Everything seems to be running like it used to no extra browsers.
Thank you so much for your patience and expertise.
Here is the log
ComboFix 10-05-05.04 - JOHN BAITY 05/05/2010 21:34:24.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1535.1040 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\WindowsUpdate
c:\windows\system32\BSTIEPrintCtl1.dll
Infected copy of c:\windows\system32\drivers\kbdhid.sys was found and disinfected
Restored copy from - Kitty had a snack
.
((((((((((((((((((((((((( Files Created from 2010-04-06 to 2010-05-06 )))))))))))))))))))))))))))))))
.
2010-05-05 21:47 . 2010-04-29 20:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-05 21:47 . 2010-05-05 21:47 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-05-05 21:47 . 2010-04-29 20:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-05-04 21:05 . 2010-05-04 21:06 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-06 02:31 . 2007-12-26 20:53 ——– d—–w- c:\documents and settings\JOHN BAITY\Application Data\WTablet
2010-05-05 17:19 . 2004-06-27 19:04 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-05-05 12:27 . 2004-06-27 19:04 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-05-04 12:58 . 2010-02-26 21:30 566432 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\EmailScanner.dll
2010-05-04 12:58 . 2009-10-12 13:45 893952 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\threatwork.exe
2010-05-04 12:58 . 2009-10-27 17:25 15880 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\lsdelete.exe
2010-05-04 12:58 . 2009-10-12 19:35 15880 —-a-w- c:\windows\system32\lsdelete.exe
2010-05-04 12:58 . 2009-10-12 13:45 211600 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\lavamessage.dll
2010-05-04 12:58 . 2009-10-12 13:45 397480 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\lavalicense.dll
2010-05-04 12:58 . 2009-10-12 13:45 574632 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\aawapi.dll
2010-05-04 12:58 . 2009-10-27 17:25 221920 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\VipreBridge.dll
2010-05-04 12:58 . 2009-10-12 13:45 443344 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\UpdateManager.dll
2010-05-04 12:58 . 2009-10-12 13:45 167824 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\ShellExt.dll
2010-05-04 12:56 . 2009-10-27 17:24 6306640 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Resources.dll
2010-05-04 12:56 . 2009-10-12 13:44 335728 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\RPAPI.dll
2010-05-04 12:56 . 2009-10-12 13:44 95248 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\PrivacyClean.dll
2010-05-04 12:56 . 2010-02-26 21:29 16456 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\EmailScannerBridge.dll
2010-05-04 12:56 . 2009-10-12 13:44 967640 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\CEAPI.dll
2010-05-04 12:55 . 2009-10-12 13:44 866224 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Ad-AwareCommand.exe
2010-05-04 12:55 . 2009-10-12 13:44 871320 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Ad-AwareAdmin.exe
2010-05-04 12:55 . 2009-10-12 13:44 1598464 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Ad-Aware.exe
2010-05-04 12:55 . 2010-05-04 12:55 755096 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\AAWWSC.exe
2010-05-04 12:55 . 2009-10-12 13:44 834248 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\AAWTray.exe
2010-05-04 12:55 . 2009-10-12 13:44 1285864 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\AAWService.exe
2010-04-30 03:19 . 2010-03-07 11:20 439816 —-a-w- c:\documents and settings\JOHN BAITY\Application Data\Real\Update\setup3.10\setup.exe
2010-04-29 02:41 . 2010-04-29 02:41 13407072 —-a-w- c:\documents and settings\JOHN BAITY\Application Data\Real\Update\setup3.10\chr\ChromeInstaller.exe
2010-04-19 02:46 . 2009-12-16 22:22 128768 —ha-w- c:\windows\system32\mlfcache.dat
2010-04-12 12:44 . 2009-08-02 21:38 ——– d—–w- c:\program files\McAfee
