Okay here are the things you requested of me in the order you requested. The kaspersky scan took a few hours all totalled up.
Combo-Fix:
ComboFix 09-07-28.01 - Susan White 07/28/2009 22:06.4.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.495.175 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix\ComboFix.exe
Command switches used :: c:\documents and settings\Susan White\Desktop\CFScript.txt
AV: AVG Anti-Virus *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((( Files Created from 2009-06-28 to 2009-07-29 )))))))))))))))))))))))))))))))
.
2009-07-15 00:52 . 2009-07-15 00:56 10 —-a-w- c:\windows\popcinfo.dat
2009-07-14 01:38 . 2009-07-14 02:14 ——– d—–w- c:\documents and settings\Susan White\Application Data\BitTorrent
2009-07-14 01:38 . 2009-07-14 01:38 ——– d—–w- c:\program files\BitTorrent
2009-07-14 01:36 . 2009-07-14 01:36 ——– d—–w- c:\documents and settings\Susan White\Application Data\Convivea
2009-07-14 01:36 . 2009-04-10 23:40 118784 —-a-w- c:\documents and settings\Susan White\Application Data\Convivea\Bit_Che\scripts\x.exe
2009-07-14 01:36 . 2008-03-28 15:07 20992 —-a-w- c:\documents and settings\Susan White\Application Data\Convivea\Bit_Che\languages\compare.exe
2009-07-14 01:36 . 2008-03-28 15:02 60928 —-a-w- c:\documents and settings\Susan White\Application Data\Convivea\Bit_Che\scripts\update.exe
2009-07-14 01:36 . 2007-07-12 00:43 24557 —-a-w- c:\documents and settings\Susan White\Application Data\Convivea\Bit_Che\scripts\special.exe
2009-07-14 01:36 . 2003-08-19 10:06 80896 —-a-w- c:\documents and settings\Susan White\Application Data\Convivea\Bit_Che\scripts\x.dll
2009-07-14 01:12 . 2009-07-14 01:12 ——– d—–w- c:\documents and settings\Susan White\Application Data\AVS4YOU
2009-07-14 01:12 . 2009-07-14 01:12 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\AVS4YOU
2009-07-14 01:10 . 2009-07-14 01:11 ——– d—–w- c:\program files\Common Files\AVSMedia
2009-07-14 01:10 . 2008-08-13 16:22 974848 —-a-w- c:\windows\system32\mfc70.dll
2009-07-14 01:10 . 2008-08-13 16:22 487424 —-a-w- c:\windows\system32\msvcp70.dll
2009-07-14 01:10 . 2008-08-13 16:22 344064 —-a-w- c:\windows\system32\msvcr70.dll
2009-07-14 01:10 . 2008-08-13 16:22 1700352 —-a-w- c:\windows\system32\GdiPlus.dll
2009-07-14 01:10 . 2009-07-14 01:11 ——– d—–w- c:\program files\AVS4YOU
2009-07-14 01:10 . 2008-08-13 16:22 24576 —-a-w- c:\windows\system32\msxml3a.dll
2009-07-13 02:20 . 2009-07-13 02:20 ——– d—–w- c:\documents and settings\Susan White\Application Data\MSNInstaller
2009-07-07 22:05 . 2009-07-07 22:05 ——– d—–w- c:\program files\Elaborate Bytes
2009-07-06 15:14 . 2009-07-06 15:14 ——– d-sh–w- c:\windows\system32\config\systemprofile\PrivacIE
2009-07-06 15:14 . 2009-07-06 15:14 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\Yahoo!
