ok, heres the combofix log
ComboFix 10-08-17.04 - Joe 08/18/2010 22:25:58.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1496 [GMT -4:00]
Running from: c:\documents and settings\Joe\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((( Files Created from 2010-07-19 to 2010-08-19 )))))))))))))))))))))))))))))))
.
2010-07-20 21:41 . 2010-07-20 21:41 4368224 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2010-07-20 21:41 . 2010-07-20 21:41 1615200 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgssie.dll
2010-07-20 21:41 . 2010-07-20 21:41 1373536 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgssff.dll
2010-07-20 21:41 . 2010-07-20 21:41 1107296 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgxpl.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-17 19:58 . 2004-05-16 14:12 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-07-23 20:55 . 2010-04-13 03:30 -------- d-----w- c:\documents and settings\Joe\Application Data\vlc
2010-07-22 02:01 . 2009-08-17 01:55 -------- d-----w- c:\documents and settings\Joe\Application Data\uTorrent
2010-07-19 23:08 . 2010-07-19 23:08 242896 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtdix.sys
2010-07-19 23:08 . 2010-07-19 23:08 216200 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgldx86.sys
2010-07-19 23:08 . 2009-08-12 09:02 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-07-19 23:08 . 2010-07-19 23:08 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-07-19 23:08 . 2009-08-12 09:02 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-07-19 23:08 . 2010-07-19 23:08 813336 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avginet.dll
2010-07-19 23:08 . 2010-07-19 23:08 624920 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgiproxy.exe
2010-07-19 23:08 . 2010-07-19 23:08 1690464 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.dll
2010-07-19 23:08 . 2010-07-19 23:08 1038688 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.exe
2010-07-08 01:51 . 2010-07-07 18:38 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-07-07 18:38 . 2010-07-07 18:38 2568656 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player.exe
2010-07-06 23:01 . 2009-08-12 10:02 -------- d-----w- c:\program files\Electronic Arts
2010-07-06 23:00 . 2004-05-15 17:42 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-07-04 05:34 . 2010-07-04 05:34 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-06-26 16:10 . 2010-04-20 03:00 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-06-24 15:34 . 2010-06-24 15:34 -------- d-----w- c:\documents and settings\Joe\Application Data\Malwarebytes
2010-06-24 15:34 . 2010-06-24 15:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-24 04:40 . 2010-06-24 03:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-06-24 03:11 . 2010-06-24 03:11 388096 ----a-r- c:\documents and settings\Joe\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-06-24 02:39 . 2010-06-24 02:39 1152444 ----a-w- c:\windows\is-F9O56.tmp
2010-06-11 03:43 . 2010-05-19 03:14 57344 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-06-11 03:43 . 2010-06-11 03:43 56997 ----a-w- c:\documents and settings\All Users\Application Data\DivX\WebPlayer\Uninstaller.exe
2010-06-11 03:43 . 2010-06-11 03:43 56765 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-06-11 03:43 . 2010-06-11 03:43 57715 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Player\Uninstaller.exe
2010-06-11 03:43 . 2010-06-11 03:43 53600 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Update\Uninstaller.exe
2010-06-11 03:43 . 2010-06-11 03:43 54153 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DFXPlugin\Uninstaller.exe
2010-06-11 03:42 . 2010-06-11 03:42 54128 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Converter\Uninstaller.exe
2010-06-11 03:42 . 2010-06-11 03:42 54644 ----a-w- c:\documents and settings\All Users\Application Data\DivX\TranscodeEngine\Uninstaller.exe
2010-06-11 03:42 . 2010-06-11 03:42 54101 ----a-w- c:\documents and settings\All Users\Application Data\DivX\MPEG2Plugin\Uninstaller.exe
2010-06-11 03:42 . 2010-05-19 03:13 895256 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe
2010-06-11 03:42 . 2010-05-19 03:13 1062184 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\Resource.dll
2010-06-04 02:04 . 2009-08-12 09:02 29584 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-05-28 18:09 . 2010-05-28 18:09 61440 ----a-w- c:\documents and settings\Joe\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-79285046-n\decora-sse.dll
2010-05-28 18:09 . 2010-05-28 18:09 503808 ----a-w- c:\documents and settings\Joe\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-541e97d9-n\msvcp71.dll
2010-05-28 18:09 . 2010-05-28 18:09 499712 ----a-w- c:\documents and settings\Joe\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-541e97d9-n\jmc.dll
2010-05-28 18:09 . 2010-05-28 18:09 348160 ----a-w- c:\documents and settings\Joe\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-541e97d9-n\msvcr71.dll
2010-05-28 18:09 . 2010-05-28 18:09 12800 ----a-w- c:\documents and settings\Joe\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-79285046-n\decora-d3d.dll
.
