Hi,
My Threatfire started up again after the combofix restarted the computer and it caused it to lock up, but I re ran it and the report shows both runs so it should give you the info you needed.
"ComboFix 09-05-24.03 - Rachel Walker 05/24/2009 17:33.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1022.319 [GMT -4:00]
Running from: c:\documents and settings\Rachel Walker.TAVARISHKA\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\documents and settings\Rachel Walker.TAVARISHKA\Application Data\ezpinst.log
c:\documents and settings\Rachel Walker.TAVARISHKA\Application Data\inst.exe
c:\program files\Altnet
c:\program files\Altnet\DBBackup\Sigfiles.db
c:\program files\Altnet\Download Manager\altnetuninstall.exe
c:\program files\Altnet\Download Manager\asmend.exe
c:\program files\Altnet\Download Manager\asmps.dll
c:\program files\Altnet\Download Manager\dminfo3.cab
c:\program files\Altnet\Download Manager\dminstall7.cab
c:\program files\Altnet\Download Manager\dmsetup.bmp
c:\program files\Altnet\Download Manager\dmsetupbig.bmp
c:\program files\Altnet\Download Manager\jsinstall.cab
c:\program files\Altnet\Download Manager\jslegals.txt
c:\program files\Altnet\Download Manager\selectdir.txt
c:\program files\Altnet\Download Manager\selectdir1st.txt
c:\program files\Altnet\Points Manager\LocalPages\altnet.css
c:\program files\Altnet\Points Manager\LocalPages\gradient.gif
c:\program files\Altnet\Points Manager\LocalPages\local_firstuse.html
c:\program files\Altnet\Points Manager\LocalPages\local_points.html
c:\program files\Altnet\Points Manager\LocalPages\local_redeem.html
c:\program files\Altnet\Points Manager\LocalPages\local_start.html
c:\program files\Altnet\Points Manager\LocalPages\local_wallet.html
c:\program files\Altnet\Points Manager\LocalPages\notconnected.gif
c:\program files\Altnet\Points Manager\LocalPages\offline.gif
c:\program files\Altnet\Points Manager\LocalPages\pixel.gif
c:\program files\Altnet\Points Manager\Points Manager.exe.Manifest
c:\program files\Altnet\Points Manager\settings.cab
c:\program files\Altnet\Points Manager\setup.cab
c:\program files\Altnet\Points Manager\Skin\back-over.bmp
c:\program files\Altnet\Points Manager\Skin\back.bmp
c:\program files\Altnet\Points Manager\Skin\bottom.bmp
c:\program files\Altnet\Points Manager\Skin\bottomleft.bmp
c:\program files\Altnet\Points Manager\Skin\bottomright.bmp
c:\program files\Altnet\Points Manager\Skin\close-over.bmp
c:\program files\Altnet\Points Manager\Skin\close.bmp
c:\program files\Altnet\Points Manager\Skin\forward-over.bmp
c:\program files\Altnet\Points Manager\Skin\forward.bmp
c:\program files\Altnet\Points Manager\Skin\help-bottom.bmp
c:\program files\Altnet\Points Manager\Skin\help-over.bmp
c:\program files\Altnet\Points Manager\Skin\help-sel.bmp
c:\program files\Altnet\Points Manager\Skin\help-top.bmp
c:\program files\Altnet\Points Manager\Skin\help-topleft.bmp
c:\program files\Altnet\Points Manager\Skin\help-topright.bmp
c:\program files\Altnet\Points Manager\Skin\help.bmp
c:\program files\Altnet\Points Manager\Skin\Help.xml
c:\program files\Altnet\Points Manager\Skin\left.bmp
c:\program files\Altnet\Points Manager\Skin\maximise-over.bmp
c:\program files\Altnet\Points Manager\Skin\maximise.bmp
c:\program files\Altnet\Points Manager\Skin\mb_bottom.bmp
