Hi Gringo
Here is the Combofix log as requested,
I noted that after running Combofix and then going online I got the message: Firefox is not currently set as your default browser, although it was before I ran Combofix, is this normal?
ComboFix 11-05-08.04 - Derek 09/05/2011 19:43:35.5.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3069.1397 [GMT 1:00]
Running from: c:\users\Derek\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((( Files Created from 2011-04-09 to 2011-05-09 )))))))))))))))))))))))))))))))
.
.
2011-05-09 19:04 . 2011-05-09 19:04 -------- d-----w- c:\users\Public\AppData\Local\temp
2011-05-09 19:04 . 2011-05-09 19:04 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-05-09 19:04 . 2011-05-09 19:04 -------- d-----w- c:\users\Ann\AppData\Local\temp
2011-05-07 00:00 . 2011-05-09 19:05 -------- d-----w- c:\users\Derek\AppData\Local\temp
2011-05-06 22:44 . 2011-05-06 22:44 -------- d-----w- C:\TDSSKiller_Quarantine
2011-05-06 22:19 . 2011-05-06 21:22 16432 ----a-w- c:\windows\system32\lsdelete.exe
2011-05-06 21:17 . 2011-04-29 11:12 64512 ----a-w- c:\windows\system32\drivers\Lbd.sys
2011-05-06 11:28 . 2011-05-06 11:28 -------- d-----w- c:\users\Derek\Pavark
2011-05-06 11:13 . 2011-05-06 11:23 -------- d-----w- c:\programdata\SecTaskMan
2011-05-06 11:13 . 2011-05-06 11:13 -------- d-----w- c:\program files\Security Task Manager
2011-05-05 21:40 . 2011-05-05 21:40 3263 ----a-w- C:\register.reg
2011-05-05 01:27 . 2011-05-05 01:27 -------- d-----w- c:\program files\MagicISO
2011-05-04 12:18 . 2011-05-04 12:18 -------- d-----w- c:\program files\ESET
2011-05-04 11:30 . 2011-05-04 11:30 2418162 ----a-w- C:\MGtools.exe
2011-05-03 20:52 . 2011-05-07 16:58 -------- d-----w- c:\program files\WhatsRunning
2011-05-03 15:46 . 2011-05-03 15:47 -------- d-----w- C:\Combo-Fix
2011-05-03 09:59 . 2011-04-18 17:17 307288 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-05-03 09:59 . 2011-04-18 17:12 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-05-03 09:59 . 2011-04-18 17:16 49240 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-05-03 09:59 . 2011-04-18 17:13 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-05-03 09:58 . 2011-04-18 17:17 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-05-03 09:58 . 2011-04-18 17:13 53592 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-05-03 09:58 . 2011-04-18 17:25 40112 ----a-w- c:\windows\avastSS.scr
2011-05-03 09:58 . 2011-04-18 17:25 199304 ----a-w- c:\windows\system32\aswBoot.exe
2011-05-03 09:58 . 2011-05-03 09:58 -------- d-----w- c:\programdata\AVAST Software
2011-05-03 09:58 . 2011-05-03 09:58 -------- d-----w- c:\program files\AVAST Software
2011-05-03 01:53 . 2011-03-03 15:40 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2011-05-03 01:53 . 2011-03-03 13:35 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2011-05-03 01:52 . 2011-03-12 21:55 876032 ----a-w- c:\windows\system32\XpsPrint.dll
2011-05-02 17:56 . 2011-05-02 17:56 -------- d-----w- c:\users\Derek\AppData\Roaming\SUPERAntiSpyware.com
2011-05-02 17:56 . 2011-05-02 17:56 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2011-05-02 17:55 . 2011-05-06 22:28 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-05-02 17:29 . 2011-05-02 17:29 -------- d-----w- c:\programdata\WindowsSearch
2011-05-02 16:22 . 2011-05-02 16:22 102400 ----a-w- c:\windows\RegBootClean.exe
2011-05-02 11:46 . 2011-05-02 11:56 -------- d-----w- c:\users\Derek\AppData\Roaming\Ydmeik
2011-05-01 20:10 . 2011-05-01 20:10 -------- d-----w- c:\program files\TomTom International B.V
2011-05-01 20:10 . 2011-05-01 20:10 -------- d-----w- c:\program files\TomTom HOME 2
2011-04-30 14:24 . 2011-04-30 14:29 -------- d-----w- c:\program files\BBS Tools
