Thanks for the quick replies. My computer is still behaving fine. Here is the combofix report:
ComboFix 10-06-17.02 - Justis 06/18/2010 12:01:43.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.502.196 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\st325602.dll
c:\windows\system32\win.com
.
((((((((((((((((((((((((( Files Created from 2010-05-18 to 2010-06-18 )))))))))))))))))))))))))))))))
.
2010-06-18 03:16 . 2010-06-18 03:16 ——– d—–w- c:\program files\ESET
2010-06-18 03:09 . 2010-06-18 03:09 ——– d-sh–w- c:\documents and settings\Justis\PrivacIE
2010-06-18 03:02 . 2010-06-18 03:02 ——– d-sh–w- c:\documents and settings\Justis\IETldCache
2010-06-18 02:32 . 2010-06-18 02:32 ——– d—–w- c:\windows\ie8updates
2010-06-18 02:28 . 2010-06-18 02:31 ——– dc-h–w- c:\windows\ie8
2010-06-18 02:22 . 2010-05-06 10:41 599040 -c—-w- c:\windows\system32\dllcache\msfeeds.dll
2010-06-18 02:22 . 2010-05-06 10:41 55296 -c—-w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-06-18 02:22 . 2010-05-06 10:41 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2010-06-18 02:22 . 2010-05-06 10:41 743424 -c—-w- c:\windows\system32\dllcache\iedvtool.dll
2010-06-18 02:22 . 2010-05-06 10:41 247808 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2010-06-18 02:22 . 2010-05-06 10:41 1985536 -c—-w- c:\windows\system32\dllcache\iertutil.dll
2010-06-18 02:22 . 2010-05-06 10:41 11076096 -c—-w- c:\windows\system32\dllcache\ieframe.dll
2010-06-18 02:19 . 2010-04-16 11:43 41984 -c—-w- c:\windows\system32\dllcache\iecompat.dll
2010-06-07 16:43 . 2010-06-07 16:43 ——– d—–w- c:\program files\iPod
2010-06-07 16:43 . 2010-06-07 16:45 ——– d—–w- c:\program files\iTunes
2010-06-07 16:43 . 2010-06-07 16:45 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-06-07 16:37 . 2010-06-07 16:38 ——– d—–w- c:\program files\QuickTime
2010-06-07 16:32 . 2010-06-07 16:32 ——– d—–w- c:\program files\Bonjour
2010-06-07 16:27 . 2010-06-07 16:27 73000 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.1.1.12\SetupAdmin.exe
2010-06-07 14:44 . 2010-06-07 14:44 40228 —ha-w- c:\windows\system32\mlfcache.dat
2010-06-02 13:06 . 2010-06-02 13:06 29512 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgmfx86.sys
2010-06-02 13:06 . 2010-06-02 13:06 242896 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtdix.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-18 03:08 . 2010-01-12 00:37 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2010-06-07 16:43 . 2010-03-03 03:03 ——– d—–w- c:\program files\Common Files\Apple
2010-06-05 19:08 . 2010-01-19 17:38 ——– d—–w- c:\program files\Microsoft Silverlight
2010-06-02 13:06 . 2010-01-12 00:37 242896 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-06-02 13:06 . 2010-01-12 00:37 29584 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-05-16 16:10 . 2010-01-12 18:10 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-05-06 10:41 . 2004-08-04 05:56 916480 —-a-w- c:\windows\system32\wininet.dll
2010-05-02 05:56 . 2004-08-04 04:17 1850880 —-a-w- c:\windows\system32\win32k.sys
2010-04-29 20:35 . 2010-03-03 03:10 ——– d—–w- c:\documents and settings\Justis\Application Data\Apple Computer
2010-04-29 19:39 . 2010-01-12 18:10 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 19:39 . 2010-01-12 18:10 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-28 03:30 . 2010-03-03 03:03 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2010-04-26 23:29 . 2010-02-05 22:51 ——– d—–w- c:\program files\Lx_cats
2010-04-26 20:23 . 2010-04-26 20:15 ——– d—–w- c:\documents and settings\All Users\Application Data\DivX
