Hey - I just saw that you replied. Before seeing that suggestion though, I went a head and ran combofix and here is that result:
ComboFix 09-12-26.05 - Andy 12/27/2009 7:35.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2038.1363 [GMT -7:00]
Running from: c:\documents and settings\Andy\Desktop\commy.exe.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: Online Armor Firewall *disabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}
.
((((((((((((((((((((((((( Files Created from 2009-11-27 to 2009-12-27 )))))))))))))))))))))))))))))))
.
2009-12-27 05:22 . 2009-12-27 05:24 -------- d-----w- C:\commy.exe
2009-12-22 17:39 . 2009-12-16 01:58 3776280 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
2009-12-22 17:39 . 2009-12-16 01:58 4043032 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2009-12-22 17:39 . 2009-12-16 01:58 3967256 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2009-12-22 17:39 . 2009-12-16 01:58 916248 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcfgx.dll
2009-12-21 23:03 . 2009-12-21 23:03 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-12-21 22:59 . 2009-12-21 22:59 -------- d-sh--w- c:\documents and settings\Andy\IETldCache
2009-12-21 22:52 . 2009-12-22 01:09 -------- d-----w- c:\windows\ie8updates
2009-12-21 22:49 . 2009-12-21 22:50 -------- dc-h--w- c:\windows\ie8
2009-12-21 22:47 . 2009-10-29 07:45 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-12-21 22:47 . 2009-10-29 07:45 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-12-21 22:44 . 2009-10-02 04:44 92160 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-12-18 15:34 . 2009-12-18 15:34 294656 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avglngx.dll
2009-12-18 15:34 . 2009-12-16 01:58 2352920 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgresf.dll
2009-12-16 23:25 . 2009-12-16 23:25 -------- d-----w- c:\program files\uTorrent
2009-12-16 23:24 . 2009-12-27 14:39 -------- d-----w- c:\documents and settings\Andy\Application Data\uTorrent
2009-12-16 04:56 . 2009-12-27 05:09 -------- d-----w- c:\documents and settings\All Users\Application Data\OnlineArmor
2009-12-16 04:56 . 2009-12-16 04:56 -------- d-----w- c:\documents and settings\Andy\Application Data\OnlineArmor
2009-12-16 04:55 . 2009-12-05 14:28 24656 ----a-w- c:\windows\system32\drivers\OAmon.sys
2009-12-16 04:55 . 2009-12-05 14:27 29776 ----a-w- c:\windows\system32\drivers\OAnet.sys
2009-12-16 04:55 . 2009-12-05 14:27 223312 ----a-w- c:\windows\system32\drivers\OADriver.sys
2009-12-16 04:55 . 2009-12-16 04:55 -------- d-----w- c:\program files\Tall Emu
2009-12-16 01:59 . 2009-12-16 01:59 -------- d-----w- c:\documents and settings\Andy\Local Settings\Application Data\AVG Security Toolbar
2009-12-16 01:59 . 2009-12-25 01:55 -------- d-----w- C:\$AVG
2009-12-16 01:59 . 2009-12-16 01:59 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-12-16 01:59 . 2009-12-16 01:59 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-12-16 01:59 . 2009-12-16 01:59 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-12-16 01:59 . 2009-12-16 01:59 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-12-16 01:59 . 2009-12-27 05:56 -------- d-----w- c:\windows\system32\drivers\Avg
