Here's the log:
ComboFix 09-12-09.04 - HP_Administrator 12/11/2009 6:47.6.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1015.581 [GMT -6:00]
Running from: c:\documents and settings\HP_Administrator.STEPH\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\HP_Administrator.STEPH\Desktop\cfscript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
--------------- FCopy ---------------
c:\windows\$hf_mig$\KB956572\SP3QFE\ntoskrnl.exe --> c:\windows\system32\ntoskrnl.exe
c:\windows\system32\dllcache\ntkrnlpa.exe --> c:\windows\system32\ntkrnlpa.exe
.
((((((((((((((((((((((((( Files Created from 2009-11-11 to 2009-12-11 )))))))))))))))))))))))))))))))
.
2009-12-10 21:27 . 2009-12-10 21:27 -------- d-----w- c:\program files\Java
2009-12-10 21:22 . 2009-12-10 21:27 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-10 11:57 . 2005-06-17 13:33 872064 ----a-w- c:\windows\system32\drivers\iastor.sys
2009-12-10 11:57 . 2005-06-17 13:33 872064 ----a-w- C:\iastor.sys
2009-12-08 22:03 . 2008-04-13 18:40 96512 ----a-w- C:\atapi.sys
2009-12-08 22:03 . 2008-04-13 18:40 96512 ------w- c:\windows\system32\drivers\atapi.sys
2009-12-05 23:56 . 2009-12-05 23:56 -------- d-----w- c:\program files\ERUNT
2009-12-05 16:54 . 2009-12-05 16:54 -------- d-----w- C:\_OTL
2009-12-04 10:40 . 2009-12-04 10:40 -------- d-sh--w- c:\documents and settings\HP_Administrator.STEPH\PrivacIE
2009-12-03 22:28 . 2009-12-03 22:28 -------- d-----w- c:\documents and settings\All Users\Application Data\PopCap Games
2009-12-03 22:08 . 2009-12-03 22:08 -------- d-----w- c:\windows\system32\scripting
2009-12-03 22:08 . 2009-12-03 22:08 -------- d-----w- c:\windows\system32\en
2009-12-03 07:56 . 2008-04-14 00:12 20992 ------w- c:\windows\system32\spupdwxp.exe
2009-12-03 07:55 . 2004-08-04 03:29 1897408 ------w- c:\windows\system32\drivers\nv4_mini.sys
2009-12-03 07:54 . 2008-04-14 00:11 37376 ------w- c:\windows\system32\l2gpstore.dll
2009-12-03 07:53 . 2008-04-14 00:12 20992 ------w- c:\windows\system32\faxpatch.exe
2009-12-03 03:04 . 2009-12-03 03:04 -------- d-----w- c:\documents and settings\HP_Administrator.STEPH\Application Data\MSNInstaller
2009-12-03 03:00 . 2009-12-03 11:16 -------- d-----w- C:\95f68d2ffe30c13af7d76c3b3815
2009-12-03 02:41 . 2009-12-03 02:41 -------- d--h--w- c:\windows\system32\GroupPolicy
2009-12-03 02:30 . 2008-04-15 15:17 295424 ------w- c:\windows\system32\dllcache\termsrv.dll
2009-12-02 21:55 . 2008-06-13 11:05 272128 ------w- c:\windows\system32\drivers\bthport.sys
2009-12-02 21:53 . 2009-03-06 14:22 284160 ------w- c:\windows\system32\dllcache\pdh.dll
2009-12-02 21:53 . 2009-02-09 12:10 401408 ------w- c:\windows\system32\dllcache\rpcss.dll
2009-12-02 21:53 . 2009-02-09 12:10 473600 ------w- c:\windows\system32\dllcache\fastprox.dll
2009-12-02 21:53 . 2009-02-06 11:11 110592 ------w- c:\windows\system32\dllcache\services.exe
