This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Registry problems

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

MearsMan,

How do I get my desktop image back?

I'm not sure yet but if I can't find the cause, I'll send you over to the Tech Team when we are done. As I understand it, everything works except for your background picture.

Second question: shouldn't I try to find out why Trend Microvirus and Ad-Aware Ad Watch are still running, when they've been uninstalled? Could this be the cause of all the weird problems I've been having?

Yes. That's why I was trying to get the log that ComboFix produces. Please continue with previous instructions and don't stop it this time.
Tomk, The computer won't let me run this string. It converts it to "C:\Users\Tomas de Torquemada\Desktop\combofix.exe/killall" and tells me "Windows cannot find "':\Users\Tomas' Make sure you typed the name correctly, then try again. (Tomas de Torquemada is the name of my administrator account. I also have another account, which I stopped using, called "Dad's Computer). I also checked the Security Center section of Control Panel. Under Virus Protection it lists Trend Micro antivirus and says "this program reports that it is up to date and that virus scanning is on". When I click on "Show me the antivirus programs on this computer," I get AVG (which is installed and turned off at the moment), and Trend (which is uninstalled yet supposedly turned on). Under Spyware and Other Malware Protection, it reports that Windows Defender is turned on, and lists AVG (off), Lavasoft Ad-Watch Live (uninstalled but supposdly on), Trend (see above), and Windows Defender. It does not list Malwarebytes, which I installed at the recommendation of AVG (which is apparently only a manual scanner). Please advise - thanks again.
MearsMan,

Alright. Let's regroup, get a different scan, and come at this from a different angle.

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
Tomk,

Thanks, here is OTL.Txt: (Extras,Txt in 2nd post)

OTL logfile created on: 7/8/2009 2:03:38 PM - Run 1
OTL by OldTimer - Version 3.0.6.5 Folder = C:\Users\Tomas de Torquemada\Desktop
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.16851)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.87 Gb Total Physical Memory | 1.11 Gb Available Physical Memory | 59.51% Memory free
3.96 Gb Paging File | 3.18 Gb Available in Paging File | 80.44% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 289.31 Gb Total Space | 259.10 Gb Free Space | 89.56% Space Free | Partition Type: NTFS
Drive D: | 8.78 Gb Total Space | 0.76 Gb Free Space | 8.66% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive J: | 245.73 Mb Total Space | 235.75 Mb Free Space | 95.94% Space Free | Partition Type: FAT

Computer Name: DADSCOMPUTER
Current User Name: Tomas de Torquemada
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2008/05/22 21:49:00 | 00,118,784 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\nvvsvc.exe
PRC - [2009/06/22 09:29:44 | 00,298,776 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgwdsvc.exe
PRC - [2007/01/17 14:20:10 | 00,061,440 | —- | M] (Hewlett-Packard Company) – c:\Program Files\Common Files\LightScribe\LSSrvc.exe
PRC - [2003/06/19 23:25:00 | 00,322,120 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
PRC - [2009/06/22 09:29:46 | 00,486,680 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgrsx.exe
PRC - [2009/06/22 09:29:46 | 00,594,712 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgnsx.exe
PRC - [2009/03/30 16:28:36 | 01,533,808 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
PRC - [2009/06/22 09:29:46 | 00,692,504 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgcsrvx.exe
PRC - [2007/10/18 07:37:04 | 00,386,560 | —- | M] (Conexant Systems, Inc.) – C:\Windows\System32\DRIVERS\xaudio.exe
PRC - [2006/11/02 05:46:02 | 00,143,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\WUDFHost.exe
PRC - [2009/03/02 21:59:26 | 00,247,296 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wbem\wmiprvse.exe
PRC - [2009/03/30 16:28:36 | 00,183,152 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
PRC - [2008/10/29 02:20:29 | 02,923,520 | —- | M] (Microsoft Corporation) – C:\Windows\Explorer.EXE
PRC - [2006/09/28 09:42:24 | 00,065,536 | —- | M] (Hewlett-Packard Company) – C:\hp\support\hpsysdrv.exe
PRC - [2007/02/15 06:59:00 | 00,118,784 | —- | M] (OsdMaestro) – C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
PRC - [2008/01/15 12:26:18 | 04,874,240 | —- | M] (Realtek Semiconductor) – C:\Windows\RtHDVCpl.exe
PRC - [2009/04/11 17:49:55 | 00,148,888 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2009/06/22 09:29:46 | 01,948,440 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgtray.exe
PRC - [2006/11/02 05:45:50 | 00,037,376 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wbem\unsecapp.exe
PRC - [2005/02/02 12:44:24 | 00,061,440 | —- | M] (Hewlett-Packard Company) – C:\hp\kbd\kbd.exe
PRC - [2009/07/08 14:00:26 | 00,513,536 | —- | M] (OldTimer Tools) – C:\Users\Tomas de Torquemada\Desktop\OTL.exe

========== Win32 Services (SafeList) ==========

SRV - [2009/06/22 09:29:44 | 00,298,776 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgwdsvc.exe – (avg8wd [Auto | Running])
SRV - [2008/07/27 14:00:25 | 00,069,632 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2006/11/02 08:35:28 | 00,291,840 | —- | M] (Microsoft Corporation) – C:\Windows\ehome\ehRecvr.exe – (ehRecvr [On_Demand | Stopped])
SRV - [2006/11/02 08:35:29 | 00,131,072 | —- | M] (Microsoft Corporation) – C:\Windows\ehome\ehsched.exe – (ehSched [On_Demand | Stopped])
SRV - [2006/11/02 08:35:29 | 00,013,312 | —- | M] (Microsoft Corporation) – C:\Windows\ehome\ehstart.dll – (ehstart [Auto | Stopped])
SRV - [2006/11/02 05:46:13 | 00,989,696 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wevtsvc.dll – (Eventlog [Auto | Running])
SRV - [2008/06/19 21:18:04 | 00,046,104 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe – (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2007/01/03 21:40:21 | 00,136,120 | —- | M] (Google) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe – (gusvc [On_Demand | Stopped])
SRV - [2004/10/22 06:24:18 | 00,073,728 | —- | M] (Macrovision Corporation) – c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe – (IDriverT [On_Demand | Stopped])
SRV - [2008/06/19 21:17:49 | 00,881,664 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe – (idsvc [Unknown | Stopped])
SRV - [2007/01/17 14:20:10 | 00,061,440 | —- | M] (Hewlett-Packard Company) – c:\Program Files\Common Files\LightScribe\LSSrvc.exe – (LightScribeService [Auto | Running])
SRV - [2003/06/19 23:25:00 | 00,322,120 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE – (MDM [Auto | Running])
SRV - [2008/06/19 21:17:50 | 00,132,096 | —- | M] (Microsoft Corporation) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe – (NetTcpPortSharing [Disabled | Stopped])
SRV - [2008/05/22 21:49:00 | 00,118,784 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\nvvsvc.exe – (nvsvc [Auto | Running])
SRV - [2003/07/28 12:28:22 | 00,089,136 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose [On_Demand | Stopped])
SRV - [2007/03/26 16:21:20 | 00,887,544 | —- | M] (Sonic Solutions) – c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe – (RoxMediaDB9 [On_Demand | Stopped])
SRV - [2007/03/08 21:54:46 | 00,074,656 | —- | M] (MicroVision Development, Inc.) – c:\Program Files\Common Files\SureThing Shared\stllssvr.exe – (stllssvr [On_Demand | Stopped])
SRV - [2007/09/02 07:03:50 | 00,265,912 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Defender\mpsvc.dll – (WinDefend [Auto | Stopped])
SRV - [2009/03/30 16:28:36 | 01,533,808 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE – (wlidsvc [Auto | Running])
SRV - [2006/11/02 08:36:04 | 00,895,488 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Player\wmpnetwk.exe – (WMPNetworkSvc [On_Demand | Stopped])
SRV - [2007/10/18 07:37:04 | 00,386,560 | —- | M] (Conexant Systems, Inc.) – C:\Windows\System32\DRIVERS\xaudio.exe – (XAudioService [Auto | Running])

