I have the file saved to the desktop. Here is the log from the first scan.
ComboFix 09-12-18.03 - The Dents 12/19/2009 11:12:33.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2037.608 [GMT -6:00]
Running from: c:\users\The Dents\Downloads\KittyFix.exe
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-1400113804-1914402855-3429530994-500
c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
c:\$recycle.bin\S-1-5-21-2229376273-1468763496-2003331228-500
c:\program files\SelectRebates
c:\program files\SelectRebates\FFToolbar\chrome.manifest
c:\program files\SelectRebates\FFToolbar\chrome\sahtoolbar.jar
c:\program files\SelectRebates\FFToolbar\defaults\preferences\sahtoolbar.js
c:\program files\SelectRebates\FFToolbar\install.rdf
c:\program files\SelectRebates\SahImages\bg-gradient.gif
c:\program files\SelectRebates\SahImages\button-close.gif
c:\program files\SelectRebates\SahImages\sah-logopop.gif
c:\program files\SelectRebates\SahImages\SAHS_popuplogo2.gif
c:\program files\SelectRebates\SelectAlerts.dat
c:\program files\SelectRebates\SelectRebates.exe
c:\program files\SelectRebates\SelectRebates.ini
c:\program files\SelectRebates\SelectRebatesA.dat
c:\program files\SelectRebates\SelectRebatesB.dat
c:\program files\SelectRebates\SelectRebatesBT.dat
c:\program files\SelectRebates\SelectRebatesDownload.exe
c:\program files\SelectRebates\SelectRebatesH.dat
c:\program files\SelectRebates\SRebates.dll
c:\program files\SelectRebates\SRFF3.dll
c:\program files\SelectRebates\Toolbar\basis.xml
c:\program files\SelectRebates\Toolbar\basis.xml.bak
c:\program files\SelectRebates\Toolbar\Basis.xml.dym
c:\program files\SelectRebates\Toolbar\Blank.bmp
c:\program files\SelectRebates\Toolbar\CashBack.bmp
c:\program files\SelectRebates\Toolbar\Coupons.bmp
c:\program files\SelectRebates\Toolbar\GroceryCoupon.bmp
c:\program files\SelectRebates\Toolbar\i_magnifying.bmp
c:\program files\SelectRebates\Toolbar\icons.bmp
c:\program files\SelectRebates\Toolbar\ImageCache\alert-red.bmp
c:\program files\SelectRebates\Toolbar\logo.bmp
c:\program files\SelectRebates\Toolbar\logo_24.bmp
c:\program files\SelectRebates\Toolbar\logo_HotSpots.bmp
c:\program files\SelectRebates\Toolbar\ReviewSite.bmp
c:\program files\SelectRebates\Toolbar\RightControls.dym
c:\program files\SelectRebates\Toolbar\Scissors.bmp
c:\program files\SelectRebates\Toolbar\ShOPathometoolbar.dll
c:\programdata\Microsoft\Network\Downloader\qmgr0.dat
c:\programdata\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\Cursors\aero_link.cur
c:\windows\system32\f3PSSavr.scr
----- BITS: Possible infected sites -----
hxxp://www.spiralfrog.com
.
((((((((((((((((((((((((( Files Created from 2009-11-19 to 2009-12-19 )))))))))))))))))))))))))))))))
.
