Evilfantasy you are a star! Many thanks here is the log report
ComboFix 09-09-22.01 - Terry Bent 22/09/2009 14:11.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.254.97 [GMT -4:00]
Running from: c:\documents and settings\Terry Bent\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1351 [VPS 090921-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: COMODO Firewall *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Terry Bent\Application Data\0200000007dc7cf8517C.manifest
c:\documents and settings\Terry Bent\Application Data\0200000007dc7cf8517O.manifest
c:\documents and settings\Terry Bent\Application Data\0200000007dc7cf8517P.manifest
c:\documents and settings\Terry Bent\Application Data\0200000007dc7cf8517S.manifest
c:\documents and settings\Terry Bent\Application Data\0200000007dc7cf8530C.manifest
c:\documents and settings\Terry Bent\Application Data\0200000007dc7cf8530O.manifest
c:\documents and settings\Terry Bent\Application Data\0200000007dc7cf8530P.manifest
c:\documents and settings\Terry Bent\Application Data\0200000007dc7cf8530S.manifest
c:\documents and settings\Terry Bent\Application Data\0200000007dc7cf8669C.manifest
c:\documents and settings\Terry Bent\Application Data\0200000007dc7cf8669O.manifest
c:\documents and settings\Terry Bent\Application Data\0200000007dc7cf8669P.manifest
c:\documents and settings\Terry Bent\Application Data\0200000007dc7cf8669S.manifest
c:\program files\QUAD Utilities
c:\program files\QUAD Utilities\QUAD Registry Cleaner\Vista Scheduler.dll
c:\windows\Installer\10ee59.msp
c:\windows\Installer\10ee5c.msp
c:\windows\Installer\10ee5f.msp
c:\windows\Installer\123c16.msp
c:\windows\Installer\123c19.msp
c:\windows\Installer\123c1c.msp
c:\windows\Installer\123c1d.msp
c:\windows\Installer\123c20.msp
c:\windows\Installer\13240b.msp
c:\windows\Installer\13240e.msp
c:\windows\Installer\132411.msp
c:\windows\Installer\133d57b.msp
c:\windows\Installer\133d57e.msp
c:\windows\Installer\133d581.msp
c:\windows\Installer\13542e.msp
c:\windows\Installer\13f857c.msp
c:\windows\Installer\13f857f.msp
c:\windows\Installer\13f8582.msp
c:\windows\Installer\14a31f7.msp
c:\windows\Installer\14a31fa.msp
c:\windows\Installer\14a31fd.msp
c:\windows\Installer\150355.msp
c:\windows\Installer\150358.msp
c:\windows\Installer\15035b.msp
c:\windows\Installer\15b58e.msp
c:\windows\Installer\15b591.msp
c:\windows\Installer\15ce56.msp
c:\windows\Installer\15ce59.msp
c:\windows\Installer\15ce5c.msp
c:\windows\Installer\16b871c.msp
c:\windows\Installer\16b871f.msp
c:\windows\Installer\16b8722.msp
c:\windows\Installer\16d7c7.msp
c:\windows\Installer\16d7ca.msp
c:\windows\Installer\16d7cd.msp
c:\windows\Installer\17c3782.msp
c:\windows\Installer\17c3785.msp
c:\windows\Installer\17c3788.msp
c:\windows\Installer\17de88.msp
c:\windows\Installer\17de8b.msp
c:\windows\Installer\17de8e.msp
c:\windows\Installer\1846189.msp
c:\windows\Installer\184618c.msp
c:\windows\Installer\184618f.msp
c:\windows\Installer\18a7a5.msp
c:\windows\Installer\18a7a8.msp
c:\windows\Installer\18a7ab.msp
c:\windows\Installer\18ac87.msp
c:\windows\Installer\18ac8a.msp