2009-12-16 01:58 . 2009-12-16 01:58 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-12-16 01:58 . 2009-12-16 01:58 -------- d-----w- c:\program files\AVG
2009-12-16 01:58 . 2009-12-16 01:58 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2009-12-16 01:58 . 2009-12-16 05:09 -------- d-----w- c:\windows\SxsCaPendDel
2009-12-16 00:33 . 2009-12-16 00:33 -------- d-----w- c:\program files\Java
2009-12-16 00:33 . 2009-12-16 00:33 152576 ----a-w- c:\documents and settings\Andy\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-12-16 00:28 . 2009-12-16 00:28 79488 ----a-w- c:\documents and settings\Andy\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-12-12 14:20 . 2009-12-12 14:20 -------- d-----w- c:\documents and settings\Andy\Application Data\Malwarebytes
2009-12-12 14:20 . 2009-12-03 23:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-12 14:20 . 2009-12-12 14:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-12 14:20 . 2009-12-12 14:20 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-12 14:20 . 2009-12-03 23:13 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-12 03:32 . 2009-10-29 07:45 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2009-12-12 03:32 . 2009-10-29 07:45 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-12-12 03:32 . 2009-10-29 07:45 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll
2009-12-12 03:32 . 2009-10-29 07:45 11069952 -c----w- c:\windows\system32\dllcache\ieframe.dll
2009-12-12 03:32 . 2009-10-28 14:36 13824 -c----w- c:\windows\system32\dllcache\ieudinit.exe
2009-12-12 03:32 . 2009-03-08 11:11 445952 -c--a-w- c:\windows\system32\dllcache\ieapfltr.dll
2009-12-12 03:32 . 2009-03-08 11:31 59904 -c--a-w- c:\windows\system32\dllcache\icardie.dll
2009-12-12 03:32 . 2009-02-07 04:07 3698584 -c--a-w- c:\windows\system32\dllcache\ieapfltr.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-16 23:20 . 2009-11-12 15:58 1 ----a-w- c:\documents and settings\Andy\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-12-16 00:33 . 2009-10-11 23:12 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-11-18 17:46 . 2009-11-18 17:46 -------- d-----w- c:\documents and settings\Andy\Application Data\HorizonWimba
2009-11-12 10:16 . 2009-09-23 18:44 16504 ----a-w- c:\documents and settings\Andy\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-12 05:27 . 2009-11-12 05:27 -------- d-----w- c:\documents and settings\Andy\Application Data\OpenOffice.org
2009-11-12 05:18 . 2009-11-12 05:18 -------- d-----w- c:\program files\JRE
2009-11-12 05:18 . 2009-11-12 05:18 -------- d-----w- c:\program files\OpenOffice.org 3
2009-11-03 03:42 . 2009-09-23 19:00 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-10-29 07:45 . 2008-04-14 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2008-04-14 12:00 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2008-04-14 12:00 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2008-04-14 12:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2008-04-14 12:00 270336 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2008-04-14 12:00 149504 ----a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2008-04-14 12:00 79872 ----a-w- c:\windows\system32\raschap.dll
.
(((((((((((((((((((((((((((((
