Hi Adam!
Here is the new information.
ComboFix log:
ComboFix 09-12-22.06 - Nichole 23/12/2009 9:23.6.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.2.1033.18.2037.1136 [GMT -4:00]
Running from: c:\users\Nichole\Desktop\ComboFix.exe
Command switches used :: c:\users\Nichole\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
FILE ::
"c:\windows\System32\APGNQC~1.EXE"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\windows\System32\APGNQC~1.EXE
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_trydvykmzywlpg
((((((((((((((((((((((((( Files Created from 2009-11-23 to 2009-12-23 )))))))))))))))))))))))))))))))
.
2009-12-23 13:31 . 2009-12-23 13:32 -------- d-----w- c:\users\Nichole\AppData\Local\temp
2009-12-23 13:31 . 2009-12-23 13:31 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-12-23 13:31 . 2009-12-23 13:31 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-12-22 16:07 . 2009-12-12 06:46 4043032 ----a-w- c:\programdata\avg9\update\backup\avgui.exe
2009-12-22 16:07 . 2009-12-12 06:45 3776280 ----a-w- c:\programdata\avg9\update\backup\setup.exe
2009-12-22 16:07 . 2009-12-11 13:06 916248 ----a-w- c:\programdata\avg9\update\backup\avgcfgx.dll
2009-12-21 02:08 . 2009-12-21 02:08 -------- d-----w- c:\users\Nichole\AppData\Local\Adobe
2009-12-20 21:36 . 2009-12-20 21:36 862040 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-12-20 21:36 . 2009-12-20 21:36 206944 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-12-20 21:36 . 2009-12-20 21:36 390288 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\lavalicense.dll
2009-12-20 21:36 . 2009-12-20 21:36 537576 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\aawapi.dll
2009-12-20 21:36 . 2009-12-20 21:36 370744 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2009-12-20 21:36 . 2009-12-20 21:36 194104 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Savapibridge.dll
2009-12-20 21:35 . 2009-12-20 21:35 6296864 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Resources.dll
2009-12-20 21:35 . 2009-12-20 21:35 933120 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-12-20 21:35 . 2009-12-20 21:35 816272 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-12-20 21:35 . 2009-12-20 21:35 822904 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-12-20 21:35 . 2009-12-20 21:35 1643272 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-12-20 21:35 . 2009-12-20 21:35 788880 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-12-20 21:35 . 2009-12-20 21:35 1181328 ----a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-12-18 13:51 . 2009-12-18 13:51 294656 ----a-w- c:\programdata\avg9\update\backup\avglngx.dll
2009-12-18 12:07 . 2009-12-18 12:07 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2009-12-18 12:07 . 2009-12-20 14:24 -------- d-----w- c:\users\Nichole\AppData\Roaming\SUPERAntiSpyware.com
2009-12-18 12:07 . 2009-12-20 14:24 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-12-17 21:18 . 2009-12-17 21:18 -------- d-----w- c:\users\Nichole\AppData\Roaming\Malwarebytes
2009-12-17 21:18 . 2009-12-03 20:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-17 21:18 . 2009-12-17 21:18 -------- d-----w- c:\programdata\Malwarebytes
2009-12-17 21:18 . 2009-12-17 21:18 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-17 21:18 . 2009-12-03 20:13 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-17 21:16 . 2008-11-06 06:03 -------- d-----w- C:\SDFix
2009-12-17 18:54 . 2009-12-23 13:05 0 ----a-w- c:\users\Nichole\AppData\Local\prvlcl.dat
2009-12-17 18:47 . 2009-12-17 18:47 -------- d-----w- C:\VundoFix Backups
2009-12-16 14:13 . 2009-12-16 14:13 -------- d-----w- c:\users\Nichole\AppData\Roaming\AVG9
2009-12-16 00:54 . 2009-12-22 15:56 -------- d-----w- c:\users\Nichole\AppData\Roaming\QuickScan