2009-12-02 21:53 . 2009-02-06 10:10 227840 ------w- c:\windows\system32\dllcache\wmiprvse.exe
2009-12-02 21:53 . 2009-02-09 12:10 453120 ------w- c:\windows\system32\dllcache\wmiprvsd.dll
2009-12-02 21:53 . 2009-06-25 08:25 730112 ------w- c:\windows\system32\dllcache\lsasrv.dll
2009-12-02 21:53 . 2009-02-09 12:10 617472 ------w- c:\windows\system32\dllcache\advapi32.dll
2009-12-02 21:53 . 2009-02-09 12:10 714752 ------w- c:\windows\system32\dllcache\ntdll.dll
2009-12-02 21:53 . 2009-02-06 11:06 2145280 ------w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-12-02 21:53 . 2009-02-06 10:32 2023936 ------w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-12-02 21:51 . 2008-10-24 11:21 455296 ------w- c:\windows\system32\dllcache\mrxsmb.sys
2009-12-02 21:50 . 2008-12-11 10:57 333952 ------w- c:\windows\system32\dllcache\srv.sys
2009-12-02 21:50 . 2009-07-10 13:27 1315328 ------w- c:\windows\system32\dllcache\msoe.dll
2009-12-02 21:50 . 2008-04-11 19:04 691712 ------w- c:\windows\system32\dllcache\inetcomm.dll
2009-12-02 21:49 . 2008-10-15 16:34 337408 ------w- c:\windows\system32\dllcache\netapi32.dll
2009-12-02 21:43 . 2008-05-03 11:55 2560 ------w- c:\windows\system32\xpsp4res.dll
2009-12-02 21:43 . 2008-04-21 12:08 215552 ------w- c:\windows\system32\dllcache\wordpad.exe
2009-12-01 06:40 . 2009-12-01 06:40 -------- d-----w- c:\documents and settings\HP_Administrator.STEPH\Application Data\Malwarebytes
2009-12-01 06:39 . 2009-12-03 22:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-01 06:39 . 2009-12-01 06:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-01 06:39 . 2009-12-05 23:59 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-01 06:39 . 2009-12-03 22:13 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-01 06:21 . 2009-12-01 06:21 -------- d-----w- c:\documents and settings\HP_Administrator.STEPH\Application Data\HPQ
2009-12-01 05:23 . 2009-12-01 05:23 -------- d-----w- c:\documents and settings\All Users\Application Data\SBT
2009-12-01 05:23 . 2009-12-01 05:23 -------- d-----w- c:\program files\Snapshot Viewer
2009-12-01 05:12 . 2009-12-01 05:12 -------- d-----w- c:\documents and settings\HP_Administrator.STEPH\Application Data\Microsoft Web Folders
2009-11-29 17:27 . 2009-12-01 02:49 -------- d-----w- c:\documents and settings\HP_Administrator.STEPH\Application Data\HpUpdate
2009-11-29 17:27 . 2009-11-29 17:27 -------- d-----w- c:\windows\Hewlett-Packard
2009-11-29 15:27 . 2009-11-30 23:54 -------- d-----w- c:\documents and settings\HP_Administrator.STEPH\Local Settings\Application Data\Adobe
2009-11-29 15:19 . 2001-08-18 04:36 5632 ----a-w- c:\windows\system32\ptpusb.dll
2009-11-29 15:19 . 2004-08-04 06:56 159232 ----a-w- c:\windows\system32\ptpusd.dll
2009-11-29 03:08 . 2009-11-29 03:08 -------- d-----w- c:\documents and settings\HP_Administrator.STEPH\Application Data\Yahoo!
