here is the log from the combo fix:
ComboFix 10-01-13.06 - Momz 01/13/2010 13:49:57.2.1 - x86
Running from: C:\Documents and Settings\Momz\Desktop\ComboFix.exe
AV: Norton AntiVirus *On-access scanning disabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
.
((((((((((((((((((((((((( Files Created from 2009-12-13 to 2010-01-13 )))))))))))))))))))))))))))))))
.
2010-01-12 01:44:41 . 2010-01-12 01:44:42 1956072 ----a-w- C:\Documents and Settings\Momz\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\fpupdateax\fpupdateax.exe2010-01-11 21:12:52 . 2010-01-11 21:12:52 -------- dc----w- C:\Documents and Settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2009-12-20 01:51:39 . 2009-12-16 20:42:00 43008 ----a-w- C:\Documents and Settings\Momz\Application Data\Mozilla\Firefox\Profiles\c74k418h.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2009-12-20 01:51:39 . 2009-12-16 20:42:00 340480 ----a-w- C:\Documents and Settings\Momz\Application Data\Mozilla\Firefox\Profiles\c74k418h.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2009-12-20 01:51:38 . 2009-12-16 20:42:00 872960 ----a-w- C:\Documents and Settings\Momz\Application Data\Mozilla\Firefox\Profiles\c74k418h.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2009-12-20 01:51:38 . 2009-12-16 20:41:00 346624 ----a-w- C:\Documents and Settings\Momz\Application Data\Mozilla\Firefox\Profiles\c74k418h.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2009-12-19 19:36:20 . 2009-12-19 23:28:39 -------- d-----w- C:\WINDOWS\system32\CatRoot_bak
2009-12-19 19:34:46 . 2004-08-04 06:56:44 21504 ----a-w- C:\WINDOWS\system32\drivers\hidserv.dll
2009-12-19 19:27:07 . 2009-12-19 19:27:07 -------- d-----w- C:\WINDOWS\ServicePackFiles
2009-12-19 19:23:47 . 2008-06-13 13:10:50 272128 -c----w- C:\WINDOWS\system32\dllcache\bthport.sys
2009-12-19 19:23:47 . 2008-06-13 13:10:50 272128 ------w- C:\WINDOWS\system32\drivers\bthport.sys
2009-12-17 23:16:51 . 2009-12-17 23:17:45 -------- d-----w- C:\Program Files\2Wire
2009-12-17 22:50:09 . 2001-08-17 19:48:00 12160 -c--a-w- C:\WINDOWS\system32\dllcache\mouhid.sys
2009-12-17 22:50:09 . 2001-08-17 19:48:00 12160 ----a-w- C:\WINDOWS\system32\drivers\mouhid.sys
2009-12-17 22:50:00 . 2004-08-04 06:56:44 21504 -c--a-w- C:\WINDOWS\system32\dllcache\hidserv.dll
2009-12-17 22:50:00 . 2004-08-04 06:56:44 21504 ----a-w- C:\WINDOWS\system32\hidserv.dll
2009-12-17 22:49:54 . 2001-08-17 20:02:20 9600 -c--a-w- C:\WINDOWS\system32\dllcache\hidusb.sys
2009-12-17 22:49:54 . 2001-08-17 20:02:20 9600 ----a-w- C:\WINDOWS\system32\drivers\hidusb.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-13 19:44:09 . 2005-07-26 03:14:40 -------- d-----w- C:\Program Files\Common Files\Symantec Shared
2010-01-12 01:26:55 . 2005-09-09 00:23:08 -------- d-----w- C:\Program Files\Google
2010-01-11 21:13:16 . 2005-08-11 03:35:08 16368 -c--a-w- C:\Documents and Settings\Momz\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-31 01:14:29 . 2007-03-10 19:07:39 -------- d-----w- C:\Program Files\DivX
2009-12-31 01:11:52 . 2007-03-10 19:05:19 -------- d-----w- C:\Program Files\AviSynth 2.5
2009-12-31 01:11:02 . 2005-08-14 02:14:07 -------- d-----w- C:\Program Files\Gabest
2009-12-31 01:09:34 . 2006-04-15 23:06:18 -------- d-----w- C:\Program Files\VideoLAN
2009-12-31 01:08:10 . 2008-03-14 04:01:25 -------- d-----w- C:\Program Files\Broderbund
2009-12-31 01:02:43 . 2007-05-17 02:34:49 -------- d-----w- C:\Documents and Settings\Momz\Application Data\Berlitz
2009-12-31 01:02:31 . 2005-07-26 23:55:39 -------- d--h--w- C:\Program Files\InstallShield Installation Information
2009-12-29 03:43:45 . 2008-10-15 21:32:16 -------- d-----w- C:\Program Files\Symantec
