After reading a previous post on this subject, I have run combofix. That's all I have done, and the log is below. Thank you.
ComboFix 10-01-04.01 - Nathaniel 01/08/2010 14:33:28.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.662 [GMT -5:00]
Running from: c:\documents and settings\Nathaniel\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\LocalService\Local Settings\Temporary Internet Files\Dxc.log
c:\documents and settings\Nathaniel\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Security 2010.lnk
c:\documents and settings\Nathaniel\Desktop\Internet Security 2010.lnk
c:\documents and settings\Nathaniel\Start Menu\Internet Security 2010.lnk
c:\documents and settings\NetworkService\Local Settings\Temporary Internet Files\Dxc.log
C:\LOG.TXT
c:\progra~1\3D\NTSVc.ocx
c:\program files\INSTALL.LOG
c:\program files\InternetSecurity2010
c:\program files\InternetSecurity2010\IS2010.exe
c:\program files\MSN\cewuemyjy.html
C:\resycled
c:\windows\a3kebook.ini
c:\windows\akebook.ini
c:\windows\ANS2000.INI
c:\windows\Downloaded Program Files\setup.dll
c:\windows\system32\18467.exe
c:\windows\system32\41.exe
c:\windows\system32\Cache
c:\windows\system32\Data
c:\windows\system32\Data\CTP0243W.DAT
c:\windows\system32\drivers\msqpdxtiltowyp.sys
c:\windows\system32\drivers\msqpdxwstqmxws.sys
c:\windows\system32\helper32.dll
c:\windows\system32\ldinfo.ldr
c:\windows\system32\mcrh.tmp
c:\windows\system32\msqpdxuktuirqm.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_msqpdxserv.sys
-------\Legacy_msqpdxserv.sys
-------\Legacy_COM+_MESSAGES
-------\Legacy_MSASVC
-------\Legacy_WINDOWS_OVERLAY_COMPONENTS
((((((((((((((((((((((((( Files Created from 2009-12-08 to 2010-01-08 )))))))))))))))))))))))))))))))
.
2010-01-08 19:41 . 2010-01-08 19:41 1337856 ----a-w- c:\windows\system32\IS15.exe
2010-01-08 19:41 . 2010-01-08 19:41 17408 ----a-w- c:\windows\system32\helper32.dll
2010-01-08 18:51 . 2010-01-08 18:51 33792 ----a-w- c:\windows\system32\winlogon32.exe
2010-01-08 18:51 . 2010-01-08 18:51 33792 ----a-w- c:\windows\system32\smss32.exe
2009-12-20 02:20 . 2009-12-20 02:20 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2009-12-12 14:40 . 2009-12-22 13:49 2066200 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-08 19:41 . 2010-01-08 19:41 0 ----a-w- c:\windows\system32\41.exe
2010-01-08 19:39 . 2003-07-25 11:51 288 ----a-w- c:\windows\system32\DVCStateBkp-{00000002-00000000-00000001-00001102-00000004-10031102}.dat
2010-01-08 19:39 . 2003-07-25 11:51 288 ----a-w- c:\windows\system32\DVCState-{00000002-00000000-00000001-00001102-00000004-10031102}.dat
2010-01-08 19:38 . 2003-12-07 23:21 -------- d-----w- c:\program files\3D
2010-01-08 19:11 . 2007-08-27 03:02 -------- d-----w- c:\documents and settings\Nathaniel\Application Data\Implant Dentistry
2010-01-07 04:39 . 2007-08-27 01:48 -------- d-----w- c:\program files\Implant Dentistry
2009-12-20 02:21 . 2007-02-14 02:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-06 16:52 . 2009-12-06 16:49 20 ---h--w- c:\documents and settings\All Users\Application Data\PKP_DLdw.DAT
2009-12-06 16:52 . 2009-12-06 16:51 -------- d-----w- c:\documents and settings\Nathaniel\Application Data\Nikon
2009-12-06 16:51 . 2009-12-06 16:48 20 ---h--w- c:\documents and settings\All Users\Application Data\PKP_DLdu.DAT
2009-12-06 16:50 . 2009-12-06 16:50 49152 ----a-r- c:\documents and settings\Nathaniel\Application Data\Microsoft\Installer\{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}\ARPPRODUCTICON.exe
2009-12-06 16:50 . 2009-12-06 16:49 -------- d-----w- c:\program files\Common Files\Nikon
2009-12-06 16:50 . 2009-12-06 16:50 57344 ----a-r- c:\documents and settings\Nathaniel\Application Data\Microsoft\Installer\{87441A59-5E64-4096-A170-14EFE67200C3}\ARPPRODUCTICON.exe
2009-12-06 16:49 . 2009-12-06 16:49 -------- d-----w- c:\program files\Nikon
2009-12-06 16:49 . 2009-12-06 16:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Ultima_T15
