The only problem I seemed to be having was my Google being redirected. This all started with the AV Security though and I'm worried there is more. After running Combo it appears that my Google is working again but I just tried a few random searches. Here is my Combo Log...Any suggestions appreciated. ( I can also provide an OTL or an HJT)
_______________________________________________________________________
ComboFix 10-06-27.03 - Eric 06/28/2010 3:43.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1567 [GMT -4]
Running from: c:\documents and settings\Eric\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\VisualTool
c:\program files\VisualTool\pcre3.dll
c:\program files\VisualTool\uninstall.exe
c:\windows\Downloaded Program Files\popcaploader.dll
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\system\VCL35.BPL
c:\windows\system32\hljwugsf.bin
Infected copy of c:\windows\system32\drivers\tcpip.sys was found and disinfected
Restored copy from - Kitty had a snack :p
.
((((((((((((((((((((((((( Files Created from 2010-05-28 to 2010-06-28 )))))))))))))))))))))))))))))))
.
2010-06-28 06:44 . 2010-06-28 06:44 552 ----a-w- c:\windows\system32\d3d8caps.dat
2010-06-28 05:55 . 2010-06-28 05:55 -------- d-----w- c:\windows\system32\wbem\Repository
2010-06-28 04:04 . 2010-06-28 05:53 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-06-28 03:27 . 2010-06-28 03:27 -------- d-----w- c:\program files\Trend Micro
2010-06-25 08:49 . 2010-06-25 08:54 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-06-20 09:14 . 2010-06-20 09:14 -------- d-----w- c:\documents and settings\Ciera\Application Data\IObit
2010-06-20 09:04 . 2010-06-21 19:55 -------- d-----w- c:\documents and settings\Eric\Local Settings\Application Data\scsfmkdxh
2010-06-10 21:22 . 2010-05-06 10:41 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-28 07:13 . 2007-07-04 01:18 -------- d-----w- c:\documents and settings\Eric\Application Data\OpenOffice.org2
2010-06-28 06:44 . 2008-10-16 22:14 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-06-28 06:42 . 2010-03-09 00:37 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-28 06:35 . 2009-03-25 03:44 29 -c--a-w- c:\windows\popcinfo.dat
2010-06-28 05:58 . 2007-03-07 02:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2010-06-28 05:53 . 2007-06-08 00:02 -------- d-----w- c:\program files\Common Files\Adobe
2010-06-28 04:09 . 2010-03-19 01:14 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-06-28 03:55 . 2006-10-02 08:55 -------- d-----w- c:\program files\Java
2010-06-20 18:40 . 2009-03-25 01:01 -------- d-----w- c:\documents and settings\Jordan\Application Data\OpenOffice.org2
2010-06-20 09:24 . 2009-03-07 02:32 -------- d-----w- c:\documents and settings\Jordan\Application Data\LimeWire
2010-06-20 09:13 . 2009-05-24 23:03 -------- d-----w- c:\documents and settings\Ciera\Application Data\OpenOffice.org2
2010-06-11 17:11 . 2009-11-06 00:41 -------- d-----w- c:\program files\Microsoft Silverlight
2010-06-02 13:06 . 2008-06-19 02:48 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-06-02 13:06 . 2007-07-01 23:01 29584 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-05-28 20:22 . 2010-05-28 20:22 503808 ----a-w- c:\documents and settings\Eric\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-48905b33-n\msvcp71.dll
2010-05-28 20:22 . 2010-05-28 20:22 499712 ----a-w- c:\documents and settings\Eric\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-48905b33-n\jmc.dll
2010-05-28 20:22 . 2010-05-28 20:22 348160 ----a-w- c:\documents and settings\Eric\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-48905b33-n\msvcr71.dll
2010-05-28 20:22 . 2010-05-28 20:22 61440 ----a-w- c:\documents and settings\Eric\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-65d10512-n\decora-sse.dll
2010-05-28 20:22 . 2010-05-28 20:22 12800 ----a-w- c:\documents and settings\Eric\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-65d10512-n\decora-d3d.dll
2010-05-25 01:59 . 2010-05-25 01:59 503808 ----a-w- c:\documents and settings\Ciera\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-396d1602-n\msvcp71.dll
2010-05-25 01:59 . 2010-05-25 01:59 499712 ----a-w- c:\documents and settings\Ciera\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-396d1602-n\jmc.dll