c:\windows\Installer\18ac8d.msp
c:\windows\Installer\18ac8e.msp
c:\windows\Installer\18adff3.msp
c:\windows\Installer\18adff6.msp
c:\windows\Installer\18adff9.msp
c:\windows\Installer\195460.msp
c:\windows\Installer\195463.msp
c:\windows\Installer\195466.msp
c:\windows\Installer\1962e1d.msp
c:\windows\Installer\1962e20.msp
c:\windows\Installer\1962e23.msp
c:\windows\Installer\197ccca.msp
c:\windows\Installer\197cccd.msp
c:\windows\Installer\197ccd0.msp
c:\windows\Installer\198ecff.msp
c:\windows\Installer\198ed02.msp
c:\windows\Installer\198ed05.msp
c:\windows\Installer\19ea56.msp
c:\windows\Installer\19ea59.msp
c:\windows\Installer\19ea5c.msp
c:\windows\Installer\19ea5f.msp
c:\windows\Installer\19ea60.msp
c:\windows\Installer\1a237c8.msp
c:\windows\Installer\1a237cb.msp
c:\windows\Installer\1a237ce.msp
c:\windows\Installer\1a28aca.msp
c:\windows\Installer\1a28acd.msp
c:\windows\Installer\1a28ad0.msp
c:\windows\Installer\1a51ccd.msp
c:\windows\Installer\1a51cd0.msp
c:\windows\Installer\1a51d22.msp
c:\windows\Installer\1a6ec8.msp
c:\windows\Installer\1a6ecb.msp
c:\windows\Installer\1a6ece.msp
c:\windows\Installer\1a98559.msp
c:\windows\Installer\1a9855c.msp
c:\windows\Installer\1a9855f.msp
c:\windows\Installer\1aa682.msp
c:\windows\Installer\1aa685.msp
c:\windows\Installer\1aa688.msp
c:\windows\Installer\1aa689.msp
c:\windows\Installer\1aa68c.msp
c:\windows\Installer\1b4911b.msp
c:\windows\Installer\1b4911e.msp
c:\windows\Installer\1b49121.msp
c:\windows\Installer\1b8d87.msp
c:\windows\Installer\1b8d8a.msp
c:\windows\Installer\1b8d8d.msp
c:\windows\Installer\1b99c00.msp
c:\windows\Installer\1b99c03.msp
c:\windows\Installer\1b99c06.msp
c:\windows\Installer\1bb3eb.msp
c:\windows\Installer\1bb3ee.msp
c:\windows\Installer\1bb3f1.msp
c:\windows\Installer\1c1dcea.msp
c:\windows\Installer\1c1dced.msp
c:\windows\Installer\1c1dcf0.msp
c:\windows\Installer\1c24605.msp
c:\windows\Installer\1c24608.msp
c:\windows\Installer\1c2460b.msp
c:\windows\Installer\1c9756.msp
c:\windows\Installer\1c9759.msp
c:\windows\Installer\1c975c.msp
c:\windows\Installer\1c975f.msp
c:\windows\Installer\1c9760.msp
c:\windows\Installer\1cd154a.msp
c:\windows\Installer\1cd154d.msp
c:\windows\Installer\1cd1550.msp
c:\windows\Installer\1cff418.msp
c:\windows\Installer\1cff41b.msp
c:\windows\Installer\1cff41e.msp
c:\windows\Installer\1d6fe3.msp
c:\windows\Installer\1d6fe6.msp
c:\windows\Installer\1d6fe9.msp
c:\windows\Installer\1da77fd.msp
c:\windows\Installer\1da7800.msp
c:\windows\Installer\1da7803.msp
c:\windows\Installer\1e0af9a.msp
c:\windows\Installer\1e0af9d.msp
c:\windows\Installer\1e0afa0.msp
c:\windows\Installer\1e95662.msp
c:\windows\Installer\1e95665.msp
c:\windows\Installer\1e95668.msp
c:\windows\Installer\1ecccfb.msp
c:\windows\Installer\1eccd40.msp
c:\windows\Installer\1eccd43.msp
c:\windows\Installer\1f00d42.msp
c:\windows\Installer\1f00d45.msp
c:\windows\Installer\1f00d48.msp
c:\windows\Installer\1f2b148.msp
c:\windows\Installer\1f2b14b.msp
c:\windows\Installer\1f2b14e.msp
c:\windows\Installer\1f5c02e.msp
c:\windows\Installer\1f5c031.msp
c:\windows\Installer\1f5c034.msp