2010-04-05 15:01 . 2010-04-05 15:01 516480 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\EmailScannerAddin.dll
2010-04-05 15:01 . 2010-04-05 15:01 17632 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\WSCUpdate.dll
2010-03-23 02:42 . 2010-03-23 02:40 20846064 —-a-w- c:\documents and settings\JOHN BAITY\Application Data\Real\Update\setup3.10\rp\RealPlayerSPGold.exe
2010-03-10 06:15 . 2003-01-27 19:54 420352 —-a-w- c:\windows\system32\vbscript.dll
2010-03-07 19:24 . 2010-03-07 19:24 8405312 —-a-w- c:\documents and settings\JOHN BAITY\Application Data\Real\Update\setup3.10\gtb\GOOGLE_TOOLBAR\GoogleToolbarInstaller.exe
2010-03-07 19:23 . 2010-03-07 19:23 149000 —-a-w- c:\documents and settings\JOHN BAITY\Application Data\Real\Update\setup3.10\chr_helper\LaunchHelper.exe
2010-03-07 19:21 . 2010-03-07 19:21 283280 —-a-w- c:\documents and settings\JOHN BAITY\Application Data\Real\Update\setup3.10\carb\CarboniteSetupLiteRealPreinstaller.exe
2010-03-07 19:21 . 2010-03-07 19:21 181768 —-a-w- c:\documents and settings\JOHN BAITY\Application Data\Real\Update\setup3.10\carb\LaunchHelper.exe
2010-03-07 19:21 . 2010-03-07 19:21 79368 —-a-w- c:\documents and settings\JOHN BAITY\Application Data\Real\Update\setup3.10\RUP\vista.exe
2010-03-07 19:21 . 2010-03-07 19:21 64000 —-a-w- c:\documents and settings\JOHN BAITY\Application Data\Real\Update\setup3.10\RUP\inst_config\gcapi_dll.dll
2010-03-07 19:21 . 2010-03-07 19:21 52288 —-a-w- c:\documents and settings\JOHN BAITY\Application Data\Real\Update\setup3.10\RUP\inst_config\gtapi.dll
2010-03-07 19:21 . 2010-03-07 19:21 50688 —-a-w- c:\documents and settings\JOHN BAITY\Application Data\Real\Update\setup3.10\RUP\inst_config\fftbapi.dll
2010-03-07 19:21 . 2010-03-07 19:21 49152 —-a-w- c:\documents and settings\JOHN BAITY\Application Data\Real\Update\setup3.10\RUP\inst_config\CarboniteCompatibility.dll
2010-03-07 19:21 . 2010-03-07 19:21 118784 —-a-w- c:\documents and settings\JOHN BAITY\Application Data\Real\Update\setup3.10\RUP\inst_config\compat.dll
2010-03-02 22:56 . 2002-10-16 19:52 183184 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-26 21:30 . 2009-10-27 17:25 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-02-26 21:30 . 2009-10-27 17:25 95024 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Drivers\SBREDrv.sys
2010-02-26 21:30 . 2009-10-27 17:25 566608 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\sbap.dll
2010-02-26 21:29 . 2009-10-27 17:25 1230160 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\SBTE.dll
2010-02-26 21:29 . 2009-10-27 17:25 247120 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\SBRE.dll
2010-02-25 06:24 . 2004-02-06 23:05 916480 —-a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 2001-08-18 12:00 455680 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-17 14:10 . 1980-01-01 05:00 2189952 ——w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25 . 1980-01-01 05:00 2066816 ——w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 04:33 . 2003-01-27 17:40 100864 ——w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2001-08-18 12:00 226880 —-a-w- c:\windows\system32\drivers\tcpip6.sys
2010-02-05 13:42 . 2009-10-27 17:24 3803208 —-a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\AutoLaunch.exe
2005-11-19 01:31 . 2005-11-19 01:31 774144 -c–a-w- c:\program files\RngInterstitial.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MoneyAgent"="c:\program files\Microsoft Money\System\Money Express.exe" [2001-07-25 184376]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-03-18 4363504]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2008-09-26 2356088]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-04-10 679936]
"DellTouch"="c:\windows\MMKeybd.exe" [2001-09-05 163840]
"SideWinderTrayV4"="c:\progra~1\MI948F~1\GAMECO~1\common\swtrayv4.exe" [2000-06-28 24649]
"nwiz"="nwiz.exe" [2003-07-28 323584]
