Sorry for the late reply…
ComboFix 10-05-21.06 - LYNDA 22/05/2010 17:13:40.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.510.232 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
C:\a.zip
c:\docume~1\LYNDA~1.LOU\LOCALS~1\Temp\install_flash_player.exe
c:\documents and settings\LYNDA.LOUIS\Local Settings\Application Data\icqgsym.exe
c:\program files\webmediaplayer\resources\languages_v2.xml
c:\program files\webmediaplayer\resources\webmedias
c:\program files\webmediaplayer\skins\classic.skn
c:\program files\webmediaplayer\sqlite3.dll
c:\windows\system32\18467.exe
c:\windows\system32\41.exe
c:\windows\system32\6334.exe
c:\windows\system32\bszip.dll
c:\windows\system32\crt.dat
c:\windows\system32\ES15.exe
c:\windows\system32\helpers32.dll
c:\windows\system32\kboem32.dat
c:\windows\system32\warnings.html
c:\windows\Temp\tmp3.tmp
Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty had a snack
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_NPF
((((((((((((((((((((((((( Files Created from 2010-04-22 to 2010-05-22 )))))))))))))))))))))))))))))))
.
2010-05-22 16:10 . 2008-04-13 18:40 96512 —-a-w- c:\windows\system32\drivers\atapi.sys
2010-05-22 08:33 . 2010-05-22 08:33 ——– d—–w- c:\documents and settings\Amy.FAMILY\Application Data\PC Tools
2010-05-22 08:33 . 2010-05-22 08:33 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Tools
2010-05-14 10:41 . 2010-05-21 12:26 ——– d—–w- c:\documents and settings\Amy.FAMILY\Local Settings\Application Data\WMTools Downloaded Files
2010-05-04 14:12 . 2010-05-04 14:12 ——– d—–w- c:\documents and settings\Amy.FAMILY\Application Data\Template
2010-05-01 13:04 . 2010-05-01 13:04 ——– d-sh–w- c:\documents and settings\Amy.FAMILY\IECompatCache
2010-04-24 15:14 . 2010-04-24 15:14 ——– d-sh–w- c:\documents and settings\Amy.FAMILY\PrivacIE
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-22 09:36 . 2003-10-08 11:05 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-05-22 09:16 . 2007-12-03 18:57 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-05-22 09:15 . 2010-02-15 14:13 ——– d—–w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-05-21 20:51 . 2010-05-21 20:51 20 —-a-w- c:\documents and settings\Amy.FAMILY\Application Data\qvjsge.dat
2010-05-12 10:19 . 2004-10-11 13:21 ——– d—–w- c:\program files\Common Files\Adobe
2010-05-03 08:17 . 2010-02-19 19:32 ——– d—–w- c:\documents and settings\Amy.FAMILY\Application Data\Apple Computer
2010-05-02 19:03 . 2010-03-06 11:04 ——– d—–w- c:\documents and settings\LYNDA.LOUIS\Application Data\KewlBoxPrefs
2010-04-21 17:08 . 2010-04-21 17:06 ——– d—–w- c:\program files\iTunes
2010-04-21 17:08 . 2010-04-21 17:06 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-04-21 17:06 . 2010-04-21 17:06 ——– d—–w- c:\program files\iPod
2010-04-21 17:06 . 2010-02-17 18:47 ——– d—–w- c:\program files\Common Files\Apple
2010-04-21 16:59 . 2010-02-17 18:52 ——– d—–w- c:\program files\QuickTime
2010-04-21 16:53 . 2010-04-21 16:53 ——– d—–w- c:\program files\Bonjour
2010-04-16 11:14 . 2005-11-23 17:39 ——– d—–w- c:\program files\MSN Messenger
2010-04-09 07:46 . 2010-01-25 19:17 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-03-31 09:01 . 2010-03-16 18:35 ——– d—–w- c:\documents and settings\LYNDA.LOUIS\Application Data\vlc
2010-03-26 10:15 . 2010-03-05 15:22 ——– d—–w- c:\documents and settings\Amy.FAMILY\Application Data\KewlBoxPrefs
2010-03-24 14:16 . 2009-07-11 10:33 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-03-10 06:15 . 2002-08-29 04:00 420352 —-a-w- c:\windows\system32\vbscript.dll
2010-02-25 06:24 . 2004-02-06 17:05 916480 —-a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 2002-08-29 04:00 455680 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2005-05-13 16:12 . 2005-05-13 16:12 217073 –sha-r- c:\windows\meta4.exe
2005-10-24 10:13 . 2005-10-24 10:13 66560 –sha-r- c:\windows\MOTA113.exe
2005-10-13 20:27 . 2005-10-13 20:27 422400 –sha-r- c:\windows\x2.64.exe
2005-10-07 18:14 . 2005-10-07 18:14 308224 –sha-r- c:\windows\SYSTEM32\avisynth.dll
2005-07-14 11:31 . 2005-07-14 11:31 27648 –sha-r- c:\windows\SYSTEM32\AVSredirect.dll
2005-06-26 14:32 . 2005-06-26 14:32 616448 –sha-r- c:\windows\SYSTEM32\cygwin1.dll
2005-06-21 21:37 . 2005-06-21 21:37 45568 –sha-r- c:\windows\SYSTEM32\cygz.dll
2009-09-04 11:24 . 2009-05-07 17:37 88 –sh–r- c:\windows\SYSTEM32\FC37759F07.sys
2004-01-24 23:00 . 2004-01-24 23:00 70656 –sha-r- c:\windows\SYSTEM32\i420vfw.dll
2009-09-04 11:25 . 2009-05-07 17:14 2516 –sha-w- c:\windows\SYSTEM32\KGyGaAvL.sys
2006-04-27 09:24 . 2006-04-27 09:24 2945024 –sha-r- c:\windows\SYSTEM32\Smab.dll
2005-02-28 12:16 . 2005-02-28 12:16 240128 –sha-r- c:\windows\SYSTEM32\x.264.exe
