Requested Txt files
View attachment checkup.txt
ComboFix 10-08-25.01 - Philip Moore 08/26/2010 7:47.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1403 [GMT -7:00]
Running from: c:\documents and settings\Philip Moore\My Documents\Downloads\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
Other Deletions
c:\documents and settings\All Users\Application Data\page
c:\documents and settings\All Users\Application Data\page\page.ico
c:\documents and settings\All Users\Application Data\page\page.URL
c:\program files\INSTALL.LOG
c:\program files\PC Doc Pro v5
c:\program files\PC Doc Pro v5\Log.txt
c:\program files\PC Doc Pro v5\PC Doc Pro.ini
c:\windows\a3kebook.ini
c:\windows\akebook.ini
c:\windows\ANS2000.INI
c:\windows\system32\csftxctl.ocx
.
((((((((((((((((((((((((( Files Created from 2010-07-26 to 2010-08-26 )))))))))))))))))))))))))))))))
.
2010-08-26 14:40 . 2008-05-02 16:26 1414440 ----a-w- c:\windows\system32\ShellManager310E2D762.dll
2010-08-26 00:52 . 2010-08-26 00:52 -------- d-----w- c:\documents and settings\Philip Moore\Application Data\Auslogics
2010-08-22 12:22 . 2010-08-25 00:37 -------- d-----w- c:\program files\Anti Trojan Elite
2010-08-21 23:07 . 2010-08-21 23:07 -------- d-----w- c:\documents and settings\Philip Moore\Local Settings\Application Data\Sunbelt Software
2010-08-18 12:30 . 2010-08-22 14:29 -------- d-----w- c:\program files\NetworkView36
2010-08-17 12:47 . 2010-08-17 15:23 -------- d-----w- c:\documents and settings\Philip Moore\Local Settings\Application Data\CutePDF Writer
2010-08-17 12:44 . 2009-11-05 15:39 87552 ----a-w- c:\windows\system32\cpwmon2k.dll
2010-08-17 12:44 . 2010-08-17 12:44 -------- d-----w- c:\program files\Acro Software
2010-08-17 12:22 . 2010-08-17 12:23 -------- d-----w- c:\program files\gs
2010-08-12 18:29 . 2010-08-12 18:29 2772992 ----a-w- c:\windows\system32\GPhotos.scr
2010-08-04 13:10 . 2010-07-27 05:30 705208 ----a-w- c:\documents and settings\Philip Moore\Application Data\Mozilla\Firefox\Profiles\yloszscu.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll
2010-08-04 13:10 . 2010-07-27 05:30 978664 ----a-w- c:\documents and settings\Philip Moore\Application Data\Mozilla\Firefox\Profiles\yloszscu.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
2010-07-30 13:31 . 2010-07-29 01:27 1833576 ----a-w- c:\windows\SkyTel.exe
2010-07-30 13:31 . 2010-07-29 01:27 1489512 ----a-w- c:\windows\RtlUpd.exe
2010-07-30 13:31 . 2010-07-29 01:27 53864 ----a-w- c:\windows\system32\RtkCoInstXP.dll
2010-07-30 13:31 . 2010-07-27 20:54 1251944 ----a-w- c:\windows\RtlExUpd.dll
2010-07-30 13:18 . 2010-01-12 20:35 100896 ----a-w- c:\windows\system32\RTNUninst32.dll
2010-07-30 13:05 . 2010-07-30 13:05 -------- d-----w- c:\program files\SmartTweak Software
2010-07-30 12:55 . 2010-07-30 12:55 -------- d-----w- c:\documents and settings\Philip Moore\Application Data\NVIDIA
2010-07-30 12:54 . 2010-08-24 22:56 -------- d-----w- c:\documents and settings\Philip Moore\Local Settings\Application Data\MotionDSP
2010-07-30 12:54 . 2010-08-24 22:56 -------- d-----w- c:\documents and settings\Philip Moore\Application Data\MotionDSP
2010-07-30 12:39 . 2010-07-30 12:42 -------- d-----w- c:\documents and settings\Philip Moore\Application Data\Smart PC Solutions
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-26 14:40 . 2009-02-15 17:56 -------- d-----w- c:\program files\Common Files\Nero
2010-08-26 14:40 . 2009-02-15 17:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Nero
2010-08-26 14:38 . 2009-02-24 12:46 -------- d-----w- c:\program files\filehippo.com
2010-08-26 14:25 . 2010-03-30 14:43 -------- d-----w- c:\program files\PCPitstop
2010-08-26 14:24 . 2009-02-15 20:14 -------- d-----w- c:\program files\Google
2010-08-26 14:22 . 2009-02-15 17:42 16608 ----a-w- c:\windows\gdrv.sys
2010-08-26 14:21 . 2010-06-23 12:27 4167424 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-08-26 13:57 . 2009-03-26 13:32 -------- d-----w- c:\program files\Yahoo!