SnapShot@2009-12-13_14.00.22 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-12 03:54 . 2009-07-12 03:54 65536 c:\windows\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e79c4723\vcomp.dll
+ 2009-07-12 03:32 . 2009-07-12 03:32 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80KOR.dll
+ 2009-07-12 03:32 . 2009-07-12 03:32 49152 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80JPN.dll
+ 2009-07-12 03:32 . 2009-07-12 03:32 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ITA.dll
+ 2009-07-12 03:32 . 2009-07-12 03:32 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80FRA.dll
+ 2009-07-12 03:32 . 2009-07-12 03:32 61440 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ESP.dll
+ 2009-07-12 03:32 . 2009-07-12 03:32 57344 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ENU.dll
+ 2009-07-12 03:32 . 2009-07-12 03:32 65536 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80DEU.dll
+ 2009-07-12 03:32 . 2009-07-12 03:32 45056 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80CHT.dll
+ 2009-07-12 03:32 . 2009-07-12 03:32 40960 c:\windows\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80CHS.dll
+ 2009-07-12 08:07 . 2009-07-12 08:07 57856 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfcm80u.dll
+ 2009-07-12 08:19 . 2009-07-12 08:19 69632 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfcm80.dll
+ 2009-12-27 14:19 . 2009-12-27 14:19 16384 c:\windows\Temp\Perflib_Perfdata_190.dat
+ 2009-09-23 19:02 . 2009-01-08 01:21 26144 c:\windows\system32\spupdsvc.exe
+ 2009-10-13 23:11 . 2009-01-08 01:20 16928 c:\windows\system32\spmsg.dll
+ 2008-04-14 12:00 . 2009-03-08 11:31 46592 c:\windows\system32\pngfilt.dll
+ 2008-04-14 12:00 . 2009-12-27 14:23 38162 c:\windows\system32\perfc009.dat
- 2006-06-29 15:05 . 2006-06-29 15:05 23552 c:\windows\system32\normaliz.dll
+ 2006-06-29 15:05 . 2009-01-08 01:20 23552 c:\windows\system32\normaliz.dll
- 2006-06-29 00:59 . 2006-06-29 00:59 24576 c:\windows\system32\nlsdl.dll
+ 2006-06-29 00:59 . 2009-01-08 01:20 24576 c:\windows\system32\nlsdl.dll
+ 2008-04-14 12:00 . 2009-03-08 11:31 48128 c:\windows\system32\mshtmler.dll
- 2008-04-14 12:00 . 2007-08-14 01:01 48128 c:\windows\system32\mshtmler.dll
+ 2008-04-14 12:00 . 2009-03-08 11:31 66560 c:\windows\system32\mshtmled.dll
+ 2008-04-14 12:00 . 2009-03-08 11:31 45568 c:\windows\system32\mshta.exe
- 2008-04-14 12:00 . 2007-08-14 01:32 45568 c:\windows\system32\mshta.exe
+ 2007-08-14 01:36 . 2009-03-08 11:31 13312 c:\windows\system32\msfeedssync.exe
+ 2007-08-14 01:54 . 2009-10-29 07:45 55296 c:\windows\system32\msfeedsbs.dll
+ 2008-04-14 12:00 . 2009-03-08 11:34 43008 c:\windows\system32\licmgr10.dll
+ 2008-04-14 12:00 . 2009-10-29 07:45 25600 c:\windows\system32\jsproxy.dll
+ 2008-04-14 12:00 . 2009-03-08 11:32 94720 c:\windows\system32\inseng.dll
+ 2008-04-14 12:00 . 2009-03-08 11:31 34816 c:\windows\system32\imgutil.dll
+ 2007-08-14 01:39 . 2009-03-08 11:32 36864 c:\windows\system32\ieudinit.exe
+ 2008-04-14 12:00 . 2009-03-08 11:32 71680 c:\windows\system32\iesetup.dll
+ 2008-04-14 12:00 . 2009-03-08 11:32 55808 c:\windows\system32\iernonce.dll
+ 2006-06-29 15:05 . 2009-01-08 01:20 26112 c:\windows\system32\idndl.dll
- 2006-06-29 15:05 . 2006-06-29 15:05 26112 c:\windows\system32\idndl.dll
+ 2007-08-14 01:36 . 2009-03-08 11:31 59904 c:\windows\system32\icardie.dll