========== Driver Services (SafeList) ==========

DRV - [2006/11/02 05:51:38 | 00,420,968 | —- | M] (Adaptec, Inc.) – C:\Windows\system32\drivers\adp94xx.sys – (adp94xx [Disabled | Stopped])
DRV - [2006/11/02 05:51:32 | 00,297,576 | —- | M] (Adaptec, Inc.) – C:\Windows\system32\drivers\adpahci.sys – (adpahci [Disabled | Stopped])
DRV - [2006/11/02 05:50:35 | 00,098,408 | —- | M] (Adaptec, Inc.) – C:\Windows\system32\drivers\adpu160m.sys – (adpu160m [Disabled | Stopped])
DRV - [2006/11/02 05:51:00 | 00,147,048 | —- | M] (Adaptec, Inc.) – C:\Windows\system32\drivers\adpu320.sys – (adpu320 [Disabled | Stopped])
DRV - [2006/11/02 05:50:11 | 00,071,272 | —- | M] (Adaptec, Inc.) – C:\Windows\system32\drivers\djsvs.sys – (aic78xx [Disabled | Stopped])
DRV - [2006/11/02 05:49:20 | 00,014,952 | —- | M] (Acer Laboratories Inc.) – C:\Windows\system32\drivers\aliide.sys – (aliide [Disabled | Stopped])
DRV - [2006/11/02 05:50:09 | 00,067,688 | —- | M] (Adaptec, Inc.) – C:\Windows\system32\drivers\arc.sys – (arc [Disabled | Stopped])
DRV - [2006/11/02 05:50:10 | 00,067,688 | —- | M] (Adaptec, Inc.) – C:\Windows\system32\drivers\arcsas.sys – (arcsas [Disabled | Stopped])
DRV - [2009/06/22 09:30:11 | 00,327,688 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\Drivers\avgldx86.sys – (AvgLdx86 [System | Running])
DRV - [2009/06/22 09:30:10 | 00,027,784 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\Drivers\avgmfx86.sys – (AvgMfx86 [System | Running])
DRV - [2009/06/22 09:30:17 | 00,108,552 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\Drivers\avgtdix.sys – (AvgTdiX [System | Running])
DRV - [2006/11/02 04:24:45 | 00,013,568 | —- | M] (Brother Industries, Ltd.) – C:\Windows\system32\drivers\brfiltlo.sys – (BrFiltLo [On_Demand | Stopped])
DRV - [2006/11/02 04:24:46 | 00,005,248 | —- | M] (Brother Industries, Ltd.) – C:\Windows\system32\drivers\brfiltup.sys – (BrFiltUp [On_Demand | Stopped])
DRV - [2006/11/02 04:25:24 | 00,071,808 | —- | M] (Brother Industries Ltd.) – C:\Windows\system32\drivers\brserid.sys – (Brserid [Disabled | Stopped])
DRV - [2006/11/02 04:24:44 | 00,062,336 | —- | M] (Brother Industries Ltd.) – C:\Windows\system32\drivers\brserwdm.sys – (BrSerWdm [Disabled | Stopped])
DRV - [2006/11/02 04:24:44 | 00,012,160 | —- | M] (Brother Industries Ltd.) – C:\Windows\system32\drivers\brusbmdm.sys – (BrUsbMdm [Disabled | Stopped])
DRV - [2006/11/02 04:24:47 | 00,011,904 | —- | M] (Brother Industries Ltd.) – C:\Windows\system32\drivers\brusbser.sys – (BrUsbSer [On_Demand | Stopped])
DRV - [2006/11/02 05:49:28 | 00,016,488 | —- | M] (CMD Technology, Inc.) – C:\Windows\system32\drivers\cmdide.sys – (cmdide [Disabled | Stopped])
DRV - [2006/11/02 03:30:54 | 00,117,760 | —- | M] (Intel Corporation) – C:\Windows\System32\DRIVERS\E1G60I32.sys – (E1G60 [On_Demand | Stopped])
DRV - [2006/11/02 05:51:34 | 00,316,520 | —- | M] (Emulex) – C:\Windows\system32\drivers\elxstor.sys – (elxstor [Disabled | Stopped])
DRV - [2006/11/02 05:50:10 | 00,037,480 | —- | M] (Hewlett-Packard Company) – C:\Windows\system32\drivers\hpcisss.sys – (HpCISSs [Disabled | Stopped])
DRV - [2008/05/08 05:03:18 | 00,980,992 | —- | M] (Conexant Systems, Inc.) – C:\Windows\System32\DRIVERS\HSX_DP.sys – (HSF_DP [On_Demand | Running])
DRV - [2008/05/08 05:05:18 | 00,266,752 | —- | M] (Conexant Systems, Inc.) – C:\Windows\System32\DRIVERS\HSXHWBS2.sys – (HSXHWBS2 [On_Demand | Running])
DRV - [2006/11/02 05:51:25 | 00,232,040 | —- | M] (Intel Corporation) – C:\Windows\system32\drivers\iastorv.sys – (iaStorV [Disabled | Stopped])
DRV - [2006/11/02 05:50:17 | 00,041,576 | —- | M] (Intel Corp./ICP vortex GmbH) – C:\Windows\system32\drivers\iirsp.sys – (iirsp [Disabled | Stopped])
DRV - [2009/02/11 12:38:14 | 02,324,512 | —- | M] (Realtek Semiconductor Corp.) – C:\Windows\System32\drivers\RTKVHDA.sys – (IntcAzAudAddService [On_Demand | Running])
DRV - [2006/11/02 05:50:07 | 00,035,944 | —- | M] (Integrated Technology Express, Inc.) – C:\Windows\system32\drivers\iteatapi.sys – (iteatapi [Disabled | Stopped])
DRV - [2006/11/02 05:50:09 | 00,035,944 | —- | M] (Integrated Technology Express, Inc.) – C:\Windows\system32\drivers\iteraid.sys – (iteraid [Disabled | Stopped])
DRV - [2009/04/21 22:36:30 | 00,064,160 | —- | M] (Lavasoft AB) – C:\Windows\system32\DRIVERS\Lbd.sys – (Lbd [Boot | Running])
DRV - [2006/11/02 05:50:04 | 00,065,640 | —- | M] (LSI Logic) – C:\Windows\system32\drivers\lsi_fc.sys – (LSI_FC [Disabled | Stopped])
DRV - [2006/11/02 05:50:05 | 00,065,640 | —- | M] (LSI Logic) – C:\Windows\system32\drivers\lsi_sas.sys – (LSI_SAS [Disabled | Stopped])
DRV - [2006/11/02 05:50:10 | 00,065,640 | —- | M] (LSI Logic) – C:\Windows\system32\drivers\lsi_scsi.sys – (LSI_SCSI [Disabled | Stopped])
DRV - [2006/06/19 10:26:58 | 00,012,672 | —- | M] (Conexant) – C:\Windows\System32\DRIVERS\mdmxsdk.sys – (mdmxsdk [Auto | Running])
DRV - [2006/11/02 05:49:53 | 00,028,776 | —- | M] (LSI Logic Corporation) – C:\Windows\system32\drivers\megasas.sys – (megasas [Disabled | Stopped])
DRV - [2006/11/02 05:49:59 | 00,033,384 | —- | M] (LSI Logic Corporation) – C:\Windows\system32\drivers\mraid35x.sys – (Mraid35x [Disabled | Stopped])
DRV - [2006/11/02 05:50:19 | 00,045,160 | —- | M] (IBM Corporation) – C:\Windows\system32\drivers\nfrd960.sys – (nfrd960 [Disabled | Stopped])
DRV - [2006/11/02 03:36:50 | 00,020,608 | —- | M] (N-trig Innovative Technologies) – C:\Windows\system32\drivers\ntrigdigi.sys – (ntrigdigi [Disabled | Stopped])
DRV - [2007/05/04 02:29:10 | 01,065,384 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\DRIVERS\nvmfdx32.sys – (NVENETFD [On_Demand | Running])
DRV - [2008/05/22 21:49:00 | 07,465,312 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\DRIVERS\nvlddmkm.sys – (nvlddmkm [On_Demand | Running])
DRV - [2006/11/02 05:50:24 | 00,088,680 | —- | M] (NVIDIA Corporation) – C:\Windows\system32\drivers\nvraid.sys – (nvraid [Disabled | Stopped])
DRV - [2006/11/02 05:50:13 | 00,040,040 | —- | M] (NVIDIA Corporation) – C:\Windows\system32\drivers\nvstor.sys – (nvstor [Disabled | Stopped])
DRV - [2007/10/26 18:51:24 | 00,110,624 | —- | M] (NVIDIA Corporation) – C:\Windows\system32\drivers\nvstor32.sys – (nvstor32 [Boot | Running])
DRV - [2005/12/12 13:27:00 | 00,019,072 | —- | M] (Hewlett-Packard Company) – C:\Windows\System32\DRIVERS\PS2.sys – (Ps2 [On_Demand | Stopped])
DRV - [2007/02/02 06:00:00 | 00,043,528 | —- | M] (Sonic Solutions) – C:\Windows\System32\Drivers\PxHelp20.sys – (PxHelp20 [Boot | Running])
DRV - [2006/11/02 05:51:45 | 00,900,712 | —- | M] (QLogic Corporation) – C:\Windows\system32\drivers\ql2300.sys – (ql2300 [Disabled | Stopped])
DRV - [2006/11/02 05:50:35 | 00,106,088 | —- | M] (QLogic Corporation) – C:\Windows\system32\drivers\ql40xx.sys – (ql40xx [Disabled | Stopped])
DRV - [2006/11/02 02:37:21 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\Windows\System32\drivers\secdrv.sys – (secdrv [Auto | Running])
DRV - [2006/11/02 05:50:10 | 00,038,504 | —- | M] (Silicon Integrated Systems Corp.) – C:\Windows\system32\drivers\sisraid2.sys – (SiSRaid2 [Disabled | Stopped])
DRV - [2006/11/02 05:50:16 | 00,071,784 | —- | M] (Silicon Integrated Systems) – C:\Windows\system32\drivers\sisraid4.sys – (SiSRaid4 [Disabled | Stopped])
DRV - [2006/11/02 05:50:05 | 00,035,944 | —- | M] (LSI Logic) – C:\Windows\system32\drivers\symc8xx.sys – (Symc8xx [Disabled | Stopped])
DRV - [2006/11/02 05:49:56 | 00,031,848 | —- | M] (LSI Logic) – C:\Windows\system32\drivers\sym_hi.sys – (Sym_hi [Disabled | Stopped])
DRV - [2006/11/02 05:50:03 | 00,034,920 | —- | M] (LSI Logic) – C:\Windows\system32\drivers\sym_u3.sys – (Sym_u3 [Disabled | Stopped])
DRV - [2006/11/02 05:51:25 | 00,235,112 | —- | M] (ULi Electronics Inc.) – C:\Windows\system32\drivers\uliahci.sys – (uliahci [Disabled | Stopped])
DRV - [2006/11/02 05:50:35 | 00,098,408 | —- | M] (Promise Technology, Inc.) – C:\Windows\system32\drivers\ulsata.sys – (UlSata [Disabled | Stopped])
DRV - [2006/11/02 05:50:45 | 00,115,816 | —- | M] (Promise Technology, Inc.) – C:\Windows\system32\drivers\ulsata2.sys – (ulsata2 [Disabled | Stopped])
DRV - [2006/11/02 05:49:30 | 00,017,512 | —- | M] (VIA Technologies, Inc.) – C:\Windows\system32\drivers\viaide.sys – (viaide [Disabled | Stopped])
DRV - [2006/11/02 05:50:41 | 00,112,232 | —- | M] (VIA Technologies Inc.,Ltd) – C:\Windows\system32\drivers\vsmraid.sys – (vsmraid [Disabled | Stopped])
DRV - [2008/05/08 05:04:16 | 00,661,504 | —- | M] (Conexant Systems, Inc.) – C:\Windows\System32\DRIVERS\HSX_CNXT.sys – (winachsf [On_Demand | Running])
DRV - [2007/10/18 07:36:54 | 00,008,704 | —- | M] (Conexant Systems, Inc.) – C:\Windows\System32\DRIVERS\xaudio.sys – (XAudio [Auto | Running])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://broadband.zoomtown.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://broadband.zoomtown.com
IE - URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.catholicculture.org/culture/liturgicalyear/"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5
FF - prefs.js..extensions.enabledItems: avg@igeared:2.506.014.001
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: {3713a489-0634-4472-8456-dc7abd7eba00}:1.2.2
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.11

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox [2009/06/22 09:29:44 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG8\Toolbar\Firefox\avg@igeared [2009/06/22 09:30:08 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/06/27 20:57:42 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/06/23 07:21:00 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/06/23 07:21:00 | 00,000,000 | —D | M]

