Hi Elise, here is the Combofix log. Thanks again for the help.
ComboFix 09-12-24.02 - Yat 12/24/2009 15:06:41.1.4 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3327.2836 [GMT -5:00]
Running from: c:\documents and settings\Yat\My Documents\Downloads\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Yat\Start Menu\Programs\Startup\MagicDisc.lnk
c:\windows\system32\qtplugin.exe
.
((((((((((((((((((((((((( Files Created from 2009-11-24 to 2009-12-24 )))))))))))))))))))))))))))))))
.
2009-12-24 21:08 . 2009-12-24 21:08 -------- d-----w- c:\windows\LastGood
2009-12-23 01:06 . 2009-12-23 01:06 -------- d-----w- c:\documents and settings\Yat\Application Data\MyGames
2009-12-23 01:04 . 2009-12-23 01:04 -------- d-----w- c:\windows\system32\{1361570A-7A05-4FE0-B657-E2B1D167B03D}
2009-12-13 06:49 . 2009-12-13 06:49 -------- d-----w- c:\documents and settings\Yat\Application Data\My Games
2009-12-12 02:58 . 2009-12-12 02:58 -------- d-----w- c:\program files\Firaxis Games
2009-12-11 09:37 . 2009-12-11 09:37 536576 ----a-w- c:\windows\system32\crash_report.dll
2009-12-01 20:03 . 2009-12-01 20:03 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-12-01 20:03 . 2009-12-01 20:03 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-12-01 20:03 . 2009-12-01 20:03 -------- d-----w- c:\documents and settings\Yat\Application Data\SUPERAntiSpyware.com
2009-12-01 19:26 . 2009-12-01 19:26 -------- d-----w- c:\program files\Prevx
2009-12-01 19:26 . 2009-12-01 19:26 -------- d-----w- c:\documents and settings\All Users\Application Data\PrevxCSI
2009-12-01 02:44 . 2009-12-01 02:44 -------- d-----w- c:\documents and settings\Yat\Local Settings\Application Data\AVG Security Toolbar
2009-12-01 02:43 . 2009-12-01 02:47 -------- d-----w- C:\$AVG
2009-12-01 02:42 . 2009-12-01 02:42 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-12-01 02:42 . 2009-12-01 02:42 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-12-01 02:42 . 2009-12-01 02:42 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-12-01 02:42 . 2009-12-01 02:42 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-12-01 02:42 . 2009-12-24 19:24 -------- d-----w- c:\windows\system32\drivers\Avg
2009-12-01 02:42 . 2009-12-01 02:42 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-12-01 02:41 . 2009-12-01 02:41 -------- d-----w- c:\program files\AVG
2009-12-01 02:41 . 2009-12-23 18:01 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2009-12-01 01:40 . 2009-12-01 02:09 -------- d-----w- c:\documents and settings\Yat\Application Data\QuickScan
2009-12-01 01:32 . 2009-12-01 01:32 -------- d-----w- c:\program files\Trend Micro
2009-11-30 23:59 . 2009-11-30 23:59 -------- d-----w- c:\documents and settings\All Users\Application Data\F-Secure
2009-11-30 22:48 . 2009-11-30 23:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-11-30 22:48 . 2009-11-30 22:50 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-11-30 18:17 . 2009-11-30 18:17 -------- d-----w- c:\documents and settings\Yat\Application Data\FRISK Software
2009-11-30 18:13 . 2009-12-01 17:08 -------- d-----w- c:\documents and settings\All Users\Application Data\FRISK Software
2009-11-25 19:19 . 2009-12-22 21:18 -------- d-----w- c:\program files\UB
2009-11-25 19:19 . 2009-11-25 19:20 -------- d-----w- c:\documents and settings\Yat\Application Data\UB
2009-11-25 19:19 . 2009-11-25 19:19 -------- d-----w- c:\program files\_uninstallation_info
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-24 19:45 . 2008-11-18 06:04 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-12-24 19:44 . 2008-11-18 06:04 -------- d-----w- c:\program files\Symantec
2009-12-24 19:44 . 2008-11-18 06:04 -------- d-----w- c:\program files\Symantec AntiVirus
2009-12-24 19:44 . 2008-11-18 06:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-12-23 20:51 . 2008-11-20 07:25 -------- d-----w- c:\program files\Steam
2009-12-22 21:51 . 2008-12-15 06:36 -------- d-----w- c:\documents and settings\Yat\Application Data\LimeWire
2009-12-22 13:59 . 2008-12-01 02:14 -------- d-----w- c:\program files\Mozilla Thunderbird
2009-12-14 18:11 . 2008-12-10 00:54 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-13 19:48 . 2009-01-31 18:33 -------- d-----w- c:\program files\PokerStars
2009-12-13 18:32 . 2008-11-25 00:20 -------- d-----w- c:\documents and settings\Yat\Application Data\uTorrent
2009-12-12 02:58 . 2008-11-18 03:07 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-03 21:14 . 2008-12-10 00:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-03 21:13 . 2008-12-10 00:54 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-01 20:03 . 2009-01-14 06:15 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-12-01 02:47 . 2009-11-24 16:03 -------- d-----w- c:\documents and settings\All Users\Application Data\SP
