Good evening! I had a great time, and thank you for the well wishes. I unfortunately made the mistake of closing the log text file from ComboFix. Right now, it seems that a decently important registry key that helps run programs has been marked for deletion. I tried opening both Firefox and the ComboFix log, but an error message came up saying the following: "Illegal operation attempted on a registry key that has been marked for deletion." This message came up with both Firefox and the log file, but I was able to open Firefox by right-clicking and running the program as an Administrator. I'll keep trying to open the file, but figured I'd at least post an update. If anything changes, I'll definitely post and let you know.
- Tyler
UPDATE
I restarted the computer to see what good it may or may not do, and it seemed to fix the problem I described above. At least that's the case so far, because Firefox and the log file both opened up without a problem as normal. Here is the log from ComboFix:
ComboFix 12-09-15.02 - Tyler 09/16/2012 20:55:11.1.2 - x86
Microsoft® Windows Vista™ Enterprise 6.0.6002.2.1252.1.1033.18.3059.1936 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Spybot - Search and Destroy *Disabled/Updated* {1EAF1D03-5480-F3B2-EB14-11F0F5EE2699}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\3002.abs
c:\programdata\3002.xml
c:\windows\BackUp
c:\windows\BackUp\Apple Software Update.lnk
c:\windows\BackUp\CompuTraceAgent101286-101544\Absolute_logo_vertical.gif
c:\windows\BackUp\CompuTraceAgent101286-101544\Application Agent Release Notes.TXT
c:\windows\BackUp\CompuTraceAgent101286-101544\CompuTrace.msi
c:\windows\BackUp\CompuTraceAgent101286-101544\ctmweb.exe
c:\windows\BackUp\CompuTraceAgent101286-101544\ctmweb.xsl
c:\windows\BackUp\CompuTraceAgent101286-101544\InstallationGuide.pdf
c:\windows\BackUp\CompuTraceAgent101286-101544\logo_computrace.gif
c:\windows\BackUp\CompuTraceAgent101286-101544\ntagent.exe
c:\windows\BackUp\CompuTraceAgent101286-101544\README.TXT
c:\windows\BackUp\CompuTraceAgent101286-101544\spacer.gif
c:\windows\BackUp\CompuTraceAgent101286-101544\warning.gif
c:\windows\BackUp\Default Programs.lnk
c:\windows\BackUp\desktop.ini
c:\windows\BackUp\Extras and Upgrades\Desktop.ini
c:\windows\BackUp\Extras and Upgrades\Windows Marketplace.lnk
c:\windows\BackUp\Extras and Upgrades\Windows Web.lnk
c:\windows\BackUp\Favorites\desktop.ini
c:\windows\BackUp\Favorites\Links\Customize Links.url
c:\windows\BackUp\Favorites\Links\desktop.ini
c:\windows\BackUp\Favorites\Microsoft Websites\IE Add-on site.url
c:\windows\BackUp\Favorites\Microsoft Websites\IE site on Microsoft.com.url
c:\windows\BackUp\Favorites\Microsoft Websites\Marketplace.url
c:\windows\BackUp\Favorites\Microsoft Websites\Microsoft At Home.url
c:\windows\BackUp\Favorites\Microsoft Websites\Microsoft At Work.url
c:\windows\BackUp\Favorites\Microsoft Websites\Welcome to IE7.url
c:\windows\BackUp\Favorites\MSN Websites\MSN Autos.url
c:\windows\BackUp\Favorites\MSN Websites\MSN Entertainment.url
c:\windows\BackUp\Favorites\MSN Websites\MSN Money.url
c:\windows\BackUp\Favorites\MSN Websites\MSN Sports.url
c:\windows\BackUp\Favorites\MSN Websites\MSN.url
c:\windows\BackUp\Favorites\MSN Websites\MSNBC News.url
c:\windows\BackUp\Favorites\Windows Live\Get Windows Live.url
c:\windows\BackUp\Favorites\Windows Live\Windows Live Gallery.url
c:\windows\BackUp\Favorites\Windows Live\Windows Live Mail.url
c:\windows\BackUp\Favorites\Windows Live\Windows Live Spaces.url
c:\windows\BackUp\hklm-run-20080411.reg
c:\windows\BackUp\hklm-run-20080422.reg
c:\windows\BackUp\Windows Calendar.lnk
c:\windows\BackUp\Windows Contacts.lnk
c:\windows\BackUp\Windows Live.lnk
c:\windows\BackUp\Windows Mail.lnk
.
