After I ran combofix, I can't access the internet from that computer anymore. I get an error about a registry key that is marked to be deleted.
Here is the combo fix log:
ComboFix 09-11-24.02 - SYSTEM 11/24/2009 21:35.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2037.893 [GMT -6:00]
Running from: c:\windows\system32\config\systemprofile\Desktop\Trend Micro\ComboFix.exe
SP: Windows Defender *disabled* (Outdated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\$recycle.bin\S-1-5-21-3771958223-2023274512-727475370-1000
c:\program files\Fast Browser Search
c:\program files\Fast Browser Search\IE\1.bat
c:\program files\Fast Browser Search\IE\about.html
c:\program files\Fast Browser Search\IE\affid.dat
c:\program files\Fast Browser Search\IE\basis.xml
c:\program files\Fast Browser Search\IE\basis_br.xml
c:\program files\Fast Browser Search\IE\basis_de.xml
c:\program files\Fast Browser Search\IE\basis_en.xml
c:\program files\Fast Browser Search\IE\basis_es.xml
c:\program files\Fast Browser Search\IE\basis_fr.xml
c:\program files\Fast Browser Search\IE\basis_it.xml
c:\program files\Fast Browser Search\IE\basis_nr.xml
c:\program files\Fast Browser Search\IE\basis_pt.xml
c:\program files\Fast Browser Search\IE\basis_ru.xml
c:\program files\Fast Browser Search\IE\basis_tr.xml
c:\program files\Fast Browser Search\IE\ClearRecycleBin.exe
c:\program files\Fast Browser Search\IE\error.html
c:\program files\Fast Browser Search\IE\fbsProtection.xml
c:\program files\Fast Browser Search\IE\FbsSearchProvider.xml
c:\program files\Fast Browser Search\IE\FbsSearchProviderIE8.exe
c:\program files\Fast Browser Search\IE\FBStoolbar.dll
c:\program files\Fast Browser Search\IE\fbstoolbar.jar
c:\program files\Fast Browser Search\IE\fbstoolbar.manifest
c:\program files\Fast Browser Search\IE\icons.bmp
c:\program files\Fast Browser Search\IE\IE3SH.exe
c:\program files\Fast Browser Search\IE\info.txt
c:\program files\Fast Browser Search\IE\local.xml
c:\program files\Fast Browser Search\IE\logobg.bmp
c:\program files\Fast Browser Search\IE\MTWB3SH.dll
c:\program files\Fast Browser Search\IE\MTWBtoolbar.html
c:\program files\Fast Browser Search\IE\search.bmp
c:\program files\Fast Browser Search\IE\search_br.bmp
c:\program files\Fast Browser Search\IE\search_de.bmp
c:\program files\Fast Browser Search\IE\search_es.bmp
c:\program files\Fast Browser Search\IE\search_fr.bmp
c:\program files\Fast Browser Search\IE\search_it.bmp
c:\program files\Fast Browser Search\IE\search_pt.bmp
c:\program files\Fast Browser Search\IE\search_ru.bmp
c:\program files\Fast Browser Search\IE\SearchGuardPlus.exe
c:\program files\Fast Browser Search\IE\SearchGuardPlus.ico
c:\program files\Fast Browser Search\IE\SGPU.ico
c:\program files\Fast Browser Search\IE\sgpUpdater.exe