2009-07-06 15:07 . 2009-07-06 15:08 ——– d—–w- c:\documents and settings\Susan White\Application Data\DriverCure
2009-07-06 15:06 . 2009-07-12 23:36 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\DriverCure
2009-07-06 15:06 . 2009-07-06 15:06 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\ParetoLogic
2009-07-02 16:45 . 2009-07-02 16:45 ——– d-sh–w- c:\documents and settings\NetworkService.NT AUTHORITY\IETldCache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-28 15:32 . 2008-09-03 18:02 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Google Updater
2009-07-28 15:29 . 2009-05-25 01:23 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-07-22 02:41 . 2008-11-24 17:42 256 —-a-w- c:\windows\system32\pool.bin
2009-07-15 00:52 . 2007-04-12 04:19 ——– d—–w- c:\program files\PopCap Games
2009-07-14 01:36 . 2007-11-01 21:47 ——– d—–w- c:\program files\Bit Che
2009-07-13 18:36 . 2009-05-25 01:23 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-13 18:36 . 2009-05-25 01:23 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-07-12 23:35 . 2007-11-07 17:08 ——– d—–w- c:\program files\LimeWire
2009-07-09 14:26 . 2008-11-20 22:12 ——– d—a-w- c:\documents and settings\All Users.WINDOWS\Application Data\TEMP
2009-07-09 14:15 . 2007-05-25 22:15 ——– d—–w- c:\documents and settings\Susan White\Application Data\LimeWire
2009-07-05 21:45 . 2006-11-20 16:20 ——– d—–w- c:\program files\Microsoft Digital Image 2006
2009-07-05 20:48 . 2007-05-22 03:48 ——– d—–w- c:\documents and settings\Susan White\Application Data\Image Zone Express
2009-07-04 14:03 . 2009-05-14 01:32 335752 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-22 19:59 . 2009-06-12 13:33 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\AVG Security Toolbar
2009-06-22 07:55 . 2009-06-08 21:30 3561743 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-16 13:40 . 2009-05-14 01:32 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-12 13:33 . 2009-06-12 13:33 ——– d—–w- c:\documents and settings\LocalService.NT AUTHORITY\Application Data\AVGTOOLBAR
2009-06-11 03:27 . 2006-11-17 23:23 ——– d—–w- c:\program files\Microsoft Works
2009-06-08 03:38 . 2008-06-13 21:40 4810 —-a-w- c:\documents and settings\Susan White\Application Data\wklnhst.dat
2009-06-02 18:38 . 2009-06-12 17:55 1004800 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-06-01 18:21 . 2009-06-01 18:21 73728 —-a-w- c:\documents and settings\Susan White\Application Data\LimeWire\browser\xulrunner\xulrunner-stub.exe
2009-06-01 18:21 . 2009-06-01 18:21 499712 —-a-w- c:\documents and settings\Susan White\Application Data\LimeWire\browser\xulrunner\MSVCP71.DLL
2009-06-01 18:21 . 2009-06-01 18:21 348160 —-a-w- c:\documents and settings\Susan White\Application Data\LimeWire\browser\xulrunner\msvcr71.dll
2009-06-01 18:21 . 2009-06-01 18:21 102400 —-a-w- c:\documents and settings\Susan White\Application Data\LimeWire\browser\xulrunner\xulrunner.exe
2009-06-01 18:21 . 2009-06-01 18:20 8462336 —-a-w- c:\documents and settings\Susan White\Application Data\LimeWire\browser\xulrunner\xul.dll
2009-05-22 23:08 . 2009-05-22 23:08 29696 —-a-w- c:\windows\system32\drivers\VClone.sys
2009-05-22 14:13 . 2009-05-22 13:16 256 —-a-w- c:\documents and settings\Susan White\pool.bin
2009-05-19 17:43 . 2007-05-10 05:32 376424 —-a-w- c:\documents and settings\Susan White\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-19 17:27 . 2009-05-19 17:27 6502 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\RedirectorEXE2_770DFD1204C24F4DA163D64FACCB5CBD.exe
2009-05-19 17:27 . 2009-05-19 17:27 26694 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\NewShortcut600_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-05-19 17:27 . 2009-05-19 17:27 26694 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\NewShortcut60_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-05-19 17:27 . 2009-05-19 17:27 26694 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\NewShortcut6_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-05-19 17:27 . 2009-05-19 17:27 26694 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\NewShortcut5_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-05-19 17:27 . 2009-05-19 17:27 26694 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\NewShortcut4_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-05-19 17:27 . 2009-05-19 17:27 26694 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\NewShortcut3_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-05-19 17:27 . 2009-05-19 17:27 26694 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\NewShortcut12_C6ABA3677F944B9FBB00F060701B0B5A.exe
