Ran everything in order and had no problems except while running combofix, while it was creating the backup registry it ran out of VM twice and in both cases the system took over and combo fix was able to continue and finally finished.
Thank you much for the help.
ComboFix 10-09-27.05 - Owner 09/28/2010 20:12:59.1.1 - x86
Running from: C:\Documents and Settings\Owner\My Documents\Downloads\commy.exe.exe
.
((((((((((((((((((((((((( Files Created from 2010-08-28 to 2010-09-29 )))))))))))))))))))))))))))))))
.
2010-09-28 21:33:19 . 2010-09-28 21:30:24 53632 ----a-w- C:\Documents and Settings\Default User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-09-28 21:32:14 . 2010-09-28 21:32:14 -------- d-----w- C:\Program Files\Common Files\Adobe AIR
2010-09-28 21:29:47 . 2010-09-28 21:29:48 -------- d-----w- C:\Documents and Settings\All Users\Application Data\McAfee
2010-09-28 21:29:42 . 2010-09-28 21:29:46 -------- d-----w- C:\Documents and Settings\All Users\Application Data\McAfee Security Scan
2010-09-28 21:26:59 . 2010-09-28 21:27:00 -------- d-----w- C:\Program Files\McAfee Security Scan
2010-09-28 21:26:59 . 2010-09-28 21:26:59 -------- d-----w- C:\Documents and Settings\Owner\Local Settings\Application Data\Adobe
2010-09-28 21:26:58 . 2010-09-28 21:26:58 -------- d-----w- C:\Documents and Settings\Owner\Local Settings\Application Data\NOS
2010-09-28 21:22:40 . 2010-09-28 21:22:40 -------- d-sh--w- C:\Documents and Settings\Owner\IECompatCache
2010-09-28 21:11:38 . 2010-09-28 21:11:38 -------- d-----w- C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla
2010-09-27 21:39:57 . 2010-09-27 21:39:58 388096 ----a-r- C:\Documents and Settings\Owner\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-09-27 21:39:55 . 2010-09-27 22:42:32 -------- d-----w- C:\Program Files\Trend Micro
2010-09-27 16:09:33 . 2010-09-27 16:09:33 4093792 ----a-w- C:\Documents and Settings\All Users\Application Data\avg9\update\backup\avgui.exe
2010-09-27 16:09:32 . 2010-09-27 16:09:32 3586912 ----a-w- C:\Documents and Settings\All Users\Application Data\avg9\update\backup\setup.exe
2010-09-27 16:09:28 . 2010-09-27 16:09:28 598368 ----a-w- C:\Documents and Settings\All Users\Application Data\avg9\update\backup\avgsrmx.dll
2010-09-27 16:09:27 . 2010-09-27 16:09:27 942432 ----a-w- C:\Documents and Settings\All Users\Application Data\avg9\update\backup\avgcfgx.dll
2010-09-27 16:09:27 . 2010-09-27 16:09:27 4371296 ----a-w- C:\Documents and Settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2010-09-27 16:09:25 . 2010-09-27 16:09:25 300896 ----a-w- C:\Documents and Settings\All Users\Application Data\avg9\update\backup\avgchclx.dll
2010-09-27 16:02:31 . 2010-09-27 16:02:31 1690952 ----a-w- C:\Documents and Settings\All Users\Application Data\avg9\update\backup\avgupd.dll
2010-09-27 15:43:39 . 2010-09-27 15:43:40 12536 ----a-w- C:\WINDOWS\system32\avgrsstx.dll
2010-09-27 15:42:55 . 2010-09-27 15:42:55 216400 ----a-w- C:\WINDOWS\system32\drivers\avgldx86.sys
2010-09-27 15:42:51 . 2010-09-27 15:42:51 29584 ----a-w- C:\WINDOWS\system32\drivers\avgmfx86.sys
2010-09-27 15:42:27 . 2010-09-28 22:25:36 -------- d-----w- C:\WINDOWS\system32\drivers\Avg
2010-09-27 15:42:01 . 2010-09-27 15:42:01 -------- d-----w- C:\Program Files\AVG
2010-09-27 15:41:57 . 2010-09-27 15:42:01 -------- d-----w- C:\Documents and Settings\All Users\Application Data\avg9
2010-09-27 13:46:10 . 2010-09-27 19:40:56 63488 ----a-w- C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-09-27 13:44:36 . 2010-09-27 13:44:36 52224 ----a-w- C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-09-27 13:44:08 . 2010-09-27 19:40:01 117760 ----a-w- C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-09-27 13:42:56 . 2010-09-27 13:42:56 -------- d-----w- C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
2010-09-27 13:42:32 . 2010-09-27 13:43:02 -------- d-----w- C:\Program Files\SUPERAntiSpyware
2010-09-27 13:08:42 . 2010-09-27 13:08:42 -------- d-----w- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2010-09-27 00:40:00 . 2010-09-27 00:40:04 -------- d-----w- C:\Program Files\File Scanner Library (Spybot - Search & Destroy)
