Combofix log below, and have pasted AVG log below
ComboFix 08-04-14.2 - Maria 2008-04-18 19:16:02.4 - NTFSx86 MINIMAL
Running from: C:\Documents and Settings\Maria\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-03-18 to 2008-04-18 )))))))))))))))))))))))))))))))
.
Scan "Command line scan" was finished.
Infections found:;"15"
Infected objects removed or healed;"0"
Not removed or healed.;"15"
Spyware found:;"4"
Spyware removed:;"0"
Not removed:;"4"
Warnings count:;"62"
Information count:;"0"
Scan started:;"18 April 2008, 12:21:08"
Total object scanned:;"828520"
Time needed:;"3 hour(s) 48 minute(s) 43 second(s) "
Errors encountered:;"0"
Infections
File;"Infection";"Result"
C:\Documents and Settings\John\My Documents\My Videos\ASE_Setup_Free.exe;"Trojan horse SHeur.BDYB";"Infected"
C:\Documents and Settings\Maria\Desktop\SDFix\backups\backups.zip:\backups\spnkfwad.exe;"Trojan horse Downloader.Adload.EZ";"Infected"
C:\Documents and Settings\Maria\Desktop\SDFix\backups\backups.zip;"Trojan horse Downloader.Adload.EZ";"Infected"
C:\Documents and Settings\Maria\DoctorWeb\Quarantine\fmptdpay.dll.vir;"Virus found Lop";"Infected"
C:\Documents and Settings\Maria\DoctorWeb\Quarantine\pmnLcbxw.dll.vir;"Trojan horse Generic10.KWR";"Infected"
C:\Documents and Settings\Maria\DoctorWeb\Quarantine\yknlisac.dll.vir;"Virus found Lop";"Infected"
C:\Program Files\Common Files\AOL\Backup\ACS\Current\Suite\comps\acsxpfix.exe:\ns_00002;"Trojan horse Startpage.CPM";"Infected"
C:\Program Files\Common Files\AOL\Backup\ACS\Current\Suite\comps\acsxpfix.exe;"Trojan horse Startpage.CPM";"Infected"
C:\Program Files\Common Files\AOL\Backup\ACS\Rollback\ACSLAN~1.EXE:\ns_00002;"Trojan horse Startpage.CPM";"Infected"
C:\Program Files\Common Files\AOL\Backup\ACS\Rollback\ACSLAN~1.EXE;"Trojan horse Startpage.CPM";"Infected"
C:\QooBox\Quarantine\C\WINDOWS\system32\qtrscfep.dll_old.vir;"Virus found Win32/Heur";"Infected"
C:\QooBox\Quarantine\catchme2008-04-15_211741.39.zip:\Documents and Settings\Maria\Desktop\catchme.zip:\tuvvSIyW.dll;"Trojan horse Generic10.KYZ";"Infected"
C:\QooBox\Quarantine\catchme2008-04-15_211741.39.zip:\Documents and Settings\Maria\Desktop\catchme.zip:\wvUnNfDv.dll;"Trojan horse Generic10.KWR";"Infected"
C:\QooBox\Quarantine\catchme2008-04-15_211741.39.zip:\Documents and Settings\Maria\Desktop\catchme.zip;"Trojan horse Generic10.KYZ";"Infected"
C:\QooBox\Quarantine\catchme2008-04-15_211741.39.zip;"Trojan horse Generic10.KYZ";"Infected"
Spyware
File;"Infection";"Result"
C:\Documents and Settings\Maria\Desktop\SDFix\apps\download.exe;"Potentially harmful program Tool.FF";"Potentially dangerous object"
C:\Documents and Settings\Maria\Desktop\SDFix.exe:\SDFix\apps\download.exe;"Potentially harmful program Tool.FF";"Potentially dangerous object"
C:\Documents and Settings\Maria\Desktop\SDFix.exe;"Potentially harmful program Tool.FF";"Potentially dangerous object"
C:\SDFix\apps\download.exe;"Potentially harmful program Tool.FF";"Potentially dangerous object"
Warnings
File;"Infection";"Result"
HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0EDC6C20-A31C-11DB-8AB9-0800200C9A66};"Found Adware.RogueSuspect";"Potentially dangerous object"
HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{1C78AB3F-A857-482E-80C0-3A1E5238A565};"Found Adware.Isearch";"Potentially dangerous object"
HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{3AAC4C68-AFC8-11DB-80EF-8AF955D89593};"Found Adware.RogueSuspect";"Potentially dangerous object"
HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{5054F860-748D-4840-B7B4-DDDB428421AF};"Found Adware.Generic";"Potentially dangerous object"
HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{88D758A3-D33B-45FD-91E3-67749B4057FA};"Found Adware.Generic";"Potentially dangerous object"
HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{9C691A33-7DDA-4C2F-BE4C-C176083F35CF};"Found Adware.TitanShieldAntispyware";"Potentially dangerous object"
HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{E2B2B5A1-B48C-4886-A318-723916A01024};"Found Adware.Generic";"Potentially dangerous object"
HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{E6D5237D-A6C7-4C83-A67F-F9F15586FA62};"Found Adware.Generic";"Potentially dangerous object"
HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{E8EDB60C-951E-4130-93DC-FAF1AD25F8E7};"Found Adware.Generic";"Potentially dangerous object"
HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{FE6A3E85-0F6C-49AD-8843-68FF44E7EEA9};"Found Adware.SecureServicePack";"Potentially dangerous object"
HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF};"Found Adware.Generic";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@adbrite[2].txt:\adbrite.com.d5e309c2;"Found Tracking cookie.Adbrite";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@adbrite[2].txt:\adbrite.com.71beeff9;"Found Tracking cookie.Adbrite";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@adbrite[2].txt;"Found Tracking cookie.Adbrite";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@adtech[2].txt:\adtech.de.a9245469;"Found Tracking cookie.Adtech";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@adtech[2].txt;"Found Tracking cookie.Adtech";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@advertising[2].txt:\advertising.com.203aa218;"Found Tracking cookie.Advertising";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@advertising[2].txt:\advertising.com.f62113d5;"Found Tracking cookie.Advertising";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@advertising[2].txt:\advertising.com.1820df7a;"Found Tracking cookie.Advertising";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@advertising[2].txt:\advertising.com.b624fa46;"Found Tracking cookie.Advertising";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@advertising[2].txt;"Found Tracking cookie.Advertising";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@aoluk.122.2o7[1].txt:\aoluk.122.2o7.net.7225be6f;"Found Tracking cookie.2o7";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@aoluk.122.2o7[1].txt;"Found Tracking cookie.2o7";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@atdmt[2].txt:\atdmt.com.b3e33b5f;"Found Tracking cookie.Atdmt";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@atdmt[2].txt;"Found Tracking cookie.Atdmt";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@atdmt[3].txt:\atdmt.com.b3e33b5f;"Found Tracking cookie.Atdmt";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@atdmt[3].txt;"Found Tracking cookie.Atdmt";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@bs.serving-sys[1].txt:\bs.serving-sys.com.5bf1f00f;"Found Tracking cookie.Serving-sys";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@bs.serving-sys[1].txt;"Found Tracking cookie.Serving-sys";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@doubleclick[1].txt:\doubleclick.net.bf396750;"Found Tracking cookie.Doubleclick";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@doubleclick[1].txt;"Found Tracking cookie.Doubleclick";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@doubleclick[2].txt:\doubleclick.net.bf396750;"Found Tracking cookie.Doubleclick";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@doubleclick[2].txt;"Found Tracking cookie.Doubleclick";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@fastclick[1].txt:\fastclick.net.fac3d6f0;"Found Tracking cookie.Fastclick";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@fastclick[1].txt:\fastclick.net.8a6435e9;"Found Tracking cookie.Fastclick";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@fastclick[1].txt:\fastclick.net.57e8da10;"Found Tracking cookie.Fastclick";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@fastclick[1].txt:\fastclick.net.19d0b716;"Found Tracking cookie.Fastclick";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@fastclick[1].txt:\fastclick.net.6fd479aa;"Found Tracking cookie.Fastclick";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@fastclick[1].txt;"Found Tracking cookie.Fastclick";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@media.adrevolver[1].txt:\media.adrevolver.com.5fed601d;"Found Tracking cookie.Adrevolver";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@media.adrevolver[1].txt;"Found Tracking cookie.Adrevolver";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@mediaplex[1].txt:\mediaplex.com.f652b123;"Found Tracking cookie.Mediaplex";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@mediaplex[1].txt;"Found Tracking cookie.Mediaplex";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@mediaplex[2].txt:\mediaplex.com.f652b123;"Found Tracking cookie.Mediaplex";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@mediaplex[2].txt;"Found Tracking cookie.Mediaplex";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@msnportal.112.2o7[1].txt:\msnportal.112.2o7.net.7225be6f;"Found Tracking cookie.2o7";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@msnportal.112.2o7[1].txt;"Found Tracking cookie.2o7";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@msnportal.112.2o7[2].txt:\msnportal.112.2o7.net.7225be6f;"Found Tracking cookie.2o7";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@msnportal.112.2o7[2].txt;"Found