2009-05-19 17:27 . 2009-05-19 17:27 69632 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\DesktopMgr.exe
2009-05-19 17:27 . 2009-05-19 17:27 6502 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\RedirectorEXE1_770DFD1204C24F4DA163D64FACCB5CBD.exe
2009-05-19 17:27 . 2009-05-19 17:27 6502 —-a-r- c:\documents and settings\Susan White\Application Data\Microsoft\Installer\{7CB1E63B-C999-4D17-8133-E138F41D9ECF}\RedirectorEXE_770DFD1204C24F4DA163D64FACCB5CBD.exe
2009-05-14 23:41 . 2009-05-14 01:33 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-05-14 23:41 . 2009-05-14 01:33 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-14 23:41 . 2009-05-14 01:33 12552 —-a-w- c:\windows\system32\drivers\avgrkx86.sys
2009-05-13 05:15 . 2006-02-28 12:00 915456 —-a-w- c:\windows\system32\wininet.dll
2009-05-07 15:32 . 2006-02-28 12:00 345600 —-a-w- c:\windows\system32\localspl.dll
2007-05-10 08:00 . 2007-05-10 07:59 288104 -c–a-w- c:\program files\dxwebsetup.exe
2004-10-01 21:00 . 2006-11-20 18:24 40960 -c–a-w- c:\program files\Uninstall_CDS.exe
2004-10-01 21:00 . 2006-11-20 18:24 40960 -c–a-w- c:\program files\Uninstall_CDS(2).exe
.
((((((((((((((((((((((((((((( SnapShot@2009-07-28_22.49.29 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-20 03:37 . 2009-07-28 23:39 245760 c:\windows\system32\config\systemprofile\IETldCache\index.dat
- 2009-06-20 03:37 . 2009-07-28 19:53 245760 c:\windows\system32\config\systemprofile\IETldCache\index.dat
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-26 19:42 . 2007-09-26 19:42 267064 c:\program files\iTunes\bak\iTunesHelper.exe
2008-09-10 22:40 . 2008-09-10 22:40 289576 c:\program files\iTunes\iTunesHelper.exe
2006-11-17 20:38 . 2004-10-13 16:24 1694208 c:\program files\Messenger\bak\msmsgs.exe
2008-06-28 22:14 . 2008-04-14 00:12 1695232 c:\program files\Messenger\msmsgs.exe
2007-06-29 11:24 . 2007-06-29 11:24 286720 c:\program files\QuickTime\bak\QTTask.exe
2008-09-06 20:09 . 2008-09-06 20:09 413696 c:\program files\QuickTime\QTTask.exe
2006-02-28 12:00 . 2006-02-28 12:00 15360 c:\windows\system32\bak\ctfmon.exe
2006-02-28 12:00 . 2008-04-14 00:12 15360 c:\windows\system32\ctfmon.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-16 1004800]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-16 14:29 1004800 —-a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-16 1004800]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-16 1004800]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-09-03 39408]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-03-01 2321600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exe" [2007-11-29 583048]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-12 1948440]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2008-06-08 236016]
"SiSPower"="SiSPower.dll" - c:\windows\system32\SiSPower.dll [2005-03-03 49152]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
c:\documents and settings\Owner\Start Menu\Programs\Startup\
desktop(2).ini [2006-11-17 84]
c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Utility Tray.lnk - c:\windows\system32\sistray.exe [2007-5-10 266240]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-14 23:41 11952 —-a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Susan White^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\documents and settings\Susan White\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [5/13/2009 8:33 PM 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/13/2009 8:32 PM 335752]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/13/2009 8:33 PM 108552]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [5/14/2009 6:41 PM 907032]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [5/14/2009 6:41 PM 298776]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [9/19/2007 11:47 AM 18176]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [9/19/2007 11:47 AM 7680]
S3 SysProtDrv.sys;SysProtDrv.sys;c:\documents and settings\Susan White\Desktop\SysProt\SysProt\SysProtDrv.sys [7/28/2009 11:28 AM 44288]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-07-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2009-07-29 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-09-03 20:24]
2009-07-29 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.google.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
DPF: {3F0EECCE-E138-11D1-8712-0060083D83F5} - hxxp://www.mgisoft.com/ActiveX/LPControl.cab
DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - hxxp://imikimi.com/download/imikimi_plugin_0.5.1.cab
.
