Ried: Here is the ComboFix log file. Somehow in the flurry of pop-up ads and this computer jittering around with its insanities I missed the Uninstall tool which quickly fixed AVG.
ComboFix 11-04-12.02 - T H Stearns 04/13/2011 7:33.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1578 [GMT -4:00]
Running from: c:\documents and settings\T H Stearns\My Documents\Downloads\ComboFix.exe
FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\T H Stearns\WINDOWS
c:\windows\system32\drivers\dfg.sys
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_dfg
.
.
((((((((((((((((((((((((( Files Created from 2011-03-13 to 2011-04-13 )))))))))))))))))))))))))))))))
.
.
2011-04-13 00:18 . 2011-04-13 00:18 -------- d-----w- c:\documents and settings\T H Stearns\Application Data\SUPERAntiSpyware.com
2011-04-13 00:18 . 2011-04-13 00:18 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2011-04-13 00:18 . 2011-04-13 00:18 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-04-12 11:07 . 2011-04-12 11:08 -------- d-----w- c:\documents and settings\Administrator
2011-04-10 14:41 . 2011-04-10 14:42 -------- d-----w- c:\documents and settings\T H Stearns\Local Settings\Application Data\ConduitEngine
2011-04-10 14:41 . 2011-04-10 14:41 -------- d-----w- c:\program files\ConduitEngine
2011-04-10 14:41 . 2011-04-10 14:41 0 ----a-w- c:\windows\system32\ConduitEngine.tmp
2011-04-09 19:35 . 2011-04-09 19:35 -------- d-----w- c:\documents and settings\T H Stearns\Application Data\Malwarebytes
2011-04-09 19:35 . 2010-12-20 22:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-04-09 19:35 . 2011-04-09 19:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-04-09 19:35 . 2011-04-09 19:35 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-04-09 19:35 . 2010-12-20 22:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-04-08 18:32 . 2004-08-04 12:00 5632 -c--a-w- c:\windows\system32\dllcache\smimsgif.dll
2011-04-08 18:32 . 2004-08-04 12:00 5632 -c--a-w- c:\windows\system32\dllcache\smierrsy.dll
2011-04-08 18:32 . 2004-08-04 12:00 5632 ----a-w- c:\windows\system32\wbem\snmp\smimsgif.dll
2011-04-08 18:32 . 2004-08-04 12:00 5632 ----a-w- c:\windows\system32\wbem\snmp\smierrsy.dll
2011-04-08 18:32 . 2004-08-04 12:00 15872 -c--a-w- c:\windows\system32\dllcache\smierrsm.dll
2011-04-08 18:32 . 2004-08-04 12:00 15872 ----a-w- c:\windows\system32\wbem\snmp\smierrsm.dll
2011-04-08 18:32 . 2004-08-04 12:00 10240 -c--a-w- c:\windows\system32\dllcache\snmpstup.dll
2011-04-08 18:32 . 2004-08-04 12:00 10240 ----a-w- c:\windows\system32\wbem\snmpstup.dll
2011-04-08 14:44 . 2011-04-08 14:48 -------- d-----w- c:\documents and settings\All Users\Application Data\RegSERVO
2011-04-08 14:44 . 2011-04-08 14:44 -------- d-----w- c:\program files\REGSERVO
2011-04-07 01:01 . 2011-04-07 01:01 -------- d-----w- c:\documents and settings\T H Stearns\Local Settings\Application Data\Microsoft Corporation
2011-04-04 07:59 . 2011-02-03 01:40 472808 ----a-w- c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
2011-04-03 23:34 . 2011-04-03 23:34 -------- d-----w- c:\program files\Common Files\Adobe AIR
2011-04-02 00:33 . 2001-03-15 09:18 20584 ------w- c:\windows\system32\PdfPorts.dll
2011-04-02 00:33 . 2001-03-15 09:18 65536 ------w- c:\windows\system32\adistres.dll
2011-04-02 00:33 . 2001-01-30 17:56 225280 ------w- c:\program files\Internet Explorer\PLUGINS\NPDocBox.dll
2011-04-02 00:32 . 2001-03-15 08:55 101200 ------w- c:\windows\system32\pdfshell.dll
2011-04-02 00:32 . 2011-04-02 00:32 -------- d-----w- c:\windows\system32\Adobe
2011-04-02 00:31 . 2011-04-02 00:31 -------- d-----w- c:\documents and settings\T H Stearns\Application Data\InterTrust
2011-04-02 00:30 . 2011-04-02 15:24 -------- d-----w- c:\windows\SxsCaPendDel
2011-04-01 19:28 . 2011-04-01 19:28 -------- d-----w- C:\spoolerlogs
2011-03-27 01:13 . 2011-03-27 01:13 -------- d-----w- c:\documents and settings\T H Stearns\Application Data\NCH Software
2011-03-27 00:40 . 2011-03-27 00:40 -------- d-----w- c:\documents and settings\T H Stearns\Application Data\Recordpad
2011-03-24 15:13 . 2008-04-14 00:12 26624 ----a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2011-03-19 16:10 . 2011-03-19 16:10 -------- d-----w- c:\program files\Common Files\Java
2011-03-19 16:01 . 2011-03-19 16:01 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2011-03-16 18:48 . 2008-06-30 14:02 348160 ----a-w- c:\windows\system32\msvcr71.dll
2011-03-16 18:48 . 2008-06-30 14:02 499712 ----a-w- c:\windows\system32\msvcp71.dll
2011-03-16 18:48 . 2009-08-12 15:37 38672 ----a-w- c:\windows\system32\pcleUtil.dll
2011-03-16 18:48 . 2009-01-28 15:52 142337 ----a-w- c:\windows\system32\Wait.exe
2011-03-16 18:47 . 2010-09-27 19:38 323640 ----a-w- c:\windows\system32\hcwpnp32.dll
2011-03-16 18:47 . 2010-08-26 22:07 118840 ----a-w- c:\windows\system32\hcwi2c32.dll
2011-03-16 18:47 . 2009-02-17 03:09 831554 ----a-w- c:\windows\system32\hcwtvwnd.dll
2011-03-16 18:47 . 2006-10-10 22:47 36921 ----a-w- c:\windows\system32\hcwutl32.dll
2011-03-16 18:47 . 2010-04-23 15:52 1220224 ----a-w- c:\windows\system32\drivers\hcw72DTV.sys
2011-03-16 18:47 . 2010-04-23 15:47 28928 ----a-w- c:\windows\system32\drivers\hcw72ADFilter.sys
2011-03-16 18:47 . 2008-04-13 17:46 15232 -c--a-w- c:\windows\system32\dllcache\mpe.sys
2011-03-16 18:47 . 2008-04-13 17:46 15232 ----a-w- c:\windows\system32\drivers\MPE.sys
2011-03-16 18:46 . 2010-04-23 10:47 44032 ----a-w- c:\windows\system32\hcw72Co.dll
2011-03-16 18:46 . 2008-05-20 17:37 95744 ----a-w- c:\windows\system32\hcwcpxx.ax
2011-03-16 18:46 . 2010-04-23 15:48 1217920 ----a-w- c:\windows\system32\drivers\hcw72ATV.sys
2011-03-16 18:46 . 2008-04-13 23:12 33280 ----a-w- c:\windows\system32\PsisRndr.ax
2011-03-16 18:46 . 2008-04-13 23:12 363520 -c--a-w- c:\windows\system32\dllcache\psisdecd.dll
2011-03-16 18:46 . 2008-04-13 23:12 363520 ----a-w- c:\windows\system32\PsisDecd.dll
2011-03-16 18:46 . 2008-04-13 23:12 56832 ----a-w- c:\windows\system32\MSDvbNP.ax
2011-03-16 18:46 . 2008-04-13 23:12 18432 ----a-w- c:\windows\system32\BdaPlgIn.ax
2011-03-16 18:46 . 2008-04-13 17:46 11776 -c--a-w- c:\windows\system32\dllcache\bdasup.sys
2011-03-16 18:46 . 2008-04-13 17:46 11776 ----a-w- c:\windows\system32\drivers\BdaSup.sys
2011-03-16 18:46 . 2008-04-13 17:45 60032 -c--a-w- c:\windows\system32\dllcache\usbaudio.sys
2011-03-16 18:46 . 2008-04-13 17:45 60032 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2011-03-16 18:38 . 2008-04-13 17:45 32128 -c--a-w- c:\windows\system32\dllcache\usbccgp.sys
2011-03-16 18:38 . 2008-04-13 17:45 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-07 05:33 . 2010-12-26 02:37 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:37 . 2004-08-04 12:00 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21 . 2004-08-04 12:00 1857920 ----a-w- c:\windows\system32\win32k.sys
2011-02-22 23:06 . 2004-08-04 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2011-02-22 23:06 . 2004-08-04 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-02-22 23:06 . 2004-08-04 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-02-22 11:41 . 2004-08-04 12:00 385024 ------w- c:\windows\system32\html.iec
2011-02-17 13:18 . 2004-08-04 12:00 455936 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-02-17 13:18 . 2004-08-04 12:00 357888 ----a-w- c:\windows\system32\drivers\srv.sys
2011-02-17 12:32 . 2010-12-26 03:01 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2011-02-15 12:56 . 2004-08-04 12:00 290432 ----a-w- c:\windows\system32\atmfd.dll
2011-02-09 13:53 . 2004-08-04 12:00 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53 . 2004-08-04 12:00 186880 ----a-w- c:\windows\system32\encdec.dll
2011-02-08 13:33 . 2004-08-04 12:00 978944 --sh--w- c:\windows\system32\mfc42.dll
2011-02-08 13:33 . 2004-08-04 12:00 974848 ----a-w- c:\windows\system32\mfc42u.dll
2011-02-03 01:40 . 2010-12-26 23:01 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-02-02 23:19 . 2010-12-26 22:49 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-02-02 07:58 . 2010-12-26 02:35 2067456 ----a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57 . 2010-12-26 02:35 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44 . 2004-08-04 12:00 439296 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-20 15:02 . 2011-01-20 15:02 249856 ------w- c:\windows\Setup1.exe
2011-01-20 15:02 . 2011-01-20 15:02 73216 ------w- c:\windows\ST6UNST.EXE
2011-03-18 17:53 . 2011-04-09 11:10 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2004-08-04 12:00 94784 --sh--w- c:\windows\twain.dll
2008-04-14 00:12 50688 --sh--w- c:\windows\twain_32.dll
2008-04-14 00:12 57344 --sh--w- c:\windows\system32\msvcirt.dll
2008-04-14 00:12 413696 --sh--w- c:\windows\system32\msvcp60.dll
2008-04-14 00:12 343040 --sh--w- c:\windows\system32\msvcrt.dll
2008-04-14 00:12 551936 --sh--w- c:\windows\system32\oleaut32.dll
2008-04-14 00:12 84992 --sh--w- c:\windows\system32\olepro32.dll
2008-04-14 00:12 11776 --sh--w- c:\windows\system32\regsvr32.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{37483b40-c254-4a72-bda4-22ee90182c1e}"= "c:\program files\NCH_EN\prxtbNCH0.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{37483b40-c254-4a72-bda4-22ee90182c1e}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 14:54 175912 ----a-w- c:\program files\ConduitEngine\prxConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{37483b40-c254-4a72-bda4-22ee90182c1e}]
2011-01-17 14:54 175912 ----a-w- c:\program files\NCH_EN\prxtbNCH0.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{37483b40-c254-4a72-bda4-22ee90182c1e}"= "c:\program files\NCH_EN\prxtbNCH0.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{37483b40-c254-4a72-bda4-22ee90182c1e}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{37483B40-C254-4A72-BDA4-22EE90182C1E}"= "c:\program files\NCH_EN\prxtbNCH0.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{37483b40-c254-4a72-bda4-22ee90182c1e}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2011-03-17 107000]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-03-16 2423752]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"C-Media Mixer"="Mixer.exe" [2002-10-15 1818624]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2011-01-08 111208]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-01-08 13880424]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2010-11-04 1753192]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-17 19968]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
"High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe" [2004-03-17 61952]
"EPSON Stylus Photo 2200"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE" [2002-07-01 74752]
"QuickFinder Scheduler"="c:\program files\Corel\WordPerfect Office 2002\Programs\QFSCHD100.EXE" [2001-10-02 77887]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
.
c:\documents and settings\T H Stearns\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [2011-4-1 49254]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-9-23 415072]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
.
[HKLM\~\startupfolder\C:^Documents and Settings^T H Stearns^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk]
path=c:\documents and settings\T H Stearns\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk
backup=c:\windows\pss\OpenOffice.org 3.1.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPWT myPrintMileage Agent]
2005-01-26 08:45 102400 ------w- c:\program files\Hewlett-Packard\HP Business Inkjet 1000\Toolbox\mpm.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 --sh--w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoboForm]
2011-03-17 19:22 107000 ----a-w- c:\program files\Siber Systems\AI RoboForm\robotaskbaricon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-10-29 18:49 249064 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP

xpsp2res.dll,-22009
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP

eer Name Resolution Protocol (PNRP)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
.
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 2:25 PM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 2:41 PM 67656]
S2 BT848;AVerMedia AVerTV WDM Video Capture (878);c:\windows\system32\drivers\Bt848.sys --> c:\windows\system32\drivers\Bt848.sys [?]
S2 Iprip;RIP Listener;c:\windows\System32\svchost.exe -k netsvcs [8/4/2004 8:00 AM 14336]
S3 cmudax;C-Media High Definition Audio Interface;c:\windows\system32\drivers\cmudax.sys --> c:\windows\system32\drivers\cmudax.sys [?]
S3 cpudrv;cpudrv;\??\c:\program files\SystemRequirementsLab\cpudrv.sys --> c:\program files\SystemRequirementsLab\cpudrv.sys [?]
S3 hcw72ADFilter;WinTV HVR-950 USB Audio Filter Driver;c:\windows\system32\drivers\hcw72ADFilter.sys [3/16/2011 2:47 PM 28928]
S3 hcw72ATV;WinTV HVR-950 NTSC;c:\windows\system32\drivers\hcw72ATV.sys [3/16/2011 2:46 PM 1217920]
S3 hcw72DTV;WinTV HVR-950 ATSC/QAM;c:\windows\system32\drivers\hcw72DTV.sys [3/16/2011 2:47 PM 1220224]
S3 HwIOctl;HwIOctl;\??\c:\documents and settings\T H Stearns\Desktop\Drivers\HwIOctl.sys --> c:\documents and settings\T H Stearns\Desktop\Drivers\HwIOctl.sys [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-03-27 c:\windows\Tasks\expressripShakeIcon.job
- c:\program files\NCH Swift Sound\ExpressRip\expressrip.exe [2010-12-27 17:00]
.
2011-04-08 c:\windows\Tasks\RegSERVO.job
- c:\program files\REGSERVO\RegSERVO.exe [2010-08-19 16:45]
.
2011-04-10 c:\windows\Tasks\wavepadShakeIcon.job
- c:\program files\NCH Swift Sound\WavePad\wavepad.exe [2011-03-27 00:47]
.
.
------- Supplementary Scan -------
.
uLocal Page = \blank.htm
uStart Page = hxxp://www.google.com/
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
Trusted Zone: mcafee.com
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} -
FF - ProfilePath - c:\documents and settings\T H Stearns\Application Data\Mozilla\Firefox\Profiles\szlw4l3y.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-AVG_TRAY - c:\program files\AVG\AVG10\avgtray.exe
AddRemove-Adobe Flash Player ActiveX - c:\windows\system32\Macromed\Flash\FlashUtil10l_ActiveX.exe
AddRemove-Adobe Flash Player Plugin - c:\windows\system32\Macromed\Flash\FlashUtil10l_Plugin.exe
AddRemove-Copy Utility - c:\program files\EPSON\Copy Utility\Uninst.isu
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
GMER - Rootkit Detector and Remover
Rootkit scan 2011-04-13 07:38
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1004336348-1275210071-1801674531-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(708)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
- - - - - - - > 'explorer.exe'(3244)
c:\windows\system32\WININET.dll
c:\program files\Logitech\MouseWare\System\LgWndHk.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\program files\Common Files\Logitech\Scrolling\LgMsgHk.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\EPSON\EBAPI\eEBSVC.exe
c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
c:\program files\Common Files\EPSON\EBAPI\SAgent2.exe
c:\windows\Mixer.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\tcpsvcs.exe
c:\program files\Logitech\MouseWare\system\em_exec.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\windows\System32\snmp.exe
.
**************************************************************************
.
Completion time: 2011-04-13 07:41:51 - machine was rebooted
ComboFix-quarantined-files.txt 2011-04-13 11:41
.
Pre-Run: 34,673,332,224 bytes free
Post-Run: 35,120,279,552 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 3996219C7AF3FE72E0D02FC9358238FE