OK, here's the Combofix log from yesterday.
Thanks Again for your help!
Steve W.
ComboFix 09-06-23.01 - Owner 06/24/2009 14:46.1 - NTFSx86
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\recycler\S-1-5-21-2798954481-2681687752-2502150257-1003
c:\windows\system32\drivers\SKYNETtbbmiqxn.sys
c:\windows\system32\drivers\TDSSpqlt.sys
c:\windows\system32\TDSSbrsr.dll
c:\windows\system32\TDSSbubx.log
c:\windows\system32\TDSSlxwp.dll
c:\windows\system32\TDSSnmxh.log
c:\windows\system32\TDSSoiqh.dll
c:\windows\system32\TDSSosvd.dat
c:\windows\system32\TDSSrhym.dll
c:\windows\system32\TDSSriqp.dll
c:\windows\system32\TDSSsihc.dll
c:\windows\system32\TDSStkdu.log
c:\windows\system32\TDSSxfum.dll
c:\windows\system32\drivers\SKYNETtbbmiqxn.sys
c:\windows\system32\drivers\TDSSpqlt.sys
c:\windows\system32\SKYNETephgpwsi.dat
c:\windows\system32\SKYNETijmqweyx.dll
c:\windows\system32\SKYNETiuymycfj.dat
c:\windows\system32\SKYNETspyxudot.dll
c:\windows\system32\TDSSbrsr.dll
c:\windows\system32\TDSSbubx.log
c:\windows\system32\TDSSlxwp.dll
c:\windows\system32\TDSSnmxh.log
c:\windows\system32\TDSSoiqh.dll
c:\windows\system32\TDSSosvd.dat
c:\windows\system32\TDSSrhym.dll
c:\windows\system32\TDSSriqp.dll
c:\windows\system32\TDSSsihc.dll
c:\windows\system32\TDSStkdu.log
c:\windows\system32\TDSSxfum.dll
D:\Autorun.inf
D:\Desktop.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_TDSSSERV.SYS
——-\Legacy_TDSSSERV.SYS
——-\Service_SKYNETklldnqvm
((((((((((((((((((((((((( Files Created from 2009-05-24 to 2009-06-24 )))))))))))))))))))))))))))))))
.
2009-06-24 19:04 . 2009-06-24 19:22 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-06-24 16:55 . 2009-06-24 16:55 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-06-24 00:39 . 2009-06-24 00:39 ——– d—–w- c:\program files\SDHelper (Spybot - Search & Destroy)
2009-06-24 00:39 . 2009-06-24 00:39 ——– d—–w- c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2009-06-24 00:39 . 2009-06-24 00:39 ——– d—–w- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2009-06-23 23:01 . 2009-03-09 19:06 15688 —-a-w- c:\windows\system32\lsdelete.exe
2009-06-23 22:29 . 2009-03-09 19:06 64160 —-a-w- c:\windows\system32\drivers\Lbd.sys
2009-06-23 22:29 . 2009-06-23 22:29 314200 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\threatwork.exe
2009-06-23 22:29 . 2009-06-23 22:29 25440 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\savapibridge.dll
2009-06-23 22:29 . 2009-06-23 22:29 15688 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\lsdelete.exe
2009-06-23 22:29 . 2009-06-23 22:29 169312 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\lavamessage.dll
2009-06-23 22:29 . 2009-06-23 22:29 348496 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\lavalicense.dll
2009-06-23 22:29 . 2009-06-23 22:29 296800 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\UpdateManager.dll
2009-06-23 22:27 . 2009-06-23 22:27 1630048 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Resources.dll
2009-06-23 22:26 . 2009-06-23 22:26 212848 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\RPAPI.dll
2009-06-23 22:26 . 2009-06-23 22:26 40288 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\PrivacyClean.dll
2009-06-23 22:26 . 2009-06-23 22:26 64160 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Drivers\32\lbd.sys
2009-06-23 22:26 . 2009-06-23 22:26 72704 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Drivers\32\AAWDriverTool.exe
2009-06-23 22:26 . 2009-06-23 22:26 640360 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\CEAPI.dll