+ 2008-04-14 12:00 . 2009-03-08 11:31 46592 c:\windows\system32\dllcache\pngfilt.dll
+ 2008-04-14 12:00 . 2009-03-08 11:31 48128 c:\windows\system32\dllcache\mshtmler.dll
- 2008-04-14 12:00 . 2007-08-14 01:01 48128 c:\windows\system32\dllcache\mshtmler.dll
+ 2008-04-14 12:00 . 2009-03-08 11:31 66560 c:\windows\system32\dllcache\mshtmled.dll
- 2008-04-14 12:00 . 2007-08-14 01:32 45568 c:\windows\system32\dllcache\mshta.exe
+ 2008-04-14 12:00 . 2009-03-08 11:31 45568 c:\windows\system32\dllcache\mshta.exe
+ 2008-04-14 12:00 . 2009-03-08 11:34 43008 c:\windows\system32\dllcache\licmgr10.dll
+ 2008-04-14 12:00 . 2009-10-29 07:45 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2008-04-14 12:00 . 2009-03-08 11:32 94720 c:\windows\system32\dllcache\inseng.dll
+ 2008-04-14 12:00 . 2009-03-08 11:31 34816 c:\windows\system32\dllcache\imgutil.dll
+ 2008-04-14 12:00 . 2009-03-08 11:32 71680 c:\windows\system32\dllcache\iesetup.dll
+ 2008-04-14 12:00 . 2009-03-08 11:32 55808 c:\windows\system32\dllcache\iernonce.dll
+ 2009-09-23 18:29 . 2009-03-08 11:24 68608 c:\windows\system32\dllcache\hmmapi.dll
+ 2008-04-14 12:00 . 2009-03-08 11:33 18944 c:\windows\system32\dllcache\corpol.dll
+ 2008-04-14 12:00 . 2009-03-08 11:32 72704 c:\windows\system32\dllcache\admparse.dll
+ 2008-04-14 12:00 . 2009-03-08 11:33 18944 c:\windows\system32\corpol.dll
+ 2008-04-14 12:00 . 2009-03-08 11:32 72704 c:\windows\system32\admparse.dll
+ 2009-12-21 22:52 . 2009-03-08 11:33 12288 c:\windows\ie8updates\KB976325-IE8\xpshims.dll
+ 2009-12-21 22:52 . 2009-03-08 11:31 55296 c:\windows\ie8updates\KB976325-IE8\msfeedsbs.dll
+ 2009-12-21 22:52 . 2009-03-08 11:33 25600 c:\windows\ie8updates\KB976325-IE8\jsproxy.dll
+ 2009-12-21 22:50 . 2009-03-08 21:23 58464 c:\windows\ie8\spuninst\iecustom.dll
+ 2009-12-21 22:49 . 2009-10-29 07:46 44544 c:\windows\ie8\pngfilt.dll
+ 2009-12-21 22:49 . 2007-08-14 01:01 48128 c:\windows\ie8\mshtmler.dll
+ 2009-12-21 22:49 . 2007-08-14 01:32 45568 c:\windows\ie8\mshta.exe
+ 2009-12-21 22:49 . 2007-08-14 01:36 12288 c:\windows\ie8\msfeedssync.exe
+ 2009-12-21 22:49 . 2009-10-29 07:46 52224 c:\windows\ie8\msfeedsbs.dll
+ 2009-12-21 22:49 . 2007-08-14 01:44 40960 c:\windows\ie8\licmgr10.dll
+ 2009-12-21 22:49 . 2009-10-29 07:46 27648 c:\windows\ie8\jsproxy.dll
+ 2009-12-21 22:49 . 2007-08-14 01:39 92672 c:\windows\ie8\inseng.dll
+ 2009-12-21 22:49 . 2007-08-14 01:36 36352 c:\windows\ie8\imgutil.dll
+ 2009-12-21 22:49 . 2007-08-14 01:39 55296 c:\windows\ie8\iesetup.dll
+ 2009-12-21 22:49 . 2009-10-29 07:46 44544 c:\windows\ie8\iernonce.dll
+ 2009-12-21 22:49 . 2009-10-29 07:46 78336 c:\windows\ie8\ieencode.dll
+ 2009-12-21 22:49 . 2009-10-28 14:36 70656 c:\windows\ie8\ie4uinit.exe
+ 2009-12-21 22:49 . 2009-10-29 07:46 63488 c:\windows\ie8\icardie.dll
+ 2009-12-21 22:49 . 2007-08-14 01:18 60416 c:\windows\ie8\hmmapi.dll
+ 2009-12-21 22:49 . 2009-10-29 07:46 17408 c:\windows\ie8\corpol.dll
+ 2009-12-21 22:49 . 2007-08-14 01:39 71680 c:\windows\ie8\admparse.dll
+ 2009-12-21 22:52 . 2009-03-08 11:35 2048 c:\windows\ie8updates\KB975364-IE8\iecompat.dll
+ 2009-07-12 08:12 . 2009-07-12 08:12 632656 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll
+ 2009-07-12 08:09 . 2009-07-12 08:09 554832 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcp80.dll