Tracking cookie.2o7";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@revsci[1].txt:\revsci.net.e9dbeb91;"Found Tracking cookie.Revsci";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@revsci[1].txt:\revsci.net.2df99d79;"Found Tracking cookie.Revsci";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@revsci[1].txt:\revsci.net.44927ec;"Found Tracking cookie.Revsci";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@revsci[1].txt;"Found Tracking cookie.Revsci";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@serving-sys[2].txt:\serving-sys.com.c9034af6;"Found Tracking cookie.Serving-sys";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@serving-sys[2].txt:\serving-sys.com.606c3d3b;"Found Tracking cookie.Serving-sys";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@serving-sys[2].txt:\serving-sys.com.4b416ef8;"Found Tracking cookie.Serving-sys";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@serving-sys[2].txt:\serving-sys.com.255d6f2f;"Found Tracking cookie.Serving-sys";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@serving-sys[2].txt:\serving-sys.com.6a1cf9e8;"Found Tracking cookie.Serving-sys";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@serving-sys[2].txt:\serving-sys.com.400f83f;"Found Tracking cookie.Serving-sys";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@serving-sys[2].txt;"Found Tracking cookie.Serving-sys";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@tradedoubler[1].txt:\tradedoubler.com.eab0972e;"Found Tracking cookie.Tradedoubler";"Potentially dangerous object"
C:\Documents and Settings\Maria\Cookies\maria@tradedoubler[1].txt;"Found Tracking cookie.Tradedoubler";"Potentially dangerous object"
2008-04-18 19:09 . 2008-04-18 19:09 <DIR> d-------- C:\Program Files\Comodo
2008-04-18 19:09 . 2005-11-03 09:06 211 --a------ C:\boot.ini.comodofirewall
2008-04-18 11:54 . 2008-04-18 11:54 75,272 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-04-18 11:54 . 2008-04-18 11:54 12,424 --a------ C:\WINDOWS\system32\drivers\avgrkx86.sys
2008-04-18 11:54 . 2008-04-18 11:54 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-04-18 11:53 . 2008-04-18 11:59 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-04-18 11:53 . 2008-04-18 11:53 <DIR> d-------- C:\Documents and Settings\Maria\Application Data\AVGTOOLBAR
2008-04-18 11:53 . 2008-04-18 11:53 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-04-18 11:52 . 2008-04-18 11:52 <DIR> d-------- C:\Program Files\AVG
2008-04-18 11:52 . 2008-04-18 11:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-04-17 19:49 . 2008-04-18 18:54 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-04-17 19:49 . 2008-04-17 19:49 1,409 --a------ C:\WINDOWS\QTFont.for
2008-04-16 20:30 . 2008-04-16 20:31 <DIR> d-------- C:\WINDOWS\ERUNT
2008-04-16 20:20 . 2008-04-15 11:39 <DIR> d-------- C:\SDFix
2008-04-15 23:56 . 2008-04-15 23:56 <DIR> d-------- C:\Documents and Settings\Maria\DoctorWeb
2008-04-15 21:54 . 2008-04-15 21:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-04-15 21:53 . 2008-04-15 21:53 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-04-15 21:53 . 2008-04-15 21:53 <DIR> d-------- C:\Documents and Settings\Maria\Application Data\SUPERAntiSpyware.com
2008-04-15 21:52 . 2008-04-15 21:52 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-15 00:13 . 2008-04-15 00:13 5,132 --a------ C:\WINDOWS\system32\tmp.reg
2008-04-15 00:12 . 2008-04-15 00:09 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-04-15 00:12 . 2008-04-15 00:09 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-04-15 00:12 . 2008-04-15 00:09 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-04-15 00:12 . 2008-04-15 00:09 82,432 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-04-15 00:12 . 2008-04-15 00:09 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-04-15 00:12 . 2008-04-15 00:09 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-04-15 00:12 . 2008-04-15 00:09 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-04-15 00:02 . 2008-04-18 11:56 <DIR> d-------- C:\Documents and Settings\Administrator
2008-04-14 20:36 . 2008-04-14 20:36 <DIR> d-------- C:\Program Files\Trend Micro
2008-04-14 20:32 . 2008-04-14 20:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WinZipSE
2008-04-14 20:31 . 2008-04-14 20:31 <DIR> d-------- C:\Program Files\WinZip Self-Extractor
2008-04-14 06:44 . 2008-04-14 09:14 264 --a------ C:\WINDOWS\wininit.ini