2009-06-23 22:26 . 2009-06-23 22:26 561016 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Ad-AwareCommand.exe
2009-06-23 22:25 . 2009-06-23 22:25 2349384 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Ad-Aware.exe
2009-06-23 22:25 . 2009-06-23 22:25 627536 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\AAWWSC.exe
2009-06-23 22:25 . 2009-06-23 22:25 518488 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\AAWTray.exe
2009-06-23 22:25 . 2009-06-23 22:25 1003344 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\AAWService.exe
2009-06-23 22:08 . 2009-06-23 22:08 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-06-23 22:08 . 2009-03-12 08:17 2902048 -c–a-w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
2009-06-23 22:08 . 2009-06-23 22:08 ——– d—–w- c:\program files\Lavasoft
2009-06-23 20:02 . 2009-06-23 20:02 ——– d—–w- c:\program files\HiJack This
2009-06-16 15:49 . 2009-06-16 15:49 ——– d—–w- c:\documents and settings\Owner\Application Data\Template
2009-05-27 00:19 . 2009-05-27 00:20 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Deployment
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-24 19:08 . 2006-10-16 22:18 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-17 22:03 . 2009-06-16 15:41 310 —-a-w- c:\documents and settings\Owner\Application Data\wklnhst.dat
2009-05-24 12:56 . 2009-05-15 22:03 ——– d—–w- c:\documents and settings\Owner\Application Data\TMNT
2009-05-19 14:26 . 2008-10-26 15:34 325896 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-05-19 14:26 . 2008-10-26 15:34 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-05-19 14:26 . 2008-10-26 15:34 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-05-19 14:26 . 2008-10-26 15:33 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-15 21:57 . 2009-05-09 00:28 ——– d—–w- c:\program files\Ubisoft
2009-05-15 21:57 . 2006-05-19 01:10 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-05-07 15:32 . 2004-08-26 16:11 345600 —-a-w- c:\windows\system32\localspl.dll
2009-04-29 04:56 . 2004-08-26 16:12 827392 —-a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2004-08-26 16:11 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-04-25 23:12 . 2008-10-26 15:33 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2009-04-25 23:04 . 2009-04-25 23:04 42912 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-25 23:04 . 2009-04-25 23:04 0 —-a-w- c:\documents and settings\Administrator\Application Data\wklnhst.dat
2009-04-17 12:26 . 2004-08-26 16:12 1847168 —-a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-08-26 16:12 585216 —-a-w- c:\windows\system32\rpcrt4.dll
2009-04-13 21:00 . 2009-04-13 21:00 152576 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-03-31 23:41 . 2009-03-31 23:41 2906215 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-03-27 20:53 . 2006-10-11 00:19 42912 —-a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-26 21:49 . 2008-10-26 14:16 38496 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-26 21:49 . 2008-10-26 14:16 15504 —-a-w- c:\windows\system32\drivers\mbam.sys
2004-07-08 19:59 . 2004-07-08 19:59 2768896 —-a-w- c:\program files\labeler.exe
2004-07-08 19:58 . 2004-07-08 19:58 163840 —-a-w- c:\program files\WLBVCHK.DLL
2004-07-08 19:58 . 2004-07-08 19:58 151552 —-a-w- c:\program files\WLTLVCHK.DLL
2004-07-08 19:58 . 2004-07-08 19:58 184320 —-a-w- c:\program files\WLTMPLMG.dll
2004-07-08 19:58 . 2004-07-08 19:58 163840 —-a-w- c:\program files\WLTLCVRT.DLL
2004-07-08 19:58 . 2004-07-08 19:58 180224 —-a-w- c:\program files\wlftmrg.dll
2004-07-08 19:57 . 2004-07-08 19:57 1978368 —-a-w- c:\program files\WLRCDLL.DLL
