Ok, I am attempting to send commy log here:
ComboFix 10-07-30.02 - bouncier 07/31/2010 2:44.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1919.1426 [GMT -6:00]
Running from: c:\documents and settings\bouncier\desktop\commy.exe
Command switches used :: /stepdel
AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
FW: Online Armor Firewall *enabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
c:\windows\system32\87ghd.log
c:\windows\system32\b55v0.log
c:\windows\system32\dfttuyo.txt
c:\windows\system32\Install.txt
D:\install.exe
.
((((((((((((((((((((((((( Files Created from 2010-06-28 to 2010-07-31 )))))))))))))))))))))))))))))))
.
2010-07-29 14:38 . 2010-07-29 14:38 -------- d-----w- c:\program files\Novel Games
2010-07-29 12:59 . 2010-07-29 12:59 388096 ----a-r- c:\documents and settings\bouncier\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-07-29 12:59 . 2010-07-29 13:02 -------- d-----w- c:\program files\Trend Micro
2010-07-29 11:49 . 2010-07-29 11:49 -------- d-----w- c:\documents and settings\bouncier\Application Data\Malwarebytes
2010-07-29 11:49 . 2010-04-29 21:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-29 11:49 . 2010-07-29 11:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-07-29 11:49 . 2010-04-29 21:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-07-29 11:49 . 2010-07-29 11:49 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-07-28 05:50 . 2010-07-28 06:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2010-07-28 05:50 . 2010-07-28 05:50 -------- d-----w- c:\program files\CCleaner
2010-07-28 04:48 . 2010-07-29 14:18 -------- d-----w- c:\documents and settings\bouncier\Application Data\OnlineArmor
2010-07-28 04:48 . 2010-07-28 05:13 -------- d-----w- c:\documents and settings\All Users\Application Data\OnlineArmor
2010-07-28 04:48 . 2010-07-07 18:25 22600 ----a-w- c:\windows\system32\drivers\OAmon.sys
2010-07-28 04:48 . 2010-07-07 18:25 28232 ----a-w- c:\windows\system32\drivers\OAnet.sys
2010-07-28 04:48 . 2010-07-07 18:25 236104 ----a-w- c:\windows\system32\drivers\OADriver.sys
2010-07-28 04:48 . 2010-07-28 04:48 -------- d-----w- c:\program files\Emsisoft
2010-07-28 00:15 . 2010-07-28 00:15 -------- d-----w- c:\program files\WON
2010-07-27 14:01 . 2010-07-27 14:01 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2010-07-27 07:45 . 2010-07-27 07:45 -------- d-----w- c:\documents and settings\bouncier\Local Settings\Application Data\Help
2010-07-27 02:05 . 2010-07-27 02:15 -------- d-----w- c:\program files\Exterminate It!
2010-07-26 20:27 . 2010-07-26 20:27 -------- d-----w- c:\documents and settings\bouncier\Application Data\Uniblue
2010-07-26 18:42 . 2010-07-26 18:43 -------- dc-h--w- c:\windows\ie8
2010-07-26 05:19 . 2010-07-26 05:19 -------- d-----w- c:\program files\ESET
2010-07-25 23:34 . 2010-07-25 23:34 -------- d-----w- c:\program files\ACW
2010-07-25 21:08 . 2010-06-02 10:55 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2010-07-25 21:08 . 2010-06-02 10:55 527192 ----a-w- c:\windows\system32\XAudio2_7.dll
2010-07-25 21:08 . 2010-06-02 10:55 239960 ----a-w- c:\windows\system32\xactengine3_7.dll
2010-07-25 21:08 . 2010-05-26 17:41 248672 ----a-w- c:\windows\system32\d3dx11_43.dll
2010-07-25 21:08 . 2010-05-26 17:41 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2010-07-25 21:08 . 2010-05-26 17:41 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll
2010-07-25 21:08 . 2010-05-26 17:41 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
2010-07-25 21:08 . 2010-05-26 17:41 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2010-07-25 20:20 . 2010-07-25 20:20 -------- d-----w- c:\documents and settings\bouncier\Local Settings\Application Data\FixItCenter
2010-07-25 20:02 . 2010-07-25 20:02 -------- d-----w- c:\windows\MATS