2010-05-25 01:59 . 2010-05-25 01:59 348160 ----a-w- c:\documents and settings\Ciera\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-396d1602-n\msvcr71.dll
2010-05-25 01:59 . 2010-05-25 01:59 61440 ----a-w- c:\documents and settings\Ciera\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-2c812b22-n\decora-sse.dll
2010-05-25 01:59 . 2010-05-25 01:59 12800 ----a-w- c:\documents and settings\Ciera\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-2c812b22-n\decora-d3d.dll
2010-05-20 05:01 . 2010-05-20 05:01 -------- d-----w- c:\program files\Common Files\Oberon Media
2010-05-20 05:01 . 2008-10-16 22:14 -------- d-----w- c:\program files\Oberon Media
2010-05-20 05:01 . 2008-10-16 22:14 -------- d-----w- c:\program files\MSN Games
2010-05-19 22:47 . 2010-05-19 22:46 -------- d-----w- c:\program files\iTunes
2010-05-19 22:46 . 2006-03-24 23:28 -------- d-----w- c:\program files\iPod
2010-05-19 22:46 . 2008-11-24 23:42 -------- d-----w- c:\program files\Common Files\Apple
2010-05-19 22:42 . 2010-05-19 22:42 -------- d-----w- c:\program files\Bonjour
2010-05-19 22:32 . 2010-05-19 22:32 73000 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe
2010-05-19 22:07 . 2007-01-30 22:52 -------- d-----w- c:\program files\LimeWire
2010-05-06 23:39 . 2007-12-19 02:49 -------- d-----w- c:\program files\CCleaner
2010-05-06 10:41 . 2004-08-04 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2004-08-04 12:00 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-29 19:39 . 2010-03-09 00:37 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 19:39 . 2010-03-09 00:37 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-25 21:26 . 2007-05-20 20:42 15080 -c--a-w- c:\documents and settings\Ciera\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-25 21:21 . 2010-04-25 21:21 503808 ----a-w- c:\documents and settings\Ciera\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-2adc8935-n\msvcp71.dll
2010-04-25 21:21 . 2010-04-25 21:21 499712 ----a-w- c:\documents and settings\Ciera\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-2adc8935-n\jmc.dll
2010-04-25 21:21 . 2010-04-25 21:21 348160 ----a-w- c:\documents and settings\Ciera\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-2adc8935-n\msvcr71.dll
2010-04-25 21:20 . 2010-04-25 21:20 12800 ----a-w- c:\documents and settings\Ciera\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-3a31f2e1-n\decora-d3d.dll
2010-04-25 21:20 . 2010-04-25 21:20 61440 ----a-w- c:\documents and settings\Ciera\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-3a31f2e1-n\decora-sse.dll
2010-04-22 02:02 . 2010-04-22 02:02 503808 ----a-w- c:\documents and settings\Jordan\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-776f0010-n\msvcp71.dll
2010-04-22 02:02 . 2010-04-22 02:02 499712 ----a-w- c:\documents and settings\Jordan\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-776f0010-n\jmc.dll
2010-04-22 02:02 . 2010-04-22 02:02 348160 ----a-w- c:\documents and settings\Jordan\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-776f0010-n\msvcr71.dll
2010-04-22 02:02 . 2010-04-22 02:02 61440 ----a-w- c:\documents and settings\Jordan\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-7b0f9f3b-n\decora-sse.dll
2010-04-22 02:02 . 2010-04-22 02:02 12800 ----a-w- c:\documents and settings\Jordan\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-7b0f9f3b-n\decora-d3d.dll
2010-04-20 05:30 . 2004-08-04 12:00 285696 ----a-w- c:\windows\system32\atmfd.dll
2010-04-09 00:30 . 2010-04-09 00:30 503808 ----a-w- c:\documents and settings\Eric\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-291808b9-n\msvcp71.dll
2010-04-09 00:30 . 2010-04-09 00:30 499712 ----a-w- c:\documents and settings\Eric\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-291808b9-n\jmc.dll
2010-04-09 00:30 . 2010-04-09 00:30 348160 ----a-w- c:\documents and settings\Eric\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-291808b9-n\msvcr71.dll
2010-04-09 00:30 . 2010-04-09 00:30 61440 ----a-w- c:\documents and settings\Eric\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-5250cc39-n\decora-sse.dll
2010-04-09 00:30 . 2010-04-09 00:30 12800 ----a-w- c:\documents and settings\Eric\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-5250cc39-n\decora-d3d.dll