.
((((((((((((((((((((((((( Files Created from 2012-08-17 to 2012-09-17 )))))))))))))))))))))))))))))))
.
.
2012-09-17 01:02 . 2012-09-17 01:04 ——– d—–w- c:\users\Tyler\AppData\Local\temp
2012-09-12 20:47 . 2012-09-12 20:47 ——– d—–w- c:\program files\ESET
2012-09-07 21:42 . 2012-09-07 21:43 ——– d—–w- c:\programdata\Battle.net
2012-09-06 14:27 . 2012-09-06 14:27 ——– d—–w- c:\users\Tyler\AppData\Roaming\Malwarebytes
2012-09-06 14:27 . 2012-09-06 14:27 ——– d—–w- c:\programdata\Malwarebytes
2012-09-06 14:27 . 2012-09-12 03:43 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2012-09-06 14:27 . 2012-09-07 21:04 22856 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-09-05 23:17 . 2012-09-05 23:17 ——– d—–w- c:\users\Tyler\AppData\Local\adaware
2012-09-05 23:17 . 2012-09-13 12:37 ——– d—–w- c:\programdata\Ad-Aware Browsing Protection
2012-09-05 23:16 . 2012-09-05 23:16 ——– d—–w- c:\users\Tyler\AppData\Local\Downloaded Installations
2012-09-05 22:40 . 2012-09-05 23:01 ——– d—–w- c:\programdata\Spybot - Search & Destroy
2012-09-05 22:40 . 2009-01-25 17:14 15224 —-a-w- c:\windows\system32\sdnclean.exe
2012-09-05 22:40 . 2012-09-05 22:41 ——– d—–w- c:\program files\Spybot - Search & Destroy 2
2012-09-02 02:02 . 2012-09-02 02:02 93672 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-08-28 18:21 . 2012-08-28 18:21 ——– d—–w- c:\programdata\McAfee
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-17 01:03 . 2008-05-07 13:43 17920 —-a-w- c:\windows\system32\rpcnetp.exe
2012-09-17 01:03 . 2008-04-24 17:22 58288 —-a-w- c:\windows\system32\rpcnet.dll
2012-09-02 02:04 . 2011-12-13 21:02 73416 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-02 02:04 . 2011-12-13 21:02 696520 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-09-02 02:02 . 2011-12-13 21:09 821736 —-a-w- c:\windows\system32\npdeployJava1.dll
2012-09-02 02:02 . 2011-12-13 21:09 746984 —-a-w- c:\windows\system32\deployJava1.dll
2012-08-21 09:13 . 2011-12-13 21:18 729752 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2012-08-21 09:13 . 2011-12-13 21:18 54232 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2012-08-21 09:13 . 2011-12-13 21:18 355632 —-a-w- c:\windows\system32\drivers\aswSP.sys
2012-08-21 09:13 . 2011-12-13 21:18 35928 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2012-08-21 09:13 . 2011-12-13 21:18 58680 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys
2012-08-21 09:13 . 2011-12-13 21:18 21256 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-08-21 09:12 . 2011-12-13 21:17 41224 —-a-w- c:\windows\avastSS.scr
2012-08-21 09:12 . 2011-12-13 21:17 227648 —-a-w- c:\windows\system32\aswBoot.exe
2012-07-16 17:53 . 2008-05-07 14:49 58288 ——w- c:\windows\system32\rpcnet.exe
2012-07-16 17:50 . 2008-05-07 13:45 17920 —-a-w- c:\windows\system32\rpcnetp.dll
2012-07-04 14:02 . 2012-08-15 00:50 2047488 —-a-w- c:\windows\system32\win32k.sys
2012-06-29 00:16 . 2012-08-15 00:51 1800704 —-a-w- c:\windows\system32\jscript9.dll
2012-06-29 00:09 . 2012-08-15 00:51 1129472 —-a-w- c:\windows\system32\wininet.dll
2012-06-29 00:08 . 2012-08-15 00:50 1427968 —-a-w- c:\windows\system32\inetcpl.cpl
2012-06-29 00:04 . 2012-08-15 00:51 142848 —-a-w- c:\windows\system32\ieUnatt.exe
