here is a copy of the log, no idea where its been saved to as it didnt give me an option or any prompts. i must point out though that half way thru the PEV.exe stopped working.
ComboFix 13-05-01.03 - Lisa 03/05/2013 12:12:57.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.2939.1828 [GMT 1:00]
Running from: c:\users\[removed]\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R25G1BRV\ComboFix.exe
AV: AVG AntiVirus Free Edition 2013 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
AV: Microsoft Security Essentials *Disabled/Updated* {3F839487-C7A2-C958-E30C-E2825BA31FB5}
SP: AVG AntiVirus Free Edition 2013 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
SP: Microsoft Security Essentials *Disabled/Updated* {84E27563-E198-C6D6-D9BC-D9F020245508}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Lisa\AppData\Local\temp\ppcrlui_4632_2
c:\windows\system32\pt
c:\windows\system32\pt\smartfacevcp.dll.mui
c:\windows\system32\pt\toscdspd.cpl.mui
.
.
((((((((((((((((((((((((( Files Created from 2013-04-03 to 2013-05-03 )))))))))))))))))))))))))))))))
.
.
2013-05-03 11:25 . 2013-05-03 11:35 ——– d—–w- c:\users\Lisa\AppData\Local\temp
2013-05-03 11:25 . 2013-05-03 11:25 ——– d—–w- c:\users\Public\AppData\Local\temp
2013-05-03 11:25 . 2013-05-03 11:25 ——– d—–w- c:\users\Default\AppData\Local\temp
2013-05-03 11:09 . 2013-05-03 11:09 29904 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{EB27CD8F-819C-40F9-ABC4-28D83ABE0251}\MpKslb2579036.sys
2013-05-02 20:30 . 2013-04-17 05:31 6906960 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{EB27CD8F-819C-40F9-ABC4-28D83ABE0251}\mpengine.dll
2013-05-01 20:40 . 2013-04-17 05:31 6906960 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-04-30 12:26 . 2013-04-30 12:26 ——– d—–w- c:\users\Lisa\AppData\Local\ElevatedDiagnostics
2013-04-29 07:54 . 2013-04-29 07:54 ——– d—–w- c:\programdata\WindowsSearch
2013-04-29 07:49 . 2013-04-29 07:49 ——– d—–w- c:\users\Lisa\AppData\Roaming\AVG
2013-04-29 07:46 . 2013-04-29 07:51 ——– d—–w- c:\programdata\AVG
2013-04-29 07:46 . 2013-04-29 07:46 ——– d-sh–w- c:\programdata\{D1D4879F-2279-49C9-AEBF-3B95C84EAA8F}
2013-04-29 07:44 . 2013-04-12 14:49 706640 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A48308B0-33C9-409B-8FB0-189FF59E395F}\gapaengine.dll
2013-04-29 07:40 . 2013-04-29 22:10 ——– d—–w- c:\program files\Microsoft Security Client
2013-04-28 21:48 . 2013-04-10 03:08 6906960 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FC7DF4D1-C904-491A-91B4-BFC26F82D36D}\mpengine.dll
2013-04-28 21:34 . 2013-04-28 21:34 ——– d—–w- c:\programdata\Kaspersky Lab
2013-04-28 21:10 . 2013-04-28 21:10 ——– d—–w- c:\programdata\AVG SafeGuard toolbar
2013-04-28 21:09 . 2013-04-28 21:09 ——– d—–w- c:\users\Lisa\AppData\Local\AVG SafeGuard toolbar
2013-04-28 21:09 . 2013-04-28 21:09 34592 —-a-w- c:\windows\system32\drivers\avgtpx86.sys
2013-04-28 21:09 . 2013-04-28 21:09 ——– d—–w- c:\program files\Common Files\AVG Secure Search
2013-04-28 21:09 . 2013-04-28 21:09 ——– d—–w- c:\program files\AVG SafeGuard toolbar
2013-04-28 21:06 . 2013-04-28 21:06 ——– d—–w- C:\$AVG
2013-04-28 20:58 . 2013-04-28 21:15 ——– d—–w- c:\users\Lisa\AppData\Local\Avg2013
2013-04-28 20:58 . 2013-04-28 20:58 ——– d—–w- c:\users\Lisa\AppData\Local\MFAData
2013-04-28 20:36 . 2013-04-28 20:36 ——– d—–w- c:\programdata\rwcrf
2013-04-21 14:13 . 2013-04-21 14:13 ——– d—–w- C:\found.000
2013-04-10 09:57 . 2013-03-03 19:07 1082232 —-a-w- c:\windows\system32\drivers\ntfs.sys
2013-04-10 09:55 . 2013-03-11 13:25 3603816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2013-04-10 09:55 . 2013-03-11 13:25 3551080 —-a-w- c:\windows\system32\ntoskrnl.exe
2013-04-10 09:55 . 2013-03-09 03:45 49152 —-a-w- c:\windows\system32\csrsrv.dll
2013-04-10 09:55 . 2013-03-09 01:28 64000 —-a-w- c:\windows\system32\smss.exe
2013-04-10 09:52 . 2013-03-08 03:52 2067968 —-a-w- c:\windows\system32\mstscax.dll
2013-04-10 09:51 . 2013-03-08 03:53 376320 —-a-w- c:\windows\system32\winsrv.dll
2013-04-10 09:49 . 2013-03-05 01:40 2049024 —-a-w- c:\windows\system32\win32k.sys
2013-04-09 22:09 . 2013-04-09 22:09 ——– d—–w- c:\program files\Common Files\Skype
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-03-13 10:54 . 2012-08-13 15:33 693976 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2013-03-13 10:54 . 2011-06-04 07:44 73432 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-03-12 00:10 . 2009-10-03 09:47 237088 ——w- c:\windows\system32\MpSigStub.exe
2013-03-06 23:32 . 2013-03-27 14:46 228600 —-a-w- c:\windows\system32\aswBoot.exe
2013-03-01 09:32 . 2013-03-01 09:32 22328 —-a-w- c:\windows\system32\drivers\avgidsshimx.sys
2013-02-26 22:40 . 2013-02-26 22:40 208184 —-a-w- c:\windows\system32\drivers\avgidsdriverx.sys
2013-02-14 02:52 . 2013-02-14 02:52 182072 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2013-02-12 01:57 . 2013-03-21 18:53 15872 —-a-w- c:\windows\system32\drivers\usb8023.sys
2013-02-08 03:37 . 2013-02-08 03:37 96568 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2013-02-08 03:37 . 2013-02-08 03:37 245048 —-a-w- c:\windows\system32\drivers\avglogx.sys