2010-08-26 13:57 . 2009-08-06 21:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2010-08-26 13:00 . 2010-04-29 21:23 63488 ----a-w- c:\documents and settings\Philip Moore\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-08-26 13:00 . 2009-10-31 11:14 117760 ----a-w- c:\documents and settings\Philip Moore\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-08-25 22:29 . 2009-02-19 22:59 -------- d-----w- c:\program files\ICQ
2010-08-25 14:20 . 2009-11-17 16:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-08-25 14:18 . 2009-03-05 14:39 -------- d-----w- c:\program files\Common Files\aol
2010-08-24 22:58 . 2009-03-18 14:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-08-24 22:55 . 2009-11-15 14:48 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-08-24 16:23 . 2010-03-24 12:56 -------- d-----w- c:\documents and settings\Philip Moore\Application Data\QuickScan
2010-08-21 23:06 . 2009-02-15 18:27 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-08-21 23:04 . 2009-02-15 19:00 -------- d-----w- c:\program files\CCleaner
2010-08-16 12:48 . 2010-06-18 12:03 -------- d-----w- c:\program files\Auslogics
2010-08-14 20:29 . 2009-02-15 20:02 -------- d-----w- c:\program files\nLite
2010-08-14 20:21 . 2010-02-16 13:24 -------- d-----w- c:\program files\BSR Screen Recorder 4
2010-08-11 13:16 . 2009-02-15 17:45 -------- d-----w- c:\program files\Realtek
2010-08-08 23:48 . 2010-01-05 17:28 -------- d-----w- c:\program files\Last.fm
2010-08-07 11:56 . 2010-07-09 13:09 -------- d-----w- c:\program files\MSN Toolbar Installer
2010-08-02 12:20 . 2009-11-13 13:24 -------- d-----w- c:\documents and settings\Philip Moore\Application Data\CBS Interactive
2010-08-01 19:04 . 2009-02-15 20:10 34744 ----a-w- c:\documents and settings\Philip Moore\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-08-01 12:12 . 2010-05-04 13:53 -------- d-----w- c:\program files\MSECACHE
2010-07-31 12:47 . 2010-03-17 20:05 -------- d-----w- c:\documents and settings\All Users\Application Data\TrackMania
2010-07-31 11:43 . 2010-07-26 13:04 -------- d-----w- c:\program files\Free Window Registry Repair
2010-07-30 12:58 . 2010-06-18 12:07 233696 ----a-w- c:\windows\system32\nvdrsdb1.bin
2010-07-30 12:58 . 2010-06-18 12:07 1 ----a-w- c:\windows\system32\nvdrssel.bin
2010-07-30 12:58 . 2010-06-18 12:07 233696 ----a-w- c:\windows\system32\nvdrsdb0.bin
2010-07-29 13:03 . 2010-05-31 13:36 -------- d-----w- c:\documents and settings\Philip Moore\Application Data\AVS4YOU
2010-07-29 01:27 . 2009-05-12 13:57 359016 ----a-w- c:\windows\vncutil.exe
2010-07-29 01:27 . 2009-02-15 17:46 84584 ----a-w- c:\windows\SOUNDMAN.EXE
2010-07-29 01:27 . 2009-02-15 17:46 9721960 ----a-w- c:\windows\RTLCPL.EXE
2010-07-29 01:27 . 2009-02-15 17:46 6108776 ----a-w- c:\windows\system32\drivers\RtkHDAud.sys
2010-07-29 01:27 . 2009-05-12 13:57 129640 ----a-w- c:\windows\RtkAudioService.exe
2010-07-29 01:27 . 2009-02-15 17:45 19557480 ----a-w- c:\windows\RTHDCPL.EXE
2010-07-29 01:27 . 2009-02-15 17:45 2180712 ----a-w- c:\windows\MicCal.exe
2010-07-29 01:27 . 2009-03-28 13:58 64104 ----a-w- c:\windows\ALCMTR.EXE
2010-07-29 01:27 . 2009-02-15 17:45 2815592 ----a-w- c:\windows\ALCWZRD.EXE
2010-07-26 13:27 . 2010-07-26 13:27 -------- d-----w- c:\program files\3B Software
2010-07-26 12:47 . 2010-07-26 12:40 -------- d-----w- c:\documents and settings\Philip Moore\Application Data\Error Fix
2010-07-26 12:43 . 2010-07-26 12:39 -------- d-----w- c:\program files\Error Fix