2009-12-19 17:26 . 2009-12-19 17:26 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-12-17 16:12 . 2009-12-17 16:12 690952 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-12-16 02:24 . 2004-08-04 14:00 506368 ----a-w- c:\windows\system32\msxml.dll
2009-12-16 02:24 . 2009-12-16 02:24 -------- d-----w- c:\program files\Common Files\PC Tools
2009-12-15 22:54 . 2009-12-15 22:54 -------- d-----w- c:\users\The Dents\AppData\Roaming\SupportSoft
2009-12-12 15:04 . 2009-11-09 12:31 24064 ----a-w- c:\windows\system32\nshhttp.dll
2009-12-12 15:04 . 2009-11-09 12:30 30720 ----a-w- c:\windows\system32\httpapi.dll
2009-12-12 15:04 . 2009-11-09 10:36 411648 ----a-w- c:\windows\system32\drivers\http.sys
2009-12-11 01:57 . 2009-12-11 02:00 -------- d-----w- c:\program files\Nanny Mania 2 - Hollywood
2009-12-10 04:29 . 2009-08-24 11:36 377344 ----a-w- c:\windows\system32\winhttp.dll
2009-12-10 00:25 . 2009-12-10 00:29 -------- d-----w- c:\users\The Dents\AppData\Roaming\OtherSide Realm of Eons
2009-12-08 03:14 . 2009-12-08 03:15 -------- d-----w- c:\program files\Babysitting Mania
2009-12-07 23:05 . 2009-12-11 02:51 -------- d-----w- c:\program files\Baby Luv
2009-12-06 19:08 . 2009-12-06 19:09 -------- d-----w- c:\program files\Cake Mania Main Street
2009-12-06 18:45 . 2009-12-06 18:45 1421449 ----a-w- c:\programdata\NeoEdge Networks\Yahoo_Monopoly\IAF.dll
2009-12-03 18:55 . 2009-12-03 18:55 -------- d-----w- c:\users\The Dents\AppData\Local\Clearwire
2009-12-03 18:53 . 2009-01-20 22:08 233472 ----a-w- c:\windows\system32\drivers\drxvi314.sys
2009-12-03 18:53 . 2009-01-20 22:08 1739180 ----a-w- c:\windows\system32\drivers\macxvi200.bin
2009-12-03 18:53 . 2009-01-20 22:08 54784 ----a-w- c:\windows\system32\drivers\BcmBusCtr.sys
2009-12-03 18:52 . 2009-12-03 18:52 -------- d-----w- c:\program files\Common Files\PctelEapPeer Authentication
2009-12-03 18:52 . 2009-12-03 18:52 -------- d-----w- c:\programdata\Clearwire
2009-12-03 18:52 . 2009-12-03 18:52 -------- d-----w- c:\program files\Clearwire
2009-12-02 18:58 . 2009-12-06 18:45 -------- d-----w- c:\programdata\NeoEdge Networks
2009-12-02 18:58 . 2009-12-02 18:58 1245321 ----a-w- c:\programdata\NeoEdge Networks\Yahoo_SuperCollapse3\IAF.dll
2009-11-28 07:12 . 2009-11-28 07:12 -------- d-----w- c:\users\The Dents\AppData\Roaming\casanova
2009-11-25 15:37 . 2009-10-29 09:17 2048 ----a-w- c:\windows\system32\tzres.dll
2009-11-25 15:31 . 2009-11-25 15:31 -------- d-----w- c:\program files\MSXML 4.0
2009-11-24 20:35 . 2009-08-11 16:44 1401856 ----a-w- c:\windows\system32\msxml6.dll
2009-11-24 20:35 . 2009-08-11 16:44 1248768 ----a-w- c:\windows\system32\msxml3.dll
2009-11-23 03:54 . 2009-11-23 03:55 -------- d-----w- c:\program files\Murder She Wrote
2009-11-23 03:36 . 2009-11-23 03:36 -------- d-----w- c:\users\The Dents\AppData\Roaming\Scholastic
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-19 16:43 . 2008-08-13 22:29 -------- d-----w- c:\program files\SpiralFrog
2009-12-19 06:05 . 2007-08-17 09:19 12 ----a-w- c:\windows\bthservsdp.dat
