Johnb I am typing this post from the cured computer. Thanks alot. Here are the results...
ComboFix 10-01-11.04 - Rob 01/12/2010 9:36.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.628 [GMT -5:00]
Running from: E:\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\LOG13.tmp
C:\LOG18.tmp
C:\LOG31.tmp
C:\LOG36.tmp
C:\LOG3B.tmp
C:\LOG41.tmp
c:\windows\$NtUninstallKB922582$
c:\windows\$NtUninstallKB922582$\fltlib.dll
c:\windows\$NtUninstallKB922582$\fltmc.exe
c:\windows\$NtUninstallKB922582$\fltmgr.sys
c:\windows\$NtUninstallKB922582$\spuninst\spuninst.exe
c:\windows\$NtUninstallKB922582$\spuninst\spuninst.inf
c:\windows\$NtUninstallKB922582$\spuninst\spuninst.txt
c:\windows\$NtUninstallKB922582$\spuninst\updspapi.dll
c:\windows\system32\bszip.dll
c:\windows\system32\drivers\fad.sys
E:\autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-12-12 to 2010-01-12 )))))))))))))))))))))))))))))))
.
2010-01-12 12:27 . 2010-01-12 12:27 -------- d-----w- c:\program files\Trend Micro
2010-01-12 02:57 . 2010-01-12 02:57 -------- d-----w- c:\documents and settings\Rob\Application Data\Malwarebytes
2010-01-12 02:57 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-12 02:57 . 2010-01-12 02:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-12 02:57 . 2010-01-12 12:23 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-12 02:57 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-12 00:58 . 2010-01-12 00:53 50688 ----a-w- c:\documents and settings\Rob\ATF-Cleaner.exe
2010-01-11 23:32 . 2010-01-12 00:06 -------- d-----w- c:\documents and settings\Rob\Local Settings\Application Data\vlfovr
2010-01-11 13:03 . 2010-01-11 13:03 -------- d-----w- c:\documents and settings\Rob\Application Data\ieSpell
2010-01-11 13:03 . 2010-01-11 13:03 -------- d-----w- c:\program files\ieSpell
2010-01-11 13:02 . 2010-01-11 13:03 2058849 ----a-w- c:\program files\ieSpellSetup251106.exe
2010-01-11 00:54 . 2010-01-12 14:27 -------- d-----w- c:\program files\DivX
2010-01-09 20:39 . 2009-12-16 21:16 3776280 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
2010-01-09 20:39 . 2009-12-16 21:16 4043032 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2010-01-09 20:39 . 2009-12-16 21:16 2033432 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtray.exe
2010-01-09 20:39 . 2009-12-16 21:16 3967256 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2010-01-09 20:39 . 2009-12-16 21:16 2352920 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgresf.dll
2010-01-09 20:39 . 2009-12-16 21:16 916248 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcfgx.dll
2009-12-21 04:19 . 2009-12-21 04:19 -------- d-----w- c:\windows\system32\XPSViewer
2009-12-21 04:19 . 2009-12-21 04:19 -------- d-----w- c:\program files\MSBuild
2009-12-21 04:19 . 2009-12-21 04:19 -------- d-----w- c:\program files\Reference Assemblies
2009-12-21 04:18 . 2008-07-06 12:06 89088 ------w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-12-21 04:18 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-12-21 04:18 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-12-21 04:18 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-12-21 04:18 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\dllcache\xpssvcs.dll
2009-12-21 04:18 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-12-21 04:18 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2009-12-21 04:18 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-12-21 04:18 . 2009-12-21 04:19 -------- d-----w- C:\41ffc265d2fa9979e187