2010-07-25 20:02 . 2010-07-25 20:02 -------- d-----w- c:\program files\Microsoft Fix it Center
2010-07-25 07:32 . 2010-07-25 07:34 -------- d-----w- c:\windows\system32\NtmsData
2010-07-25 05:22 . 2010-07-25 14:24 -------- d-----w- c:\program files\Free Window Registry Repair
2010-07-25 02:01 . 2010-07-25 19:08 -------- d-----w- c:\documents and settings\bouncier\Application Data\ElevatedDiagnostics
2010-07-25 00:48 . 2010-07-25 00:48 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2010-07-24 10:21 . 2010-07-28 06:34 63488 ----a-w- c:\documents and settings\bouncier\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-07-24 10:21 . 2010-07-24 10:21 52224 ----a-w- c:\documents and settings\bouncier\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-07-24 10:21 . 2010-07-28 06:34 117760 ----a-w- c:\documents and settings\bouncier\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-07-24 10:05 . 2010-07-24 10:05 -------- d-----w- c:\documents and settings\bouncier\Application Data\SUPERAntiSpyware.com
2010-07-24 10:05 . 2010-07-24 10:05 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-07-24 10:05 . 2010-07-31 06:43 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-07-24 05:00 . 2010-07-24 05:00 -------- d-----w- c:\documents and settings\All Users\Application Data\RegCure
2010-07-24 05:00 . 2010-07-24 05:01 -------- d-----w- c:\program files\RegCure
2010-07-24 04:31 . 2010-07-24 04:31 -------- d-----w- c:\program files\Common Files\Java
2010-07-24 03:07 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-24 02:53 . 2010-07-24 02:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Juno
2010-07-24 02:34 . 2006-08-11 20:41 225280 ----a-w- c:\documents and settings\bouncier\Application Data\U3\0000167A6773D0BF\0DE4F643-C398-46ec-9339-2362F2311932\Exec\U3Action.exe
2010-07-24 02:34 . 2006-05-26 07:53 19456 ----a-w- c:\documents and settings\bouncier\Application Data\U3\0000167A6773D0BF\0DE4F643-C398-46ec-9339-2362F2311932\Exec\skypeshutdown.exe
2010-07-24 02:34 . 2006-08-16 22:51 19647528 ----a-w- c:\documents and settings\bouncier\Application Data\U3\0000167A6773D0BF\0DE4F643-C398-46ec-9339-2362F2311932\Exec\Skype.exe
2010-07-24 02:34 . 2005-09-27 20:57 24064 ----a-w- c:\documents and settings\bouncier\Application Data\U3\0000167A6773D0BF\0DE4F643-C398-46ec-9339-2362F2311932\Exec\hostClnUpNoOp.exe
2010-07-24 02:32 . 2007-10-23 15:27 110592 ----a-w- c:\documents and settings\bouncier\Application Data\U3\temp\cleanup.exe
2010-07-24 02:27 . 2008-05-02 16:41 3493888 ---ha-w- c:\documents and settings\bouncier\Application Data\U3\temp\Launchpad Removal.exe
2010-07-24 02:10 . 2010-07-25 04:27 -------- d-----w- c:\program files\Cleopatras Palace
2010-07-24 02:09 . 2010-07-24 02:10 -------- d-----w- c:\program files\Bonjour
2010-07-24 02:08 . 2010-07-24 02:08 -------- d-----w- c:\program files\iTunes
2010-07-24 02:08 . 2010-07-24 02:08 -------- d-----w- c:\program files\iPod
2010-07-23 20:14 . 2010-07-24 02:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Juno(2)
2010-07-23 00:23 . 2010-07-24 02:07 -------- d-----w- c:\program files\TropicaCasino
2010-07-22 22:44 . 2010-07-24 02:07 -------- d-----w- c:\program files\Slots Jungle Casino
2010-07-20 18:49 . 2010-07-24 02:08 -------- d-----w- c:\program files\iPod(2)
2010-07-20 18:49 . 2010-07-24 02:08 -------- d-----w- c:\program files\iTunes(2)
2010-07-20 18:47 . 2010-07-24 02:08 -------- d-----w- c:\program files\Bonjour(2)
2010-07-20 07:14 . 2010-07-24 02:08 -------- d-----w- c:\documents and settings\bouncier\Application Data\CasinoStates
2010-07-20 07:14 . 2010-07-24 02:08 -------- d-----w- c:\documents and settings\All Users\Application Data\CasinoStates
2010-07-19 23:38 . 2010-07-24 02:53 -------- d-----w- c:\program files\Juno