2011-04-30 14:24 . 2011-04-30 14:24 -------- d-----w- c:\windows\BBS Tools
2011-04-28 00:22 . 2011-04-28 00:22 784136 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2011-04-26 16:09 . 2011-04-26 17:11 -------- d-----w- c:\users\Derek\AppData\Local\dj3
2011-04-26 15:20 . 2011-04-22 05:40 -------- d-----w- c:\program files\Dracula - The Path of the Dragon - Part 3
2011-04-26 14:54 . 2011-04-26 14:54 -------- d-----w- c:\users\Derek\AppData\Roaming\Colibri Games
2011-04-26 14:54 . 2011-04-26 14:54 -------- d-----w- c:\programdata\Colibri Games
2011-04-26 14:54 . 2011-04-26 14:54 -------- d-----w- c:\program files\The Tiny Bang Story
2011-04-25 17:37 . 2011-04-25 17:37 -------- d-----w- c:\users\Derek\AppData\Roaming\Funlinker
2011-04-25 16:14 . 2011-04-25 16:14 -------- d-----w- c:\programdata\Avalon-Legends-Solitaire
2011-04-25 16:11 . 2011-04-25 16:11 -------- d-----w- c:\users\Derek\AppData\Roaming\DGform
2011-04-23 20:57 . 2011-04-23 20:57 -------- d-----w- c:\program files\iPod
2011-04-23 20:57 . 2011-04-23 20:58 -------- d-----w- c:\program files\iTunes
2011-04-23 20:54 . 2011-04-23 20:54 -------- d-----w- c:\program files\Bonjour
2011-04-23 17:07 . 2011-04-23 17:07 -------- d-----w- c:\programdata\Particles
2011-04-23 17:06 . 2011-04-23 17:06 -------- d-----w- c:\programdata\Far Mills
2011-04-23 14:05 . 2011-04-23 14:05 -------- d-----w- c:\users\Derek\AppData\Roaming\GigantGames
2011-04-18 14:52 . 2011-04-18 14:52 -------- d-----w- c:\users\Derek\AppData\Roaming\ShamanGS
2011-04-15 11:13 . 2011-03-15 04:05 6792528 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A79C2122-094D-4F90-AD73-64AE7DC44EE9}\mpengine.dll
2011-04-13 17:18 . 2011-04-13 17:19 -------- d-----w- c:\program files\Total Audio MP3 Converter
2011-04-13 14:52 . 2011-04-13 14:54 -------- d-----w- c:\users\Derek\AppData\Roaming\Mp3tag
2011-04-13 14:52 . 2011-04-13 14:52 -------- d-----w- c:\program files\Mp3tag
2011-04-11 23:40 . 2011-04-14 20:41 -------- d-----w- c:\users\Derek\Calibre Library
2011-04-11 23:40 . 2011-04-14 18:53 -------- d-----w- c:\users\Derek\AppData\Roaming\calibre
2011-04-11 23:39 . 2011-04-11 23:40 -------- d-----w- c:\program files\Calibre2
2011-04-11 21:29 . 2011-04-11 21:29 -------- d-----w- c:\users\Ann\AppData\Local\Sony Corporation
2011-04-11 21:29 . 2011-04-11 21:29 -------- d-----w- c:\users\Ann\AppData\Local\kinoma
2011-04-11 12:05 . 2011-04-11 12:05 -------- d-----w- c:\users\Derek\Library
2011-04-11 12:04 . 2011-04-11 12:04 -------- d-----w- c:\programdata\kinoma
2011-04-11 12:04 . 2011-04-11 12:04 -------- d-----w- c:\program files\DIFX
2011-04-11 12:04 . 2011-04-11 12:05 -------- d-----w- c:\users\Derek\AppData\Local\Sony Corporation
2011-04-11 12:04 . 2011-04-11 12:04 -------- d-----w- c:\program files\Sony
2011-04-11 12:04 . 2011-04-11 12:04 -------- d-----w- c:\program files\Common Files\Sony Shared
2011-04-11 12:02 . 2011-04-11 12:02 -------- d-----w- c:\users\Derek\AppData\Local\kinoma
2011-04-09 21:27 . 2011-04-09 21:27 -------- d-----w- c:\users\Derek\AppData\Roaming\Enki Games
2011-04-09 21:22 . 2011-04-09 21:22 -------- d-----w- c:\users\Derek\AppData\Roaming\thejoyoffarming
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-06 21:22 . 2010-04-27 19:01 98392 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-04-06 15:20 . 2011-04-06 15:20 91424 ----a-w- c:\windows\system32\dnssd.dll
2011-04-06 15:20 . 2011-04-06 15:20 107808 ----a-w- c:\windows\system32\dns-sd.exe
2011-04-05 19:57 . 2011-04-05 19:57 86528 ----a-w- c:\windows\system32\iesysprep.dll
2011-04-05 19:57 . 2011-04-05 19:57 76800 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2011-04-05 19:57 . 2011-04-05 19:57 74752 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe
2011-04-05 19:57 . 2011-04-05 19:57 74752 ----a-w- c:\windows\system32\iesetup.dll