2012-06-29 00:00 . 2012-08-15 00:51 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2012-09-11 02:40 . 2012-09-11 02:39 260576 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-08-21 09:12 121528 —-a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Spybot-S&D Cleaning"="c:\program files\Spybot - Search & Destroy 2\SDCleaner.exe" [2012-08-30 3513352]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-10-24 3563520]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-10-02 200704]
"Dell Webcam Central"="c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" [2008-10-17 442536]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-08-21 4282728]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-03-27 421736]
"nwiz"="c:\program files\NVIDIA Corporation\nview\nwiz.exe" [2012-04-27 1634112]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"SDTray"="c:\program files\Spybot - Search & Destroy 2\SDTray.exe" [2012-08-30 3904536]
"Ad-Aware Browsing Protection"="c:\programdata\Ad-Aware Browsing Protection\adawarebp.exe" [2011-10-21 198032]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Clean Access Agent.lnk - c:\program files\Cisco Systems\Clean Access Agent\CCAAgent.exe [2007-6-28 2056266]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rpcnet]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2012-09-17 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2011-12-13 02:04]
.
2012-09-17 c:\windows\Tasks\Check for updates (Spybot - Search & Destroy).job
- c:\program files\Spybot - Search & Destroy 2\SDUpdate.exe [2012-09-05 18:11]
.
2012-09-12 c:\windows\Tasks\Refresh immunization (Spybot - Search & Destroy).job
- c:\program files\Spybot - Search & Destroy 2\SDImmunize.exe [2012-09-05 18:10]
.
2012-09-05 c:\windows\Tasks\Scan the system (Spybot - Search & Destroy).job
- c:\program files\Spybot - Search & Destroy 2\SDScan.exe [2012-09-05 18:11]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.bridgew.edu/
uInternet Settings,ProxyOverride = *.local
Trusted Zone: bridgew.edu
Trusted Zone: microsoft.com\update
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
FF - ProfilePath -
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{687578b9-7132-4a7a-80e4-30ee31099e03} - (no file)
Notify-SDWinLogon - SDWinLogon.dll
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-09-16 21:04
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
———————— Other Running Processes ————————
.
c:\windows\system32\nvvsvc.exe
c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\system32\WLANExt.exe
c:\windows\System32\bcmwltry.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe
c:\program files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\dldtcoms.exe
c:\program files\Intel\WiFi\bin\EvtEng.exe
c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\Common Files\Intel\WirelessCommon\RegSrvc.exe
c:\windows\system32\rpcnet.exe
c:\program files\Spybot - Search & Destroy 2\SDFSSvc.exe
c:\program files\TeamViewer\Version7\TeamViewer_Service.exe
c:\program files\Spybot - Search & Destroy 2\SDUpdSvc.exe
c:\program files\Spybot - Search & Destroy 2\SDWSCSvc.exe
c:\program files\NVIDIA Corporation\Display\nvtray.exe
c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe
c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Completion time: 2012-09-16 21:08:50 - machine was rebooted
ComboFix-quarantined-files.txt 2012-09-17 01:08
.
Pre-Run: 52,245,741,568 bytes free
Post-Run: 51,833,683,968 bytes free
.
- - End Of File - - 3EE97CB87E3C28625B3BFA44EB43B07D