+ 2009-07-12 08:08 . 2009-07-12 08:08 479232 c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcm80.dll
- 2008-04-14 12:00 . 2008-04-14 12:00 121856 c:\windows\system32\xmllite.dll
+ 2008-04-14 12:00 . 2009-01-08 01:21 121856 c:\windows\system32\xmllite.dll
+ 2007-08-14 01:45 . 2009-03-08 11:34 208384 c:\windows\system32\WinFXDocObj.exe
+ 2008-04-14 12:00 . 2009-03-08 11:34 236544 c:\windows\system32\webcheck.dll
+ 2008-04-14 12:00 . 2009-03-08 11:33 420352 c:\windows\system32\vbscript.dll
- 2008-04-14 12:00 . 2009-10-29 07:46 105984 c:\windows\system32\url.dll
+ 2008-04-14 12:00 . 2009-03-08 11:34 105984 c:\windows\system32\url.dll
+ 2008-04-14 12:00 . 2009-12-27 14:23 305886 c:\windows\system32\perfh009.dat
+ 2008-04-14 12:00 . 2009-10-29 07:45 206848 c:\windows\system32\occache.dll
+ 2008-04-14 12:00 . 2009-03-08 11:32 611840 c:\windows\system32\mstime.dll
+ 2008-04-14 12:00 . 2009-03-08 11:34 193536 c:\windows\system32\msrating.dll
+ 2008-04-14 12:00 . 2009-03-08 11:22 156160 c:\windows\system32\msls31.dll
- 2008-04-14 12:00 . 2007-08-14 01:54 156160 c:\windows\system32\msls31.dll
+ 2007-08-14 01:54 . 2009-10-29 07:45 594432 c:\windows\system32\msfeeds.dll
+ 2009-01-08 01:20 . 2009-01-08 01:20 265720 c:\windows\system32\msdbg2.dll
+ 2008-04-14 12:00 . 2009-06-22 06:44 726528 c:\windows\system32\jscript.dll
+ 2009-12-16 00:33 . 2009-12-16 00:33 149280 c:\windows\system32\javaws.exe
- 2009-10-11 23:12 . 2009-10-11 23:12 149280 c:\windows\system32\javaws.exe
+ 2009-12-16 00:33 . 2009-12-16 00:33 145184 c:\windows\system32\javaw.exe
- 2009-10-11 23:12 . 2009-10-11 23:12 145184 c:\windows\system32\javaw.exe
- 2009-10-11 23:12 . 2009-10-11 23:12 145184 c:\windows\system32\java.exe
+ 2009-12-16 00:33 . 2009-12-16 00:33 145184 c:\windows\system32\java.exe
+ 2007-08-14 01:54 . 2009-03-08 11:22 164352 c:\windows\system32\ieui.dll
+ 2008-04-14 12:00 . 2009-10-29 07:45 184320 c:\windows\system32\iepeers.dll
+ 2008-04-14 12:00 . 2009-10-29 07:45 387584 c:\windows\system32\iedkcs32.dll
+ 2007-07-11 19:27 . 2009-03-08 11:11 445952 c:\windows\system32\ieapfltr.dll
+ 2008-04-14 12:00 . 2009-03-08 11:32 163840 c:\windows\system32\ieakui.dll
+ 2008-04-14 12:00 . 2009-03-08 11:33 229376 c:\windows\system32\ieaksie.dll
+ 2008-04-14 12:00 . 2009-03-08 11:33 125952 c:\windows\system32\ieakeng.dll
+ 2008-04-14 12:00 . 2009-10-28 14:40 173056 c:\windows\system32\ie4uinit.exe
+ 2008-04-14 12:00 . 2009-03-08 11:31 216064 c:\windows\system32\dxtrans.dll
+ 2008-04-14 12:00 . 2009-03-08 11:31 348160 c:\windows\system32\dxtmsft.dll
+ 2008-04-14 12:00 . 2009-10-29 07:45 916480 c:\windows\system32\dllcache\wininet.dll
+ 2008-04-14 12:00 . 2009-03-08 11:34 236544 c:\windows\system32\dllcache\webcheck.dll
+ 2009-09-23 18:30 . 2009-03-08 11:33 759296 c:\windows\system32\dllcache\VGX.dll
+ 2008-04-14 12:00 . 2009-03-08 11:33 420352 c:\windows\system32\dllcache\vbscript.dll
- 2008-04-14 12:00 . 2009-10-29 07:46 105984 c:\windows\system32\dllcache\url.dll
+ 2008-04-14 12:00 . 2009-03-08 11:34 105984 c:\windows\system32\dllcache\url.dll
+ 2009-01-08 01:20 . 2009-01-08 01:20 134144 c:\windows\system32\dllcache\sqmapi.dll
+ 2008-04-14 12:00 . 2009-10-29 07:45 206848 c:\windows\system32\dllcache\occache.dll
