\resources\standard.jpg
c:\program files\Webroot\WebrootSecurity\Backup\resources\Thumbs.db
c:\program files\Webroot\WebrootSecurity\Backup\resources\welcomebg.jpg
c:\program files\Webroot\WebrootSecurity\Backup\resources\wsdl\auth.wsdl
c:\program files\Webroot\WebrootSecurity\Backup\resources\wsdl\bulkWebMethods.wsdl
c:\program files\Webroot\WebrootSecurity\Backup\resources\wsdl\client.wsdl
c:\program files\Webroot\WebrootSecurity\Backup\resources\wsdl\functions.wsdl
c:\program files\Webroot\WebrootSecurity\Backup\resources\wsdl\utilities.wsdl
c:\program files\Webroot\WebrootSecurity\Backup\resources\wsdl\wsconfig.wsdl
c:\program files\Webroot\WebrootSecurity\Backup\resources\wsdl\wsparamlist1.wsdl
c:\program files\Webroot\WebrootSecurity\Backup\resources\wsdl\wsparamlist2.wsdl
c:\program files\Webroot\WebrootSecurity\Backup\resources\wsdl\wsparamlist3.wsdl
c:\program files\Webroot\WebrootSecurity\Backup\resources\wsdl\wsparamlist4.wsdl
c:\program files\Webroot\WebrootSecurity\Backup\resources\wsdl\wsprocess1.wsdl
c:\program files\Webroot\WebrootSecurity\Backup\resources\wsdl\wsprocess2.wsdl
c:\program files\Webroot\WebrootSecurity\Backup\resources\wsdl\wsprotect.wsdl
c:\program files\Webroot\WebrootSecurity\Backup\resources\wsdl\wsrecoverdown.wsdl
c:\program files\Webroot\WebrootSecurity\Backup\resources\wsdl\wsrecovervb.wsdl
c:\program files\Webroot\WebrootSecurity\Backup\resources\wsdl\wsstrrecovervb.wsdl
c:\program files\Webroot\WebrootSecurity\Backup\rvstyle.css
c:\program files\Webroot\WebrootSecurity\Backup\saxfile.dll
c:\program files\Webroot\WebrootSecurity\Backup\SMButton.ocx
c:\program files\Webroot\WebrootSecurity\Backup\sosbutton.ocx
c:\program files\Webroot\WebrootSecurity\Backup\SOSClientApi.dll
c:\program files\Webroot\WebrootSecurity\Backup\SOSClientApi.tlb
c:\program files\Webroot\WebrootSecurity\Backup\sosCompress.dll
c:\program files\Webroot\WebrootSecurity\Backup\SOSControls.dll
c:\program files\Webroot\WebrootSecurity\Backup\sosdelta.dll
c:\program files\Webroot\WebrootSecurity\Backup\SOSLibrary.dll
c:\program files\Webroot\WebrootSecurity\Backup\SosLocalBackup.exe
c:\program files\Webroot\WebrootSecurity\Backup\sosonlinebackupservice.exe
c:\program files\Webroot\WebrootSecurity\Backup\SOSOnlineWizards.dll
c:\program files\Webroot\WebrootSecurity\Backup\SOSTools.dll
c:\program files\Webroot\WebrootSecurity\Backup\SOSTreeViewControls.dll
c:\program files\Webroot\WebrootSecurity\Backup\SOSUninstall.exe
c:\program files\Webroot\WebrootSecurity\Backup\sosuploadagent.exe
c:\program files\Webroot\WebrootSecurity\Backup\SStorage.exe
c:\program files\Webroot\WebrootSecurity\Backup\SStorage.exe.config
c:\program files\Webroot\WebrootSecurity\Backup\SStorageLib.dll
c:\program files\Webroot\WebrootSecurity\Backup\SSubTmr6.dll
c:\program files\Webroot\WebrootSecurity\Backup\TaskScheduler.dll
c:\program files\Webroot\WebrootSecurity\Backup\TaskScheduler.tlb
c:\program files\Webroot\WebrootSecurity\Backup\UnregisterCOM.bat
c:\program files\Webroot\WebrootSecurity\Backup\UnregisterNET1.1.bat
c:\program files\Webroot\WebrootSecurity\Backup\UnregisterNET2.0.bat
c:\program files\Webroot\WebrootSecurity\Backup\UnregistryHive.reg
c:\program files\Webroot\WebrootSecurity\Backup\UploadAgentApi.dll
c:\program files\Webroot\WebrootSecurity\Backup\UploadAgentApi.tlb
c:\program files\Webroot\WebrootSecurity\Backup\v2_template.mdb
c:\program files\Webroot\WebrootSecurity\Backup\VLBtnBar.ocx
c:\program files\Webroot\WebrootSecurity\Backup\VlUtils.dll
c:\program files\Webroot\WebrootSecurity\Backup\VSBackupNet.dll
c:\program files\Webroot\WebrootSecurity\Backup\VSBackupNet.tlb
c:\program files\Webroot\WebrootSecurity\Backup\VSBackupVista.dll
c:\program files\Webroot\WebrootSecurity\Backup\WinService.dll
c:\program files\Webroot\WebrootSecurity\Backup\WiseApi.dll
c:\program files\Webroot\WebrootSecurity\Backup\WiseApi.tlb
c:\program files\Webroot\WebrootSecurity\Backup\wsdlgen3.dll