c:\program files\Altnet\Points Manager\Skin\mb_bottomleft.bmp
c:\program files\Altnet\Points Manager\Skin\mb_bottomright.bmp
c:\program files\Altnet\Points Manager\Skin\mb_left.bmp
c:\program files\Altnet\Points Manager\Skin\mb_right.bmp
c:\program files\Altnet\Points Manager\Skin\mb_top.bmp
c:\program files\Altnet\Points Manager\Skin\mb_topleft.bmp
c:\program files\Altnet\Points Manager\Skin\mb_topright.bmp
c:\program files\Altnet\Points Manager\Skin\message.xml
c:\program files\Altnet\Points Manager\Skin\minimise-over.bmp
c:\program files\Altnet\Points Manager\Skin\minimise.bmp
c:\program files\Altnet\Points Manager\Skin\points-disabled.bmp
c:\program files\Altnet\Points Manager\Skin\points-over.bmp
c:\program files\Altnet\Points Manager\Skin\points-sel.bmp
c:\program files\Altnet\Points Manager\Skin\points.bmp
c:\program files\Altnet\Points Manager\Skin\redeem-disabled.bmp
c:\program files\Altnet\Points Manager\Skin\redeem-over.bmp
c:\program files\Altnet\Points Manager\Skin\redeem-sel.bmp
c:\program files\Altnet\Points Manager\Skin\redeem.bmp
c:\program files\Altnet\Points Manager\Skin\refresh-over.bmp
c:\program files\Altnet\Points Manager\Skin\refresh.bmp
c:\program files\Altnet\Points Manager\Skin\right.bmp
c:\program files\Altnet\Points Manager\Skin\Sav3BD.tmp
c:\program files\Altnet\Points Manager\Skin\settings-disabled.bmp
c:\program files\Altnet\Points Manager\Skin\settings-over.bmp
c:\program files\Altnet\Points Manager\Skin\settings-sel.bmp
c:\program files\Altnet\Points Manager\Skin\settings.bmp
c:\program files\Altnet\Points Manager\Skin\Skin.xml
c:\program files\Altnet\Points Manager\Skin\start-disabled.bmp
c:\program files\Altnet\Points Manager\Skin\start-over.bmp
c:\program files\Altnet\Points Manager\Skin\start-sel.bmp
c:\program files\Altnet\Points Manager\Skin\start.bmp
c:\program files\Altnet\Points Manager\Skin\top.bmp
c:\program files\Altnet\Points Manager\Skin\topleft-pro.bmp
c:\program files\Altnet\Points Manager\Skin\topleft-reg.bmp
c:\program files\Altnet\Points Manager\Skin\topleft.bmp
c:\program files\Altnet\Points Manager\Skin\topright.bmp
c:\program files\Altnet\Points Manager\Skin\wallet-disabled.bmp
c:\program files\Altnet\Points Manager\Skin\wallet-over.bmp
c:\program files\Altnet\Points Manager\Skin\wallet-sel.bmp
c:\program files\Altnet\Points Manager\Skin\wallet.bmp
c:\program files\INSTALL.LOG
c:\program files\Mozilla Firefox\plugins\NPNd2fn.dll
c:\program files\Need2Find
c:\program files\Need2Find\bar\1.bin\N2FFXTBR.JAR
c:\program files\Need2Find\bar\1.bin\N2NTSTBR.JAR
c:\program files\Need2Find\bar\1.bin\N2PLUGIN.DLL
c:\program files\Need2Find\bar\1.bin\NPND2FN.DLL
c:\program files\Need2Find\bar\1.bin\PARTNER.DAT
c:\program files\Need2Find\bar\Cache\
00194656
c:\program files\Need2Find\bar\Cache\
001947EC
c:\program files\Need2Find\bar\Cache\
00196C1E
c:\program files\Need2Find\bar\Cache\
00196D95
c:\program files\Need2Find\bar\Cache\files.ini
c:\program files\Need2Find\bar\History\search
c:\program files\Need2Find\bar\Settings\prevcfg.htm
c:\windows\system32\Ijl11.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_TDSSSERV.SYS
-------\Service_TDSSserv.sys
((((((((((((((((((((((((( Files Created from 2009-04-24 to 2009-05-24 )))))))))))))))))))))))))))))))
.