+ 2008-04-14 12:00 . 2009-03-08 11:32 611840 c:\windows\system32\dllcache\mstime.dll
+ 2008-04-14 12:00 . 2009-03-08 11:34 193536 c:\windows\system32\dllcache\msrating.dll
- 2008-04-14 12:00 . 2007-08-14 01:54 156160 c:\windows\system32\dllcache\msls31.dll
+ 2008-04-14 12:00 . 2009-03-08 11:22 156160 c:\windows\system32\dllcache\msls31.dll
+ 2008-04-14 12:00 . 2009-06-22 06:44 726528 c:\windows\system32\dllcache\jscript.dll
+ 2009-09-23 18:29 . 2009-03-08 21:09 638816 c:\windows\system32\dllcache\iexplore.exe
+ 2008-04-14 12:00 . 2009-10-29 07:45 184320 c:\windows\system32\dllcache\iepeers.dll
+ 2008-04-14 12:00 . 2009-10-29 07:45 387584 c:\windows\system32\dllcache\iedkcs32.dll
+ 2008-04-14 12:00 . 2009-03-08 11:32 163840 c:\windows\system32\dllcache\ieakui.dll
+ 2008-04-14 12:00 . 2009-03-08 11:33 229376 c:\windows\system32\dllcache\ieaksie.dll
+ 2008-04-14 12:00 . 2009-03-08 11:33 125952 c:\windows\system32\dllcache\ieakeng.dll
+ 2008-04-14 12:00 . 2009-10-28 14:40 173056 c:\windows\system32\dllcache\ie4uinit.exe
+ 2008-04-14 12:00 . 2009-03-08 11:31 216064 c:\windows\system32\dllcache\dxtrans.dll
+ 2008-04-14 12:00 . 2009-03-08 11:31 348160 c:\windows\system32\dllcache\dxtmsft.dll
+ 2008-04-14 12:00 . 2009-03-08 11:32 128512 c:\windows\system32\dllcache\advpack.dll
+ 2008-04-14 12:00 . 2009-03-08 11:32 128512 c:\windows\system32\advpack.dll
+ 2009-12-16 01:58 . 2009-12-16 01:58 424448 c:\windows\Installer\1cc0375.msi
+ 2009-12-16 00:33 . 2009-12-16 00:33 537600 c:\windows\Installer\1780a76.msi
+ 2009-12-21 22:52 . 2009-03-08 11:34 914944 c:\windows\ie8updates\KB976325-IE8\wininet.dll
+ 2009-12-21 22:52 . 2009-05-26 11:40 382840 c:\windows\ie8updates\KB976325-IE8\spuninst\updspapi.dll
+ 2009-12-21 22:52 . 2009-05-26 11:40 231288 c:\windows\ie8updates\KB976325-IE8\spuninst\spuninst.exe
+ 2009-12-21 22:52 . 2009-03-08 11:34 109568 c:\windows\ie8updates\KB976325-IE8\occache.dll
+ 2009-12-21 22:52 . 2009-03-08 11:32 594432 c:\windows\ie8updates\KB976325-IE8\msfeeds.dll
+ 2009-12-21 22:52 . 2009-03-08 11:33 246784 c:\windows\ie8updates\KB976325-IE8\ieproxy.dll
+ 2009-12-21 22:52 . 2009-03-08 11:31 183808 c:\windows\ie8updates\KB976325-IE8\iepeers.dll
+ 2009-12-21 22:52 . 2009-03-08 21:09 391536 c:\windows\ie8updates\KB976325-IE8\iedkcs32.dll
+ 2009-12-21 22:52 . 2009-03-08 11:32 173056 c:\windows\ie8updates\KB976325-IE8\ie4uinit.exe
+ 2009-12-21 22:52 . 2009-05-26 11:40 382840 c:\windows\ie8updates\KB975364-IE8\spuninst\updspapi.dll
+ 2009-12-21 22:52 . 2009-05-26 11:40 231288 c:\windows\ie8updates\KB975364-IE8\spuninst\spuninst.exe
+ 2009-12-22 01:09 . 2008-07-08 13:02 382840 c:\windows\ie8updates\KB971961-IE8\spuninst\updspapi.dll
+ 2009-12-22 01:09 . 2008-07-08 13:02 231288 c:\windows\ie8updates\KB971961-IE8\spuninst\spuninst.exe
+ 2009-12-22 01:09 . 2009-03-08 11:33 726528 c:\windows\ie8updates\KB971961-IE8\jscript.dll
+ 2009-12-21 22:49 . 2009-10-29 07:46 832512 c:\windows\ie8\wininet.dll
+ 2009-12-21 22:49 . 2007-08-14 01:45 206336 c:\windows\ie8\winfxdocobj.exe
+ 2009-12-21 22:49 . 2009-10-29 07:46 233472 c:\windows\ie8\webcheck.dll
+ 2009-12-21 22:49 . 2008-05-27 17:23 765952 c:\windows\ie8\vgx.dll
+ 2009-12-21 22:49 . 2008-05-09 10:53 430080 c:\windows\ie8\vbscript.dll