2009-12-06 16:49 . 2009-12-06 16:48 -------- d-----w- c:\documents and settings\All Users\Application Data\EnterNHelp
2009-12-06 16:49 . 2009-12-06 16:49 -------- d-----w- c:\program files\Common Files\muvee Technologies
2009-12-06 16:49 . 2009-12-06 16:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Nikon
2009-12-06 16:48 . 2008-12-26 04:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-11-22 17:22 . 2003-07-29 20:00 -------- d-----w- c:\documents and settings\Nathaniel\Application Data\Aim
2009-11-12 03:07 . 2009-11-12 03:07 -------- d-----w- c:\documents and settings\Nathaniel\Application Data\NeroDigital
2009-11-09 02:38 . 2009-11-09 02:38 152576 ----a-w- c:\documents and settings\Nathaniel\Application Data\Sun\Java\jre1.6.0_16\lzma.dll
2008-01-21 01:09 . 2008-01-20 19:23 72 --sh--w- c:\windows\SA63D8217.tmp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-14 21:07 1004800 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-25 68856]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PRONoMgr.exe"="c:\program files\Intel\NCS\PROSet\PRONoMgr.exe" [2003-03-11 86016]
"ATIPTA"="c:\program files\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE" [2003-02-21 315392]
"DVDSentry"="c:\windows\System32\DSentry.exe" [2002-08-14 28672]
"CTSysVol"="c:\program files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe" [2002-10-29 49152]
"CTDVDDet"="c:\program files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE" [2002-09-30 45056]
"CTHelper"="CTHELPER.EXE" [2003-02-20 28672]
"AsioReg"="CTASIO.DLL" [2003-02-20 110592]
"MoneyStartUp10.0"="c:\program files\Microsoft Money\System\Activation.exe" [2001-07-25 241714]
"AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-12-17 684032]
"HPDJ Taskbar Utility"="c:\windows\System32\spool\drivers\w32x86\3\hpztsb05.exe" [2002-05-24 188416]
"HPHmon04"="c:\windows\System32\hphmon04.exe" [2002-06-20 339968]
"HPHUPD04"="c:\program files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe" [2002-05-24 49152]
"Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-17 69632]
"DeadAIM"="c:\program files\AIM\\DeadAIM.ocm" [2003-02-24 266313]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-12-12 2043160]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-05-30 292136]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2008-07-09 570664]
"smss32.exe"="c:\windows\system32\smss32.exe" [2010-01-08 33792]
c:\documents and settings\Nathaniel\Start Menu\Programs\Startup\
Nikon Monitor.lnk - c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe [2007-10-18 479232]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
APC UPS Status.lnk - c:\program files\APC\APC PowerChute Personal Edition\Display.exe [2003-7-29 221247]
Device Detector 3.lnk - c:\program files\OLYMPUS\DeviceDetector\DevDtct2.exe [2007-1-14 114688]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"SpecifyDefaultButtons"= 0 (0x0)
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\system32\winlogon32.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-28 13:03 11952 ----a-w- c:\windows\SYSTEM32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"%windir%\\system32\\tcpip.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Nero\\Nero8\\Nero Home\\NeroHome.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [2/8/2009 8:49 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [2/8/2009 8:49 PM 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [6/2/2009 2:32 PM 297752]
S2 OlCamudp;OLYMPUS Digital Camera;c:\windows\SYSTEM32\DRIVERS\olcamudp.sys [7/31/2003 12:07 AM 10379]
S3 MA8512M;MA8512M;c:\windows\SYSTEM32\DRIVERS\MA8512M.sys [1/25/2006 4:22 PM 25300]
S3 MA8512U;MA8512U;c:\windows\SYSTEM32\DRIVERS\MA8512U.sys [1/25/2006 4:22 PM 49106]
S3 NUVision;NUVision II Video Service;c:\windows\SYSTEM32\DRIVERS\nuvvid2.sys [10/18/2003 3:40 PM 153760]
S3 scsiscan;SCSI Scanner Driver;c:\windows\SYSTEM32\DRIVERS\scsiscan.sys [1/9/2008 4:48 PM 10880]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-02-25 16:12 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