[2008/08/31 14:26:28 | 00,000,000 | —D | M] – C:\Users\Tomas de Torquemada\AppData\Roaming\mozilla\Extensions
[2008/08/31 14:26:28 | 00,000,000 | —D | M] – C:\Users\Tomas de Torquemada\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/07/07 17:56:03 | 00,000,000 | —D | M] – C:\Users\Tomas de Torquemada\AppData\Roaming\mozilla\Firefox\Profiles\6ar7u071.default\extensions
[2009/06/28 10:06:48 | 00,000,000 | —D | M] – C:\Users\Tomas de Torquemada\AppData\Roaming\mozilla\Firefox\Profiles\6ar7u071.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/06/21 22:47:49 | 00,000,000 | —D | M] – C:\Users\Tomas de Torquemada\AppData\Roaming\mozilla\Firefox\Profiles\6ar7u071.default\extensions\{3713a489-0634-4472-8456-dc7abd7eba00}
[2009/07/07 17:56:03 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/06/23 07:21:00 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/04/11 17:50:51 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/06/23 07:20:58 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/06/23 07:20:58 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/04/11 17:49:56 | 00,410,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2009/06/23 07:20:59 | 00,065,528 | —- | M] (mozilla.org) – C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2007/03/22 19:23:30 | 00,017,248 | —- | M] (Microsoft Corporation) – C:\Program Files\mozilla firefox\plugins\NPOFFICE.DLL
[2009/02/27 12:13:42 | 00,103,792 | —- | M] (Adobe Systems Inc.) – C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2007/10/25 06:14:11 | 00,131,072 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2007/10/25 06:14:11 | 00,131,072 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2007/10/25 06:14:12 | 00,131,072 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2007/10/25 06:14:12 | 00,131,072 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2007/10/25 06:14:12 | 00,131,072 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2007/10/25 06:14:12 | 00,131,072 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2007/10/25 06:14:12 | 00,131,072 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll
[2009/06/09 22:10:16 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/06/09 22:10:16 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/06/22 09:32:53 | 00,001,489 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\avg_igeared.xml
[2009/06/09 22:10:16 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/06/09 22:10:16 | 00,002,343 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/06/09 22:10:16 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/06/09 22:10:16 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml

O1 HOSTS File: (761 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [KBD] C:\HP\KBD\KbdStub.EXE ()
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [OsdMaestro] C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe (OsdMaestro)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Launcher] C:\Windows\SMINST\launcher.exe (soft thinks)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskmgr = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in )
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.200.1 192.168.200.1
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\microsoft shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\microsoft shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/04/24 14:36:00 | 00,000,074 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\Windows\System32\lsdelete.exe ()

========== Files/Folders - Created Within 30 Days ==========

[2009/07/08 14:00:13 | 00,513,536 | —- | C] (OldTimer Tools) – C:\Users\Tomas de Torquemada\Desktop\OTL.exe
[2009/07/08 12:21:36 | 00,026,624 | —- | C] () – C:\Users\Tomas de Torquemada\Desktop\Barack Hussein Obama.doc
[2009/07/08 10:52:23 | 03,046,728 | —- | C] () – C:\Users\Tomas de Torquemada\Desktop\ComboFix.exe
[2009/07/07 08:55:30 | 00,000,000 | —D | C] – C:\Qoobox
[2009/07/07 08:55:27 | 00,320,000 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cmd.execf
[2009/07/07 08:55:20 | 00,000,000 | —D | C] – C:\32788R22FWJFW
[2009/07/06 12:43:18 | 00,000,000 | —D | C] – C:\Program Files\VS Revo Group
[2009/07/06 12:33:50 | 00,000,000 | —D | C] – C:\Rooter$
[2009/06/30 17:55:24 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/06/29 16:34:00 | 00,000,000 | —D | C] – C:\Windows\Sun
[2009/06/28 01:44:39 | 00,000,000 | —D | C] – C:\PerfLogs
[2009/06/27 22:24:01 | 00,000,000 | —D | C] – C:\b144cf093e9e7c9bcf1b
[2009/06/27 20:56:27 | 03,596,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.dll
[2009/06/27 20:56:27 | 00,671,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2009/06/27 20:56:27 | 00,389,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2009/06/27 20:56:26 | 06,066,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieframe.dll
[2009/06/27 20:56:25 | 01,159,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\urlmon.dll
[2009/06/27 20:56:24 | 00,827,392 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wininet.dll
[2009/06/27 20:56:24 | 00,459,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2009/06/27 20:56:24 | 00,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2009/06/27 20:56:24 | 00,347,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtmsft.dll
[2009/06/27 20:56:24 | 00,268,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iertutil.dll
[2009/06/27 20:56:24 | 00,102,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\occache.dll
[2009/06/27 20:56:23 | 01,830,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2009/06/27 20:56:23 | 00,477,696 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmled.dll
[2009/06/27 20:56:23 | 00,230,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2009/06/27 20:56:23 | 00,214,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxtrans.dll
[2009/06/27 20:56:23 | 00,124,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\advpack.dll
[2009/06/27 20:56:23 | 00,078,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieencode.dll
[2009/06/27 20:56:23 | 00,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\admparse.dll
[2009/06/27 20:56:23 | 00,063,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardie.dll
[2009/06/27 20:56:23 | 00,027,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2009/06/27 20:56:22 | 01,383,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2009/06/27 20:56:22 | 00,383,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2009/06/27 20:56:22 | 00,180,736 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2009/06/27 20:56:22 | 00,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieakui.dll
[2009/06/27 20:56:22 | 00,070,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2009/06/27 20:56:22 | 00,056,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2009/06/27 20:56:22 | 00,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtmler.dll
[2009/06/27 20:56:22 | 00,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pngfilt.dll
[2009/06/27 20:56:22 | 00,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2009/06/27 20:56:22 | 00,026,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2009/06/25 17:32:26 | 00,000,000 | —D | C] – C:\Program Files\Microsoft
[2009/06/24 22:55:48 | 00,105,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
[2009/06/24 22:55:48 | 00,097,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardapi.dll
[2009/06/24 22:55:47 | 00,622,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardagt.exe
[2009/06/24 22:55:47 | 00,043,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHostProxy.dll
[2009/06/24 22:55:47 | 00,037,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardcpl.cpl
[2009/06/24 22:55:47 | 00,011,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardres.dll
[2009/06/24 22:55:46 | 00,781,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationNative_v0300.dll
[2009/06/24 22:55:43 | 00,326,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHost.exe
[2009/06/24 22:44:06 | 00,096,760 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dfshim.dll
[2009/06/24 22:44:00 | 00,282,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscoree.dll
[2009/06/24 22:43:58 | 00,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netfxperf.dll
[2009/06/24 22:43:33 | 00,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscorier.dll
[2009/06/24 22:43:24 | 00,083,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscories.dll
[2009/06/24 22:36:32 | 00,696,832 | —- | C] (Microsoft Corporation) – C:\Windows\System32\localspl.dll
[2009/06/24 22:36:28 | 02,028,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2009/06/24 22:35:05 | 00,788,992 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rpcrt4.dll
[2009/06/23 08:44:18 | 00,000,000 | -H-D | C] – C:\$AVG8.VAULT$
[2009/06/22 17:27:40 | 00,000,000 | —D | C] – C:\Users\Tomas de Torquemada\Desktop\My Documents
[2009/06/22 16:58:35 | 00,002,044 | —- | C] () – C:\Users\Tomas de Torquemada\Desktop\Microsoft Office Excel 2003.lnk
[2009/06/22 16:58:28 | 00,002,609 | —- | C] () – C:\Users\Tomas de Torquemada\Desktop\Microsoft Office Word 2003.lnk
[2009/06/22 16:58:19 | 00,002,633 | —- | C] () – C:\Users\Tomas de Torquemada\Desktop\Microsoft Office Outlook 2003.lnk
[2009/06/22 09:32:53 | 00,000,000 | —D | C] – C:\Users\Tomas de Torquemada\AppData\Local\AVG Security Toolbar
[2009/06/22 09:30:18 | 00,011,952 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\avgrsstx.dll
[2009/06/22 09:30:17 | 00,108,552 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgtdix.sys
[2009/06/22 09:30:11 | 00,327,688 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2009/06/22 09:30:10 | 37,904,461 | —- | C] () – C:\Windows\System32\drivers\Avg\incavi.avm
[2009/06/22 09:30:10 | 06,061,540 | —- | C] () – C:\Windows\System32\drivers\Avg\avi7.avg
[2009/06/22 09:30:10 | 00,463,779 | —- | C] () – C:\Windows\System32\drivers\Avg\miniavi.avg
[2009/06/22 09:30:10 | 00,027,784 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgmfx86.sys
[2009/06/22 09:30:10 | 00,016,302 | —- | C] () – C:\Windows\System32\drivers\Avg\microavi.avg
[2009/06/22 09:30:10 | 00,000,000 | —D | C] – C:\Windows\System32\drivers\Avg
[2009/06/22 09:30:08 | 00,000,000 | —D | C] – C:\ProgramData\AVG Security Toolbar
[2009/06/22 09:29:44 | 00,000,000 | —D | C] – C:\Program Files\AVG
[2009/06/22 09:05:33 | 00,000,000 | —D | C] – C:\Users\Tomas de Torquemada\AppData\Local\Microsoft Games
[2009/06/13 21:14:13 | 00,428,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2009/06/13 21:14:11 | 00,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisrndr.ax
[2009/06/13 21:14:10 | 00,292,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisdecd.dll
[2009/06/13 21:14:06 | 01,244,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mcmde.dll
[2009/06/13 21:14:05 | 00,177,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2009/06/13 21:14:05 | 00,068,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Mpeg2Data.ax
[2009/06/13 21:14:04 | 00,080,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSNP.ax
[2009/06/13 21:14:04 | 00,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSDvbNP.ax
[2009/06/10 15:26:15 | 00,000,000 | —D | C] – C:\Users\Tomas de Torquemada\AppData\Roaming\PCToolsFirewallPlus
[2009/06/09 22:19:56 | 00,038,160 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/06/09 22:19:55 | 00,019,096 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2009/06/09 22:19:54 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/06/09 22:09:51 | 00,001,744 | —- | C] () – C:\Users\Tomas de Torquemada\Desktop\Mozilla Firefox.lnk
[2009/06/09 18:17:46 | 00,000,000 | —D | C] – C:\ProgramData\TEMP
[2009/06/09 18:17:29 | 00,000,000 | —D | C] – C:\Program Files\Common Files\PC Tools
[2009/06/06 14:30:35 | 00,000,213 | —- | C] () – C:\Windows\Quicken.ini
[2009/04/08 17:34:21 | 00,000,083 | —- | C] () – C:\Windows\forminfo.ini
[2007/10/04 18:25:42 | 00,077,824 | —- | C] () – C:\Windows\System32\hpzids01.dll
[2007/07/29 12:53:54 | 00,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2007/04/24 14:04:59 | 00,102,400 | —- | C] () – C:\Windows\System32\pywintypes24.dll
[2007/04/24 14:04:58 | 00,327,680 | —- | C] () – C:\Windows\System32\pythoncom24.dll
[2007/03/06 04:47:24 | 00,000,000 | —- | C] () – C:\Windows\System32\px.ini
[2007/01/12 10:07:48 | 00,520,192 | —- | C] () – C:\Windows\System32\CddbPlaylist2Roxio.dll
[2007/01/12 10:07:48 | 00,204,800 | —- | C] () – C:\Windows\System32\CddbFileTaggerRoxio.dll
[2006/11/02 08:35:32 | 00,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 06:23:31 | 00,000,240 | —- | C] () – C:\Windows\win.ini
[2006/11/02 06:23:31 | 00,000,219 | —- | C] () – C:\Windows\system.ini
[2006/11/02 03:40:29 | 00,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2003/01/07 15:05:08 | 00,002,695 | —- | C] () – C:\Windows\System32\OUTLPERF.INI