c:\program files\Fast Browser Search\IE\sgpUpdater.xml
c:\program files\Fast Browser Search\IE\SGPUpdaterS.exe
c:\program files\Fast Browser Search\IE\tbhelper.dll
c:\program files\Fast Browser Search\IE\tbs_include_script_003175.js
c:\program files\Fast Browser Search\IE\tbs_include_script_005064.js
c:\program files\Fast Browser Search\IE\tbs_include_script_012817.js
c:\program files\Fast Browser Search\IE\Toolbar Help.htm
c:\program files\Fast Browser Search\IE\uninstall.exe
c:\program files\Fast Browser Search\IE\uninstalSGP.exe
c:\program files\Fast Browser Search\IE\uninstalSGPU.exe
c:\program files\Fast Browser Search\IE\update.exe
c:\program files\Fast Browser Search\IE\version.txt
c:\program files\FunWebProducts
c:\program files\Internet Explorer\msimg32.dll
c:\program files\MyWebSearch
c:\program files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL
c:\program files\MyWebSearch\bar\1.bin\MWSBAR.DLL
c:\program files\MyWebSearch\bar\2.bin\F3HTMLMU.DLL
c:\program files\MyWebSearch\bar\2.bin\F3SCRCTR.DLL
c:\program files\MyWebSearch\bar\2.bin\MWSBAR.DLL
c:\program files\MyWebSearch\bar\2.bin\MWSOEMON.EXE
c:\program files\MyWebSearch\bar\2.bin\MWSOESTB.DLL
c:\program files\MyWebSearch\bar\3.bin\F3BKGERR.JPG
c:\program files\MyWebSearch\bar\3.bin\F3CJpeg.dll
c:\program files\MyWebSearch\bar\3.bin\F3DTactl.dll
c:\program files\MyWebSearch\bar\3.bin\F3HISTSW.DLL
c:\program files\MyWebSearch\bar\3.bin\F3HTMLMU.DLL
c:\program files\MyWebSearch\bar\3.bin\F3HTTPCT.DLL
c:\program files\MyWebSearch\bar\3.bin\F3IMSTUB.DLL
c:\program files\MyWebSearch\bar\3.bin\F3POPSWT.DLL
c:\program files\MyWebSearch\bar\3.bin\F3PSSAVR.SCR
c:\program files\MyWebSearch\bar\3.bin\F3REPROX.DLL
c:\program files\MyWebSearch\bar\3.bin\F3RESTUB.DLL
c:\program files\MyWebSearch\bar\3.bin\F3SCHMON.EXE
c:\program files\MyWebSearch\bar\3.bin\F3SCrctr.dll
c:\program files\MyWebSearch\bar\3.bin\F3SPACER.WMV
c:\program files\MyWebSearch\bar\3.bin\F3WALLPP.DAT
c:\program files\MyWebSearch\bar\3.bin\FWPBUDDY.PNG
c:\program files\MyWebSearch\bar\3.bin\M3FFXTBR.JAR
c:\program files\MyWebSearch\bar\3.bin\M3FFXTBR.MANIFEST
c:\program files\MyWebSearch\bar\3.bin\M3HIGHIN.EXE
c:\program files\MyWebSearch\bar\3.bin\M3HTML.DLL
c:\program files\MyWebSearch\bar\3.bin\M3IDLE.DLL
c:\program files\MyWebSearch\bar\3.bin\M3IMPIPE.EXE
c:\program files\MyWebSearch\bar\3.bin\M3MEDINT.EXE
c:\program files\MyWebSearch\bar\3.bin\M3MSG.DLL
c:\program files\MyWebSearch\bar\3.bin\M3NTSTBR.JAR
c:\program files\MyWebSearch\bar\3.bin\M3NTSTBR.MANIFEST
c:\program files\MyWebSearch\bar\3.bin\M3OUtlcn.dll
c:\program files\MyWebSearch\bar\3.bin\M3PLUGIN.DLL
c:\program files\MyWebSearch\bar\3.bin\M3SKIN.DLL
c:\program files\MyWebSearch\bar\3.bin\M3SKPLAY.EXE
c:\program files\MyWebSearch\bar\3.bin\M3SLSRCH.EXE