2009-12-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2009-12-19 c:\windows\Tasks\Windows Update.job
- c:\windows\SYSTEM32\WUPDMGR.EXE [2002-08-29 10:00]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.mustangworld.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: c:\windows\system32\helper32.dll
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {1C3DE665-D259-4C72-9D7D-C51FCB4CCFB9} - hxxp://modularmadness.viewnetcam.com:50001/SysCamInst.cab
FF - ProfilePath - c:\documents and settings\Nathaniel\Application Data\Mozilla\Firefox\Profiles\2k8wucy6.default\
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\Nathaniel\Application Data\Mozilla\Firefox\Profiles\2k8wucy6.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPZoneSB.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nppl3260.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nprjplug.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nprpjplug.dll
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-SB Audigy 2 Startup Menu - (no file)
HKCU-Run-Internet Security 2010 - c:\program files\InternetSecurity2010\IS2010.exe
Notify-AtiExtEvent - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-08 14:41
Windows 5.1.2600 Service Pack 2 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
c:\windows\system32\helper32.dll 17408 bytes executable
c:\windows\system32\IS15.exe 1337856 bytes executable
scan completed successfully
hȋdden files: 2
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\APC\APC PowerChute Personal Edition\mainserv.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\System32\CTsvcCDA.exe
c:\windows\System32\inetsrv\inetinfo.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\wdfmgr.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\System32\MsPMSPSv.exe
c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Nero\Lib\NMIndexingService.exe
c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
.
**************************************************************************
.
Completion time: 2010-01-08 14:46:57 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-08 19:46
Pre-Run: 19,487,178,752 bytes free
Post-Run: 20,181,975,040 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
- - End Of File - - 10F5F90F5581934584B9482C7ECD404E
ComboFix 10-01-04.01 - Nathaniel 01/08/2010 14:33:28.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.662 [GMT -5:00]
Running from: c:\documents and settings\Nathaniel\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\LocalService\Local Settings\Temporary Internet Files\Dxc.log
c:\documents and settings\Nathaniel\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Security 2010.lnk
c:\documents and settings\Nathaniel\Desktop\Internet Security 2010.lnk
c:\documents and settings\Nathaniel\Start Menu\Internet Security 2010.lnk
c:\documents and settings\NetworkService\Local Settings\Temporary Internet Files\Dxc.log
C:\LOG.TXT
c:\progra~1\3D\NTSVc.ocx
c:\program files\INSTALL.LOG
c:\program files\InternetSecurity2010
c:\program files\InternetSecurity2010\IS2010.exe
c:\program files\MSN\cewuemyjy.html
C:\resycled
c:\windows\a3kebook.ini
c:\windows\akebook.ini
c:\windows\ANS2000.INI
c:\windows\Downloaded Program Files\setup.dll
c:\windows\system32\18467.exe
c:\windows\system32\41.exe
c:\windows\system32\Cache
c:\windows\system32\Data
c:\windows\system32\Data\CTP0243W.DAT
c:\windows\system32\drivers\msqpdxtiltowyp.sys
c:\windows\system32\drivers\msqpdxwstqmxws.sys
c:\windows\system32\helper32.dll
c:\windows\system32\ldinfo.ldr
c:\windows\system32\mcrh.tmp
c:\windows\system32\msqpdxuktuirqm.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_msqpdxserv.sys
-------\Legacy_msqpdxserv.sys
-------\Legacy_COM+_MESSAGES
-------\Legacy_MSASVC
-------\Legacy_WINDOWS_OVERLAY_COMPONENTS
((((((((((((((((((((((((( Files Created from 2009-12-08 to 2010-01-08 )))))))))))))))))))))))))))))))
.