========== Files - Modified Within 30 Days ==========

[2009/07/08 14:00:26 | 00,513,536 | —- | M] (OldTimer Tools) – C:\Users\Tomas de Torquemada\Desktop\OTL.exe
[2009/07/08 13:20:13 | 00,003,456 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/07/08 13:20:13 | 00,003,456 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/07/08 12:49:48 | 00,026,624 | —- | M] () – C:\Users\Tomas de Torquemada\Desktop\Barack Hussein Obama.doc
[2009/07/08 12:11:41 | 00,002,609 | —- | M] () – C:\Users\Tomas de Torquemada\Desktop\Microsoft Office Word 2003.lnk
[2009/07/08 11:30:48 | 00,002,633 | —- | M] () – C:\Users\Tomas de Torquemada\Desktop\Microsoft Office Outlook 2003.lnk
[2009/07/08 11:16:29 | 02,730,540 | -H– | M] () – C:\Users\Tomas de Torquemada\AppData\Local\IconCache.db
[2009/07/08 10:52:55 | 03,046,728 | —- | M] () – C:\Users\Tomas de Torquemada\Desktop\ComboFix.exe
[2009/07/08 10:21:24 | 37,904,461 | —- | M] () – C:\Windows\System32\drivers\Avg\incavi.avm
[2009/07/08 10:20:12 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2009/07/07 18:59:28 | 00,016,302 | —- | M] () – C:\Windows\System32\drivers\Avg\microavi.avg
[2009/07/07 09:10:18 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2009/07/07 08:55:27 | 00,320,000 | —- | M] (Microsoft Corporation) – C:\Windows\System32\cmd.execf
[2009/07/06 22:36:00 | 00,000,472 | —- | M] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2009/06/30 18:49:26 | 00,463,779 | —- | M] () – C:\Windows\System32\drivers\Avg\miniavi.avg
[2009/06/25 17:44:59 | 00,720,952 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2009/06/25 17:44:59 | 00,621,314 | —- | M] () – C:\Windows\System32\perfh009.dat
[2009/06/25 17:44:59 | 00,104,662 | —- | M] () – C:\Windows\System32\perfc009.dat
[2009/06/25 08:32:48 | 00,433,768 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2009/06/24 23:10:22 | 00,000,240 | —- | M] () – C:\Windows\win.ini
[2009/06/24 22:55:41 | 47,251,456 | —- | M] () – C:\Windows\ocsetup_install_NetFx3.etl
[2009/06/24 22:55:41 | 00,327,680 | —- | M] () – C:\Windows\ocsetup_cbs_install_NetFx3.perf
[2009/06/24 22:55:41 | 00,065,536 | —- | M] () – C:\Windows\ocsetup_cbs_install_NetFx3.dpx
[2009/06/22 16:58:35 | 00,002,044 | —- | M] () – C:\Users\Tomas de Torquemada\Desktop\Microsoft Office Excel 2003.lnk
[2009/06/22 09:30:18 | 00,011,952 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\avgrsstx.dll
[2009/06/22 09:30:17 | 00,108,552 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgtdix.sys
[2009/06/22 09:30:11 | 00,327,688 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgldx86.sys
[2009/06/22 09:30:10 | 06,061,540 | —- | M] () – C:\Windows\System32\drivers\Avg\avi7.avg
[2009/06/22 09:30:10 | 00,027,784 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Windows\System32\drivers\avgmfx86.sys
[2009/06/17 11:27:56 | 00,038,160 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/06/17 11:27:44 | 00,019,096 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2009/06/09 22:09:51 | 00,001,744 | —- | M] () – C:\Users\Tomas de Torquemada\Desktop\Mozilla Firefox.lnk

========== LOP Check ==========

[2009/06/22 08:52:14 | 00,000,000 | —D | M] – C:\Users\Tomas de Torquemada\AppData\Roaming
[2008/02/18 10:42:38 | 00,000,000 | —D | M] – C:\Users\Tomas de Torquemada\AppData\Roaming\Intuit
[2006/11/02 08:37:34 | 00,000,000 | —D | M] – C:\Users\Tomas de Torquemada\AppData\Roaming\Media Center Programs
[2009/06/10 15:26:20 | 00,000,000 | —D | M] – C:\Users\Tomas de Torquemada\AppData\Roaming\PCToolsFirewallPlus
[2008/03/08 08:50:11 | 00,000,000 | —D | M] – C:\Users\Tomas de Torquemada\AppData\Roaming\WinBatch
[2009/07/06 22:36:00 | 00,000,472 | —- | M] () – C:\Windows\Tasks\Ad-Aware Update (Weekly).job
[2009/07/07 09:10:18 | 00,000,006 | -H– | M] () – C:\Windows\Tasks\SA.DAT
[2009/07/07 09:09:24 | 00,032,644 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:1CA73D29
@Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:C31F31E6
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:7E95B6FD
< End of report >
And here is Extras.Txt:

OTL Extras logfile created on: 7/8/2009 2:03:38 PM - Run 1
OTL by OldTimer - Version 3.0.6.5 Folder = C:\Users\Tomas de Torquemada\Desktop
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.16851)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.87 Gb Total Physical Memory | 1.11 Gb Available Physical Memory | 59.51% Memory free
3.96 Gb Paging File | 3.18 Gb Available in Paging File | 80.44% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 289.31 Gb Total Space | 259.10 Gb Free Space | 89.56% Space Free | Partition Type: NTFS
Drive D: | 8.78 Gb Total Space | 0.76 Gb Free Space | 8.66% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive J: | 245.73 Mb Total Space | 235.75 Mb Free Space | 95.94% Space Free | Partition Type: FAT

Computer Name: DADSCOMPUTER
Current User Name: Tomas de Torquemada
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 1
"InternetSettingsDisableNotify" = 1
"AutoUpdateDisableNotify" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
File not found – C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{0CFD3BAF-9F4D-4D70-BD0B-638EA2504C25}" = PSSWCORE
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{10A44844-4465-456E-8C97-80BDD4F68845}" = Windows Live ID Sign-in Assistant
"{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}" = Roxio Creator EasyArchive
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{2DBE41DD-2129-4C65-A3D3-5647236A60F3}" = Quicken 2005
"{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}" = Rhapsody Player Engine
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Roxio Activation Module
"{55979C41-7D6A-49CC-B591-64AC1BBE2C8B}" = HP Picasso Media Center Add-In
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{6AF49698-949A-4C89-9B31-041D2CCB5FBD}" = muvee autoProducer 6.0
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{74EC78BC-B379-4E29-9006-8F161DCAABA6}" = Apple Software Update
"{75E71ADD-042C-4F30-BFAC-A9EC42351313}" = Python 2.4.3
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8CEA85DE-955B-4BF4-87F2-0BAA62821633}" = HP Photosmart Essential2.5
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{938B1CD7-7C60-491E-AA90-1F1888168240}" = Roxio MyDVD Basic v9
"{95A890AA-B3B1-44B6-9C18-A8F7AB3EE7FC}" = QuickTime
"{9DBA770F-BF73-4D39-B1DF-6035D95268FC}" = HP Customer Feedback
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{AE3CF174-872C-46C6-B9F6-C0593F3BC7B8}" = Microsoft Office Live Add-in 1.4
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator Basic v9
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE386A4E-D0DA-4208-8235-BCE43275C694}" = LightScribe 1.4.142.1
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player Plugin
"AVG8Uninstall" = AVG Free 8.5
"CCleaner" = CCleaner (remove only)
"CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200C14F1" = Soft Data Fax Modem with SmartCP
"HijackThis" = HijackThis 2.0.2
"HP Photosmart Essential" = HP Photosmart Essential 2.0
"InstallShield_{2DBE41DD-2129-4C65-A3D3-5647236A60F3}" = Quicken 2005
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.0.11)" = Mozilla Firefox (3.0.11)
"NVIDIA Drivers" = NVIDIA Drivers
"OsdMaestro" = HP On-Screen Cap/Num/Scroll Lock Indicator
"PC-Doctor 5 for Windows" = Hardware Diagnostic Tools
"Picasa2" = Picasa 2
"RealPlayer 6.0" = RealPlayer
"Revo Uninstaller" = Revo Uninstaller 1.83
"Rhapsody" = Rhapsody
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"WildTangent hpdesktop Master Uninstall" = My HP Games
"ZoomTown" = ZoomTown Software

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 7/6/2009 12:45:01 PM | Computer Name = DadsComputer | Source = VSS | ID = 8194
Description =

Error - 7/6/2009 12:45:01 PM | Computer Name = DadsComputer | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

Error - 7/6/2009 12:45:05 PM | Computer Name = DadsComputer | Source = Application Error | ID = 1000
Description = Faulting application Ad-AwareAE.exe, version 8.0.0.0, time stamp 0x48bf6ca2,
faulting module mia.lib, version 6.0.6000.16386, time stamp 0x4549bdc9, exception
code 0xc0000135, fault offset 0x00008fc7, process id 0x3e0, application start time
0x01c9fe591d19f9a7.