2009-05-24 19:34 . 2009-05-24 19:34 -------- d-----w c:\documents and settings\Rachel Walker.TAVARISHKA\Application Data\Malwarebytes
2009-05-24 19:34 . 2009-04-06 19:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-05-24 19:33 . 2009-04-06 19:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-24 19:33 . 2009-05-24 19:33 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-24 19:33 . 2009-05-24 19:34 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-05-24 17:35 . 2009-05-24 17:37 -------- d-----w c:\program files\trend micro
2009-05-24 17:35 . 2009-05-24 18:12 -------- d-----w C:\rsit
2009-05-23 20:05 . 2009-05-23 20:05 3925567 ----a-w c:\program files\FileZilla_3.2.4.1_win32-setup.exe
2009-05-23 19:52 . 2009-05-23 19:52 382976 ----a-w c:\program files\wpk29.exe
2009-05-23 19:47 . 2009-05-23 19:47 -------- d-----w c:\program files\Nsasoft
2009-05-23 19:46 . 2009-05-23 19:46 1371784 ----a-w c:\program files\productkeyexplorer_setup.exe
2009-05-23 19:38 . 2009-05-23 19:38 -------- d-----w c:\program files\keyfinder.2.0.1
2009-05-23 19:38 . 2009-05-23 19:38 337932 ----a-w c:\program files\keyfinder.2.0.1.zip
2009-05-23 15:42 . 2009-05-15 19:54 65536 ----a-w c:\documents and settings\Rachel Walker.TAVARISHKA\Application Data\Mozilla\Firefox\Profiles\f9y9h3vq.default\extensions\{916ab64c-bc3e-471b-8e60-29551922a7ba}\components\Engine.dll
2009-05-21 03:07 . 2009-05-21 03:07 390664 ----a-w c:\documents and settings\Rachel Walker.TAVARISHKA\Application Data\Real\RealPlayer\Update\RealPlayer11.exe
2009-05-14 19:01 . 2009-05-14 19:01 -------- d-----w C:\b85cd6de1a21e97918
2009-05-09 20:10 . 2009-05-09 20:39 -------- d-----w c:\program files\CamStudio
2009-05-09 20:10 . 2009-05-09 20:10 1364995 ----a-w c:\program files\CamStudio20.exe
2009-05-06 02:41 . 2009-05-06 02:41 867416 ----a-w c:\program files\SetupGamevance.exe
2009-05-04 16:18 . 2009-05-09 21:22 -------- d-----w c:\documents and settings\Rachel Walker.TAVARISHKA\Application Data\vlc
2009-05-04 16:15 . 2009-05-04 16:15 -------- d-----w c:\documents and settings\Rachel Walker.TAVARISHKA\Local Settings\Application Data\Graboid_Inc
2009-05-04 16:15 . 2009-05-04 16:17 -------- d-----w c:\documents and settings\Rachel Walker.TAVARISHKA\Local Settings\Application Data\Graboid
2009-05-04 16:15 . 2009-05-04 16:15 -------- d-----w c:\documents and settings\Rachel Walker.TAVARISHKA\Application Data\MozillaControl
2009-05-04 16:13 . 2009-05-04 16:13 -------- d-----w c:\program files\Mozilla ActiveX Control v1.7.12
2009-05-04 16:12 . 2009-05-04 16:12 -------- d-----w c:\program files\VideoLAN
2009-05-04 16:11 . 2009-05-04 16:13 -------- d-----w c:\program files\Graboid
2009-05-04 16:09 . 2009-05-04 16:10 9060544 ----a-w c:\program files\GraboidVideoSetup.exe
2009-05-02 07:56 . 2009-05-02 07:56 -------- d--h--w c:\windows\PIF
2009-05-02 07:54 . 2009-05-02 07:54 -------- d-----w c:\program files\7-Zip
2009-04-29 22:40 . 2009-04-29 22:42 -------- d-----w C:\iOrgSoft Mod Converter OutPut
2009-04-29 22:29 . 2009-04-29 22:29 -------- d-----w c:\documents and settings\Rachel Walker.TAVARISHKA\Application Data\AVS4YOU
2009-04-29 22:29 . 2009-04-29 22:29 -------- d-----w c:\documents and settings\All Users\Application Data\AVS4YOU
2009-04-29 22:26 . 2009-04-29 22:46 -------- d-----w c:\program files\Common Files\AVSMedia
2009-04-29 22:26 . 2009-04-29 22:46 -------- d-----w c:\program files\AVS4YOU
2009-04-29 22:18 . 2009-04-29 22:25 54364552 ----a-w c:\program files\AVSVideoConverter.exe
2009-04-29 22:15 . 2009-04-29 22:15 -------- d-----w c:\program files\iOrgSoft
2009-04-29 22:13 . 2009-04-29 22:15 -------- d-----w c:\documents and settings\Rachel Walker.TAVARISHKA\Application Data\GetRightToGo
2009-04-29 22:12 . 2009-04-29 22:12 366136 ----a-w c:\program files\Download_iOrgSoftModConverter3.1.8_trial.exe
2009-04-29 20:17 . 2009-04-29 20:20 -------- d-----w c:\program files\Safecracker
2009-04-29 19:55 . 2009-04-29 19:55 208480 ----a-w c:\program files\bigfishgames_p39584727_s1_l1.exe
2009-04-29 18:24 . 2009-04-29 18:24 -------- d-----w c:\documents and settings\Rachel Walker.TAVARISHKA\Local Settings\Application Data\Hotspot_Shield