2009-12-16 00:54 . 2009-11-26 21:39 678912 ----a-w- c:\users\Nichole\AppData\Roaming\Mozilla\Firefox\Profiles\37flfpuk.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\bdqscan.dll
2009-12-16 00:54 . 2009-11-26 21:37 768512 ----a-w- c:\users\Nichole\AppData\Roaming\Mozilla\Firefox\Profiles\37flfpuk.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
2009-12-15 15:57 . 2009-12-15 19:13 -------- d-----w- c:\users\Nichole\AppData\Roaming\FileZilla
2009-12-15 15:56 . 2009-12-15 15:56 -------- d-----w- c:\program files\FileZilla FTP Client
2009-12-14 19:15 . 2009-12-14 19:15 2146304 ----a-w- c:\windows\system32\GPhotos.scr
2009-12-13 22:46 . 2009-12-02 13:19 15880 ----a-w- c:\windows\system32\lsdelete.exe
2009-12-13 21:35 . 2009-12-13 21:35 -------- dc----w- c:\windows\system32\DRVSTORE
2009-12-13 21:35 . 2009-12-02 13:19 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-12-13 21:34 . 2009-12-13 21:34 -------- dc-h--w- c:\programdata\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}
2009-12-13 21:34 . 2009-12-07 14:10 2953352 -c--a-w- c:\programdata\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}\Ad-AwareInstallation.exe
2009-12-13 21:33 . 2009-12-13 21:33 -------- d-----w- c:\program files\Lavasoft
2009-12-12 07:00 . 2009-11-09 13:34 24064 ----a-w- c:\windows\system32\nshhttp.dll
2009-12-12 07:00 . 2009-11-09 13:30 31232 ----a-w- c:\windows\system32\httpapi.dll
2009-12-12 07:00 . 2009-11-09 11:17 396800 ----a-w- c:\windows\system32\drivers\http.sys
2009-12-12 06:46 . 2009-12-11 13:07 1082648 ----a-w- c:\programdata\avg9\update\backup\avgxpl.dll
2009-12-12 06:46 . 2009-12-11 13:07 1074456 ----a-w- c:\programdata\avg9\update\backup\avgcmgr.exe
2009-12-12 06:46 . 2009-12-11 13:06 1336600 ----a-w- c:\programdata\avg9\update\backup\avgssff.dll
2009-12-12 06:46 . 2009-12-11 13:06 1494088 ----a-w- c:\programdata\avg9\update\backup\avgwd.dll
2009-12-12 06:46 . 2009-12-11 13:06 744728 ----a-w- c:\programdata\avg9\update\backup\avgscanx.exe
2009-12-12 06:46 . 2009-12-11 13:06 562456 ----a-w- c:\programdata\avg9\update\backup\avgsrmx.dll
2009-12-12 06:46 . 2009-12-11 13:06 361752 ----a-w- c:\programdata\avg9\update\backup\avgsrmax.exe
2009-12-12 06:46 . 2009-12-12 06:45 2352920 ----a-w- c:\programdata\avg9\update\backup\avgresf.dll
2009-12-12 06:46 . 2009-12-11 13:07 1946392 ----a-w- c:\programdata\avg9\update\backup\avgapix.dll
2009-12-12 06:46 . 2009-12-11 13:07 615704 ----a-w- c:\programdata\avg9\update\backup\avgcertx.dll
2009-12-12 06:46 . 2009-12-11 13:07 502040 ----a-w- c:\programdata\avg9\update\backup\avgrsx.exe
2009-12-12 06:45 . 2009-12-11 13:07 798488 ----a-w- c:\programdata\avg9\update\backup\avginet.dll
2009-12-11 13:21 . 2009-12-12 06:45 3967256 ----a-w- c:\programdata\avg9\update\backup\avgcorex.dll
2009-12-11 13:21 . 2009-12-11 13:07 497944 ----a-w- c:\programdata\avg9\update\backup\avgchjwx.dll
2009-12-11 13:20 . 2009-12-11 13:20 844056 ----a-w- c:\programdata\avg9\update\backup\avgupd.exe
2009-12-11 13:20 . 2009-12-11 13:20 1658136 ----a-w- c:\programdata\avg9\update\backup\avgupd.dll
2009-12-11 13:09 . 2009-12-11 13:12 -------- d-----w- C:\$AVG
2009-12-11 13:06 . 2009-12-21 17:36 -------- d-----w- c:\programdata\avg9
2009-12-11 12:18 . 2009-12-11 12:18 -------- d-----w- c:\programdata\e9e676d
2009-12-09 23:34 . 2009-10-07 12:47 232960 ----a-w- c:\windows\system32\rastls.dll
2009-12-09 23:34 . 2009-10-07 12:47 274432 ----a-w- c:\windows\system32\raschap.dll
2009-12-04 14:03 . 2009-12-04 14:03 251376 ----a-w- c:\users\Nichole\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
2009-12-04 06:08 . 2009-12-04 06:08 764168 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-11-29 02:54 . 2009-12-20 09:42 439816 ----a-w- c:\users\Nichole\AppData\Roaming\Real\Update\setup3.09\setup.exe
2009-11-27 09:18 . 2009-10-29 07:59 2048 ----a-w- c:\windows\system32\tzres.dll