c:\program files\MyWebSearch\bar\3.bin\M3SRCHMN.EXE
c:\program files\MyWebSearch\bar\3.bin\MWSBAR.DLL
c:\program files\MyWebSearch\bar\3.bin\MWSOEMON.EXE
c:\program files\MyWebSearch\bar\3.bin\MWSOEPLG.DLL
c:\program files\MyWebSearch\bar\3.bin\MWSOESTB.DLL
c:\program files\MyWebSearch\bar\3.bin\MWSSVC.EXE
c:\program files\MyWebSearch\bar\3.bin\NPMYWEBS.DLL
c:\program files\MyWebSearch\bar\Avatar\COMMON.F3S
c:\program files\MyWebSearch\bar\Game\CHECKERS.F3S
c:\program files\MyWebSearch\bar\Game\CHESS.F3S
c:\program files\MyWebSearch\bar\Game\REVERSI.F3S
c:\program files\MyWebSearch\bar\icons\CM.ICO
c:\program files\MyWebSearch\bar\icons\MFC.ICO
c:\program files\MyWebSearch\bar\icons\PSS.ICO
c:\program files\MyWebSearch\bar\icons\SMILEY.ICO
c:\program files\MyWebSearch\bar\icons\WB.ICO
c:\program files\MyWebSearch\bar\icons\ZWINKY.ICO
c:\program files\MyWebSearch\bar\Message\COMMON.F3S
c:\program files\MyWebSearch\bar\Notifier\COMMON.F3S
c:\program files\MyWebSearch\bar\Notifier\DOG.F3S
c:\program files\MyWebSearch\bar\Notifier\FISH.F3S
c:\program files\MyWebSearch\bar\Notifier\KUNGFU.F3S
c:\program files\MyWebSearch\bar\Notifier\LIFEGARD.F3S
c:\program files\MyWebSearch\bar\Notifier\MAID.F3S
c:\program files\MyWebSearch\bar\Notifier\MAILBOX.F3S
c:\program files\MyWebSearch\bar\Notifier\OPERA.F3S
c:\program files\MyWebSearch\bar\Notifier\ROBOT.F3S
c:\program files\MyWebSearch\bar\Notifier\SEDUCT.F3S
c:\program files\MyWebSearch\bar\Notifier\SURFER.F3S
c:\program files\MyWebSearch\bar\Settings\s_pid.dat
c:\program files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
c:\program files\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL
c:\program files\MyWebSearch\SrchAstt\3.bin\MWSSRCAS.DLL
c:\program files\SGPSA
c:\program files\SGPSA\mtwb3sh.dll
c:\windows\010112010146116101.xxe
c:\windows\0101120101464855.xxe
c:\windows\0101120101465050.xxe
c:\windows\0101120101465249.xxe
c:\windows\0101120101465349.xxe
c:\windows\0101120101465649.xxe
c:\windows\bk23567.dat
c:\windows\rdr_1255745779.exe
c:\windows\system32\buhojazi.dll
c:\windows\system32\busirado.dll
c:\windows\system32\f3PSSavr.scr
c:\windows\system32\herutoho.dll
c:\windows\system32\hizuriki.dll
c:\windows\system32\hogumana.dll
c:\windows\system32\huwulita.dll
c:\windows\system32\kozodobe.dll
c:\windows\system32\kuzapiso.dll
c:\windows\system32\meyeyihi.dll
c:\windows\system32\mofomugo.dll
c:\windows\system32\reforola.dll
c:\windows\system32\tilufewa.dll
c:\windows\system32\veyozuli.dll
c:\windows\system32\vonineye.dll
c:\windows\system32\zadoleso.dll
c:\windows\Tasks\aecqldom.job
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_MyWebSearchService
((((((((((((((((((((((((( Files Created from 2009-10-25 to 2009-11-25 )))))))))))))))))))))))))))))))
.
