OK! Here's the ComboFix log file. Will wait for further instructions and won't touch the laptop for now.
ComboFix 09-11-17.03 - Joan Fletc 11/17/2009 10:39.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1015.628 [GMT -5:00]
Running from: c:\documents and settings\Joan Fletc\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Spyware Doctor with AntiVirus *On-access scanning enabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Downloaded Program Files\popcaploader.dll
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\system32\_004753_.tmp.dll
c:\windows\system32\_004754_.tmp.dll
c:\windows\system32\_004755_.tmp.dll
c:\windows\system32\_004756_.tmp.dll
c:\windows\system32\_004763_.tmp.dll
c:\windows\system32\_004764_.tmp.dll
c:\windows\system32\_004765_.tmp.dll
c:\windows\system32\_004766_.tmp.dll
c:\windows\system32\mssfc.dll
c:\windows\system32\sfcfiles.dat
c:\windows\system32\tdlwsp.dll
C:\xcrashdump.dat
Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it
.
((((((((((((((((((((((((( Files Created from 2009-10-17 to 2009-11-17 )))))))))))))))))))))))))))))))
.
2009-11-10 18:32 . 2009-11-10 18:32 34816 ----a-w- c:\windows\system32\drivers\rootrepeal.sys
2009-11-10 16:26 . 2009-10-08 16:31 149456 ----a-w- c:\windows\SGDetectionTool.dll
2009-11-10 16:26 . 2009-10-08 16:31 767952 ----a-w- c:\windows\BDTSupport.dll
2009-11-10 16:26 . 2008-11-26 17:08 131 ----a-w- c:\windows\IDB.zip
2009-11-10 16:26 . 2009-10-08 16:31 165840 ----a-w- c:\windows\PCTBDRes.dll
2009-11-10 16:26 . 2009-10-08 16:31 1636304 ----a-w- c:\windows\PCTBDCore.dll
2009-11-10 16:26 . 2009-10-02 19:19 1152470 ----a-w- c:\windows\UDB.zip
2009-11-10 16:21 . 2009-09-24 13:55 229304 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-11-10 16:21 . 2009-10-06 21:31 87784 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-11-10 16:21 . 2009-09-23 21:10 207280 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-11-10 16:20 . 2009-09-03 14:45 70408 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2009-11-10 16:20 . 2009-11-10 16:26 -------- d-----w- c:\program files\Common Files\PC Tools
2009-11-10 16:20 . 2009-11-10 16:20 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2009-11-10 16:20 . 2009-11-17 15:31 -------- d-----w- c:\program files\Spyware Doctor
2009-11-10 16:20 . 2009-11-10 16:20 -------- d-----w- c:\documents and settings\Joan Fletc\Application Data\PC Tools
2009-11-10 15:58 . 2009-11-10 15:58 -------- d-----w- c:\documents and settings\Joan Fletc\Local Settings\Application Data\Threat Expert
2009-11-06 14:32 . 2009-10-20 18:05 2064152 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-11-01 13:16 . 2009-11-10 23:07 -------- d-----w- c:\documents and settings\All Users\Application Data\SITEguard
2009-11-01 13:14 . 2009-11-01 13:15 -------- d-----w- c:\program files\STOPzilla!
2009-11-01 13:14 . 2009-11-17 15:28 -------- d-----w- c:\documents and settings\All Users\Application Data\STOPzilla!