2004-01-24 23:00 . 2004-01-24 23:00 70656 –sha-r- c:\windows\SYSTEM32\yv12vfw.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-01-05 2002160]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpeedTouch USB Diagnostics"="c:\program files\Thomson\SpeedTouch USB\Dragdiag.exe" [2004-01-26 866816]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-10-19 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-10-19 126976]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-17 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-03-26 142120]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
BT Yahoo! Help.lnk - c:\program files\BT Yahoo\BT Yahoo Help\bin\matcli.exe [2010-2-15 217088]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 14:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-12 17:37 11952 —-a-w- c:\windows\SYSTEM32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 AvgRkx86;avgrkx86.sys;c:\windows\SYSTEM32\DRIVERS\avgrkx86.sys [11/05/2009 19:32 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [11/05/2009 19:32 325896]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\SYSTEM32\DRIVERS\avgtdix.sys [11/05/2009 19:32 108552]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [05/01/2010 08:56 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [05/01/2010 08:56 74480]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [05/01/2010 08:56 7408]
S0 esff;esff;c:\windows\system32\drivers\esff.sys –> c:\windows\system32\drivers\esff.sys [?]
S2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe –> c:\progra~1\AVG\AVG8\avgemc.exe [?]
S2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe –> c:\progra~1\AVG\AVG8\avgwdsvc.exe [?]
S2 gupdate1ca2bb85a67c670;Google Update Service (gupdate1ca2bb85a67c670);c:\program files\Google\Update\GoogleUpdate.exe [02/09/2009 11:30 133104]
S2 SVKP;SVKP; [x]
S3 EraserUtilDrv10614;EraserUtilDrv10614;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10614.sys –> c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10614.sys [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2010-05-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2010-05-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-02 10:30]
2010-05-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-02 10:30]
2010-05-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1981325244-2770366524-784814343-1015Core.job
- c:\documents and settings\Amy.FAMILY\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-03-10 21:00]
2010-05-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1981325244-2770366524-784814343-1015UA.job
- c:\documents and settings\Amy.FAMILY\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-03-10 21:00]
2009-12-23 c:\windows\Tasks\NSSstub.job
- c:\windows\system32\Adobe\Shockwave 11\nssstub.exe [2009-12-17 20:29]
2010-05-22 c:\windows\Tasks\User_Feed_Synchronization-{0E0F1A53-A5B0-4B2F-AA2C-FCF35A3FAFC1}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 03:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = www.rihannadaily.com
mSearch Bar = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/sb/*http://uk.docs.yahoo.com/info/bt_side.html
uInternet Settings,ProxyOverride = local
uSearchURL,(Default) = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/su/*http://uk.search.yahoo.com/
Trusted Zone: digital-supply.com
Trusted Zone: get-key-se10.com
FF - ProfilePath - c:\documents and settings\LYNDA.LOUIS\Application Data\Mozilla\Firefox\Profiles\k2mrq08p.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2151295&SearchSource;=3&q;=
FF - prefs.js: browser.search.selectedEngine - Rihanna Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT2151295&SearchSource;=13
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2151295&SearchSource;=2&q;=
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.
- - - - ORPHANS REMOVED - - - -
BHO-{2AFC0E7A-BDC7-933C-C3BE-97FC5AFEBD9C} - c:\windows\system32\rxoq.dll
WebBrowser-{A057A204-BACC-4D26-B2F2-48F8CCAB3ED4} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-05-22 17:28
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\Toolbar\QuickComplete]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
@DACL=(02 0000)
@=""
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
@DACL=(02 0000)
@=""
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
@DACL=(02 0000)
@=""
"Installed"="1"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(692)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(3180)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\PSIService.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\windows\wanmpsvc.exe
c:\program files\BT Yahoo\BT Yahoo Help\bin\mad.exe
c:\program files\BT Yahoo\BT Yahoo Help\bin\mpbtn.exe
c:\progra~1\Motive\ASSTCO~1\MOTIVE~1.EXE
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2010-05-22 17:44:21 - machine was rebooted
ComboFix-quarantined-files.txt 2010-05-22 16:43
Pre-Run: 16,693,723,136 bytes free
Post-Run: 16,631,918,592 bytes free
- - End Of File - - 901BC3EBB01850C9A25D3EA2AD7CB89D