seems like I am starting to climb out of things. Somehow managed to run A2antimalware (was extremely slow) and after that some programs started to run.
here is the scans from combofix and hijackthis
Also something disabled the printer (tried to reinstall it, but still no luck) Also usb ports at the back of computer don't seem to be working, (had to move mouse over to the front port)
ComboFix 10-01-25.02 - Julie Hulevich 01/27/2010 9:55.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.1015.494 [GMT -7:00]
Running from: c:\documents and settings\Julie Hulevich\Desktop\ComboFix.exe
AV: a-squared Anti-Malware *On-access scanning enabled* (Updated) {0F8591BB-342B-4493-91C3-4E948ED21255}
AV: AVG Anti-Virus *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\MSN6
c:\documents and settings\All Users\Application Data\MSN6\au.ini
c:\documents and settings\Julie Hulevich\Application Data\MSN6
c:\documents and settings\Julie Hulevich\Application Data\MSN6\au.ini
c:\documents and settings\Julie Hulevich\Application Data\MSN6\msndata001.dat
c:\documents and settings\Julie Hulevich\Application Data\MSN6\msndata002.dat
c:\documents and settings\Julie Hulevich\Application Data\MSN6\msndata003.dat
c:\documents and settings\Julie Hulevich\Application Data\MSN6\msndata004.dat
c:\documents and settings\Julie Hulevich\Application Data\MSN6\msndata005.dat
c:\documents and settings\Julie Hulevich\Application Data\MSN6\UserData\{8AC12CC4-25C7-01C5-0200-00004A571783}\fastsettings.dat
c:\documents and settings\Julie Hulevich\Application Data\MSN6\UserData\{8AC12CC4-25C7-01C5-0200-00004A571783}\favcache.xml
c:\documents and settings\Julie Hulevich\Application Data\MSN6\UserData\{8AC12CC4-25C7-01C5-0200-00004A571783}\favorites.xml
c:\documents and settings\Julie Hulevich\Application Data\MSN6\UserData\{8AC12CC4-25C7-01C5-0200-00004A571783}\localsettings.xml
c:\documents and settings\Julie Hulevich\Application Data\MSN6\UserData\{8AC12CC4-25C7-01C5-0200-00004A571783}\settings.xml
c:\documents and settings\Julie Hulevich\Cookies\MM2048.DAT
c:\program files\INSTALL.LOG
c:\recycler\S-1-5-21-1409082233-1078145449-725345543-1003
c:\recycler\S-1-5-21-3123157274-2644546615-1827650332-1003
C:\s
c:\windows\a3kebook.ini
c:\windows\akebook.ini
c:\windows\ANS2000.INI
c:\windows\Fonts\acrsec.fon
c:\windows\Fonts\acrsecB.fon
c:\windows\Fonts\acrsecI.fon
c:\windows\system32\11478.exe
c:\windows\system32\11942.exe
c:\windows\system32\12382.exe
c:\windows\system32\14604.exe
c:\windows\system32\153.exe
c:\windows\system32\15724.exe
c:\windows\system32\16827.exe
c:\windows\system32\17421.exe
c:\windows\system32\18467.exe
c:\windows\system32\19169.exe
c:\windows\system32\23281.exe
c:\windows\system32\24464.exe
c:\windows\system32\26500.exe
c:\windows\system32\26962.exe
c:\windows\system32\28145.exe
c:\windows\system32\292.exe
c:\windows\system32\29358.exe
c:\windows\system32\2995.exe
c:\windows\system32\32391.exe
c:\windows\system32\3902.exe
c:\windows\system32\41.exe
c:\windows\system32\4827.exe
c:\windows\system32\491.exe
c:\windows\system32\5436.exe
c:\windows\system32\5705.exe
c:\windows\system32\6334.exe
c:\windows\system32\9961.exe
c:\windows\system32\helper32.dll
c:\windows\system32\IS15.exe
c:\windows\unins000.dat
c:\windows\unins000.exe
Infected copy of c:\windows\system32\qmgr.dll was found and disinfected
Restored copy from - c:\windows\$NtUninstallKB842773$\qmgr.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
((((((((((((((((((((((((( Files Created from 2009-12-27 to 2010-01-27 )))))))))))))))))))))))))))))))
.