c:\windows\Installer\1ff0d1.msp
c:\windows\Installer\204f658.msp
c:\windows\Installer\204f65b.msp
c:\windows\Installer\204f65e.msp
c:\windows\Installer\2064c05.msp
c:\windows\Installer\2064c08.msp
c:\windows\Installer\2064c0b.msp
c:\windows\Installer\206dea0.msp
c:\windows\Installer\206dea3.msp
c:\windows\Installer\206dea6.msp
c:\windows\Installer\20c807.msp
c:\windows\Installer\20c80a.msp
c:\windows\Installer\20c80d.msp
c:\windows\Installer\20e109b.msp
c:\windows\Installer\20e109e.msp
c:\windows\Installer\20e10a1.msp
c:\windows\Installer\2169fe4.msp
c:\windows\Installer\2169fe7.msp
c:\windows\Installer\2169fea.msp
c:\windows\Installer\21a0ff5.msp
c:\windows\Installer\21a0ff8.msp
c:\windows\Installer\21a0ffb.msp
c:\windows\Installer\21fd5ec.msp
c:\windows\Installer\21fd5ef.msp
c:\windows\Installer\21fd5f2.msp
c:\windows\Installer\2217fa4.msp
c:\windows\Installer\2217fa7.msp
c:\windows\Installer\2217faa.msp
c:\windows\Installer\224fff.msp
c:\windows\Installer\225002.msp
c:\windows\Installer\225005.msp
c:\windows\Installer\2268a3b.msp
c:\windows\Installer\2268a3e.msp
c:\windows\Installer\2268a41.msp
c:\windows\Installer\2283e0.msp
c:\windows\Installer\2283e3.msp
c:\windows\Installer\2283e6.msp
c:\windows\Installer\229946e.msp
c:\windows\Installer\2299471.msp
c:\windows\Installer\2299474.msp
c:\windows\Installer\22a2a3.msp
c:\windows\Installer\22a2a6.msp
c:\windows\Installer\22d7df4.msp
c:\windows\Installer\22d7df7.msp
c:\windows\Installer\22d7dfa.msp
c:\windows\Installer\2305dac.msp
c:\windows\Installer\2305daf.msp
c:\windows\Installer\2305db2.msp
c:\windows\Installer\23b5e8.msp
c:\windows\Installer\23b5eb.msp
c:\windows\Installer\23b5ee.msp
c:\windows\Installer\2452958.msp
c:\windows\Installer\245295b.msp
c:\windows\Installer\245295e.msp
c:\windows\Installer\24c99a.msp
c:\windows\Installer\24c99d.msp
c:\windows\Installer\24c9a0.msp
c:\windows\Installer\251c98.msp
c:\windows\Installer\251c9b.msp
c:\windows\Installer\251c9c.msp
c:\windows\Installer\251c9f.msp
c:\windows\Installer\263b6a.msp
c:\windows\Installer\263b6d.msp
c:\windows\Installer\263b70.msp
c:\windows\Installer\263e0a.msp
c:\windows\Installer\263e0d.msp
c:\windows\Installer\263e10.msp
c:\windows\Installer\266b34.msp
c:\windows\Installer\272fbd.msp
c:\windows\Installer\272fc0.msp
c:\windows\Installer\272fc3.msp
c:\windows\Installer\276236.msp
c:\windows\Installer\276239.msp
c:\windows\Installer\27623c.msp
c:\windows\Installer\27623f.msp
c:\windows\Installer\276240.msp
c:\windows\Installer\27aceb.msp
c:\windows\Installer\27acee.msp
c:\windows\Installer\27acf1.msp
c:\windows\Installer\27acf2.msp
c:\windows\Installer\27acf5.msp
c:\windows\Installer\284e8a.msp
c:\windows\Installer\284e8d.msp
c:\windows\Installer\284e90.msp
c:\windows\Installer\28dcd0.msp
c:\windows\Installer\28dcd3.msp
c:\windows\Installer\28dcd6.msp
c:\windows\Installer\2975a9a.msp
c:\windows\Installer\2975a9d.msp
c:\windows\Installer\2975aa0.msp
c:\windows\Installer\2990bf.msp
c:\windows\Installer\2990c2.msp
c:\windows\Installer\2990c5.msp
c:\windows\Installer\2a61ca.msp
c:\windows\Installer\2a61cd.msp
c:\windows\Installer\2a61d0.msp