2011-04-05 19:57 . 2011-04-05 19:57 63488 ----a-w- c:\windows\system32\tdc.ocx
2011-04-05 19:57 . 2011-04-05 19:57 48640 ----a-w- c:\windows\system32\mshtmler.dll
2011-04-05 19:57 . 2011-04-05 19:57 367104 ----a-w- c:\windows\system32\html.iec
2011-04-05 19:57 . 2011-04-05 19:57 23552 ----a-w- c:\windows\system32\licmgr10.dll
2011-04-05 19:57 . 2011-04-05 19:57 161792 ----a-w- c:\windows\system32\msls31.dll
2011-04-05 19:57 . 2011-04-05 19:57 1427456 ----a-w- c:\windows\system32\inetcpl.cpl
2011-04-05 19:57 . 2011-04-05 19:57 1126912 ----a-w- c:\windows\system32\wininet.dll
2011-04-05 19:57 . 2011-04-05 19:57 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-04-05 19:57 . 2011-04-05 19:57 35840 ----a-w- c:\windows\system32\imgutil.dll
2011-04-05 19:57 . 2011-04-05 19:57 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-04-05 19:57 . 2011-04-05 19:57 1797632 ----a-w- c:\windows\system32\jscript9.dll
2011-04-05 19:57 . 2011-04-05 19:57 152064 ----a-w- c:\windows\system32\wextract.exe
2011-04-05 19:57 . 2011-04-05 19:57 150528 ----a-w- c:\windows\system32\iexpress.exe
2011-04-05 19:57 . 2011-04-05 19:57 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2011-04-05 19:57 . 2011-04-05 19:57 11776 ----a-w- c:\windows\system32\mshta.exe
2011-04-05 19:57 . 2011-04-05 19:57 110592 ----a-w- c:\windows\system32\IEAdvpack.dll
2011-04-05 19:57 . 2011-04-05 19:57 101888 ----a-w- c:\windows\system32\admparse.dll
2011-04-05 19:28 . 2011-04-05 19:28 499712 ----a-w- c:\windows\system32\msvcp71.dll
2011-04-05 19:28 . 2011-04-05 19:28 348160 ----a-w- c:\windows\system32\msvcr71.dll
2011-03-03 15:40 . 2011-05-03 01:53 173056 ----a-w- c:\windows\apppatch\AcXtrnal.dll
2011-03-03 15:40 . 2011-05-03 01:53 542720 ----a-w- c:\windows\apppatch\AcLayers.dll
2011-03-03 15:40 . 2011-05-03 01:53 458752 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2011-03-03 15:40 . 2011-05-03 01:53 2159616 ----a-w- c:\windows\apppatch\AcGenral.dll
2011-02-23 07:27 . 2011-02-23 07:27 941160 ----a-w- c:\windows\system32\nvdispco322090.dll
2011-02-23 07:27 . 2011-02-23 07:27 837736 ----a-w- c:\windows\system32\nvgenco322040.dll
2011-02-23 07:27 . 2011-02-23 07:27 57960 ----a-w- c:\windows\system32\OpenCL.dll
2011-02-23 07:27 . 2011-02-23 07:27 5654120 ----a-w- c:\windows\system32\nvwgf2um.dll
2011-02-23 07:27 . 2011-02-23 07:27 4942952 ----a-w- c:\windows\system32\nvcuda.dll
2011-02-23 07:27 . 2011-02-23 07:27 2895976 ----a-w- c:\windows\system32\nvcuvid.dll
2011-02-23 07:27 . 2011-02-23 07:27 2251368 ----a-w- c:\windows\system32\nvcuvenc.dll
2011-02-23 07:27 . 2011-02-23 07:27 15047272 ----a-w- c:\windows\system32\nvoglv32.dll
2011-02-23 07:27 . 2011-02-23 07:27 13011560 ----a-w- c:\windows\system32\nvcompiler.dll
2011-02-23 07:27 . 2011-02-23 07:27 10920 ----a-w- c:\windows\system32\drivers\nvBridge.kmd
2011-02-23 07:27 . 2011-02-23 07:27 10468360 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2011-02-23 07:27 . 2010-04-03 21:55 1965672 ----a-w- c:\windows\system32\nvapi.dll
2011-02-23 07:27 . 2010-04-03 21:55 10079336 ----a-w- c:\windows\system32\nvd3dum.dll
2011-02-22 14:13 . 2011-04-05 19:55 288768 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-02-22 13:33 . 2011-04-05 19:55 1068544 ----a-w- c:\windows\system32\DWrite.dll
2011-02-22 13:33 . 2011-04-05 19:55 797696 ----a-w- c:\windows\system32\FntCache.dll
2011-02-18 16:36 . 2011-02-18 16:36 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2011-02-18 16:36 . 2011-02-18 16:36 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll
2011-05-01 11:20 . 2011-04-05 19:55 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2007-03-09 07:12 27648 --sha-w- c:\windows\System32\AVSredirect.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-04-18 17:25 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"NETGEARDigitalEntertainer"="c:\program files\NETGEAR\NETGEAR Digital Entertainer for Windows\receiver.exe" [2009-04-29 3498712]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2010-05-04 288048]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-05-06 2424192]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ThreatFire"="c:\program files\ThreatFire\TFTray.exe" [2010-01-14 378128]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2010-03-12 49208]
"Reader Library Launcher"="c:\program files\Sony\Reader\Data\bin\launcher\Reader Library Launcher.exe" [2010-07-13 906648]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-04-14 421160]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-04-18 3460784]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Secunia PSI Tray.lnk - c:\program files\Secunia\PSI\psi_tray.exe [2011-1-10 291896]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /r \??\n:\0autocheck autochk *\0autocheck lsdelete\0autocheck lsdelete\0autocheck lsdelete
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Audible Download Manager.lnk]
backup=c:\windows\pss\Audible Download Manager.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Vista Caller-ID.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Vista Caller-ID.lnk
backup=c:\windows\pss\Vista Caller-ID.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKLM\~\startupfolder\C:^Users^Derek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^BBC iPlayer Desktop.lnk]
backup=c:\windows\pss\BBC iPlayer Desktop.lnk.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^Derek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MagicDisc.lnk]
backup=c:\windows\pss\MagicDisc.lnk.Startup
backupExtension=.Startup
.
[HKLM\~\startupfolder\C:^Users^Derek^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Shrink Pic.lnk]
backup=c:\windows\pss\Shrink Pic.lnk.Startup
backupExtension=.Startup
path=c:\users\Derek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Shrink Pic.lnk
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-20 23:07 932288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-01-31 08:44 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2010-04-01 09:16 357696 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EADM]
2011-02-03 07:55 11509760 ----a-w- c:\program files\Electronic Arts\EADM\EADMUI\EADMUI.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-04-14 10:32 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 17:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-02-18 10:43 248040 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2011-04-05 19:28 273544 ----a-w- c:\program files\real\realplayer\Update\realsched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
2011-03-09 12:30 247728 ----a-w- c:\program files\TomTom HOME 2\TomTomHOMERunner.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
2010-03-09 02:52 15872 ----a-w- c:\program files\Unlocker\UnlockerAssistant.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2010-05-04 14:37 288048 ----a-w- c:\program files\uTorrent\uTorrent.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-19 07:38 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2008-01-19 07:33 202240 ----a-w- c:\program files\Windows Media Player\wmpnscfg.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-1968005606-1059869509-243170324-1000]
"EnableNotificationsRef"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-10-14 136176]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2011-05-02 2146496]
R2 Secunia Update Agent;Secunia Update Agent;c:\program files\Secunia\PSI\sua.exe [2011-01-10 399416]
R3 FXDrv32;FXDrv32;D:\FXDrv32.sys [x]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2010-10-14 136176]