2009-11-25 13:10 . 2009-11-25 13:10 73216 ----a-w- c:\windows\ST6UNST.EXE
2009-11-25 13:10 . 2009-11-25 13:10 286720 ------w- c:\windows\Setup1.exe
2009-11-25 08:14 . 2009-08-10 13:05 2048 ----a-w- c:\windows\system32\msxml6r.dll
2009-11-25 08:14 . 2009-08-10 13:05 1406464 ----a-w- c:\windows\system32\msxml6.dll
2009-11-25 08:14 . 2009-08-10 13:05 2048 ----a-w- c:\windows\system32\msxml3r.dll
2009-11-25 08:14 . 2009-08-10 13:05 1260032 ----a-w- c:\windows\system32\msxml3.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-23 11:41 . 2008-06-26 21:21 1356 ----a-w- c:\users\Nichole\AppData\Local\d3d9caps.dat
2009-12-19 03:19 . 2009-07-19 04:06 -------- d-----w- c:\users\Nichole\AppData\Roaming\Skype
2009-12-18 20:04 . 2009-07-19 04:08 -------- d-----w- c:\users\Nichole\AppData\Roaming\skypePM
2009-12-18 11:04 . 2008-03-04 04:56 107336 ----a-w- c:\users\Nichole\AppData\Local\GDIPFONTCACHEV1.DAT
2009-12-18 04:37 . 2007-12-04 06:53 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-16 13:14 . 2008-02-14 00:02 308248 ----a-w- c:\windows\system32\drivers\iaStor.sys
2009-12-15 19:55 . 2008-10-21 11:17 -------- d-sh--w- c:\program files\AKProg
2009-12-15 19:21 . 2008-10-26 19:40 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-12-15 19:17 . 2008-10-26 19:40 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-12-13 21:33 . 2008-05-27 03:54 -------- d-----w- c:\programdata\Lavasoft
2009-12-11 13:09 . 2008-10-26 19:42 -------- d-----w- c:\programdata\avg8
2009-12-11 13:09 . 2009-04-01 02:02 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-12-11 13:09 . 2008-10-26 19:42 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-12-11 13:09 . 2008-10-26 19:42 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-12-11 13:09 . 2008-10-26 19:42 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-12-11 13:06 . 2008-10-26 19:42 -------- d-----w- c:\program files\AVG
2009-12-11 00:39 . 2008-03-28 15:53 -------- d-----w- c:\users\Nichole\AppData\Roaming\LimeWire
2009-12-10 07:04 . 2008-03-07 01:45 -------- d-----w- c:\programdata\Microsoft Help
2009-12-05 01:33 . 2008-06-21 01:54 1 ----a-w- c:\users\Nichole\AppData\Roaming\OpenOffice.org2\user\uno_packages\cache\stamp.sys
2009-12-05 01:33 . 2008-06-21 01:53 -------- d-----w- c:\users\Nichole\AppData\Roaming\OpenOffice.org2
2009-12-01 20:39 . 2009-08-08 01:14 -------- d-----w- c:\program files\Google
2009-11-10 04:29 . 2009-11-10 04:29 -------- d-----w- c:\program files\Microsoft
2009-11-03 00:42 . 2009-10-04 13:20 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-11-02 02:53 . 2008-12-22 17:54 -------- d-----w- c:\program files\Audible
2009-11-01 15:46 . 2008-03-04 04:48 -------- d-----w- c:\program files\Microsoft Works
2009-10-27 15:05 . 2009-12-09 23:35 832512 ----a-w- c:\windows\system32\wininet.dll
2009-10-27 15:01 . 2009-12-09 23:35 56320 ----a-w- c:\windows\system32\iesetup.dll
2009-10-27 15:01 . 2009-12-09 23:35 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-10-27 15:01 . 2009-12-09 23:35 52736 ----a-w- c:\windows\AppPatch\iebrshim.dll
2009-10-27 14:59 . 2009-12-09 23:35 72704 ----a-w- c:\windows\system32\admparse.dll
2009-10-27 12:27 . 2009-12-09 23:35 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-10-27 10:56 . 2009-12-09 23:35 48128 ----a-w- c:\windows\system32\mshtmler.dll
2007-08-25 02:52 . 2008-03-20 10:16 300400 ----a-w- c:\program files\mozilla firefox\components\coFFPlgn.dll
.
