Things look much better. The System Fix program is gone, no pop-ups, and the Start Menu is back.
ComboFix 11-12-04.02 - Greg 12/04/2011 8:26.5.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1399 [GMT -5:00]
Running from: c:\documents and settings\Greg\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Greg\Application Data\Microsoft\Internet Explorer\Quick Launch\System Fix.lnk
c:\documents and settings\Greg\Start Menu\Programs\System Fix
c:\documents and settings\Greg\Start Menu\Programs\System Fix\System Fix.lnk
c:\documents and settings\Greg\Start Menu\Programs\System Fix\Uninstall System Fix.lnk
c:\documents and settings\NetworkService\Start Menu\Programs\Shop to Win 11
c:\documents and settings\NetworkService\Start Menu\Programs\Shop to Win 11\Check out Previous Winners.lnk
c:\documents and settings\NetworkService\Start Menu\Programs\Shop to Win 11\Frequently Asked Questions.lnk
c:\documents and settings\NetworkService\Start Menu\Programs\Shop to Win 11\How can I win $100,000.lnk
c:\documents and settings\NetworkService\Start Menu\Programs\Shop to Win 11\How can I win $500 Today.lnk
c:\documents and settings\NetworkService\Start Menu\Programs\Shop to Win 11\Shop To Win Privacy Policy.lnk
c:\documents and settings\NetworkService\Start Menu\Programs\Shop to Win 11\Shop to Win Terms and Conditions.lnk
c:\documents and settings\NetworkService\Start Menu\Programs\Shop to Win 11\Sweepstakes Official Rules.lnk
c:\documents and settings\NetworkService\Start Menu\Programs\Shop to Win 11\Uninstall.lnk
c:\documents and settings\NetworkService\Start Menu\Programs\Shop to Win 11\View My Shop to Win Account.lnk
c:\documents and settings\NetworkService\Start Menu\Programs\Shop to Win 11\Visit the Shop to Win Mall.lnk
c:\program files\Shop to Win 11
c:\program files\Shop to Win 11\%APPDATA%\FCSB000063127\Toolbar\patch.bat
c:\program files\Shop to Win 11\%APPDATA%\FCSB000063127\Toolbar\settings.xml
c:\program files\Shop to Win 11\%APPDATA%\FCSB000063127\Toolbar\ShoppingBHO.dll
c:\program files\Shop to Win 11\%APPDATA%\FCSB000063127\Toolbar\ShopToWin.ico
c:\program files\Shop to Win 11\%APPDATA%\FCSB000063127\Toolbar\Uninst.exe
c:\program files\Shop to Win 11\%APPDATA%\FCSB000063127\Toolbar\version.txt
c:\windows\CSC\d6
c:\windows\system32\usmt\migwiz_a.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-11-04 to 2011-12-04 )))))))))))))))))))))))))))))))
.
.
2011-11-25 17:12 . 2011-11-25 20:52 -------- d-----w- c:\documents and settings\Greg\Application Data\Tether
2011-11-25 17:09 . 2009-01-09 21:18 27136 ----a-r- c:\windows\system32\drivers\RimSerial.sys
2011-11-25 17:09 . 2011-11-25 17:09 -------- d-----w- c:\program files\Common Files\Research In Motion
2011-11-25 17:09 . 2011-11-25 17:09 -------- d-----w- c:\program files\Research In Motion
2011-11-25 17:08 . 2010-11-17 20:53 45608 ----a-w- c:\windows\system32\drivers\qrkis.sys
2011-11-25 17:08 . 2011-11-25 17:08 -------- d-----w- c:\program files\Tether
2011-11-16 20:54 . 2011-11-16 20:54 -------- d-----w- c:\windows\Internet Logs
2011-11-16 20:53 . 2011-11-16 20:53 -------- d-----w- c:\program files\Common Files\Deterministic Networks
2011-11-16 20:53 . 2011-11-16 20:53 -------- d-----w- c:\program files\Cisco Systems
2011-11-10 00:46 . 2011-11-18 04:14 -------- d-----w- c:\documents and settings\Greg\Local Settings\Application Data\Akamai
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-10 14:22 . 2010-04-18 07:07 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-10-03 18:13 . 2010-04-18 07:33 499712 ----a-w- c:\windows\system32\msvcp71.dll
2011-10-03 18:13 . 2010-04-18 07:33 348160 ----a-w- c:\windows\system32\msvcr71.dll
2011-09-28 07:06 . 2004-08-04 10:00 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41 . 2011-09-26 15:41 611328 ------w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41 . 2004-08-04 10:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41 . 2004-08-04 10:00 20480 ----a-w- c:\windows\system32\oleaccrc.dll
2011-09-06 13:20 . 2004-08-04 10:00 1858944 ----a-w- c:\windows\system32\win32k.sys
2010-03-11 04:01 . 2010-03-11 04:01 124272 ----a-w- c:\program files\mozilla firefox\plugins\CCMSDK.dll
2010-03-11 04:40 . 2010-03-11 04:40 13168 ----a-w- c:\program files\mozilla firefox\plugins\cgpcfg.dll
2010-03-11 04:02 . 2010-03-11 04:02 70512 ----a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll
2010-03-11 04:01 . 2010-03-11 04:01 91504 ----a-w- c:\program files\mozilla firefox\plugins\confmgr.dll
2010-03-11 04:01 . 2010-03-11 04:01 22384 ----a-w- c:\program files\mozilla firefox\plugins\ctxlogging.dll
2010-03-11 04:00 . 2010-03-11 04:00 255344 ----a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll
2010-03-11 04:01 . 2010-03-11 04:01 31088 ----a-w- c:\program files\mozilla firefox\plugins\icafile.dll
2010-03-11 04:01 . 2010-03-11 04:01 40304 ----a-w- c:\program files\mozilla firefox\plugins\icalogon.dll
2009-10-05 17:49 . 2009-10-05 17:49 652640 ----a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2010-03-11 04:02 . 2010-03-11 04:02 23920 ----a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-07-04 11:43 122512 ----a-w- c:\program files\Alwil Software\Avast5\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Akamai NetSession Interface"="c:\documents and settings\Greg\Local Settings\Application Data\Akamai\netsession_win.exe" [2011-11-17 3303000]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-10-24 2220032]
"ConnectionCenter"="c:\program files\Citrix\ICA Client\concentr.exe" [2010-03-11 300400]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-06-09 13537280]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-19 421888]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-07-07 1047656]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2010-4-18 50688]
VPN Client.lnk - c:\windows\Installer\{1CE60928-8325-49A8-8B06-633E48DD2B67}\Icon3E5562ED7.ico [2011-11-16 6144]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Documents and Settings\\Greg\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Documents and Settings\\Greg\\Local Settings\\Application Data\\Akamai\\netsession_win.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1040:TCP"= 1040:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [4/16/2011 9:05 PM 441176]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [4/18/2010 2:17 AM 309848]
R1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\drivers\ctxusbm.sys [10/5/2009 9:08 AM 65584]
R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [8/4/2004 5:00 AM 14336]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4/18/2010 2:17 AM 19544]
R2 NIHardwareService;NIHardwareService;c:\program files\Common Files\Native Instruments\Hardware\NIHardwareService.exe [3/9/2011 6:08 AM 3857408]
R2 regi;regi;c:\windows\system32\drivers\regi.sys [4/17/2007 7:09 PM 11032]
R2 Tether;Tether;c:\program files\Tether\TBService.exe [11/25/2011 12:08 PM 50416]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [4/18/2010 2:20 AM 41272]
S3 NWUSBCDFIL;Novatel Wireless Installation CD;c:\windows\system32\drivers\NwUsbCdFil.sys [7/8/2010 9:52 AM 20480]
S3 NWUSBModem_000;Novatel Wireless USB Modem Driver (vGEN);c:\windows\system32\drivers\nwusbmdm_000.sys [7/8/2010 9:52 AM 176384]
S3 NWUSBPort_000;Novatel Wireless USB Status Port Driver (vGEN);c:\windows\system32\drivers\nwusbser_000.sys [7/8/2010 9:52 AM 176384]
S3 NWUSBPort2_000;Novatel Wireless USB Status2 Port Driver (vGEN);c:\windows\system32\drivers\nwusbser2_000.sys [7/8/2010 9:52 AM 176384]
S3 qrkis;Tether Miniport;c:\windows\system32\drivers\qrkis.sys [11/25/2011 12:08 PM 45608]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - 00209930
*Deregistered* - 00209930
*Deregistered* - pwdorkob
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder
.
2011-08-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 15:50]
.
2011-12-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-1614895754-725345543-1003Core.job
- c:\documents and settings\Greg\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-08-22 16:30]
.
2011-12-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1960408961-1614895754-725345543-1003UA.job
- c:\documents and settings\Greg\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-08-22 16:30]
.
2011-12-02 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2010-04-18 02:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: ed.gov\fpass
Trusted Zone: ed.gov\www.fpass
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{66C08B5E-5281-421F-9E88-7DC42551C6A0}: NameServer = 208.67.222.222,208.67.220.220
DPF: vzTCPConfig - hxxp://my.verizon.com/micro/speedoptimizer/fios/vzTCPConfig.CAB
FF - ProfilePath - c:\documents and settings\Greg\Application Data\Mozilla\Firefox\Profiles\hig1dv12.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - user.js: network.protocol-handler.warn-external.dnupdate - false
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-12-04 08:40
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Akamai]
"ServiceDll"="c:\program files\common files\akamai/netsession_win_d768ebc.dll"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(1032)
c:\windows\System32\BCMLogon.dll
.
Completion time: 2011-12-04 08:46:16
ComboFix-quarantined-files.txt 2011-12-04 13:46
.
Pre-Run: 155,430,850,560 bytes free
Post-Run: 155,420,520,448 bytes free
.
- - End Of File - - 8F4CB6AC7311C0D23B6DBCE11E1F2FE2