Hi thanks again for your help here is the log
ComboFix 09-07-05.04 - Hunter 06/07/2009 18:58.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.2045.1137 [GMT 1:00]
Running from: c:\users\[removed]\Desktop\Everton.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Antispyware *enabled* (Updated) {57463B2F-DD60-468D-BC89-6D5403DDF541}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
ADS - Windows: deleted 24 bytes in 1 streams.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-2031794746-3310518143-4181126009-500
c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
C:\setuplog.exe
c:\users\Hunter\AppData\Roaming\inst.exe
c:\windows\system32\AutoRun.inf
c:\windows\system32\drivers\MSIVXtiqtixtrbpxvtverdrpnptapolofbefd.sys
c:\windows\system32\MSIVXcount
c:\windows\system32\MSIVXevqqwpwoteljpwrxuwynrjwdwjtsssbl.dll
c:\windows\system32\MSIVXpbpvcahkidanlblbrrphvbqyiopfivfi.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_MSIVXserv.sys
((((((((((((((((((((((((( Files Created from 2009-06-06 to 2009-07-06 )))))))))))))))))))))))))))))))
.
2009-07-06 18:05 . 2009-07-06 18:05 ——– d—–w- c:\users\Hunter\AppData\Local\temp
2009-07-06 14:34 . 2009-07-06 14:34 ——– d—–w- c:\users\Hunter\AppData\Local\Apple
2009-07-05 13:44 . 2009-07-05 13:44 ——– d—–w- c:\users\Hunter\AppData\Local\WinZip
2009-07-04 21:39 . 2009-07-04 21:39 ——– d—–w- c:\windows\Sun
2009-07-04 21:33 . 2009-07-04 21:33 680 —-a-w- c:\users\Hunter\AppData\Local\d3d9caps.dat
2009-07-04 15:30 . 2009-07-04 22:06 ——– d—–w- c:\users\Hunter\AppData\Roaming\Antispyware
2009-07-03 20:51 . 2009-07-03 23:42 ——– d—–w- c:\users\Hunter\DoctorWeb
2009-07-03 14:47 . 2009-07-03 14:47 ——– d—–w- c:\program files\DVDTool
2009-07-03 14:17 . 2009-07-03 14:26 ——– d—–w- c:\users\Hunter\AppData\Roaming\Vso
2009-07-03 14:17 . 2009-07-03 14:26 47360 —-a-w- c:\users\Hunter\AppData\Roaming\pcouffin.sys
2009-07-03 14:17 . 2009-07-03 14:17 47360 —-a-w- c:\windows\system32\drivers\pcouffin.sys
2009-06-24 08:48 . 2009-06-17 08:37 2052888 —-a-w- c:\programdata\avg8\update\backup\avgcorex.dll
2009-06-17 08:38 . 2009-06-12 09:01 1261344 —-a-w- c:\programdata\avg8\update\backup\avgwd.dll
2009-06-17 08:38 . 2009-06-12 09:01 829208 —-a-w- c:\programdata\avg8\update\backup\avgcfgx.dll
2009-06-17 08:38 . 2009-06-12 09:01 3298072 —-a-w- c:\programdata\avg8\update\backup\setup.exe
2009-06-12 09:03 . 2009-06-12 11:20 ——– d—–w- c:\programdata\AVG Security Toolbar
2009-06-12 09:01 . 2009-06-12 09:00 1452312 —-a-w- c:\programdata\avg8\update\backup\avgupd.dll
2009-06-09 13:15 . 2005-06-13 11:58 9143000 —-a-w- c:\programdata\Driving Test Success\AdbeRdr60_enu.exe
2009-06-09 13:15 . 2009-07-02 08:51 ——– d—–w- c:\programdata\Driving Test Success
2009-06-09 13:15 . 2009-06-09 13:15 ——– d—–w- c:\program files\Hazard Perception 2005-2006
2009-06-08 14:30 . 2009-06-08 14:30 456304 —-a-w- c:\programdata\Google\Google Toolbar\Update\gtbC140.tmp.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-06 17:26 . 2009-01-08 19:24 ——– d—–w- c:\program files\Steam
2009-07-06 15:58 . 2008-05-21 11:30 ——– d—–w- c:\programdata\avg8
2009-07-05 13:44 . 2007-06-15 17:05 ——– d—–w- c:\programdata\WinZip
2009-07-05 12:48 . 2007-06-11 07:49 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-07-03 21:26 . 2007-09-06 19:06 ——– d—–w- c:\users\Hunter\AppData\Roaming\uTorrent
2009-07-02 21:15 . 2008-09-05 22:04 ——– d—–w- c:\users\Hunter\AppData\Roaming\DVD Flick
2009-07-02 11:25 . 2009-01-08 19:25 ——– d—–w- c:\program files\Common Files\Steam
2009-06-17 08:37 . 2007-12-10 22:03 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-12 09:02 . 2008-05-21 11:30 327688 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-11 19:49 . 2007-06-15 17:07 ——– d—–w- c:\programdata\DVD Shrink
2009-06-09 16:57 . 2009-05-19 16:46 ——– d—–w- c:\program files\SlySoft
2009-05-19 16:51 . 2009-05-19 16:51 ——– d—–w- c:\programdata\SlySoft
2009-05-09 05:50 . 2009-06-10 09:02 915456 —-a-w- c:\windows\system32\wininet.dll
2009-05-09 05:34 . 2009-06-10 09:02 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-05-06 09:15 . 2008-05-21 11:30 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-04-23 12:43 . 2009-06-10 09:02 784896 —-a-w- c:\windows\system32\rpcrt4.dll