2010-07-19 23:38 . 2010-07-24 02:53 -------- d-----w- C:\JunoInstaller
2010-07-19 19:54 . 2010-07-19 20:11 109976 ----a-w- c:\windows\hpoins08.dat
2010-07-19 19:54 . 2006-01-24 07:11 7577 ------w- c:\windows\hpomdl08.dat
2010-07-19 11:39 . 2010-07-19 11:39 -------- d-----w- c:\documents and settings\bouncier2\Local Settings\Application Data\PCHealth
2010-07-19 10:04 . 2010-07-19 10:04 -------- d-----w- c:\documents and settings\bouncier2\Local Settings\Application Data\Apple Computer
2010-07-19 10:04 . 2010-07-19 10:04 20456 ----a-w- c:\documents and settings\bouncier2\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-19 10:03 . 2010-07-19 10:03 -------- d-----w- c:\documents and settings\bouncier2\IETldCache
2010-07-19 10:03 . 2010-07-24 02:09 -------- d-----w- c:\documents and settings\bouncier2\Local Settings\Application Data\Microsoft
2010-07-19 10:03 . 2010-07-24 02:09 -------- d-s---w- c:\documents and settings\bouncier2
2010-07-18 20:36 . 2010-07-24 02:10 -------- d-----w- c:\program files\Cleopatras Palace(2)
2010-07-18 06:11 . 2010-07-24 02:35 -------- d-----w- c:\program files\NetZeroInstaller
2010-07-18 06:04 . 2010-07-24 10:59 -------- d-----w- c:\documents and settings\bouncier\Application Data\U3
2010-07-17 21:34 . 2010-07-18 06:29 86 ---h--w- c:\windows\popcreg.dat
2010-07-17 21:34 . 2010-07-18 06:29 32 ----a-w- c:\windows\popcinfot.dat
2010-07-17 20:24 . 2010-07-17 20:24 -------- d-----w- c:\program files\PopCap Games
2010-07-13 17:40 . 2010-07-24 02:12 -------- d-----w- c:\program files\RTF Convertor
2010-07-13 14:23 . 2010-07-25 13:59 -------- d-----w- c:\documents and settings\bouncier\Application Data\GlarySoft
2010-07-13 14:23 . 2010-07-25 13:59 -------- d-----w- c:\program files\Glary Registry Repair
2010-07-13 01:25 . 2010-07-24 02:12 -------- d-----w- c:\program files\AZ RTF to PDF Converter
2010-07-08 22:53 . 2006-02-28 12:00 1677824 -c--a-w- c:\windows\system32\dllcache\chsbrkr.dll
2010-07-08 22:53 . 2006-02-28 12:00 1677824 ----a-w- c:\windows\system32\chsbrkr.dll
2010-07-08 22:53 . 2006-02-28 12:00 838144 -c--a-w- c:\windows\system32\dllcache\chtbrkr.dll
2010-07-08 22:53 . 2006-02-28 12:00 838144 ----a-w- c:\windows\system32\chtbrkr.dll
2010-07-08 22:53 . 2006-02-28 12:00 70656 -c--a-w- c:\windows\system32\dllcache\korwbrkr.dll
2010-07-08 22:53 . 2006-02-28 12:00 70656 ----a-w- c:\windows\system32\korwbrkr.dll
2010-07-08 22:53 . 2006-02-28 12:00 98304 -c--a-w- c:\windows\system32\dllcache\msir3jp.dll
2010-07-08 22:53 . 2006-02-28 12:00 98304 ----a-w- c:\windows\system32\msir3jp.dll
2010-07-08 22:51 . 2006-02-28 12:00 57398 -c--a-w- c:\windows\system32\dllcache\imjpdadm.exe
2010-07-08 22:51 . 2006-02-28 12:00 45109 -c--a-w- c:\windows\system32\dllcache\imjpuex.exe
2010-07-08 22:50 . 2006-02-28 12:00 6656 -c--a-w- c:\windows\system32\dllcache\c_is2022.dll
2010-07-08 22:50 . 2006-02-28 12:00 6656 ----a-w- c:\windows\system32\c_is2022.dll
2010-07-08 22:49 . 2001-08-18 04:36 8704 -c--a-w- c:\windows\system32\dllcache\kbdjpn.dll
2010-07-08 22:49 . 2001-08-18 04:36 8704 ----a-w- c:\windows\system32\kbdjpn.dll
2010-07-08 22:49 . 2001-08-18 04:36 8192 -c--a-w- c:\windows\system32\dllcache\kbdkor.dll
2010-07-08 22:49 . 2001-08-18 04:36 8192 ----a-w- c:\windows\system32\kbdkor.dll
2010-07-08 22:49 . 2001-08-17 20:55 6144 -c--a-w- c:\windows\system32\dllcache\kbd101c.dll
2010-07-08 22:49 . 2001-08-17 20:55 6144 ----a-w- c:\windows\system32\kbd101c.dll
2010-07-08 22:49 . 2001-08-17 20:55 5632 -c--a-w- c:\windows\system32\dllcache\kbd103.dll
2010-07-08 22:49 . 2001-08-17 20:55 5632 ----a-w- c:\windows\system32\kbd103.dll
2010-07-08 22:49 . 2001-08-17 20:55 6144 -c--a-w- c:\windows\system32\dllcache\kbd101b.dll
2010-07-08 22:49 . 2001-08-17 20:55 6144 ----a-w- c:\windows\system32\kbd101b.dll
