here is the combofix file
ComboFix 08-09-05.02 - Owner 2008-09-06 12:40:31.1 - NTFSx86
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\salesmonitor
C:\Documents and Settings\LocalService\Application Data\wsnpoem
C:\Documents and Settings\LocalService\Application Data\wsnpoem\audio.dll
C:\Documents and Settings\NetworkService\Application Data\wsnpoem
C:\Documents and Settings\NetworkService\Application Data\wsnpoem\audio.dll
C:\Documents and Settings\Owner\ResErrors.log
C:\Program Files\PCHealthCenter\
0.exe
C:\Program Files\PCHealthCenter\1.exe
C:\Program Files\PCHealthCenter\1.ico
C:\Program Files\PCHealthCenter\2.gif
C:\Program Files\PCHealthCenter\2.ico
C:\Program Files\PCHealthCenter\3.exe
C:\Program Files\PCHealthCenter\3.gif
C:\Program Files\PCHealthCenter\4.exe
C:\Program Files\PCHealthCenter\sc.html
C:\Program Files\ShoppingReport
C:\WINDOWS\BM7f2b995b.txt
C:\WINDOWS\BM7f2b995b.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\Fonts\acrsecB.fon
C:\WINDOWS\Fonts\acrsecI.fon
C:\WINDOWS\smdat32m.sys
C:\WINDOWS\system32\abeeg.bak1
C:\WINDOWS\system32\abeeg.bak2
C:\WINDOWS\system32\abeeg.ini
C:\WINDOWS\system32\abeeg.ini2
C:\WINDOWS\system32\abeeg.tmp
C:\WINDOWS\system32\actskn43.ocx
C:\WINDOWS\system32\aekyslgv.ini
C:\WINDOWS\system32\afpealwf.ini
C:\WINDOWS\system32\aiefnbkd.ini
C:\WINDOWS\system32\aowcrnlk.ini
C:\WINDOWS\system32\atjwiplu.ini
C:\WINDOWS\system32\axwundrb.ini
C:\WINDOWS\system32\bfqltpqr.ini
C:\WINDOWS\system32\bvswvyyh.ini
C:\WINDOWS\system32\bxlghpdp.ini
C:\WINDOWS\system32\cbrondqm.ini
C:\WINDOWS\system32\cefbgmde.ini
C:\WINDOWS\system32\clokkhgq.ini
C:\WINDOWS\system32\cmjptwvr.ini
C:\WINDOWS\system32\crmdmsiq.ini
C:\WINDOWS\system32\cvutuegp.ini
C:\WINDOWS\system32\cyokgxvq.ini
C:\WINDOWS\system32\defgddhj.ini
C:\WINDOWS\system32\dinryqcj.ini
C:\WINDOWS\system32\duypxboi.ini
C:\WINDOWS\system32\eaxrxqhh.ini
C:\WINDOWS\system32\egfwicxh.ini
C:\WINDOWS\system32\emqpjbwv.ini
C:\WINDOWS\system32\eogrnpla.ini
C:\WINDOWS\system32\fjojwolh.ini
C:\WINDOWS\system32\fjtebqxq.ini
C:\WINDOWS\system32\ghljuwpx.ini
C:\WINDOWS\system32\gjglfvus.ini
C:\WINDOWS\system32\gkhhunft.ini
C:\WINDOWS\system32\gpenkkdg.ini
C:\WINDOWS\system32\gsgrbulp.ini
C:\WINDOWS\system32\hkqkcxby.ini
C:\WINDOWS\system32\hlrjychp.ini
C:\WINDOWS\system32\hodfpedd.ini
C:\WINDOWS\system32\husshnyj.ini
C:\WINDOWS\system32\hyqqeknt.ini
C:\WINDOWS\system32\ihavqnox.ini
C:\WINDOWS\system32\isiemqjf.ini
C:\WINDOWS\system32\iyvhlrpd.ini
C:\WINDOWS\system32\krruaevq.ini
C:\WINDOWS\system32\ksxtooeh.ini
C:\WINDOWS\system32\ldkpmrwv.ini
C:\WINDOWS\system32\ltnumspr.ini
C:\WINDOWS\system32\luylmdko.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\menaolby.ini
C:\WINDOWS\system32\mfojyfps.ini
C:\WINDOWS\system32\mlddapll.ini
C:\WINDOWS\system32\mnyvljrs.ini
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\mwslbbfl.ini
C:\WINDOWS\system32\naslkdif.ini
C:\WINDOWS\system32\ndwogbol.ini
C:\WINDOWS\system32\ngicgmdh.ini
C:\WINDOWS\system32\nydjdaul.ini
C:\WINDOWS\system32\ocglxvmr.ini
C:\WINDOWS\system32\onhnnidp.ini
C:\WINDOWS\system32\pclgmflw.ini
C:\WINDOWS\system32\pispselk.ini
C:\WINDOWS\system32\putpneql.ini
C:\WINDOWS\system32\pvjffxoh.ini
C:\WINDOWS\system32\pvohxsau.ini
C:\WINDOWS\system32\qgermewr.ini
C:\WINDOWS\system32\qheaikhm.ini
C:\WINDOWS\system32\qibjhjhm.ini
C:\WINDOWS\system32\qtlfuits.ini
C:\WINDOWS\system32\qvpeqjoy.ini
C:\WINDOWS\system32\ralkbbdx.ini
C:\WINDOWS\system32\rklfjurj.ini
C:\WINDOWS\system32\rnnoxqjs.ini
C:\WINDOWS\system32\rqvqbueu.ini
C:\WINDOWS\system32\rtl60.bpl
C:\WINDOWS\system32\rudtuksb.ini
C:\WINDOWS\system32\semreprg.ini
C:\WINDOWS\system32\slgqpmmo.ini