2010-01-08 19:41 . 2010-01-08 19:41 1337856 ----a-w- c:\windows\system32\IS15.exe
2010-01-08 19:41 . 2010-01-08 19:41 17408 ----a-w- c:\windows\system32\helper32.dll
2010-01-08 18:51 . 2010-01-08 18:51 33792 ----a-w- c:\windows\system32\winlogon32.exe
2010-01-08 18:51 . 2010-01-08 18:51 33792 ----a-w- c:\windows\system32\smss32.exe
2009-12-20 02:20 . 2009-12-20 02:20 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2009-12-12 14:40 . 2009-12-22 13:49 2066200 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-08 19:41 . 2010-01-08 19:41 0 ----a-w- c:\windows\system32\41.exe
2010-01-08 19:39 . 2003-07-25 11:51 288 ----a-w- c:\windows\system32\DVCStateBkp-{00000002-00000000-00000001-00001102-00000004-10031102}.dat
2010-01-08 19:39 . 2003-07-25 11:51 288 ----a-w- c:\windows\system32\DVCState-{00000002-00000000-00000001-00001102-00000004-10031102}.dat
2010-01-08 19:38 . 2003-12-07 23:21 -------- d-----w- c:\program files\3D
2010-01-08 19:11 . 2007-08-27 03:02 -------- d-----w- c:\documents and settings\Nathaniel\Application Data\Implant Dentistry
2010-01-07 04:39 . 2007-08-27 01:48 -------- d-----w- c:\program files\Implant Dentistry
2009-12-20 02:21 . 2007-02-14 02:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-06 16:52 . 2009-12-06 16:49 20 ---h--w- c:\documents and settings\All Users\Application Data\PKP_DLdw.DAT
2009-12-06 16:52 . 2009-12-06 16:51 -------- d-----w- c:\documents and settings\Nathaniel\Application Data\Nikon
2009-12-06 16:51 . 2009-12-06 16:48 20 ---h--w- c:\documents and settings\All Users\Application Data\PKP_DLdu.DAT
2009-12-06 16:50 . 2009-12-06 16:50 49152 ----a-r- c:\documents and settings\Nathaniel\Application Data\Microsoft\Installer\{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}\ARPPRODUCTICON.exe
2009-12-06 16:50 . 2009-12-06 16:49 -------- d-----w- c:\program files\Common Files\Nikon
2009-12-06 16:50 . 2009-12-06 16:50 57344 ----a-r- c:\documents and settings\Nathaniel\Application Data\Microsoft\Installer\{87441A59-5E64-4096-A170-14EFE67200C3}\ARPPRODUCTICON.exe
2009-12-06 16:49 . 2009-12-06 16:49 -------- d-----w- c:\program files\Nikon
2009-12-06 16:49 . 2009-12-06 16:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Ultima_T15
2009-12-06 16:49 . 2009-12-06 16:48 -------- d-----w- c:\documents and settings\All Users\Application Data\EnterNHelp
2009-12-06 16:49 . 2009-12-06 16:49 -------- d-----w- c:\program files\Common Files\muvee Technologies
2009-12-06 16:49 . 2009-12-06 16:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Nikon
2009-12-06 16:48 . 2008-12-26 04:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-11-22 17:22 . 2003-07-29 20:00 -------- d-----w- c:\documents and settings\Nathaniel\Application Data\Aim
2009-11-12 03:07 . 2009-11-12 03:07 -------- d-----w- c:\documents and settings\Nathaniel\Application Data\NeroDigital
2009-11-09 02:38 . 2009-11-09 02:38 152576 ----a-w- c:\documents and settings\Nathaniel\Application Data\Sun\Java\jre1.6.0_16\lzma.dll
2008-01-21 01:09 . 2008-01-20 19:23 72 --sh--w- c:\windows\SA63D8217.tmp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-14 21:07 1004800 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-25 68856]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PRONoMgr.exe"="c:\program files\Intel\NCS\PROSet\PRONoMgr.exe" [2003-03-11 86016]
"ATIPTA"="c:\program files\ATI TECHNOLOGIES\ATI CONTROL PANEL\ATIPTAXX.EXE" [2003-02-21 315392]
"DVDSentry"="c:\windows\System32\DSentry.exe" [2002-08-14 28672]
"CTSysVol"="c:\program files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe" [2002-10-29 49152]
"CTDVDDet"="c:\program files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE" [2002-09-30 45056]
"CTHelper"="CTHELPER.EXE" [2003-02-20 28672]
"AsioReg"="CTASIO.DLL" [2003-02-20 110592]
"MoneyStartUp10.0"="c:\program files\Microsoft Money\System\Activation.exe" [2001-07-25 241714]
"AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-12-17 684032]
"HPDJ Taskbar Utility"="c:\windows\System32\spool\drivers\w32x86\3\hpztsb05.exe" [2002-05-24 188416]
"HPHmon04"="c:\windows\System32\hphmon04.exe" [2002-06-20 339968]
"HPHUPD04"="c:\program files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe" [2002-05-24 49152]
"Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-17 69632]