R3 MobileAdapter;Mobile Adapter USB Modem and USB Serial;c:\windows\system32\DRIVERS\qscnusb.sys [2009-09-17 103552]
R3 PSI;PSI;c:\windows\system32\DRIVERS\psi_mf.sys [2010-09-01 15544]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R3 WsAudio_DeviceS(1);WsAudio_DeviceS(1);c:\windows\system32\drivers\WsAudio_DeviceS(1).sys [2009-10-13 25704]
R3 WsAudio_DeviceS(2);WsAudio_DeviceS(2);c:\windows\system32\drivers\WsAudio_DeviceS(2).sys [2009-10-13 25704]
R3 WsAudio_DeviceS(3);WsAudio_DeviceS(3);c:\windows\system32\drivers\WsAudio_DeviceS(3).sys [2009-10-13 25704]
R3 WsAudio_DeviceS(4);WsAudio_DeviceS(4);c:\windows\system32\drivers\WsAudio_DeviceS(4).sys [2009-10-13 25704]
R3 WsAudio_DeviceS(5);WsAudio_DeviceS(5);c:\windows\system32\drivers\WsAudio_DeviceS(5).sys [2009-10-13 25704]
R3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2008-01-19 16896]
R4 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-11-18 691696]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2011-04-29 64512]
S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-06-30 28552]
S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2010-01-14 51984]
S0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2010-01-14 59664]
S1 aswSnx;aswSnx; [x]
S1 aswSP;aswSP; [x]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-04-18 53592]
S2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-10-20 50704]
S2 recvrsvc.exe;NETGEAR Receiver Service;c:\program files\NETGEAR\NETGEAR Digital Entertainer for Windows\recvrsvc.exe [2009-04-29 172808]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 Secunia PSI Agent;Secunia PSI Agent;c:\program files\Secunia\PSI\PSIA.exe [2011-01-10 993848]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-07-09 248936]
S2 ThreatFire;ThreatFire;c:\program files\ThreatFire\TFService.exe service [x]
S2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [2011-03-09 92592]
S3 DKRtWrt;DKRtWrt;c:\windows\system32\DRIVERS\DKRtWrt.sys [2009-12-10 45616]
S3 imvad_multi;NETGEAR Digital Entertainer Virtual Audio Device;c:\windows\system32\drivers\imvad.sys [2007-04-26 17792]
S3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2010-01-14 33552]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - NORMANDY
*Deregistered* - Lavasoft Kernexplorer
*Deregistered* - Normandy
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2011-05-09 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2011-04-29 15:14]
.
2011-05-09 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2010-12-31 10:47]
.
2011-05-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-14 18:01]
.
2011-05-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-10-14 18:01]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.uk/
uInternet Settings,ProxyOverride = *.local
FF - ProfilePath - c:\users\Derek\AppData\Roaming\Mozilla\Firefox\Profiles\h7qq1gk5.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - user.js: browser.blink_allowed - true
FF - user.js: network.prefetch-next - true
FF - user.js: nglayout.initialpaint.delay - 50
FF - user.js: layout.spellcheckDefault - 1
FF - user.js: browser.search.openintab - false
FF - user.js: browser.tabs.closeButtons - 1
FF - user.js: browser.tabs.opentabfor.middleclick - true
FF - user.js: browser.tabs.tabMinWidth - 100
FF - user.js: yahoo.homepage.dontask - true
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-A Girl in the City 1.00 - c:\program files\Games\A Girl in the City\Uninstall.exe
AddRemove-Aladdin and the Wonderful Lamp The 1001 Nights Extended 1.00 - c:\program files\Games\Aladdin and the Wonderful Lamp The 1001 Nights Extended\Uninstall.exe
AddRemove-Allora and The Broken Portal 1.00 - c:\program files\Games\Allora and The Broken Portal\Uninstall.exe
