Here is the Combofix log...also attached it.
ComboFix 09-10-04.01 - Chris 10/05/2009 21:14.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.502.211 [GMT -4:00]
Running from: c:\documents and settings\Chris\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\Installer\eb4a287.msp
----- BITS: Possible infected sites -----
hxxp://knowledgeadventure.cachefly.net
Infected copy of c:\windows\system32\drivers\atapi.sys was found and disinfected
Kitty ate it
.
((((((((((((((((((((((((( Files Created from 2009-09-06 to 2009-10-06 )))))))))))))))))))))))))))))))
.
2009-10-05 17:50 . 2009-10-05 17:56 -------- d-----w- C:\fixwareout
2009-10-05 16:24 . 2009-10-05 16:24 -------- d-----w- c:\program files\CCleaner
2009-10-05 13:01 . 2009-10-05 13:01 160272 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2009-10-05 02:52 . 2009-10-05 02:52 -------- d-----w- c:\documents and settings\Chris\Application Data\Malwarebytes
2009-10-05 02:52 . 2009-09-10 18:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-05 02:52 . 2009-10-05 02:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-10-05 02:52 . 2009-09-10 18:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-05 02:52 . 2009-10-05 02:52 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-05 01:56 . 2009-10-05 01:56 -------- d-----w- c:\program files\Trend Micro
2009-10-05 01:47 . 2009-07-03 14:49 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-10-05 01:47 . 2009-10-05 01:47 -------- dc----w- c:\windows\system32\DRVSTORE
2009-10-05 01:34 . 2009-10-05 01:34 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864}
2009-10-05 01:33 . 2009-10-05 01:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-10-05 01:33 . 2009-10-05 01:33 -------- d-----w- c:\program files\Lavasoft
2009-10-04 03:46 . 2009-10-04 03:46 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-09-27 17:50 . 2000-06-20 18:42 6736 ----a-w- c:\windows\system32\WINGDIB.DRV
2009-09-27 17:50 . 2000-06-20 18:42 188960 ----a-w- c:\windows\system32\WINGDE.DLL
2009-09-27 17:50 . 2000-06-20 18:42 92208 ----a-w- c:\windows\system32\WING.DLL
2009-09-27 17:50 . 2000-06-20 18:42 12800 ----a-w- c:\windows\system32\WING32.DLL
2009-09-24 03:05 . 2009-09-24 03:06 -------- d-----w- c:\documents and settings\Chris\Application Data\Trillian
2009-09-24 02:58 . 2009-09-24 03:05 -------- d-----w- c:\program files\Trillian
2009-09-16 00:45 . 2009-09-16 00:45 -------- d-----w- c:\documents and settings\Chris\Local Settings\Application Data\Apple Computer
2009-09-12 17:51 . 2009-09-12 17:51 -------- d-----w- c:\documents and settings\Blake\Local Settings\Application Data\Mozilla
2009-09-12 16:05 . 2009-09-12 16:05 -------- d-sh--w- c:\documents and settings\Blake\PrivacIE
2009-09-12 16:05 . 2009-09-27 17:47 -------- d-----w- c:\program files\LEGO Media
2009-09-12 16:05 . 1996-11-05 20:13 299008 ----a-w- c:\windows\uninst.exe
2009-09-12 16:04 . 2009-09-12 16:04 -------- d-----w- c:\documents and settings\Blake\WINDOWS
2009-09-12 15:48 . 2009-09-12 15:48 -------- d-----w- c:\documents and settings\Blake\Local Settings\Application Data\HP
2009-09-12 15:48 . 2009-09-12 15:48 88800 ----a-w- c:\documents and settings\Blake\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-12 15:47 . 2009-09-12 15:47 -------- d-----w- c:\documents and settings\Blake\Application Data\InstallShield
2009-09-12 15:47 . 2009-09-12 15:47 -------- d-sh--w- c:\documents and settings\Blake\IETldCache
2009-09-11 23:38 . 2009-09-11 23:38 -------- d-----w- c:\program files\Common Files\Sonic Shared
2009-09-11 23:38 . 2009-09-11 23:39 -------- d-----w- c:\program files\Roxio
2009-09-11 03:02 . 2009-09-11 03:02 -------- d-sh--w- c:\documents and settings\Chris\IECompatCache
2009-09-11 02:58 . 2009-09-11 03:06 -------- d-----w- c:\documents and settings\Chris\Application Data\CamfrogWEB
2009-09-11 02:57 . 2009-09-11 02:57 -------- d-----w- c:\program files\CFWebAdvancedU
2009-09-09 03:16 . 2009-09-09 03:16 -------- d-----w- c:\program files\DVD Decrypter
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-04 04:28 . 2009-08-06 05:17 -------- d-----w- c:\program files\ThinkVantage