2009-11-25 03:48 . 2009-11-25 03:48 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2009-11-25 03:48 . 2009-11-25 03:48 -------- d-----w- c:\users\TEMP\AppData\Local\temp
2009-11-25 03:48 . 2009-11-25 03:48 -------- d-----w- c:\users\matt\AppData\Local\temp
2009-11-25 03:48 . 2009-11-25 03:48 -------- d-----w- c:\users\Liz\AppData\Local\temp
2009-11-25 03:48 . 2009-11-25 03:48 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-11-25 03:48 . 2009-11-25 03:48 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2009-11-25 03:30 . 2009-11-25 03:31 49152 d-----w- C:\32788R22FWJFW
2009-11-25 02:39 . 2009-11-25 02:39 4096 d-----w- C:\JustZIPit
2009-11-25 02:39 . 2009-11-25 02:39 386560 ----a-w- c:\windows\System32\config\systemprofile\AppData\Roaming\Free-backup.info\JustZIPit\JustZIPit.exe
2009-11-25 02:39 . 2009-11-25 02:39 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Roaming\Free-backup.info
2009-11-25 00:45 . 2009-11-25 00:45 -------- d-----w- c:\program files\Trend Micro
2009-11-24 03:16 . 2009-11-24 03:16 10752 ----a-w- c:\windows\DCEBoot.exe
2009-11-24 00:53 . 2009-11-24 00:53 -------- d-----w- c:\programdata\WindowsSearch
2009-11-23 04:10 . 2009-11-23 03:16 497944 ----a-w- c:\programdata\avg9\update\backup\avgchjwx.dll
2009-11-23 04:10 . 2009-11-23 03:16 3963648 ----a-w- c:\programdata\avg9\update\backup\avgcorex.dll
2009-11-23 04:08 . 2009-11-23 03:16 877848 ----a-w- c:\programdata\avg9\update\backup\avgupd.exe
2009-11-23 04:08 . 2009-11-23 03:16 1657112 ----a-w- c:\programdata\avg9\update\backup\avgupd.dll
2009-11-23 03:17 . 2009-11-23 05:35 -------- d-----w- C:\$AVG
2009-11-23 03:17 . 2009-11-23 03:17 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-11-23 03:17 . 2009-11-23 03:17 161800 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2009-11-23 03:17 . 2009-11-23 03:17 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-11-23 03:17 . 2009-11-23 03:17 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-11-23 03:17 . 2009-11-23 03:17 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-11-23 03:16 . 2009-11-25 00:33 4096 d-----w- c:\windows\system32\drivers\Avg
2009-11-23 03:15 . 2009-11-23 03:15 24856 ----a-w- c:\windows\system32\drivers\avgfwd6x.sys
2009-11-23 03:15 . 2009-11-23 03:15 -------- d-----w- c:\program files\AVG
2009-11-23 03:15 . 2009-11-23 03:15 4096 d-----w- c:\programdata\avg9
2009-11-22 19:06 . 2009-11-25 03:28 4096 d-----w- c:\program files\TrojanHunter 5.2
2009-11-22 18:30 . 2009-11-22 18:30 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Roaming\McAfee
2009-11-22 17:54 . 2009-11-22 17:54 -------- d-sh--w- c:\windows\system32\%APPDATA%
2009-11-22 15:32 . 2009-11-22 15:32 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Roaming\TrojanHunter
2009-11-22 06:17 . 2009-11-22 06:17 -------- d-----w- c:\program files\CCleaner
2009-11-22 06:11 . 2009-11-22 06:11 4096 d-----w- c:\program files\TrojanHunter 5.0
2009-11-22 05:50 . 2009-11-25 00:30 4096 d-----w- c:\programdata\PCPitstop
2009-11-22 05:50 . 2009-11-22 05:50 -------- d-----w- c:\program files\PCPitstop
2009-11-22 02:59 . 2009-11-04 22:53 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys
2009-11-22 02:59 . 2009-11-04 22:54 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-11-22 02:59 . 2009-11-04 22:54 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-11-22 02:59 . 2009-11-04 22:54 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-11-22 02:59 . 2009-11-04 22:54 214664 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-11-22 02:59 . 2009-07-16 18:32 130424 ----a-w- c:\windows\system32\drivers\Mpfp.sys
2009-11-22 02:58 . 2009-11-22 02:59 -------- d-----w- c:\program files\McAfee.com
2009-11-22 02:58 . 2009-11-22 02:59 4096 d-----w- c:\program files\Common Files\McAfee
2009-11-22 02:58 . 2009-11-22 02:58 -------- d-----w- c:\users\TEMP\AppData\Local\Mozilla
2009-11-22 02:58 . 2009-11-25 00:29 4096 d-----w- c:\program files\McAfee
2009-11-22 02:46 . 2009-11-22 20:58 4096 d-----w- c:\programdata\McAfee
2009-11-22 02:38 . 2009-08-07 02:24 44768 ----a-w- c:\windows\system32\wups2.dll
2009-11-22 02:38 . 2009-08-07 02:24 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-11-22 02:38 . 2009-08-07 02:23 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-11-22 02:38 . 2009-08-07 01:45 2421760 ----a-w- c:\windows\system32\wucltux.dll
2009-11-22 02:36 . 2009-08-07 01:23 171608 ----a-w- c:\windows\system32\wuwebv.dll
2009-11-22 02:36 . 2009-08-07 00:44 33792 ----a-w- c:\windows\system32\wuapp.exe
2009-11-22 02:08 . 2009-11-22 02:08 0 ----a-w- c:\windows\nsreg.dat
2009-11-22 02:07 . 2009-11-22 02:07 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\Mozilla
2009-11-11 06:28 . 2009-11-11 06:28 247280 ----a-w- c:\users\TEMP\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
2009-10-31 15:51 . 2009-05-18 19:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-10-31 15:51 . 2008-04-17 18:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-10-31 15:50 . 2009-10-31 15:50 -------- d-----w- c:\program files\iPod
2009-10-31 15:50 . 2009-10-31 15:51 4096 d-----w- c:\program files\iTunes
2009-10-31 15:50 . 2009-10-31 15:51 -------- d-----w- c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-10-31 15:47 . 2009-10-31 15:48 4096 d-----w- c:\program files\QuickTime
2009-10-29 01:58 . 2009-10-29 01:58 79144 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-22 06:03 . 2007-04-10 09:04 8192 d--h--w- c:\program files\InstallShield Installation Information
2009-10-31 15:53 . 2008-11-24 01:32 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Roaming\Apple Computer
2009-10-31 15:50 . 2007-12-25 17:43 -------- d-----w- c:\program files\Common Files\Apple
2009-10-19 02:33 . 2009-10-19 02:33 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Roaming\ooVoo Details
2009-10-18 14:18 . 2009-10-16 03:04 8240 ----a-w- c:\windows\fs1235.dat
2009-10-17 13:02 . 2007-10-07 06:48 58896 ----a-w- c:\windows\system32\config\systemprofile\AppData\Local\GDIPFONTCACHEV1.DAT
2009-10-16 20:20 . 2009-10-15 22:03 29 ----a-w- c:\windows\bk20856.dat
2009-10-15 12:01 . 2006-11-02 11:18 4096 d-----w- c:\program files\Windows Mail
2009-10-15 11:54 . 2007-10-06 20:20 8192 d-----w- c:\programdata\Microsoft Help
2009-10-11 00:36 . 2009-10-11 00:28 -------- d-----w- c:\program files\PlaySushi
2009-09-30 01:34 . 2007-11-25 15:41 58896 ----a-w- c:\users\matt\AppData\Local\GDIPFONTCACHEV1.DAT
2009-09-20 04:39 . 2008-10-29 17:27 58896 ----a-w- c:\users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2009-09-14 09:44 . 2009-10-14 21:29 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2009-09-12 13:00 . 2008-11-11 00:48 58896 ----a-w- c:\users\TEMP\AppData\Local\GDIPFONTCACHEV1.DAT