2009-12-19 05:03 . 2007-11-04 01:37 -------- d-----w- c:\program files\Lx_cats
2009-12-19 03:15 . 2009-09-02 04:07 -------- d-----w- c:\program files\McAfee
2009-12-18 01:35 . 2008-01-19 05:13 -------- d-----w- c:\users\The Dents\AppData\Roaming\PlayFirst
2009-12-18 01:35 . 2008-01-19 05:13 -------- d-----w- c:\programdata\PlayFirst
2009-12-16 04:29 . 2008-06-14 03:53 -------- d-----w- c:\users\The Dents\AppData\Roaming\MysteryStudio
2009-12-12 05:33 . 2009-07-28 02:27 -------- d-----w- c:\users\The Dents\AppData\Roaming\Gamers Digital
2009-12-12 05:33 . 2009-07-28 02:27 -------- d-----w- c:\programdata\Gamers Digital
2009-12-10 17:31 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-12-08 03:19 . 2007-12-09 02:57 -------- d-----w- c:\users\The Dents\AppData\Roaming\SpinTop
2009-12-06 18:45 . 2008-11-06 20:14 -------- d-----w- c:\program files\Yahoo! Games
2009-12-06 04:19 . 2007-12-19 19:38 -------- d-----w- c:\programdata\iWin Games
2009-12-06 03:39 . 2007-08-21 21:22 116816 ----a-w- c:\windows\system32\config\systemprofile\AppData\Local\GDIPFONTCACHEV1.DAT
2009-12-06 02:46 . 2007-08-21 21:31 116816 ----a-w- c:\users\The Dents\AppData\Local\GDIPFONTCACHEV1.DAT
2009-12-06 02:42 . 2007-08-17 09:41 -------- d-----w- c:\program files\Google
2009-12-06 02:36 . 2009-11-19 02:41 -------- d-----w- c:\program files\palmOne
2009-12-06 02:34 . 2009-09-10 21:19 -------- d-----w- c:\program files\Sony
2009-12-06 02:26 . 2009-07-09 00:14 -------- d-----w- c:\program files\Zylom Games
2009-12-06 02:25 . 2009-10-10 18:28 -------- d-----w- c:\program files\LimeWire
2009-12-06 01:41 . 2007-12-19 19:40 -------- d-----w- c:\program files\iWin.com
2009-12-06 01:27 . 2009-10-10 18:28 -------- d-----w- c:\users\The Dents\AppData\Roaming\LimeWire
2009-12-01 21:48 . 2007-08-17 09:36 -------- d-----w- c:\programdata\McAfee
2009-11-27 04:42 . 2009-06-19 20:39 -------- d-----w- c:\users\The Dents\AppData\Roaming\IMVU
2009-11-24 15:26 . 2008-07-11 23:08 -------- d-----w- c:\program files\RealArcade
2009-11-24 15:23 . 2009-07-15 23:04 -------- d-----w- c:\programdata\Norton
2009-11-24 15:23 . 2007-09-06 03:05 -------- d-----w- c:\program files\Norton Security Scan
2009-11-23 19:29 . 2007-08-17 09:26 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-11-21 06:40 . 2009-12-10 04:28 916480 ----a-w- c:\windows\system32\wininet.dll
2009-11-21 06:34 . 2009-12-10 04:28 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-11-21 06:34 . 2009-12-10 04:28 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-11-21 04:59 . 2009-12-10 04:28 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-11-21 00:00 . 2009-07-17 23:00 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-11-20 21:56 . 2009-11-19 02:41 65536 ----a-r- c:\users\The Dents\AppData\Roaming\Microsoft\Installer\{E434580A-2D4A-4433-A81E-4BCAE86AD148}\NewShortcut6.4DA64122_6F1D_4317_BC6A_2B3299881D1B.exe
2009-11-20 21:56 . 2009-11-19 02:41 65536 ----a-r- c:\users\The Dents\AppData\Roaming\Microsoft\Installer\{E434580A-2D4A-4433-A81E-4BCAE86AD148}\NewShortcut5.4DA64122_6F1D_4317_BC6A_2B3299881D1B.exe
