about to run MBAM right now, but here's the combofix results.
ComboFix 10-07-21.02 - Nathalie 22/07/2010 13:44:05.4.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.2.1033.18.3070.1785 [GMT -7:00]
Running from: c:\users\Nathalie\Desktop\ComboFix.exe
Command switches used :: c:\users\Nathalie\Desktop\CFScript.txt
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\LimeWire
c:\program files\LimeWire\aopalliance.jar.tmp
c:\program files\LimeWire\clink.jar.tmp
c:\program files\LimeWire\commons-codec-1.3.jar.tmp
c:\program files\LimeWire\commons-logging.jar.tmp
c:\program files\LimeWire\commons-net.jar.tmp
c:\program files\LimeWire\daap.jar.tmp
c:\program files\LimeWire\dnsjava.jar.tmp
c:\program files\LimeWire\forms.jar.tmp
c:\program files\LimeWire\foxtrot.jar.tmp
c:\program files\LimeWire\gettext-commons.jar.tmp
c:\program files\LimeWire\guice-1.0.jar.tmp
c:\program files\LimeWire\hsqldb.jar.tmp
c:\program files\LimeWire\httpclient-4.0-alpha5-20080522.192134-5.jar.tmp
c:\program files\LimeWire\httpcore-4.0-beta2-20080510.140437-10.jar.tmp
c:\program files\LimeWire\httpcore-nio-4.0-beta2-20080510.140437-10.jar.tmp
c:\program files\LimeWire\icu4j.jar.tmp
c:\program files\LimeWire\jaudiotagger.jar.tmp
c:\program files\LimeWire\jcraft.jar.tmp
c:\program files\LimeWire\jdic.jar.tmp
c:\program files\LimeWire\jdic_stub.jar.tmp
c:\program files\LimeWire\jflac.jar.tmp
c:\program files\LimeWire\jl.jar.tmp
c:\program files\LimeWire\jmdns.jar.tmp
c:\program files\LimeWire\jogg.jar.tmp
c:\program files\LimeWire\jorbis.jar.tmp
c:\program files\LimeWire\log4j.jar.tmp
c:\program files\LimeWire\looks.jar.tmp
c:\program files\LimeWire\messages.jar.tmp
c:\program files\LimeWire\mp3spi.jar.tmp
c:\program files\LimeWire\onion-common.jar.tmp
c:\program files\LimeWire\onion-fec.jar.tmp
c:\program files\LimeWire\ProgressTabs.jar.tmp
c:\program files\LimeWire\swt.jar.tmp
c:\program files\LimeWire\themes.jar.tmp
c:\program files\LimeWire\toolbarResult
c:\program files\LimeWire\tritonus.jar.tmp
c:\program files\LimeWire\vorbisspi.jar.tmp
.
((((((((((((((((((((((((( Files Created from 2010-06-22 to 2010-07-22 )))))))))))))))))))))))))))))))
.
2010-07-22 20:49 . 2010-07-22 20:57 -------- d-----w- c:\users\Nathalie\AppData\Local\temp
2010-07-22 20:49 . 2010-07-22 20:49 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-07-22 20:49 . 2010-07-22 20:49 -------- d-----w- c:\users\Guest\AppData\Local\temp
2010-07-22 20:49 . 2010-07-22 20:49 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-07-22 08:49 . 2010-07-22 08:49 -------- d-----w- c:\users\Nathalie\AppData\Local\Threat Expert
2010-07-22 07:23 . 2010-07-22 07:23 -------- d-----w- c:\program files\Enigma Software Group
2010-07-22 07:21 . 2010-07-22 07:38 -------- d-----w- c:\windows\95431C66CF9A4913BFFF6050785AFB65.TMP
2010-07-22 07:21 . 2010-07-22 07:21 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-07-22 07:07 . 2010-07-22 09:03 -------- d-----w- c:\program files\Spyware Doctor
2010-07-22 06:43 . 2010-07-22 20:57 766464 ----a-w- c:\windows\system32\drivers\elpiy.sys
2010-07-22 06:43 . 2010-07-22 18:35 120 ----a-w- c:\users\Nathalie\AppData\Local\Pwimixor.dat
2010-07-22 06:43 . 2010-07-22 08:36 0 ----a-w- c:\users\Nathalie\AppData\Local\Nzuwatodejex.bin
2010-07-15 18:46 . 2010-07-15 18:46 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-07-09 09:12 . 2010-07-09 09:12 -------- d-----w- c:\program files\Common Files\Java
2010-07-09 09:12 . 2010-07-09 09:12 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-06-26 20:54 . 2010-04-14 17:47 293376 ----a-w- c:\windows\system32\psisdecd.dll
2010-06-26 20:53 . 2010-04-14 17:46 428544 ----a-w- c:\windows\system32\EncDec.dll