C:\WINDOWS\system32\smxhetns.ini
C:\WINDOWS\system32\snohfeoj.ini
C:\WINDOWS\system32\sobddnqb.ini
C:\WINDOWS\system32\songctuq.ini
C:\WINDOWS\system32\subblnyj.ini
C:\WINDOWS\system32\syvwtqfp.ini
C:\WINDOWS\system32\thoofdxn.ini
C:\WINDOWS\system32\tkllgboy.ini
C:\WINDOWS\system32\turypyxd.ini
C:\WINDOWS\system32\twifkngh.ini
C:\WINDOWS\system32\ukgubtux.ini
C:\WINDOWS\system32\utkavdyv.ini
C:\WINDOWS\system32\uttss.bak1
C:\WINDOWS\system32\uttss.ini
C:\WINDOWS\system32\utuunaey.ini
C:\WINDOWS\system32\uuksbjoq.ini
C:\WINDOWS\system32\uvtmhvjo.ini
C:\WINDOWS\system32\uyaflonv.ini
C:\WINDOWS\system32\vagolmdh.ini
C:\WINDOWS\system32\vbrltnbl.ini
C:\WINDOWS\system32\VIE1.exe
C:\WINDOWS\system32\VIE2.exe
C:\WINDOWS\system32\VIE3.exe
C:\WINDOWS\system32\vodcsnxu.ini
C:\WINDOWS\system32\vokyijfo.ini
C:\WINDOWS\system32\vpswfbwk.ini
C:\WINDOWS\system32\vqypemwc.ini
C:\WINDOWS\system32\wfdcsrjg.ini
C:\WINDOWS\system32\xmacwxss.ini
C:\WINDOWS\system32\xvqntnay.ini
C:\WINDOWS\system32\ynlqcugk.ini
C:\WINDOWS\system32\yvmadmbu.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_DHLP
-------\Legacy_POWERMANAGER
-------\Service_PowerManager
((((((((((((((((((((((((( Files Created from 2008-08-06 to 2008-09-06 )))))))))))))))))))))))))))))))
.
2008-09-06 10:48 . 2008-09-06 10:48 <DIR> d-------- C:\Program Files\Trend Micro
2008-09-02 21:23 . 2008-09-06 12:38 <DIR> d--h----- C:\$AVG8.VAULT$
2008-09-02 21:10 . 2008-09-06 12:13 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-09-02 21:10 . 2008-09-02 21:37 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\AVGTOOLBAR
2008-09-02 21:10 . 2008-09-02 21:10 97,928 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-09-02 21:10 . 2008-09-02 21:10 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-09-02 21:10 . 2008-09-02 21:10 12,936 --a------ C:\WINDOWS\system32\drivers\avgrkx86.sys
2008-09-02 21:10 . 2008-09-02 21:10 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-09-02 21:06 . 2008-09-02 21:06 <DIR> d-------- C:\Program Files\AVG
2008-09-02 21:06 . 2008-09-02 21:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-09-02 21:06 . 2008-09-02 21:06 45,568 --a------ C:\WINDOWS\system32\avgfwdx.dll
2008-09-02 21:06 . 2008-09-02 21:06 23,296 --a------ C:\WINDOWS\system32\drivers\avgfwdx.sys
2008-09-02 20:13 . 2008-08-28 15:57 3,262 --a------ C:\WINDOWS\system32\2.ico
2008-09-02 20:09 . 2008-09-06 12:48 <DIR> d-------- C:\Program Files\PCHealthCenter
2008-09-02 20:09 . 2008-09-02 22:01 <DIR> d-------- C:\Program Files\MSA
2008-09-02 20:09 . 2008-08-28 15:57 3,262 --a------ C:\WINDOWS\system32\1.ico
2008-08-31 12:51 . 2008-08-31 12:51 4,212 ---h----- C:\WINDOWS\system32\imlictbl.dat
2008-08-31 12:41 . 2008-08-31 12:41 <DIR> d-------- C:\WINDOWS\system32\scripting
2008-08-31 12:41 . 2008-08-31 12:41 <DIR> d-------- C:\WINDOWS\system32\en
2008-08-31 12:41 . 2008-08-31 12:41 <DIR> d-------- C:\WINDOWS\system32\bits
2008-08-31 12:41 . 2008-08-31 12:41 <DIR> d-------- C:\WINDOWS\l2schemas
2008-08-31 12:36 . 2008-08-31 12:42 <DIR> d-------- C:\WINDOWS\ServicePackFiles
2008-08-31 12:25 . 2008-08-31 12:25 <DIR> d-------- C:\WINDOWS\EHome
2008-08-30 12:35 . 2008-08-30 12:35 <DIR> d-------- C:\WINDOWS\Internet Logs
2008-08-30 12:13 . 2008-09-03 09:24 <DIR> d-------- C:\Program Files\IMsecure
2008-08-30 12:13 . 2003-10-23 13:47 1,155,142 --a------ C:\WINDOWS\system32\imslsp.dll
2008-08-30 12:13 . 2003-10-23 13:43 241,664 --a------ C:\WINDOWS\system32\lockbox.dll
2008-08-30 12:13 . 2003-08-09 12:19 110,660 --a------ C:\WINDOWS\system32\zlimclnup.exe
2008-08-30 12:13 . 2003-10-10 04:47 45,056 --a------ C:\WINDOWS\system32\IMregexp.dll