2010-01-27 04:27 . 2005-06-21 22:43 163840 ----a-w- c:\windows\system32\igfxres.dll
2010-01-27 03:34 . 2002-08-29 12:00 29760 -c--a-w- c:\windows\system32\dllcache\znetm.dll
2010-01-27 03:34 . 2002-08-29 12:00 13894 -c--a-w- c:\windows\system32\dllcache\zonelibm.dll
2010-01-27 03:34 . 2002-08-29 12:00 113222 -c--a-w- c:\windows\system32\dllcache\zoneclim.dll
2010-01-27 03:34 . 2002-08-29 12:00 4677 -c--a-w- c:\windows\system32\dllcache\zeeverm.dll
2010-01-27 03:34 . 2002-08-29 12:00 41029 -c--a-w- c:\windows\system32\dllcache\zcorem.dll
2010-01-27 03:34 . 2002-08-29 12:00 36937 -c--a-w- c:\windows\system32\dllcache\zclientm.exe
2010-01-27 03:34 . 2002-08-29 12:00 119808 -c--a-w- c:\windows\system32\dllcache\winmine.exe
2010-01-27 03:32 . 2002-08-29 12:00 6144 -c--a-w- c:\windows\system32\dllcache\kbdax2.dll
2010-01-27 03:31 . 2002-05-14 19:08 16437 -c--a-w- c:\windows\system32\dllcache\shtml.exe
2010-01-27 03:30 . 2001-08-18 05:36 171008 ----a-w- c:\windows\system32\LXAESUI.DLL
2010-01-27 03:29 . 2010-01-27 03:29 -------- d-----w- c:\documents and settings\Default User\Application Data\DivX
2010-01-27 03:26 . 2002-08-29 08:06 182400 ----a-w- c:\windows\system32\drivers\rdpdr.sys
2010-01-27 02:35 . 2001-08-17 20:59 50048 ----a-w- c:\windows\system32\drivers\DMusic.sys
2010-01-27 02:34 . 2002-08-29 08:32 5888 ----a-w- c:\windows\system32\drivers\splitter.sys
2010-01-27 02:34 . 2002-08-29 08:27 56576 ----a-w- c:\windows\system32\drivers\redbook.sys
2010-01-27 02:32 . 2002-08-29 10:41 49664 ----a-w- c:\windows\system32\vfwwdm32.dll
2010-01-27 02:03 . 2002-08-29 10:46 38024 ----a-w- c:\windows\system32\drivers\termdd.sys
2010-01-27 02:02 . 2002-08-29 12:00 696320 -c--a-w- c:\windows\system32\dllcache\sapi.dll
2010-01-27 02:02 . 2002-08-29 12:00 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
2010-01-27 02:02 . 2002-08-29 12:00 13312 ----a-w- c:\windows\system32\irclass.dll
2010-01-27 02:02 . 2002-08-29 12:00 10496 -c--a-w- c:\windows\system32\dllcache\irenum.sys
2010-01-27 02:02 . 2002-08-29 12:00 10496 ----a-w- c:\windows\system32\drivers\irenum.sys
2010-01-27 02:02 . 2002-08-29 12:00 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
2010-01-27 02:02 . 2002-08-29 12:00 24661 ----a-w- c:\windows\system32\spxcoins.dll
2010-01-27 02:02 . 2002-08-29 12:00 132096 ----a-w- c:\windows\system\WINSPOOL.DRV
2010-01-27 02:02 . 2002-08-29 10:41 71168 ----a-w- c:\windows\system32\storprop.dll
2010-01-26 17:34 . 2010-01-26 17:43 -------- d-----w- C:\$AVG
2010-01-25 07:12 . 2010-01-25 07:12 -------- d-----w- c:\windows\ERUNT
2010-01-25 06:42 . 2010-01-27 16:17 -------- d-----w- c:\program files\a-squared Anti-Malware
2010-01-25 05:45 . 2010-01-26 22:46 -------- d-----w- C:\SDFix
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-27 03:30 . 2010-01-27 03:30 2678 ----a-w- c:\windows\java\Packages\Data\VVJ1VLVL.DAT
2010-01-27 03:30 . 2010-01-27 03:30 2678 ----a-w- c:\windows\java\Packages\Data\VNHJL7F1.DAT