2010-07-08 22:49 . 2008-04-14 00:09 6144 -c--a-w- c:\windows\system32\dllcache\kbd106.dll
2010-07-08 22:49 . 2008-04-14 00:09 6144 ----a-w- c:\windows\system32\kbd106.dll
2010-07-08 00:08 . 2010-07-25 04:27 -------- d-----w- c:\program files\VIP Lounge
2010-07-07 07:28 . 2010-07-27 02:49 -------- d-----w- c:\documents and settings\bouncier\Application Data\Apple Computer
2010-07-07 07:28 . 2009-05-18 19:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-07-07 07:28 . 2008-04-17 18:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2010-07-07 07:27 . 2010-07-07 07:28 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-07-07 07:26 . 2010-07-18 16:52 -------- d-----w- c:\program files\QuickTime
2010-07-07 07:26 . 2010-07-24 02:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-07-07 07:26 . 2010-07-07 07:26 -------- d-----w- c:\documents and settings\bouncier\Local Settings\Application Data\Apple
2010-07-07 07:26 . 2010-07-07 07:26 -------- d-----w- c:\program files\Apple Software Update
2010-07-07 07:26 . 2010-07-28 05:24 -------- dc----w- c:\windows\system32\DRVSTORE
2010-07-07 07:25 . 2010-07-24 02:08 -------- d-----w- c:\program files\Common Files\Apple
2010-07-07 07:25 . 2010-07-07 07:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2010-07-07 07:21 . 2010-07-07 07:28 -------- d-----w- c:\documents and settings\bouncier\Local Settings\Application Data\Apple Computer
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-30 13:30 . 2010-07-29 18:48 -------- d-----w- c:\program files\Common Files\Real
2010-07-30 13:30 . 2010-07-29 18:48 -------- d-----w- c:\program files\Real
2010-07-30 13:30 . 2010-07-30 13:30 -------- d-----w- c:\documents and settings\bouncier\Application Data\7Spins
2010-07-30 13:30 . 2010-07-30 13:30 -------- d-----w- c:\documents and settings\All Users\Application Data\7Spins
2010-07-30 13:30 . 2010-07-30 13:30 -------- d-----w- c:\program files\7Spins
2010-07-30 13:30 . 2010-07-29 21:35 -------- d-----w- c:\program files\Mozilla Firefox(2)
2010-07-29 21:36 . 2010-07-29 21:36 0 ----a-w- c:\windows\nsreg.dat
2010-07-28 05:50 . 2010-06-22 17:34 -------- d-----w- c:\program files\Yahoo!
2010-07-25 22:49 . 2010-03-27 07:00 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-07-25 22:34 . 2010-03-27 06:58 -------- d-----w- c:\program files\Common Files\InstallShield
2010-07-25 13:34 . 2010-04-04 08:17 -------- d-----w- c:\program files\Ask.com
2010-07-25 04:27 . 2010-07-01 05:57 -------- d-----w- c:\program files\WinPalace
2010-07-24 04:31 . 2010-04-20 05:49 -------- d-----w- c:\program files\Java
2010-07-24 02:17 . 2010-04-04 00:44 -------- d-----w- c:\documents and settings\All Users\Application Data\SpeedBit
2010-07-19 12:14 . 2010-03-27 06:20 76487 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-07-18 23:35 . 2010-04-05 21:19 -------- d-----w- c:\program files\Eusing Free Registry Cleaner
2010-07-18 23:06 . 2010-04-29 09:53 -------- d-----w- c:\program files\Vegascasino21
2010-07-18 22:53 . 2010-03-27 20:10 -------- d-----w- c:\program files\Atlantis
2010-07-18 18:42 . 2010-03-27 07:22 -------- d-----w- c:\documents and settings\bouncier\Application Data\ATI
2010-07-18 04:45 . 2010-04-05 16:07 83 ----a-w- c:\windows\popcinfo.dat
2010-07-09 20:29 . 2010-03-27 07:23 20456 ----a-w- c:\documents and settings\bouncier\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-06 00:09 . 2010-06-06 00:02 -------- d-----w- c:\documents and settings\bouncier\Application Data\HpUpdate
2010-06-29 02:18 . 2010-03-27 20:21 -------- d-----w- c:\program files\Microsoft Security Essentials
2010-06-23 02:31 . 2010-06-22 17:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2010-06-22 17:34 . 2010-06-22 17:34 -------- d-----w- c:\documents and settings\bouncier\Application Data\Yahoo!