2009-04-29 18:16 . 2009-04-29 18:16 -------- d-----w c:\documents and settings\Rachel Walker.TAVARISHKA\Local Settings\Application Data\Conduit
2009-04-29 18:16 . 2008-06-26 18:34 11776 ----a-w c:\documents and settings\Rachel Walker.TAVARISHKA\Application Data\Mozilla\Firefox\Profiles\f9y9h3vq.default\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d}\components\FFAlert.dll
2009-04-29 18:16 . 2008-06-26 18:34 114688 ----a-w c:\documents and settings\Rachel Walker.TAVARISHKA\Application Data\Mozilla\Firefox\Profiles\f9y9h3vq.default\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d}\components\npmozax.dll
2009-04-29 18:08 . 2009-04-29 18:08 -------- d-----w c:\program files\Conduit
2009-04-29 18:08 . 2009-04-29 18:24 -------- d-----w c:\program files\Hotspot_Shield
2009-04-29 18:07 . 2009-04-29 18:08 -------- d-----w c:\program files\Hotspot Shield
2009-04-29 18:06 . 2009-04-29 18:06 3558198 ----a-w c:\program files\HSS-1.15-install-anchorfree-76-conduit.zip
2009-04-27 18:28 . 2009-05-24 19:28 -------- d-----w c:\documents and settings\Rachel Walker.TAVARISHKA\Application Data\FileZilla
2009-04-27 18:27 . 2009-05-23 20:07 -------- d-----w c:\program files\FileZilla FTP Client
2009-04-27 18:26 . 2009-04-27 18:26 3929393 ----a-w c:\program files\FileZilla_3.2.4_win32-setup.exe
2009-04-25 20:52 . 2009-04-25 20:52 -------- d-----w c:\windows\FOW4BJQY6DLT18GO
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-24 21:16 . 2009-04-11 17:56 -------- d-----w c:\documents and settings\Rachel Walker.TAVARISHKA\Application Data\WTablet
2009-05-24 21:16 . 2007-06-26 02:00 -------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-05-21 01:09 . 2007-05-02 01:48 -------- d--h--w c:\documents and settings\Rachel Walker.TAVARISHKA\Application Data\Move Networks
2009-05-20 04:02 . 2005-02-05 05:11 -------- d-----w c:\program files\Common Files\Symantec Shared
2009-04-30 03:59 . 2009-02-23 01:37 -------- d-----w c:\documents and settings\All Users\Application Data\BigFishGamesCache
2009-04-20 02:32 . 2009-04-10 20:19 -------- d-----w c:\program files\Ice Cream Craze - Tycoon Takeover
2009-04-17 16:28 . 2009-04-17 16:28 390664 ----a-w c:\documents and settings\Rachel Walker.TAVARISHKA\Application Data\Real\Update\temp\~Upg0\RealPlayer11.exe
2009-04-16 21:03 . 2009-04-16 21:03 208480 ----a-w c:\program files\bigfishgames_p38386682_s1_l1.exe
2009-04-16 18:54 . 2009-04-16 18:54 -------- d-----w c:\program files\Sam's Real Estate
2009-04-16 03:24 . 2009-04-16 03:24 -------- d-----w c:\documents and settings\Rachel Walker.TAVARISHKA\Application Data\blg
2009-04-16 03:24 . 2009-04-16 03:24 -------- d-----w c:\documents and settings\All Users\Application Data\blg
2009-04-16 02:00 . 2009-04-16 01:59 -------- d-----w c:\program files\Spa Mania
2009-04-15 04:12 . 2009-04-15 04:12 -------- d-----w c:\documents and settings\All Users\Application Data\Fugazo
2009-04-15 04:12 . 2009-04-15 04:08 -------- d-----w c:\program files\FishCo
2009-04-15 04:05 . 2009-04-15 04:04 -------- d-----w c:\program files\DQ Tycoon
2009-04-13 03:38 . 2009-04-13 03:38 -------- d-----w c:\program files\Squeeze Page Wizard
2009-04-13 03:37 . 2009-04-13 03:37 0 ----a-w C:\
[email protected]2009-04-12 02:08 . 2009-04-11 04:53 -------- d-----w c:\program files\Nanny Mania 2 - Goes to Hollywood
2009-04-11 17:56 . 2005-08-11 01:54 -------- d-----w c:\program files\Tablet
2009-04-11 17:54 . 2005-08-11 01:54 14221 ----a-w c:\windows\system32\tablet.dat
2009-04-11 17:51 . 2009-04-11 17:50 8369448 ----a-w c:\program files\WacomTablet_610-6.exe
2009-04-11 04:54 . 2009-04-11 04:54 -------- d-----w c:\documents and settings\All Users\Application Data\Gogii
2009-04-10 20:46 . 2009-04-10 20:46 -------- d-----w c:\documents and settings\Rachel Walker.TAVARISHKA\Application Data\ShinyTales
2009-04-10 20:45 . 2009-04-10 20:25 -------- d-----w c:\documents and settings\Rachel Walker.TAVARISHKA\Application Data\Be a King
2009-04-10 20:25 . 2009-04-10 20:25 -------- d-----w c:\program files\Wonderburg
2009-04-10 20:21 . 2009-04-10 20:20 -------- d-----w c:\program files\Be a King
2009-04-10 06:04 . 2009-04-10 06:04 -------- d-----w c:\documents and settings\Rachel Walker.TAVARISHKA\Application Data\Softplicity