2009-12-20 18:10 . 2009-12-20 18:10 -------- d-----w- c:\documents and settings\Rob\Local Settings\Application Data\realtech_VR
2009-12-20 16:11 . 2009-12-20 16:11 -------- d-----w- c:\documents and settings\All Users\Application Data\realtech VR
2009-12-20 14:52 . 2009-12-20 14:53 23510720 ----a-w- c:\program files\dotnetfx.exe
2009-12-20 14:51 . 2009-12-20 18:11 -------- d-----w- c:\program files\realtech VR
2009-12-20 14:50 . 2009-12-20 14:50 1446797 ----a-w- c:\program files\glview315.exe
2009-12-17 18:19 . 2009-12-17 18:20 1015348 ----a-w- c:\program files\p95v2511.zip
2009-12-17 18:09 . 2009-12-17 18:09 -------- d-----w- c:\documents and settings\Rob\Local Settings\Application Data\Help
2009-12-17 18:07 . 2009-12-17 18:07 61895 ----a-w- c:\program files\super_pi_mod-1.5.zip
2009-12-17 01:53 . 2009-12-17 01:54 1956528 ----a-w- c:\program files\install_flash_player_ax.exe
2009-12-16 21:16 . 2009-12-16 21:29 -------- d-----w- C:\$AVG
2009-12-16 21:16 . 2010-01-12 13:54 -------- d-----w- c:\windows\system32\drivers\Avg
2009-12-16 21:16 . 2009-12-16 21:16 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-12-16 21:16 . 2009-12-16 21:16 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-12-16 21:16 . 2009-12-16 21:16 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-12-16 21:16 . 2009-12-16 21:16 -------- d-----w- c:\program files\AVG
2009-12-16 21:16 . 2009-12-16 21:16 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-07-25 02:24 . 2009-12-07 17:39 -------- d---a-w- c:\program files\Guru3D.com
2010-01-10 00:20 . 2005-08-26 18:11 47824 -c--a-w- c:\documents and settings\Rob\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-07 18:04 . 2006-12-08 20:53 56 -csh--r- c:\windows\system32\7861C787A2.sys
2010-01-07 18:04 . 2006-12-08 20:53 1786 -csha-w- c:\windows\system32\KGyGaAvL.sys
2010-01-05 13:42 . 2009-11-22 14:27 -------- d-----w- c:\documents and settings\Rob\Application Data\vlc
2009-12-19 14:16 . 2007-02-01 04:25 -------- d-----w- c:\documents and settings\Rob\Application Data\AdobeUM
2009-12-17 01:38 . 2009-10-04 01:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2009-12-17 01:34 . 2005-08-09 23:16 -------- d-----w- c:\program files\MUSICMATCH
2009-12-16 05:03 . 2006-03-21 20:47 -------- d-----w- c:\program files\Sierra On-Line
2009-12-09 14:24 . 2009-12-09 14:24 1935266 ----a-w- c:\program files\pod25ins.exe
2009-12-09 13:44 . 2009-12-09 13:44 2079170 ----a-w- c:\program files\win_ver3_full.exe
2009-12-08 00:02 . 2009-12-08 00:02 -------- d-----w- c:\program files\oZone3D
2009-12-08 00:02 . 2009-12-08 00:01 1783527 ----a-w- c:\program files\FurMark_v1.6.0.exe
2009-12-07 17:41 . 2009-12-07 17:41 -------- d-----w- c:\program files\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition
2009-12-07 17:39 . 2009-12-07 17:39 2841613 ----a-w- c:\program files\RivaTuner224c-[Guru3D.com].exe
2009-12-07 17:33 . 2009-12-07 17:31 -------- d-----w- c:\program files\ATITool
2009-12-07 17:31 . 2009-12-07 17:30 1359106 ----a-w- c:\program files\ATITool_0.26.exe
2009-12-05 02:26 . 2009-10-18 00:00 127325 ----a-w- c:\documents and settings\Rob\Application Data\Move Networks\uninstall.exe
2009-12-05 02:26 . 2008-11-01 22:22 -------- d-----w- c:\documents and settings\Rob\Application Data\Move Networks
2009-12-05 02:26 . 2009-08-13 19:21 4187512 ----a-w- c:\documents and settings\Rob\Application Data\Move Networks\plugins\npqmp071505000011.dll
2009-12-05 02:26 . 2009-12-05 02:26 1408800 ----a-w- c:\documents and settings\Rob\Application Data\Move Networks\MoveMediaPlayerWin_071505000011.exe