c:\windows\Installer\2a61d3.msp
c:\windows\Installer\2a61d4.msp
c:\windows\Installer\2a6cc7.msp
c:\windows\Installer\2a6cca.msp
c:\windows\Installer\2a6ccd.msp
c:\windows\Installer\2a6cce.msp
c:\windows\Installer\2a6cd1.msp
c:\windows\Installer\2ab048a.msp
c:\windows\Installer\2ab048d.msp
c:\windows\Installer\2ab0490.msp
c:\windows\Installer\2b3883.msp
c:\windows\Installer\2b3886.msp
c:\windows\Installer\2b3889.msp
c:\windows\Installer\2b388a.msp
c:\windows\Installer\2b388d.msp
c:\windows\Installer\2c20e0.msp
c:\windows\Installer\2c20e3.msp
c:\windows\Installer\2c20e6.msp
c:\windows\Installer\2d7498.msp
c:\windows\Installer\2d749b.msp
c:\windows\Installer\2d749e.msp
c:\windows\Installer\2e38f2.msp
c:\windows\Installer\2e38f5.msp
c:\windows\Installer\2e38f8.msp
c:\windows\Installer\2e38f9.msp
c:\windows\Installer\2e38fc.msp
c:\windows\Installer\2e7bc7.msp
c:\windows\Installer\2e7bca.msp
c:\windows\Installer\2e7bd4.msp
c:\windows\Installer\2f9fc5.msp
c:\windows\Installer\2f9fc8.msp
c:\windows\Installer\2f9fcb.msp
c:\windows\Installer\2ff25a.msp
c:\windows\Installer\300c5a.msp
c:\windows\Installer\300c5d.msp
c:\windows\Installer\300c60.msp
c:\windows\Installer\30489c6.msp
c:\windows\Installer\30489c9.msp
c:\windows\Installer\30489cc.msp
c:\windows\Installer\30a9f2.msp
c:\windows\Installer\30a9f5.msp
c:\windows\Installer\30a9f8.msp
c:\windows\Installer\31e521.msp
c:\windows\Installer\31e524.msp
c:\windows\Installer\31e527.msp
c:\windows\Installer\31e52a.msp
c:\windows\Installer\31e52b.msp
c:\windows\Installer\326cef.msp
c:\windows\Installer\326cf2.msp
c:\windows\Installer\326cf5.msp
c:\windows\Installer\326cf8.msp
c:\windows\Installer\326cf9.msp
c:\windows\Installer\32b7e3.msp
c:\windows\Installer\32b7e6.msp
c:\windows\Installer\32b7e9.msp
c:\windows\Installer\32b7ea.msp
c:\windows\Installer\32b7ed.msp
c:\windows\Installer\335df6.msp
c:\windows\Installer\335df9.msp
c:\windows\Installer\335dfc.msp
c:\windows\Installer\335dff.msp
c:\windows\Installer\335e00.msp
c:\windows\Installer\33da6a.msp
c:\windows\Installer\33da6d.msp
c:\windows\Installer\33da70.msp
c:\windows\Installer\345e20.msp
c:\windows\Installer\345e23.msp
c:\windows\Installer\345e26.msp
c:\windows\Installer\3730d8.msp
c:\windows\Installer\3730e5.msp
c:\windows\Installer\3730e8.msp
c:\windows\Installer\3730e9.msp
c:\windows\Installer\3730ec.msp
c:\windows\Installer\3793f7.msp
c:\windows\Installer\3793fa.msp
c:\windows\Installer\3793fd.msp
c:\windows\Installer\37efc3.msp
c:\windows\Installer\37efc6.msp
c:\windows\Installer\37efc7.msp
c:\windows\Installer\37efca.msp
c:\windows\Installer\38032c.msp
c:\windows\Installer\38032f.msp
c:\windows\Installer\380332.msp
c:\windows\Installer\380335.msp
c:\windows\Installer\380336.msp
c:\windows\Installer\386cf2.msp
c:\windows\Installer\386cf5.msp
c:\windows\Installer\386cf8.msp
c:\windows\Installer\3b83c7.msp
c:\windows\Installer\3b83ca.msp
c:\windows\Installer\3b83cd.msp
c:\windows\Installer\3c9d07.msp
c:\windows\Installer\3c9d0a.msp
c:\windows\Installer\3c9d0d.msp
c:\windows\Installer\3d5ff9.msp
c:\windows\Installer\3d5ffc.msp
c:\windows\Installer\3d5fff.msp