2008-08-30 12:12 . 2003-08-20 07:53 684,032 --a------ C:\WINDOWS\system32\libeay32_0.9.6g.dll
2008-08-30 12:12 . 2003-10-23 14:02 110,592 --a------ C:\WINDOWS\system32\imsinstall.dll
2008-08-30 12:08 . 2008-08-30 12:08 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Broderbund LLC
2008-08-29 11:21 . 2008-09-06 12:20 13,151 --a------ C:\logfile
2008-08-29 11:09 . 2008-08-29 11:09 <DIR> d-------- C:\Program Files\Common Files\Kodak
2008-08-26 19:44 . 2008-04-13 18:12 1,737,856 --------- C:\WINDOWS\system32\mtxparhd.dll
2008-08-26 19:43 . 2004-08-03 22:41 1,041,536 --------- C:\WINDOWS\system32\drivers\hsfdpsp2.sys
2008-08-26 19:42 . 2008-04-13 18:11 1,888,992 --------- C:\WINDOWS\system32\ati3duag.dll
2008-08-22 12:47 . 2008-08-23 12:38 126 --a------ C:\Documents and Settings\Owner\delself.bat
2008-08-22 11:06 . 2008-08-22 11:06 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\Weather Studio
2008-08-22 11:06 . 2008-09-02 22:01 <DIR> d-------- C:\Program Files\paemitd
2008-08-22 11:06 . 2008-08-22 11:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\tilsxavm
2008-08-17 15:40 . 2008-08-17 15:40 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\iWin
2008-08-17 13:29 . 2008-08-17 13:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Zylom
2008-08-17 12:18 . 2008-08-17 12:18 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\SpinTop
2008-08-12 16:41 . 2008-04-11 13:04 691,712 -----c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-06 18:56 --------- d-----w C:\Program Files\tzphsr
2008-09-03 15:23 --------- d-----w C:\Program Files\Google
2008-09-03 15:21 --------- d-----w C:\Program Files\Machine Programming
2008-09-03 08:34 --------- d-----w C:\Program Files\MailFrontier
2008-09-02 02:20 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-08-29 17:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kodak
2008-08-29 17:07 --------- d-----w C:\Program Files\Kodak
2008-08-22 21:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-18 04:34 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-18 18:34 586,240 ----a-w C:\WINDOWS\WLXPGSS.SCR
2007-11-25 02:51 374 ----a-w C:\Documents and Settings\Owner\Application Data\internaldb6334.dat
2007-11-25 02:37 555 ----a-w C:\Documents and Settings\Owner\Application Data\internaldb8467.dat
2007-11-25 02:37 18,432 ----a-w C:\Documents and Settings\Owner\Application Data\internaldb41.dat
2007-08-21 04:36 166 ----a-w C:\Documents and Settings\Owner\Application Data\wklnhst.dat
2006-11-06 06:29 774,144 ----a-w C:\Program Files\RngInterstitial.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{14E3CE90-8B1B-9BB9-5571-01B58BB2F24C}]
2008-09-06 12:56 122880 --a------ C:\Program Files\tzphsr\procapiapp.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [2005-06-02 1957888]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-08-18 1832272]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"TSClientMSIUninstaller"="C:\WINDOWS\Installer\TSClientMsiTrans\tscuinst.vbs" [2007-10-30 13801]
"TSClientAXDisabler"="C:\WINDOWS\Installer\TSClientMsiTrans\tscdsbl.bat" [2008-01-18 2247]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-08-12 102400]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-08-12 684032]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-08-20 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-08-20 118784]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"Creative WebCam Tray"="C:\Program Files\Creative\Shared Files\CAMTRAY.EXE" [2004-07-30 245760]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 49152]