2009-12-19 19:38:43 . 2009-12-19 19:38:43 0 ---ha-w- C:\WINDOWS\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2009-12-19 19:38:30 . 2009-12-19 19:38:30 0 ---ha-w- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-11-21 16:36:13 . 2004-08-04 04:56:42 470528 ----a-w- C:\WINDOWS\AppPatch\aclayers.dll
2009-10-29 05:48:04 . 2004-08-04 04:56:48 662016 ------w- C:\WINDOWS\system32\wininet.dll
2009-10-21 06:00:55 . 2004-08-04 04:56:46 75776 ----a-w- C:\WINDOWS\system32\strmfilt.dll
2009-10-21 06:00:55 . 2004-08-04 04:56:44 25088 ----a-w- C:\WINDOWS\system32\httpapi.dll
2009-10-20 14:58:48 . 2004-08-04 03:00:14 263552 ----a-w- C:\WINDOWS\system32\drivers\http.sys
2009-12-29 23:54:12 . 2007-03-10 19:38:50 119808 ----a-w- C:\Program Files\mozilla firefox\components\GoogleDesktopMozilla.dll
2007-03-10 19:20:31 . 2007-03-10 19:08:14 56 --sh--r- C:\WINDOWS\system32\2ADB922766.sys
2007-03-10 19:20:31 . 2007-03-10 19:08:13 5852 -csha-w- C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 16:24:37 1694208]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-01-12 01:27:17 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 18:47:52 57344]
"S3TRAY2"="S3tray2.exe" [2003-02-25 09:33:14 69632]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-04-15 23:30:38 180269]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-12-29 23:54:12 30192]
"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-11 09:19:34 69632]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 11:24:52 286720]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 09:25:21 144784]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-09-17 07:27:02 52848]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-24 29696]
hp psc 2000 Series.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe [2002-6-11 323646]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
officejet 6100.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe [2002-6-11 147456]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\BitComet\\BitComet.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"12581:TCP"= 12581:TCP:BitComet 12581 TCP
"12581:UDP"= 12581:UDP:BitComet 12581 UDP
R2 SVKP;SVKP;C:\WINDOWS\system32\SVKP.sys [12/25/2006 12:21:17 PM 2368]
.
Contents of the 'Scheduled Tasks' folder
2008-10-18 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 19:57:52 . 2007-08-29 19:57:52]
2010-01-02 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Momz.job
- C:\PROGRA~1\NORTON~1\NORTON~2\Navw32.exe [2005-09-24 01:37:56 . 2007-05-23 18:13:40]
2009-12-28 C:\WINDOWS\Tasks\Norton AntiVirus - Run Norton QuickScan - Momz.job
- C:\PROGRA~1\NORTON~1\NORTON~2\Navw32.exe [2005-09-24 01:37:56 . 2007-05-23 18:13:40]
2008-10-20 C:\WINDOWS\Tasks\Norton SystemWorks One Button Checkup.job
- C:\Program Files\Norton SystemWorks\OBC.exe [2005-10-06 03:02:30 . 2005-10-06 03:02:30]
2009-12-29 C:\WINDOWS\Tasks\Symantec Drmc.job
- C:\Program Files\Common Files\Symantec Shared\SymDrmc.exe [2005-10-04 01:20:10 . 2005-10-04 01:20:10]
2010-01-13 C:\WINDOWS\Tasks\Symantec NetDetect.job
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE [2008-10-15 21:32:40 . 2005-09-09 19:21:51]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.aimtoday.comuSearch Page =
hxxp://www.google.comuSearch Bar =
hxxp://www.google.com/iemStart Page =
hxxp://www.yahoo.com/mSearch Bar =
hxxp://www.google.com/ieuSearchAssistant =
hxxp://www.google.com/ieuSearchURL,(Default) =
hxxp://www.google.com/search?q=%sIE: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: Yahoo! &SMS -
file:///C:\Program Files\Yahoo!\Common/ycsms.htm
FF - ProfilePath - C:\Documents and Settings\Momz\Application Data\Mozilla\Firefox\Profiles\c74k418h.default\
FF - component: C:\Program Files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - plugin: C:\Program Files\Mozilla Firefox\plugins\npmnqmp07010901.dll
FF - plugin: C:\Program Files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: C:\Program Files\Mozilla Firefox\plugins\npunagi2.dll
.