c:\windows\Installer\3d6000.msp
c:\windows\Installer\3d6003.msp
c:\windows\Installer\3e43b2.msp
c:\windows\Installer\3e43b5.msp
c:\windows\Installer\3e43b8.msp
c:\windows\Installer\3e43bb.msp
c:\windows\Installer\3e43bc.msp
c:\windows\Installer\3eba49.msp
c:\windows\Installer\3eba4c.msp
c:\windows\Installer\3eba55.msp
c:\windows\Installer\3eea43.msp
c:\windows\Installer\3eea46.msp
c:\windows\Installer\3eea49.msp
c:\windows\Installer\3eea4a.msp
c:\windows\Installer\3eea4d.msp
c:\windows\Installer\3f5fff.msp
c:\windows\Installer\3f6002.msp
c:\windows\Installer\3f6005.msp
c:\windows\Installer\3f6006.msp
c:\windows\Installer\3f6009.msp
c:\windows\Installer\4244b8.msp
c:\windows\Installer\4244bb.msp
c:\windows\Installer\4244be.msp
c:\windows\Installer\4244c1.msp
c:\windows\Installer\4244c2.msp
c:\windows\Installer\428bf3.msp
c:\windows\Installer\428bf6.msp
c:\windows\Installer\428bf9.msp
c:\windows\Installer\4300b5.msp
c:\windows\Installer\4300b8.msp
c:\windows\Installer\4300bb.msp
c:\windows\Installer\43aa49d.msp
c:\windows\Installer\43aa49e.msp
c:\windows\Installer\43aa49f.msp
c:\windows\Installer\43aa4a0.msp
c:\windows\Installer\43aa4a1.msp
c:\windows\Installer\45e8ba.msp
c:\windows\Installer\45e8bd.msp
c:\windows\Installer\45e8c0.msp
c:\windows\Installer\45e8c1.msp
c:\windows\Installer\45e8c4.msp
c:\windows\Installer\4607bc.msp
c:\windows\Installer\4607bf.msp
c:\windows\Installer\4607c2.msp
c:\windows\Installer\4623ee.msp
c:\windows\Installer\4623f1.msp
c:\windows\Installer\4623f4.msp
c:\windows\Installer\482f7e.msp
c:\windows\Installer\482f81.msp
c:\windows\Installer\482f84.msp
c:\windows\Installer\482f87.msp
c:\windows\Installer\482f88.msp
c:\windows\Installer\493804.msp
c:\windows\Installer\493807.msp
c:\windows\Installer\49380a.msp
c:\windows\Installer\49380b.msp
c:\windows\Installer\49380e.msp
c:\windows\Installer\495e2a.msp
c:\windows\Installer\495e2d.msp
c:\windows\Installer\495e30.msp
c:\windows\Installer\49fc2f.msp
c:\windows\Installer\49fc32.msp
c:\windows\Installer\49fc35.msp
c:\windows\Installer\4bf31d.msp
c:\windows\Installer\4bf320.msp
c:\windows\Installer\4bf323.msp
c:\windows\Installer\4bf324.msp
c:\windows\Installer\4bf327.msp
c:\windows\Installer\4cf664.msp
c:\windows\Installer\4cf667.msp
c:\windows\Installer\4cf66a.msp
c:\windows\Installer\4dccbf.msp
c:\windows\Installer\4dccc2.msp
c:\windows\Installer\4dccc5.msp
c:\windows\Installer\4dff87.msp
c:\windows\Installer\4dff8a.msp
c:\windows\Installer\4dff8d.msp
c:\windows\Installer\4fbb8f.msp
c:\windows\Installer\4fbb92.msp
c:\windows\Installer\4fbb95.msp
c:\windows\Installer\4fbb98.msp
c:\windows\Installer\4fbb99.msp
c:\windows\Installer\509768.msp
c:\windows\Installer\50976b.msp
c:\windows\Installer\50976e.msp
c:\windows\Installer\51d334.msp
c:\windows\Installer\51d337.msp
c:\windows\Installer\51d33a.msp
c:\windows\Installer\51d33b.msp
c:\windows\Installer\51d33e.msp
c:\windows\Installer\51ec69.msp
c:\windows\Installer\51ec6c.msp
c:\windows\Installer\51ec6f.msp
c:\windows\Installer\51ec72.msp
c:\windows\Installer\51ec73.msp
c:\windows\Installer\53bdbe.msp