2009-11-01 13:14 . 2009-11-01 13:14 -------- d-----w- c:\program files\Common Files\iS3
2009-10-29 19:33 . 2009-10-29 19:33 17217008 ----a-w- c:\documents and settings\Joan Fletc\Application Data\Real\Update\setup\rp\RealPlayerSPGold.exe
2009-10-29 15:46 . 2009-10-29 15:46 -------- d-----w- c:\documents and settings\All Users\Application Data\F-Secure
2009-10-29 13:10 . 2004-08-04 12:00 15360 ----a-w- c:\windows\Copy of TASKMAN.EXE
2009-10-29 12:38 . 2009-10-29 17:39 -------- d-----w- c:\program files\seweke
2009-10-27 16:08 . 2009-10-27 16:08 545424 ----a-r- c:\windows\system32\SZComp5.dll
2009-10-27 16:08 . 2009-10-27 16:08 402064 ----a-r- c:\windows\system32\SZBase5.dll
2009-10-27 15:59 . 2009-10-27 15:59 17408 ----a-r- c:\windows\system32\SZIO5.dll
2009-10-20 19:40 . 2009-10-20 19:40 126976 ----a-r- c:\windows\system32\IS3HTUI5.dll
2009-10-20 19:40 . 2009-10-20 19:40 393216 ----a-r- c:\windows\system32\IS3DBA5.dll
2009-10-20 19:38 . 2009-10-20 19:38 385024 ----a-r- c:\windows\system32\IS3UI5.dll
2009-10-20 19:37 . 2009-10-20 19:37 61440 ----a-r- c:\windows\system32\IS3Hks5.dll
2009-10-20 19:37 . 2009-10-20 19:37 23040 ----a-r- c:\windows\system32\IS3XDat5.dll
2009-10-20 19:35 . 2009-10-20 19:35 225280 ----a-r- c:\windows\system32\IS3Win325.dll
2009-10-20 19:35 . 2009-10-20 19:35 94208 ----a-r- c:\windows\system32\IS3Inet5.dll
2009-10-20 19:35 . 2009-10-20 19:35 90112 ----a-r- c:\windows\system32\IS3Svc5.dll
2009-10-20 19:31 . 2009-10-20 19:31 729088 ----a-r- c:\windows\system32\IS3Base5.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-17 15:53 . 2008-06-07 14:29 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-11-17 14:24 . 2007-07-17 22:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-10-29 16:30 . 2008-08-26 19:26 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-23 11:55 . 2008-05-26 15:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-10-23 11:53 . 2008-05-26 15:25 -------- d-----w- c:\documents and settings\Joan Fletc\Application Data\skypePM
2009-10-22 11:44 . 2008-12-04 00:03 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-10-14 13:40 . 2007-09-14 02:46 -------- d-----w- c:\program files\Verizon
2009-10-11 22:22 . 2008-10-04 14:43 4045528 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-09-29 22:35 . 2009-09-29 22:35 64000 ----a-w- c:\documents and settings\Joan Fletc\Application Data\Real\Update\setup\RUP\inst_config\gcapi_dll.dll
2009-09-29 22:35 . 2009-09-29 22:35 52288 ----a-w- c:\documents and settings\Joan Fletc\Application Data\Real\Update\setup\RUP\inst_config\gtapi.dll
2009-09-29 22:35 . 2009-09-29 22:35 50688 ----a-w- c:\documents and settings\Joan Fletc\Application Data\Real\Update\setup\RUP\inst_config\fftbapi.dll
2009-09-29 22:35 . 2009-09-29 22:35 114688 ----a-w- c:\documents and settings\Joan Fletc\Application Data\Real\Update\setup\RUP\inst_config\compat.dll
2009-09-25 18:06 . 2009-09-18 20:30 -------- d-----w- c:\program files\PopCap Games
2009-09-25 18:05 . 2009-09-25 17:16 22 ----a-w- c:\windows\popcinfot.dat
2009-09-25 17:15 . 2009-09-25 17:15 -------- d-----w- c:\documents and settings\All Users\Application Data\PopCap Games
2009-09-25 05:37 . 2004-08-04 12:00 667136 ----a-w- c:\windows\system32\wininet.dll
2009-09-25 05:37 . 2004-08-04 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-09-23 13:07 . 2009-04-19 12:25 -------- d-----w- c:\program files\Cruise Shark
2009-09-15 15:06 . 2009-09-15 15:06 8406648 ----a-w- c:\documents and settings\Joan Fletc\Application Data\Real\Update\setup\gtb_us\GOOGLE_TOOLBAR\GoogleToolbarInstaller.exe
2009-09-15 15:05 . 2009-09-15 15:05 10309448 ----a-w- c:\documents and settings\Joan Fletc\Application Data\Real\Update\setup\chr\ChromeInstaller.exe
2009-09-11 14:18 . 2009-03-30 22:23 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-10 18:54 . 2008-08-26 19:26 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 18:53 . 2008-08-26 19:26 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-10 14:37 . 2009-09-10 14:37 488968 ----a-w- c:\documents and settings\Joan Fletc\Application Data\Real\Update\setup\setup.exe
2009-09-04 21:03 . 2004-08-04 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-26 08:00 . 2004-08-04 12:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-22 14:00 . 2008-12-04 00:04 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-22 14:00 . 2008-12-04 00:04 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-22 14:00 . 2007-07-16 20:19 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2008-08-07 02:18 . 2008-08-07 02:18 122880 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
------- Sigcheck -------
[7] 2008-04-14 . 9DD07AF82244867CA36681EA2D29CE79 . 1614848 . . [5.1.2600.5512] . . c:\windows\ServicePackFiles\i386\sfcfiles.dll
[7] 2004-08-04 . 30A609E00BD1D4FFC49D6B5A432BE7F2 . 1580544 . . [5.1.2600.2180] . . c:\windows\$NtServicePackUninstall$\sfcfiles.dll