Error - 7/6/2009 5:08:52 PM | Computer Name = DadsComputer | Source = Application Error | ID = 1000
Description = Faulting application GooredFix.exe, version 2.0.0.342, time stamp
0x4a4e5044, faulting module ntdll.dll, version 6.0.6000.16386, time stamp 0x4549bdc9,
exception code 0xc0000005, fault offset 0x00061ad5, process id 0x590, application
start time 0x01c9fe7de86e7d20.

Error - 7/6/2009 5:16:31 PM | Computer Name = DadsComputer | Source = Application Error | ID = 1000
Description = Faulting application GooredFix.exe, version 2.0.0.342, time stamp
0x4a4e5044, faulting module ntdll.dll, version 6.0.6000.16386, time stamp 0x4549bdc9,
exception code 0xc0000005, fault offset 0x00061ad5, process id 0xce0, application
start time 0x01c9fe7f0745c855.

Error - 7/7/2009 9:06:00 AM | Computer Name = DadsComputer | Source = WinDefendRtp | ID = 3003
Description = %%827 Real-Time Protection checkpoint has encountered an error and
failed to start. User: DadsComputer\Tomas de Torquemada Checkpoint ID: 1 Error Code:
0x80070005 Error description: Access is denied.

Error - 7/7/2009 9:10:26 AM | Computer Name = DadsComputer | Source = WinDefendRtp | ID = 3003
Description = %%827 Real-Time Protection checkpoint has encountered an error and
failed to start. User: DadsComputer\Tomas de Torquemada Checkpoint ID: 1 Error Code:
0x80070005 Error description: Access is denied.

Error - 7/8/2009 11:56:31 AM | Computer Name = DadsComputer | Source = WinDefendRtp | ID = 3003
Description = %%827 Real-Time Protection checkpoint has encountered an error and
failed to start. User: DadsComputer\Tomas de Torquemada Checkpoint ID: 1 Error Code:
0x80070005 Error description: Access is denied.

Error - 7/8/2009 1:54:16 PM | Computer Name = DadsComputer | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

Error - 7/8/2009 1:54:16 PM | Computer Name = DadsComputer | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

[ Media Center Events ]
Error - 12/21/2007 8:04:06 PM | Computer Name = DadsComputer | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 3/28/2008 5:32:45 PM | Computer Name = DadsComputer | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 4/18/2008 8:08:47 AM | Computer Name = DadsComputer | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight.

Error - 4/18/2008 6:49:23 PM | Computer Name = DadsComputer | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight.

Error - 5/25/2008 8:04:56 PM | Computer Name = DadsComputer | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight.

Error - 5/31/2008 5:34:13 PM | Computer Name = DadsComputer | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

Error - 6/2/2008 7:26:24 AM | Computer Name = DadsComputer | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight.

Error - 6/7/2008 10:02:54 AM | Computer Name = DadsComputer | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight.

Error - 6/9/2008 7:46:50 AM | Computer Name = DadsComputer | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package MCESpotlight.

Error - 8/28/2008 6:37:16 AM | Computer Name = DadsComputer | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.

[ System Events ]
Error - 7/7/2009 9:06:01 AM | Computer Name = DadsComputer | Source = TermService | ID = 1057
Description =

Error - 7/7/2009 9:06:02 AM | Computer Name = DadsComputer | Source = Service Control Manager | ID = 7000
Description =

Error - 7/7/2009 9:06:02 AM | Computer Name = DadsComputer | Source = Service Control Manager | ID = 7026
Description =

Error - 7/7/2009 9:09:57 AM | Computer Name = DadsComputer | Source = ACPI | ID = 327686
Description = IRQARB: ACPI BIOS does not contain an IRQ for the device in PCI slot
9, function 0. Please contact your system vendor for technical assistance.

Error - 7/7/2009 9:09:57 AM | Computer Name = DadsComputer | Source = ACPI | ID = 327686
Description = IRQARB: ACPI BIOS does not contain an IRQ for the device in PCI slot
11, function 0. Please contact your system vendor for technical assistance.

Error - 7/7/2009 9:10:29 AM | Computer Name = DadsComputer | Source = TermService | ID = 1057
Description =

Error - 7/7/2009 9:10:32 AM | Computer Name = DadsComputer | Source = Service Control Manager | ID = 7000
Description =

Error - 7/7/2009 9:10:32 AM | Computer Name = DadsComputer | Source = Service Control Manager | ID = 7026
Description =

Error - 7/7/2009 9:10:29 PM | Computer Name = DadsComputer | Source = TermService | ID = 1057
Description =

Error - 7/8/2009 10:20:06 AM | Computer Name = DadsComputer | Source = TermService | ID = 1057
Description =


< End of report >
MearsMan,

Double click on OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Processes
explorer.exe

:OTL
DRV - [2009/04/21 22:36:30 | 00,064,160 | —- | M] (Lavasoft AB) – C:\Windows\system32\DRIVERS\Lbd.sys – (Lbd [Boot | Running])
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
[2009/07/06 22:36:00 | 00,000,472 | —- | M] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job

:Files
C:\Program Files\Trend Micro
C:\program files\lavasoft

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL log and a new HJT log.


Please go to http://virusscan.jotti.org , click on Browse, and upload the following file for analysis:

c:\windows\system32\userinit.exe <===this file

Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.

Please do the same for :
c:\windows\explorer.exe <===this file
Tomk, Here is the OTL report (it required the computer to reboot first). I will post a new HJT log in next post. All processes killed ========== PROCESSES ========== No active process named explorer.exe was found! ========== OTL ========== Service\Driver Lbd stopped successfully. Service\Driver Lbd deleted successfully. C:\Windows\System32\DRIVERS\Lbd.sys moved successfully. Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} C:\Windows\Downloaded Program Files\erma.inf moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found. C:\Windows\tasks\Ad-Aware Update (Weekly).job moved successfully. ========== FILES ========== C:\Program Files\Trend Micro\HijackThis\backups moved successfully. C:\Program Files\Trend Micro\HijackThis moved successfully. C:\Program Files\Trend Micro moved successfully. File\Folder C:\program files\lavasoft not found. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Dad's Computer ->Temp folder emptied: 978150 bytes ->Temporary Internet Files folder emptied: 1417774 bytes ->Java cache emptied: 9738232 bytes ->FireFox cache emptied: 32933577 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public User: Tomas de Torquemada ->Temp folder emptied: 34055 bytes ->Temporary Internet Files folder emptied: 742253 bytes ->Java cache emptied: 8548535 bytes ->FireFox cache emptied: 80645734 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes Windows Temp folder emptied: 75474 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 128.85 mb OTL by OldTimer - Version 3.0.6.5 log created on 07082009_145453 Files\Folders moved on Reboot… Registry entries deleted on Reboot…
Tomk,

Here is the new HJT report. I will post the 2 file analyses in a third and final post.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:00:48 PM, on 7/8/2009
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16851)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\hp\kbd\kbd.exe
C:\Windows\system32\SearchFilterHost.exe
C:\_OTL\MovedFiles\07082009_145453\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://broadband.zoomtown.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://broadband.zoomtown.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O13 - Gopher Prefix:
O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone
O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 5463 bytes
Tomk, Scan of C:\windows\system32\userinit.exe: [ArcaVir] 2009-07-08 Found nothing [G DATA] 2009-07-08 Found nothing [A-Squared] 2009-07-08 Found nothing [Ikarus] 2009-07-08 Found nothing [Avast! antivirus] 2009-07-08 Found nothing [Kaspersky Anti-Virus] 2009-07-08 Found nothing [Grisoft AVG Anti-Virus] 2009-07-08 Found nothing [ESET NOD32] 2009-07-08 Found nothing [Avira AntiVir] 2009-07-08 Found nothing [Norman Virus Control] 2009-07-08 Found nothing [Softwin BitDefender] 2009-07-08 Found nothing [Panda Antivirus] 2009-07-08 Found nothing [ClamAV] 2009-07-08 Found nothing [Quick Heal] 2009-07-08 Found nothing [CPsecure] 2009-07-08 Found nothing [Sophos] 2009-07-08 Found nothing [Dr.Web] 2009-07-08 Found nothing [VirusBlokAda VBA32] 2009-07-07 Found nothing [Frisk F-Prot Antivirus] 2009-07-08 Found nothing [VirusBuster] 2009-07-08 Found nothing [F-Secure Anti-Virus] 2009-07-08 Found nothing Scan of c:\windows\explorer.exe: This file has been scanned before. The results for this previous scan are listed below. Filename: explorer.exe Status: Scan finished. 0 out of 20 scanners reported malware. Scan taken on: Mon 1 Jun 2009 19:32:54 (CET) Permalink (Tomk: one scanner, G Data, says "No results available."
MearsMan,

You did fine. I was just concerned that we might have a file infector at work. It looks OK.

Now we are going to try to run ComboFix again. If it squawks, run it anyway. First drag your copy to the recycle bin and we will start fresh.

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Tomk,

Light appeared at end of tunnel! (my desktop image is back). Here are the results of the Combofix scan:

ComboFix 09-07-08.01 - Tomas de Torquemada 07/08/2009 15:43.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1918.1200 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Trend Micro AntiVirus - Virus Protection *On-access scanning enabled* (Updated) {9596F8E6-38C3-4C51-80B9-8C94D2E25B07}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Lavasoft Ad-Watch Live! *enabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Trend Micro AntiVirus - Spyware Protection *enabled* (Updated) {7241C815-3D0F-4059-9AF4-BF225B1D78B9}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\$recycle.bin\S-1-5-21-1008506705-2743244613-1336843627-1000(0)
c:\$recycle.bin\S-1-5-21-1008506705-2743244613-1336843627-500
c:\$recycle.bin\S-1-5-21-2135763593-744632397-750408714-500
c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
c:\windows\Installer\16cdcf.msi
c:\windows\Installer\34731c8.msi

.
((((((((((((((((((((((((( Files Created from 2009-06-08 to 2009-07-08 )))))))))))))))))))))))))))))))
.