AddRemove-Amanda Rose The Game of Time 1.00 - c:\program files\Games\Amanda Rose The Game of Time\Uninstall.exe
AddRemove-Amelies Cafe Holiday Spirit 1.00 - c:\program files\Games\Amelies Cafe Holiday Spirit\Uninstall.exe
AddRemove-Apparitions Kotsmine Hills 1.00 - c:\program files\Games\Apparitions Kotsmine Hills\Uninstall.exe
AddRemove-Art of Murder Cards of Destiny BFG 1.00 - c:\program files\Games\Art of Murder Cards of Destiny BFG\Uninstall.exe
AddRemove-Aspectus Rinascimento Chronicles 1.00 - c:\program files\Games\Aspectus Rinascimento Chronicles\Uninstall.exe
AddRemove-Avalon Legends Solitaire 1.00 - c:\program files\Games\Avalon Legends Solitaire\Uninstall.exe
AddRemove-Awakening 2 Moonfell Wood 1.00 - c:\program files\Games\Awakening 2 Moonfell Wood\Uninstall.exe
AddRemove-Awakening The Dreamless Castle 1.00 - c:\program files\Games\Awakening The Dreamless Castle\Uninstall.exe
AddRemove-Blood and Ruby New 1.00 - c:\program files\Games\Blood and Ruby New\Uninstall.exe
AddRemove-Cave Quest 1.00 - c:\program files\Games\Cave Quest\Uninstall.exe
AddRemove-Celtic Lore Sidhe Hills 1.00 - c:\program files\Games\Celtic Lore Sidhe Hills\Uninstall.exe
AddRemove-Christmas Wonderland 1.00 - c:\program files\Games\Christmas Wonderland\Uninstall.exe
AddRemove-Chronicles of Albian The Magic Convention 1.00 - c:\program files\Games\Chronicles of Albian The Magic Convention\Uninstall.exe
AddRemove-Chronicles of Mystery Secret of the Lost Kingdom 1.00 - c:\program files\Games\Chronicles of Mystery Secret of the Lost Kingdom\Uninstall.exe
AddRemove-Clutter 1.00 - c:\program files\Games\Clutter\Uninstall.exe
AddRemove-Conveyor Chaos 1.00 - c:\program files\Games\Conveyor Chaos\Uninstall.exe
AddRemove-Crazy Machines New from the Lab 1.00 - c:\program files\Games\Crazy Machines New from the Lab\Uninstall.exe
AddRemove-Crossworlds The Flying City 1.00 - c:\program files\Games\Crossworlds The Flying City\Uninstall.exe
AddRemove-Curse of the Ghost Ship 1.00 - c:\program files\Games\Curse of the Ghost Ship\Uninstall.exe
AddRemove-Dark Parables 2 The Exiled Prince Collectors Edition 1.00 - c:\program files\Games\Dark Parables 2 The Exiled Prince Collectors Edition\Uninstall.exe
AddRemove-Dark Ritual 1.00 - c:\program files\Games\Dark Ritual\Uninstall.exe
AddRemove-Drawn Dark Flight Regular Edition 1.00 - c:\program files\Games\Drawn Dark Flight Regular Edition\Uninstall.exe
AddRemove-Dream Chronicles The Book of Water Collectors Edition 1.00 - c:\program files\Games\Dream Chronicles The Book of Water Collectors Edition\Uninstall.exe
AddRemove-Dream Day 7 True Love 1.00 - c:\program files\Games\Dream Day 7 True Love\Uninstall.exe
AddRemove-Dream Mysteries Case of the Red Fox 1.00 - c:\program files\Games\Dream Mysteries Case of the Red Fox\Uninstall.exe
AddRemove-Dying for Daylight 1.00 - c:\program files\Games\Dying for Daylight\Uninstall.exe
AddRemove-Echoes of Sorrow 1.00 - c:\program files\Games\Echoes of Sorrow\Uninstall.exe
AddRemove-Elixir of Immortality 1.00 - c:\program files\Games\Elixir of Immortality\Uninstall.exe
AddRemove-Elves Inc.Christmas Mission 1.00 - c:\program files\Games\Elves Inc.Christmas Mission\Uninstall.exe
AddRemove-Emily Archer and the Curse of Tutankhamun 1.00 - c:\program files\Games\Emily Archer and the Curse of Tutankhamun\Uninstall.exe
AddRemove-Empress of the Deep 2 Song of the Blue Whale CE 1.00 - c:\program files\Games\Empress of the Deep 2 Song of the Blue Whale CE\Uninstall.exe
AddRemove-Epic Adventures Cursed Onboard 1.00 - c:\program files\Games\Epic Adventures Cursed Onboard\Uninstall.exe
AddRemove-Epic Escapes Dark Seas 1.00 - c:\program files\Games\Epic Escapes Dark Seas\Uninstall.exe
AddRemove-Fallen Shadows 1.00 - c:\program files\Games\Fallen Shadows\Uninstall.exe