2010-04-09 00:29 . 2008-12-11 23:45 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-04-08 17:20 . 2010-04-08 17:20 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-04-08 17:20 . 2010-04-08 17:20 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-04-05 22:37 . 2009-03-24 17:48 15080 ----a-w- c:\documents and settings\Jordan\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-04-19 14:25 2117704 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2006-03-31 36864]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2010-05-26 2346192]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-11-15 77824]
"ASUS Probe"="c:\program files\ASUS\Asus Probe\AsusProb.exe" [2002-12-06 617984]
"Launch Ai Booster"="c:\program files\ASUS\Ai Booster\OverClk.exe" [2005-06-16 3627520]
"D-Link AirPlus XtremeG"="c:\program files\D-Link\AirPlus XtremeG\AirPlusCFG.exe" [2004-09-22 987136]
"ANIWZCS2Service"="c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2004-08-16 45056]
"WinFoxV2"="c:\windows\system32\WF2K.EXE" [2006-03-17 1486848]
"WinFast2KLoadDefault"="wf2kcpl.dll" [2006-03-17 668672]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-03-09 7561216]
"nwiz"="nwiz.exe" [2006-03-09 1519616]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2004-12-10 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2005-01-12 241664]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-03-09 86016]
"WINDVDPatch"="CTHELPER.EXE" [2002-07-02 24576]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"Jet Detection"="c:\program files\Creative\SBLive\PROGRAM\ADGJDet.exe" [2001-11-29 28672]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 32768]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-03-17 47392]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-06-02 2065248]
"accrdsub"="c:\program files\ActivIdentity\ActivClient\accrdsub.exe" [2007-05-15 293168]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SWHelper"="c:\windows\system32\Macromed\Shockwave 10\PostUpdate.exe" [2010-06-20 53248]
c:\documents and settings\Ciera\Start Menu\Programs\Startup\
OpenOffice.org 2.2.lnk - c:\program files\OpenOffice.org 2.2\program\quickstart.exe [2007-2-2 393216]
c:\documents and settings\Jordan\Start Menu\Programs\Startup\
OpenOffice.org 2.2.lnk - c:\program files\OpenOffice.org 2.2\program\quickstart.exe [2007-2-2 393216]
c:\documents and settings\Eric\Start Menu\Programs\Startup\
OpenOffice.org 2.2.lnk - c:\program files\OpenOffice.org 2.2\program\quickstart.exe [2007-2-2 393216]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
ActivClient Agent.lnk - c:\program files\ActivIdentity\ActivClient\acsagent.exe [2007-5-15 130864]
HotSync Manager.lnk - c:\program files\Palm\Hotsync.exe [2008-1-3 1392640]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2003-9-16 237568]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2006-3-30 196608]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2006-3-21 434176]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ackpbsc]
2007-05-15 21:08 112640 ----a-w- c:\windows\system32\ackpbsc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\acunlock]
2007-05-15 21:08 281088 ----a-w- c:\program files\ActivIdentity\ActivClient\acunlock.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-03-13 14:06 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0sprecovr \SystemRoot\sprecovr.txt
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\WinFox\\Living\\wfupdate.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\mshta.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Java\\jre1.5.0_05\\bin\\javaw.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP:DHCP Discovery Service
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/18/2008 10:48 PM 216200]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [6/18/2008 10:48 PM 242896]
R2 accoca;ActivClient Middleware Service;c:\program files\ActivIdentity\ActivClient\accoca.exe [5/15/2007 5:08 PM 182576]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [3/13/2010 10:05 AM 916760]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [3/13/2010 10:06 AM 308064]
R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\system32\drivers\A3AB.sys [9/2/2004 10:01 PM 396480]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [10/6/2009 4:32 PM 133104]
.