2004-06-15 15:59 . 2004-06-15 15:59 193 —-a-w- c:\program files\labeler.dpf
2004-01-26 22:34 . 2004-01-26 22:34 2238 —-a-r- c:\program files\labeler.ico
2003-11-21 23:41 . 2003-11-21 23:41 383811 —-a-w- c:\program files\labeler.chm
2003-10-10 17:26 . 2003-10-10 17:26 456 —-a-w- c:\program files\welcome.zdw
2003-10-10 17:26 . 2003-10-10 17:26 348896 —-a-w- c:\program files\splashhi.bmp
2003-10-10 17:26 . 2003-10-10 17:26 117356 —-a-w- c:\program files\splashlo.bmp
2003-10-10 17:24 . 2003-10-10 17:24 1685504 —-a-w- c:\program files\LTCLR13n.dll
2008-12-20 13:05 . 2006-12-23 11:33 67688 —-a-w- c:\program files\mozilla firefox\components\jar50.dll
2008-12-20 13:05 . 2006-12-23 11:33 54368 —-a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-20 13:05 . 2006-12-23 11:33 34944 —-a-w- c:\program files\mozilla firefox\components\myspell.dll
2008-12-20 13:05 . 2006-12-23 11:33 46712 —-a-w- c:\program files\mozilla firefox\components\spellchk.dll
2008-12-20 13:05 . 2006-12-23 11:33 172136 —-a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Google Update"="c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-05-27 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-05 53248]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"readericon"="c:\program files\Digital Media Reader\readericon45G.exe" [2005-12-10 139264]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb06.exe" [2002-07-11 188416]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"EPSON Stylus CX4200 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAEA.EXE" [2005-03-08 98304]
"EPSON Stylus CX4200 Series (Copy 1)"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAEA.EXE" [2005-03-08 98304]
"EPSON Stylus CX4200 Series (Copy 2)"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIAEA.EXE" [2005-03-08 98304]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-03-09 515416]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-04-05 16120832]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]
"washindex"="c:\program files\Washer\washidx.exe" [2001-04-03 64512]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" [X]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-19 14:26 11952 —-a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BigFix.lnk
backup=c:\windows\pss\BigFix.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8097:TCP"= 8097:TCP:EarthLink UHP Modem Support
"42361:TCP"= 42361:TCP:PORT_42361
"11094:TCP"= 11094:TCP:PORT_11094
"18470:TCP"= 18470:TCP:PORT_18470
"25325:TCP"= 25325:TCP:PORT_25325
"32794:TCP"= 32794:TCP:PORT_32794
"11669:TCP"= 11669:TCP:PORT_11669
"22735:TCP"= 22735:TCP:PORT_22735
"45446:TCP"= 45446:TCP:PORT_45446
"45979:TCP"= 45979:TCP:PORT_45979
"19274:TCP"= 19274:TCP:PORT_19274
"6133:TCP"= 6133:TCP:PORT_6133
"39832:TCP"= 39832:TCP:PORT_39832
"33151:TCP"= 33151:TCP:PORT_33151
"17432:TCP"= 17432:TCP:PORT_17432
"57891:TCP"= 57891:TCP:PORT_57891
"33857:TCP"= 33857:TCP:PORT_33857
"21774:TCP"= 21774:TCP:PORT_21774
"62223:TCP"= 62223:TCP:PORT_62223
"38485:TCP"= 38485:TCP:PORT_38485
"19735:TCP"= 19735:TCP:PORT_19735
"47083:TCP"= 47083:TCP:PORT_47083
"23639:TCP"= 23639:TCP:PORT_23639
"48703:TCP"= 48703:TCP:PORT_48703
"41750:TCP"= 41750:TCP:PORT_41750
"59106:TCP"= 59106:TCP:PORT_59106
"13575:TCP"= 13575:TCP:PORT_13575
"15889:TCP"= 15889:TCP:PORT_15889
"60198:TCP"= 60198:TCP:PORT_60198
"63363:TCP"= 63363:TCP:PORT_63363
"47201:TCP"= 47201:TCP:PORT_47201
"20990:TCP"= 20990:TCP:PORT_20990
"14898:TCP"= 14898:TCP:PORT_14898
"62977:TCP"= 62977:TCP:PORT_62977
"46280:TCP"= 46280:TCP:PORT_46280
