To Gringo,
Here is the ComboFix log:
ComboFix 10-08-21.04 - User 08/21/2010 18:00:29.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.503.253 [GMT -7:00]
Running from: c:\documents and settings\User\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((( Files Created from 2010-07-22 to 2010-08-22 )))))))))))))))))))))))))))))))
.
2010-08-15 19:26 . 2010-08-15 19:26 -------- d-----w- c:\documents and settings\User\Application Data\Malwarebytes
2010-08-15 19:26 . 2010-04-29 22:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-15 19:26 . 2010-08-15 19:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-08-15 19:26 . 2010-04-29 22:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-08-15 19:26 . 2010-08-15 19:26 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-08-07 02:22 . 2010-08-07 02:22 -------- d-----w- c:\program files\Trend Micro
2010-08-06 20:12 . 2010-08-06 21:00 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-08-06 02:45 . 2010-08-07 04:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-08-06 02:45 . 2010-08-06 02:50 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-08-06 02:13 . 2010-08-06 02:14 -------- d-----w- c:\windows\system32\NtmsData
2010-08-05 22:06 . 2010-08-05 22:06 -------- d-----w- c:\documents and settings\User\Application Data\AVG9
2010-08-05 21:52 . 2010-08-05 21:52 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-08-05 21:51 . 2010-08-05 21:52 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-08-05 21:51 . 2010-08-05 21:51 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-08-05 21:51 . 2010-08-05 21:51 29584 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-08-05 21:51 . 2010-08-21 17:50 -------- d-----w- c:\windows\system32\drivers\Avg
2010-08-05 21:47 . 2010-08-05 21:47 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-08-04 19:42 . 2010-08-04 19:42 -------- d-----w- c:\windows\system32\wbem\Repository
2010-08-03 19:19 . 2010-08-03 19:19 -------- d-----w- c:\program files\Common Files\Java
2010-07-23 19:16 . 2010-07-23 19:16 0 ----a-w- c:\windows\nsreg.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-22 00:40 . 2009-12-22 08:26 1 ----a-w- c:\documents and settings\User\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-08-05 22:02 . 2009-08-05 03:36 -------- d-----w- c:\program files\CCleaner
2010-06-30 12:31 . 2004-08-04 12:00 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-27 05:44 . 2010-06-27 05:39 -------- d-----w- c:\documents and settings\User\Application Data\vlc
2010-06-27 05:37 . 2010-06-27 05:37 -------- d-----w- c:\program files\VideoLAN
2010-06-24 12:22 . 2004-08-04 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-23 13:44 . 2004-08-04 12:00 1851904 ----a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27 . 2004-08-04 12:00 354304 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-17 19:05 . 2010-06-17 19:05 25024 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-17 14:03 . 2004-08-04 12:00 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-16 04:09 . 2010-06-16 04:07 2605008 ----a-w- c:\documents and settings\User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe
2010-06-14 14:31 . 2009-08-04 21:59 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-14 07:41 . 2004-08-04 12:00 1172480 ----a-w- c:\windows\system32\msxml3.dll
2010-06-11 04:07 . 2010-06-11 04:07 26 ----a-w- c:\windows\winstart.bat
2010-06-11 04:07 . 2010-06-11 04:07 123 ----a-w- c:\windows\tmpcpyis.bat
2010-06-11 04:07 . 2010-06-11 04:07 122 ----a-w- c:\windows\tmpdelis.bat
2010-06-10 04:43 . 2010-06-10 04:43 37 ----a-w- c:\windows\eN.bat
2010-06-01 17:37 . 2010-06-15 18:57 221568 ------w- c:\windows\system32\MpSigStub.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-08-05 21:52 12536 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG9_TRAY]
2010-08-05 21:50 2065760 ----a-w- c:\progra~1\AVG\AVG9\avgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ----a-w- c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
2005-09-20 16:32 77824 ----a-w- c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
2005-09-20 16:36 114688 ----a-w- c:\windows\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
2005-09-20 16:35 94208 ----a-w- c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
2004-08-04 12:00 455168 ----a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
2004-10-14 21:42 1404928 ----a-w- c:\program files\Analog Devices\Core\smax4pnp.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [8/5/2010 2:51 PM 216400]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [8/5/2010 2:51 PM 243024]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [8/5/2010 2:49 PM 308136]
S4 gupdate;Google Update Service (gupdate);"c:\program files\Google\Update\GoogleUpdate.exe" /svc --> c:\program files\Google\Update\GoogleUpdate.exe [?]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
TCP: {B3201FDE-9DD2-47B0-B4D6-34B9CA2E6443} = 68.94.156.1 68.94.157.1
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-08-21 18:03
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2220)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-08-21 18:06:10
ComboFix-quarantined-files.txt 2010-08-22 01:06
ComboFix2.txt 2010-08-17 01:20
Pre-Run: 65,828,970,496 bytes free
Post-Run: 65,900,609,536 bytes free
- - End Of File - - A88F910874551AA87EA65D5E52B05BD5
- My internet is slow again after about 10 minutes.
I think it has to do with facebook or its apps.
Should I format my computer instead?
Thanks for everything.
Looking forward to hearing from you.