Combo Fix log
Here is the Combo fix log. Everything seems much better. I notice a file association had changed but that's not a big deal. Had some problems with the printer but thay may be something else as well.
ComboFix 09-06-20.04 - Ken 06/21/2009 14:11.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.760.241 [GMT -7:00]
Running from: c:\documents and settings\Ken\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-2487754012-219335672-3048498749-1000
c:\$recycle.bin\S-1-5-21-2487754012-219335672-3048498749-1000\desktop.ini
.
((((((((((((((((((((((((( Files Created from 2009-05-21 to 2009-06-21 )))))))))))))))))))))))))))))))
.
2009-06-19 17:21 . 2009-06-21 16:21 -------- d-----w- C:\Anti-Virus Software
2009-06-19 16:23 . 2009-06-17 18:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-19 16:23 . 2009-06-19 16:23 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-19 16:23 . 2009-06-17 18:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-19 14:56 . 2009-06-19 14:56 390664 ----a-w- c:\documents and settings\Ken\Application Data\Real\RealPlayer\Update\realplayer11gold.exe
2009-06-19 14:39 . 2009-06-19 14:39 -------- d-----w- c:\program files\Trend Micro
2009-06-18 02:10 . 2009-06-18 02:10 -------- d-----w- c:\documents and settings\Ken\Local Settings\Application Data\Symantec
2009-06-18 01:49 . 2009-06-19 17:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-06-18 01:49 . 2009-06-19 17:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2009-06-18 01:46 . 2009-06-18 01:47 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-06-18 01:44 . 2009-06-18 01:51 -------- d-----w- c:\documents and settings\Ken\Application Data\GetRightToGo
2009-06-17 05:19 . 2009-06-17 05:19 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-06-17 05:17 . 2009-06-17 05:17 422 ----a-w- c:\documents and settings\Ken\Application Data\Ahead\socks32.exe
2009-06-17 05:17 . 2009-06-17 05:17 16141 ----a-w- c:\documents and settings\Ken\Application Data\alot\megalon.exe
2009-06-17 05:17 . 2009-06-17 05:17 145131 ----a-w- c:\documents and settings\Ken\Application Data\Aladdin Systems\horsi.exe
2009-06-17 05:17 . 2009-06-17 05:17 13221 ----a-w- c:\documents and settings\Ken\Application Data\AdobeUM\reniga.dll
2009-06-17 05:17 . 2009-06-17 05:17 11232 ----a-w- c:\documents and settings\Ken\Application Data\Adobe\moha.exe
2009-06-17 04:51 . 2009-06-17 04:51 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-06-17 02:42 . 2009-06-17 02:42 -------- d-----w- c:\program files\Free M4a to MP3 Converter
2009-06-16 14:37 . 2009-06-16 14:37 -------- d-sh--w- c:\documents and settings\Ken\PrivacIE
2009-06-11 14:52 . 2009-04-30 21:22 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-06-11 14:52 . 2009-04-30 21:22 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-06-09 23:40 . 2009-06-09 23:40 152576 ----a-w- c:\documents and settings\Ken\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-07 14:24 . 2009-06-07 14:24 -------- d-sh--w- c:\documents and settings\Ken\IETldCache
2009-06-07 06:13 . 2009-06-18 01:47 -------- d-----w- c:\windows\ie8updates
2009-06-07 06:12 . 2009-05-12 05:11 102912 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-06-07 06:09 . 2009-04-29 04:55 78336 -c--a-w- c:\windows\system32\dllcache\ieencode.dll
2009-06-07 06:09 . 2009-04-29 04:55 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-03 06:05 . 2009-06-03 06:05 -------- d-----w- c:\documents and settings\Ken\Application Data\Neuratron
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-21 20:31 . 2007-02-03 05:40 -------- d-----w- c:\program files\Juno
2009-06-21 01:23 . 2007-12-07 18:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-06-19 17:36 . 2007-02-03 05:27 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-06-19 17:25 . 2007-02-03 05:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-18 01:48 . 2007-12-15 22:30 -------- d-----w- c:\documents and settings\Ken\Application Data\alot
2009-06-15 14:11 . 2007-12-07 06:57 -------- d-----w- c:\documents and settings\Ken\Application Data\EndNote
2009-06-15 00:23 . 2007-09-25 01:25 -------- d-----w- c:\documents and settings\Ken\Application Data\Echo AudioFire Console
2009-06-09 23:41 . 2007-02-04 00:46 -------- d-----w- c:\program files\Java
2009-06-04 14:52 . 2008-06-10 03:31 98304 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-06-02 14:50 . 2007-02-05 19:52 41376 ----a-w- c:\documents and settings\Ken\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-02 14:32 . 2007-10-24 05:02 -------- d-----w- c:\documents and settings\Ken\Application Data\Sibelius Software
2009-06-02 14:25 . 2009-06-02 14:25 604 ---ha-w- c:\program files\STLL Notifier
2009-06-02 14:25 . 2007-10-24 05:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Sibelius Software
2009-06-01 04:59 . 2009-03-28 22:39 -------- d-----w- c:\documents and settings\Ken\Application Data\uTorrent
2009-05-24 22:18 . 2009-05-01 04:31 -------- d-----w- c:\program files\XRECODE
2009-05-21 18:33 . 2009-04-22 03:56 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-05-20 17:21 . 2007-02-03 18:10 -------- d-----w- c:\program files\Common Files\Adobe
2009-05-15 05:28 . 2007-04-01 02:52 -------- d--h--w- c:\documents and settings\Ken\Application Data\Move Networks
2009-05-09 01:08 . 2009-05-09 01:08 -------- d-----w- c:\documents and settings\Ken\Application Data\Malwarebytes
2009-05-09 01:08 . 2009-05-09 01:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-08 13:55 . 2007-02-03 03:53 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-07 15:32 . 2004-08-04 12:00 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-06 01:13 . 2009-02-13 00:20 -------- d-----w- c:\documents and settings\Ken\Application Data\Skype