2009-07-08 19:47 . 2009-07-08 19:47 ——– d—–w- c:\users\Tomas de Torquemada\AppData\Local\temp
2009-07-08 19:47 . 2009-07-08 19:47 ——– d—–w- c:\users\Dad's Computer\AppData\Local\temp
2009-07-08 18:54 . 2009-07-08 18:54 ——– d—–w- C:\_OTL
2009-07-06 16:43 . 2009-07-06 16:43 ——– d—–w- c:\program files\VS Revo Group
2009-07-06 16:33 . 2009-07-06 16:33 ——– d—–w- C:\Rooter$
2009-06-29 20:34 . 2009-06-29 20:34 ——– d—–w- c:\windows\Sun
2009-06-28 05:44 . 2009-06-28 05:44 ——– d—–w- C:\PerfLogs
2009-06-28 02:24 . 2009-06-28 17:57 ——– d—–w- C:\b144cf093e9e7c9bcf1b
2009-06-26 18:23 . 2009-06-14 20:07 1004800 —-a-w- c:\programdata\AVG Security Toolbar\IEToolbar.dll
2009-06-25 21:32 . 2009-06-25 21:32 ——– d—–w- c:\program files\Microsoft
2009-06-25 02:55 . 2008-06-20 01:18 105016 —-a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-06-25 02:55 . 2008-06-20 01:17 97800 —-a-w- c:\windows\system32\infocardapi.dll
2009-06-25 02:55 . 2008-06-20 01:18 43544 —-a-w- c:\windows\system32\PresentationHostProxy.dll
2009-06-25 02:55 . 2008-06-20 01:17 622080 —-a-w- c:\windows\system32\icardagt.exe
2009-06-25 02:55 . 2008-06-20 01:17 11264 —-a-w- c:\windows\system32\icardres.dll
2009-06-25 02:55 . 2008-06-20 01:18 781344 —-a-w- c:\windows\system32\PresentationNative_v0300.dll
2009-06-25 02:55 . 2008-06-20 01:18 326160 —-a-w- c:\windows\system32\PresentationHost.exe
2009-06-25 02:44 . 2008-07-27 18:00 96760 —-a-w- c:\windows\system32\dfshim.dll
2009-06-25 02:44 . 2008-07-27 18:00 282112 —-a-w- c:\windows\system32\mscoree.dll
2009-06-25 02:43 . 2008-07-27 18:00 41984 —-a-w- c:\windows\system32\netfxperf.dll
2009-06-25 02:43 . 2008-07-27 18:00 158720 —-a-w- c:\windows\system32\mscorier.dll
2009-06-25 02:43 . 2008-07-27 18:00 83968 —-a-w- c:\windows\system32\mscories.dll
2009-06-25 02:36 . 2009-04-23 12:56 696832 —-a-w- c:\windows\system32\localspl.dll
2009-06-25 02:36 . 2009-04-21 12:04 2028032 —-a-w- c:\windows\system32\win32k.sys
2009-06-25 02:35 . 2009-04-23 13:01 788992 —-a-w- c:\windows\system32\rpcrt4.dll
2009-06-23 12:44 . 2009-07-03 03:07 ——– d–h–w- C:\$AVG8.VAULT$
2009-06-22 15:55 . 2009-06-22 15:55 ——– d—–w- c:\users\Dad's Computer\AppData\Local\AVG Security Toolbar
2009-06-22 13:35 . 2009-06-22 13:35 3561743 —-a-w- c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-22 13:32 . 2009-06-22 13:32 ——– d—–w- c:\users\Tomas de Torquemada\AppData\Local\AVG Security Toolbar
2009-06-22 13:30 . 2009-06-22 13:30 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-06-22 13:30 . 2009-06-22 13:30 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-06-22 13:30 . 2009-06-22 13:30 327688 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-22 13:30 . 2009-07-08 14:21 ——– d—–w- c:\windows\system32\drivers\Avg
2009-06-22 13:30 . 2009-06-22 13:30 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-22 13:30 . 2009-06-26 18:23 ——– d—–w- c:\programdata\AVG Security Toolbar
2009-06-22 13:29 . 2009-06-22 13:29 ——– d—–w- c:\program files\AVG
2009-06-22 13:05 . 2009-06-22 13:27 ——– d—–w- c:\users\Tomas de Torquemada\AppData\Local\Microsoft Games
2009-06-18 01:55 . 2009-06-21 20:59 ——– d—–w- c:\users\Tomas de Torquemada\{f3ac81ae-0593-4ff7-90fc-fce7e128dee5}
2009-06-14 01:14 . 2009-04-30 12:42 428032 —-a-w- c:\windows\system32\EncDec.dll
2009-06-14 01:14 . 2009-04-30 12:52 292352 —-a-w- c:\windows\system32\psisdecd.dll
2009-06-14 01:14 . 2009-04-30 12:44 1244672 —-a-w- c:\windows\system32\mcmde.dll
2009-06-12 02:13 . 2009-06-12 02:13 ——– d—–w- c:\users\Dad's Computer\AppData\Roaming\Malwarebytes
2009-06-10 21:45 . 2009-06-10 21:46 ——– d—–w- c:\users\Dad's Computer\AppData\Roaming\PCToolsFirewallPlus
2009-06-10 19:26 . 2009-06-10 19:26 ——– d—–w- c:\users\Tomas de Torquemada\AppData\Roaming\PCToolsFirewallPlus
2009-06-10 02:19 . 2009-06-17 15:27 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-10 02:19 . 2009-06-17 15:27 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-06-10 02:19 . 2009-06-22 13:36 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-06-10 02:01 . 2009-06-10 02:01 ——– d—–w- c:\users\Dad's Computer\AppData\Roaming\PC Tools
2009-06-09 22:17 . 2009-06-22 12:53 ——– d—–w- c:\program files\Common Files\PC Tools

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-28 13:47 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Calendar
2009-06-28 13:47 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Sidebar
2009-06-28 13:47 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Collaboration
2009-06-28 13:47 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-06-28 13:47 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Photo Gallery
2009-06-28 13:47 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Journal
2009-06-28 13:47 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Defender
2009-06-25 21:42 . 2009-06-02 02:35 ——– d—–w- c:\programdata\NVIDIA
2009-06-22 13:28 . 2008-08-31 18:23 ——– d—–w- c:\programdata\avg8
2009-06-14 01:31 . 2007-04-24 18:38 ——– d—–w- c:\program files\Microsoft Works
2009-06-09 21:28 . 2007-04-24 18:49 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-06-09 21:28 . 2007-04-24 18:49 ——– d—–w- c:\programdata\Symantec
2009-06-06 18:36 . 2007-07-29 19:34 ——– d—–w- c:\program files\Quicken
2009-06-06 18:31 . 2007-04-24 18:17 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-06-06 18:30 . 2009-06-06 18:30 ——– d—–w- c:\program files\Common Files\Palo Alto Software
2009-06-06 18:30 . 2009-06-06 18:30 ——– d—–w- c:\program files\Common Files\Intuit
2009-06-06 10:22 . 2009-06-05 18:25 ——– d—–w- c:\programdata\NOS
2009-06-06 10:22 . 2009-06-05 18:25 ——– d—–w- c:\program files\NOS
2009-06-05 18:31 . 2009-06-05 18:31 ——– d—–w- c:\program files\Common Files\Adobe AIR
2009-06-05 18:30 . 2009-06-05 18:30 ——– d—–w- c:\program files\Common Files\Adobe
2009-06-05 18:17 . 2008-02-09 13:02 124152 —-a-w- c:\users\Tomas de Torquemada\AppData\Local\GDIPFONTCACHEV1.DAT
2009-06-05 17:48 . 2009-06-02 12:02 124152 —-a-w- c:\users\Dad's Computer\AppData\Local\GDIPFONTCACHEV1.DAT
2009-06-05 16:28 . 2009-05-19 07:09 ——– d—–w- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-06-05 14:49 . 2009-06-05 14:49 ——– d—–w- c:\program files\Common Files\L&H
2009-06-05 14:49 . 2009-06-05 14:49 ——– d—–w- c:\program files\Microsoft ActiveSync
2009-06-05 14:47 . 2009-06-05 14:47 ——– d—–w- c:\program files\Microsoft.NET
2009-06-04 22:58 . 2009-02-04 03:31 ——– d–h–w- c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-06-04 22:58 . 2007-04-24 18:20 ——– d—–w- c:\programdata\WildTangent
2009-06-04 22:58 . 2009-03-08 01:48 ——– d—–w- c:\program files\CCleaner
2009-06-04 22:56 . 2009-05-13 17:59 ——– d—–w- c:\program files\Microsoft Silverlight
2009-06-04 22:56 . 2007-10-25 10:13 ——– d—–w- c:\programdata\Apple Computer
2009-06-04 22:56 . 2007-10-25 10:12 ——– d—–w- c:\programdata\Apple
2009-06-04 22:56 . 2007-04-24 18:31 ——– d—–w- c:\programdata\Roxio
2009-06-04 22:56 . 2007-04-24 18:25 ——– d—–w- c:\programdata\HP
2009-06-04 22:52 . 2007-07-29 19:33 ——– d—–w- c:\users\Dad's Computer\AppData\Roaming\Intuit
2009-06-02 21:02 . 2007-07-29 17:48 ——– d—–w- c:\users\Dad's Computer\AppData\Roaming\Adobe(671)
2009-06-02 12:05 . 2007-09-02 10:59 ——– d—–w- c:\users\Dad's Computer\AppData\Roaming\Mozilla(681)
2009-06-02 11:53 . 2007-07-29 19:33 ——– d—–w- c:\users\Dad's Computer\AppData\Roaming\Intuit(672)
2009-05-22 16:37 . 2009-05-22 16:37 ——– d—–w- c:\users\Tomas de Torquemada\AppData\Roaming\Malwarebytes
2009-05-22 16:37 . 2009-05-22 16:37 ——– d—–w- c:\programdata\Malwarebytes
2009-05-09 02:48 . 2009-05-09 02:48 766808 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-04-29 02:36 . 2009-04-29 02:36 299352 —-a-w- c:\programdata\Lavasoft\Ad-Aware\update\threatwork.exe
2009-04-24 16:22 . 2009-06-28 00:56 827392 —-a-w- c:\windows\system32\wininet.dll
2009-04-24 16:14 . 2009-06-28 00:56 56320 —-a-w- c:\windows\system32\iesetup.dll
2009-04-24 16:14 . 2009-06-28 00:56 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-04-24 16:11 . 2009-06-28 00:56 72704 —-a-w- c:\windows\system32\admparse.dll
2009-04-24 13:53 . 2009-06-28 00:56 26624 —-a-w- c:\windows\system32\ieUnatt.exe
2009-04-24 12:25 . 2009-06-28 00:56 48128 —-a-w- c:\windows\system32\mshtmler.dll
2009-04-11 21:49 . 2009-04-11 21:50 410984 —-a-w- c:\windows\system32\deploytk.dll
2007-08-25 19:37 . 2007-08-25 19:37 22 –sha-w- c:\windows\SMINST\HPCD.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-14 20:07 1004800 —-a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2007-09-02 1006264]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2006-09-28 65536]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
"OsdMaestro"="c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-11 148888]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-22 1948440]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-23 13539872]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-01-15 4874240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2007-03-07 44168]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{8E28FB53-0613-4605-A2A4-A8D921636135}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{CC72DC5A-C75C-49C7-A3E5-654B4AE2FFC5}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{A0E68D27-0623-4BEA-B02A-3A45AFBA3B8E}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{994D992D-FC82-4B65-B300-AC250F8D453E}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{D3153266-F3C2-423C-80DC-654067BE065C}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{B397EA17-5F85-4598-B491-FF856B065299}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"TCP Query User{8388812E-9B1F-41B9-BEB5-3C6639B98C17}c:\\program files\\real\\realplayer\\realplay.exe"= UDP:c:\program files\real\realplayer\realplay.exe:RealPlayer
"UDP Query User{0E23F119-6E1D-4E34-A043-61D802B6B894}c:\\program files\\real\\realplayer\\realplay.exe"= TCP:c:\program files\real\realplayer\realplay.exe:RealPlayer
"{221A338C-4318-46CC-88B5-1B2CAC7CAEAF}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"TCP Query User{EFBDF2BF-55A4-4304-8CA9-876E5FA83572}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{FA187EC1-9898-49FE-A750-E9F3142C9E02}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"{273876F6-D545-4740-9174-DBF539AA35D6}"= Disabled:UDP:c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe:Spy Sweeper
"{9F2FFF14-4A10-45FE-A14D-A57DAE8443DD}"= Disabled:TCP:c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe:Spy Sweeper
"{FE5BFE4B-F986-442B-8F12-8C168B4E13BF}"= c:\program files\AVG\AVG8\avgnsx.exe:avgnsx.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= c:\program files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [6/22/2009 9:30 AM 327688]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [6/22/2009 9:30 AM 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [6/22/2009 9:29 AM 298776]
R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE [3/30/2009 4:28 PM 1533808]
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-Lavasoft Ad-Aware Service