2009-11-29 03:08 . 2009-12-03 11:27 -------- d-----w- c:\documents and settings\HP_Administrator.STEPH\Application Data\HPAppData
2009-11-28 16:17 . 2009-11-28 16:17 -------- d-----w- c:\documents and settings\HP_Administrator.STEPH\Application Data\HP
2009-11-28 16:15 . 2009-11-28 16:15 -------- d-----w- c:\documents and settings\HP_Administrator.STEPH\Local Settings\Application Data\HP
2009-11-28 16:08 . 2007-01-17 16:37 16496 ----a-r- c:\windows\system32\drivers\HPZipr12.sys
2009-11-28 16:08 . 2007-01-17 16:37 49920 ----a-r- c:\windows\system32\drivers\HPZid412.sys
2009-11-28 16:07 . 2007-11-06 01:06 278016 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\hpzpp5mu.dll
2009-11-28 16:07 . 2007-11-06 01:07 118272 ----a-w- c:\windows\system32\hpz3l5mu.dll
2009-11-28 16:07 . 2007-11-07 02:10 271704 ----a-r- c:\windows\system32\hpzids01.dll
2009-11-28 16:07 . 2007-01-17 16:37 21568 ----a-r- c:\windows\system32\drivers\HPZius12.sys
2009-11-28 16:06 . 2007-10-31 10:35 729088 ----a-r- c:\windows\system32\hpwwiax4.dll
2009-11-28 16:06 . 2007-10-31 10:35 593920 ----a-r- c:\windows\system32\hpwtscl3.dll
2009-11-28 16:06 . 2007-01-17 16:37 364544 ----a-r- c:\windows\system32\hppldcoi.dll
2009-11-28 16:06 . 2007-01-17 16:37 309760 ----a-r- c:\windows\system32\difxapi.dll
2009-11-28 16:06 . 2007-01-17 16:31 294912 ----a-r- c:\windows\system32\hpovst11.dll
2009-11-28 15:52 . 2009-11-28 15:52 -------- dc----w- c:\windows\system32\DRVSTORE
2009-11-28 08:01 . 2009-11-28 08:01 -------- d-sh--w- c:\documents and settings\HP_Administrator.STEPH\UserData
2009-11-28 05:13 . 2001-08-17 21:48 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2009-11-28 05:12 . 2008-04-13 18:47 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2009-11-28 05:12 . 2008-04-13 18:45 10368 ----a-w- c:\windows\system32\drivers\hidusb.sys
2009-11-28 05:12 . 2008-04-13 18:45 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2009-11-28 04:13 . 2009-11-28 04:13 -------- d-----w- c:\documents and settings\HP_Administrator.STEPH\Local Settings\Application Data\Apple
2009-11-28 04:12 . 2009-11-28 04:12 -------- d-----w- c:\documents and settings\HP_Administrator.STEPH\Local Settings\Application Data\Apple Computer
2009-11-28 04:01 . 2009-11-28 04:01 -------- d-----w- C:\$AVG
2009-11-28 04:00 . 2009-11-28 04:00 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-11-28 04:00 . 2009-11-28 04:00 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2009-11-28 04:00 . 2009-11-28 04:00 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-11-28 04:00 . 2009-11-28 04:00 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-11-28 04:00 . 2009-12-10 21:51 -------- d-----w- c:\windows\system32\drivers\Avg
2009-11-28 04:00 . 2009-12-04 10:39 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-11-28 04:00 . 2009-11-28 16:13 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2009-11-28 03:52 . 2009-11-28 03:52 -------- d-----w- c:\documents and settings\HP_Administrator.STEPH\Local Settings\Application Data\Mozilla
2009-11-28 03:43 . 2009-12-11 12:47 -------- d-sh--r- c:\windows\system32\dllcache
2009-11-28 03:30 . 2009-11-28 03:30 -------- d-----w- c:\documents and settings\HP_Administrator.STEPH\Application Data\PhraseExpress
2009-11-28 03:29 . 2008-04-13 18:45 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2009-11-28 03:19 . 2006-03-07 09:44 51976 ----a-w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-28 03:19 . 2006-03-07 09:42 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Intuit
2009-11-28 03:19 . 2006-03-07 08:46 136 ----a-w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\fusioncache.dat
2009-11-28 03:18 . 2006-03-07 10:06 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Symantec
2009-11-28 03:18 . 2006-03-07 10:06 -------- d-----w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\ApplicationHistory
2009-11-28 03:18 . 2006-03-07 09:55 -------- d-----w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\Google
2009-11-28 03:18 . 2006-03-07 09:40 -------- d-----w- c:\windows\system32\config\systemprofile\WINDOWS