2010-09-27 00:39:59 . 2010-09-27 00:40:05 -------- d-----w- C:\Program Files\TeaTimer (Spybot - Search & Destroy)
2010-09-27 00:39:59 . 2010-09-27 00:40:05 -------- d-----w- C:\Program Files\SDHelper (Spybot - Search & Destroy)
2010-09-27 00:39:59 . 2010-09-27 00:40:03 -------- d-----w- C:\Program Files\Misc. Support Library (Spybot - Search & Destroy)
2010-09-27 00:04:09 . 2009-11-21 15:51:04 471552 -c----w- C:\WINDOWS\system32\dllcache\aclayers.dll
2010-09-27 00:03:23 . 2010-06-14 14:31:20 744448 -c----w- C:\WINDOWS\system32\dllcache\helpsvc.exe
2010-09-27 00:00:35 . 2010-06-24 12:21:56 743424 -c----w- C:\WINDOWS\system32\dllcache\iedvtool.dll
2010-09-26 23:56:24 . 2010-06-18 13:36:12 3558912 -c----w- C:\WINDOWS\system32\dllcache\moviemk.exe
2010-09-26 21:02:18 . 2008-04-13 18:45:38 26368 -c--a-w- C:\WINDOWS\system32\dllcache\usbstor.sys
2010-09-26 00:23:40 . 2008-04-13 18:39:48 14592 -c--a-w- C:\WINDOWS\system32\dllcache\kbdhid.sys
2010-09-26 00:23:40 . 2008-04-13 18:39:48 14592 ----a-w- C:\WINDOWS\system32\drivers\kbdhid.sys
2010-09-26 00:23:04 . 2008-04-13 18:45:28 10368 -c--a-w- C:\WINDOWS\system32\dllcache\hidusb.sys
2010-09-26 00:23:04 . 2008-04-13 18:45:28 10368 ----a-w- C:\WINDOWS\system32\drivers\hidusb.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-28 23:30:18 . 2006-03-20 03:55:56 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Viewpoint
2010-09-27 13:38:58 . 2006-01-07 03:40:06 -------- d-----w- C:\Documents and Settings\Owner\Application Data\Lavasoft
2010-09-27 12:57:09 . 2006-03-18 21:27:37 -------- d-----w- C:\Program Files\ewido anti-malware
2010-09-27 12:57:09 . 2006-01-07 03:50:07 -------- d-----w- C:\Program Files\Spybot - Search & Destroy
2010-09-27 12:51:34 . 2006-01-07 03:50:10 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2010-09-27 01:17:52 . 2006-01-06 03:04:04 -------- d-----w- C:\Program Files\Common Files\Real
2010-09-27 01:17:14 . 2006-01-06 02:37:45 -------- d-----w- C:\Program Files\Gateway
2010-09-27 01:17:12 . 2006-01-06 02:59:12 -------- d-----w- C:\Program Files\pc-doctor for windows
2010-09-27 00:34:38 . 2009-06-20 08:41:11 -------- d-----w- C:\Program Files\CCleaner
2010-08-17 13:17:06 . 2005-06-10 23:55:46 58880 ----a-w- C:\WINDOWS\system32\spoolsv.exe
2010-07-22 15:49:15 . 2004-03-06 02:16:11 590848 ----a-w- C:\WINDOWS\system32\rpcrt4.dll
2010-07-22 05:57:20 . 2009-06-20 10:09:43 5120 ----a-w- C:\WINDOWS\system32\xpsp4res.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 17:13:36 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG9_TRAY]
2010-09-27 15:42:14 2065760 ----a-w- C:\PROGRA~1\AVG\AVG9\avgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2006-01-06 02:37:59 114688 ----a-w- C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2006-01-06 02:38:02 155648 ----a-w- C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2010-09-10 16:20:20 2424560 ----a-w- C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
R3 McComponentHostService;McAfee Security Scan Component Host Service;C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 12:49:20 227232]
R3 PCDRDRV;Pcdr Helper Driver;C:\PROGRA~1\PC-DOC~1\DIAGNO~1\PCDRDRV.sys
S1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2010-09-27 15:42:55 216400]
S1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 18:25:48 12872]
S1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 18:41:30 67656]
S2 avg9wd;AVG Free WatchDog;C:\Program Files\AVG\AVG9\avgwdsvc.exe [2010-09-27 15:42:07 308136]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride = <local>
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
DPF: DirectAnimation Java Classes - file://C:\WINDOWS\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://C:\WINDOWS\Java\classes\xmldso.cab
FF - ProfilePath - C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\n08om8ce.default\
FF - prefs.js: browser.startup.homepage -
www.yahoo.com---- FIREFOX POLICIES ----
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-AVG7_CC - C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
MSConfigStartUp-GWMDMMSG - GWMDMMSG.exe
MSConfigStartUp-RealTray - C:\Program Files\Real\RealPlayer\RealPlay.exe