Hi thewall,
OK - I followed your instructions exactly - downloaded combofix, disabled AVG, ran a scan. Here is the combofix scan log:
Thanks and Go Gators. vancwa
______________________________________________________________________________________________________________________________________________________________________________
ComboFix 10-02-27.04 - Frank 02/27/2010 12:00:35.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3071.2462 [GMT -8:00]
Running from: c:\documents and settings\Frank\My Documents\bleepingcomputer\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Downloaded Program Files\Temp
c:\windows\system32\BSTIEPrintCtl1.dll
F:\Autorun.inf
Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it
.
((((((((((((((((((((((((( Files Created from 2010-01-27 to 2010-02-27 )))))))))))))))))))))))))))))))
.
2010-02-26 20:01 . 2010-02-26 20:01 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2010-02-24 03:23 . 2010-02-24 03:23 -------- d-----w- c:\documents and settings\Frank\Application Data\Office Genuine Advantage
2010-02-22 06:39 . 2010-02-22 06:39 5115824 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-02-22 06:38 . 2010-02-22 06:38 -------- d-----w- c:\documents and settings\Frank\Application Data\Malwarebytes
2010-02-22 06:38 . 2010-01-08 00:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-22 06:38 . 2010-02-22 06:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-22 06:38 . 2010-01-08 00:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-22 06:37 . 2010-02-22 06:38 -------- d-----w- c:\program files\Malwarebyte
2010-02-21 05:25 . 2010-02-21 05:25 95024 ------w- c:\windows\system32\drivers\SBREDrv.sys
2010-02-21 05:25 . 2010-02-21 05:25 95024 ------w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Drivers\SBREDrv.sys
2010-02-21 05:25 . 2010-02-21 05:25 598368 ------w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\EmailScanner.dll
2010-02-21 05:25 . 2010-02-21 05:25 566608 ------w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\sbap.dll
2010-02-21 05:25 . 2010-02-21 05:25 562272 ------w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\aawapi.dll
2010-02-21 05:25 . 2010-02-21 05:25 221408 ------w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\VipreBridge.dll
2010-02-21 05:25 . 2010-02-21 05:25 247120 ------w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\SBRE.dll
2010-02-21 05:25 . 2010-02-21 05:25 1230160 ------w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\SBTE.dll
2010-02-21 05:25 . 2010-02-21 05:25 17480 ------w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\EmailScannerBridge.dll
2010-02-21 05:24 . 2010-02-21 05:24 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-02-21 05:24 . 2010-02-04 15:53 2954656 -c----w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}\Ad-AwareInstaller.exe
2010-02-18 07:13 . 2010-02-18 07:15 -------- d-----w- c:\program files\Windows Live Safety Center
2010-02-18 03:30 . 2010-02-18 03:30 -------- d-----w- c:\windows\system32\wbem\Repository
2010-02-17 17:21 . 2010-02-26 17:24 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-01-31 00:51 . 2010-01-31 00:52 -------- d-----w- c:\documents and settings\Frank\Application Data\GARMIN
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-27 06:15 . 2009-10-30 17:28 0 ----a-w- c:\documents and settings\Tammy\Local Settings\Application Data\prvlcl.dat
2010-02-26 17:23 . 2009-08-02 21:47 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-02-25 02:18 . 2009-11-23 01:36 79488 ----a-w- c:\documents and settings\Frank\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-02-24 16:21 . 2009-11-24 07:42 79488 ----a-w- c:\documents and settings\Tammy\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-02-24 13:52 . 2008-09-17 02:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-02-21 06:33 . 2008-09-17 02:35 -------- d-----w- c:\documents and settings\All Users\Application Data\DVD Shrink
2010-02-21 05:45 . 2008-04-14 12:00 96512 ----a-w- c:\windows\system32\drivers\atapi.sys
2010-02-21 05:24 . 2009-09-07 15:42 -------- d-----w- c:\program files\Lavasoft
2010-02-05 00:49 . 2009-08-08 01:42 1616248 ------w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-02-04 15:53 . 2009-09-07 15:43 64288 ------w- c:\windows\system32\drivers\Lbd.sys
2010-01-26 06:17 . 2010-01-26 06:17 152576 ------w- c:\documents and settings\Frank\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-01-18 03:10 . 2010-01-18 03:10 0 ------w- c:\windows\nsreg.dat
2010-01-05 10:00 . 2008-04-14 12:00 832512 ----a-w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2008-04-14 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2008-04-14 12:00 17408 ----a-w- c:\windows\system32\corpol.dll
2010-01-01 01:28 . 2010-01-01 01:27 -------- d-----w- c:\program files\EZ_backtest
2009-12-31 16:50 . 2008-04-14 12:00 353792 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-30 01:33 . 2009-03-01 03:51 -------- d-----w- c:\program files\TurboTax
2009-12-20 19:05 . 2009-12-20 19:05 360584 ------w- c:\windows\system32\drivers\avgtdix.sys
2009-12-20 19:05 . 2009-12-20 19:05 12464 ------w- c:\windows\system32\avgrsstx.dll
2009-12-20 19:05 . 2009-12-20 19:05 333192 ------w- c:\windows\system32\drivers\avgldx86.sys
2009-12-20 19:05 . 2009-12-20 19:05 28424 ------w- c:\windows\system32\drivers\avgmfx86.sys
2009-12-16 18:43 . 2008-09-13 03:01 343040 ----a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:08 . 2008-04-14 12:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2009-12-13 20:49 . 2008-09-25 19:10 66472 ------w- c:\documents and settings\Tammy\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-08 19:26 . 2008-04-14 12:00 2145280 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:43 . 2008-04-14 00:01 2023936 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 18:22 . 2008-04-14 12:00 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-11-30 16:43 . 2009-09-21 15:43 3695616 ------w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\AutoLaunch.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"PxDotNetLoader"="c:\program files\Fidelity\Active Trader Pro\Fidelity Active Trader\System\ATPStartupAssistant.exe" [2009-03-25 42336]