c:\program files\Webroot\WebrootSecurity\Backup\Xceed.Compression.dll
c:\program files\Webroot\WebrootSecurity\Backup\Xceed.Compression.Formats.dll
c:\program files\Webroot\WebrootSecurity\Backup\Xceed.FileSystem.dll
c:\program files\Webroot\WebrootSecurity\Backup\Xceed.Zip.dll
c:\program files\Webroot\WebrootSecurity\Backup\XceedCry.dll
c:\program files\Webroot\WebrootSecurity\Backup\XceedZip.dll
c:\program files\Webroot\WebrootSecurity\Backup\xd.exe
c:\program files\Webroot\WebrootSecurity\Backup\xfclient.dll
c:\program files\Webroot\WebrootSecurity\Backup\XFileNet.dll
c:\program files\Webroot\WebrootSecurity\Backup\XFileNet.tlb
c:\program files\Webroot\WebrootSecurity\Backup\XHSC10.dll
c:\program files\Webroot\WebrootSecurity\Backup\XPExplorerBar.dll
c:\windows\Tasks\uaevfwsi.job
c:\windows\ubuyosegefimif.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_WEBROOTSPYSWEEPERSERVICE
-------\Legacy_WRCONSUMERSERVICE
-------\Service_WebrootSpySweeperService
-------\Service_WRConsumerService
((((((((((((((((((((((((( Files Created from 2008-12-19 to 2009-01-19 )))))))))))))))))))))))))))))))
.
2009-01-18 14:08 . 2009-01-18 14:08 <DIR> d-------- c:\documents and settings\larryb\Application Data\Aim
2009-01-18 14:03 . 2009-01-18 14:03 <DIR> d-------- c:\documents and settings\larryb\Application Data\HP
2009-01-11 21:55 . 2009-01-11 22:38 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2009-01-11 21:55 . 2009-01-11 23:23 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-11 21:47 . 2004-08-04 00:56 116,224 --a------ c:\windows\system32\dllcache\xrxwiadr.dll
2009-01-11 21:47 . 2001-08-17 22:37 27,648 --a------ c:\windows\system32\dllcache\xrxftplt.exe
2009-01-11 21:47 . 2001-08-17 22:36 23,040 --a------ c:\windows\system32\dllcache\xrxwbtmp.dll
2009-01-11 21:47 . 2001-08-17 22:36 17,408 --a------ c:\windows\system32\dllcache\xrxscnui.dll
2009-01-11 21:47 . 2001-08-17 22:37 4,608 --a------ c:\windows\system32\dllcache\xrxflnch.exe
2009-01-11 21:46 . 2001-08-17 13:28 771,581 --a------ c:\windows\system32\dllcache\winacisa.sys
2009-01-11 21:46 . 2004-08-03 22:31 154,624 --a------ c:\windows\system32\dllcache\wlluc48.sys
2009-01-11 21:46 . 2001-08-17 22:37 99,865 --a------ c:\windows\system32\dllcache\xlog.exe
2009-01-11 21:46 . 2001-08-17 22:36 53,760 --a------ c:\windows\system32\dllcache\wiamsmud.dll
2009-01-11 21:46 . 2001-08-17 12:12 34,890 --a------ c:\windows\system32\dllcache\wlandrv2.sys
2009-01-11 21:46 . 2004-08-03 22:29 19,455 --a------ c:\windows\system32\dllcache\wvchntxx.sys
2009-01-11 21:46 . 2001-08-17 12:11 16,970 --a------ c:\windows\system32\dllcache\xem336n5.sys
2009-01-11 21:46 . 2004-08-03 22:29 12,063 --a------ c:\windows\system32\dllcache\wsiintxx.sys
2009-01-11 21:46 . 2004-08-03 23:07 8,832 --a------ c:\windows\system32\dllcache\wmiacpi.sys
2009-01-11 21:46 . 2004-08-04 00:56 8,192 --a------ c:\windows\system32\dllcache\wshirda.dll
2009-01-11 21:44 . 2001-08-17 13:28 794,654 --a------ c:\windows\system32\dllcache\usr1801.sys
2009-01-11 21:43 . 2001-08-17 22:36 525,568 --a------ c:\windows\system32\dllcache\tridxp.dll
2009-01-11 21:42 . 2001-08-17 14:56 315,520 --a------ c:\windows\system32\dllcache\trid3d.dll
2009-01-11 21:41 . 2001-08-17 12:18 285,760 --a------ c:\windows\system32\dllcache\stlnata.sys
2009-01-11 21:40 . 2004-08-04 05:00 456,704 --a------ c:\windows\system32\dllcache\smtpsvc.dll
2009-01-11 21:39 . 2004-08-03 22:41 404,990 --a------ c:\windows\system32\dllcache\slntamr.sys
2009-01-11 21:38 . 2001-08-17 22:36 386,560 --a------ c:\windows\system32\dllcache\sgiul50.dll
2009-01-11 21:37 . 2001-08-17 22:36 495,616 --a------ c:\windows\system32\dllcache\sblfx.dll
2009-01-11 21:36 . 2004-08-04 00:56 397,056 --a------ c:\windows\system32\dllcache\s3gnb.dll
2009-01-11 21:35 . 2001-08-17 13:28 899,146 --a------ c:\windows\system32\dllcache\r2mdkxga.sys
2009-01-11 21:32 . 2001-08-17 14:04 173,696 --a------ c:\windows\system32\dllcache\philcam2.sys