2009-11-21 13:41 . 2008-12-09 20:21 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-11-10 23:34 . 2009-11-10 23:34 -------- d-----w- c:\program files\Microsoft Silverlight
2009-11-10 23:34 . 2009-11-10 23:29 -------- d-----w- c:\program files\Microsoft
2009-11-10 23:33 . 2009-11-10 23:33 -------- d-----w- c:\program files\Microsoft Office Outlook Connector
2009-11-10 23:33 . 2008-11-19 02:07 -------- d-----w- c:\program files\Windows Live
2009-11-10 23:32 . 2009-11-10 23:32 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-11-10 23:31 . 2009-11-10 23:31 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-11-10 23:28 . 2009-11-10 23:28 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-11-10 23:20 . 2009-11-10 23:20 -------- d-----w- c:\program files\Common Files\Windows Live
2009-11-05 07:22 . 2008-11-25 05:49 -------- d-----w- c:\program files\Warcraft III
2009-11-02 21:56 . 2008-11-22 22:33 -------- d-----w- c:\documents and settings\Yat\Application Data\PLT Scheme
2009-10-28 03:53 . 2008-11-18 18:13 189184 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-10-28 03:49 . 2008-11-18 18:13 138064 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-10-27 05:52 . 2008-11-28 04:05 -------- d-----w- c:\documents and settings\Yat\Application Data\Bioshock
2009-10-26 02:09 . 2009-02-06 20:28 -------- d-----w- c:\program files\The Witcher
2009-10-26 02:08 . 2009-03-09 18:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Electronic Arts
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-11-25 18:01 1230080 ----a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-11-25 1230080]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-11-23 2001648]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2007-08-31 988584]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-08-31 1037736]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-26 13680640]
"nwiz"="nwiz.exe" [2008-12-26 1657376]
"Six Engine"="c:\program files\ASUS\Six Engine\SixEngine.exe" [2008-06-03 5964800]
"XboxStat"="c:\program files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2007-09-26 734264]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2006-10-23 620152]
"RTHDCPL"="RTHDCPL.EXE" [2008-11-07 17421824]
"H2O"="c:\program files\SyncroSoft\Pos\H2O\cledx.exe" [2005-12-18 307200]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-30 136600]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-12-26 86016]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-13 342312]
"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-12-12 642856]
"Linksys Wireless Manager"="c:\program files\Linksys\Linksys Wireless Manager\LinksysWirelessManager.exe" [2009-05-11 1348144]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2009-12-12 2033432]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-F400-7760-000000000003}\_SC_Acrobat.exe [2008-11-20 295606]
Adobe Acrobat Synchronizer.lnk - c:\program files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe [2006-10-23 734872]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-27 304128]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"crash_report"= {495FE683-6249-4A05-8D1A-8F7CD8DF5A6D} - c:\windows\system32\crash_report.dll [2009-12-11 536576]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-12-01 02:42 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\FPAVServer]
@=""
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\SideApps\\StrongDC\\StrongDC.exe"=
"c:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"c:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx9.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx10.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Launcher.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"=
"c:\\Program Files\\Sierra\\FEAR\\FEAR.exe"=
"c:\\Program Files\\Mass Effect\\Binaries\\MassEffect.exe"=
"c:\\Program Files\\Mass Effect\\MassEffectLauncher.exe"=
"c:\\Program Files\\Rockstar Games\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"c:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic.exe"=
"c:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic_online.exe"=
"c:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic_ds.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Stardock Games\\Sins of a Solar Empire\\Sins of a Solar Empire.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\WINDOWS\\system32\\searchprotocolhost.exe"=
"c:\\Program Files\\EA Games\\Mirror's Edge\\Binaries\\MirrorsEdge.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Ubisoft\\Tom Clancy's Rainbow Six Vegas\\Binaries\\R6Vegas_Game.exe"=