"33330:TCP"= 33330:TCP:PORT_33330
"29669:TCP"= 29669:TCP:PORT_29669
"48919:TCP"= 48919:TCP:PORT_48919
"19373:TCP"= 19373:TCP:PORT_19373
"40431:TCP"= 40431:TCP:PORT_40431
"49551:TCP"= 49551:TCP:PORT_49551
"35848:TCP"= 35848:TCP:PORT_35848
"30016:TCP"= 30016:TCP:PORT_30016
"43407:TCP"= 43407:TCP:PORT_43407
"47295:TCP"= 47295:TCP:PORT_47295
"27066:TCP"= 27066:TCP:PORT_27066
"41176:TCP"= 41176:TCP:PORT_41176
"51781:TCP"= 51781:TCP:PORT_51781
"5441:TCP"= 5441:TCP:PORT_5441
"40829:TCP"= 40829:TCP:PORT_40829
"19078:TCP"= 19078:TCP:PORT_19078
"28196:TCP"= 28196:TCP:PORT_28196
"10719:TCP"= 10719:TCP:PORT_10719
"26524:TCP"= 26524:TCP:PORT_26524
"63575:TCP"= 63575:TCP:PORT_63575
"32524:TCP"= 32524:TCP:PORT_32524
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [6/23/2009 5:29 PM 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [10/26/2008 10:34 AM 325896]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [10/26/2008 10:33 AM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [10/26/2008 10:33 AM 908568]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [10/26/2008 10:33 AM 298776]
R2 IntuitUpdateService;Intuit Update Service;c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [10/10/2008 5:45 AM 13088]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 2:06 PM 951632]
S3 BW2NDIS5;BW2NDIS5;c:\windows\system32\Drivers\BW2NDIS5.sys –> c:\windows\system32\Drivers\BW2NDIS5.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2009-06-23 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 19:06]
2009-06-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]
2009-06-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1295111268-1439950885-485887587-1003.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-27 00:20]
2009-06-24 c:\windows\Tasks\User_Feed_Synchronization-{848549F4-6A7F-4DF9-8F00-4AA95DFA61BE}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 17:58]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-VSOCheckTask - c:\progra~1\McAfee.com\VSO\mcmnhdlr.exe
HKLM-Run-VirusScan Online - c:\program files\McAfee.com\VSO\mcvsshld.exe
HKLM-Run-OASClnt - c:\program files\McAfee.com\VSO\oasclnt.exe
HKLM-Run-MSKDetectorExe - c:\progra~1\McAfee\SPAMKI~1\MSKDetct.exe
HKLM-Run-MSKAGENTEXE - c:\progra~1\McAfee\SPAMKI~1\MskAgent.exe
HKLM-Run-MPFExe - c:\progra~1\McAfee.com\PERSON~1\MpfTray.exe
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
uSearchMigratedDefaultURL = hxxp://www.google.com/
mStart Page = hxxp://www.google.com
mSearchMigratedDefaultURL = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = 64.136.44.66;64.136.52.66;searchap.untd.com;127.0.0.1;localhost;*microsoft.com;*
windowsupdate.com;*wustat.windows.com;*.pogo.com;*test-speed.com;liveupdate.symantecliveupdate.com;*symantec.com;*.nai.com;*.networkass
ociates.com;*.dir.untd.com;cf.netzero.net;qs.netzero.net;*.prod.untd.com;;*.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: turbotax.com
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-06-24 14:57
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(536)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(2960)
c:\progra~1\WINDOW~2\wmpband.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\windows\system32\wdfmgr.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wbem\unsecapp.exe
c:\progra~1\Yahoo!\MESSEN~1\Ymsgr_tray.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-06-24 15:03 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-24 20:03
Pre-Run: 47,001,452,544 bytes free
Post-Run: 47,145,148,416 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
315 — E O F — 2009-06-13 08:03