2009-04-10 06:04 . 2009-04-10 06:04 -------- d-----w c:\program files\PDF Combine
2009-04-10 06:03 . 2009-04-10 06:03 1806722 ----a-w c:\program files\PDFCombine_Download.exe
2009-04-08 19:32 . 2009-04-08 19:32 3991064 ----a-w c:\program files\CutePDFEvl.exe
2009-04-07 03:36 . 2009-04-07 03:27 -------- d-----w c:\program files\GPLGS
2009-04-07 03:35 . 2009-04-07 03:35 5254656 ----a-w c:\program files\converter.exe
2009-04-07 03:33 . 2009-04-07 03:19 1613856 ----a-w c:\program files\CuteWriter.exe
2009-04-03 18:18 . 2009-04-03 18:18 33256 ----a-w c:\windows\system32\drivers\HssDrv.sys
2009-03-29 23:42 . 2005-05-13 16:03 125872 -c--a-w c:\documents and settings\Rachel Walker.TAVARISHKA\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-29 20:57 . 2005-05-12 04:31 -------- d-----w c:\program files\Common Files\Adobe
2009-03-29 17:24 . 2008-08-03 16:14 -------- d-----w c:\documents and settings\Rachel Walker.TAVARISHKA\Application Data\Download Manager
2009-03-21 01:07 . 2009-03-21 01:07 2945816 ----a-w c:\program files\dotnetfx3setup.exe
2009-03-09 15:34 . 2009-04-11 02:56 971776 ----a-w c:\documents and settings\Rachel Walker.TAVARISHKA\Application Data\Mozilla\Firefox\Profiles\f9y9h3vq.default\extensions\
[email protected]\platform\WINNT_x86-msvc\plugins\npmnqmp071303000006.dll
2009-03-03 18:19 . 2008-12-15 03:53 39184 ----a-w c:\windows\system32\drivers\TfSysMon.sys
2009-03-03 18:19 . 2008-12-15 03:53 33040 ----a-w c:\windows\system32\drivers\TfNetMon.sys
2009-03-03 18:19 . 2008-12-15 03:53 12560 ----a-w c:\windows\system32\drivers\TfKbMon.sys
2009-03-03 18:19 . 2008-12-15 03:53 51472 ----a-w c:\windows\system32\drivers\TfFsMon.sys
2009-03-01 18:22 . 2009-03-01 17:09 208480 ----a-w c:\program files\bigfishgames_p34459394_s1_l1.exe
2009-02-28 00:10 . 2009-02-28 00:10 208480 ----a-w c:\program files\bigfishgames_p34261019_s1_l1.exe
2009-02-27 01:30 . 2009-02-27 01:30 208480 ----a-w c:\program files\bettysbeerbar_s1_l1_gF22T1L1_d450239732.exe
2009-02-26 01:25 . 2009-02-26 01:19 94398232 ----a-w c:\program files\yahoo_cakemania3-1_tm6-3.exe
2009-02-22 14:52 . 2009-02-22 14:52 1837280 ----a-w c:\program files\snpvw.exe
2008-12-15 03:52 . 2008-12-15 03:49 23150144 ----a-w c:\program files\tfinstall.exe
2008-12-15 02:12 . 2008-12-15 02:12 9393928 ----a-w c:\program files\Free-SpyHunter-Scanner-Install.exe
2008-12-08 18:01 . 2008-12-08 18:01 437168 ----a-w c:\program files\msgr9us.exe
2008-12-08 17:57 . 2008-12-08 17:56 4127367 ----a-w c:\program files\setuppoivy.exe
2008-12-08 17:42 . 2008-12-08 17:42 4171086 ----a-w c:\program files\SetupSMSListo.exe
2008-12-08 17:21 . 2008-12-08 17:21 4148830 ----a-w c:\program files\setupVoipwise.exe
2008-11-03 21:06 . 2008-11-03 21:06 607640 ----a-w c:\program files\jxpiinstall.exe
2008-10-12 21:12 . 2008-10-12 21:11 27288880 ----a-w c:\program files\QuickTimeInstaller.exe
2008-10-05 19:22 . 2008-10-05 19:20 35386936 ----a-w c:\program files\yahoo_farmfrenzy2_tm6-3.exe
2008-09-28 20:05 . 2008-09-28 20:05 8906792 ----a-w c:\program files\TypingMaster700.exe
2008-08-04 17:39 . 2008-08-04 17:11 486108144 ----a-w c:\program files\ADBEPHSPCS3_WWE.exe
2008-06-01 19:03 . 2008-06-01 19:03 1427520 ----a-w c:\program files\Silverlight.exe
2008-04-21 02:40 . 2008-04-21 02:40 284184 ----a-w c:\program files\PopCapPluginInstaller_v2.exe
2008-03-10 17:28 . 2008-03-10 17:28 1462221 ----a-w c:\program files\gifcon32.exe
2008-03-10 17:27 . 2008-03-10 17:27 3374896 ----a-w c:\program files\vvpro.exe
2008-01-20 02:59 . 2008-01-20 02:49 83142656 ----a-w c:\program files\AI10try.exe
2008-01-16 01:11 . 2008-01-16 01:11 111 ----a-w c:\program files\kern_Font1.txt
2008-01-16 00:39 . 2008-01-16 00:39 6625744 ----a-w c:\program files\FontCreatorSetup.exe
2008-01-06 19:51 . 2008-01-06 18:20 258512864 ----a-w c:\program files\CorelDRAWGraphicsSuiteX3_dlm.exe
2007-10-08 02:06 . 2007-10-08 02:06 1906648 ----a-w c:\program files\SetupAnyDVD6174.exe
2007-10-06 02:07 . 2007-10-06 02:07 4835008 ----a-w c:\program files\1clickdvdcopyprosetup3.0.1.8.exe
2007-10-06 01:55 . 2007-10-06 01:55 615934 ----a-w c:\program files\setup_dvd2one213.exe
