Removed AVG
Updated Adobe
Updated Java (I had the latest version)
deleted combofix and re-downloaded it.
latest combofix log file below....
ComboFix 10-01-19.03 - Owner 01/19/2010 18:57:53.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2039.1596 [GMT -5:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\18467.exe
c:\windows\system32\26500.exe
c:\windows\system32\6334.exe
c:\windows\system32\Thumbs.db
.
((((((((((((((((((((((((( Files Created from 2009-12-20 to 2010-01-20 )))))))))))))))))))))))))))))))
.
2010-01-19 23:51 . 2010-01-19 23:51 -------- d-----w- c:\documents and settings\Default User\Local Settings\Application Data\Adobe
2010-01-19 23:49 . 2009-11-20 11:08 38784 ----a-w- c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-01-19 23:48 . 2010-01-19 23:48 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2010-01-19 23:48 . 2010-01-19 23:56 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-01-19 00:18 . 2010-01-19 00:18 -------- d-----w- c:\documents and settings\Owner\log
2010-01-19 00:18 . 2010-01-19 00:18 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\Mozilla
2010-01-18 22:13 . 2010-01-18 22:13 161296 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2010-01-18 19:08 . 2010-01-18 22:33 -------- d-----w- C:\$AVG
2010-01-18 19:07 . 2010-01-18 19:07 -------- d-----w- c:\program files\AVG
2010-01-18 17:23 . 2010-01-18 17:23 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-01-18 17:22 . 2010-01-18 17:22 152576 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-01-18 17:22 . 2010-01-18 17:22 79488 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-01-18 05:03 . 2010-01-18 17:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-01-18 03:51 . 2010-01-19 00:17 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-18 03:28 . 2010-01-18 03:28 -------- d-----w- c:\program files\TrendMicro
2010-01-16 17:31 . 2010-01-16 17:31 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2010-01-12 23:56 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-10 00:17 . 2010-01-18 17:40 -------- d-----w- C:\CC Cleaner
2010-01-10 00:13 . 2010-01-10 00:13 -------- d-----w- c:\program files\CCleaner
2009-12-26 01:31 . 2009-12-26 01:31 51912 ---ha-w- c:\windows\system32\mlfcache.dat
2009-12-25 02:53 . 2009-12-25 02:54 -------- d-----w- c:\program files\QuickTime
2009-12-25 02:45 . 2009-12-25 02:45 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-19 23:50 . 2005-02-06 01:40 -------- d-----w- c:\program files\Common Files\Adobe
2010-01-19 23:49 . 2009-08-10 22:57 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-01-19 03:39 . 2004-08-03 22:59 96512 ----a-w- c:\windows\system32\drivers\atapi.sys
2010-01-19 00:18 . 2009-03-11 04:45 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-18 21:12 . 2009-08-12 18:21 -------- d-----w- c:\documents and settings\Owner\Application Data\TuneUpMedia
2010-01-18 17:23 . 2004-11-15 22:07 -------- d-----w- c:\program files\Java
2010-01-18 04:22 . 2009-04-01 02:25 5115823 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-13 05:13 . 2006-03-13 23:48 -------- d-----w- c:\documents and settings\Owner\Application Data\Apple Computer
2010-01-13 05:11 . 2009-08-12 18:21 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUpMedia
2010-01-07 21:07 . 2009-03-11 04:45 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 21:07 . 2009-03-11 04:45 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-25 02:59 . 2009-08-03 14:31 -------- d-----w- c:\program files\iTunes
2009-12-25 02:58 . 2006-03-13 23:44 -------- d-----w- c:\program files\iPod
2009-12-25 02:58 . 2009-07-11 14:34 -------- d-----w- c:\program files\Common Files\Apple
2009-12-08 02:42 . 2009-07-29 02:48 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-11-21 15:51 . 2004-11-15 20:29 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-20 11:08 . 2009-08-10 22:57 38784 ----a-w- c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-10-29 07:45 . 2004-11-15 20:30 916480 ------w- c:\windows\system32\wininet.dll
2005-09-10 13:50 . 2005-07-16 13:43 61920 ----a-w- c:\program files\MC
2005-02-27 17:38 . 2005-02-27 17:38 2342432 ----a-w- c:\program files\LimeWireWin.exe
.