2009-01-11 21:32 . 2001-08-17 22:36 121,344 --a------ c:\windows\system32\dllcache\phvfwext.dll
2009-01-11 21:32 . 2001-08-17 14:04 92,416 --a------ c:\windows\system32\dllcache\phildec.sys
2009-01-11 21:32 . 2001-08-17 14:04 75,776 --a------ c:\windows\system32\dllcache\philcam1.sys
2009-01-11 21:32 . 2001-08-17 14:07 19,840 --a------ c:\windows\system32\dllcache\philtune.sys
2009-01-11 21:30 . 2001-08-17 12:50 198,144 --a------ c:\windows\system32\dllcache\nv3.sys
2009-01-11 21:29 . 2004-08-03 22:31 132,695 --a------ c:\windows\system32\dllcache\netwlan5.sys
2009-01-11 21:28 . 2004-08-04 00:56 1,737,856 --a------ c:\windows\system32\dllcache\mtxparhd.dll
2009-01-11 21:27 . 2001-08-17 12:50 320,384 --a------ c:\windows\system32\dllcache\mgaum.sys
2009-01-11 21:26 . 2001-08-17 13:28 802,683 --a------ c:\windows\system32\dllcache\ltsm.sys
2009-01-11 21:25 . 2001-08-17 22:36 372,824 --a------ c:\windows\system32\dllcache\iconf32.dll
2009-01-11 21:24 . 2004-08-03 22:41 1,041,536 --a------ c:\windows\system32\dllcache\hsfdpsp2.sys
2009-01-11 21:23 . 2001-08-17 13:28 542,879 --a------ c:\windows\system32\dllcache\hsf_msft.sys
2009-01-11 21:22 . 2001-08-17 14:56 1,733,120 --a------ c:\windows\system32\dllcache\g400d.dll
2009-01-11 21:21 . 2001-08-17 13:28 595,647 --a------ c:\windows\system32\dllcache\es56cvmp.sys
2009-01-11 21:20 . 2001-08-17 13:28 634,134 --a------ c:\windows\system32\dllcache\el656ct5.sys
2009-01-11 21:19 . 2001-08-17 12:14 952,007 --a------ c:\windows\system32\dllcache\diwan.sys
2009-01-11 21:18 . 2001-08-17 12:13 980,034 --a------ c:\windows\system32\dllcache\cicap.sys
2009-01-11 21:17 . 2001-08-17 13:28 871,388 --a------ c:\windows\system32\dllcache\bcmdm.sys
2009-01-11 21:16 . 2004-08-04 00:56 870,784 --a------ c:\windows\system32\dllcache\ati3d1ag.dll
2009-01-11 21:15 . 2004-08-04 05:00 2,134,528 --a------ c:\windows\system32\dllcache\smtpsnap.dll
2009-01-10 17:13 . 2004-08-04 05:00 24,576 --a------ c:\windows\system32\userinit.exe
2009-01-10 17:13 . 2004-08-04 05:00 24,576 --a------ c:\windows\system32\dllcache\userinit.exe
2009-01-10 16:23 . 2009-01-18 14:04 <DIR> d--h----- c:\documents and settings\larryb\Application Data\GTek
2009-01-10 15:47 . 2006-08-02 21:51 <DIR> d-------- c:\documents and settings\larryb\Application Data\Intel
2009-01-10 15:47 . 2006-05-16 21:56 <DIR> d-------- c:\documents and settings\larryb\Application Data\ATI
2009-01-10 15:46 . 2009-01-19 11:26 <DIR> d-------- c:\documents and settings\larryb
2009-01-10 13:32 . 2009-01-10 13:32 <DIR> d-------- c:\program files\Alwil Software
2009-01-07 21:52 . 2009-01-07 21:52 <DIR> d-------- c:\program files\Trend Micro
2009-01-07 21:49 . 2009-01-07 21:49 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2009-01-06 18:15 . 2009-01-06 18:15 850 --a------ c:\windows\system32\ProductTweaks.xml
2009-01-06 18:15 . 2009-01-06 18:15 385 --a------ c:\windows\system32\user_gensett.xml
2009-01-06 18:04 . 2009-01-06 18:04 <DIR> d-------- c:\program files\BitDefender
2009-01-06 18:02 . 2009-01-13 19:33 <DIR> d-------- c:\program files\Common Files\BitDefender
2008-12-31 23:16 . 2008-11-13 17:11 1,553,272 --a------ c:\windows\WRSetup.dll
2008-12-31 23:13 . 2008-12-31 23:13 164 --a------ C:\install.dat
2008-12-31 22:53 . 2008-12-31 22:53 <DIR> d-------- c:\windows\system32\config\systemprofile\Application Data\s_4610_fHx8fHx8fDEyNDMzOTE2NzR8_
2008-12-26 10:08 . 2008-12-31 09:54 <DIR> d-------- c:\program files\TLC
2008-12-26 10:08 . 2008-12-31 09:54 303 --a------ c:\windows\EReg077.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-10 23:24 --------- d-----w c:\program files\Steam
2009-01-06 22:43 --------- d-----w c:\program files\McAfee.com
2009-01-06 22:43 --------- d-----w c:\documents and settings\All Users\Application Data\McAfee
2008-12-27 22:13 --------- d-----w c:\program files\Google