2010-07-23 14:29 . 2009-02-24 13:06 -------- d-----w- c:\program files\Virtual Earth 3D
2010-07-23 13:06 . 2009-02-15 18:27 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-07-23 13:05 . 2009-03-04 13:59 -------- d-----w- c:\program files\NVIDIA Corporation
2010-07-17 12:42 . 2010-07-09 11:54 -------- d-----w- c:\program files\Ask.com
2010-07-17 12:18 . 2010-07-09 12:27 -------- d-----w- c:\program files\Mozilla Firefox 4.0 Beta 1
2010-07-16 18:34 . 2009-02-15 22:08 -------- d-----w- c:\documents and settings\Philip Moore\Application Data\LimeWire
2010-07-16 18:34 . 2010-03-29 18:27 -------- d-----w- c:\documents and settings\All Users\Application Data\STOPzilla!
2010-07-13 18:54 . 2010-07-13 18:09 -------- d-----w- c:\program files\AOL 9.1
2010-07-13 18:11 . 2009-02-15 18:20 -------- d-----w- c:\documents and settings\Philip Moore\Application Data\AOL
2010-07-13 18:11 . 2009-02-15 18:19 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL
2010-07-13 18:11 . 2010-07-13 18:09 -------- d-----w- c:\program files\Common Files\aolshare
2010-07-13 18:09 . 2009-11-21 15:46 711392 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4334.34.7\comps\sysinfo\SinfInst.exe
2010-07-13 18:09 . 2009-02-15 18:12 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL Downloads
2010-07-13 18:08 . 2009-11-21 15:46 607392 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4334.34.7\comps\tpspd\wbsetup.exe
2010-07-13 18:08 . 2009-11-21 15:46 260040 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4334.34.7\comps\acs\ecuinst.exe
2010-07-13 18:08 . 2009-11-21 15:46 15920 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4334.34.7\comps\ccu\ocpchk.dll
2010-07-13 18:08 . 2009-11-21 15:46 6144 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4334.34.7\comps\afix\ocfcheck.dll
2010-07-13 18:04 . 2009-11-21 15:46 2439824 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4334.34.7\comps\ccu\ocpinsti.exe
2010-07-13 18:04 . 2009-11-21 15:46 11312 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4334.34.7\comps\acs\ecuchk.dll
2010-07-13 18:04 . 2009-11-21 15:46 1893728 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4334.34.7\waol-0.4334.34.7.exe
2010-07-13 18:03 . 2009-11-21 15:45 1475416 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4334.34.7\comps\ocp\ocpinst.exe
2010-07-13 18:03 . 2009-11-21 15:45 45056 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4334.34.7\comps\sysinfo\SiNdInst.dll
2010-07-13 18:03 . 2009-11-21 15:45 67120 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4334.34.7\comps\ccu\instSup.dll
2010-07-13 18:03 . 2009-11-21 15:45 61440 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4334.34.7\comps\vwpt\VPPrePop.exe
2010-07-13 18:03 . 2009-11-21 15:45 54832 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4334.34.7\comps\parcon\AOLParconLink.exe
2010-07-13 18:03 . 2009-11-21 15:44 8139800 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4334.34.7\comps\acs\acssetup.exe
2010-07-13 18:02 . 2009-11-21 15:44 99256 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4334.34.7\comps\sm\sminstlp.exe
2010-07-13 18:02 . 2009-11-21 15:44 62816 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4334.34.7\comps\ocp\ocpgc.exe
2010-07-13 18:02 . 2009-11-21 15:44 1134216 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4334.34.7\comps\flash\flash9ex.exe
2010-07-13 18:02 . 2009-11-21 15:44 75104 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4334.34.7\comps\ocp\instSup.dll
2010-07-13 18:02 . 2009-11-21 15:44 10800 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4334.34.7\comps\afix\wsfixchk.dll