2009-11-20 21:56 . 2009-11-19 02:41 65536 ----a-r- c:\users\The Dents\AppData\Roaming\Microsoft\Installer\{E434580A-2D4A-4433-A81E-4BCAE86AD148}\NewShortcut4.4DA64122_6F1D_4317_BC6A_2B3299881D1B.exe
2009-11-20 21:56 . 2009-11-19 02:41 65536 ----a-r- c:\users\The Dents\AppData\Roaming\Microsoft\Installer\{E434580A-2D4A-4433-A81E-4BCAE86AD148}\NewShortcut1.4DA64122_6F1D_4317_BC6A_2B3299881D1B.exe
2009-11-20 21:56 . 2009-11-19 02:41 49152 ----a-r- c:\users\The Dents\AppData\Roaming\Microsoft\Installer\{E434580A-2D4A-4433-A81E-4BCAE86AD148}\NewShortcut3.4DA64122_6F1D_4317_BC6A_2B3299881D1B.exe
2009-11-19 03:34 . 2009-11-19 03:34 -------- d-----w- c:\users\The Dents\AppData\Roaming\Arcsoft
2009-11-19 03:19 . 2009-11-19 03:19 -------- d-----w- c:\programdata\QuickTime
2009-11-19 02:45 . 2009-11-19 02:45 -------- d-----w- c:\programdata\HotSync
2009-11-19 02:38 . 2009-11-19 02:38 -------- d-----w- c:\users\The Dents\AppData\Roaming\HotSync
2009-11-19 02:38 . 2009-11-19 02:44 53248 ----a-w- c:\windows\PalmDevC.dll
2009-11-19 01:21 . 2008-11-18 20:19 -------- d-----w- c:\users\The Dents\AppData\Roaming\Artogon
2009-11-18 13:39 . 2009-11-18 13:39 -------- d-----w- c:\program files\Windows Portable Devices
2009-11-18 13:38 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-11-18 13:38 . 2009-11-18 13:38 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
2009-11-18 13:38 . 2009-11-18 13:38 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-18 05:14 . 2008-12-04 00:16 -------- d-----w- c:\programdata\Alawar Stargaze
2009-11-14 21:39 . 2008-10-09 16:08 -------- d-----w- c:\users\The Dents\AppData\Roaming\Playrix Entertainment
2009-11-14 06:11 . 2009-11-14 06:10 -------- d-----w- c:\program files\Big City Adventure - New York City
2009-11-12 02:05 . 2008-09-28 03:20 -------- d-----w- c:\users\The Dents\AppData\Roaming\funkitron
2009-11-12 00:37 . 2009-11-12 00:37 -------- d-----w- c:\users\The Dents\AppData\Roaming\blg
2009-11-12 00:37 . 2009-11-12 00:37 -------- d-----w- c:\programdata\blg
2009-11-10 04:06 . 2009-11-10 04:06 -------- d-----w- c:\users\The Dents\AppData\Roaming\Lazy Turtle Games
2009-11-10 02:16 . 2008-09-28 01:23 46128 ----a-w- c:\programdata\iWin Games\firefox\iWinArcadeLauncher.exe
2009-11-10 02:05 . 2008-08-20 21:12 -------- d-----w- c:\users\The Dents\AppData\Roaming\Yahoo!
2009-11-06 05:35 . 2009-09-20 02:49 -------- d-----w- c:\users\The Dents\AppData\Roaming\Merscom
2009-11-06 05:35 . 2009-09-20 02:49 -------- d-----w- c:\programdata\Merscom
2009-11-04 03:03 . 2009-11-04 03:01 -------- d-----w- c:\users\The Dents\AppData\Roaming\TitanicMystery
2009-11-04 03:02 . 2009-11-04 03:02 -------- d-----w- c:\programdata\1912 Titanic Mystery
2009-11-03 04:15 . 2009-11-03 04:15 -------- d-----w- c:\programdata\GameHouse
2009-11-03 02:42 . 2009-10-09 13:07 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-11-02 15:34 . 2008-01-03 00:50 -------- d-----w- c:\programdata\Yahoo! Companion
2009-11-02 15:34 . 2007-08-17 09:42 -------- d-----w- c:\program files\Yahoo!