AddRemove-Fishers Family Farm 1.00 - c:\program files\Games\Fishers Family Farm\Uninstall.exe
AddRemove-Gravely Silent House of Deadlock Collectors Edition 1.00 - c:\program files\Games\Gravely Silent House of Deadlock Collectors Edition\Uninstall.exe
AddRemove-Guardians of Magic Amandas Awakening 1.00 - c:\program files\Games\Guardians of Magic Amandas Awakening\Uninstall.exe
AddRemove-Hallowed Legends Samhain CE 1.00 - c:\program files\Games\Hallowed Legends Samhain CE\Uninstall.exe
AddRemove-Hexus 1.00 - c:\program files\Games\Hexus\Uninstall.exe
AddRemove-Hidden Mysteries Salem Secrets 1.00 - c:\program files\Games\Hidden Mysteries Salem Secrets\Uninstall.exe
AddRemove-Insider Tales The Stolen Venus 2 1.00 - c:\program files\Games\Insider Tales The Stolen Venus 2\Uninstall.exe
AddRemove-Jack of all Tribes 1.00 - c:\program files\Games\Jack of all Tribes\Uninstall.exe
AddRemove-Jane Lucky 1.00 - c:\program files\Games\Jane Lucky\Uninstall.exe
AddRemove-Jewel Quest Mysteries The Seventh Gate Collectors Edition 1.27 - c:\program files\Games\Jewel Quest Mysteries The Seventh Gate Collectors Edition\Uninstall.exe
AddRemove-Jewelry Secret Mystery Stones 1.00 - c:\program files\Games\Jewelry Secret Mystery Stones\Uninstall.exe
AddRemove-Kingdom of Seven Seals 1.00 - c:\program files\Games\Kingdom of Seven Seals\Uninstall.exe
AddRemove-Koi Solitaire 1.00 - c:\program files\Games\Koi Solitaire\Uninstall.exe
AddRemove-Maestro Music of Death Collectors Edition 1.00 - c:\program files\Games\Maestro Music of Death Collectors Edition\Uninstall.exe
AddRemove-Margrave The Curse of the Severed Heart CE 1.00 - c:\program files\Games\Margrave The Curse of the Severed Heart CE\Uninstall.exe
AddRemove-Master Thief Skyscraping Sting 1.00 - c:\program files\Games\Master Thief Skyscraping Sting\Uninstall.exe
AddRemove-Muse 1.00 - c:\program files\Games\Muse\Uninstall.exe
AddRemove-My Kingdom for the Princess 2 1.1 - c:\program files\Games\My Kingdom for the Princess 2\Uninstall.exe
AddRemove-Mystery Agency A Vampires Kiss 1.00 - c:\program files\Games\Mystery Agency A Vampires Kiss\Uninstall.exe
AddRemove-Mystery Agency Secrets of the Orient 1.00 - c:\program files\Games\Mystery Agency Secrets of the Orient\Uninstall.exe
AddRemove-Mystery Case Files 13th Skull Collectors Edition 1.00 - c:\program files\Games\Mystery Case Files 13th Skull Collectors Edition\Uninstall.exe
AddRemove-Mystery Novel 1.00 - c:\program files\Games\Mystery Novel\Uninstall.exe
AddRemove-Mystery Seekers The Secret of the Haunted Mansion 1.00 - c:\program files\Games\Mystery Seekers The Secret of the Haunted Mansion\Uninstall.exe
AddRemove-Nora Roberts Vision in White 1.00 - c:\program files\Games\Nora Roberts Vision in White\Uninstall.exe
AddRemove-Once Upon a Farm 1.00 - c:\program files\Games\Once Upon a Farm\Uninstall.exe
AddRemove-Our Worst Fears Stained Skin 1.00 - c:\program files\Games\Our Worst Fears Stained Skin\Uninstall.exe
AddRemove-PuppetShow Lost Town CE 1.00 - c:\program files\Games\PuppetShow Lost Town CE\Uninstall.exe
AddRemove-Rare Treasures Dinnerware Trading Company BFG 1.00 - c:\program files\Games\Rare Treasures Dinnerware Trading Company BFG\Uninstall.exe
AddRemove-Reading the Dead 1.00 - c:\program files\Games\Reading the Dead\Uninstall.exe
AddRemove-Relics of Fate A Penny Macey Mystery 1.00 - c:\program files\Games\Relics of Fate A Penny Macey Mystery\Uninstall.exe
AddRemove-Robins Island Adventure 1.00 - c:\program files\Games\Robins Island Adventure\Uninstall.exe
AddRemove-Royal Challenge Solitaire 1.00 - c:\program files\Games\Royal Challenge Solitaire\Uninstall.exe
AddRemove-Secret Missions Mata Hari and the Kaisers Submarines 1.00 - c:\program files\Games\Secret Missions Mata Hari and the Kaisers Submarines\Uninstall.exe