2010-01-27 03:30 . 2010-01-27 03:30 2678 ----a-w- c:\windows\java\Packages\Data\QE5JXZTB.DAT
2010-01-27 03:30 . 2010-01-27 03:30 2678 ----a-w- c:\windows\java\Packages\Data\I3ZTFTJL.DAT
2010-01-27 03:30 . 2010-01-27 03:30 2678 ----a-w- c:\windows\java\Packages\Data\7ZTR757T.DAT
2010-01-27 03:28 . 2003-02-13 21:27 23388 ----a-w- c:\windows\system32\emptyregdb.dat
2010-01-26 01:32 . 2009-02-23 00:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2010-01-21 19:43 . 2009-03-28 15:06 -------- d-----w- c:\program files\Microsoft Silverlight
2010-01-14 18:12 . 2009-10-02 19:48 181120 ------w- c:\windows\system32\MpSigStub.exe
2009-12-31 19:08 . 2008-03-30 21:07 -------- d-----w- c:\documents and settings\Julie Hulevich\Application Data\shrink_pic
2009-12-08 00:39 . 2003-09-30 01:42 -------- d-----w- c:\program files\DivX
2009-12-08 00:32 . 2009-06-06 14:29 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-12-04 16:58 . 2009-06-06 18:56 -------- d-----w- c:\documents and settings\All Users\Application Data\ATI MMC
2009-12-01 23:16 . 2009-03-10 01:17 -------- d-----w- c:\documents and settings\Julie Hulevich\Application Data\Skype
2009-12-01 23:01 . 2009-03-10 01:19 -------- d-----w- c:\documents and settings\Julie Hulevich\Application Data\skypePM
2009-11-19 18:48 . 2009-11-27 22:50 872960 ----a-w- c:\documents and settings\Julie Hulevich\Application Data\Mozilla\Firefox\Profiles\1gnrq81a.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2009-11-19 18:48 . 2009-11-27 22:50 43008 ----a-w- c:\documents and settings\Julie Hulevich\Application Data\Mozilla\Firefox\Profiles\1gnrq81a.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2009-11-19 18:48 . 2009-11-27 22:50 340480 ----a-w- c:\documents and settings\Julie Hulevich\Application Data\Mozilla\Firefox\Profiles\1gnrq81a.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2009-11-19 18:48 . 2009-11-27 22:50 346624 ----a-w- c:\documents and settings\Julie Hulevich\Application Data\Mozilla\Firefox\Profiles\1gnrq81a.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2009-11-14 00:47 . 2009-11-14 00:47 856064 ----a-w- c:\windows\system32\divx_xx0c.dll
2009-11-14 00:47 . 2009-11-14 00:47 856064 ----a-w- c:\windows\system32\divx_xx07.dll
2009-11-14 00:47 . 2009-11-14 00:47 847872 ----a-w- c:\windows\system32\divx_xx0a.dll
2009-11-14 00:47 . 2009-11-14 00:47 843776 ----a-w- c:\windows\system32\divx_xx16.dll
2009-11-14 00:47 . 2009-11-14 00:47 839680 ----a-w- c:\windows\system32\divx_xx11.dll
2009-11-14 00:47 . 2009-11-14 00:47 696320 ----a-w- c:\windows\system32\DivX.dll
2005-01-12 22:08 . 2005-01-12 22:08 56 --sh--r- c:\windows\system32\125F6599E1.sys
2005-07-14 19:31 . 2006-05-24 17:37 27648 --sha-w- c:\windows\system32\AVSredirect.dll
2007-05-15 17:00 . 2007-01-21 06:05 22848032 --sha-w- c:\windows\system32\drivers\fidbox.dat
2007-05-15 17:00 . 2007-01-21 06:05 1503264 --sha-w- c:\windows\system32\drivers\fidbox2.dat
.