2009-11-01 03:19 . 2009-10-31 20:41 -------- d-----w- c:\program files\Playalot Games
2009-11-01 03:17 . 2008-01-19 03:47 -------- d-----w- c:\program files\Oberon Media
2009-10-31 23:17 . 2008-01-19 08:01 -------- d-----w- c:\programdata\JollyBear
2009-10-31 20:58 . 2009-10-31 20:56 -------- d-----w- c:\program files\iTunes
2009-10-31 20:57 . 2009-10-31 20:57 -------- d-----w- c:\program files\iPod
2009-10-31 20:57 . 2007-10-28 00:19 -------- d-----w- c:\program files\Common Files\Apple
2009-10-31 20:48 . 2009-10-31 20:48 79144 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-10-31 20:45 . 2008-07-15 00:18 -------- d-----w- c:\users\The Dents\AppData\Roaming\SpinTop Games
2009-10-31 20:43 . 2009-10-31 20:43 64 ----a-w- c:\windows\GPlrLanc.dat
2009-10-31 20:43 . 2009-10-31 20:43 -------- d-----w- c:\programdata\Free Ride Games
2009-10-31 20:43 . 2009-10-31 20:43 -------- d-----w- c:\users\The Dents\AppData\Roaming\Titanium Gears
2009-10-28 05:15 . 2008-01-20 07:22 16 ----a-w- c:\windows\popcinfo.dat
2009-10-27 05:19 . 2009-10-27 05:19 -------- d-----w- c:\users\The Dents\AppData\Roaming\GTM_Bodie
2009-10-26 01:02 . 2008-02-23 16:44 -------- d-----w- c:\users\The Dents\AppData\Roaming\Big Fish Games
2009-10-24 16:58 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
2009-10-24 16:58 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-10-24 16:58 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
2009-10-24 16:58 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
2009-10-24 16:57 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
2009-10-24 16:57 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
2009-10-23 16:25 . 2008-12-31 16:50 -------- d-----w- c:\programdata\Microsoft Help
2009-10-22 20:27 . 2008-01-20 00:47 -------- d-----w- c:\users\The Dents\AppData\Roaming\Flood Light Games
2009-10-22 20:27 . 2008-01-20 00:47 -------- d-----w- c:\programdata\Flood Light Games
2009-10-22 19:53 . 2009-09-17 00:56 -------- d-----w- c:\users\The Dents\AppData\Roaming\ERS G-Studio
2009-10-22 18:42 . 2009-10-22 18:41 -------- d-----w- c:\users\The Dents\AppData\Roaming\MissTeriTale3
2009-10-21 03:35 . 2009-04-16 02:50 -------- d-----w- c:\programdata\Meridian93
2009-10-21 03:34 . 2009-10-21 03:34 -------- d-----w- c:\users\The Dents\AppData\Roaming\art2
2009-10-21 03:34 . 2009-04-16 02:49 -------- d-----w- c:\users\The Dents\AppData\Roaming\Meridian93
2009-10-08 21:08 . 2009-11-18 13:25 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2009-10-08 21:08 . 2009-11-18 13:25 234496 ----a-w- c:\windows\system32\oleacc.dll
2009-10-08 21:07 . 2009-11-18 13:25 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2009-10-07 11:36 . 2009-12-10 04:28 243712 ----a-w- c:\windows\system32\rastls.dll
2009-10-01 01:02 . 2009-11-18 13:26 2537472 ----a-w- c:\windows\system32\wpdshext.dll
2009-10-01 01:02 . 2009-11-18 13:27 30208 ----a-w- c:\windows\system32\WPDShextAutoplay.exe
2009-10-01 01:02 . 2009-11-18 13:26 334848 ----a-w- c:\windows\system32\PortableDeviceApi.dll
2007-08-17 17:12 . 2007-08-17 17:09 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-07-17 22:20 279944 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-07-17 279944]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-07-17 279944]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-03-18 4363504]
"QuickPhrase"="c:\program files\TypingMaster\QuickPhrase\quickphrase.exe" [2008-11-18 638456]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"RegistryMechanic"="c:\program files\Registry Mechanic\RMTray.exe" [2009-11-25 292824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-04-18 159744]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-05-16 138008]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-05-16 154392]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-05-16 133912]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-04-16 184320]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-03-16 17920]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"HostManager"="c:\program files\Common Files\AOL\1189175660\ee\AOLSoftware.exe" [2006-09-26 50736]
"LXCJCATS"="c:\windows\system32\spool\DRIVERS\W32X86\3\LXCJtime.dll" [2006-11-21 106496]
"lxcjmon.exe"="c:\program files\Lexmark 8300 Series\lxcjmon.exe" [2007-05-08 205744]
"EzPrint"="c:\program files\Lexmark 8300 Series\ezprint.exe" [2007-05-08 103344]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"SpiralFrog"="c:\program files\SpiralFrog\Spiralfrog.exe" [2008-03-12 163128]
"lxdfmon.exe"="c:\program files\Lexmark 6500 Series\lxdfmon.exe" [2007-06-12 455600]
"lxdfamon"="c:\program files\Lexmark 6500 Series\lxdfamon.exe" [2007-06-01 20480]