Contents of the 'Scheduled Tasks' folder
2010-06-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2010-06-28 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 15:20]
2010-06-28 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-01-31 04:31]
2010-06-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-06 20:32]
2010-06-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-06 20:32]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: {A91DEB0D-AD0D-453E-9AC8-60178EC24212} - hxxp://www.can-am.brp.com/brphtml/canamreborn/player/vivid_ocx.jpeg
FF - ProfilePath - c:\documents and settings\Eric\Application Data\Mozilla\Firefox\Profiles\803g8fgz.default\
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\Eric\Application Data\Move Networks\plugins\npqmp071503000010.dll
FF - plugin: c:\progra~1\Palm\PACKAG~1\NPInstal.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.chrome.favicons - fales
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: general.useragent.extra.zencast -
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
AddRemove-VisualTool - c:\program files\VisualTool\uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-28 03:53
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(800)
c:\windows\system32\ackpbsc.dll
c:\windows\system32\aclog.dll
c:\windows\system32\ACLIBEAY.dll
c:\windows\system32\acevtsub.dll
c:\windows\system32\asphat32.dll
c:\windows\system32\acerrmes.dll
c:\windows\system32\aspcom.dll
c:\program files\ActivIdentity\ActivClient\Resources\Merged\acerrmrc.dll
c:\program files\ActivIdentity\ActivClient\Resources\Merged\asphatrc.dll
c:\program files\ActivIdentity\ActivClient\acunlock.dll
c:\windows\system32\aipingui.dll
c:\program files\ActivIdentity\ActivClient\Resources\Merged\aipinguirc.dll
c:\program files\ActivIdentity\ActivClient\resources\acCobAPIrc.dll
c:\program files\ActivIdentity\ActivClient\Resources\Merged\acunlockrc.dll
.
Completion time: 2010-06-28 03:55:48
ComboFix-quarantined-files.txt 2010-06-28 07:55
Pre-Run: 58,931,056,640 bytes free
Post-Run: 61,700,784,128 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - DB94D13143C3D90906EEC3BDC3E9F9AE
_______________________________________________________________________
ComboFix 10-06-27.03 - Eric 06/28/2010 3:43.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1567 [GMT -4]
Running from: c:\documents and settings\Eric\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\VisualTool
c:\program files\VisualTool\pcre3.dll
c:\program files\VisualTool\uninstall.exe
c:\windows\Downloaded Program Files\popcaploader.dll
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\system\VCL35.BPL
c:\windows\system32\hljwugsf.bin
Infected copy of c:\windows\system32\drivers\tcpip.sys was found and disinfected
Restored copy from - Kitty had a snack :p
.
((((((((((((((((((((((((( Files Created from 2010-05-28 to 2010-06-28 )))))))))))))))))))))))))))))))
.