2008-12-27 21:06 --------- d-----w c:\documents and settings\me\Application Data\Move Networks
2008-12-19 03:23 --------- d-----w c:\documents and settings\me\Application Data\AdobeUM
2008-12-02 23:25 --------- d-----w c:\documents and settings\me\Application Data\Ventrilo
2008-12-01 23:59 --------- d-----w c:\program files\iTunes
2008-12-01 23:59 --------- d-----w c:\program files\iPod
2008-12-01 23:59 --------- d-----w c:\program files\Common Files\Apple
2008-12-01 23:59 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-01 23:56 --------- d-----w c:\program files\QuickTime
2006-05-25 18:37 56 --sh--r c:\windows\system32\
01C65777F2.sys
2006-05-23 21:23 88 -csh--r c:\windows\system32\F27757C601.sys
2006-05-25 18:37 3,766 -csha-w c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( snapshot@2009-01-19_10.25.37.75 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-01-19 18:16:12 16,384 ----atw c:\windows\temp\Perflib_Perfdata_cc.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-22 68856]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"AIM"="c:\program files\AIM\aim.exe" [2005-08-05 67160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShowLOMControl"="" [X]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-11-29 761947]
"SunJavaUpdateSched"="c:\program files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 32881]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2006-05-16 26112]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-11 290816]
"mxomssmenu"="c:\program files\Maxtor\OneTouch Status\maxmenumgr.exe" [2005-10-17 81920]
"MaxtorOneTouch"="c:\program files\Maxtor\OneTouch\utils\Onetouch.exe" [2006-03-27 712704]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-07-19 221184]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-06-08 458752]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"IPHSend"="c:\program files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 124520]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-05-01 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-05-01 602182]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2005-03-23 217088]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"HostManager"="c:\program files\Common Files\AOL\1148442532\ee\AOLSoftware.exe" [2006-04-20 50792]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-09 49152]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2005-05-31 122941]
"ClubBox"="c:\program files\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2005-08-12 45056]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"SigmatelSysTrayApp"="stsystra.exe" [2005-11-16 c:\windows\stsystra.exe]
c:\documents and settings\me\Start Menu\Programs\Startup\
MEMonitor.lnk - c:\program files\Verizon Wireless\V CAST Music Manager\MEMonitor.exe [2007-11-27 947544]
Shortcut to Free Sticky Notes.LNK - c:\program files\Free Sticky Notes\freenote.exe [2002-06-20 49152]
Yahoo! Widgets.lnk - c:\program files\Yahoo!\Widgets\YahooWidgets.exe [2007-12-11 3746856]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2005-11-18 1724416]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-05-16 24576]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 806912]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
--a------ 2008-11-26 12:18 81000 c:\progra~1\ALWILS~1\Avast4\ashDisp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"VSSERV"=2 (0x2)
"Arrakis3"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1148442532\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1148442532\\ee\\aim6.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Documents and Settings\\me\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\me\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\drivers\ssfs0bbc.sys [2008-11-12 29808]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-01-10 111184]
R4 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-01-10 20560]
R4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-03-28 24652]