((((((((((((((((((((((((((((( SnapShot_2009-12-21_18.20.07 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-11-26 04:02 . 2009-12-15 20:03 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-11-26 04:02 . 2009-12-22 15:00 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-11-26 04:02 . 2009-12-15 20:03 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-11-26 04:02 . 2009-12-22 15:00 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-11-26 04:02 . 2009-12-15 20:03 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-11-26 04:02 . 2009-12-22 15:00 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-12-21 17:39 . 2009-12-21 17:39 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-12-23 08:25 . 2009-12-23 08:25 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-12-23 08:25 . 2009-12-23 08:25 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-12-21 17:39 . 2009-12-21 17:39 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Desktop Manager.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Desktop Manager.lnk
backup=c:\windows\pss\Desktop Manager.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^Nichole^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Get 2 FREE Audiobooks.lnk]
path=c:\users\Nichole\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Get 2 FREE Audiobooks.lnk
backup=c:\windows\pss\Get 2 FREE Audiobooks.lnk.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Nichole^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 2.4.lnk]
path=c:\users\Nichole\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 2.4.lnk
backup=c:\windows\pss\OpenOffice.org 2.4.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2007-05-11 08:06 40048 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
2007-10-25 08:44 212992 ----a-w- c:\program files\Apoint2K\Apoint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG9_TRAY]
2009-12-12 06:45 2033432 ----a-w- c:\progra~1\AVG\AVG9\avgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2006-11-02 12:35 125440 ----a-w- c:\windows\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2008-09-23 23:13 133104 ----atw- c:\users\Nichole\AppData\Local\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk]
2007-01-01 21:22 3739648 ----a-w- c:\users\Nichole\AppData\Roaming\Google\Google Talk\googletalk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2008-01-02 21:06 166424 ----a-w- c:\windows\System32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
2007-10-03 23:15 480560 ----a-w- c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
2007-10-03 23:44 178712 ----a-w- c:\program files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2008-01-02 21:07 141848 ----a-w- c:\windows\System32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2009-02-20 17:22 4363504 ----a-w- c:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2009-07-26 20:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2008-01-02 21:07 133656 ----a-w- c:\windows\System32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
2007-10-01 03:34 181544 ----a-w- c:\program files\HP\QuickPlay\QPService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2008-02-01 03:13 385024 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2008-03-05 11:46 1232896 ----a-w- c:\program files\Windows Sidebar\sidebar.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 20:07 2260480 --sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2008-06-10 07:27 144784 ----a-w- c:\program files\Java\jre1.6.0_07\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2008-04-02 23:53 185896 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UCam_Menu]
2007-09-14 00:32 222504 ------w- c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2007-12-04 07:15 1006264 ----a-w- c:\program files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2006-11-02 12:36 201728 ----a-w- c:\program files\Windows Media Player\wmpnscfg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
2009-02-20 17:22 4363504 ----a-w- c:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{0228e555-4f9c-4e35-a3ec-b109a192b4c2}]