2010-06-28 06:44 . 2010-06-28 06:44 552 ----a-w- c:\windows\system32\d3d8caps.dat
2010-06-28 05:55 . 2010-06-28 05:55 -------- d-----w- c:\windows\system32\wbem\Repository
2010-06-28 04:04 . 2010-06-28 05:53 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-06-28 03:27 . 2010-06-28 03:27 -------- d-----w- c:\program files\Trend Micro
2010-06-25 08:49 . 2010-06-25 08:54 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-06-20 09:14 . 2010-06-20 09:14 -------- d-----w- c:\documents and settings\Ciera\Application Data\IObit
2010-06-20 09:04 . 2010-06-21 19:55 -------- d-----w- c:\documents and settings\Eric\Local Settings\Application Data\scsfmkdxh
2010-06-10 21:22 . 2010-05-06 10:41 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-28 07:13 . 2007-07-04 01:18 -------- d-----w- c:\documents and settings\Eric\Application Data\OpenOffice.org2
2010-06-28 06:44 . 2008-10-16 22:14 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-06-28 06:42 . 2010-03-09 00:37 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-28 06:35 . 2009-03-25 03:44 29 -c--a-w- c:\windows\popcinfo.dat
2010-06-28 05:58 . 2007-03-07 02:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2010-06-28 05:53 . 2007-06-08 00:02 -------- d-----w- c:\program files\Common Files\Adobe
2010-06-28 04:09 . 2010-03-19 01:14 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-06-28 03:55 . 2006-10-02 08:55 -------- d-----w- c:\program files\Java
2010-06-20 18:40 . 2009-03-25 01:01 -------- d-----w- c:\documents and settings\Jordan\Application Data\OpenOffice.org2
2010-06-20 09:24 . 2009-03-07 02:32 -------- d-----w- c:\documents and settings\Jordan\Application Data\LimeWire
2010-06-20 09:13 . 2009-05-24 23:03 -------- d-----w- c:\documents and settings\Ciera\Application Data\OpenOffice.org2
2010-06-11 17:11 . 2009-11-06 00:41 -------- d-----w- c:\program files\Microsoft Silverlight
2010-06-02 13:06 . 2008-06-19 02:48 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-06-02 13:06 . 2007-07-01 23:01 29584 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-05-28 20:22 . 2010-05-28 20:22 503808 ----a-w- c:\documents and settings\Eric\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-48905b33-n\msvcp71.dll
2010-05-28 20:22 . 2010-05-28 20:22 499712 ----a-w- c:\documents and settings\Eric\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-48905b33-n\jmc.dll
2010-05-28 20:22 . 2010-05-28 20:22 348160 ----a-w- c:\documents and settings\Eric\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-48905b33-n\msvcr71.dll
2010-05-28 20:22 . 2010-05-28 20:22 61440 ----a-w- c:\documents and settings\Eric\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-65d10512-n\decora-sse.dll
2010-05-28 20:22 . 2010-05-28 20:22 12800 ----a-w- c:\documents and settings\Eric\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-65d10512-n\decora-d3d.dll
2010-05-25 01:59 . 2010-05-25 01:59 503808 ----a-w- c:\documents and settings\Ciera\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-396d1602-n\msvcp71.dll
2010-05-25 01:59 . 2010-05-25 01:59 499712 ----a-w- c:\documents and settings\Ciera\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-396d1602-n\jmc.dll
2010-05-25 01:59 . 2010-05-25 01:59 348160 ----a-w- c:\documents and settings\Ciera\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-396d1602-n\msvcr71.dll
2010-05-25 01:59 . 2010-05-25 01:59 61440 ----a-w- c:\documents and settings\Ciera\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-2c812b22-n\decora-sse.dll
2010-05-25 01:59 . 2010-05-25 01:59 12800 ----a-w- c:\documents and settings\Ciera\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-2c812b22-n\decora-d3d.dll
2010-05-20 05:01 . 2010-05-20 05:01 -------- d-----w- c:\program files\Common Files\Oberon Media
2010-05-20 05:01 . 2008-10-16 22:14 -------- d-----w- c:\program files\Oberon Media
2010-05-20 05:01 . 2008-10-16 22:14 -------- d-----w- c:\program files\MSN Games
2010-05-19 22:47 . 2010-05-19 22:46 -------- d-----w- c:\program files\iTunes
2010-05-19 22:46 . 2006-03-24 23:28 -------- d-----w- c:\program files\iPod
2010-05-19 22:46 . 2008-11-24 23:42 -------- d-----w- c:\program files\Common Files\Apple
2010-05-19 22:42 . 2010-05-19 22:42 -------- d-----w- c:\program files\Bonjour
2010-05-19 22:32 . 2010-05-19 22:32 73000 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe
2010-05-19 22:07 . 2007-01-30 22:52 -------- d-----w- c:\program files\LimeWire
2010-05-06 23:39 . 2007-12-19 02:49 -------- d-----w- c:\program files\CCleaner