S3 gwiopm;gwiopm;\??\d:\gwiopm.sys --> d:\gwiopm.sys [?]
S4 BDVEDISK;BDVEDISK;\??\c:\program files\BitDefender\BitDefender 2009\BDVEDISK.sys --> c:\program files\BitDefender\BitDefender 2009\BDVEDISK.sys [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
2009-01-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2009-01-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1846488606-3996386486-3940884211-1005.job
- c:\documents and settings\me\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-18 23:32]
.
- - - - ORPHANS REMOVED - - - -
ShellIconOverlayIdentifiers-{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD} - c:\program files\Webroot\WebrootSecurity\Backup\CtxMenu_1_0_0_10.dll
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.dell.com
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
IE: {{d81ca86b-ef63-42af-bee3-4502d9a03c2d} -
http://wwws.musicmatch.com/mmz/openWebRadio.html
FF - ProfilePath - c:\documents and settings\larryb\Application Data\Mozilla\Firefox\Profiles\
06wmbhih.default\
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npnul32.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\NPOFFICE.DLL
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npqtplugin.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npqtplugin2.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npqtplugin3.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npqtplugin4.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npqtplugin5.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npqtplugin6.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npqtplugin7.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava11.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava12.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava13.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava14.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava32.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJPI142_03.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-19 13:18:00
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(976)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\WLKEEPER.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe
c:\program files\Dell\NicConfigSvc\NicConfigSvc.exe
c:\program files\Maxtor\OneTouch\Utils\SyncServices.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\system32\locator.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\progra~1\Intel\Wireless\Bin\Dot1XCfg.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Logitech\Video\FxSvr2.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosOBEX.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe
.
**************************************************************************
.
Completion time: 2009-01-19 13:22:39 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-19 18:22:36
ComboFix2.txt 2009-01-19 15:26:46
Pre-Run: 28,222,410,752 bytes free
Post-Run: 28,178,255,872 bytes free
560 --- E O F --- 2008-12-18 08:01:54
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:24:30 PM, on 1/19/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\AOL\1148442532\ee\AOLSoftware.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\AIM\aim.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\larryb.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://go.microsoft.com/fwlink/?LinkId=74005
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ShowLOMControl]
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1148442532\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ClubBox] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} -
http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MaxBackServiceInt - Unknown owner - C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: MaxSyncService (NTService1) - - C:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
--
End of file - 11358 bytes
Thanks,
larryb