Below is the log. By the way, once combofix was finished running I tried opening firefox and then explorer and got the same error message for both - "Illegal operation attempted o a registry key that has been marked for deletion." So I had to restart the computer and then firefox was able to be opened.
ComboFix 10-10-01.07 - JohnAdmin 10/02/2010 13:11:36.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3069.1789 [GMT -4:00]
Running from: c:\users\John & Sophie\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Files Created from 2010-09-02 to 2010-10-02 )))))))))))))))))))))))))))))))
.
2010-10-02 17:18 . 2010-10-02 17:18 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-10-02 17:18 . 2010-10-02 17:18 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-10-02 17:18 . 2010-10-02 17:18 -------- d-----w- c:\users\JohnAdmin\AppData\Local\temp
2010-10-02 17:06 . 2010-10-02 17:07 -------- d-----w- C:\32788R22FWJFW
2010-09-30 00:22 . 2010-04-28 21:35 267896 ----a-w- c:\programdata\McAfee\MSC\Updates\Installs\3\msc\mcutil.dll
2010-09-30 00:22 . 2010-04-28 21:13 820488 ----a-w- c:\programdata\McAfee\MSC\Updates\Installs\3\msc\McInst.exe
2010-09-29 23:16 . 2010-04-28 21:35 267896 ----a-w- c:\programdata\McAfee\MSC\Updates\Installs\2\msc\mcutil.dll
2010-09-29 23:16 . 2010-04-28 21:13 820488 ----a-w- c:\programdata\McAfee\MSC\Updates\Installs\2\msc\McInst.exe
2010-09-29 13:27 . 2010-04-28 21:35 267896 ----a-w- c:\programdata\McAfee\MSC\Updates\Installs\Download_Files\vso\mcutil.dll
2010-09-29 13:27 . 2010-04-28 21:35 267896 ----a-w- c:\programdata\McAfee\MSC\Updates\Installs\Download_Files\msc\mcutil.dll
2010-09-29 13:27 . 2010-04-28 21:35 267896 ----a-w- c:\programdata\McAfee\MSC\Updates\Installs\1\msc\mcutil.dll
2010-09-29 13:27 . 2010-04-28 21:13 820488 ----a-w- c:\programdata\McAfee\MSC\Updates\Installs\Download_Files\vso\McInst.exe
2010-09-29 13:27 . 2010-04-28 21:13 820488 ----a-w- c:\programdata\McAfee\MSC\Updates\Installs\Download_Files\msc\McInst.exe
2010-09-29 13:27 . 2010-04-28 21:13 820488 ----a-w- c:\programdata\McAfee\MSC\Updates\Installs\1\msc\McInst.exe
2010-09-29 07:09 . 2010-06-22 12:57 2048 ----a-w- c:\windows\system32\tzres.dll
2010-09-25 10:18 . 2010-09-25 10:18 -------- d-----w- c:\programdata\WindowsSearch
2010-09-23 12:56 . 2010-09-23 12:56 620896 ----a-w- c:\programdata\avg9\update\backup\avgnsx.exe
2010-09-23 12:56 . 2010-09-23 12:56 4093792 ----a-w- c:\programdata\avg9\update\backup\avgui.exe
2010-09-23 12:56 . 2010-09-23 12:56 3586912 ----a-w- c:\programdata\avg9\update\backup\setup.exe
2010-09-23 12:56 . 2010-09-23 12:56 1619296 ----a-w- c:\programdata\avg9\update\backup\avgssie.dll
2010-09-23 12:56 . 2010-09-23 12:56 1377632 ----a-w- c:\programdata\avg9\update\backup\avgssff.dll
2010-09-23 12:56 . 2010-09-23 12:56 942432 ----a-w- c:\programdata\avg9\update\backup\avgcfgx.dll
2010-09-23 12:56 . 2010-09-23 12:56 598368 ----a-w- c:\programdata\avg9\update\backup\avgsrmx.dll
2010-09-23 12:56 . 2010-09-23 12:56 4371296 ----a-w- c:\programdata\avg9\update\backup\avgcorex.dll
2010-09-23 12:56 . 2010-09-23 12:56 300896 ----a-w- c:\programdata\avg9\update\backup\avgchclx.dll
2010-09-23 12:54 . 2010-09-23 12:54 1690952 ----a-w- c:\programdata\avg9\update\backup\avgupd.dll
2010-09-19 15:44 . 2010-09-19 15:44 -------- d-----w- c:\users\JohnAdmin\AppData\Roaming\HPAppData
2010-09-19 15:42 . 2010-09-19 15:42 -------- d-----w- c:\users\JohnAdmin\AppData\Local\AVG Security Toolbar
2010-09-16 10:11 . 2010-09-16 10:11 -------- d-----w- C:\9935303ec0ed577f6fac
2010-09-15 18:14 . 2010-04-05 16:08 317952 ----a-w- c:\windows\system32\MP4SDECD.DLL
2010-09-15 18:14 . 2010-08-17 13:32 126464 ----a-w- c:\windows\system32\spoolsv.exe
2010-09-15 18:14 . 2010-04-16 16:10 501760 ----a-w- c:\windows\system32\usp10.dll
2010-09-15 18:14 . 2010-05-27 19:16 738816 ----a-w- c:\windows\system32\inetcomm.dll
2010-09-09 06:50 . 2010-06-01 00:32 9344 ----a-w- c:\windows\system32\drivers\mfeclnk.sys
2010-09-09 06:49 . 2010-06-01 00:32 83496 ----a-w- c:\windows\system32\drivers\mferkdet.sys
2010-09-09 06:49 . 2010-06-01 00:32 64304 ----a-w- c:\windows\system32\drivers\mfenlfk.sys
2010-09-09 06:49 . 2010-06-01 00:32 160720 ----a-w- c:\windows\system32\drivers\mfewfpk.sys
2010-09-09 06:49 . 2010-06-01 00:32 95568 ----a-w- c:\windows\system32\drivers\mfeapfk.sys
2010-09-09 06:49 . 2010-06-01 00:32 55456 ----a-w- c:\windows\system32\drivers\cfwids.sys
2010-09-09 06:49 . 2010-06-01 00:32 312616 ----a-w- c:\windows\system32\drivers\mfefirek.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-02 17:07 . 2010-01-01 17:05 0 ----a-w- c:\users\John & Sophie\AppData\Local\prvlcl.dat
2010-09-20 07:01 . 2007-11-25 21:58 -------- d-----w- c:\programdata\Microsoft Help
2010-09-19 15:40 . 2007-11-02 00:05 86576 ----a-w- c:\users\JohnAdmin\AppData\Local\GDIPFONTCACHEV1.DAT
2010-09-16 10:11 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-09-09 22:19 . 2007-10-29 15:13 -------- d-----w- c:\program files\McAfee.com