"DeadAIM"="c:\program files\AIM\\DeadAIM.ocm" [2003-02-24 266313]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-12-12 2043160]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-05-30 292136]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2008-07-09 570664]
"smss32.exe"="c:\windows\system32\smss32.exe" [2010-01-08 33792]
c:\documents and settings\Nathaniel\Start Menu\Programs\Startup\
Nikon Monitor.lnk - c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe [2007-10-18 479232]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
APC UPS Status.lnk - c:\program files\APC\APC PowerChute Personal Edition\Display.exe [2003-7-29 221247]
Device Detector 3.lnk - c:\program files\OLYMPUS\DeviceDetector\DevDtct2.exe [2007-1-14 114688]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"SpecifyDefaultButtons"= 0 (0x0)
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Userinit"="c:\windows\system32\winlogon32.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-28 13:03 11952 ----a-w- c:\windows\SYSTEM32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"%windir%\\system32\\tcpip.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Nero\\Nero8\\Nero Home\\NeroHome.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [2/8/2009 8:49 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [2/8/2009 8:49 PM 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [6/2/2009 2:32 PM 297752]
S2 OlCamudp;OLYMPUS Digital Camera;c:\windows\SYSTEM32\DRIVERS\olcamudp.sys [7/31/2003 12:07 AM 10379]
S3 MA8512M;MA8512M;c:\windows\SYSTEM32\DRIVERS\MA8512M.sys [1/25/2006 4:22 PM 25300]
S3 MA8512U;MA8512U;c:\windows\SYSTEM32\DRIVERS\MA8512U.sys [1/25/2006 4:22 PM 49106]
S3 NUVision;NUVision II Video Service;c:\windows\SYSTEM32\DRIVERS\nuvvid2.sys [10/18/2003 3:40 PM 153760]
S3 scsiscan;SCSI Scanner Driver;c:\windows\SYSTEM32\DRIVERS\scsiscan.sys [1/9/2008 4:48 PM 10880]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2009-02-25 16:12 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
2009-12-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2009-12-19 c:\windows\Tasks\Windows Update.job
- c:\windows\SYSTEM32\WUPDMGR.EXE [2002-08-29 10:00]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.mustangworld.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: c:\windows\system32\helper32.dll
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {1C3DE665-D259-4C72-9D7D-C51FCB4CCFB9} - hxxp://modularmadness.viewnetcam.com:50001/SysCamInst.cab
FF - ProfilePath - c:\documents and settings\Nathaniel\Application Data\Mozilla\Firefox\Profiles\2k8wucy6.default\
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\Nathaniel\Application Data\Mozilla\Firefox\Profiles\2k8wucy6.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPZoneSB.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nppl3260.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nprjplug.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nprpjplug.dll
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-SB Audigy 2 Startup Menu - (no file)
HKCU-Run-Internet Security 2010 - c:\program files\InternetSecurity2010\IS2010.exe
Notify-AtiExtEvent - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-08 14:41
Windows 5.1.2600 Service Pack 2 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
c:\windows\system32\helper32.dll 17408 bytes executable
c:\windows\system32\IS15.exe 1337856 bytes executable
scan completed successfully
hȋdden files: 2
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\APC\APC PowerChute Personal Edition\mainserv.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\System32\CTsvcCDA.exe
c:\windows\System32\inetsrv\inetinfo.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\wdfmgr.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\System32\MsPMSPSv.exe
c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Nero\Lib\NMIndexingService.exe
c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
.
**************************************************************************
.
Completion time: 2010-01-08 14:46:57 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-08 19:46
Pre-Run: 19,487,178,752 bytes free
Post-Run: 20,181,975,040 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
- - End Of File - - 10F5F90F5581934584B9482C7ECD404E