2009-10-04 04:28 . 2009-08-06 05:05 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-01 11:26 . 2009-08-14 03:42 89184 ----a-w- c:\documents and settings\Chris\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-30 21:22 . 2009-08-16 21:52 89184 ----a-w- c:\documents and settings\Cheryl\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-25 02:46 . 2009-08-14 02:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-09-12 15:48 . 2009-08-08 23:08 128 ----a-w- c:\documents and settings\Blake\Local Settings\Application Data\fusioncache.dat
2009-09-12 11:54 . 2009-08-30 11:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Knowledge Adventure
2009-09-12 05:50 . 2009-08-15 01:05 256 ----a-w- c:\windows\system32\pool.bin
2009-09-11 23:41 . 2009-08-14 23:23 -------- d-----w- c:\program files\Common Files\Roxio Shared
2009-09-11 23:38 . 2009-08-14 23:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Roxio
2009-09-11 23:20 . 2009-08-14 23:15 -------- d-----w- c:\program files\Common Files\Research In Motion
2009-08-30 12:06 . 2009-08-30 12:05 -------- d-----w- c:\program files\QuickTime
2009-08-30 12:04 . 2009-08-30 12:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-08-30 11:56 . 2009-08-30 11:53 -------- d-----w- c:\program files\JumpStart World
2009-08-30 11:53 . 2009-08-30 11:53 -------- d-----w- c:\program files\Common Files\Knowledge Adventure
2009-08-25 00:51 . 2009-08-25 00:51 -------- d-----w- c:\documents and settings\Chris\Application Data\InterVideo
2009-08-18 23:22 . 2009-08-15 04:20 68999 ----a-w- c:\windows\hpoins05.dat
2009-08-18 23:21 . 2009-08-18 23:21 -------- d-----w- c:\documents and settings\Chris\Application Data\AdobeUM
2009-08-17 02:32 . 2009-08-17 02:32 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-17 02:32 . 2009-08-17 02:32 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-08-17 02:32 . 2009-08-17 02:32 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-17 02:32 . 2009-08-17 02:32 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-17 02:31 . 2009-08-17 02:31 -------- d-----w- c:\program files\AVG
2009-08-17 02:31 . 2009-08-17 02:31 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-08-17 01:38 . 2009-08-17 01:38 -------- d-----w- c:\documents and settings\Chris\Application Data\AVG8
2009-08-17 01:36 . 2009-08-06 05:05 -------- d-----w- c:\program files\ThinkPad
2009-08-16 23:44 . 2009-08-06 05:21 -------- d-----w- c:\program files\IBM ThinkVantage
2009-08-16 23:15 . 2009-08-12 23:27 -------- d-----w- c:\program files\OpenOffice.org 3
2009-08-16 23:04 . 2009-08-16 23:04 -------- d-----w- c:\documents and settings\Chris\Application Data\InstallShield
2009-08-16 21:51 . 2009-08-06 23:47 129 ----a-w- c:\documents and settings\Cheryl\Local Settings\Application Data\fusioncache.dat
2009-08-16 21:51 . 2009-08-16 21:51 -------- d-----w- c:\documents and settings\Cheryl\Application Data\InstallShield
2009-08-16 07:02 . 2009-08-16 07:02 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-08-15 04:28 . 2009-08-15 04:28 -------- d-----w- c:\documents and settings\All Users\Application Data\HP
2009-08-15 04:27 . 2009-08-15 04:26 -------- d-----w- c:\program files\Common Files\HP
2009-08-15 04:25 . 2009-08-15 04:22 -------- d-----w- c:\program files\HP
2009-08-15 04:25 . 2009-08-15 04:25 -------- d-----w- c:\program files\Hewlett-Packard
2009-08-15 04:24 . 2009-08-15 04:24 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2009-08-15 01:04 . 2009-08-15 01:04 -------- d-----w- c:\documents and settings\Chris\Application Data\Research In Motion
2009-08-15 01:04 . 2009-08-15 01:04 256 ----a-w- c:\documents and settings\Chris\pool.bin
2009-08-14 23:25 . 2009-08-14 23:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Sonic
2009-08-14 23:23 . 2009-08-06 05:05 -------- d-----w- c:\program files\Common Files\InstallShield
2009-08-14 23:15 . 2009-08-14 23:15 -------- d-----w- c:\program files\Research In Motion
2009-08-14 02:56 . 2009-08-14 02:56 -------- d-----w- c:\program files\Microsoft Works
2009-08-14 02:53 . 2009-08-14 02:53 -------- d-----w- c:\program files\Microsoft.NET
2009-08-12 23:32 . 2009-08-12 23:32 -------- d-----w- c:\documents and settings\Chris\Application Data\OpenOffice.org