2009-12-04 23:25 . 2009-12-04 23:25 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation
2009-12-04 23:24 . 2009-12-04 23:24 -------- d-----w- c:\program files\NVIDIA Corporation
2009-12-04 22:24 . 2009-12-04 22:24 92899864 ----a-w- c:\program files\195.62_desktop_winxp_32bit_english_whql.exe
2009-12-03 01:40 . 2009-12-03 01:40 2502808 ----a-w- c:\program files\cpuz_152_setup.exe
2009-12-03 01:39 . 2009-12-03 01:39 460112 ----a-w- c:\program files\GPU-Z.0.3.8.exe
2009-12-02 21:39 . 2009-12-02 21:39 -------- d-----w- c:\program files\Common Files\Canon
2009-11-22 14:26 . 2009-11-22 14:26 -------- d-----w- c:\program files\VideoLAN
2009-11-22 14:24 . 2009-11-22 14:24 18030130 ----a-w- c:\program files\vlc-1.0.3-win32.exe
2009-11-21 08:46 . 2009-11-21 08:46 86016 ----a-w- c:\windows\system32\frapsvid.dll
2009-11-21 02:34 . 2009-12-04 22:26 69632 ----a-w- c:\windows\system32\OpenCL.dll
2009-11-21 02:34 . 2009-12-04 22:26 4038656 ----a-w- c:\windows\system32\nvcuda.dll
2009-11-21 02:34 . 2009-12-04 22:26 2259560 ----a-w- c:\windows\system32\nvcuvid.dll
2009-11-21 02:34 . 2009-12-04 22:26 1989224 ----a-w- c:\windows\system32\nvcuvenc.dll
2009-11-21 02:34 . 2009-12-04 22:26 13602816 ----a-w- c:\windows\system32\nvoglnt.dll
2009-11-21 02:34 . 2009-12-04 22:26 182888 ----a-w- c:\windows\system32\nvcodins.dll
2009-11-21 02:34 . 2009-12-04 22:26 182888 ----a-w- c:\windows\system32\nvcod.dll
2009-11-21 02:34 . 2009-12-04 22:26 11374592 ----a-w- c:\windows\system32\nvcompiler.dll
2009-11-21 02:34 . 2009-12-04 22:26 1056768 ----a-w- c:\windows\system32\nvapi.dll
2009-11-21 02:34 . 2009-12-04 22:26 2293286 ----a-w- c:\windows\system32\nvdata.bin
2009-11-21 02:34 . 2004-08-04 05:56 6282752 ----a-w- c:\windows\system32\nv4_disp.dll
2009-11-21 02:34 . 2004-08-04 03:29 10235968 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2009-11-21 01:32 . 2009-11-21 01:32 278120 ----a-w- c:\windows\system32\nvmccs.dll
2009-11-21 01:32 . 2009-11-21 01:32 154216 ----a-w- c:\windows\system32\nvsvc32.exe
2009-11-21 01:32 . 2009-11-21 01:32 145000 ----a-w- c:\windows\system32\nvcolor.exe
2009-11-21 01:32 . 2009-11-21 01:32 12669544 ----a-w- c:\windows\system32\nvcpl.dll
2009-11-21 01:32 . 2009-11-21 01:32 110184 ----a-w- c:\windows\system32\nvmctray.dll
2009-11-21 01:32 . 2009-11-21 01:32 81920 ----a-w- c:\windows\system32\nvwddi.dll
2009-11-20 15:59 . 2009-11-20 15:59 3004832 ----a-w- c:\program files\BitTorrent-6.3.exe
2009-11-17 08:03 . 2009-09-17 01:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-11-17 08:02 . 2009-09-17 01:42 -------- d-----w- c:\program files\Microsoft Works
2009-10-29 23:26 . 2009-10-29 23:25 4938616 ----a-w- c:\program files\Silverlight.exe
2009-10-29 07:45 . 2004-08-04 10:00 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2004-08-04 10:00 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-04 10:00 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 10:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-18 00:00 . 2009-06-16 06:35 4183416 ----a-w- c:\documents and settings\Rob\Application Data\Move Networks\plugins\npqmp071503000010.dll
2009-10-18 00:00 . 2009-10-18 00:00 1686272 -c--a-w- c:\documents and settings\Rob\Application Data\Move Networks\MoveMediaPlayerWin_071503000010.exe
2009-09-17 20:49 . 2009-09-17 20:49 55792 ----a-w- c:\program files\SetGoogleSearch.exe
2009-09-17 01:22 . 2009-09-17 01:22 366048 ----a-w- c:\program files\X12-30351-DLM.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-01-23 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-01-23 126976]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-11-21 110184]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-11-21 12669544]