+ 2009-12-21 22:49 . 2009-10-29 07:46 105984 c:\windows\ie8\url.dll
+ 2009-12-21 22:50 . 2009-01-08 01:21 382496 c:\windows\ie8\spuninst\updspapi.dll
+ 2009-12-21 22:50 . 2009-01-08 01:20 231456 c:\windows\ie8\spuninst\spuninst.exe
+ 2009-12-21 22:49 . 2006-09-07 00:43 213216 c:\windows\ie8\spuninst.exe
+ 2009-12-21 22:49 . 2009-10-29 07:46 102912 c:\windows\ie8\occache.dll
+ 2009-12-21 22:49 . 2009-10-29 07:46 671232 c:\windows\ie8\mstime.dll
+ 2009-12-21 22:49 . 2009-10-29 07:46 193024 c:\windows\ie8\msrating.dll
+ 2009-12-21 22:49 . 2007-08-14 01:54 156160 c:\windows\ie8\msls31.dll
+ 2009-12-21 22:49 . 2009-10-29 07:46 477696 c:\windows\ie8\mshtmled.dll
+ 2009-12-21 22:49 . 2009-10-29 07:46 459264 c:\windows\ie8\msfeeds.dll
+ 2009-12-21 22:49 . 2009-08-13 15:16 512000 c:\windows\ie8\jscript.dll
+ 2009-12-21 22:49 . 2009-10-28 06:54 634632 c:\windows\ie8\iexplore.exe
+ 2009-12-21 22:49 . 2007-08-14 01:54 180736 c:\windows\ie8\ieui.dll
+ 2009-12-21 22:49 . 2009-10-29 07:46 268288 c:\windows\ie8\iertutil.dll
+ 2009-12-21 22:49 . 2007-08-14 01:54 287744 c:\windows\ie8\ieproxy.dll
+ 2009-12-21 22:49 . 2007-08-14 01:54 191488 c:\windows\ie8\iepeers.dll
+ 2009-12-21 22:49 . 2009-10-29 07:46 385024 c:\windows\ie8\iedkcs32.dll
+ 2009-12-21 22:49 . 2009-10-29 07:46 380928 c:\windows\ie8\ieapfltr.dll
+ 2009-12-21 22:49 . 2009-10-28 06:52 161792 c:\windows\ie8\ieakui.dll
+ 2009-12-21 22:49 . 2009-10-29 07:46 230400 c:\windows\ie8\ieaksie.dll
+ 2009-12-21 22:49 . 2009-10-29 07:46 153088 c:\windows\ie8\ieakeng.dll
+ 2009-12-21 22:49 . 2009-10-29 07:46 214528 c:\windows\ie8\dxtrans.dll
+ 2009-12-21 22:49 . 2009-10-29 07:46 347136 c:\windows\ie8\dxtmsft.dll
+ 2009-12-21 22:49 . 2009-10-29 07:46 124928 c:\windows\ie8\advpack.dll
+ 2009-07-12 03:46 . 2009-07-12 03:46 1093120 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80u.dll
+ 2009-07-12 03:46 . 2009-07-12 03:46 1105920 c:\windows\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80.dll
+ 2008-04-14 12:00 . 2009-10-29 07:45 1208832 c:\windows\system32\urlmon.dll
+ 2008-04-14 12:00 . 2009-10-29 07:45 5940736 c:\windows\system32\mshtml.dll
+ 2007-08-14 01:34 . 2009-10-29 07:45 1985536 c:\windows\system32\iertutil.dll
+ 2007-02-12 23:10 . 2009-02-07 04:07 3698584 c:\windows\system32\ieapfltr.dat
+ 2008-04-14 12:00 . 2009-10-29 07:45 1208832 c:\windows\system32\dllcache\urlmon.dll
+ 2008-04-14 12:00 . 2009-10-29 07:45 5940736 c:\windows\system32\dllcache\mshtml.dll
+ 2009-12-21 22:52 . 2009-03-08 11:34 1206784 c:\windows\ie8updates\KB976325-IE8\urlmon.dll
+ 2009-12-21 22:52 . 2009-03-08 11:41 5937152 c:\windows\ie8updates\KB976325-IE8\mshtml.dll
+ 2009-12-21 22:52 . 2009-03-08 11:32 1985024 c:\windows\ie8updates\KB976325-IE8\iertutil.dll
+ 2009-12-21 22:49 . 2009-10-29 07:46 1168384 c:\windows\ie8\urlmon.dll
+ 2009-12-21 22:49 . 2009-10-29 20:16 3598336 c:\windows\ie8\mshtml.dll
+ 2009-12-21 22:49 . 2009-10-29 07:46 6067200 c:\windows\ie8\ieframe.dll
+ 2009-12-21 22:49 . 2009-06-29 08:33 2452872 c:\windows\ie8\ieapfltr.dat
+ 2007-08-14 01:54 . 2009-10-29 07:45 11069952 c:\windows\system32\ieframe.dll