2009-11-28 03:18 . 2006-03-07 09:31 -------- d-----w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\Wildtangent
2009-11-28 03:18 . 2006-03-07 08:51 -------- d-----w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150050}
2009-11-24 02:07 . 2009-11-24 02:07 -------- d-sh--w- c:\documents and settings\HP_Administrator\IECompatCache
2009-11-17 23:53 . 2009-11-17 23:53 -------- d-----w- c:\program files\Common Files\Sony Shared
2009-11-17 00:47 . 2009-11-17 00:47 -------- d-----w- c:\program files\Conduit
2009-11-17 00:47 . 2009-11-17 00:47 -------- d-----w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\Conduit
2009-11-17 00:47 . 2009-11-17 14:12 -------- d-----w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\XfireXO
2009-11-17 00:47 . 2009-11-17 00:47 -------- d-----w- c:\program files\XfireXO
2009-11-12 00:39 . 2009-11-12 00:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Hewlett-Packard
2009-11-12 00:14 . 2007-11-07 02:04 1373528 ----a-r- c:\windows\hpzshl01.exe
2009-11-12 00:14 . 2008-01-07 14:10 10563 ----a-r- c:\windows\hpwscr19.dat
2009-11-12 00:14 . 2007-11-07 02:15 1140056 ----a-r- c:\windows\hpzmsi01.exe
2009-11-12 00:13 . 2009-11-12 00:14 -------- d-----w- c:\windows\yellowtail
2009-11-12 00:10 . 2009-11-28 16:15 176731 ----a-w- c:\windows\hpwins19.dat
2009-11-12 00:10 . 2008-01-07 14:08 997 ----a-r- c:\windows\hpwmdl19.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-11 02:54 . 2007-12-15 19:02 58 ---h--w- c:\windows\popcreg.dat
2009-12-11 02:54 . 2007-12-15 19:02 20 ----a-w- c:\windows\popcinfot.dat
2009-12-10 21:26 . 2009-11-28 16:19 152576 ----a-w- c:\documents and settings\HP_Administrator.STEPH\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-12-10 21:26 . 2009-11-28 16:18 79488 ----a-w- c:\documents and settings\HP_Administrator.STEPH\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-12-09 17:34 . 2006-03-07 09:42 -------- d-----w- c:\program files\Quicken
2009-12-05 23:59 . 2009-12-05 23:59 4844296 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-12-05 23:54 . 2006-03-07 09:26 83312 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-03 22:28 . 2007-12-15 19:02 -------- d-----w- c:\program files\PopCap Games
2009-12-03 22:12 . 2005-08-31 04:01 92947 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-12-03 22:12 . 2009-12-03 22:12 45056 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\uninstallUI\eHelpSetup.exe
2009-12-03 22:12 . 2009-12-03 22:12 61440 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\modemutil.dll
2009-12-03 22:12 . 2009-12-03 22:12 44032 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\Scripts\devcon.exe
2009-12-03 22:12 . 2009-12-03 22:12 40960 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\ScDmi.dll
2009-12-03 22:12 . 2009-12-03 22:12 341048 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\HPBasicDetection3.dll
2009-12-03 22:12 . 2009-12-03 22:12 32768 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\uploadHSC.dll
2009-12-03 22:12 . 2009-12-03 22:12 32768 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\Scom.dll
2009-12-03 22:12 . 2009-12-03 22:12 217088 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
2009-12-03 22:12 . 2009-12-03 22:12 163840 ----a-w- c:\windows\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\modemcheck.dll
2009-12-01 05:22 . 2005-11-15 01:06 -------- d-----w- c:\program files\microsoft frontpage
2009-12-01 02:48 . 2005-01-25 01:30 139264 ----a-w- c:\windows\system32\hpzjrd01.dll
2009-12-01 02:45 . 2006-03-07 09:15 -------- d-----w- c:\documents and settings\All Users\Application Data\HP
2009-11-29 14:24 . 2009-11-28 03:20 145 ----a-w- c:\documents and settings\HP_Administrator.STEPH\Local Settings\Application Data\fusioncache.dat
2009-11-29 03:08 . 2006-08-10 21:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-11-28 16:55 . 2008-12-10 01:10 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-11-28 16:24 . 2008-12-10 01:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-11-28 16:15 . 2006-03-07 09:50 -------- d-----w- c:\program files\PC-Doctor 5 for Windows
2009-11-28 16:02 . 2006-03-07 09:34 -------- d-----w- c:\program files\Hewlett-Packard