2010-06-25 10:00 . 2009-11-08 17:55 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-06-25 10:00 . 2009-11-08 17:55 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-06-25 10:00 . 2009-11-08 17:55 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-06-25 10:00 . 2009-11-08 17:55 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-06-25 10:00 . 2009-11-08 17:55 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-06-23 21:35 . 2010-04-16 16:05 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2010-06-23 21:35 . 2010-04-16 14:17 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-22 09:04 . 2008-08-08 21:53 67100 ----a-w- c:\users\Nathalie\AppData\Roaming\nvModes.dat
2010-07-22 09:04 . 2008-08-07 04:31 109200 ----a-w- c:\users\Nathalie\AppData\Local\GDIPFONTCACHEV1.DAT
2010-07-22 07:21 . 2009-07-10 08:03 -------- d-----w- c:\program files\BitLord
2010-07-15 18:46 . 2010-01-11 06:24 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-07-15 18:46 . 2010-01-11 06:24 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-07-14 21:02 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-07-14 08:24 . 2009-05-04 03:16 -------- d-----w- c:\users\Nathalie\AppData\Roaming\dvdcss
2010-07-09 09:12 . 2008-04-25 03:08 -------- d-----w- c:\program files\Java
2010-07-09 09:08 . 2008-04-25 00:41 725832 ----a-w- c:\windows\system32\perfh00C.dat
2010-07-09 09:08 . 2008-04-25 00:41 150634 ----a-w- c:\windows\system32\perfc00C.dat
2010-06-25 10:03 . 2008-08-07 04:22 -------- d-----w- c:\program files\Microsoft.NET
2010-06-17 09:25 . 2010-06-17 09:25 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2010-06-10 20:07 . 2009-04-27 04:49 -------- d-----w- c:\program files\Microsoft Silverlight
2010-06-10 10:18 . 2008-08-07 04:21 -------- d-----w- c:\programdata\Microsoft Help
2010-06-08 23:13 . 2010-06-08 23:13 -------- d-----w- c:\users\Guest\AppData\Roaming\Malwarebytes
2010-06-08 23:13 . 2010-06-08 23:13 -------- d-----w- c:\users\Guest\AppData\Roaming\Apple Computer
2010-06-08 23:13 . 2010-06-08 23:13 109200 ----a-w- c:\users\Guest\AppData\Local\GDIPFONTCACHEV1.DAT
2010-06-04 08:15 . 2010-06-04 07:40 -------- d-----w- c:\program files\Cooking Academy
2010-06-04 07:38 . 2010-06-04 07:38 -------- d-----w- c:\program files\bfgclient
2010-06-03 22:19 . 2008-06-18 14:02 -------- d-----w- c:\program files\HP Games
2010-06-03 09:27 . 2008-06-18 14:01 -------- d-----w- c:\programdata\WildTangent
2010-06-03 09:25 . 2010-06-03 09:25 -------- d-----w- c:\programdata\Fugazo
2010-06-02 21:34 . 2010-01-11 06:24 29584 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-05-30 10:30 . 2010-05-30 10:30 -------- d-----w- c:\users\Nathalie\AppData\Roaming\Ludia
2010-05-30 10:30 . 2010-05-30 10:30 -------- d-----w- c:\programdata\Ludia
2010-05-30 02:10 . 2010-05-30 02:10 -------- d-----w- c:\users\Nathalie\AppData\Roaming\funkitron
2010-05-26 16:16 . 2010-06-10 09:34 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-05-26 14:25 . 2010-06-10 09:34 289792 ----a-w- c:\windows\system32\atmfd.dll
2010-05-04 18:42 . 2010-06-10 09:34 833024 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 18:37 . 2010-06-10 09:34 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-05-04 16:53 . 2010-06-10 09:34 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2010-05-01 13:53 . 2010-06-10 09:33 2036224 ----a-w- c:\windows\system32\win32k.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{9b339f6e-ddcd-401b-8764-230adbd01761}"= "c:\program files\Messenger_Plus_Live\tbMess.dll" [2009-12-31 2349080]
[HKEY_CLASSES_ROOT\clsid\{9b339f6e-ddcd-401b-8764-230adbd01761}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9b339f6e-ddcd-401b-8764-230adbd01761}]
2009-12-31 19:53 2349080 ----a-w- c:\program files\Messenger_Plus_Live\tbMess.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{9b339f6e-ddcd-401b-8764-230adbd01761}"= "c:\program files\Messenger_Plus_Live\tbMess.dll" [2009-12-31 2349080]
[HKEY_CLASSES_ROOT\clsid\{9b339f6e-ddcd-401b-8764-230adbd01761}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{9B339F6E-DDCD-401B-8764-230ADBD01761}"= "c:\program files\Messenger_Plus_Live\tbMess.dll" [2009-12-31 2349080]
