Here's the next CF.txt file
ComboFix 09-09-28.01 - Owner 09/28/2009 22:03.3.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1527.825 [GMT -7:00]
Running from: c:\documents and settings\Owner\Desktop\Combo-Fix.exe
Command switches used :: E:\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
- REDUCED FUNCTIONALITY MODE -
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
--------------- FCopy ---------------
c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\proquota.exe --> c:\windows\system32\proquota.exe
.
((((((((((((((((((((((((( Files Created from 2009-08-28 to 2009-09-29 )))))))))))))))))))))))))))))))
.
2009-09-29 05:03 . 2009-09-29 05:03 -------- d-----w- c:\windows\LastGood
2009-09-29 05:03 . 2004-08-04 12:00 50176 -c--a-w- c:\windows\system32\dllcache\proquota.exe
2009-09-29 05:03 . 2004-08-04 12:00 50176 ----a-w- c:\windows\system32\proquota.exe
2009-09-29 04:20 . 2009-09-29 04:21 -------- d-----w- C:\New Folder
2009-09-26 06:33 . 2009-09-26 06:33 -------- d-----w- C:\found.000
2009-09-24 05:57 . 2009-09-24 05:14 71680 ----a-w- C:\mbr.exe
2009-09-13 05:42 . 2009-09-13 05:42 -------- d-----w- c:\documents and settings\Cory\Application Data\Malwarebytes
2009-09-12 04:24 . 2009-09-12 04:24 -------- d-----w- c:\documents and settings\Freddie\Application Data\Malwarebytes
2009-09-09 04:57 . 2009-09-09 04:57 -------- d-----w- c:\documents and settings\Owner\Application Data\GOL_byHasbro
2009-09-09 04:47 . 2009-09-09 04:47 -------- d-----w- C:\GameHouse Games
2009-09-09 04:45 . 2009-09-09 04:45 -------- d-----w- c:\program files\RealArcade
2009-09-07 17:57 . 2009-09-07 17:57 -------- d-----w- c:\documents and settings\All Users\Application Data\kds_kodak
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-29 04:05 . 2008-05-27 03:59 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-10 21:54 . 2008-08-17 19:03 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 21:53 . 2008-05-27 03:59 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-10 04:24 . 2008-09-07 04:19 -------- d-----w- c:\program files\Microsoft Silverlight
2009-09-08 04:41 . 2007-01-23 22:27 -------- d-----w- c:\program files\IKEA HomePlanner
2009-09-07 23:46 . 2006-09-17 17:57 -------- d-----w- c:\documents and settings\Owner\Application Data\U3
2009-09-07 21:57 . 2004-11-16 04:32 -------- d-----w- c:\program files\Notebook Maximizer
2009-09-07 18:22 . 2008-08-17 20:53 -------- d-----w- c:\documents and settings\Owner\Application Data\AdobeUM
2009-08-29 03:31 . 2007-07-04 15:49 37592 -c--a-w- c:\documents and settings\Freddie\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-27 05:46 . 2008-01-01 21:37 37592 ----a-w- c:\documents and settings\Cory\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-26 02:24 . 2006-08-25 20:58 37592 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-25 10:16 . 2009-08-25 10:16 -------- d-----w- c:\program files\MSBuild
2009-08-25 10:16 . 2009-08-25 10:16 -------- d-----w- c:\program files\Reference Assemblies
2009-08-25 10:03 . 2009-08-25 10:03 -------- d-----w- c:\program files\MSXML 6.0
2009-08-25 03:26 . 2008-10-27 01:38 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-25 03:26 . 2008-10-27 01:38 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-25 03:26 . 2008-10-27 01:38 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-18 18:04 . 2009-08-18 18:04 -------- d-----w- c:\program files\Marvell
2009-08-06 08:10 . 2009-08-06 08:10 282624 ----a-w- c:\windows\system32\yk51x86.dll
2009-08-06 08:10 . 2004-11-16 03:20 297728 ----a-w- c:\windows\system32\drivers\yk51x86.sys
2009-08-05 09:11 . 2004-11-15 23:32 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-17 18:55 . 2004-11-15 23:32 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 06:43 . 2004-11-15 23:33 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2008-02-10 04:01 . 2008-02-10 04:01 10752 --sha-w- c:\program files\Thumbs.db
2007-12-10 02:53 . 2007-12-10 02:41 1679619 ----a-w- c:\program files\Uninst.isu
2006-10-21 16:09 . 2006-10-21 16:09 985904 ----a-w- c:\program files\FreecorderSetup.exe
2001-09-02 00:01 . 2007-12-10 02:43 1486848 ----a-r- c:\program files\TONKA Monster Trucks.exe
2001-08-31 05:59 . 2007-12-10 02:43 21139 ------w- c:\program files\Readme.txt
2001-08-28 02:14 . 2007-12-10 02:43 40960 ------w- c:\program files\TONKA MONSTER TRUCKS Install Guide.DOC
2001-08-15 22:39 . 2007-12-10 02:43 2202 ------w- c:\program files\Tonka Monster Trucks.ico
.
