Enclosed are the contents of the combo fix log:
ComboFix 09-12-21.02 - Dan Short 12/21/2009 23:29:24.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1013.758 [GMT -5:00]
Running from: c:\documents and settings\Dan Short\desktop\commy.exe
Command switches used :: /stepdel
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Dan Short\Local Settings\Application Data\nnojbq
c:\documents and settings\Dan Short\Local Settings\Application Data\nnojbq\cheisysguard.exe
c:\windows\system32\drivers\gaopdxsjrtlkaw.sys
c:\windows\system32\drivers\gaopdxviqjoykj.sys
c:\windows\system32\gaopdxvnlrfmtm.dll
C:\Autorun.inf
c:\windows\system32\drivers\gaopdxsjrtlkaw.sys
c:\windows\system32\drivers\gaopdxviqjoykj.sys
c:\windows\system32\gaopdxcounter
c:\windows\system32\gaopdxvnlrfmtm.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_gaopdxserv.sys
-------\Legacy_gaopdxserv.sys
((((((((((((((((((((((((( Files Created from 2009-11-22 to 2009-12-22 )))))))))))))))))))))))))))))))
.
2009-12-22 03:25 . 2009-12-22 03:25 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-12-22 02:14 . 2009-12-22 02:15 -------- d-----w- c:\documents and settings\All Users\AVP 2009
2009-12-22 01:43 . 2009-12-22 01:43 43640 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-19 17:51 . 2009-12-19 17:51 -------- d-----w- c:\documents and settings\Dan Short\Application Data\DataSafeOnline
2009-12-19 17:46 . 2007-06-14 00:21 172032 ----a-w- c:\windows\system32\igfxres.dll
2009-12-19 17:40 . 2004-08-04 10:00 538624 -c--a-w- c:\windows\system32\dllcache\spider.exe
2009-12-19 17:39 . 2004-08-04 10:00 10129408 -c--a-w- c:\windows\system32\dllcache\hwxkor.dll
2009-12-19 17:21 . 2004-08-04 10:00 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
2009-12-19 17:21 . 2004-08-04 10:00 24661 ----a-w- c:\windows\system32\spxcoins.dll
2009-12-19 17:21 . 2004-08-04 10:00 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
2009-12-19 17:21 . 2004-08-04 10:00 13312 ----a-w- c:\windows\system32\irclass.dll
2009-12-19 12:11 . 2009-12-19 12:11 -------- d-----w- c:\windows\dell
2009-12-17 15:59 . 2009-12-17 15:59 79488 ----a-w- c:\documents and settings\Dan Short\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-22 04:36 . 2007-08-23 21:13 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-19 17:51 . 2007-08-29 00:43 43640 ----a-w- c:\documents and settings\Dan Short\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-19 17:36 . 2004-08-10 18:02 23444 ----a-w- c:\windows\system32\emptyregdb.dat
2009-11-20 04:55 . 2009-10-30 03:42 -------- d-----w- c:\program files\NCH Software
2009-11-03 23:26 . 2007-08-23 21:05 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-11-03 23:26 . 2007-08-23 21:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-11-03 23:25 . 2007-08-28 23:07 -------- d-----w- c:\program files\Hewlett-Packard
2009-11-03 23:23 . 2007-08-23 21:06 -------- d-----w- c:\program files\Symantec
2009-11-03 23:16 . 2009-10-30 03:43 -------- d-----w- c:\documents and settings\Dan Short\Application Data\NCH Software
2009-11-03 23:16 . 2009-10-30 03:43 -------- d-----w- c:\documents and settings\All Users\Application Data\NCH Software
2009-11-03 22:52 . 2009-11-03 01:32 -------- d-----w- c:\program files\ToggleEN
2009-11-03 01:32 . 2009-11-03 01:32 -------- d-----w- c:\program files\Conduit
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{038cb5c7-48ea-4af9-94e0-a1646542e62b}"= "c:\program files\ToggleEN\tbTog1.dll" [2009-11-03 2166296]
[HKEY_CLASSES_ROOT\clsid\{038cb5c7-48ea-4af9-94e0-a1646542e62b}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{038cb5c7-48ea-4af9-94e0-a1646542e62b}]
2009-11-03 22:52 2166296 ----a-w- c:\program files\ToggleEN\tbTog1.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{038cb5c7-48ea-4af9-94e0-a1646542e62b}"= "c:\program files\ToggleEN\tbTog1.dll" [2009-11-03 2166296]
[HKEY_CLASSES_ROOT\clsid\{038cb5c7-48ea-4af9-94e0-a1646542e62b}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{038CB5C7-48EA-4AF9-94E0-A1646542E62B}"= "c:\program files\ToggleEN\tbTog1.dll" [2009-11-03 2166296]
[HKEY_CLASSES_ROOT\clsid\{038cb5c7-48ea-4af9-94e0-a1646542e62b}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-17 68856]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Dell Network Assistant.lnk - c:\windows\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe [2007-8-23 7168]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2007-6-21 282624]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
"10426:UDP"= 10426:UDP:SingleClick ICC
"86:TCP"= 86:TCP:BroadCam Video Streaming Server TCP/IP Port
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [11/2/2007 5:29 PM 17920]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [11/2/2007 5:29 PM 7680]
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\drivers\motport.sys [11/2/2007 5:29 PM 22528]
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.geekpolice.net/forum.htmuSearch Page =
hxxp://www.google.comuSearchMigratedDefaultUrl =
hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZRxdm429YYUS&fl=0&ptb=7bCvMJFCJZeZBle5o1Z9Kw&url=http://edits.mywebsearch.com/toolbaredits/barsearch.jhtml&st=sb&searchfor={searchTerms}uSearch Bar =
hxxp://www.google.com/iemDefault_Search_URL =
hxxp://www.google.com/ieuSearchAssistant =
hxxp://www.google.com/ieuSearchURL,(Default) =
hxxp://www.google.com/search?q=%smSearchAssistant =
hxxp://www.google.com/ieIE: &Search -
http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZRxdm429YYUSIE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-A_M_P_NET - c:\program files\AntiMalware_Pro\AntiMalware_Pro.exe
**************************************************************************
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
scan completed successfully
hȋdden files:
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1884)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Dell Network Assistant\hnm_svc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
c:\program files\Dell Network Assistant\ezi_hnm2.exe
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-12-21 23:40:36 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-22 04:40
Pre-Run: 25,846,792,192 bytes free
Post-Run: 33,973,252,096 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - 215104C70AE7A92BD678A3025E4AC329