2008-04-14 01:10 . 2008-04-14 18:41 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-14 01:10 . 2008-04-14 09:55 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-14 00:28 . 2008-04-14 00:28 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-04-13 23:07 . 2008-04-13 23:07 <DIR> d-------- C:\Documents and Settings\John\Application Data\TmpRecentIcons
2008-04-13 21:01 . 2008-04-13 21:04 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2008-04-13 17:00 . 2008-04-13 17:00 <DIR> d--h----- C:\WINDOWS\PIF
2008-04-13 11:37 . 2008-04-14 21:38 <DIR> d-------- C:\Documents and Settings\Maria\Application Data\TmpRecentIcons
2008-04-13 10:32 . 2008-04-15 23:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\yhmpszip
2008-03-25 22:26 . 2008-03-25 22:26 1,747 --ah----- C:\hpothb07.tif
2008-03-25 22:26 . 2008-03-25 22:26 932 --ah----- C:\hpothb07.dat
2008-03-25 22:25 . 2008-03-25 22:25 175 --ah----- C:\Documents and Settings\Maria\hpothb07.dat
2008-03-25 22:25 . 2008-03-25 22:25 0 --ah----- C:\Documents and Settings\Guest\hpothb07.dat
2008-03-25 22:24 . 2008-03-25 22:34 722 --ah----- C:\Documents and Settings\All Users\hpothb07.dat
2008-03-25 16:46 . 2008-03-25 16:47 <DIR> d-------- C:\Program Files\iTunes
2008-03-25 16:27 . 2008-03-25 16:29 <DIR> d-------- C:\Program Files\QuickTime
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-18 17:14 --------- d-----w C:\Program Files\McAfee.com
2008-04-18 11:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee.com
2008-04-15 23:19 --------- d-----w C:\Program Files\Common Files\Scanner
2008-04-13 20:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
2008-04-13 20:20 --------- d-----w C:\Program Files\Yahoo!
2008-04-13 17:22 --------- d-----w C:\Program Files\DivX
2008-04-09 14:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-03-25 15:47 --------- d-----w C:\Program Files\iPod
2008-03-08 23:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\TomTom
2008-03-08 23:00 --------- d-----w C:\Program Files\TomTom HOME 2
2008-03-08 22:50 --------- d-----w C:\Program Files\Java
2008-03-08 22:09 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-08 21:34 --------- d-----w C:\Documents and Settings\John\Application Data\InstallShield
2008-03-08 21:29 --------- d-----w C:\Program Files\TomTom DesktopSuite
2008-03-08 21:28 --------- d-----w C:\Documents and Settings\Maria\Application Data\TomTom
2006-02-20 21:35 863 ----a-w C:\Program Files\INSTALL.LOG
.
((((((((((((((((((((((((((((( snapshot@2008-04-15_21.36.38.03 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-15 20:15:25 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-04-18 18:24:45 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2006-07-11 08:41:36 345,656 ----a-w C:\WINDOWS\Downloaded Program Files\ewidoOnlineScan.dll
+ 2008-04-15 10:38:48 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-04-16 19:31:24 5,730,304 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\
00000001\NTUSER.DAT
+ 2008-04-16 19:31:25 155,648 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\
00000002\UsrClass.dat
+ 2008-04-15 10:38:48 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-04-16 19:31:04 5,730,304 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\
00000001\NTUSER.DAT
+ 2008-04-16 19:31:04 155,648 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\
00000002\UsrClass.dat
+ 2008-04-15 20:53:56 18,944 ----a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
+ 2008-04-15 20:53:57 65,024 ----a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
+ 2008-04-18 10:53:54 26,184 ----a-w C:\WINDOWS\system32\drivers\avgmfx86.sys
+ 2008-04-18 18:09:09 75,520 ----a-w C:\WINDOWS\system32\drivers\cmdmon.sys
+ 2008-04-18 18:09:09 51,328 ----a-w C:\WINDOWS\system32\drivers\inspect.sys
+ 2006-12-01 21:56:00 96,256 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_cbb27474\ATL80.dll
+ 2006-12-01 23:25:52 1,101,824 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80.dll
+ 2006-12-01 23:25:56 1,093,120 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80u.dll
+ 2006-12-01 23:25:58 69,632 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80.dll
+ 2006-12-01 23:26:00 57,856 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80u.dll
+ 2006-12-01 23:08:00 40,960 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHS.dll
+ 2006-12-01 23:08:00 45,056 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHT.dll
+ 2006-12-01 23:08:00 65,536 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80DEU.dll
+ 2006-12-01 23:08:00 57,344 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ENU.dll
+ 2006-12-01 23:08:00 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ESP.dll
+ 2006-12-01 23:08:00 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80FRA.dll
+ 2006-12-01 23:08:00 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ITA.dll
+ 2006-12-01 23:08:00 49,152 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80JPN.dll
+ 2006-12-01 23:08:00 49,152 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80KOR.dll
+ 2006-12-01 23:46:44 65,536 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6c18549a\vcomp.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
2008-04-18 11:53 2051328 --a------ C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= "C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL" [2008-04-18 11:53 2051328]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 08:56 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="NvQTwk" []
"WCOLOREAL"="C:\Program Files\COMPAQ\Coloreal\coloreal.exe" [2002-01-22 16:46 131072]
"CPQEASYACC"="C:\Program Files\Compaq\Easy Access Button Support\StartEAK.exe" [2001-12-14 14:01 32768]
"srmclean"="C:\Cpqs\Scom\srmclean.exe" [ ]
"Smapp"="C:\Program Files\Analog Devices\SoundMAX\Smtray.exe" [2001-10-12 15:45 69632]
"AutoLogon"="" []
"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-11 04:19 69632]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2005-10-01 09:24 26112]
"HostManager"="C:\Program Files\Common Files\AOL\1131841800\ee\AOLSoftware.exe" [2006-11-17 14:21 50736]
"Camera Detector"="C:\PROGRA~1\ACDSYS~1\DEVDET~1\DEVDET~1.exe" [2002-12-09 15:35 208896]
"AOLDialer"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [2007-12-07 16:30 71008]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 23:46 57344]
"AOLAspSunset2"="C:\Documents and Settings\All Users\Application Data\AOL\UserProfiles\All Users\antiSpyware\dat\updates\aspapp\sunsetAsp2.exe" [ ]
"PCSuiteTrayApplication"="C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2007-03-23 14:20 227328]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-01 00:13 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 14:10 267048]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-04-18 11:53 1177368]
"COMODO Firewall Pro"="C:\Program Files\Comodo\Firewall\CPF.exe" [2008-04-18 19:09 1115728]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 08:56 15360]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 16:58 1744896]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
AOL 9.0 Tray Icon.lnk - C:\Program Files\AOL 9.0\aoltray.exe [2006-06-13 22:22:30 156784]
hp psc 2000 Series.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe [2002-06-27 01:20:58 323646]
Microsoft Works Calendar Reminders.lnk - C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [1999-09-05 00:23:00 53317]
officejet 6100.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe [2002-06-27 01:21:30 147456]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli scecli
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\AOL 9.0\\waol.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Common Files\\AOL\\1131841800\\ee\\aolsoftware.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
R0 AvgRkx86;avgrkx86.sys;C:\WINDOWS\system32\Drivers\avgrkx86.sys [2008-04-18 11:54]
S1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-04-18 11:53]
S1 EACMOS;EACMOS;C:\WINDOWS\system32\drivers\EACMOS.SYS []
S1 sdcplh;sdcplh;C:\WINDOWS\system32\drivers\sdcplh.sys [2006-01-06 17:53]
S2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-04-18 11:53]
S2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-04-18 11:53]
S2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-04-18 11:54]
S3 52f0f2d3-1f4d-4c4c-b2c3-b42d5e1e9837;52f0f2d3-1f4d-4c4c-b2c3-b42d5e1e9837;E:\Player\cds300.dll []
S3 PPPoEWin;PPPoEWin Miniport;C:\WINDOWS\system32\DRIVERS\PPPoEWin.SYS []
S3 w550bus;Sony Ericsson W550 driver (WDM);C:\WINDOWS\system32\DRIVERS\w550bus.sys [2005-08-01 14:46]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c8022d17-c08c-11dc-8a4a-00038a000015}]
\Shell\AutoRun\command - G:\InstallTomTomHOME.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-04-15 11:37:06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2006-03-09 22:34:54 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 2100 series#1128025151.job"
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-04-18 19:25:39
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-04-18 19:36:53 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-18 18:36:47
ComboFix2.txt 2008-04-17 17:12:15
ComboFix3.txt 2008-04-15 20:39:11
Pre-Run: 41,779,068,928 bytes free
Post-Run: 41,763,651,584 bytes free
.
2008-04-09 14:23:30 --- E O F ---