[HKEY_CLASSES_ROOT\clsid\{9b339f6e-ddcd-401b-8764-230adbd01761}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"Gestionnaire Antidote.exe"="c:\program files\Druide\Antidote\Gestionnaire Antidote.exe" [2006-09-11 439992]
"Gcuzayerox"="c:\users\Nathalie\AppData\Local\prvwbar.dll" [2008-01-21 72192]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-09-19 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-19 8497696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-09-19 81920]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-18 1033512]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-09-19 202032]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-09-04 554320]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 311296]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-15 49152]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-01-08 1394000]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-07-15 2065760]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-03-26 142120]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Gestionnaire Antidote.exe"="c:\program files\Druide\Antidote\Gestionnaire Antidote.exe" [2006-09-11 439992]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnk.CommonStartup
backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2009-07-26 23:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UCam_Menu]
2007-08-17 06:13 218408 ------w- c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate1ca2d0924894d30;Google Update Service (gupdate1ca2d0924894d30);c:\program files\Google\Update\GoogleUpdate.exe [2009-09-04 133104]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2009-05-28 721904]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-07-15 216400]
S1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2010-07-15 243024]
S2 {22D78859-9CE9-4B77-BF18-AC83E81A9263};{22D78859-9CE9-4B77-BF18-AC83E81A9263};c:\program files\HP\QuickPlay\000.fcl [2007-12-20 41456]
S2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-07-15 308136]
--- Other Services/Drivers In Memory ---
*Deregistered* - elpiy
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2010-07-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-04 02:40]
2010-07-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-04 02:40]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.facebook.com/?ref=hpmStart Page =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_ca&c=81&bd=Pavilion&pf=laptopIE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
DPF: CabBuilder -
hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab.
**************************************************************************
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{22D78859-9CE9-4B77-BF18-AC83E81A9263}]
"ImagePath"="\??\c:\program files\HP\QuickPlay\000.fcl"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\elpiy]
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(3728)
c:\program files\Hewlett-Packard\HP Advisor\Pillars\Market\MLDeskBand.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\WLANExt.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\HP\QuickPlay\Kernel\TV\QPSched.exe
c:\windows\system32\conime.exe
c:\windows\System32\rundll32.exe
c:\program files\AVG\AVG9\avgtray.exe
c:\program files\Hewlett-Packard\Shared\HpqToaster.exe
c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\servicing\TrustedInstaller.exe
c:\program files\Common Files\Java\Java Update\jucheck.exe
.
**************************************************************************
.
Completion time: 2010-07-22 14:07:58 - machine was rebooted
ComboFix-quarantined-files.txt 2010-07-22 21:07
ComboFix2.txt 2010-07-22 19:00
ComboFix3.txt 2010-01-11 03:42
ComboFix4.txt 2010-01-11 02:02
Pre-Run: 79,597,232,128 bytes free
Post-Run: 79,804,026,880 bytes free
- - End Of File - - BA8E1AC00BB482186072187EB63546D8