"Motive SmartBridge"="C:\PROGRA~1\TELUSE~1\SMARTB~1\MotiveSB.exe" [2007-09-29 393216]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 286720]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-09-02 1235736]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
"AKCfHYz6lj"="C:\Documents and Settings\All Users\Application Data\tilsxavm\bylalmvw.exe" [2008-08-22 69632]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 29696]
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2007-02-20 282624]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
R0 AvgRkx86;avgrkx86.sys;C:\WINDOWS\system32\Drivers\avgrkx86.sys [2008-09-02 12936]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-09-02 97928]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-09-02 875288]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-09-02 231704]
R2 avgfws8;AVG8 Firewall;C:\PROGRA~1\AVG\AVG8\avgfws8.exe [2008-09-02 1220888]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-09-02 76040]
R3 Avgfwdx;Avgfwdx;C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2008-09-02 23296]
S3 Avgfwfd;AVG network filter service;C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2008-09-02 23296]
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{08FCF7E3-5F7D-444E-8554-76A516EB3C6C} - C:\Program Files\Weather Studio\bin\WeatherStudio.dll
WebBrowser-{4F802BCF-44AA-4C28-935A-CBEDC24B5375} - C:\Program Files\Weather Studio\bin\WeatherStudio.dll
HKCU-Run-HistoryKill - C:\Program Files\HistoryKill 2007\histkill.exe
HKCU-Run-NoWayVirus - C:\Program Files\NoWayVirus\pgs.exe
HKCU-Run-\VIE1.exe - C:\Windows\System32\VIE1.exe
HKCU-Run-\VIE2.exe - C:\Windows\System32\VIE2.exe
HKCU-Run-\VIE3.exe - C:\Windows\System32\VIE3.exe
HKCU-Run-\VIE4.exe - C:\Windows\System32\VIE4.exe
HKLM-Run-GotSmiley - C:\PROGRA~1\GOTSMI~1\GSYUpdater.exe
HKLM-Run-7c18aac7 - C:\WINDOWS\system32\ueubqvqr.dll
HKLM-Run-Salestart(1) - C:\Program Files\Common Files\SystemErrorFixer\strpmon.exe dm=http://systemerrorfixer.com ad=http://systemerrorfixer.com
HKLM-Run-SeekmoOE - C:\Program Files\Seekmo\bin\10.0.345.0\OEAddOn.exe
SSODL-sysapp-{5805C4BC-B095-1C26-289A-0AF42906500A} - C:\Program Files\paemitd\sysapp.dll
Notify-mljgg - C:\WINDOWS\system32\mljgg.dll
Notify-__c0081FF6 - C:\WINDOWS\system32\__c0081FF6.dat
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
R1 -: HKCU-Internet Settings,ProxyOverride = 127.0.0.1
O9 -: {240FF121-9EF3-4e9f-A397-9E189045B6A1} - "C:\PROGRA~1\GOTSMI~1\GSYUpdater.exe"
O16 -: Microsoft XML Parser for Java - file://C:\WINDOWS\Java\classes\xmldso.cab
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
O16 -: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files/Monopoly%20Here%20and%20Now/Images/stg_drm.ocx
C:\WINDOWS\Downloaded Program Files\stg_drm.ocx
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\stg_drm.ocx
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\stg_drm.ocx
C:\WINDOWS\Downloaded Program Files\CONFLICT.3\stg_drm.ocx
C:\WINDOWS\Downloaded Program Files\CONFLICT.4\stg_drm.ocx
C:\WINDOWS\Downloaded Program Files\CONFLICT.5\stg_drm.ocx
O16 -: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file:///C:/Program%20Files/SCRABBLE/Images/armhelper.ocx
C:\WINDOWS\Downloaded Program Files\armhelper.ocx
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-09-06 12:51:32
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\wdfmgr.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
.
**************************************************************************
.
Completion time: 2008-09-06 13:04:48 - machine was rebooted [Owner]
ComboFix-quarantined-files.txt 2008-09-06 19:04:15
Pre-Run: 8,962,609,152 bytes free
Post-Run: 8,916,951,040 bytes free
341 --- E O F --- 2008-09-01 19:25:57