2007-09-24 02:26 . 2007-09-24 02:25 8815464 ----a-w c:\program files\RhapsodyHp.exe
2007-09-23 01:43 . 2007-09-23 01:42 11691880 ----a-w c:\program files\NapsterSetup-US-NCOM-3.8.1.4.exe
2007-07-08 01:05 . 2007-07-08 01:04 15732984 ----a-w c:\program files\Google_Earth_BZXD.exe
2007-02-19 02:00 . 2007-02-19 01:59 25998680 ----a-w c:\program files\FSS_DP40.exe
2007-02-02 17:24 . 2007-02-02 17:24 1397331 ----a-w c:\program files\MonkeyJam Setup 3.0b.050529.exe
2007-01-26 01:46 . 2007-01-26 01:41 20917185 ----a-w c:\program files\ts32setup.zip
2006-11-14 01:30 . 2006-11-14 01:31 831259 ----a-w c:\program files\installer_Upload2Phone.exe
2006-10-27 14:20 . 2006-02-01 02:35 1355912 ----a-w c:\program files\install_flash_player.exe
2006-04-29 04:42 . 2005-06-02 01:05 36465208 -c--a-w c:\program files\iTunesSetup.exe
2005-08-16 14:03 . 2005-08-16 14:03 5402624 -c--a-w c:\program files\movlib12.exe
2005-07-30 01:59 . 2005-07-30 01:58 4999031 -c--a-w c:\program files\Bc4000_00.zip
2005-07-08 19:32 . 2005-07-08 19:32 201728 -c--a-w c:\program files\EOTM Flyer-July 2005.doc
2005-07-08 18:01 . 2005-07-08 18:01 210944 -c--a-w c:\program files\EOTM Nominees flyer- July 2005.doc
2005-07-02 00:28 . 2005-07-02 00:27 4277840 -c--a-w c:\program files\icq5_setup.exe
2005-06-30 23:26 . 2005-06-30 23:25 4610480 -c--a-w c:\program files\icqpro2003b.exe
2005-06-24 03:05 . 2005-06-19 01:26 10048456 -c--a-w c:\program files\yahoo_dinerdash_tm5-3.exe
2005-06-11 02:01 . 2005-06-11 02:01 317856 -c--a-w c:\program files\esheep.exe
2005-05-12 17:22 . 2005-05-12 17:22 774144 -c--a-w c:\program files\RngInterstitial.dll
2005-05-12 17:12 . 2005-05-12 17:11 8219278 -c--a-w c:\program files\RhapsodyReal.EXE
2005-05-12 17:11 . 2005-05-12 17:09 10843680 -c--a-w c:\program files\RealPlayer10-5GOLD_bb.exe
2005-05-12 17:10 . 2005-05-12 17:10 213920 -c--a-w c:\program files\realarcade_W4D0.exe
2005-05-12 16:51 . 2005-05-12 16:51 4827968 -c--a-w c:\program files\Firefox Setup 1.0.4.exe
2005-05-12 05:45 . 2005-05-12 05:35 4466776 -c--a-w c:\program files\Install_AIM.exe
2007-10-08 02:07 . 2007-10-08 02:07 24 --sh--w c:\windows\SE7AF1741.tmp
2008-06-17 02:48 . 2008-01-06 20:06 88 --sh--r c:\windows\system32\9F9C63D044.sys
2008-06-17 02:48 . 2008-01-06 19:58 2828 --sha-w c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( SnapShot@2009-05-24_20.41.32 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-05-24 21:18 . 2009-05-24 21:18 16384 c:\windows\Temp\Perflib_Perfdata_a24.dat
+ 2009-05-24 21:16 . 2009-05-24 21:16 16384 c:\windows\Temp\Perflib_Perfdata_680.dat
+ 2009-05-24 21:16 . 2009-05-24 21:16 16384 c:\windows\Temp\Perflib_Perfdata_20c.dat
+ 2005-06-17 22:07 . 2007-07-27 13:41 26488 c:\windows\system32\spupdsvc.exe
+ 2008-04-05 16:51 . 2007-07-27 13:41 16760 c:\windows\system32\spmsg.dll
+ 2009-05-24 21:21 . 2009-05-24 21:21 24576 c:\windows\Microsoft.NET\Framework\v1.1.4322\Temporary ASP.NET Files\neodesk\7f9a09e9\3618fa52\upk8mpif.dll
+ 2009-05-24 21:21 . 2009-05-24 21:21 4096 c:\windows\Microsoft.NET\Framework\v1.1.4322\Temporary ASP.NET Files\neodesk\7f9a09e9\3618fa52\ptic3y0j.dll
+ 2009-05-24 21:20 . 2009-05-24 21:21 3072 c:\windows\Microsoft.NET\Framework\v1.1.4322\Temporary ASP.NET Files\neodesk\7f9a09e9\3618fa52\enhg6e7b.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]
2008-06-25 03:17 1569304 ----a-w c:\program files\Hotspot_Shield\tbHots.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
2009-04-29 18:07 218160 ----a-w c:\program files\Hotspot Shield\hssie\HssIE.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2005-01-18 196608]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [BU]
"CTSyncU.exe"="c:\program files\Creative\Sync Manager Unicode\CTSyncU.exe" [2006-09-29 700416]
"VeohPlugin"="c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2008-10-09 3502840]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2008-11-06 4347120]
"windpipe"="c:\documents and settings\Rachel Walker.TAVARISHKA\Application Data\Google\fhexj6825097.exe" [BU]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-04 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-04 688218]