"Motive SmartBridge"="c:\progra~1\SBCSEL~1\SMARTB~1\MotiveSB.exe" [2003-12-10 380928]
"HostManager"="c:\program files\Common Files\AOL\1158509529\ee\AOLSoftware.exe" [2006-05-10 50760]
"IPHSend"="c:\program files\Common Files\AOL\IPHSend\IPHSend.exe" [2006-02-17 124520]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2003-07-28 49152]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2003-07-28 4841472]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-07-08 1176808]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-11-04 198160]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
c:\documents and settings\JOHN BAITY\Start Menu\Programs\Startup\
OneNote Table Of Contents.onetoc2 [2008-11-13 3656]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
AT&T; Self Support Tool.lnk - c:\program files\SBC Self Support Tool\bin\matcli.exe [2005-11-5 217088]
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\EA SPORTS\\NASCAR Thunder TM 2004\\NASCAR_Thunder_2004.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Papyrus\\NASCAR Racing 2003 Season\\NR2003.exe"=
"c:\\WINDOWS\\PCHEALTH\\HELPCTR\\Binaries\\helpctr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1158509529\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\1158509529\\ee\\aim6.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\SYSTEM32\\fxsclnt.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundRouterRequest"= 0 (0x0)
R0 Lbd;Lbd;c:\windows\SYSTEM32\DRIVERS\Lbd.sys [10/12/2009 8:30 AM 64288]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2/4/2010 10:52 AM 1285864]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [8/2/2009 4:44 PM 93320]
R2 Nhksrv;Netropa NHK Server;c:\windows\Nhksrv.exe [8/6/2001 1:41 PM 28672]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/10/2007 8:41 PM 24652]
R3 Msikbd2k;DellTouch;c:\windows\SYSTEM32\DRIVERS\Msikbd2k.sys [10/3/2000 3:18 PM 6942]
R3 tbcspud;Santa Cruz Driver;c:\windows\SYSTEM32\DRIVERS\tbcspud.sys [6/24/2009 1:44 PM 144768]
R3 tbcwdm;Santa Cruz WDM Driver;c:\windows\SYSTEM32\DRIVERS\tbcwdm.sys [6/24/2009 1:44 PM 545088]
S3 hati1tux;hati1tux;\??\c:\docume~1\JOHNBA~1\LOCALS~1\Temp\hati1tux.sys –> c:\docume~1\JOHNBA~1\LOCALS~1\Temp\hati1tux.sys [?]
S3 SWUSBFLT;Microsoft SideWinder VIA Filter Driver;c:\windows\SYSTEM32\DRIVERS\SWUSBFLT.SYS [10/24/2002 7:31 PM 3968]
S3 vtdg46xx;vtdg46xx;c:\progra~1\TURTLE~1\SANTAC~1\CONTRO~1\vtdg46xx.sys [6/24/2009 1:44 PM 19232]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
2010-05-04 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]
2010-04-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-08-02 17:22]
2010-05-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-08-02 17:22]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://dsl.sbc.yahoo.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\JOHN BAITY\Start Menu\Programs\IMVU\Run IMVU.lnk
Trusted Zone: clubpenguin.com
Trusted Zone: internet
Trusted Zone: mcafee.com
DPF: ChatSpace Full Java Client 4.0.0.320 - hxxp://irc.everywherechat.com:8000/Java/cfs40320.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{6A048BB7-E017-4326-B207-AA996C77BBCB} - (no file)
HKCU-Run-MsnMsgr - c:\program files\MSN Messenger\MsnMsgr.Exe
HKCU-Run-Aim6 - (no file)
AddRemove-LiveUpdate - c:\program files\Symantec\LiveUpdate\LSETUP.EXE
AddRemove-_{0C180787-F8C8-42FD-A9D3-689BA44BEAAF} - c:\program files\Corel\Corel Painter Essentials 3\MSILauncher {0C180787-F8C8-42FD-A9D3-689BA44BEAAF}
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-05-05 21:55
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-1482789601-3646181656-3495054330-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
Completion time: 2010-05-05 22:04:40
ComboFix-quarantined-files.txt 2010-05-06 03:04
Pre-Run: 1,843,216,384 bytes free
Post-Run: 1,867,079,680 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
- - End Of File - - F2D99C0DE590295697E19D965C3D42E8