2010-06-22 10:36 . 2010-04-20 05:50 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-06-20 17:58 . 2010-06-19 02:08 -------- d-----w- c:\program files\Microsoft Silverlight
2010-06-19 02:08 . 2010-06-19 02:08 -------- d-----w- c:\program files\Microsoft SQL Server
2010-06-18 23:36 . 2010-06-18 23:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-06-18 23:36 . 2010-06-18 23:36 193824 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\VBExpress\9.0\1033\ResourceCache.dll
2010-06-18 23:35 . 2010-06-18 23:35 416 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\MSDN\9.0\1033\ResourceCache.dll
2010-06-18 23:34 . 2010-06-18 23:32 -------- d-----w- c:\program files\Microsoft Visual Studio 9.0
2010-06-18 23:32 . 2010-06-18 23:32 -------- d-----w- c:\program files\Microsoft.NET
2010-06-18 23:32 . 2010-06-18 23:32 -------- d-----w- c:\program files\Microsoft SDKs
2010-06-16 02:01 . 2010-06-16 02:01 72504 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
2010-06-14 14:31 . 2010-03-27 06:18 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-09 04:21 . 2010-06-09 04:21 -------- d-----w- c:\program files\Common Files\Software Update Utility
2010-06-09 04:16 . 2010-06-09 04:15 -------- d-----w- c:\documents and settings\bouncier\Application Data\acccore
2010-06-09 04:14 . 2010-06-09 04:14 -------- d-----w- c:\documents and settings\All Users\Application Data\AIM
2010-06-09 04:14 . 2010-06-09 04:14 -------- d-----w- c:\program files\AIM
2010-06-09 04:14 . 2010-06-09 04:13 -------- d-----w- c:\program files\Common Files\AOL
2010-06-01 17:37 . 2010-03-28 09:00 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-27 01:52 . 2010-05-27 01:52 503808 ----a-w- c:\documents and settings\bouncier\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-70f5cbff-n\msvcp71.dll
2010-05-27 01:52 . 2010-05-27 01:52 499712 ----a-w- c:\documents and settings\bouncier\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-70f5cbff-n\jmc.dll
2010-05-27 01:52 . 2010-05-27 01:52 348160 ----a-w- c:\documents and settings\bouncier\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-70f5cbff-n\msvcr71.dll
2010-05-27 01:48 . 2010-05-27 01:48 61440 ----a-w- c:\documents and settings\bouncier\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-66666ea4-n\decora-sse.dll
2010-05-27 01:48 . 2010-05-27 01:48 12800 ----a-w- c:\documents and settings\bouncier\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-66666ea4-n\decora-d3d.dll
2010-05-19 10:26 . 2010-05-19 10:26 32608 ----a-w- c:\windows\king-uninstall.exe
2010-05-18 22:35 . 2010-05-18 22:35 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-05-18 22:35 . 2010-05-18 22:35 75040 ----a-w- c:\windows\system32\jdns_sd.dll
2010-05-18 22:35 . 2010-05-18 22:35 197920 ----a-w- c:\windows\system32\dnssdX.dll
2010-05-18 22:35 . 2010-05-18 22:35 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-05-06 10:41 . 2006-02-28 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-06 10:41 . 2006-02-28 12:00 916480 ----a-w- c:\windows\system32\wininet(2)(2).dll
2010-05-06 10:41 . 2006-02-28 12:00 1209344 ----a-w- c:\windows\system32\urlmon(2)(2).dll
2010-05-06 10:41 . 2009-03-08 10:32 1985536 ----a-w- c:\windows\system32\iertutil(2)(2).dll
2010-05-06 10:41 . 2009-03-08 10:39 11076096 ----a-w- c:\windows\system32\ieframe(2)(2).dll
2010-05-06 02:02 . 2010-04-29 09:59 77824 ----a-w- c:\documents and settings\bouncier\Application Data\Vegascasino21\download\update.exe
2010-05-06 02:02 . 2010-04-29 09:59 77824 ----a-w- c:\documents and settings\All Users\Application Data\Vegascasino21\download\update.exe
.