+ 2009-12-21 22:52 . 2009-03-08 11:39 11063808 c:\windows\ie8updates\KB976325-IE8\ieframe.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-11-25 20:01 1230080 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2009-12-16 289584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-05-16 138008]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-05-16 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-05-16 138008]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-07-20 1228800]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-10-26 1024000]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-10-25 2220032]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-16 149280]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2009-12-16 2033432]
"@OnlineArmor GUI"="c:\program files\Tall Emu\Online Armor\oaui.exe" [2009-12-05 6622920]
c:\documents and settings\Andy\Start Menu\Programs\Startup\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= "c:\progra~1\TALLEM~1\ONLINE~1\oaevent.dll" [2009-12-05 923336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-12-16 01:59 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [12/15/2009 6:59 PM 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [12/15/2009 6:59 PM 360584]
R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [12/15/2009 9:55 PM 223312]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [12/15/2009 9:55 PM 24656]
R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [12/15/2009 9:55 PM 29776]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [12/15/2009 6:58 PM 906520]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [12/15/2009 6:58 PM 285392]
R2 OAcat;Online Armor Helper Service;c:\program files\Tall Emu\Online Armor\oacat.exe [12/15/2009 9:55 PM 1282248]
R2 SvcOnlineArmor;Online Armor;c:\program files\Tall Emu\Online Armor\oasrv.exe [12/15/2009 9:55 PM 3291336]
S0 cerc6;cerc6; [x]
S2 gupdate1ca4c562023c416;Google Update Service (gupdate1ca4c562023c416);c:\program files\Google\Update\GoogleUpdate.exe [10/13/2009 3:40 PM 133104]
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.openofficestart.com/?cfg=1-2-1-krsuDefault_Search_URL =
hxxp://www.google.com/ieuInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) =
hxxp://www.google.com/search?q=%sIE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
FF - ProfilePath - c:\documents and settings\Andy\Application Data\Mozilla\Firefox\Profiles\5jh9bcfd.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
hxxp://www.openofficestart.com/?cfg=1-2-1-krsFF - prefs.js: keyword.URL -
hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avgb&type=yahoo_avg_hs2-tb-web_us&p=FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
- - - - ORPHANS REMOVED - - - -
HKU-Default-Run-DWQueuedReporting - c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-12-27 07:42
Windows 5.1.2600 Service Pack 3 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
scan completed successfully
hȋdden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(544)
c:\windows\System32\BCMLogon.dll
- - - - - - - > 'explorer.exe'(3800)
c:\windows\system32\WININET.dll
c:\program files\Tall Emu\Online Armor\OAwatch.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-12-27 07:45:54
ComboFix-quarantined-files.txt 2009-12-27 14:45
ComboFix2.txt 2009-12-13 14:01
Pre-Run: 230,910,435,328 bytes free
Post-Run: 231,407,357,952 bytes free
- - End Of File - - B1C10F443A71E734484574E6C16B75F9