2009-11-28 15:59 . 2008-11-27 05:33 -------- d-----w- c:\documents and settings\All Users\Application Data\HP Product Assistant
2009-11-28 04:15 . 2008-01-16 02:56 -------- d-----w- c:\program files\QuickTime
2009-11-28 04:14 . 2007-08-16 02:10 -------- d-----w- c:\program files\Common Files\Apple
2009-11-28 04:13 . 2007-04-08 20:52 -------- d-----w- c:\program files\Apple Software Update
2009-11-28 04:01 . 2008-05-13 04:16 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-11-28 04:00 . 2009-12-01 04:34 497944 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgchjwx.dll
2009-11-28 04:00 . 2009-12-01 04:34 3963648 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2009-11-28 04:00 . 2009-12-01 04:33 877848 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.exe
2009-11-28 04:00 . 2009-12-01 04:33 1657112 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgupd.dll
2009-11-28 04:00 . 2008-05-13 04:16 -------- d-----w- c:\program files\AVG
2009-11-28 03:49 . 2006-03-07 09:59 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-11-28 03:49 . 2006-03-07 09:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-11-28 03:39 . 2006-03-07 09:29 -------- d-----w- c:\program files\WildTangent
2009-11-28 03:39 . 2006-03-07 08:46 -------- d-----w- c:\program files\GemMaster
2009-11-28 03:29 . 2009-11-28 03:28 1835 --sha-r- c:\windows\system32\drivers\103C_HP_CPC_ER190AA-ABA s7420n_YC_0Pavi_QCNH613_E62NAemMPA1_48_IOnyx2_SASUSTeK Computer INC._V1.xx_B3.06_T051028_WXP2_L409_M1016_J250_7Intel_8Pentium M_91.7_#060810_N80861064_Z11C10620_G80862582.MRK
2009-11-24 01:16 . 2007-01-09 16:50 -------- d-----w- c:\program files\Windows Media Connect 2
2009-11-22 20:51 . 2007-10-07 03:33 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\ZoomBrowser EX
2009-11-22 20:47 . 2007-10-07 03:24 -------- d-----w- c:\documents and settings\All Users\Application Data\ZoomBrowser
2009-11-22 06:25 . 2008-06-11 21:11 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Xfire
2009-11-19 17:48 . 2009-12-01 06:04 872960 ----a-w- c:\documents and settings\HP_Administrator.STEPH\Application Data\Mozilla\Firefox\Profiles\w2qpsr3m.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2009-11-19 17:48 . 2009-12-01 06:04 43008 ----a-w- c:\documents and settings\HP_Administrator.STEPH\Application Data\Mozilla\Firefox\Profiles\w2qpsr3m.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2009-11-19 17:48 . 2009-12-01 06:04 340480 ----a-w- c:\documents and settings\HP_Administrator.STEPH\Application Data\Mozilla\Firefox\Profiles\w2qpsr3m.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2009-11-19 17:48 . 2009-12-01 06:04 346624 ----a-w- c:\documents and settings\HP_Administrator.STEPH\Application Data\Mozilla\Firefox\Profiles\w2qpsr3m.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2009-11-15 23:21 . 2009-01-20 04:42 1 ----a-w- c:\documents and settings\HP_Administrator\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-11-13 08:25 . 2009-11-17 00:47 52224 ------w- c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\lszntw0e.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\components\FFExternalAlert.dll
2009-11-13 08:25 . 2009-11-17 00:47 114688 ------w- c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\lszntw0e.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\components\npmozax.dll
2009-11-11 10:54 . 2007-10-19 02:18 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\GameHouse
2009-11-11 10:54 . 2008-05-13 04:16 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\AVGTOOLBAR
2009-11-09 22:43 . 2009-11-09 22:43 -------- d-----w- c:\program files\Common Files\SupportSoft
2009-11-09 22:43 . 2009-11-09 22:43 -------- d-----w- c:\program files\ComcastUI
2009-11-02 03:27 . 2008-09-20 01:28 -------- d-----w- c:\program files\Windows Live
2009-11-02 03:25 . 2008-08-05 01:56 -------- d-----w- c:\program files\MIcrosoft
2009-10-29 07:45 . 2004-08-10 04:00 916480 ------w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2004-08-10 04:00 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-10 04:00 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-10 04:00 265728 ------w- c:\windows\system32\drivers\http.sys