2009-08-12 23:26 . 2009-08-12 23:26 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-08-12 23:26 . 2009-08-12 23:26 -------- d-----w- c:\program files\Java
2009-08-12 03:34 . 2009-08-08 01:44 -------- d-----w- c:\program files\Windows Desktop Search
2009-08-12 03:31 . 2009-08-06 05:20 -------- d-----w- c:\program files\PC-Doctor for Windows
2009-08-12 03:29 . 2009-08-06 05:26 -------- d-----w- c:\program files\Multimedia Center for Think Offerings
2009-08-11 00:02 . 2009-08-11 00:02 -------- d-----w- c:\program files\Citrix
2009-08-10 23:53 . 2009-08-10 23:53 -------- d-----w- c:\documents and settings\Cheryl\Application Data\AdobeUM
2009-08-10 23:49 . 2009-08-10 23:49 -------- d-----w- c:\program files\Common Files\Adobe
2009-08-10 00:58 . 2009-08-08 17:29 -------- d-----w- c:\documents and settings\Cheryl\Application Data\Smart-Shopper
2009-08-08 23:22 . 2009-08-08 23:21 -------- d-----w- c:\documents and settings\Blake\Application Data\Smart-Shopper
2009-08-08 23:09 . 2009-08-08 23:09 -------- d-----w- c:\documents and settings\Blake\Application Data\Windows Desktop Search
2009-08-08 17:30 . 2009-08-08 17:30 -------- d-----w- c:\documents and settings\Cheryl\Application Data\Windows Desktop Search
2009-08-08 14:23 . 2009-08-08 14:21 -------- d-----w- c:\program files\jZip
2009-08-08 02:25 . 2009-08-08 02:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-08-08 02:23 . 2009-08-08 02:23 -------- d-----w- c:\program files\Yahoo!
2009-08-08 01:55 . 2009-08-08 01:55 -------- d-----w- c:\program files\MSBuild
2009-08-08 01:55 . 2009-08-08 01:55 -------- d-----w- c:\program files\Reference Assemblies
2009-08-08 01:43 . 2009-08-08 01:43 -------- d-----w- c:\program files\Windows Media Connect 2
2009-08-08 01:39 . 2009-08-06 05:15 -------- d-----w- c:\program files\Windows Media Connect
2009-08-08 01:39 . 2009-08-06 05:43 128 ----a-w- c:\documents and settings\Chris\Local Settings\Application Data\fusioncache.dat
2009-08-07 18:57 . 2009-08-07 00:03 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-08-07 18:56 . 2009-08-07 00:03 -------- d-----w- c:\program files\NOS
2009-08-06 05:15 . 2009-08-06 05:15 136 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\fusioncache.dat
2009-08-06 05:09 . 2009-08-06 05:09 17119 ----a-w- c:\windows\system32\drivers\AegisP.sys
2009-08-06 04:11 . 2009-08-06 04:11 0 ----a-w- c:\windows\nsreg.dat
2009-08-06 02:51 . 2009-08-06 05:29 40 ----a-w- c:\windows\system32\profile.dat
2009-08-05 09:01 . 1980-01-01 07:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-17 19:01 . 1980-01-01 07:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 03:43 . 1980-01-01 07:00 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2007-06-21 22:38 . 2007-06-21 22:38 30280 ----a-w- c:\program files\mozilla firefox\plugins\cgpcfg.dll
2007-06-21 22:38 . 2007-06-21 22:38 79432 ----a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll
2007-06-21 22:38 . 2007-06-21 22:38 71240 ----a-w- c:\program files\mozilla firefox\plugins\confmgr.dll
2007-06-21 22:38 . 2007-06-21 22:38 140872 ----a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll
2007-06-21 22:39 . 2007-06-21 22:39 38472 ----a-w- c:\program files\mozilla firefox\plugins\icafile.dll
2007-06-21 22:39 . 2007-06-21 22:39 46664 ----a-w- c:\program files\mozilla firefox\plugins\icalogon.dll
2007-06-21 22:39 . 2007-06-21 22:39 34376 ----a-w- c:\program files\mozilla firefox\plugins\logging.dll
2007-06-21 22:39 . 2007-06-21 22:39 685640 ----a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2007-06-21 22:40 . 2007-06-21 22:40 30280 ----a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-27 4351216]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
"Google Update"="c:\documents and settings\Chris\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-08-14 133104]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2008-10-24 206112]
"amsg"="c:\program files\ThinkVantage\AMSG\Amsg.exe" [2005-08-02 475136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2008-07-04 118784]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-07-04 1323008]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-09-09 94208]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-09-09 77824]