"c:\\Program Files\\Ubisoft\\Tom Clancy's Rainbow Six Vegas\\Binaries\\R6Vegas_Launcher.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Electronic Arts\\Battlefield 2142\\BF2142.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaW.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaWmp.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\WINDOWS\\system32\\svchost.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\call of duty modern warfare 2\\iw4sp.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\call of duty modern warfare 2\\iw4mp.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\left 4 dead\\srcds.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"7385:TCP"= 7385:TCP:spport
"24462:TCP"= 24462:TCP:spport
"9535:TCP"= 9535:TCP:spport
"11253:TCP"= 11253:TCP:spport
R0 mv61xx;mv61xx;c:\windows\system32\drivers\mv61xx.sys [6/23/2008 5:21 PM 150568]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [11/30/2009 9:42 PM 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [11/30/2009 9:42 PM 360584]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [11/23/2009 8:43 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [11/23/2009 8:43 AM 74480]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [11/30/2009 9:41 PM 285392]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [11/10/2009 6:33 PM 54752]
R3 CLEDX;Team H2O CLEDX service;c:\windows\system32\drivers\cledx.sys [11/27/2008 7:28 PM 33792]
R3 rt2870;Linksys 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys [9/9/2009 10:42 AM 709248]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [11/23/2009 8:43 AM 7408]
S2 SPService;SPService;c:\windows\system32\svchost.exe -k netsvc [4/14/2008 6:42 AM 14336]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\Windows Live\Family Safety\fsssvc.exe [8/5/2009 10:48 PM 704864]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [11/25/2008 12:02 PM 717296]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - GTNDIS5
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
netsvc REG_MULTI_SZ SPService
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ca/
uInternet Settings,ProxyOverride = *.local
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Yat\Application Data\Mozilla\Firefox\Profiles\90pov9cb.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.google.ca
FF - prefs.js: keyword.URL - hxxp://ca.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_ca&p=
FF - component: c:\documents and settings\Yat\Application Data\Mozilla\Firefox\Profiles\90pov9cb.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\bdqscan.dll
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\Yat\Application Data\Mozilla\Firefox\Profiles\90pov9cb.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.
- - - - ORPHANS REMOVED - - - -
ShellIconOverlayIdentifiers-{96AFBE69-C3B0-4b00-8578-D933D2896EE2} - c:\documents and settings\all users\application data\sp\sp.dll
HKCU-Run-EA Core - c:\program files\Electronic Arts\EADM\Core.exe
Notify-NavLogon - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-12-24 16:13
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-796845957-1326574676-1801674531-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:fa,ed,fa,c1,7f,49,6a,a4,aa,ea,92,08,2f,a7,29,ed,8a,69,c1,9d,12,13,0d,
2f,ee,9a,c1,86,51,a4,08,8a,60,3d,95,19,b2,f4,46,5a,5c,68,48,9c,9d,d5,51,7c,\
"??"=hex:35,fc,c6,3d,c9,02,ad,db,37,1f,61,de,0f,33,8f,50
[HKEY_USERS\S-1-5-21-796845957-1326574676-1801674531-1003\Software\SecuROM\License information*]
"datasecu"=hex:cd,28,dd,30,3b,54,6a,2d,8f,bd,01,41,67,44,2f,2a,4d,fa,b4,b9,84,
28,1b,5f,ac,2a,10,7d,b4,de,cc,35,ce,88,4c,a2,34,36,7c,66,7c,a9,8e,53,9f,d1,\
"rkeysecu"=hex:da,e4,54,51,a2,49,35,b9,82,9a,a6,74,66,ea,02,bf
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•A~*]
"AB141C35E9F4BF344B9FC010BB17F68A"=""
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1052)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
- - - - - - - > 'explorer.exe'(5324)
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\crash_report.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
c:\program files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
c:\windows\system32\SearchIndexer.exe
c:\program files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
c:\windows\system32\wscntfy.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\program files\Microsoft IntelliType Pro\dpupdchk.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
c:\program files\Windows Live\Toolbar\wltuser.exe
c:\windows\SoftwareDistribution\Download\a9adf18fc8eded94a5e1af98a7572830\update\update.exe
.
**************************************************************************
.
Completion time: 2009-12-24 16:22:09 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-24 21:21
Pre-Run: 31,022,280,704 bytes free
Post-Run: 31,385,387,008 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - F0C870825439AEF802741DCA1799FAFC