c:\windows\system32\sfcfiles.dll ... is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-17 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-08-02 802816]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-06-08 94208]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-06-08 77824]
"Persistence"="c:\windows\system32\igfxpers.exe" [2005-06-08 114688]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-07-27 1388544]
"THotkey"="c:\program files\Toshiba\Toshiba Applet\thotkey.exe" [2004-12-14 368640]
"Verizon_McciTrayApp"="c:\program files\Verizon\McciTrayApp.exe" [2009-03-10 1553920]
"MBBalloon"="c:\program files\HOTALBUMMyBOX\MBBalloon.exe" [2007-02-09 789120]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-11-03 2028312]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\agrsmmsg.exe [2005-04-12 88358]
c:\documents and settings\Joan Fletc\Start Menu\Programs\Startup\
DING!.lnk - c:\program files\Southwest Airlines\Ding\Ding.exe [2006-6-22 462848]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Cruise Shark.lnk - c:\program files\Cruise Shark\CruiseShark.exe [2009-5-14 274944]
MediaChecker.lnk - c:\program files\HOTALBUMMyBOX\MediaChecker.exe [2007-2-13 915096]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-22 14:00 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [11/10/2009 11:21 AM 207280]
R0 PzWDM;PzWDM;c:\windows\system32\drivers\PzWDM.sys [10/7/2007 7:31 AM 15172]
R0 szkg5;szkg5;c:\windows\system32\drivers\SZKG.sys [5/12/2009 2:13 PM 61328]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [12/3/2008 7:04 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [12/3/2008 7:04 PM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [12/3/2008 7:03 PM 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [12/3/2008 7:03 PM 297752]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\Spyware Doctor\BDT\BDTUpdateService.exe [11/10/2009 11:26 AM 112592]
R2 Viewpoint Service;Viewpoint Service;c:\program files\Viewpoint\Common\ViewpointService.exe [6/30/2008 11:13 PM 30152]
S0 is3srv;is3srv;c:\windows\system32\drivers\is3srv.sys [5/12/2009 2:13 PM 61328]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [7/17/2007 5:05 PM 29744]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [11/10/2009 11:20 AM 358600]
--- Other Services/Drivers In Memory ---
*Deregistered* - mbr
.
Contents of the 'Scheduled Tasks' folder
2009-11-17 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-07-17 22:15]
.
.
------- Supplementary Scan -------
.
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: {{0362b485-11fe-469c-ae98-42f478e581a0} - c:\program files\Yapta\YaptaSettings.exe
IE: {{0094A600-9BDD-4019-BAFE-487284F7D476} - {C3C07AD6-ACE9-43EE-A2AF-45BC13F6275F} - c:\program files\Yapta\YaptaSidebar.dll
LSP: c:\program files\Common Files\iS3\Anti-Spyware\iS3lsp.dll
DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} - hxxp://www.shockwave.com/content/goldrush/sis/gamehouseplayer.cab
DPF: {E41BA393-9078-424E-9554-9DB5126F5F4C} - hxxp://www.shockwave.com/content/dreamchronicles2/sis/dream2web.1.0.0.13.cab
FF - ProfilePath - c:\documents and settings\Joan Fletc\Application Data\Mozilla\Firefox\Profiles\xugrv0f2.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - component: c:\documents and settings\All Users\Application Data\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
FF - component: c:\documents and settings\All Users\Application Data\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c}\components\metricsloader.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
FF - plugin: c:\program files\Picasa2\npPicasa2.dll
FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint_.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
BHO-{7D962AFF-680D-483A-8D04-6B1ACDDF00E8} - (no file)
Toolbar-SITEguard - (no file)
SharedTaskScheduler-{2b5b5c9d-000a-4fb0-aec6-826b3cffbcaa} - (no file)
SSODL-wojuferig-{2b5b5c9d-000a-4fb0-aec6-826b3cffbcaa} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-11-17 10:54
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(968)
c:\program files\Common Files\iS3\Anti-Spyware\iS3lsp.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\program files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
c:\windows\system32\wdfmgr.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
c:\program files\Intel\Wireless\Bin\Dot1XCfg.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
.
**************************************************************************
.
Completion time: 2009-11-17 11:05 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-17 16:05
Pre-Run: 77,460,717,568 bytes free
Post-Run: 79,200,645,120 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
Current=4 Default=4 Failed=3 LastKnownGood=5 Sets=1,2,3,4,5
- - End Of File - - 99CF1FCBBAA0A8A926D0154BB3814E20