((((((((((((((((((((((((((((( SnapShot@2009-09-29_03.12.07 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-09-29 05:03 . 2008-04-14 00:12 50176 c:\windows\LastGood\system32\proquota.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-07-18 01:20 279944 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-07-24 16:55 1090816 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-07-18 279944]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-07-18 279944]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2003-09-05 65536]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\lib\NMBgMonitor.exe" [2005-11-10 94208]
"Creative Detector"="c:\program files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-03 102400]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-10-08 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-10-08 126976]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-14 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-14 688218]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2003-09-06 184320]
"AGRSMMSG"="c:\windows\AGRSMMSG.exe" [2004-10-28 88363]
"Tvs"="c:\program files\Toshiba\Tvs\TvsTray.exe" [2004-11-13 73728]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-07-27 1388544]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-08-03 122939]
"TPSMain"="c:\windows\system32\TPSMain.exe" [2004-08-27 278528]
"PadTouch"="c:\program files\TOSHIBA\Touch and Launch\PadExe.exe" [2004-09-07 1077301]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 172032]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 241664]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2005-12-04 461584]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-01-27 401408]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-01-27 385024]
"EOUApp"="c:\program files\Intel\Wireless\Bin\EOUWiz.exe" [2006-01-27 356352]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-25 2007832]
"EKIJ5000StatusMonitor"="c:\windows\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe" [2007-11-13 1052672]
"THotkey"="c:\program files\Toshiba\Toshiba Applet\thotkey.exe" [2004-12-15 368640]
"SmoothView"="c:\program files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2004-09-15 135168]
"PCClient.exe"="c:\program files\Trend Micro\Antivirus\PCClient.exe" [2004-02-17 634949]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2004-02-18 49152]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 57344]
"TFncKy"="TFncKy.exe" [BU]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2004-12-7 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2006-01-27 13:12 110592 ----a-w- c:\program files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-25 03:26 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rootrepeal.sys]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^TONKA« Construction 2 Registration.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\TONKA« Construction 2 Registration.lnk
backup=c:\windows\pss\TONKA« Construction 2 Registration.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [10/26/2008 6:38 PM 335240]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [10/26/2008 6:38 PM 297752]
R2 IntuitUpdateService;Intuit Update Service;c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [10/10/2008 5:45 AM 13088]
R2 KodakSvc;Kodak AiO Device Service;c:\program files\Kodak\Printer\Center\KodakSvc.exe [12/13/2007 12:07 PM 18944]
R2 Tmfilter;Tmfilter;c:\windows\system32\drivers\TmXPFlt.sys [3/5/2004 12:53 PM 204816]
R2 Tmntsrv;Trend NT Realtime Service;c:\program files\Trend Micro\Antivirus\Tmntsrv.exe [2/17/2004 3:57 PM 241737]
R2 Tmpreflt;Tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [3/5/2004 12:53 PM 36368]
R2 tmproxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Antivirus\tmproxy.exe [2/17/2004 3:58 PM 204873]
.
Contents of the 'Scheduled Tasks' folder
2009-07-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=20008&gct=&gc=1&q=%s
IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: turbotax.com
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://www.gamehouse.com/games/zylom/zylomplayer.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-28 22:03
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(632)
c:\program files\Intel\Wireless\Bin\LgNotify.dll
- - - - - - - > 'explorer.exe'(3104)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\TPwrCfg.DLL
c:\windows\system32\TPwrReg.dll
c:\windows\system32\TPSTrace.DLL
.
Completion time: 2009-09-29 22:05
ComboFix-quarantined-files.txt 2009-09-29 05:05
ComboFix2.txt 2009-09-29 04:17
ComboFix3.txt 2009-09-29 03:17
Pre-Run: 21,402,832,896 bytes free
Post-Run: 21,385,822,208 bytes free
190 --- E O F --- 2009-09-09 05:16
Fred