"Persistence"="c:\windows\system32\igfxpers.exe" [2005-09-09 114688]
"EZEJMNAP"="c:\progra~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe" [2005-08-10 237568]
"TPHOTKEY"="c:\progra~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe" [2005-08-29 94208]
"AMSG"="c:\program files\ThinkVantage\AMSG\Amsg.exe" [2005-08-02 475136]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2008-10-24 206112]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2008-10-24 79136]
"PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2005-08-10 139264]
"BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2005-08-10 208896]
"TPKMAPHELPER"="c:\program files\ThinkPad\Utilities\TpKmapAp.exe" [2005-08-12 864256]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-12 148888]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-09-13 49152]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-17 2007832]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-08-30 282624]
"BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2009-05-14 623888]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2009-04-11 236016]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"TP4EX"="tp4ex.exe" - c:\windows\system32\TP4EX.exe [2005-08-02 40960]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2009-8-6 24576]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-4 258048]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-4 53248]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-17 02:32 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2005-07-06 06:45 28672 ----a-w- c:\windows\system32\notifyf2.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2005-06-17 05:23 24576 ----a-w- c:\windows\system32\tphklock.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\LEGO Media\\Games\\LEGO Chess\\Lego Chess.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [10/4/2009 9:47 PM 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [8/16/2009 10:32 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [8/16/2009 10:32 PM 108552]
R1 TPPWRIF;TPPWRIF;c:\windows\system32\drivers\TPPWRIF.SYS [8/6/2009 1:32 AM 4442]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [8/16/2009 10:31 PM 297752]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/3/2009 10:49 AM 1028432]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-10-05 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 01:46]
2009-10-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3613155644-3150293659-1215151773-1005Core.job
- c:\documents and settings\Chris\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-14 03:53]
2009-10-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3613155644-3150293659-1215151773-1005UA.job
- c:\documents and settings\Chris\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-14 03:53]
2009-10-05 c:\windows\Tasks\PMTask.job
- c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2009-08-06 08:10]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} - hxxp://activex.camfrogweb.com/advanced/2.0.2.3/cfweb_activex.camfrogweb.com-advanced-2.0.2.3_instmodule.exe
FF - ProfilePath - c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\7yimmcp8.default\
FF - prefs.js: browser.startup.homepage - hxxp://michigan.rivals.com/default.asp?SID=883&ReturnTo=michigan%2Erivals%2Ecom&LIN=1
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\7yimmcp8.default\extensions\LogMeInClient@logmein.com\plugins\npRACtrl.dll
FF - plugin: c:\documents and settings\Chris\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npicaN.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
- - - - ORPHANS REMOVED - - - -
Notify-NavLogon - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-05 21:21
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(928)
c:\windows\system32\tphklock.dll
.
Completion time: 2009-10-06 21:23
ComboFix-quarantined-files.txt 2009-10-06 01:23
Pre-Run: 21,199,233,024 bytes free
Post-Run: 21,791,719,424 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect
285 --- E O F --- 2009-09-02 15:18