c:\windows\Installer\53bdc1.msp
c:\windows\Installer\53bdc4.msp
c:\windows\Installer\53bdc5.msp
c:\windows\Installer\53bdc8.msp
c:\windows\Installer\571584.msp
c:\windows\Installer\571587.msp
c:\windows\Installer\57158a.msp
c:\windows\Installer\57158b.msp
c:\windows\Installer\57158e.msp
c:\windows\Installer\57a9f4.msp
c:\windows\Installer\57a9f7.msp
c:\windows\Installer\57a9fa.msp
c:\windows\Installer\57a9fb.msp
c:\windows\Installer\57a9fe.msp
c:\windows\Installer\5a6b66.msp
c:\windows\Installer\5a6b69.msp
c:\windows\Installer\5a6b6c.msp
c:\windows\Installer\5cd66b.msp
c:\windows\Installer\5f69d7.msp
c:\windows\Installer\5f69da.msp
c:\windows\Installer\5f69dd.msp
c:\windows\Installer\5f69de.msp
c:\windows\Installer\5f69e1.msp
c:\windows\Installer\60df41.msp
c:\windows\Installer\60df44.msp
c:\windows\Installer\60df47.msp
c:\windows\Installer\60df48.msp
c:\windows\Installer\60df4b.msp
c:\windows\Installer\611db1.msp
c:\windows\Installer\611db4.msp
c:\windows\Installer\611db7.msp
c:\windows\Installer\611db8.msp
c:\windows\Installer\611dbb.msp
c:\windows\Installer\63e6b5.msp
c:\windows\Installer\63e6b8.msp
c:\windows\Installer\63e6bb.msp
c:\windows\Installer\63fb17.msp
c:\windows\Installer\63fb1a.msp
c:\windows\Installer\63fb1d.msp
c:\windows\Installer\63fb1e.msp
c:\windows\Installer\63fb21.msp
c:\windows\Installer\664e9c.msp
c:\windows\Installer\664e9f.msp
c:\windows\Installer\664ea2.msp
c:\windows\Installer\664ea3.msp
c:\windows\Installer\664ea6.msp
c:\windows\Installer\6d34e8.msp
c:\windows\Installer\6d34eb.msp
c:\windows\Installer\6d34ee.msp
c:\windows\Installer\7646a0.msp
c:\windows\Installer\7646a3.msp
c:\windows\Installer\7646a6.msp
c:\windows\Installer\86e255.msp
c:\windows\Installer\86e258.msp
c:\windows\Installer\86e25b.msp
c:\windows\Installer\883f74.msp
c:\windows\Installer\883f77.msp
c:\windows\Installer\883f7a.msp
c:\windows\Installer\8b9f0a.msp
c:\windows\Installer\8b9f0d.msp
c:\windows\Installer\8b9f10.msp
c:\windows\Installer\90e1a9.msp
c:\windows\Installer\90e1ac.msp
c:\windows\Installer\90e1af.msp
c:\windows\Installer\90e1b0.msp
c:\windows\Installer\90e1b3.msp
c:\windows\Installer\91c63c.msp
c:\windows\Installer\91c63f.msp
c:\windows\Installer\a4a1d0.msp
c:\windows\Installer\a4a1d3.msp
c:\windows\Installer\a4a1d6.msp
c:\windows\Installer\a8414d.msp
c:\windows\Installer\a84150.msp
c:\windows\Installer\a84153.msp
c:\windows\Installer\a84156.msp
c:\windows\Installer\a84157.msp
c:\windows\Installer\b5f6b3.msp
c:\windows\Installer\b5f6b6.msp
c:\windows\Installer\b5f6b9.msp
c:\windows\Installer\b5f6ba.msp
c:\windows\Installer\b5f6bd.msp
c:\windows\Installer\bd8a7.msp
c:\windows\Installer\bd8aa.msp
c:\windows\Installer\bd8ad.msp
c:\windows\Installer\bf320b.msp
c:\windows\Installer\bf320e.msp
c:\windows\Installer\bf3211.msp
c:\windows\Installer\e6194.msp
c:\windows\Installer\e6197.msp
c:\windows\Installer\e619a.msp
c:\windows\Installer\f206.msi
c:\windows\system32\puaB6lr.vbs
c:\windows\system32\RIxS9VW6iU5Wx.vbs
c:\windows\system32\WSjCbgaGG4fhN8N.vbs
.
((((((((((((((((((((((((( Files Created from 2009-08-22 to 2009-09-22 )))))))))))))))))))))))))))))))
.