"SpybotSD TeaTimer"="c:\program files\Spybot S&D\Spybot - Search & Destroy\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTHelper"="CTHELPER.EXE" [2008-06-28 19456]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13529088]
"nwiz"="nwiz.exe" [2008-05-03 1630208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-03 86016]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb11.exe" [2006-01-07 172032]
"HPHUPD06"="c:\windows\HP 8150\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2006-01-07 49152]
"HP Software Update"="c:\windows\HP 8150\HP Software Update\HPWuSchd2.exe" [2004-02-12 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"HPHmon06"="c:\windows\system32\hphmon06.exe" [2006-01-07 659456]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"hpqSRMon"="c:\windows\HP 8150\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-12-13 642856]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-27 413696]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2010-02-21 815184]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-10-23 217194]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-9-20 113664]
HP Digital Imaging Monitor.lnk - c:\windows\HP 8150\digital imaging\bin\hpqtra08.exe [2004-5-28 241664]
MarketBrowser.lnk - c:\program files\Marketbrowser\lmt\mktbrws.exe [2009-8-23 2972160]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
VIA RAID TOOL.lnk - c:\program files\VIA\RAID\raid_tool.exe [2009-7-26 585728]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-12-20 19:05 12464 ------w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Pml Driver HPZ12"=3 (0x3)
"avg8wd"=2 (0x2)
"AdobeActiveFileMonitor7.0"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\HP 8150\\digital imaging\\bin\\hpqpse.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\Bin\\hpqPhotoCrm.exe"=
"c:\\WINDOWS\\HP 8150\\digital imaging\\bin\\hpqsudi.exe"=
"c:\\WINDOWS\\HP 8150\\digital imaging\\bin\\hpqpsapp.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP:DHCP Discovery Service
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [9/7/2009 7:43 AM 64288]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [12/20/2009 11:05 AM 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [12/20/2009 11:05 AM 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [12/20/2009 11:05 AM 285392]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2/4/2010 7:52 AM 1229232]
R2 LinksysUpdater;Linksys Updater;c:\program files\Linksys\Linksys Updater\bin\LinksysUpdater.exe [11/13/2008 11:43 AM 204800]
R3 COMMONFX.SYS;COMMONFX.SYS;c:\windows\system32\drivers\COMMONFX.sys [6/27/2008 6:21 PM 99352]
R3 CTAUDFX.SYS;CTAUDFX.SYS;c:\windows\system32\drivers\CTAUDFX.sys [6/27/2008 6:21 PM 555032]
R3 CTSBLFX.SYS;CTSBLFX.SYS;c:\windows\system32\drivers\CTSBLFX.sys [6/27/2008 6:21 PM 566296]
S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.sys [6/27/2008 6:21 PM 99352]
S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.sys [6/27/2008 6:21 PM 555032]
S3 CTERFXFX.SYS;CTERFXFX.SYS;c:\windows\system32\drivers\CTERFXFX.sys [6/27/2008 6:21 PM 100888]
S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.sys [6/27/2008 6:21 PM 100888]
S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.sys [6/27/2008 6:21 PM 566296]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\e:\ntglm7x.sys --> e:\NTGLM7X.sys [?]
S4 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [9/16/2008 11:03 AM 169312]
.
Contents of the 'Scheduled Tasks' folder
2010-02-27 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 05:25]
2010-02-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
2010-02-27 c:\windows\Tasks\HP Usg Daily FY04.job
- c:\windows\HP 8150\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\pexpress\hphped06.exe [2008-09-18 05:09]
2010-02-27 c:\windows\Tasks\User_Feed_Synchronization-{5362173C-89B4-471D-BF5B-CEE96DA6F1C0}.job
- c:\windows\system32\msfeedssync.exe [2007-08-14 01:36]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
Trusted Zone: intuit.com\ttlc
Trusted Zone: turbotax.com
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.1.0/GarminAxControl.CAB
DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} - hxxp://offers.e-centives.com/cif/download/bin/actxcab.cab
DPF: {DEA6994F-3ED5-40BC-B5E3-0FD02411B1B4} - hxxp://www.costcophotocenter.com/upload/activex/v3_0_0_1/PhotoCenter_ActiveX_Control.cab?
FF - ProfilePath - c:\documents and settings\Frank\Application Data\Mozilla\Firefox\Profiles\kovwwuyz.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/|https://www.fidelity.com/
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-23C3F5C0 - c:\docume~1\tammy\locals~1\tempor~1\content.ie5\bb9vfloo\speedu~1.exe
Notify-AtiExtEvent - (no file)
AddRemove-ToneGen - c:\program files\NCH Software\ToneGen\uninst.exe
**************************************************************************
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
CTHelper = CTHELPER.EXE?
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2676)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\system32\java.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-02-27 12:13:32 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-27 20:13
Pre-Run: 135,405,867,008 bytes free
Post-Run: 136,341,385,216 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 1B76E954E7F9938158B54E0901D09D92