(((((((((((((((((((((((((((((
SnapShot@2010-07-04_23.15.41 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-07-07 18:38 . 2010-07-07 18:38 231888 c:\windows\system32\Macromed\flash\FlashUtil10h_Plugin.exe
+ 2009-07-18 03:21 . 2010-07-07 18:38 5612496 c:\windows\system32\Macromed\flash\NPSWF32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="c:\program files\AIM6\aim6.exe" [2009-07-09 49968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ALiRaid"="c:\program files\ALIRAID\ALiRaid.exe" [2004-01-09 401408]
"PRONoMgr.exe"="c:\program files\Intel\NCS\PROSet\PRONoMgr.exe" [2003-03-11 86016]
"SBDrvDet"="c:\program files\Creative\SB Drive Det\SBDrvDet.exe" [2002-12-04 45056]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-03-23 335872]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RTHDCPL"="RTHDCPL.EXE" [2008-04-10 16861184]
"CMCService"="c:\program files\ATI\Catalyst Media Center\CMCService.exe" [2008-06-06 172032]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-07-19 2065760]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-07-19 23:08 12536 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
2003-10-06 22:57 24576 ----a-w- c:\windows\system32\CTHELPER.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSysVol]
2003-07-02 17:03 57344 ----a-w- c:\program files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-10-30 11:57 369200 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-06-03 00:50 1144104 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG9.0]
2007-04-19 21:00 125792 ----a-w- c:\progra~1\COMMON~1\MICROS~1\IME\IMJP9\IMJPMIG.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-11-13 00:33 141600 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-11 07:08 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 20:07 2260480 --sha-r- g:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-02-18 15:43 248040 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Hewlett-Packard\\HP Color Inkjet CP1700\\ToolBox\\HPWATBX.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"g:\\Program Files\\BrightShadow\\BrightShadow.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58513:TCP"= 58513:TCP:Pando Media Booster
"58513:UDP"= 58513:UDP:Pando Media Booster
R0 m5228;m5228;c:\windows\system32\drivers\m5228.sys [5/15/2004 1:41 PM 44925]
R0 m5281;m5281;c:\windows\system32\drivers\m5281.sys [5/15/2004 1:41 PM 49357]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [8/12/2009 5:02 AM 216400]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [8/12/2009 5:02 AM 243024]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [7/19/2010 7:08 PM 308136]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [8/12/2009 4:54 AM 24652]
S2 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe --> c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [?]
S3 GSSUSB;Gilat SkyBlaster USB Adapter;c:\windows\system32\drivers\gssNic.sys [5/16/2004 7:05 AM 161681]
S3 iteio;iteio;c:\windows\system32\drivers\ITEIO.SYS [5/16/2004 12:32 PM 3680]
S3 itsernum;itsernum Filter ÅX°Êµ{¦¡;c:\windows\system32\drivers\itsernum.sys [5/16/2004 12:32 PM 20133]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\e:\ntglm7x.sys --> e:\NTGLM7X.sys [?]
S3 Winacusb;Winacusb;c:\windows\system32\drivers\winacusb.sys [5/16/2004 12:28 PM 933818]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [11/23/2009 2:47 AM 691696]
.
Contents of the 'Scheduled Tasks' folder
2010-08-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 20:34]
2010-08-18 c:\windows\Tasks\Norton Security Scan for Joe.job
- c:\program files\Norton Security Scan\Engine\2.7.3.34\Nss.exe [2010-06-11 05:27]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://register.starband.net/IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: aol.com\free
TCP: {9F8EFC6E-3039-435B-AFDE-7D7F17129B90} = 24.25.5.148,24.25.5.147
DPF: DirectAnimation Java Classes -
file://c:\windows\Java\classes\dajava.cabDPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cabDPF: {3AF4DACE-36ED-42EF-9DFC-ADC34DA30CFF} -
file://e:\content\include\XPPatchInstaller.CABFF - ProfilePath - c:\documents and settings\Joe\Application Data\Mozilla\Firefox\Profiles\2vmklbu7.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.aol.comFF - plugin: c:\documents and settings\Joe\Application Data\Move Networks\plugins\npqmp071505000011.dll
FF - plugin: c:\documents and settings\Joe\Application Data\Move Networks\plugins\npqmp071701000002.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nppopcaploader.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.
**************************************************************************
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1085031214-484763869-682003330-1003\Software\SecuROM\License information*]
"datasecu"=hex:a1,d8,a3,44,d5,54,a8,b0,41,bb,85,29,ca,51,99,17,c6,c3,b6,3d,e6,
b7,76,b1,48,1c,e5,62,9e,e3,79,79,af,d3,71,c4,cd,a7,58,b1,2a,f3,73,17,45,9b,\
"rkeysecu"=hex:64,b6,bd,e1,3e,80,9e,c4,40,b4,90,83,87,8e,33,49
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(684)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(3508)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-08-18 22:32:30
ComboFix-quarantined-files.txt 2010-08-19 02:32
ComboFix2.txt 2010-07-04 23:17
Pre-Run: 3,832,057,856 bytes free
Post-Run: 3,822,235,648 bytes free
Current=7 Default=7 Failed=6 LastKnownGood=8 Sets=1,2,3,4,5,6,7,8
- - End Of File - - 48B47642D31CAFF0E43A7645858152BE