2009-09-10 17:30 . 2009-10-14 21:32 213504 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 12:24 . 2009-10-14 21:29 61440 ----a-w- c:\windows\system32\msasn1.dll
2009-09-04 10:55 . 2009-08-22 12:31 8192 ----a-w- c:\users\Public\mtwb.dat
2009-08-31 13:55 . 2009-10-14 21:31 293376 ----a-w- c:\windows\system32\psisdecd.dll
2009-08-31 13:55 . 2009-10-14 21:31 428544 ----a-w- c:\windows\system32\EncDec.dll
2009-08-29 00:42 . 2009-08-29 00:42 40448 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-08-29 00:42 . 2009-08-29 00:42 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-08-28 12:39 . 2009-09-02 23:53 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-08-28 10:15 . 2009-09-02 23:53 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-27 05:22 . 2009-10-14 21:31 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-27 05:17 . 2009-10-14 21:31 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-08-27 05:17 . 2009-10-14 21:31 71680 ----a-w- c:\windows\system32\iesetup.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"Google Update"="c:\users\Default\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-11-02 135664]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2009-09-03 3342336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-23 815104]
"AcerOrbicamRibbon"="c:\program files\Acer\OrbiCam10\OrbiCam.exe" [2006-11-29 754712]
"LogitechCommunicationsManager"="c:\program files\Common Files\Logitech\LComMgr\Communications_Helper.exe" [2006-10-31 304664]
"LVCOMSX"="c:\program files\Common Files\Logitech\LComMgr\LVComSX.exe" [2006-11-29 244512]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2009-11-23 2020120]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-03-01 4390912]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Exetender"="c:\program files\Free Ride Games\GPlayer.exe" [2008-11-10 2057216]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Empowering Technology Launcher.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Empowering Technology Launcher.lnk
backup=c:\windows\pss\Empowering Technology Launcher.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^Liz^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\users\Liz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3771958223-2023274512-727475370-1002]
"EnableNotificationsRef"=dword:00000001
R0 AvgRkx86;avgrkx86.sys;c:\windows\System32\drivers\avgrkx86.sys [11/22/2009 9:17 PM 161800]
R1 Avgfwfd;AVG network filter service;c:\windows\System32\drivers\avgfwd6x.sys [11/22/2009 9:15 PM 24856]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [11/22/2009 9:17 PM 333192]
R1 AvgTdiX;AVG Network Redirector;c:\windows\System32\drivers\avgtdix.sys [11/22/2009 9:17 PM 360584]
R2 ALaunchService;ALaunch Service;c:\acer\ALaunch\ALaunchSvc.exe [4/10/2007 4:11 AM 50688]
R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [11/22/2009 9:16 PM 285392]
R2 avgfws9;AVG Firewall;c:\program files\AVG\AVG9\avgfws9.exe [11/22/2009 9:16 PM 2304192]
R2 PCPitstop Scheduling;PCPitstop Scheduling;c:\program files\PCPitstop\PCPitstopScheduleService.exe [11/21/2009 11:50 PM 90352]
R2 X4HSX32Ex;X4HSX32Ex;c:\program files\Free Ride Games\X4HSX32Ex.sys [12/19/2008 10:02 PM 29856]
.