2009-09-21 20:01 . 2009-09-21 20:01 -------- d-----w- c:\program files\Trend Micro
2009-09-21 17:07 . 2009-09-21 17:07 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-09-21 17:06 . 2009-09-21 17:06 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-09-21 17:06 . 2009-09-21 17:06 -------- d-----w- c:\documents and settings\Terry Bent\Application Data\SUPERAntiSpyware.com
2009-09-21 17:05 . 2009-09-21 17:05 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-09-21 16:37 . 2009-09-21 16:38 -------- d-----w- c:\program files\CCleaner
2009-09-21 14:14 . 2009-09-21 14:17 -------- d-----w- C:\e04d35a4b1bff03a60
2009-09-21 13:57 . 2009-09-21 14:04 -------- d-----w- c:\program files\Ace Utilities
2009-09-20 15:21 . 2009-09-20 15:21 604488 ----a-w- c:\windows\system32\TUProgSt.exe
2009-09-20 15:20 . 2009-09-20 15:20 -------- d-----w- c:\documents and settings\Terry Bent\Application Data\TuneUp Software
2009-09-20 15:18 . 2009-09-20 15:18 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
2009-09-20 15:18 . 2009-09-21 19:31 -------- d-----w- c:\program files\TuneUp Utilities 2009
2009-09-20 15:17 . 2009-09-20 15:17 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
2009-09-19 16:47 . 2009-09-19 16:47 -------- d-----w- c:\documents and settings\Terry Bent\Local Settings\Application Data\Opera
2009-09-19 16:45 . 2009-09-19 18:19 -------- d-----w- c:\program files\Opera
2009-09-16 14:12 . 2009-09-21 13:54 -------- d-----w- c:\documents and settings\Terry Bent\Incomplete
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-21 19:57 . 2004-12-21 05:06 -------- d-----w- c:\program files\Java
2009-09-21 14:04 . 2009-08-08 15:55 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-21 13:55 . 2009-01-22 18:35 -------- d-----w- c:\documents and settings\Terry Bent\Application Data\LimeWire
2009-09-19 17:13 . 2009-08-18 14:09 179792 ----a-w- c:\windows\system32\guard32.dll
2009-09-19 17:13 . 2009-08-18 14:09 87104 ----a-w- c:\windows\system32\drivers\inspect.sys
2009-09-19 17:13 . 2009-08-18 14:09 25160 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2009-09-19 17:13 . 2009-08-18 14:09 132296 ----a-w- c:\windows\system32\drivers\cmdguard.sys
2009-09-17 14:09 . 2009-01-08 15:56 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-16 14:27 . 2009-09-16 14:27 0 ----a-w- c:\windows\system32\18C.tmp
2009-09-10 18:54 . 2009-01-08 15:56 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 18:53 . 2009-01-08 15:56 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-23 21:38 . 2009-01-08 18:55 74824 ----a-w- c:\documents and settings\Terry Bent\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-19 15:18 . 2009-08-19 15:00 -------- d-----w- c:\program files\Password Solutions
2009-08-19 15:00 . 2009-08-19 15:00 -------- d-----w- c:\documents and settings\Terry Bent\Application Data\Password Solutions
2009-08-18 16:52 . 2009-08-18 16:50 -------- d-----w- c:\program files\iTunes
2009-08-18 16:51 . 2009-08-18 16:51 -------- d-----w- c:\program files\iPod
2009-08-18 16:51 . 2009-04-07 20:09 -------- d-----w- c:\program files\Common Files\Apple
2009-08-18 15:26 . 2009-08-18 14:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Comodo
2009-08-18 14:08 . 2009-08-18 14:08 -------- d-----w- c:\program files\COMODO
2009-08-18 13:05 . 2009-08-18 13:05 -------- d-----w- c:\program files\MSBuild
2009-08-18 13:05 . 2009-08-18 13:05 -------- d-----w- c:\program files\Reference Assemblies
2009-08-17 16:10 . 2009-01-29 13:17 1279456 ----a-w- c:\windows\system32\aswBoot.exe
2009-08-17 16:06 . 2009-01-29 13:18 93392 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-08-17 16:06 . 2009-01-29 13:18 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-08-17 16:05 . 2009-01-29 13:18 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-08-17 16:05 . 2009-01-29 13:18 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-08-17 16:04 . 2009-01-29 13:18 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-08-17 16:04 . 2009-01-29 13:18 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-08-17 16:03 . 2009-01-29 13:18 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-08-17 16:02 . 2009-01-29 13:18 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-08-17 13:20 . 2009-05-09 13:49 294912 ----a-w- c:\windows\uninst.exe
2009-08-16 16:04 . 2009-08-16 16:04 -------- d-----w- c:\program files\MySQL
2009-08-13 13:38 . 2009-08-13 13:38 -------- d-----w- c:\documents and settings\Terry Bent\Application Data\Unyk
2009-08-13 13:38 . 2009-08-13 13:36 -------- d-----w- c:\program files\Unyk Syncro
2009-08-12 14:13 . 2009-08-08 14:47 -------- d-----w- c:\program files\Lavasoft
2009-08-12 14:13 . 2009-08-08 14:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-08-08 16:54 . 2009-08-08 16:54 -------- d-----r- c:\program files\Skype
2009-08-08 16:54 . 2009-01-09 15:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-08-08 16:54 . 2009-08-08 16:54 -------- d-----w- c:\program files\Common Files\Skype
2009-08-08 15:44 . 2009-08-08 15:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-08-08 15:43 . 2009-08-08 15:43 -------- d-----w- c:\program files\Google
2009-08-05 09:01 . 2004-08-04 11:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 14:12 . 2009-08-04 14:11 -------- d-----w- c:\program files\Analog Devices