------- Sigcheck -------
[-] 2008-04-14 . F92E1076C42FCD6DB3D72D8CFE9816D5 . 13824 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\wscntfy.exe
[-] 2004-08-04 . 49911DD39E023BB6C45E4E436CFBD297 . 13824 . . [5.1.2600.2180] . . c:\windows\system32\wscntfy.exe
[-] 2008-04-14 . 295D21F14C335B53CB8154E5B1F892B9 . 129024 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\xmlprov.dll
[-] 2004-08-04 . EEF46DAB68229A14DA3D8E73C99E2959 . 129536 . . [5.1.2600.2180] . . c:\windows\system32\xmlprov.dll
[-] 2008-04-13 . 3BB22519A194418D5FEC05D800A19AD0 . 36608 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ip6fw.sys
[-] 2004-08-04 . 4448006B6BC60E6C027932CFC38D6855 . 29056 . . [5.1.2600.2180] . . c:\windows\system32\drivers\ip6fw.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1062144]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1062144]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1062144]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATI Launchpad"="c:\program files\ATI Multimedia\main\launchpd.exe" [2005-05-05 102400]
"ATI DeviceDetect"="c:\program files\ATI Multimedia\main\ATIDtct.EXE" [2005-05-05 53248]
"Spyware Doctor"="c:\program files\Spyware Doctor\swdoctor.exe" [2005-04-01 1469680]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-01-28 155648]
"OpwareSE2"="c:\program files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-06-21 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-06-21 126976]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2007-03-28 593920]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-12-15 2043160]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-04-12 185896]
"TELUS_McciTrayApp"="c:\program files\TELUS\TELUS Support Centre\bin\McciTrayApp.exe" [2007-10-08 1462272]
"TelusWCC_McciTrayApp"="c:\program files\TELUS\TELUS Wireless Connection Manager\McciTrayApp.exe" [2006-03-10 543232]
"TEPA.exe"="c:\program files\TELUS\eProtect Advisor\TEPA.exe" [2007-05-14 2061816]
"a-squared"="c:\program files\A-SQUARED ANTI-MALWARE\a2guard.exe" [2010-01-02 3280712]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\System32\CTFMON.EXE" [2002-08-29 13312]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 39264]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2002-08-29 51200]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2002-08-29 40960]
c:\documents and settings\Julie Hulevich\Start Menu\Programs\Startup\
Shrink Pic.lnk - c:\program files\Shrink Pic\shrink_pic.exe [2007-9-18 3032472]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-07-30 15:57 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *\0SsiEfr.e
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-01-12 04:16 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2005-09-26 00:11 94208 ----a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
2006-11-12 10:48 157592 ----a-w- c:\program files\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2007-01-19 18:54 5674352 ----a-w- c:\program files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2005-09-26 00:11 155648 ----a-w- c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2008-01-28 18:43 2097488 --sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyware Doctor]
2005-04-01 22:15 1469680 ----a-w- c:\program files\Spyware Doctor\swdoctor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2005-11-10 19:03 36975 ----a-w- c:\program files\Java\jre1.5.0_06\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2008-04-12 03:07 185896 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2006-11-04 00:20 866584 ----a-w- c:\program files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"kavsvc"=2 (0x2)
"dvpapi"=2 (0x2)
"gusvc"=3 (0x3)
"Autodesk Network Licensing Service"=3 (0x3)
"Autodesk Licensing Service"=3 (0x3)
"Adobe LM Service"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\SmartFTP Client 2.0\\SmartFTP.exe"=
"c:\\Program Files\\WOW\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Flock\\flock\\flock.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"45680:UDP"= 45680:UDP:mutorrent
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [3/26/2008 9:41 PM 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/26/2008 9:41 PM 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/26/2008 9:41 PM 108552]
R2 a2AntiMalware;a-squared Anti-Malware Service;c:\program files\a-squared Anti-Malware\a2service.exe [1/24/2010 11:42 PM 1858144]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [6/16/2009 11:19 AM 908056]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [3/26/2008 9:41 PM 297752]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 5:19 PM 13592]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [5/22/2006 10:58 PM 639224]
S2 gupdate1c9954d1134e28e;Google Update Service (gupdate1c9954d1134e28e);c:\program files\Google\Update\GoogleUpdate.exe [2/22/2009 5:24 PM 133104]
S2 IcRecUsb;IC Recorder Driver;c:\windows\system32\drivers\IcRecUsb.sys [6/7/2007 5:32 PM 17432]
S3 ADPK;TRUST SPYC@M 300S;c:\windows\system32\drivers\SQCaptur.sys [9/14/2003 10:34 AM 30921]
S3 alcan5ln;Alcatel SpeedTouch(tm) USB ADSL RFC1483 Networking Driver (NDIS);c:\windows\system32\drivers\alcan5ln.sys [1/7/2004 6:58 PM 36960]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys --> c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [?]