2009-04-23 12:42 . 2009-06-10 09:02 636928 —-a-w- c:\windows\system32\localspl.dll
2009-04-21 11:55 . 2009-06-10 09:02 2033152 —-a-w- c:\windows\system32\win32k.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-16 08:29 1004800 —-a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"Steam"="c:\program files\Steam\Steam.exe" [2009-06-10 1217784]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-10 39408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-03-02 185896]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-03-28 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-03-30 267048]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-12 1948440]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-10-09 102400]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2006-11-20 4018176]
c:\users\Hunter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2008-10-16 575488]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{B4B573E1-7C6A-4DE6-B4FC-FB723CC9687F}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"TCP Query User{7E5F9DA2-0753-405C-B684-06195EE2643A}c:\\westwood\\ra2\\game.exe"= UDP:c:\westwood\ra2\game.exe:Main executable for Red Alert 2
"UDP Query User{8479CC03-DFEE-4F3C-B3E7-D47B10B8EB25}c:\\westwood\\ra2\\game.exe"= TCP:c:\westwood\ra2\game.exe:Main executable for Red Alert 2
"{446ECA33-E671-4A93-BC6B-8AFB9EB002C4}"= UDP:c:\westwood\RA2\Ra2.exe:Red Alert 2
"{3FE25EE4-0952-4A98-9C41-01F664F5F78D}"= TCP:c:\westwood\RA2\Ra2.exe:Red Alert 2
"{7EAC4B53-42DE-4147-8890-581DB903183B}"= UDP:c:\program files\BullGuard Software\BullGuard\BullGuard.exe:BullGuard
"{981D5111-F978-44EB-A877-D7E3037B404D}"= TCP:c:\program files\BullGuard Software\BullGuard\BullGuard.exe:BullGuard
"{F2B0DD4A-1E53-4AB1-A35A-E21B93B2E6CE}"= UDP:c:\westwood\Internet\REGISTER.EXE:Internet Registration
"{C8670947-EE85-402C-90B3-B9853D3BF6EA}"= TCP:c:\westwood\Internet\REGISTER.EXE:Internet Registration
"TCP Query User{5F0A6153-B10E-444E-B038-BD26314B461F}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{3F3ADAD8-84E6-4267-A6D8-41E67C9EE260}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{0E763C74-FC32-4CED-A54D-5A1478518D79}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"{1ACEE53A-C5C7-4F38-8752-7E5599FC6209}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent
"TCP Query User{B6A35FB2-9870-49A4-ABA3-856AA2CDBFD8}c:\\program files\\tvants\\tvants.exe"= UDP:c:\program files\tvants\tvants.exe:TVAnts
"UDP Query User{722551ED-1C0A-4B09-83F2-41D9A25430CE}c:\\program files\\tvants\\tvants.exe"= TCP:c:\program files\tvants\tvants.exe:TVAnts
"{8F2A6D36-ABEC-41A7-A1EC-FF981D55BF8F}"= UDP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"{D823F2C6-F9E2-4330-9310-6AF40AA2DD69}"= TCP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"TCP Query User{7A665497-BFB6-4823-9826-0988D1E916B3}c:\\program files\\nero\\nero 7\\nero mediahome\\nmmediaserver.exe"= UDP:c:\program files\nero\nero 7\nero mediahome\nmmediaserver.exe:Nero MediaHome
"UDP Query User{96769D86-DF32-4EA5-A1D6-1A4AFE8533F4}c:\\program files\\nero\\nero 7\\nero mediahome\\nmmediaserver.exe"= TCP:c:\program files\nero\nero 7\nero mediahome\nmmediaserver.exe:Nero MediaHome
"{C6AB4FB2-AFD2-447C-A93B-B70AC0C7182E}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{D25861BE-FD09-4A36-B6FB-38EDEAC48871}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{66A8CDC7-FB82-441D-9123-E913B8943D81}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{13FCA693-E8A4-45F7-ADF3-7EC4CCFDA579}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{9582084A-2CEF-434C-90AB-A2F562D0F082}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{6AB1D5A9-F731-4B4F-ADD3-97525E8281A5}"= inRosettaStoneLtdServices.exe:Rosetta Stone Online Component (inbound)
"{440EC3CD-6C53-4913-8424-2DB3F24A6B90}"= RosettaStoneVersion3.exe:Rosetta Stone V3 Application (inbound)
"{0D60FA12-F5C4-4679-985F-5C75DCAB7269}"= UDP:c:\program files\Steam\SteamApps\common\football manager 2009\fm.exe:Football Manager 2009