**************************************************************************
driver loading error catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-28 22:15
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-507921405-308236825-725345543-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'explorer.exe'(2580)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\HPZipm12.exe
c:\progra~1\AVG\AVG8\avgam.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-07-29 22:24 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-29 03:24
ComboFix2.txt 2009-07-29 00:45
ComboFix3.txt 2009-07-28 22:53
ComboFix4.txt 2009-03-04 16:25
Pre-Run: 122,471,665,664 bytes free
Post-Run: 122,447,327,232 bytes free
257 — E O F — 2009-07-19 02:06
MalwareBytes Log:
Malwarebytes' Anti-Malware 1.39
Database version: 2525
Windows 5.1.2600 Service Pack 3
7/28/2009 10:36:59 PM
mbam-log-2009-07-28 (22-36-59).txt
Scan type: Quick Scan
Objects scanned: 120591
Time elapsed: 4 minute(s), 35 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Kaspersky Log:
Wednesday, July 29, 2009
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Wednesday, July 29, 2009 06:15:47
Records in database: 2560065
Scan settings
Scan using the following database extended
Scan archives yes
Scan mail databases yes
Scan area My Computer
A:\
C:\
D:\
Scan statistics
Files scanned 87442
Threat name 5
Infected objects 11
Suspicious objects 0
Duration of the scan 02:32:37
File name Threat name Threats count
C:\Deckard\System Scanner\20090221035923\backup\DOCUME~1\SUSANW~1\LOCALS~1\Temp\.tt288.tmp.vbs Infected: Backdoor.Win32.Frauder.eo 1
C:\Deckard\System Scanner\20090221035923\backup\DOCUME~1\SUSANW~1\LOCALS~1\Temp\.tt4.tmp.vbs Infected: Backdoor.Win32.Frauder.eo 1
C:\Deckard\System Scanner\20090221035923\backup\DOCUME~1\SUSANW~1\LOCALS~1\Temp\.tt7.tmp.vbs Infected: Backdoor.Win32.Frauder.eo 1
C:\Deckard\System Scanner\20090221035923\backup\DOCUME~1\SUSANW~1\LOCALS~1\Temp\.tt8.tmp.vbs Infected: Backdoor.Win32.Frauder.eo 1
C:\Documents and Settings\Susan White\My Documents\LimeWire\Saved\asher roth.mp3 Infected: Trojan-Downloader.WMA.GetCodec.u 1
C:\Documents and Settings\Susan White\My Documents\LimeWire\Saved\go head mac bre z.mp3 Infected: Trojan-Downloader.WMA.GetCodec.w 1
C:\Documents and Settings\Susan White\My Documents\LimeWire\Saved\life would really suck without.mp3 Infected: Trojan-Downloader.WMA.GetCodec.w 1
C:\Documents and Settings\Susan White\My Documents\LimeWire\Saved\the affilates (hot new track).au Infected: Trojan-Downloader.WMA.GetCodec.u 1
C:\System Volume Information\_restore{92326D68-0999-4147-A5A9-63DE7970BEF0}\RP344\A0059462.sys Infected: Rootkit.Win32.Agent.mig 1
C:\System Volume Information\_restore{92326D68-0999-4147-A5A9-63DE7970BEF0}\RP344\A0059463.dll Infected: Packed.Win32.Tdss.w 1
C:\System Volume Information\_restore{92326D68-0999-4147-A5A9-63DE7970BEF0}\RP344\A0059464.dll Infected: Packed.Win32.Tdss.w 1
The selected area was scanned.