2010-09-09 17:56 . 2007-10-29 15:13 -------- d-----w- c:\program files\McAfee
2010-09-09 17:55 . 2007-10-29 15:13 -------- d-----w- c:\program files\Common Files\McAfee
2010-09-09 06:50 . 2006-11-02 10:25 86016 ----a-w- c:\windows\Inf\infstor.dat
2010-09-09 06:50 . 2006-11-02 10:25 51200 ----a-w- c:\windows\Inf\infpub.dat
2010-09-09 06:50 . 2006-11-02 10:25 143360 ----a-w- c:\windows\Inf\infstrng.dat
2010-08-14 14:56 . 2010-08-14 14:56 -------- d-----w- c:\program files\Coupons
2010-07-15 13:42 . 2009-10-24 19:24 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-07-15 13:42 . 2010-07-15 13:42 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-07-15 13:42 . 2009-10-24 19:24 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-06-28 23:54 . 2008-08-14 06:54 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2010-06-01 00:32 . 2010-09-09 06:50 24376 ----a-w- c:\program files\mozilla firefox\components\Scriptff.dll
2007-10-29 22:47 . 2007-10-29 22:41 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-04-19 14:25 2117704 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMBgMonitor.exe" [2007-10-23 202024]
"AIM"="c:\program files\AIM\aim.exe" [2006-08-01 67112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-05-25 17920]
"RtHDVCpl"="RtHDVCpl.exe" [2007-05-11 4452352]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"dscactivate"="c:\dell\dsca.exe" [2007-07-30 16384]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-06-28 30192]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 1836328]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-07-15 2065760]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-05-28 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-05-28 8429568]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-05-28 81920]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2010-03-12 49208]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-07-01 1193848]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-10-29 50688]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-10-16 214360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-06-28 30192]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2010-04-29 38224]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-06-01 83496]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-07-15 216400]
S1 AvgTdiX;AVG Free Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2010-07-15 243024]
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2010-06-01 64304]
S1 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2010-06-01 160720]
S2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [2010-07-21 921952]
S2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2010-07-15 308136]
S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2010-03-10 271480]
S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 271480]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2010-06-01 188136]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [2010-06-01 141792]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-06-01 55456]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-06-01 312616]
S3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2008-01-19 16896]
--- Other Services/Drivers In Memory ---
*Deregistered* - mfeavfk01
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=0071029IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
DPF: vzTCPConfig -
hxxps://www.verizon.net/WhatsNext/CheckMyPc/vzTCPConfig.CABFF - ProfilePath - c:\users\JohnAdmin\AppData\Roaming\Mozilla\Firefox\Profiles\jmxe9w03.default\
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpClipBook.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpClipBookDB.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpNeoLogger.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSaturn.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSmartSelect.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSmartWebPrinting.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpSWPOperation.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPLogging.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTC.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXPMTL.dll
FF - component: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\components\hpXREStub.dll
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - component: c:\program files\Mozilla Firefox\components\Scriptff.dll
FF - plugin: c:\program files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3\plugins\nphpclipbook.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-10-02 13:18
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-10-02 13:20:45
ComboFix-quarantined-files.txt 2010-10-02 17:20
ComboFix2.txt 2010-09-26 13:03
Pre-Run: 372,667,039,744 bytes free
Post-Run: 372,706,099,200 bytes free
- - End Of File - - EB56ABB9D1CFCFA8C2B87F46C1C9262E