2010-04-26 20:23 . 2010-04-26 20:23 57344 —-a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-04-26 20:22 . 2010-04-26 20:22 56766 —-a-w- c:\documents and settings\All Users\Application Data\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-04-26 20:22 . 2010-04-26 20:15 ——– d—–w- c:\program files\DivX
2010-04-26 20:22 . 2010-04-26 20:22 56978 —-a-w- c:\documents and settings\All Users\Application Data\DivX\WebPlayer\Uninstaller.exe
2010-04-26 20:21 . 2010-04-26 20:21 53600 —-a-w- c:\documents and settings\All Users\Application Data\DivX\Update\Uninstaller.exe
2010-04-26 20:21 . 2010-04-26 20:21 57679 —-a-w- c:\documents and settings\All Users\Application Data\DivX\Player\Uninstaller.exe
2010-04-26 20:21 . 2010-04-26 20:21 ——– d—–w- c:\documents and settings\Justis\Application Data\DivX
2010-04-26 20:20 . 2010-04-26 20:20 84040 —-a-w- c:\documents and settings\All Users\Application Data\DivX\TransferWizard\Uninstaller.exe
2010-04-26 20:20 . 2010-04-26 20:20 57054 —-a-w- c:\documents and settings\All Users\Application Data\DivX\DSDesktopComponents\Uninstaller.exe
2010-04-26 20:20 . 2010-04-26 20:20 54166 —-a-w- c:\documents and settings\All Users\Application Data\DivX\DSAVCDecoder\Uninstaller.exe
2010-04-26 20:20 . 2010-04-26 20:20 57532 —-a-w- c:\documents and settings\All Users\Application Data\DivX\DSASPDecoder\Uninstaller.exe
2010-04-26 20:20 . 2010-04-26 20:20 56458 —-a-w- c:\documents and settings\All Users\Application Data\DivX\DivXDecoderShortcut\Uninstaller.exe
2010-04-26 20:20 . 2010-04-26 20:20 54174 —-a-w- c:\documents and settings\All Users\Application Data\DivX\DSAACDecoder\Uninstaller.exe
2010-04-26 20:20 . 2010-04-26 20:20 54153 —-a-w- c:\documents and settings\All Users\Application Data\DivX\DFXPlugin\Uninstaller.exe
2010-04-26 20:20 . 2010-04-26 20:20 54128 —-a-w- c:\documents and settings\All Users\Application Data\DivX\Converter\Uninstaller.exe
2010-04-26 20:20 . 2010-04-26 20:20 54629 —-a-w- c:\documents and settings\All Users\Application Data\DivX\TranscodeEngine\Uninstaller.exe
2010-04-26 20:20 . 2010-04-26 20:20 54101 —-a-w- c:\documents and settings\All Users\Application Data\DivX\MPEG2Plugin\Uninstaller.exe
2010-04-26 20:20 . 2010-04-26 20:20 57409 —-a-w- c:\documents and settings\All Users\Application Data\DivX\ControlPanel\Uninstaller.exe
2010-04-26 20:19 . 2010-04-26 20:19 52963 —-a-w- c:\documents and settings\All Users\Application Data\DivX\MSVC80CRTRedist\Uninstaller.exe
2010-04-26 20:19 . 2010-04-26 20:19 ——– d—–w- c:\program files\Common Files\DivX Shared
2010-04-26 20:19 . 2010-04-26 20:19 54073 —-a-w- c:\documents and settings\All Users\Application Data\DivX\Qt4.5\Uninstaller.exe
2010-04-26 20:19 . 2010-04-26 20:19 56969 —-a-w- c:\documents and settings\All Users\Application Data\DivX\ASPEncoder\Uninstaller.exe
2010-04-26 20:15 . 2010-04-26 20:22 754984 —-a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\Resource.dll
2010-04-26 20:15 . 2010-04-26 20:15 144696 —-a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.exe
2010-04-26 20:15 . 2010-04-26 20:22 1180952 —-a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe
2010-04-20 05:51 . 2004-08-04 05:56 285696 —-a-w- c:\windows\system32\atmfd.dll
2010-04-16 12:33 . 2010-03-03 03:04 41472 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2010-04-16 12:33 . 2010-03-03 03:04 3003680 —-a-w- c:\windows\system32\usbaaplrc.dll
2010-04-08 17:20 . 2010-04-08 17:20 91424 —-a-w- c:\windows\system32\dnssd.dll
2010-04-08 17:20 . 2010-04-08 17:20 107808 —-a-w- c:\windows\system32\dns-sd.exe
2010-03-31 01:58 . 2010-04-26 20:20 44944 ——w- c:\windows\system32\drivers\PxHelp20.sys
2010-03-31 01:58 . 2010-04-26 20:20 9200 ——w- c:\windows\system32\drivers\cdralw2k.sys
2010-03-31 01:58 . 2010-04-26 20:20 9072 ——w- c:\windows\system32\drivers\cdr4_xp.sys
2010-03-31 01:58 . 2010-04-26 20:20 123888 ——w- c:\windows\system32\pxcpyi64.exe