2010-05-06 10:41 . 2004-08-04 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2004-08-04 12:00 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-29 19:39 . 2010-03-09 00:37 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 19:39 . 2010-03-09 00:37 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-25 21:26 . 2007-05-20 20:42 15080 -c--a-w- c:\documents and settings\Ciera\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-25 21:21 . 2010-04-25 21:21 503808 ----a-w- c:\documents and settings\Ciera\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-2adc8935-n\msvcp71.dll
2010-04-25 21:21 . 2010-04-25 21:21 499712 ----a-w- c:\documents and settings\Ciera\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-2adc8935-n\jmc.dll
2010-04-25 21:21 . 2010-04-25 21:21 348160 ----a-w- c:\documents and settings\Ciera\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-2adc8935-n\msvcr71.dll
2010-04-25 21:20 . 2010-04-25 21:20 12800 ----a-w- c:\documents and settings\Ciera\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-3a31f2e1-n\decora-d3d.dll
2010-04-25 21:20 . 2010-04-25 21:20 61440 ----a-w- c:\documents and settings\Ciera\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-3a31f2e1-n\decora-sse.dll
2010-04-22 02:02 . 2010-04-22 02:02 503808 ----a-w- c:\documents and settings\Jordan\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-776f0010-n\msvcp71.dll
2010-04-22 02:02 . 2010-04-22 02:02 499712 ----a-w- c:\documents and settings\Jordan\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-776f0010-n\jmc.dll
2010-04-22 02:02 . 2010-04-22 02:02 348160 ----a-w- c:\documents and settings\Jordan\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-776f0010-n\msvcr71.dll
2010-04-22 02:02 . 2010-04-22 02:02 61440 ----a-w- c:\documents and settings\Jordan\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-7b0f9f3b-n\decora-sse.dll
2010-04-22 02:02 . 2010-04-22 02:02 12800 ----a-w- c:\documents and settings\Jordan\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-7b0f9f3b-n\decora-d3d.dll
2010-04-20 05:30 . 2004-08-04 12:00 285696 ----a-w- c:\windows\system32\atmfd.dll
2010-04-09 00:30 . 2010-04-09 00:30 503808 ----a-w- c:\documents and settings\Eric\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-291808b9-n\msvcp71.dll
2010-04-09 00:30 . 2010-04-09 00:30 499712 ----a-w- c:\documents and settings\Eric\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-291808b9-n\jmc.dll
2010-04-09 00:30 . 2010-04-09 00:30 348160 ----a-w- c:\documents and settings\Eric\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-291808b9-n\msvcr71.dll
2010-04-09 00:30 . 2010-04-09 00:30 61440 ----a-w- c:\documents and settings\Eric\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-5250cc39-n\decora-sse.dll
2010-04-09 00:30 . 2010-04-09 00:30 12800 ----a-w- c:\documents and settings\Eric\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-5250cc39-n\decora-d3d.dll
2010-04-09 00:29 . 2008-12-11 23:45 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-04-08 17:20 . 2010-04-08 17:20 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-04-08 17:20 . 2010-04-08 17:20 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-04-05 22:37 . 2009-03-24 17:48 15080 ----a-w- c:\documents and settings\Jordan\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-04-19 14:25 2117704 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2006-03-31 36864]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2010-05-26 2346192]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-11-15 77824]
"ASUS Probe"="c:\program files\ASUS\Asus Probe\AsusProb.exe" [2002-12-06 617984]
"Launch Ai Booster"="c:\program files\ASUS\Ai Booster\OverClk.exe" [2005-06-16 3627520]
"D-Link AirPlus XtremeG"="c:\program files\D-Link\AirPlus XtremeG\AirPlusCFG.exe" [2004-09-22 987136]
"ANIWZCS2Service"="c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2004-08-16 45056]
"WinFoxV2"="c:\windows\system32\WF2K.EXE" [2006-03-17 1486848]
"WinFast2KLoadDefault"="wf2kcpl.dll" [2006-03-17 668672]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-03-09 7561216]
"nwiz"="nwiz.exe" [2006-03-09 1519616]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2004-12-10 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2005-01-12 241664]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-03-09 86016]
"WINDVDPatch"="CTHELPER.EXE" [2002-07-02 24576]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"Jet Detection"="c:\program files\Creative\SBLive\PROGRAM\ADGJDet.exe" [2001-11-29 28672]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 32768]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-03-17 47392]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-06-02 2065248]