"Symantec NetDriver Monitor"="c:\progra~1\SYMNET~1\SNDMon.exe" [2005-05-27 100056]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-03 136600]
"hpWirelessAssistant"="c:\program files\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe" [2004-12-09 790528]
"eabconfg.cpl"="c:\program files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 290816]
"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2004-11-05 233534]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2005-03-23 58992]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-12-22 344064]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2004-10-08 221184]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-01-18 458752]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2005-01-18 217088]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb12.exe" [2004-06-26 172032]
"StrgSync.exe"="c:\program files\StorageSync\StrgSync.exe" [2005-10-08 3032576]
"AltnetPointsManager"="c:\program files\altnet\points manager\points manager.exe" [BU]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2006-09-25 229952]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-17 49152]
"NapsterShell"="c:\program files\Napster\napster.exe" [2007-01-12 323216]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-03-29 185896]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"ThreatFire"="c:\program files\ThreatFire\TFTray.exe" [2009-03-03 263440]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-12 640376]
c:\documents and settings\Rachel Walker.TAVARISHKA\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 110592]
MostFun.lnk - c:\program files\MostFun\Bin\MostFun.exe [2007-5-29 147456]
PowerReg Scheduler V3.exe [2007-10-21 225280]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 110592]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-5-14 241664]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-5-14 53248]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2005-7-7 450560]
Microsoft Office.lnk - c:\program files\Microsoft Office2000\Office\OSA9.EXE [1999-2-17 65588]
TabUserW.exe.lnk - c:\windows\system32\WTablet\TabUserW.exe [2006-2-10 106496]
ymetray.lnk - c:\program files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe [2006-8-14 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\system32\\msiexec.exe"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\MostFun\\Bin\\MostFun.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"c:\\Program Files\\Microsoft Games\\Zoo Tycoon 2\\zt.exe"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\Program Files\\Voipwise.com\\Voipwise\\Voipwise.exe"=
"c:\\Program Files\\SMSlisto.com\\SMSlisto\\SMSlisto.exe"=
"c:\\Program Files\\PoivY.com\\PoivY\\PoivY.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Ipswitch\\WS_FTP Home\\wsftpgui.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2082:TCP"= 2082:TCP:dwart
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [12/14/2008 11:53 PM 51472]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [12/14/2008 11:53 PM 39184]
R2 AdobeActiveFileMonitor;Adobe Active File Monitor;c:\program files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe [10/4/2004 5:47 AM 98304]
R2 HssSrv;Hotspot Shield Helper Service;c:\program files\Hotspot Shield\HssWPR\hsssrv.exe [4/21/2009 9:12 PM 328752]
R2 PhotoshopElementsDeviceConnect;Photoshop Elements Device Connect;c:\program files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe [10/4/2004 4:40 AM 118784]
R2 TabletServiceWacom;TabletServiceWacom;c:\windows\system32\Wacom_Tablet.exe [4/11/2009 1:55 PM 2749224]
R2 ThreatFire;ThreatFire;c:\program files\ThreatFire\TFService.exe service --> c:\program files\ThreatFire\TFService.exe service [?]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/10/2007 10:04 PM 24652]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [5/12/2005 5:03 AM 192896]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [12/14/2008 11:53 PM 33040]
S3 HssTrayService;Hotspot Shield Tray Service;c:\program files\Hotspot Shield\bin\HssTrayService.exe [4/22/2009 5:34 PM 34352]
S3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [4/11/2009 1:55 PM 15656]
--- Other Services/Drivers In Memory ---
*Deregistered* - mchInjDrv
.