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://broadband.zoomtown.com
mStart Page = hxxp://broadband.zoomtown.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Tomas de Torquemada\AppData\Roaming\Mozilla\Firefox\Profiles\6ar7u071.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.catholicculture.org/culture/liturgicalyear/
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-08 15:47
Windows 6.0.6000 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Completion time: 2009-07-08 15:49
ComboFix-quarantined-files.txt 2009-07-08 19:49

Pre-Run: 278,333,390,848 bytes free
Post-Run: 278,237,433,856 bytes free

227 — E O F — 2009-06-28 02:21
MearsMan,

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    SecCenter::
    {9596F8E6-38C3-4C51-80B9-8C94D2E25B07}
    {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
    {7241C815-3D0F-4059-9AF4-BF225B1D78B9}
    
    Folder::
    c:\programdata\Lavasoft
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.



Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Tomk,

Here is the new Combofix report. Kaspersky scan to follow in next post. Thanks.

ComboFix 09-07-08.01 - Tomas de Torquemada 07/08/2009 21:26.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1918.1097 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Tomas de Torquemada\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Trend Micro AntiVirus - Virus Protection *On-access scanning enabled* (Updated) {9596F8E6-38C3-4C51-80B9-8C94D2E25B07}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Lavasoft Ad-Watch Live! *enabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Trend Micro AntiVirus - Spyware Protection *enabled* (Updated) {7241C815-3D0F-4059-9AF4-BF225B1D78B9}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\programdata\Lavasoft
c:\programdata\Lavasoft\Ad-Aware\Logs\Service_2009-06-04-15-10-26.log
c:\programdata\Lavasoft\Ad-Aware\Logs\Service_2009-06-05-10-37-23.log
c:\programdata\Lavasoft\Ad-Aware\Logs\Service_2009-06-05-12-47-51.log
c:\programdata\Lavasoft\Ad-Aware\Logs\Service_2009-06-05-12-58-46.log
c:\programdata\Lavasoft\Ad-Aware\Logs\Service_2009-06-05-14-59-34.log
c:\programdata\Lavasoft\Ad-Aware\Logs\Service_2009-06-05-17-02-08.log
c:\programdata\Lavasoft\Ad-Aware\Logs\Service_2009-06-06-06-47-09.log
c:\programdata\Lavasoft\Ad-Aware\Logs\Service_2009-06-09-17-31-16.log
c:\programdata\Lavasoft\Ad-Aware\settings.dat
c:\programdata\Lavasoft\Ad-Aware\ThreatWork\Submit\WNASPINT.DLL
c:\programdata\Lavasoft\Ad-Aware\update\AAWService.exe
c:\programdata\Lavasoft\Ad-Aware\update\AAWTray.exe
c:\programdata\Lavasoft\Ad-Aware\update\AAWWSC.exe
c:\programdata\Lavasoft\Ad-Aware\update\Ad-Aware.exe
c:\programdata\Lavasoft\Ad-Aware\update\Ad-AwareAdmin.exe
c:\programdata\Lavasoft\Ad-Aware\update\Ad-AwareCommand.exe
c:\programdata\Lavasoft\Ad-Aware\update\CEAPI.dll
c:\programdata\Lavasoft\Ad-Aware\update\Drivers\32\AAWDriverTool.exe
c:\programdata\Lavasoft\Ad-Aware\update\Drivers\32\lbd.cat
c:\programdata\Lavasoft\Ad-Aware\update\Drivers\32\lbd.inf
c:\programdata\Lavasoft\Ad-Aware\update\Drivers\32\lbd.sys
c:\programdata\Lavasoft\Ad-Aware\update\Drivers\64\AAWDriverTool.exe
c:\programdata\Lavasoft\Ad-Aware\update\Drivers\64\lbd.cat
c:\programdata\Lavasoft\Ad-Aware\update\Drivers\64\lbd.sys
c:\programdata\Lavasoft\Ad-Aware\update\lavalicense.dll
c:\programdata\Lavasoft\Ad-Aware\update\lavamessage.dll
c:\programdata\Lavasoft\Ad-Aware\update\lsdelete.exe
c:\programdata\Lavasoft\Ad-Aware\update\new\Help\Ad-Awaremanual-EN.chm.new
c:\programdata\Lavasoft\Ad-Aware\update\new\Lang\EN.lslang.new
c:\programdata\Lavasoft\Ad-Aware\update\PrivacyClean.dll
c:\programdata\Lavasoft\Ad-Aware\update\Resources.dll
c:\programdata\Lavasoft\Ad-Aware\update\RPAPI.dll
c:\programdata\Lavasoft\Ad-Aware\update\savapibridge.dll
c:\programdata\Lavasoft\Ad-Aware\update\ShellExt.dll
c:\programdata\Lavasoft\Ad-Aware\update\threatwork.exe
c:\programdata\Lavasoft\Ad-Aware\update\UpdateManager.dll

.
((((((((((((((((((((((((( Files Created from 2009-06-09 to 2009-07-09 )))))))))))))))))))))))))))))))
.

2009-07-09 01:28 . 2009-07-09 01:28 ——– d—–w- c:\users\Tomas de Torquemada\AppData\Local\temp
2009-07-09 01:28 . 2009-07-09 01:28 ——– d—–w- c:\users\Dad's Computer\AppData\Local\temp
2009-07-08 18:54 . 2009-07-08 18:54 ——– d—–w- C:\_OTL
2009-07-06 16:43 . 2009-07-06 16:43 ——– d—–w- c:\program files\VS Revo Group
2009-07-06 16:33 . 2009-07-06 16:33 ——– d—–w- C:\Rooter$
2009-06-29 20:34 . 2009-06-29 20:34 ——– d—–w- c:\windows\Sun
2009-06-28 05:44 . 2009-06-28 05:44 ——– d—–w- C:\PerfLogs
2009-06-28 02:24 . 2009-06-28 17:57 ——– d—–w- C:\b144cf093e9e7c9bcf1b
2009-06-26 18:23 . 2009-06-14 20:07 1004800 —-a-w- c:\programdata\AVG Security Toolbar\IEToolbar.dll
2009-06-25 21:32 . 2009-06-25 21:32 ——– d—–w- c:\program files\Microsoft
2009-06-25 02:55 . 2008-06-20 01:18 105016 —-a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-06-25 02:55 . 2008-06-20 01:17 97800 —-a-w- c:\windows\system32\infocardapi.dll
2009-06-25 02:55 . 2008-06-20 01:18 43544 —-a-w- c:\windows\system32\PresentationHostProxy.dll
2009-06-25 02:55 . 2008-06-20 01:17 622080 —-a-w- c:\windows\system32\icardagt.exe
2009-06-25 02:55 . 2008-06-20 01:17 11264 —-a-w- c:\windows\system32\icardres.dll
2009-06-25 02:55 . 2008-06-20 01:18 781344 —-a-w- c:\windows\system32\PresentationNative_v0300.dll
2009-06-25 02:55 . 2008-06-20 01:18 326160 —-a-w- c:\windows\system32\PresentationHost.exe
2009-06-25 02:44 . 2008-07-27 18:00 96760 —-a-w- c:\windows\system32\dfshim.dll
2009-06-25 02:44 . 2008-07-27 18:00 282112 —-a-w- c:\windows\system32\mscoree.dll
2009-06-25 02:43 . 2008-07-27 18:00 41984 —-a-w- c:\windows\system32\netfxperf.dll
2009-06-25 02:43 . 2008-07-27 18:00 158720 —-a-w- c:\windows\system32\mscorier.dll
2009-06-25 02:43 . 2008-07-27 18:00 83968 —-a-w- c:\windows\system32\mscories.dll
2009-06-25 02:36 . 2009-04-23 12:56 696832 —-a-w- c:\windows\system32\localspl.dll
2009-06-25 02:36 . 2009-04-21 12:04 2028032 —-a-w- c:\windows\system32\win32k.sys
2009-06-25 02:35 . 2009-04-23 13:01 788992 —-a-w- c:\windows\system32\rpcrt4.dll
2009-06-23 12:44 . 2009-07-03 03:07 ——– d–h–w- C:\$AVG8.VAULT$
2009-06-22 15:55 . 2009-06-22 15:55 ——– d—–w- c:\users\Dad's Computer\AppData\Local\AVG Security Toolbar
2009-06-22 13:35 . 2009-06-22 13:35 3561743 —-a-w- c:\programdata\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-22 13:32 . 2009-06-22 13:32 ——– d—–w- c:\users\Tomas de Torquemada\AppData\Local\AVG Security Toolbar
2009-06-22 13:30 . 2009-06-22 13:30 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-06-22 13:30 . 2009-06-22 13:30 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-06-22 13:30 . 2009-06-22 13:30 327688 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-22 13:30 . 2009-07-08 14:21 ——– d—–w- c:\windows\system32\drivers\Avg
2009-06-22 13:30 . 2009-06-22 13:30 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-22 13:30 . 2009-06-26 18:23 ——– d—–w- c:\programdata\AVG Security Toolbar
2009-06-22 13:29 . 2009-06-22 13:29 ——– d—–w- c:\program files\AVG
2009-06-22 13:05 . 2009-06-22 13:27 ——– d—–w- c:\users\Tomas de Torquemada\AppData\Local\Microsoft Games
2009-06-18 01:55 . 2009-06-21 20:59 ——– d—–w- c:\users\Tomas de Torquemada\{f3ac81ae-0593-4ff7-90fc-fce7e128dee5}
2009-06-14 01:14 . 2009-04-30 12:42 428032 —-a-w- c:\windows\system32\EncDec.dll
2009-06-14 01:14 . 2009-04-30 12:52 292352 —-a-w- c:\windows\system32\psisdecd.dll
2009-06-14 01:14 . 2009-04-30 12:44 1244672 —-a-w- c:\windows\system32\mcmde.dll
2009-06-12 02:13 . 2009-06-12 02:13 ——– d—–w- c:\users\Dad's Computer\AppData\Roaming\Malwarebytes
2009-06-10 21:45 . 2009-06-10 21:46 ——– d—–w- c:\users\Dad's Computer\AppData\Roaming\PCToolsFirewallPlus
2009-06-10 19:26 . 2009-06-10 19:26 ——– d—–w- c:\users\Tomas de Torquemada\AppData\Roaming\PCToolsFirewallPlus
2009-06-10 02:19 . 2009-06-17 15:27 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-10 02:19 . 2009-06-17 15:27 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-06-10 02:19 . 2009-06-22 13:36 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-06-10 02:01 . 2009-06-10 02:01 ——– d—–w- c:\users\Dad's Computer\AppData\Roaming\PC Tools
2009-06-09 22:17 . 2009-06-22 12:53 ——– d—–w- c:\program files\Common Files\PC Tools