Contents of the 'Scheduled Tasks' folder
2009-11-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3771958223-2023274512-727475370-1002Core.job
- c:\users\Default\AppData\Local\Google\Update\GoogleUpdate.exe [2009-11-02 02:54]
2009-11-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3771958223-2023274512-727475370-1002UA.job
- c:\users\Default\AppData\Local\Google\Update\GoogleUpdate.exe [2009-11-02 02:54]
2009-11-22 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-11-22 18:22]
2009-11-22 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-11-22 18:22]
2009-11-25 c:\windows\Tasks\User_Feed_Synchronization-{63A03D36-4E5F-4208-A186-418FA1F8141A}.job
- c:\windows\system32\msfeedssync.exe [2009-10-14 03:41]
2009-11-25 c:\windows\Tasks\User_Feed_Synchronization-{E63C9BD3-FBDC-4D57-B6E9-3C60F118C076}.job
- c:\windows\system32\msfeedssync.exe [2009-10-14 03:41]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://en.us.acer.yahoo.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
IE: &Search -
http://edits.mywebse...arch.jhtml?p=ZC
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: internet
Trusted Zone: mcafee.com
DPF: {0C92900E-4D5A-4F04-ACC9-729E1767BBAE} - hxxp://www.ritzpix.com/net/Uploader/LPUploader45.cab
FF - ProfilePath - c:\windows\System32\config\SYSTEM~1\AppData\Roaming\Mozilla\Firefox\Profiles\pf0onznw.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: browser.startup.homepage - hxxp://search.notepad.com
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\progra~1\SONYON~1\npsoe.dll
FF - plugin: c:\program files\Free Ride Games\npExentCtl.dll
FF - plugin: c:\program files\McAfee\Supportability\MVT\NPMVTPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPMyWebS.dll
FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: c:\users\Default\AppData\Local\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\users\TEMP\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
HKLM-Run-MyWebSearch Plugin - c:\progra~1\MYWEBS~1\bar\3.bin\M3PLUGIN.DLL
HKLM-Run-My Web Search Bar Search Scope Monitor - c:\progra~1\MYWEBS~1\bar\3.bin\m3SrchMn.exe
HKLM-Run-kokadehuy - c:\windows\system32\hizuriki.dll
HKLM-Run-eRecoveryService - (no file)
SharedTaskScheduler-{4deb8c89-5f42-4e42-9dc8-858e6f0d431a} - (no file)
SharedTaskScheduler-{d63283f1-6b7e-4327-8905-8b95d33855e2} - (no file)
SharedTaskScheduler-{c18ffeb2-c024-474f-8003-f0d19a8a5f2a} - (no file)
SharedTaskScheduler-{c6afd853-2924-4586-b309-df5474881642} - (no file)
SharedTaskScheduler-{0ad37cf9-4c49-4829-8d48-b04c9672b4cd} - (no file)
SharedTaskScheduler-{48ed6674-5e78-4ee0-b0b3-811fe1d0bb94} - c:\windows\system32\hizuriki.dll
SharedTaskScheduler-{182ceb49-cad4-4366-96c5-1d37bcafbac9} - c:\windows\system32\pehuraba.dll
SSODL-toditizab-{4deb8c89-5f42-4e42-9dc8-858e6f0d431a} - (no file)
SSODL-mitevuriv-{d63283f1-6b7e-4327-8905-8b95d33855e2} - (no file)
SSODL-libifafeb-{c18ffeb2-c024-474f-8003-f0d19a8a5f2a} - (no file)
SSODL-nitahopuz-{c6afd853-2924-4586-b309-df5474881642} - (no file)
SSODL-fisunevaf-{0ad37cf9-4c49-4829-8d48-b04c9672b4cd} - (no file)
SSODL-ladugihit-{48ed6674-5e78-4ee0-b0b3-811fe1d0bb94} - c:\windows\system32\hizuriki.dll
SSODL-pufahayoy-{182ceb49-cad4-4366-96c5-1d37bcafbac9} - c:\windows\system32\pehuraba.dll
AddRemove-AcerOrbiCamDrv - c:\program files\Common Files\Acer\OrbiCam\BIN\SETUP.EXE UNINSTALL REMOVEPROMPT
AddRemove-CCleaner - c:\program files\CCleaner\uninst.exe
AddRemove-GridVista - c:\windows\UnInst32.exe GridV.UNI
AddRemove-LManager - c:\windows\UnInst32.exe LManager.UNI
AddRemove-Monopoly - c:\program files\Yahoo! Games\Monopoly\Uninstall.exe {6517CFDF-B7A4-77B6-2371-C76608D3C976}
**************************************************************************
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-11-24 21:53
ComboFix-quarantined-files.txt 2009-11-25 03:53
Pre-Run: 31,394,951,168 bytes free
Post-Run: 31,395,368,960 bytes free
- - End Of File - - 546382BAB2FBFCC4D8A3535122FC7370