2009-05-06 00:35 . 2009-02-13 00:23 -------- d-----w- c:\documents and settings\Ken\Application Data\skypePM
2009-05-01 21:33 . 2009-01-24 02:10 -------- d-----w- c:\program files\7-Zip
2009-05-01 16:00 . 2009-01-28 15:24 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-05-01 16:00 . 2007-02-03 04:55 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-05-01 16:00 . 2008-07-22 00:31 325896 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-05-01 15:59 . 2009-04-01 02:30 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-04-29 04:56 . 2004-08-04 12:00 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-22 03:55 . 2009-04-22 03:55 152576 ----a-w- c:\documents and settings\Ken\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-04-17 12:26 . 2004-08-04 12:00 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-08-04 12:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2008-11-12 01:01 . 2008-11-12 01:01 122880 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-06-19_14.30.09 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-21 15:17 . 2009-06-21 15:17 16384 c:\windows\Temp\Perflib_Perfdata_6c4.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Ken\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-04 133104]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-27 68856]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-03-28 198160]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-05-01 1947928]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - c:\windows\system32\narrator.exe [2008-04-14 53760]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-01 16:00 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=c:\windows\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=c:\windows\pss\Google Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=c:\windows\pss\HP Image Zone Fast Start.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak software updater.lnk
backup=c:\windows\pss\Kodak software updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ZuneWlanCfgSvc"=3 (0x3)
"ZuneNetworkSvc"=3 (0x3)
"WZCSVC"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"WDBtnMgrSvc.exe"=2 (0x2)
"RioMSC"=2 (0x2)
"LightScribeService"=2 (0x2)
"iPod Service"=3 (0x3)
"Ati HotKey Poller"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Juno\\bin\\juno.exe"=
"c:\\Program Files\\Rio\\Rio Music Manager\\riomm.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Steinberg\\Cubase SX 3\\Cubasesx3.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Macromedia\\Dreamweaver MX\\Dreamweaver.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
"c:\\Program Files\\SpiralFrog\\Spiralfrog.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe"=
"g:\\Sibelius 6\\RegTool.exe"=
"g:\\Sibelius 6\\Sibelius.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [7/21/2008 5:31 PM 325896]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/31/2009 7:30 PM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [3/31/2009 7:30 PM 908568]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [1/28/2009 8:24 AM 298776]
R3 echo1394;AudioFire service;c:\windows\system32\drivers\echo1394.sys [11/21/2008 7:08 PM 68864]
R3 SynasUSB;SynasUSB;c:\windows\system32\drivers\SynasUSB.sys [2/3/2007 8:56 PM 24080]
S3 echo3g;Echo3G Service;c:\windows\system32\drivers\echo3g.sys [4/2/2007 9:56 AM 210048]
S3 EWAVE;EWAVE;c:\windows\system32\drivers\ew.sys [2/10/2007 11:38 AM 1447040]
S3 FILESPY;FILESPY;c:\windows\system32\drivers\FileSpy.sys [2/10/2007 11:38 AM 26992]
S3 GigNIC;NDIS5.1 Miniport Driver for Belkin Gigabit Desktop Card;c:\windows\system32\drivers\GigNIC.sys [2/2/2007 9:03 PM 175104]
S3 GoogleDesktopManager-092308-165331;Google Desktop Manager 5.8.809.23506;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [11/11/2008 6:00 PM 30192]
S3 NSTATION;NSTATION;c:\windows\system32\drivers\NSTATION.sys [2/10/2007 11:38 AM 18944]
S3 rig3avs;rig3avs;c:\windows\system32\drivers\rig3avs.sys [4/18/2008 6:09 PM 25600]
S3 rig3usb;rig3usb;c:\windows\system32\drivers\rig3usb.sys [4/18/2008 6:09 PM 186368]
S3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;c:\windows\system32\DRIVERS\rt2870.sys --> c:\windows\system32\DRIVERS\rt2870.sys [?]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [4/27/2008 5:22 PM 11520]
S4 WDBtnMgrSvc.exe;WD Drive Manager Service;c:\program files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe [1/30/2008 4:52 AM 106496]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
2009-06-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
2009-06-21 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-07-24 07:12]
2009-06-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1935655697-1957994488-725345543-1004.job
- c:\documents and settings\Ken\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-04 18:49]
.
.
------- Supplementary Scan -------
.
mStart Page = hxxp://www.google.com
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
DPF: {5D80A6D1-B500-47DA-82B8-EB9875F85B4D} - hxxp://dl.google.com/dl/desktop/nv/GoogleGadgetPluginIEWin.cab
DPF: {EFD1E13D-1CB3-4545-B754-CA410FE7734F} - hxxp://www.costcophotocenter.com/upload/activex/v3_0_0_2/PhotoCenter_ActiveX_Control.cab?
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-06-21 14:18
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(680)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-06-21 14:23
ComboFix-quarantined-files.txt 2009-06-21 21:23
ComboFix2.txt 2009-06-19 14:35
Pre-Run: 2,328,555,520 bytes free
Post-Run: 2,308,907,008 bytes free
235 --- E O F --- 2009-06-18 17:21