2009-08-04 14:11 . 2004-12-21 05:07 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-03 18:52 . 2009-08-03 18:44 -------- d-----w- c:\program files\Driver Checker
2009-07-31 19:23 . 2009-01-22 18:32 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-31 16:14 . 2009-01-09 18:23 -------- d-----w- c:\program files\Microsoft ActiveSync
2009-07-31 13:58 . 2009-01-22 18:20 -------- d-----w- c:\program files\LimeWire
2009-07-29 12:32 . 2009-07-29 12:32 -------- d-----w- c:\documents and settings\Terry Bent\Application Data\iolo
2009-07-29 12:32 . 2009-07-29 12:32 -------- d-----w- c:\documents and settings\All Users\Application Data\iolo
2009-07-25 15:18 . 2009-07-02 14:07 -------- d-----w- c:\documents and settings\Terry Bent\Application Data\Facebook
2009-07-17 19:01 . 2004-08-04 11:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 03:43 . 2004-08-04 11:00 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-06-29 16:12 . 2004-08-04 11:00 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2004-08-04 11:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2004-08-04 11:00 17408 ----a-w- c:\windows\system32\corpol.dll
2009-06-25 08:25 . 2004-08-04 11:00 730112 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2004-08-04 11:00 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2004-08-04 11:00 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2004-08-04 11:00 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:25 . 2004-08-04 11:00 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2004-08-04 11:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2004-07-19 306688]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-08-13 122939]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2005-03-17 57393]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2005-03-17 40960]
"SetDefPrt"="c:\program files\Brother\Brmfl06a\BrStDvPt.exe" [2005-01-26 49152]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2006-04-10 61440]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2009-09-19 1799952]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-31 149280]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\SYSTEM32\guard32.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk]
backup=c:\windows\pss\KODAK Software Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Terry Bent^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk]
backup=c:\windows\pss\OpenOffice.org 3.1.lnkStartup
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
"swg"=c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe"
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"LogitechVideoRepair"=c:\program files\Logitech\Video\ISStart.exe
"LogitechVideoTray"=c:\program files\Logitech\Video\LogiTray.exe
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" /r
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
"BrMfcWnd"=c:\program files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 aswSP;avast! Self Protection;c:\windows\SYSTEM32\DRIVERS\aswSP.sys [29/01/2009 09:18 114768]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\SYSTEM32\DRIVERS\cmdguard.sys [18/08/2009 10:09 132296]
R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\SYSTEM32\DRIVERS\cmdhlp.sys [18/08/2009 10:09 25160]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [15/09/2009 11:42 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [15/09/2009 11:42 74480]
R2 aswFsBlk;aswFsBlk;c:\windows\SYSTEM32\DRIVERS\aswFsBlk.sys [29/01/2009 09:18 20560]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [15/09/2009 11:42 7408]
S3 tap0801;Smarthide TAP driver;c:\windows\SYSTEM32\DRIVERS\tap0801.sys [12/10/2007 09:07 55808]
.
Contents of the 'Scheduled Tasks' folder
2009-09-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2009-09-22 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-08-08 15:43]
2009-09-22 c:\windows\Tasks\Unyk Outlook Sync Client - Terry Bent.job
- c:\program files\Unyk Syncro\OutlookPlugin.exe [2009-07-20 14:42]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.uk/
mStart Page = hxxp://www.google.com
mWindow Title =
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
DPF: {774FE9E1-A8F8-4A40-9706-8F673D8DB6ED} - hxxp://www.unyk.com/Diffusion/ActiveX/UNYKContactsFinder.cab
FF - ProfilePath - c:\documents and settings\Terry Bent\Application Data\Mozilla\Firefox\Profiles\jke6s4j4.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk
FF - prefs.js: network.proxy.type - 4
FF - component: c:\program files\Real\RealPlayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1636.7222\npCIDetect13.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
- - - - ORPHANS REMOVED - - - -
Notify-64b8c927517 - (no file)
Notify-64b8c927530 - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-09-22 14:20
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•A~*]
"AB141C35E9F4BF344B9FC010BB17F68A"=""
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(884)
c:\windows\system32\guard32.dll
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
- - - - - - - > 'lsass.exe'(956)
c:\windows\system32\guard32.dll
.
Completion time: 2009-09-22 14:23
ComboFix-quarantined-files.txt 2009-09-22 18:23
Pre-Run: 19,539,779,584 bytes free
Post-Run: 19,594,760,192 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
762 --- E O F --- 2009-09-22 13:07