"{961E0AD4-2E6F-40C9-AA38-2CBE85A38DC6}"= TCP:c:\program files\Steam\SteamApps\common\football manager 2009\fm.exe:Football Manager 2009
"{23491FB8-0ED0-40B2-9F7D-EE06C6F6162C}"= UDP:c:\program files\Steam\SteamApps\common\football manager 2009\fm.exe:Football Manager 2009
"{1FF8C24A-41A9-4F43-95BB-C026E5434824}"= TCP:c:\program files\Steam\SteamApps\common\football manager 2009\fm.exe:Football Manager 2009
"{15FC519C-AC52-448F-9C1A-733538848D52}"= Disabled:UDP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"{1DD6D8E8-4995-4D78-A343-9A1FF64A8970}"= Disabled:TCP:c:\program files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
R0 O2MDRDR;O2MDRDR;c:\windows\System32\drivers\o2media.sys [14/11/2005 13:28 34176]
R0 O2SDRDR;O2SDRDR;c:\windows\System32\drivers\o2sd.sys [19/12/2005 17:15 28800]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [21/05/2008 12:30 327688]
R1 M9207;LifeView M9207 USB Digital TV BOX;c:\windows\System32\drivers\M9207BDA.sys [11/06/2007 09:21 54400]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [21/05/2008 12:30 298776]
S3 RTL2831UBDA;REALTEK 2831U BDA Driver;c:\windows\System32\drivers\RTL2831UBDA.sys [13/04/2007 15:04 62720]
S3 RTL2831UUSB;REALTEK 2831U USB Driver;c:\windows\System32\drivers\RTL2831UUSB.sys [13/04/2007 15:20 24064]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2009-07-06 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-06 19:05
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-07-06 19:06
ComboFix-quarantined-files.txt 2009-07-06 18:06
Pre-Run: 65,075,474,432 bytes free
Post-Run: 65,807,978,496 bytes free
179 — E O F — 2009-06-30 09:15
Also when i try to zip up and attach the attach.txt i encounter problems so i hope it is ok but i have posted it below:
NLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-06-26.01)
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume2
Install Date: 13/06/2007 11:57:53
System Uptime: 07/05/2009 14:09:31 (1416 hours ago)
Motherboard: MTC | | MTC
Processor: Intel® Core™2 CPU T7200 @ 2.00GHz | CPU | 1992/667mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 144 GiB total, 56.985 GiB free.
E: is CDROM ()
F: is CDROM (CDFS)
==== Disabled Device Manager Items =============
==== System Restore Points ===================
==== Installed Programs ======================
32 Bit HP CIO Components Installer
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)
Adobe Flash Player ActiveX
Adobe Reader 8.1.2
Adobe Reader 8.1.2 Security Update 1 (KB403742)
AIO_Scan
Apple Mobile Device Support
Apple Software Update
µTorrent
AVG Free 8.5
BufferChm
Command & Conquer Red Alert 2
Copy
CustomerResearchQFolder
Destination Component
DeviceDiscovery
DeviceManagementQFolder
DJ_AIO_ProductContext
DJ_AIO_Software
DJ_AIO_Software_min
DVD Decrypter (Remove Only)
DVD Flick
DVD Shrink 3.2
DVDTool
eSupportQFolder
ExtractNow
F2100
F2100_doccd
F2100_Help
Football Manager 2009
G-Force Blue
Google Toolbar for Internet Explorer
Hazard Perception 2005/6
HDAUDIO Soft Data Fax Modem with SmartCP
HP Customer Participation Program 9.0
HP Deskjet All-In-One Software 9.0
HP Imaging Device Functions 9.0
HP Photosmart Essential 2.01
HP Photosmart Essential2.01
HP Smart Web Printing
HP Solution Center 9.0
HP Update
HPProductAssistant
HPSSupply
iTunes
Java™ 6 Update 2
Java™ 6 Update 3
Java™ 6 Update 5
Java™ 6 Update 7
K-Lite Codec Pack 3.8.0 Basic
MagicDisc 2.7.105
Malwarebytes' Anti-Malware
MarketResearch
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB929729)
Microsoft Office Professional Edition 2003
Microsoft Visual C++ 2005 Redistributable
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB941833)
MSXML 4.0 SP2 (KB954430)
Nero 7 Essentials
PowerDVD
PSSWCORE
QuickTime
RealPlayer
Realtek High Definition Audio Driver
Rosetta Stone V3
SAGEM F@st 800-840
Scan
Shockwave
SolutionCenter
Status
Steam
Synaptics Pointing Device Driver
Toolbox
TrayApp
UnloadSupport
VideoToolkit01
WebReg
Westwood Shared Internet Components
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Live Toolbar
==== End Of File ===========================
Many thanks for your time
hunterberg