((((((((((((((((((((((((((((( SnapShot@2010-01-18_16.58.56 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-01-19 23:33 . 2010-01-19 23:33 16384 c:\windows\temp\Perflib_Perfdata_6d0.dat
- 2004-11-15 21:45 . 2010-01-18 16:43 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2004-11-15 21:45 . 2010-01-19 03:28 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2010-01-16 17:31 . 2010-01-19 03:28 16384 c:\windows\system32\config\systemprofile\IETldCache\index.dat
- 2010-01-16 17:31 . 2010-01-18 16:43 16384 c:\windows\system32\config\systemprofile\IETldCache\index.dat
+ 2004-11-15 21:45 . 2010-01-19 03:28 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2004-11-15 21:45 . 2010-01-18 16:43 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2010-01-19 23:49 . 2010-01-19 23:49 27648 c:\windows\Installer\f3890.msi
+ 2010-01-18 17:23 . 2010-01-18 17:23 149280 c:\windows\system32\javaws.exe
+ 2010-01-18 17:23 . 2010-01-18 17:23 145184 c:\windows\system32\javaw.exe
+ 2010-01-18 17:23 . 2010-01-18 17:23 145184 c:\windows\system32\java.exe
- 2004-11-15 21:45 . 2010-01-18 16:43 278528 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2004-11-15 21:45 . 2010-01-19 03:28 278528 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2010-01-18 17:23 . 2010-01-18 17:23 537600 c:\windows\Installer\786a6.msi
+ 2010-01-19 00:16 . 2010-01-19 00:18 2413136 c:\windows\system32\Restore\rstrlog.dat
+ 2010-01-19 23:51 . 2010-01-19 23:51 3940352 c:\windows\Installer\f39c5.msi
- 2005-05-11 02:54 . 2010-01-05 00:17 29634504 c:\windows\system32\MRT.exe
+ 2005-05-11 02:54 . 2010-01-04 21:17 29634504 c:\windows\system32\MRT.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AGRSMMSG"="AGRSMMSG.exe" [2005-03-04 88209]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-10-08 126976]
"WD Button Manager"="WDBtnMgr.exe" [2007-12-12 339968]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-01-18 149280]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=c:\windows\pss\HP Image Zone Fast Start.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2004-10-13 20:00 57344 ----a-w- c:\windows\ALCMTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
2004-10-21 21:44 2744832 ----a-w- c:\windows\ALCWZRD.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2004-09-10 05:10 344064 ----a-w- c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ------w- c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
2004-08-12 21:45 61952 ----a-w- c:\windows\system32\Hdaudpropshortcut.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2006-02-19 06:41 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2004-10-08 15:31 155648 ----a-w- c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-11-12 21:33 141600 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-11 04:08 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2004-10-21 18:20 77824 ----a-w- c:\windows\SoundMan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VAIO Recovery]
2003-04-20 05:08 28672 ----a-w- c:\windows\SONYSYS\VAIO Recovery\Partseal.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"lanmanworkstation"=2 (0x2)
"WmiApSrv"=3 (0x3)
"VSS"=3 (0x3)
"UPS"=3 (0x3)
"TermService"=3 (0x3)
"LmHosts"=2 (0x2)
"wscsvc"=2 (0x2)
"SamSs"=2 (0x2)
"seclogon"=2 (0x2)
"RDSessMgr"=3 (0x3)
"xmlprov"=3 (0x3)
"mnmsrvc"=3 (0x3)
"Netlogon"=3 (0x3)
"NtLmSsp"=3 (0x3)
"IDriverT"=3 (0x3)
"CiSvc"=3 (0x3)
"helpsvc"=2 (0x2)
"FastUserSwitchingCompatibility"=3 (0x3)
"ERSvc"=2 (0x2)
"Browser"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
2009-09-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2005-02-05 c:\windows\Tasks\Registration reminder 1.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-11-15 00:12]
2005-02-05 c:\windows\Tasks\Registration reminder 3.job
- c:\windows\system32\OOBE\oobebaln.exe [2004-11-15 00:12]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
Trusted Zone: autotrader.com\www
Trusted Zone: go.com\sports.espn
Trusted Zone: intuit.com
Trusted Zone: tdameritrade.com
Trusted Zone: turbotax.com
.
- - - - ORPHANS REMOVED - - - -
Toolbar-Locked - (no file)
Notify-avgrsstarter - avgrsstx.dll
MSConfigStartUp-AVG9_TRAY - c:\progra~1\AVG\AVG9\avgtray.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-19 19:03
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(520)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2010-01-19 19:07:03
ComboFix-quarantined-files.txt 2010-01-20 00:07
Pre-Run: 120,925,433,856 bytes free
Post-Run: 121,018,929,152 bytes free
- - End Of File - - 691C1B098C2CD5B2E9CFF0FFE3FE464C