2010-03-31 01:58 . 2010-04-26 20:20 125424 ——w- c:\windows\system32\pxinsi64.exe
2010-03-31 01:58 . 2010-04-26 20:20 133616 ——w- c:\windows\system32\pxafs.dll
2010-03-30 19:30 . 2010-01-11 21:33 46056 —-a-w- c:\documents and settings\Justis\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-04-19 14:25 2117704 —-a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Justis\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-01-12 135664]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-16 1392640]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-06-02 2065248]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-03-31 138008]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-03-31 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-03-31 138008]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"IntelZeroConfig"="c:\program files\Intel\WiFi\bin\ZCfgSvc.exe" [2009-05-21 1372160]
"IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2009-05-21 1202448]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2005-10-07 176128]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-07-20 1228800]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"lxddmon.exe"="c:\program files\Lexmark 2500 Series\lxddmon.exe" [2007-06-12 291760]
"lxddamon"="c:\program files\Lexmark 2500 Series\lxddamon.exe" [2007-04-30 20480]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-04-12 1135912]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2010-1-11 24576]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-03-17 12:06 12464 —-a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\WINDOWS\\system32\\lxddcoms.exe"=
"c:\\Program Files\\Lexmark 2500 Series\\lxddamon.exe"=
"c:\\Program Files\\Lexmark 2500 Series\\App4R.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxddpswx.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxddjswx.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxddtime.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Lexmark 2500 Series\\lxddmon.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [1/11/2010 8:37 PM 216200]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [1/11/2010 8:37 PM 242896]
R2 ASFIPmon;Broadcom ASF IP Monitor;c:\program files\Broadcom\ASFIPMon\AsfIpMon.exe [10/18/2005 6:11 PM 61440]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [3/17/2010 8:04 AM 916760]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [3/17/2010 8:06 AM 308064]
R2 lxdd_device;lxdd_device;c:\windows\system32\lxddcoms.exe -service –> c:\windows\system32\lxddcoms.exe -service [?]
S2 lxddCATSCustConnectService;lxddCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxddserv.exe [2/5/2010 6:49 PM 99248]
.
Contents of the 'Scheduled Tasks' folder
2010-06-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2010-06-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-117609710-1580818891-839522115-1003Core.job
- c:\documents and settings\Justis\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-01-12 00:44]
2010-06-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-117609710-1580818891-839522115-1003UA.job
- c:\documents and settings\Justis\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-01-12 00:44]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Justis\Application Data\Mozilla\Firefox\Profiles\twl1yao6.default\
FF - plugin: c:\documents and settings\Justis\Local Settings\Application Data\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-06-18 12:06
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2010-06-18 12:09:08
ComboFix-quarantined-files.txt 2010-06-18 16:09
Pre-Run: 66,291,449,856 bytes free
Post-Run: 66,304,114,688 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 6D75C411AFC9E8641A25EE83F12B782D