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-28 13:47 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Calendar
2009-06-28 13:47 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Sidebar
2009-06-28 13:47 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Collaboration
2009-06-28 13:47 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2009-06-28 13:47 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Photo Gallery
2009-06-28 13:47 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Journal
2009-06-28 13:47 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Defender
2009-06-25 21:42 . 2009-06-02 02:35 ——– d—–w- c:\programdata\NVIDIA
2009-06-22 13:28 . 2008-08-31 18:23 ——– d—–w- c:\programdata\avg8
2009-06-14 01:31 . 2007-04-24 18:38 ——– d—–w- c:\program files\Microsoft Works
2009-06-09 21:28 . 2007-04-24 18:49 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-06-09 21:28 . 2007-04-24 18:49 ——– d—–w- c:\programdata\Symantec
2009-06-06 18:36 . 2007-07-29 19:34 ——– d—–w- c:\program files\Quicken
2009-06-06 18:31 . 2007-04-24 18:17 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-06-06 18:30 . 2009-06-06 18:30 ——– d—–w- c:\program files\Common Files\Palo Alto Software
2009-06-06 18:30 . 2009-06-06 18:30 ——– d—–w- c:\program files\Common Files\Intuit
2009-06-06 10:22 . 2009-06-05 18:25 ——– d—–w- c:\programdata\NOS
2009-06-06 10:22 . 2009-06-05 18:25 ——– d—–w- c:\program files\NOS
2009-06-05 18:31 . 2009-06-05 18:31 ——– d—–w- c:\program files\Common Files\Adobe AIR
2009-06-05 18:30 . 2009-06-05 18:30 ——– d—–w- c:\program files\Common Files\Adobe
2009-06-05 18:17 . 2008-02-09 13:02 124152 —-a-w- c:\users\Tomas de Torquemada\AppData\Local\GDIPFONTCACHEV1.DAT
2009-06-05 17:48 . 2009-06-02 12:02 124152 —-a-w- c:\users\Dad's Computer\AppData\Local\GDIPFONTCACHEV1.DAT
2009-06-05 16:28 . 2009-05-19 07:09 ——– d—–w- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-06-05 14:49 . 2009-06-05 14:49 ——– d—–w- c:\program files\Common Files\L&H
2009-06-05 14:49 . 2009-06-05 14:49 ——– d—–w- c:\program files\Microsoft ActiveSync
2009-06-05 14:47 . 2009-06-05 14:47 ——– d—–w- c:\program files\Microsoft.NET
2009-06-04 22:58 . 2009-02-04 03:31 ——– d–h–w- c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-06-04 22:58 . 2007-04-24 18:20 ——– d—–w- c:\programdata\WildTangent
2009-06-04 22:58 . 2009-03-08 01:48 ——– d—–w- c:\program files\CCleaner
2009-06-04 22:56 . 2009-05-13 17:59 ——– d—–w- c:\program files\Microsoft Silverlight
2009-06-04 22:56 . 2007-10-25 10:13 ——– d—–w- c:\programdata\Apple Computer
2009-06-04 22:56 . 2007-10-25 10:12 ——– d—–w- c:\programdata\Apple
2009-06-04 22:56 . 2007-04-24 18:31 ——– d—–w- c:\programdata\Roxio
2009-06-04 22:56 . 2007-04-24 18:25 ——– d—–w- c:\programdata\HP
2009-06-04 22:52 . 2007-07-29 19:33 ——– d—–w- c:\users\Dad's Computer\AppData\Roaming\Intuit
2009-06-02 21:02 . 2007-07-29 17:48 ——– d—–w- c:\users\Dad's Computer\AppData\Roaming\Adobe(671)
2009-06-02 12:05 . 2007-09-02 10:59 ——– d—–w- c:\users\Dad's Computer\AppData\Roaming\Mozilla(681)
2009-06-02 11:53 . 2007-07-29 19:33 ——– d—–w- c:\users\Dad's Computer\AppData\Roaming\Intuit(672)
2009-05-22 16:37 . 2009-05-22 16:37 ——– d—–w- c:\users\Tomas de Torquemada\AppData\Roaming\Malwarebytes
2009-05-22 16:37 . 2009-05-22 16:37 ——– d—–w- c:\programdata\Malwarebytes
2009-05-09 02:48 . 2009-05-09 02:48 766808 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
2009-04-24 16:22 . 2009-06-28 00:56 827392 —-a-w- c:\windows\system32\wininet.dll
2009-04-24 16:14 . 2009-06-28 00:56 56320 —-a-w- c:\windows\system32\iesetup.dll
2009-04-24 16:14 . 2009-06-28 00:56 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-04-24 16:11 . 2009-06-28 00:56 72704 —-a-w- c:\windows\system32\admparse.dll
2009-04-24 13:53 . 2009-06-28 00:56 26624 —-a-w- c:\windows\system32\ieUnatt.exe
2009-04-24 12:25 . 2009-06-28 00:56 48128 —-a-w- c:\windows\system32\mshtmler.dll
2009-04-11 21:49 . 2009-04-11 21:50 410984 —-a-w- c:\windows\system32\deploytk.dll
2007-08-25 19:37 . 2007-08-25 19:37 22 –sha-w- c:\windows\SMINST\HPCD.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-14 20:07 1004800 —-a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2007-09-02 1006264]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2006-09-28 65536]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
"OsdMaestro"="c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-11 148888]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-22 1948440]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-23 13539872]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-01-15 4874240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2007-03-07 44168]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{8E28FB53-0613-4605-A2A4-A8D921636135}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{CC72DC5A-C75C-49C7-A3E5-654B4AE2FFC5}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{A0E68D27-0623-4BEA-B02A-3A45AFBA3B8E}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{994D992D-FC82-4B65-B300-AC250F8D453E}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{D3153266-F3C2-423C-80DC-654067BE065C}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{B397EA17-5F85-4598-B491-FF856B065299}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"TCP Query User{8388812E-9B1F-41B9-BEB5-3C6639B98C17}c:\\program files\\real\\realplayer\\realplay.exe"= UDP:c:\program files\real\realplayer\realplay.exe:RealPlayer
"UDP Query User{0E23F119-6E1D-4E34-A043-61D802B6B894}c:\\program files\\real\\realplayer\\realplay.exe"= TCP:c:\program files\real\realplayer\realplay.exe:RealPlayer
"{221A338C-4318-46CC-88B5-1B2CAC7CAEAF}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"TCP Query User{EFBDF2BF-55A4-4304-8CA9-876E5FA83572}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{FA187EC1-9898-49FE-A750-E9F3142C9E02}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"{273876F6-D545-4740-9174-DBF539AA35D6}"= Disabled:UDP:c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe:Spy Sweeper
"{9F2FFF14-4A10-45FE-A14D-A57DAE8443DD}"= Disabled:TCP:c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe:Spy Sweeper
"{FE5BFE4B-F986-442B-8F12-8C168B4E13BF}"= c:\program files\AVG\AVG8\avgnsx.exe:avgnsx.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= c:\program files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [6/22/2009 9:30 AM 327688]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [6/22/2009 9:30 AM 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [6/22/2009 9:29 AM 298776]
R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE [3/30/2009 4:28 PM 1533808]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://broadband.zoomtown.com
mStart Page = hxxp://broadband.zoomtown.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Tomas de Torquemada\AppData\Roaming\Mozilla\Firefox\Profiles\6ar7u071.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.catholicculture.org/culture/liturgicalyear/
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-08 21:28
Windows 6.0.6000 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Completion time: 2009-07-09 21:30
ComboFix-quarantined-files.txt 2009-07-09 01:30
ComboFix2.txt 2009-07-08 19:49

Pre-Run: 278,296,764,416 bytes free
Post-Run: 278,214,725,632 bytes free

257 — E O F — 2009-06-28 02:21
Tomk, Here are the results of the Kaspersky scan: (do we now do another Combofix scan to get rid of the Trend Microvirus files?) ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0 REPORT Thursday, July 9, 2009 Operating System: Microsoft Windows Vista Home Premium Edition, 32-bit (build 6000) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Thursday, July 09, 2009 03:24:13 Records in database: 2446086 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ G:\ H:\ I:\ J:\ Scan statistics: Files scanned: 123765 Threat name: 0 Infected objects: 0 Suspicious objects: 0 Duration of the scan: 02:05:15 No malware has been detected. The scan area is clean. The selected area was scanned.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI