Hooray, it ran!
OK, here's the combofix log:
****************
ComboFix 09-09-05.02 - Kari & Fred 09/06/2009 8:30.1.2 - NTFSx86 NETWORK
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2046.1632 [GMT -7:00]
Running from: c:\users\Kari & Fred\Desktop\Combo-Fix.exe
AV: avast! antivirus 4.8.1169 [VPS 090901-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
SP: avast! antivirus 4.8.1169 [VPS 090901-0] *enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
SP: Spybot - Search and Destroy *enabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
c:\users\Kari & Fred\iexplore.exe
c:\users\Kari & Fred\Kari & Fred.exe
c:\windows\Installer\a528c8.msi
c:\windows\system32\bincd32.dat
c:\windows\system32\drivers\rotscxmvqtyqvv.sys
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\rotscxixwmwpjv.dll
c:\windows\system32\rotscxmenrosip.dat
c:\windows\system32\rotscxpxpwisfp.dll
c:\windows\system32\rotscxsutbsxjr.dat
c:\windows\system32\sysnet.dat
c:\windows\wpd99.drv
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ROTSCXNDPIFITQ
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
-------\Service_AntipPro2009_100
-------\Service_rotscxndpifitq
((((((((((((((((((((((((( Files Created from 2009-08-06 to 2009-09-06 )))))))))))))))))))))))))))))))
.
2009-09-06 15:36 . 2009-09-06 15:36 -------- d-----w- c:\users\Kelsey\AppData\Local\temp
2009-09-06 15:36 . 2009-09-06 16:10 -------- d-----w- c:\users\Kari & Fred\AppData\Local\temp
2009-09-06 15:36 . 2009-09-06 15:36 -------- d-----w- c:\users\Jenelle\AppData\Local\temp
2009-09-04 22:26 . 2009-09-06 11:37 -------- d-----w- c:\windows\system32\log
2009-09-04 22:26 . 2009-09-04 22:26 1055648 ----a-w- C:\RootkitBuster_2.52.1013.zip
2009-09-04 22:18 . 2009-09-04 22:20 3192102 ----a-w- C:\ComboFix.exe
2009-09-04 20:52 . 2009-09-04 20:55 -------- d-----w- c:\program files\Trend Micro
2009-09-04 20:51 . 2009-09-04 20:52 812344 ----a-w- C:\HJTInstall.exe
2009-09-04 19:24 . 2009-09-06 11:37 -------- d--h--w- c:\windows\PIF
2009-09-04 18:50 . 2009-08-03 20:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-04 18:50 . 2009-09-06 11:14 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-04 18:50 . 2009-08-03 20:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-04 16:51 . 2009-09-04 18:48 -------- d-----w- c:\program files\Malwarebytes' Anti-Malwarexxx
2009-09-04 16:32 . 2009-09-04 16:32 0 ----a-w- C:\settings.dat
2009-09-04 16:28 . 2009-09-04 16:29 464491 ----a-w- c:\users\Kari & Fred\RootRepeal.zip
2009-09-04 15:49 . 2009-09-04 16:30 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-09-04 15:49 . 2009-09-04 15:54 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-09-04 15:46 . 2009-09-04 15:46 16409960 ----a-w- c:\users\Kari & Fred\spybotsd162.exe
2009-09-04 06:56 . 2004-08-04 14:00 506368 ----a-w- c:\windows\system32\msxml.dll
2009-09-04 06:54 . 2009-09-04 06:54 26709272 ----a-w- c:\users\Kari & Fred\sdsetup.exe
2009-09-04 06:32 . 2009-09-04 06:33 10752 ----a-w- c:\users\Kari & Fred\exefix_xp.com
2009-09-04 05:57 . 2009-09-04 05:57 -------- d-----w- c:\users\Kari & Fred\AppData\Roaming\Malwarebytes
2009-09-04 05:57 . 2009-09-04 05:57 -------- d-----w- c:\programdata\Malwarebytes
2009-09-04 05:56 . 2009-09-04 05:56 3942048 ----a-w- C:\mbam-setup.exe
2009-09-04 05:43 . 2009-09-04 05:43 308160 ----a-w- C:\avast_home_setup.exe
2009-09-02 23:53 . 2009-08-28 12:39 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2009-09-02 23:53 . 2009-08-28 10:15 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2009-09-02 18:09 . 2009-09-06 15:22 -------- d-sh--w- c:\users\Kari & Fred\AppData\Roaming\lowsec
2009-09-02 16:38 . 2009-09-06 12:27 1356 ----a-w- c:\users\Kari & Fred\AppData\Local\d3d9caps.dat
2009-09-02 14:04 . 2009-09-02 14:04 206 ----a-w- c:\users\Kari & Fred\npdwus.bat
2009-08-28 04:31 . 2009-08-28 04:31 122 ----a-w- c:\users\Kari & Fred\DEQLKH.bat
2009-08-26 23:45 . 2009-08-26 23:45 -------- d-----w- c:\users\Kari & Fred\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-08-26 10:01 . 2009-06-22 10:22 2048 ----a-w- c:\windows\system32\tzres.dll
2009-08-22 10:10 . 2008-06-20 01:14 105016 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-08-22 10:10 . 2008-06-20 01:14 97800 ----a-w- c:\windows\system32\infocardapi.dll
2009-08-22 10:10 . 2008-06-20 01:14 43544 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2009-08-22 10:10 . 2008-06-20 01:14 11264 ----a-w- c:\windows\system32\icardres.dll
2009-08-22 10:10 . 2008-06-20 01:14 622080 ----a-w- c:\windows\system32\icardagt.exe
2009-08-22 10:10 . 2008-06-20 01:14 781344 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
2009-08-22 10:10 . 2008-06-20 01:14 326160 ----a-w- c:\windows\system32\PresentationHost.exe
2009-08-22 10:01 . 2008-07-27 18:03 96760 ----a-w- c:\windows\system32\dfshim.dll
2009-08-22 10:01 . 2008-07-27 18:03 282112 ----a-w- c:\windows\system32\mscoree.dll
2009-08-22 10:01 . 2008-07-27 18:03 41984 ----a-w- c:\windows\system32\netfxperf.dll
2009-08-22 10:01 . 2008-07-27 18:03 158720 ----a-w- c:\windows\system32\mscorier.dll
2009-08-22 10:01 . 2008-07-27 18:03 83968 ----a-w- c:\windows\system32\mscories.dll
2009-08-18 21:41 . 2009-08-18 21:41 -------- d-----w- c:\program files\EG Toolbar
2009-08-18 21:41 . 2009-08-18 21:41 -------- d-----w- c:\programdata\AGI
2009-08-18 21:41 . 2009-08-18 21:41 -------- d-----w- c:\program files\AGI
2009-08-17 03:56 . 2009-07-17 14:35 71680 ----a-w- c:\windows\system32\atl.dll
2009-08-17 03:56 . 2009-06-10 12:12 160256 ----a-w- c:\windows\system32\wkssvc.dll
2009-08-17 03:56 . 2009-06-04 12:34 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-08-17 03:56 . 2009-06-10 12:07 91136 ----a-w- c:\windows\system32\avifil32.dll
2009-08-17 03:55 . 2009-07-14 13:00 313344 ----a-w- c:\windows\system32\wmpdxm.dll
2009-08-17 03:55 . 2009-07-14 12:59 4096 ----a-w- c:\windows\system32\dxmasf.dll
2009-08-17 03:55 . 2009-07-14 12:58 7680 ----a-w- c:\windows\system32\spwmp.dll
2009-08-17 03:55 . 2009-07-14 10:59 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-08-13 18:14 . 2009-09-04 16:29 472064 ----a-w- C:\RootRepeal.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-06 11:34 . 2007-07-16 05:40 -------- d-----w- c:\programdata\Google Updater
2009-09-04 17:36 . 2008-04-18 03:23 -------- d-----w- c:\programdata\pdf995
2009-08-22 15:55 . 2007-05-29 02:12 -------- d-----w- c:\users\Kari & Fred\AppData\Roaming\Apple Computer
2009-08-22 15:47 . 2008-07-20 14:23 -------- d-----w- c:\program files\Instant CD & DVD Burner
2009-08-17 10:03 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-08-14 13:58 . 2009-09-04 06:56 7396 ----a-w- c:\windows\system32\drivers\pctcore.cat
2009-08-06 12:40 . 2009-08-06 04:49 -------- d-----w- c:\programdata\NOS
2009-08-06 12:40 . 2009-08-06 04:49 -------- d-----w- c:\program files\NOS
2009-08-06 06:59 . 2009-01-28 18:08 -------- d-----w- c:\program files\Microsoft Silverlight
2009-08-06 04:56 . 2007-06-03 15:45 -------- d-----w- c:\program files\Common Files\Adobe
2009-08-06 04:52 . 2009-08-06 04:52 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-07-21 21:52 . 2009-07-29 04:22 915456 ----a-w- c:\windows\system32\wininet.dll
2009-07-21 21:47 . 2009-07-29 04:22 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-07-21 21:47 . 2009-07-29 04:22 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-07-21 20:13 . 2009-07-29 04:22 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-06-15 15:24 . 2009-07-15 09:57 156672 ----a-w- c:\windows\system32\t2embed.dll
2009-06-15 15:20 . 2009-07-15 09:57 72704 ----a-w- c:\windows\system32\fontsub.dll
2009-06-15 15:20 . 2009-07-15 09:57 10240 ----a-w- c:\windows\system32\dciman32.dll
2009-06-15 12:52 . 2009-07-15 09:57 289792 ----a-w- c:\windows\system32\atmfd.dll
2008-04-18 03:25 . 2008-04-18 03:25 67072 ----a-w- c:\program files\pdf995.dot
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{0BC6E3FA-78EF-4886-842C-5A1258C4455A}"= "mscoree.dll" [2008-07-27 282112]
[HKEY_CLASSES_ROOT\clsid\{0bc6e3fa-78ef-4886-842c-5a1258c4455a}]
[HKEY_CLASSES_ROOT\agcore.AGUtils]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0bc6e3fa-78ef-4886-842c-5a1258c4455a}]
2008-07-27 18:03 282112 ----a-w- c:\windows\System32\mscoree.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{9df9b682-9c18-4a01-bac3-a265ca7cd866}"= "mscoree.dll" [2008-07-27 282112]
[HKEY_CLASSES_ROOT\clsid\{9df9b682-9c18-4a01-bac3-a265ca7cd866}]
[HKEY_CLASSES_ROOT\EGToolbar.EGToolbar]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-16 68856]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-03-29 79224]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"WPCUMI"="c:\windows\system32\WpcUmi.exe" [2006-11-02 176128]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2007-09-08 2595480]
"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageHome\TimounterMonitor.exe" [2007-09-08 905056]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2007-09-08 140568]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-18 136600]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe" [2007-08-24 240112]
"DMXLauncher"="c:\program files\Roxio\CinePlayer\DMXLauncher.exe" [2007-08-14 113136]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-09-12 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-12 8497696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-09-12 81920]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-9-11 576104]
HotSync Manager.lnk - c:\program files\Palm\Hotsync.exe [2008-1-3 1392640]
Yahoo! Autosync.lnk - c:\program files\Yahoo!\Yahoo! Autosync\AutosyncForYahoo.exe [2007-8-21 391680]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{C2E19DDF-306F-46E4-AC87-680E7E4BB898}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{D789942A-287F-4F96-93BC-EEB4F3CE4CC5}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{AC5396FA-BF9D-40EC-8A6D-55D5663BBCD8}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{52BF51D0-2541-478B-BAB6-F6087AEDB0AA}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{0C8FB912-D19A-40AD-992A-88BC0B42428C}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{0D72C73A-8CD0-4276-B404-E4A200125E9D}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{4B85C46B-3206-4160-B084-C4F70C1BCA93}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{8B40D769-3BDC-40EC-AE8E-CD843C27B783}"= UDP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{6E8F65DF-C3F5-4E02-BF4D-106377A51662}"= TCP:c:\program files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"TCP Query User{1F4E9A77-9C28-457E-A010-B6C7DF21B06C}c:\\program files\\rhapsody\\rhapsody.exe"= UDP:c:\program files\rhapsody\rhapsody.exe:RealNetworks Rhapsody
"UDP Query User{AA875618-0D1C-4E51-987E-C724D562F6AD}c:\\program files\\rhapsody\\rhapsody.exe"= TCP:c:\program files\rhapsody\rhapsody.exe:RealNetworks Rhapsody
"{1733E126-5D98-4E13-893C-8FC3E8F1776D}"= UDP:c:\program files\TurboTax\Deluxe 2007\32bit\ttax.exe:TurboTax
"{E4050DD7-482E-4CF0-B48D-1E27B3148D51}"= TCP:c:\program files\TurboTax\Deluxe 2007\32bit\ttax.exe:TurboTax
"{A678376E-0072-4E01-8F6B-B5B22DC54D14}"= UDP:c:\program files\TurboTax\Deluxe 2007\32bit\updatemgr.exe:TurboTax Update Manager
"{66E15B23-BD88-4A4A-AD81-445AD2EA1226}"= TCP:c:\program files\TurboTax\Deluxe 2007\32bit\updatemgr.exe:TurboTax Update Manager
"{81853639-F6C8-4E26-AEAF-335094B31528}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
"{7158EC17-3DB9-49F7-8AD2-6D98F7EF0CC4}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{624331FE-B56B-41A0-8A4C-78468A48D311}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{115FB5F0-8F05-4789-943E-6ECDDFFD58CB}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{F8FDAC71-30AC-41E6-999F-811CD8705C7F}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
S1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [4/8/2008 9:20 PM 75856]
S2 AGCoreService;AG Core Services;c:\program files\AGI\core\3.0\AGCoreService.exe [8/18/2009 2:41 PM 40960]
S2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [4/8/2008 9:20 PM 20560]
S2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [6/1/2007 9:21 AM 50768]
S2 IntuitUpdateService;Intuit Update Service;c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [10/10/2008 5:45 AM 13088]
S2 Roxio Upnp Server 10;Roxio Upnp Server 10;c:\program files\Roxio\Digital Home 10\RoxioUpnpService10.exe [8/24/2007 3:53 PM 362992]
S2 RoxLiveShare10;LiveShare P2P Server 10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe [8/24/2007 3:52 PM 309744]
S2 RoxWatch10;Roxio Hard Drive Watcher 10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe [8/24/2007 3:52 PM 166384]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [9/4/2009 8:49 AM 1153368]
S2 tgsrvc_chatsupport.palm.com;SupportSoft Repair Service (chatsupport.palm.com);c:\program files\chatsupport.palm.com\bin\tgsrvc.exe [5/21/2008 5:24 AM 148768]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [12/9/2007 3:48 PM 24652]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [1/28/2009 11:07 AM 55264]
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [12/8/2008 6:01 PM 533344]
S3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;c:\program files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [8/24/2007 3:53 PM 72176]
S3 RoxMediaDB10;RoxMediaDB10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [8/24/2007 3:52 PM 1083888]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-09-06 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-05-28 16:25]
2009-09-06 c:\windows\Tasks\User_Feed_Synchronization-{772D9F7B-0E68-441F-A3A4-AB7FDE0E0B86}.job
- c:\windows\system32\msfeedssync.exe [2009-07-29 20:13]
2009-09-06 c:\windows\Tasks\User_Feed_Synchronization-{89FEEB60-617B-499F-A824-2C6370ECC6C9}.job
- c:\windows\system32\msfeedssync.exe [2009-07-29 20:13]
2009-09-06 c:\windows\Tasks\User_Feed_Synchronization-{9E718C97-9091-472A-8027-7B8F1ACA2A3C}.job
- c:\windows\system32\msfeedssync.exe [2009-07-29 20:13]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-HotSync - c:\program files\PalmSource\Desktop\HotSync.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://www.yahoo.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
LSP: c:\windows\system32\wpclsp.dll
Trusted Zone: real.com\rhap-app-4-0
Trusted Zone: real.com\rhapreg
Trusted Zone: turbotax.com
DPF: CabBuilder - hxxp://ak.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
FF - ProfilePath - c:\users\Kari & Fred\AppData\Roaming\Mozilla\Firefox\Profiles\uery8kw7.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/?.home=ytff
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p=
FF - plugin: c:\progra~1\Palm\PACKAG~1\NPInstal.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa2.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmusicn.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: c:\program files\Virtual Earth 3D\npVE3D.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-06 09:10
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
c:\windows\TEMP\TMP00000039576CEC5972BF01A5 524288 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="FirefoxHTML"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="FirefoxHTML"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="FirefoxHTML"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="FirefoxHTML"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="FirefoxHTML"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(620)
c:\windows\system32\relog_ap.dll
- - - - - - - > 'Explorer.exe'(5616)
c:\windows\system32\btmmhook.dll
c:\windows\system32\btncopy.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\audiodg.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Alwil Software\Avast4\ashDisp.exe
c:\windows\System32\rundll32.exe
c:\windows\System32\rundll32.exe
c:\windows\ehome\ehmsas.exe
c:\program files\WIDCOMM\Bluetooth Software\BTStackServer.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\System32\wbem\unsecapp.exe
.
**************************************************************************
.
Completion time: 2009-09-06 9:13 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-06 16:12
Pre-Run: The system cannot find message text for message number 0x2379 in the message file for Application.
Post-Run: 162,735,783,936 bytes free
311