"accrdsub"="c:\program files\ActivIdentity\ActivClient\accrdsub.exe" [2007-05-15 293168]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SWHelper"="c:\windows\system32\Macromed\Shockwave 10\PostUpdate.exe" [2010-06-20 53248]
c:\documents and settings\Ciera\Start Menu\Programs\Startup\
OpenOffice.org 2.2.lnk - c:\program files\OpenOffice.org 2.2\program\quickstart.exe [2007-2-2 393216]
c:\documents and settings\Jordan\Start Menu\Programs\Startup\
OpenOffice.org 2.2.lnk - c:\program files\OpenOffice.org 2.2\program\quickstart.exe [2007-2-2 393216]
c:\documents and settings\Eric\Start Menu\Programs\Startup\
OpenOffice.org 2.2.lnk - c:\program files\OpenOffice.org 2.2\program\quickstart.exe [2007-2-2 393216]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
ActivClient Agent.lnk - c:\program files\ActivIdentity\ActivClient\acsagent.exe [2007-5-15 130864]
HotSync Manager.lnk - c:\program files\Palm\Hotsync.exe [2008-1-3 1392640]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2003-9-16 237568]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2006-3-30 196608]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2006-3-21 434176]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ackpbsc]
2007-05-15 21:08 112640 ----a-w- c:\windows\system32\ackpbsc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\acunlock]
2007-05-15 21:08 281088 ----a-w- c:\program files\ActivIdentity\ActivClient\acunlock.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-03-13 14:06 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0sprecovr \SystemRoot\sprecovr.txt
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\WinFox\\Living\\wfupdate.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\mshta.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Java\\jre1.5.0_05\\bin\\javaw.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP:DHCP Discovery Service
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/18/2008 10:48 PM 216200]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [6/18/2008 10:48 PM 242896]
R2 accoca;ActivClient Middleware Service;c:\program files\ActivIdentity\ActivClient\accoca.exe [5/15/2007 5:08 PM 182576]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [3/13/2010 10:05 AM 916760]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [3/13/2010 10:06 AM 308064]
R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\system32\drivers\A3AB.sys [9/2/2004 10:01 PM 396480]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [10/6/2009 4:32 PM 133104]
.
Contents of the 'Scheduled Tasks' folder
2010-06-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2010-06-28 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 15:20]
2010-06-28 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-01-31 04:31]
2010-06-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-06 20:32]
2010-06-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-06 20:32]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: {A91DEB0D-AD0D-453E-9AC8-60178EC24212} - hxxp://www.can-am.brp.com/brphtml/canamreborn/player/vivid_ocx.jpeg
FF - ProfilePath - c:\documents and settings\Eric\Application Data\Mozilla\Firefox\Profiles\803g8fgz.default\
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\Eric\Application Data\Move Networks\plugins\npqmp071503000010.dll
FF - plugin: c:\progra~1\Palm\PACKAG~1\NPInstal.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.chrome.favicons - fales
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: general.useragent.extra.zencast -
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
AddRemove-VisualTool - c:\program files\VisualTool\uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-28 03:53
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(800)
c:\windows\system32\ackpbsc.dll
c:\windows\system32\aclog.dll
c:\windows\system32\ACLIBEAY.dll
c:\windows\system32\acevtsub.dll
c:\windows\system32\asphat32.dll
c:\windows\system32\acerrmes.dll
c:\windows\system32\aspcom.dll
c:\program files\ActivIdentity\ActivClient\Resources\Merged\acerrmrc.dll
c:\program files\ActivIdentity\ActivClient\Resources\Merged\asphatrc.dll
c:\program files\ActivIdentity\ActivClient\acunlock.dll
c:\windows\system32\aipingui.dll
c:\program files\ActivIdentity\ActivClient\Resources\Merged\aipinguirc.dll
c:\program files\ActivIdentity\ActivClient\resources\acCobAPIrc.dll
c:\program files\ActivIdentity\ActivClient\Resources\Merged\acunlockrc.dll
.
Completion time: 2010-06-28 03:55:48
ComboFix-quarantined-files.txt 2010-06-28 07:55
Pre-Run: 58,931,056,640 bytes free
Post-Run: 61,700,784,128 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - DB94D13143C3D90906EEC3BDC3E9F9AE