"Lexmark 6500 Series Fax Server"="c:\program files\Lexmark 6500 Series\fm3032.exe" [2007-06-12 308144]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-07-08 1176808]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2006-11-02 215552]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-09-07 405504]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"YMailAdvisor"="c:\program files\Yahoo!\Common\YMailAdvisor.exe" [2009-05-08 174424]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-03 111856]
"Clearwire Connection Manager"="c:\program files\Clearwire\Connection Manager\ClearwireCM.exe" [2009-02-03 54536]
"SSDMonitor"="c:\program files\Common Files\PC Tools\sMonitor\SSDMonitor.exe" [2009-11-25 104408]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-3 703280]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-8-17 50688]
QuickSet.lnk - c:\windows\Installer\{7F0C4457-8E64-491B-8D7B-991504365D1E}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe [2007-8-17 45056]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):d1,3c,2e,60,cc,54,ca,01
R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\AEstSrv.exe [12/19/2007 1:03 PM 73728]
R2 lxdf_device;lxdf_device;c:\windows\system32\lxdfcoms.exe -service --> c:\windows\system32\lxdfcoms.exe -service [?]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [9/1/2009 10:10 PM 93320]
R2 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\Common Files\PC Tools\sMonitor\StartManSvc.exe [12/15/2009 8:24 PM 583640]
R2 Workshare Protect Service;Workshare Protect Service;"c:\program files\Workshare\Modules\Workshare.Protect.Service.SvcHost.exe" [9/11/2008 6:06 PM 36864]
S2 gupdate1ca002a258b101a;Google Update Service (gupdate1ca002a258b101a);c:\program files\Google\Update\GoogleUpdate.exe [7/8/2009 6:13 PM 133104]
S2 lxdfCATSCustConnectService;lxdfCATSCustConnectService;c:\windows\System32\spool\drivers\w32x86\3\lxdfserv.exe [5/29/2007 12:06 PM 99248]
S3 bcm;Beceem Communications Inc. Tarang3;c:\windows\System32\drivers\drxvi314.sys [12/3/2009 12:53 PM 233472]
S3 bcmbusctr;Beceem Devices' Enumerator Driver;c:\windows\System32\drivers\BcmBusCtr.sys [12/3/2009 12:53 PM 54784]
S3 CACLEARWIRE;Clearwire Con App Svc;c:\program files\Clearwire\Connection Manager\ConAppsSvc.exe [1/27/2009 1:40 PM 124168]
S3 CLEARWIRERcAppSvc;Clearwire RcAppSvc;c:\program files\Clearwire\Connection Manager\RcAppSvc.exe [1/27/2009 1:40 PM 111880]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [7/18/2008 11:53 PM 21504]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\Workshare Professional 5.21.9652.292]
2008-09-13 18:03 2338816 ----a-w- c:\program files\Workshare\Modules\WMConfigAssistant.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\Workshare Protect Client]
2008-09-12 00:12 20480 ----a-w- c:\program files\Workshare\Modules\Workshare.Protect.UserInit.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 11:32 128512 ----a-w- c:\windows\System32\advpack.dll
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/?fr=fp-yie8
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*
http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
IE: &Search -
http://edits.mywebsearch.com/toolbar...p=ZNxdm117MNUS
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: internet
Trusted Zone: mcafee.com
DPF: CabBuilder - hxxp://ak.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
FF - ProfilePath - c:\users\The Dents\AppData\Roaming\Mozilla\Firefox\Profiles\9mvim6w3.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com//?fr=fp-yma3
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-yma3&type=&p=
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - (no file)
HKCU-Run-PalmOneWMPURL - e:\english\essential_software\URL\URL.bat
HKCU-Run-PalmOneAutoRun - e:\english\essential_software\Software Essentials.exe
HKLM-Run-SelectRebates - c:\program files\SelectRebates\SelectRebates.exe
**************************************************************************
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCJCATS = rundll32 c:\windows\system32\spool\DRIVERS\W32X86\3\LXCJtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aac\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aifc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aiff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flac\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4a\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.midi\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pls\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.snd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.spx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-12-19 11:30:21
ComboFix-quarantined-files.txt 2009-12-19 17:30
Pre-Run: 89,902,460,928 bytes free
Post-Run: 90,136,006,656 bytes free
- - End Of File - - D42BA1F2EFF242A676618DF399309E29