2013-02-08 03:37 . 2013-02-08 03:37 60216 —-a-w- c:\windows\system32\drivers\avgidshx.sys
2013-02-08 03:37 . 2013-02-08 03:37 170808 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2013-02-08 03:37 . 2013-02-08 03:37 39224 —-a-w- c:\windows\system32\drivers\avgrkx86.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2013-04-28 21:09 1966768 —-a-w- c:\program files\AVG SafeGuard toolbar\15.1.0.2\AVG SafeGuard toolbar_toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG SafeGuard toolbar\15.1.0.2\AVG SafeGuard toolbar_toolbar.dll" [2013-04-28 1966768]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG SafeGuard toolbar.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG SafeGuard toolbar.PugiObj]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AutoStartNPSAgent"="c:\program files\Samsung\Samsung New PC Studio\NPSAgent.exe" [2010-07-04 95576]
"Facebook Update"="c:\users\Lisa\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-07-19 138096]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2013-03-01 18643560]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-07-20 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-06 1029416]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"AVG_UI"="c:\program files\AVG\AVG2013\avgui.exe" [2013-03-13 4394032]
"vProt"="c:\program files\AVG SafeGuard toolbar\vprot.exe" [2013-04-28 1223344]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 947152]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
TRDCReminder.lnk - c:\program files\TOSHIBA\TRDCReminder\TRDCReminder.exe [2008-3-5 393216]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 14:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2007-12-06 16:12 1029416 —-a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - FSUSBEXDISK
*NewlyCreated* - MPKSLB2579036
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-04-09 20:28 1642448 —-a-w- c:\program files\Google\Chrome\Application\26.0.1410.64\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-05-03 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-13 10:54]
.
2013-05-03 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3225807831-2202106886-1861927024-1000Core.job
- c:\users\Lisa\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-10-06 11:00]
.
2013-05-03 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3225807831-2202106886-1861927024-1000UA.job
- c:\users\Lisa\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-10-06 11:00]
.
2013-05-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-03 23:06]
.
2013-05-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-03 23:06]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://uk.msn.com
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 192.168.1.1 0.0.0.0
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\15.1.0\ViProtocol.dll
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)
Toolbar-Locked - (no file)
Toolbar-10 - (no file)
WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file)
SafeBoot-WudfPf
SafeBoot-WudfRd
MSConfigStartUp-Adobe ARM - c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
AddRemove-01_Simmental - c:\program files\Samsung\USB Drivers\01_Simmental\Uninstall.exe
AddRemove-02_Siberian - c:\program files\Samsung\USB Drivers\02_Siberian\Uninstall.exe
AddRemove-03_Swallowtail - c:\program files\Samsung\USB Drivers\03_Swallowtail\Uninstall.exe
AddRemove-04_semseyite - c:\program files\Samsung\USB Drivers\04_semseyite\Uninstall.exe
AddRemove-05_Sloan - c:\program files\Samsung\USB Drivers\05_Sloan\Uninstall.exe
AddRemove-06_Spencer - c:\program files\Samsung\USB Drivers\06_Spencer\Uninstall.exe
AddRemove-07_Schorl - c:\program files\Samsung\USB Drivers\07_Schorl\Uninstall.exe
AddRemove-08_EMPChipset - c:\program files\Samsung\USB Drivers\08_EMPChipset\Uninstall.exe
AddRemove-09_Hsp - c:\program files\Samsung\USB Drivers\09_Hsp\Uninstall.exe
AddRemove-11_HSP_Plus_Default - c:\program files\Samsung\USB Drivers\11_HSP_Plus_Default\Uninstall.exe
AddRemove-16_Shrewsbury - c:\program files\Samsung\USB Drivers\16_Shrewsbury\Uninstall.exe
AddRemove-17_EMP_Chipset2 - c:\program files\Samsung\USB Drivers\17_EMP_Chipset2\Uninstall.exe
AddRemove-18_Zinia_Serial_Driver - c:\program files\Samsung\USB Drivers\18_Zinia_Serial_Driver\Uninstall.exe
AddRemove-19_VIA_driver - c:\program files\Samsung\USB Drivers\19_VIA_driver\Uninstall.exe
AddRemove-20_NXP_Driver - c:\program files\Samsung\USB Drivers\20_NXP_Driver\Uninstall.exe
AddRemove-21_Searsburg - c:\program files\Samsung\USB Drivers\21_Searsburg\Uninstall.exe
AddRemove-22_WiBro_WiMAX - c:\program files\Samsung\USB Drivers\22_WiBro_WiMAX\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2013-05-03 12:35
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2013-05-03 12:38:03
ComboFix-quarantined-files.txt 2013-05-03 11:38
.
Pre-Run: 94,218,997,760 bytes free
Post-Run: 94,481,317,888 bytes free
.
- - End Of File - - 0F05BADD8DF302FD847247C8AB2660CD