2005-07-15 21:48 479232 ----a-w- c:\program files\Google\Gmail Notifier\gnotify.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [13/12/2009 5:35 PM 64288]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [26/10/2008 3:42 PM 333192]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [31/03/2009 10:02 PM 360584]
S3 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [11/12/2009 9:07 AM 906520]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\System32\drivers\mbamswissarmy.sys [17/12/2009 5:18 PM 38224]
S4 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [11/12/2009 9:06 AM 285392]
S4 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [02/12/2009 9:19 AM 1181328]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - LAVASOFT_AD-AWARE_SERVICE
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... &pf=laptopmStart Page =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE= ... &pf=laptopIE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Nichole\AppData\Roaming\Mozilla\Firefox\Profiles\37flfpuk.default\
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\users\Nichole\AppData\Roaming\Mozilla\Firefox\Profiles\37flfpuk.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\bdqscan.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - plugin: c:\users\Nichole\AppData\Local\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\users\Nichole\AppData\Roaming\Mozilla\Firefox\Profiles\37flfpuk.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
FF - plugin: c:\users\Nichole\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-12-23 09:32
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-12-23 09:35:45
ComboFix-quarantined-files.txt 2009-12-23 13:35
ComboFix2.txt 2009-12-21 18:22
ComboFix3.txt 2009-12-21 10:17
Pre-Run: 165,957,074,944 bytes free
Post-Run: 165,935,640,576 bytes free
- - End Of File - - 612E6D9D0B72C7E54B46B4FF543D4588
Kapersky Report:
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Wednesday, December 23, 2009
Operating system: Microsoft Windows Vista Home Premium Edition, 32-bit (build 6000)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Wednesday, December 23, 2009 11:16:14
Records in database: 3402569
--------------------------------------------------------------------------------
Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes
Scan area - My Computer:
C:\
D:\
E:\
Scan statistics:
Objects scanned: 150714
Threats found: 3
Infected objects found: 3
Suspicious objects found: 0
Scan duration: 03:40:40
File name / Threat / Threats count
C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.631 1
C:\Qoobox\Quarantine\C\Windows\System32\drivers\iaStor.sys.vir Infected: Rootkit.Win32.TDSS.y 1
C:\Qoobox\Quarantine\C\Windows\System32\qtplugin.exe.vir Infected: Trojan-Downloader.Win32.Piker.sx 1
Selected area has been scanned.
New HijackThis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:10:25 PM, on 23/12/2009
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16945)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Nichole\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Users\Nichole\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\NOTEPAD.EXE
C:\Users\Nichole\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE= ... &pf=laptopR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE= ... &pf=laptopR0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O8 - Extra context menu item: Add to Google Photos Screensa&ver -
res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe (file missing)
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\Windows\System32\avgrsstx.dll
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
--
End of file - 3802 bytes
Thanks again for all of your help, especially considering the holiday that is upon us. I understand if you can't dedicate much time to this right now - I have an uninfected PC that runs on Linux, so it's certainly not an inconvenience to me.
Nichole