2009-10-16 18:12 . 2009-11-28 08:01 1119488 ----a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-10-13 10:30 . 2004-08-10 04:00 270336 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2004-08-10 04:00 149504 ----a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2004-08-10 04:00 79872 ----a-w- c:\windows\system32\raschap.dll
2008-12-10 02:21 . 2007-09-16 17:49 14459752 ----a-w- c:\program files\bloodgulch.map
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-10-16 1119488]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-10-16 1119488]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2009-10-16 1119488]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe -atboottime" [X]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-08 61952]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-11-03 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-03 118784]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 77312]
"SoundMan"="SOUNDMAN.EXE" [2005-09-21 86016]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"DMAScheduler"="c:\program files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe" [2005-11-01 90112]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-23 237568]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-11-10 249856]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2004-12-14 663552]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-15 49152]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2009-11-28 2020120]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-10 149280]
c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-9-12 384000]
c:\documents and settings\MCX1\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-3-7 27136]
c:\documents and settings\MCX2\Start Menu\Programs\Startup\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-3-7 27136]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Extender Resource Monitor.lnk - c:\windows\ehome\RMSysTry.exe [2005-10-20 18432]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
PhraseExpress.lnk - c:\program files\PhraseExpress\phraseexpress.exe [2009-3-8 3794256]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-11-28 04:00 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\PhraseExpress\\phraseexpress.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3776:UDP"= 3776:UDP:Media Center Extender Service
"3390:TCP"= 3390:TCP:Remote Media Center Experience
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [11/27/2009 10:00 PM 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [11/27/2009 10:00 PM 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [11/27/2009 10:00 PM 285392]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
getPlusHelper REG_MULTI_SZ getPlusHelper
QWAVE REG_MULTI_SZ QWAVE
.
------- Supplementary Scan -------
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=pavilion&pf=desktop
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
FF - ProfilePath - c:\documents and settings\HP_Administrator.STEPH\Application Data\Mozilla\Firefox\Profiles\w2qpsr3m.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - component: c:\documents and settings\HP_Administrator.STEPH\Application Data\Mozilla\Firefox\Profiles\w2qpsr3m.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-12-11 07:00
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3736)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\arservice.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\ehome\RMSvc.exe
c:\windows\ehome\McrdSvc.exe
c:\windows\ARPWRMSG.EXE
c:\windows\SOUNDMAN.EXE
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\windows\eHome\ehmsas.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
.
**************************************************************************
.
Completion time: 2009-12-11 07:05:35 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-11 13:05
ComboFix2.txt 2009-12-10 15:20
ComboFix3.txt 2009-12-09 18:24
Pre-Run: 154,359,484,416 bytes free
Post-Run: 154,320,252,928 bytes free
- - End Of File - - 152CBDC2E2CCB797821C85C73CBF97B5