S3 SynasUSB;SynasUSB;c:\windows\system32\drivers\synasUSB.sys [9/16/2007 6:22 PM 18432]
S3 vaxscsi;vaxscsi;c:\windows\system32\drivers\vaxscsi.sys [5/22/2006 11:03 PM 223128]
--- Other Services/Drivers In Memory ---
*Deregistered* - mchInjDrv
.
Contents of the 'Scheduled Tasks' folder
2010-01-27 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-03-28 23:50]
2010-01-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-23 00:24]
2010-01-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-23 00:24]
2010-01-27 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]
.
.
------- Supplementary Scan -------
.
uStart Page =
https://login.yahoo.com/config/login_verify2?.intl=ca&.src=ym&rl=1
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE: &Google Search
IE: Backward Links
IE: Cached Snapshot of Page
IE: Do&wnload by ReGet Deluxe - c:\program files\Common Files\ReGet Shared\CC_Link.htm
IE: Download A&ll by ReGet Deluxe - c:\program files\Common Files\ReGet Shared\CC_All.htm
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
IE: Similar Pages
IE: Translate into English
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm
Handler: intu-qt2007 - {026BF40D-BA05-467b-9F1F-AD0D7A3F5F11} - c:\program files\QuickTax 2007\ic2007pp.dll
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: TruePass EPF 7,0,100,717 - hxxps://blrscr3.egs-seg.gc.ca/applets/entrusttruepassapplet-epf.cab
DPF: TruePass EPF 7,0,100,730 - hxxps://blrscr3.egs-seg.gc.ca/applets/entrusttruepassapplet-epf.cab
DPF: TruePass EPF 7,0,100,739 - hxxps://blrscr3.egs-seg.gc.ca/applets/entrusttruepassapplet-epf.cab
FF - ProfilePath - c:\documents and settings\Julie Hulevich\Application Data\Mozilla\Firefox\Profiles\1gnrq81a.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/firefox?client=firefox-a&rlz=1R0GGGL_en
FF - prefs.js: keyword.URL - hxxp://ca.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_ca&p=
FF - component: c:\documents and settings\Julie Hulevich\Application Data\Mozilla\Firefox\Profiles\1gnrq81a.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: network.proxy.type - 0
FF - user.js: network.proxy.http -
user_pref(network.proxy.http_port,);
FF - user.js: network.proxy.no_proxies_on -
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHANS REMOVED - - - -
Notify-yayywtr - yayywtr.dll
MSConfigStartUp-igndlm - (no file)
AddRemove-CCleaner - c:\program files\CCleaner\uninst.exe
AddRemove-RealJukebox 1.0 - c:\program files\Common Files\Real\Update_OB\r1puninst.exe
AddRemove-RealPlayer 6.0 - c:\program files\Common Files\Real\Update_OB\r1puninst.exe
AddRemove-Spybot - Search & Destroy_is1 - c:\windows\unins000.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-27 10:12
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\c:\docume~1\JULIEH~1\LOCALS~1\Temp\mc2A.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-3194624122-2740737171-2644822240-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(772)
c:\windows\System32\ODBC32.dll
c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
c:\windows\System32\msctfime.ime
- - - - - - - > 'lsass.exe'(828)
c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
c:\windows\System32\dssenh.dll
- - - - - - - > 'explorer.exe'(908)
c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll
c:\program files\Shrink Pic\shrinkpici.dll
c:\program files\ScanSoft\OmniPageSE2.0\ophookSE2.dll
c:\windows\System32\msctfime.ime
c:\windows\IME\SPGRMR.DLL
c:\windows\System32\msi.dll
c:\program files\Microsoft Office\Office10\msohev.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\SmartFTP Client 2.0\smarthook.dll
c:\windows\system32\PortableDeviceTypes.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Motive\McciCMService.exe
c:\progra~1\AVG\AVG8\avgam.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\program files\Raxco\PerfectDisk\PDAgent.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\program files\Microsoft Office\Office10\WINWORD.EXE
c:\program files\Microsoft Works\MSWorks.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
.
**************************************************************************
.
Completion time: 2010-01-27 10:23:54 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-27 17:23
Pre-Run: 116,040,921,088 bytes free
Post-Run: 118,135,738,368 bytes free
winxpsp1_en_hom_bf.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /noexecute=optin
- - End Of File - - 621354243DA528FADC6D732C2D6FE33B