2010-07-13 18:02 . 2009-11-21 15:44 223152 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4334.34.7\comps\afix\wsfinst.exe
2010-07-13 18:02 . 2009-11-21 15:44 359184 ----a-w- c:\documents and settings\All Users\Application Data\AOL Downloads\waol\0.4334.34.7\comps\tb\tbsetup.exe
2010-07-12 14:12 . 2010-07-12 14:12 -------- d-----w- c:\program files\Microsoft IntelliPoint
2010-07-12 14:07 . 2010-07-12 14:07 23456 ----a-w- c:\windows\system32\drivers\DrvAgent32.sys
2010-07-12 12:38 . 2010-07-12 12:38 -------- d-----w- c:\program files\Common Files\Java
2010-07-12 12:37 . 2010-05-04 13:47 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-11 11:45 . 2010-07-11 11:45 2944904 ----a-w- c:\documents and settings\Philip Moore\Application Data\Mozilla\Firefox\Profiles\yloszscu.default\extensions\toolbar@ask.com\chrome\temp\askToolbar.exe
2010-07-10 12:49 . 2010-01-01 15:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Wondershare
2010-07-10 12:48 . 2009-11-30 19:12 -------- d-----w- c:\program files\Wondershare
2010-07-09 23:24 . 2010-07-09 23:24 81920 ----a-w- c:\windows\system32\nvwddi.dll
2010-07-09 23:24 . 2010-07-09 23:24 277608 ----a-w- c:\windows\system32\nvmccs.dll
2010-07-09 23:24 . 2010-07-09 23:24 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-07-09 23:24 . 2010-07-09 23:24 155752 ----a-w- c:\windows\system32\nvsvc32.exe
2010-07-09 23:24 . 2010-07-09 23:24 145000 ----a-w- c:\windows\system32\nvcolor.exe
2010-07-09 23:24 . 2010-07-09 23:24 13923432 ----a-w- c:\windows\system32\nvcpl.dll
2010-07-09 22:28 . 2009-03-01 16:29 32036 ---ha-w- c:\windows\system32\mlfcache.dat
2010-07-09 13:39 . 2009-11-20 15:46 -------- d-----w- c:\documents and settings\All Users\Application Data\ParetoLogic
2010-07-09 13:39 . 2009-11-20 15:46 -------- d-----w- c:\documents and settings\All Users\Application Data\DriverCure
2010-07-09 13:09 . 2010-07-09 13:09 -------- d-----w- c:\program files\MSN Toolbar
2010-07-09 12:18 . 2010-07-09 12:18 0 ---ha-w- c:\windows\system32\drivers\Msft_User_ZuneDriver_01_09_00.Wdf
2010-07-09 12:18 . 2010-07-09 12:18 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_WinUSB_01009.Wdf
2010-07-09 12:18 . 2010-07-09 12:18 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_user_01_09_00.Wdf
2010-07-07 20:46 . 2009-11-20 15:20 604776 ----a-w- c:\windows\system32\nvuninst.exe
2010-08-22 14:58 . 2010-08-22 14:58 101768 ----a-w- c:\program files\mozilla firefox\plugins\ieatgpc.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"AOL Fast Start"="c:\program files\AOL 9.1\AOL.EXE" [2008-06-03 50528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-07-09 13923432]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2009-09-29 03:34 87352 ----a-w- c:\windows\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^Philip Moore^Start Menu^Programs^Startup^Y'z Toolbar.lnk]
backup=c:\windows\pss\Y'z Toolbar.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-06-09 08:06 976832 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-06-20 02:04 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
2007-10-26 01:10 652624 ----a-w- c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ----a-w- c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FreeRAM XP]
2006-03-23 08:13 1591808 ----a-w- c:\program files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GBTUpd]
2008-04-03 18:01 297480 ----a-w- c:\program files\GIGABYTE\GBTUpd\PreRun.exe
PART ONE OF COMBO FIX. SEND SECOND PART DIRECTLY