Contents of the 'Scheduled Tasks' folder
2007-06-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2009-03-21 c:\windows\Tasks\Norton AntiVirus - Scan my computer - Rachel Walker.job
- c:\progra~1\NORTON~1\Navw32.exe [2004-08-18 16:20]
2009-05-24 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2005-02-05 16:24]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT1561552
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = localhost;*.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: &Search -
http://kl.bar.need2find.com/KL/menusearch.html?p=KLIE: &Viewpoint Search - c:\program files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
DPF: RaptisoftGameLoader - hxxp://real.gamehouse.com/real/games/raptisoft/raptisoftgameloader.cab
DPF: {195B4BBF-E1E4-4020-9773-0A8C6F65EA35} - hxxp://games.bigfishgames.com/en_cooking-dash/online/CookingDashWeb.1.0.0.9.cab
FF - ProfilePath - c:\documents and settings\Rachel Walker.TAVARISHKA\Application Data\Mozilla\Firefox\Profiles\f9y9h3vq.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1561552&SearchSource=3&q=
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.freecause.com/search?fr=freecause&ourmark=3&type=58819&p=
FF - component: c:\documents and settings\Rachel Walker.TAVARISHKA\Application Data\Mozilla\Firefox\Profiles\f9y9h3vq.default\extensions\{916ab64c-bc3e-471b-8e60-29551922a7ba}\components\Engine.dll
FF - component: c:\documents and settings\Rachel Walker.TAVARISHKA\Application Data\Mozilla\Firefox\Profiles\f9y9h3vq.default\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d}\components\FFAlert.dll
FF - plugin: c:\documents and settings\Rachel Walker.TAVARISHKA\Application Data\Mozilla\Firefox\Profiles\f9y9h3vq.default\extensions\
[email protected]\platform\WINNT_x86-msvc\plugins\npmnqmp071303000006.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npgcplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nppopcaploader.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npracplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npstrlnk.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npvirtools.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\NPVeohTVPlugin.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
---- FIREFOX POLICIES ----
FF - user.js: general.useragent.extra.zencast - Creative ZENcast v1.02.12.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-05-24 17:37
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe?


?0?7?8?5?


?,?B?



???hLC?

scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74599CE1-6A23-5483-EB701B08F9A92206}\{E02CED0D-4BCF-9035-DBE164FDC4BAFF1D}\{4E02710B-D78F-2FB3-D08A702F3A48D363}*]
"526BA65ZPQS4U365YNAELLJ5XA1"=hex:01,00,01,00,00,00,00,00,50,bd,9f,8a,7e,a0,d0,
fa,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(936)
c:\windows\system32\Ati2evxx.dll
c:\program files\ThreatFire\TFWAH.dll
c:\program files\ThreatFire\TFNI.dll
- - - - - - - > 'lsass.exe'(992)
c:\program files\ThreatFire\TFWAH.dll
- - - - - - - > 'explorer.exe'(5292)
c:\program files\ThreatFire\TFWAH.dll
c:\windows\system32\shdoclc.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-05-24 17:42
ComboFix-quarantined-files.txt 2009-05-24 21:42
Pre-Run: 13,251,145,728 bytes free
Post-Run: 13,238,345,728 bytes free
472 --- E O F --- 2009-05-23 22:47"
Hope that this helps. Thanks so much.