------- Sigcheck -------
[7] 2008-04-14 . 5F1D5F88303D4A4DBC8E5F97BA967CC3 . 15360 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\ctfmon.exe
[7] 2008-04-14 . 5F1D5F88303D4A4DBC8E5F97BA967CC3 . 15360 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\fa06e29c141c84f43a95ba02f93d3774\ctfmon.exe
[-] 2008-04-14 . 81A23C9F7FA7D6B9D927ED6E78A57878 . 15872 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe
[7] 2006-02-28 . 24232996A38C0B0CF151C2140AE29FC8 . 15360 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 0]
"Juno_uoltray"="c:\program files\Juno\exec.exe" [2009-10-05 1779712]
"Uniblue RegistryBooster 2"="e:\registry\RegistryBooster 2\RegistryBooster.exe" [2008-05-05 1923352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-10 16129536]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-06-01 1093208]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 123648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2010-04-02 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-19 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"@OnlineArmor GUI"="c:\program files\Emsisoft\Online Armor\oaui.exe" [2010-07-07 6854984]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= "c:\progra~1\Emsisoft\ONLINE~1\oaevent.dll" [2010-07-07 924488]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\bouncier\\Application Data\\U3\\0000167A6773D0BF\\0DE4F643-C398-46ec-9339-2362F2311932\\Exec\\Skype.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [7/27/2010 10:48 PM 236104]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [7/27/2010 10:48 PM 22600]
R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [7/27/2010 10:48 PM 28232]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 12:25 PM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 12:41 PM 67656]
R2 OAcat;Online Armor Helper Service;c:\program files\Emsisoft\Online Armor\oacat.exe [7/27/2010 10:48 PM 1283400]
R2 SvcOnlineArmor;Online Armor;c:\program files\Emsisoft\Online Armor\oasrv.exe [7/27/2010 10:48 PM 3364680]
S1 SABKUTIL;SABKUTIL;\??\c:\program files\SUPERAntiSpyware\SABKUTIL.sys --> c:\program files\SUPERAntiSpyware\SABKUTIL.sys [?]
S3 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\Microsoft Fix it Center\Matsvc.exe [4/10/2010 5:05 PM 266544]
S3 NtApm;NT Apm/Legacy Interface Driver;c:\windows\system32\drivers\NtApm.sys [3/26/2010 5:02 PM 9344]
S3 SetupNTGLM7X;SetupNTGLM7X;F:\NTGLM7X.SYS [6/23/2006 3:02 AM 28160]
.
Contents of the 'Scheduled Tasks' folder
2010-07-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 17:50]
2010-07-31 c:\windows\Tasks\ConfigExec.job
- c:\program files\Microsoft Fix it Center\MatsApi.dll [2010-04-10 23:05]
2010-07-31 c:\windows\Tasks\DataUpload.job
- c:\program files\Microsoft Fix it Center\MatsApi.dll [2010-04-10 23:05]
2010-07-30 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2010-05-19 23:20]
2010-07-29 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2010-05-19 23:20]
2010-07-31 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2009-11-19 22:50]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = searchap.untd.com;127.0.0.1;localhost;*microsoft.com;*windowsupdate.com;*wustat.windows.com;*test-speed.com;liveupdate.symantecliveupdate.com;*symantec.com;*.nai.com;*.networkassociates.com;cf.netzero.net;qs.netzero.net;*.quicken.com;*.pogo.com;<local>
uSearchURL,(Default) = hxxp://search.juno.com/search?action=minisearch&source=minisearch
Trusted Zone: superslots.com
TCP: {E8831E24-1AC2-4246-A40F-A353DC4B410C} = 64.136.52.73 64.136.44.73
.
- - - - ORPHANS REMOVED - - - -
Toolbar-Locked - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-07-31 02:50
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(448)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2010-07-31 02:53:52
ComboFix-quarantined-files.txt 2010-07-31 08:53
Pre-Run: 189,944,442,880 bytes free
Post-Run: 190,072,213,504 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - 29FD7BB82A2F041D1E0C216343CA3B48