AddRemove-Serpent of Isis Your Journey Continues 1.00 - c:\program files\Games\Serpent of Isis Your Journey Continues\Uninstall.exe
AddRemove-Shades of Death Royal Blood 1.00 - c:\program files\Games\Shades of Death Royal Blood\Uninstall.exe
AddRemove-Shiver Vanishing Hitchhiker Collectors Edition 1.00 - c:\program files\Games\Shiver Vanishing Hitchhiker Collectors Edition\Uninstall.exe
AddRemove-Silent Scream The Dancer 1.00 - c:\program files\Games\Silent Scream The Dancer\Uninstall.exe
AddRemove-Soul Journey 1.00 - c:\program files\Games\Soul Journey\Uninstall.exe
AddRemove-Strange Cases The Lighthouse Mystery Collectors Edition 1.00 - c:\program files\Games\Strange Cases The Lighthouse Mystery Collectors Edition\Uninstall.exe
AddRemove-Stray Souls Dollhouse Story Collectors Edition 1.00 - c:\program files\Games\Stray Souls Dollhouse Story Collectors Edition\Uninstall.exe
AddRemove-Tamara the 13th 1.00 - c:\program files\Games\Tamara the 13th\Uninstall.exe
AddRemove-The Agency of Anomalies Mystic Hospital Collectors Edition 1.00 - c:\program files\Games\The Agency of Anomalies Mystic Hospital Collectors Edition\Uninstall.exe
AddRemove-The Curse of the Ring 1.00 - c:\program files\Games\The Curse of the Ring\Uninstall.exe
AddRemove-The Dragon Dance 1.00 - c:\program files\Games\The Dragon Dance\Uninstall.exe
AddRemove-The Joy of Farming 1.00 - c:\program files\Games\The Joy of Farming\Uninstall.exe
AddRemove-The Revenge 1.00 - c:\program files\Games\The Revenge\Uninstall.exe
AddRemove-The Secret Legacy A Kate Brooks Adventure 1.00 - c:\program files\Games\The Secret Legacy A Kate Brooks Adventure\Uninstall.exe
AddRemove-The Tale of The Lost Bride and A Hidden Treasure 1.00 - c:\program files\Games\The Tale of The Lost Bride and A Hidden Treasure\Uninstall.exe
AddRemove-Time to Hurry Nicoles Story 1.00 - c:\program files\Games\Time to Hurry Nicoles Story\Uninstall.exe
AddRemove-Treasure Hunters 1.00 - c:\program files\Games\Treasure Hunters\Uninstall.exe
AddRemove-Virtual Villagers The Lost Children 1.00 - c:\program files\Games\Virtual Villagers The Lost Children\Uninstall.exe
AddRemove-Wild West Story The Beginning 1.00 - c:\program files\Games\Wild West Story The Beginning\Uninstall.exe
AddRemove-Youda Survivor 2 1.00 - c:\program files\Games\Youda Survivor 2\Uninstall.exe
AddRemove-Yucatan 1.00 - c:\program files\Games\Yucatan\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-05-09 20:04
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
.
C:\## aswSnx private storage
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet006\Services\ThreatFire]
"AlternateImagePath"=""
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1968005606-1059869509-243170324-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet006\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet006\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(772)
c:\program files\ThreatFire\TFWAH.dll
.
- - - - - - - > 'lsass.exe'(680)
c:\program files\ThreatFire\TFWAH.dll
.
- - - - - - - > 'Explorer.exe'(5820)
c:\program files\ThreatFire\TfWah.dll
c:\windows\system32\msi.dll
c:\windows\system32\EhStorShell.dll
c:\windows\system32\ACTXPRXY.DLL
c:\windows\system32\msiltcfg.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\BatMeter.dll
c:\windows\system32\FunDisc.dll
c:\windows\System32\msxml3.dll
c:\windows\system32\wscntfy.dll
.
Completion time: 2011-05-09 20:15:12
ComboFix-quarantined-files.txt 2011-05-09 19:15
ComboFix2.txt 2011-05-04 19:38
ComboFix3.txt 2011-05-02 19:38
ComboFix4.txt 2010-10-24 02:18
.
Pre-Run: 57,165,828,096 bytes free
Post-Run: 57,128,050,688 bytes free
.
Current=6 Default=6 Failed=1 LastKnownGood=5 Sets=1,3,5,6
- - End Of File - - F2F444CA6CBAD88ABE40A1D95CD8E2A7