c:\documents and settings\Rob\Start Menu\Programs\Startup\
ATITool.lnk - c:\program files\ATITool\ATITool.exe [2006-12-8 3035136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-12-16 21:16 12464 ----a-w- c:\windows\SYSTEM32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^McAfee Security Scan.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan.lnk
backup=c:\windows\pss\McAfee Security Scan.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk.disabled]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk.disabled
backup=c:\windows\pss\QuickBooks Update Agent.lnk.disabledCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Rob^Start Menu^Programs^Startup^V CAST Music Monitor.lnk.disabled]
path=c:\documents and settings\Rob\Start Menu\Programs\Startup\V CAST Music Monitor.lnk.disabled
backup=c:\windows\pss\V CAST Music Monitor.lnk.disabledStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG9_TRAY]
2010-01-09 20:39 2033432 ----a-w- c:\progra~1\AVG\AVG9\avgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 20:07 2260480 --sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2005-04-13 09:48 36975 -c--a-w- c:\program files\Java\jre1.5.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wscsvc"=2 (0x2)
"RDSessMgr"=3 (0x3)
"RasMan"=3 (0x3)
"RasAuto"=3 (0x3)
"iPod Service"=3 (0x3)
"helpsvc"=2 (0x2)
"FastUserSwitchingCompatibility"=3 (0x3)
"Apple Mobile Device"=2 (0x2)
"Spooler"=2 (0x2)
"avg9wd"=2 (0x2)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" /startup
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"AtariBanner"="c:\program files\Infogrames\Atari Anniversary Edition\Volume 2\Banner.exe" /0
"MCAgentExe"=c:\progra~1\mcafee.com\agent\mcagent.exe
"MCUpdateExe"=c:\progra~1\mcafee.com\agent\mcupdate.exe
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"mmtask"=c:\program files\Musicmatch\Musicmatch Jukebox\mmtask.exe
"RealTray"=c:\program files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
"VSOCheckTask"="c:\progra~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
"VirusScan Online"=c:\progra~1\mcafee.com\vso\mcvsshld.exe
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe"
"DMXLauncher"=c:\program files\Dell\Media Experience\DMXLauncher.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\SYSTEM32\DRIVERS\avgldx86.sys [12/16/2009 4:16 PM 333192]
S4 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [12/16/2009 4:16 PM 285392]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride = <local>
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: Lookup on Merriam Webster - file://c:\program files\ieSpell\Merriam Webster.HTM
IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
- - - - ORPHANS REMOVED - - - -
Toolbar-Locked - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-Run-nwiz - nwiz.exe
MSConfigStartUp-iTunesHelper - c:\program files\iTunes\iTunesHelper.exe
AddRemove-WebCyberCoach_wtrb - c:\program files\WebCyberCoach\b_Dell\WCC_Wipe.exe WebCyberCoach ext\wtrb
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-12 09:43
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2010-01-12 09:46:09
ComboFix-quarantined-files.txt 2010-01-12 14:45
Pre-Run: 60,020,576,256 bytes free
Post-Run: 60,004,106,240 bytes free
- - End Of File - - AB03F8FC69C80F07713650453C6165AB
Edit: How do I keep this from hapening again? I run AVG and Spybot. Do I just add malwarebytes and atf cleaner as well as superantispyware or something else?