Here is the log that Combofix produced:
ComboFix 10-10-21.05 - Ryan 22/10/2010 23:58:51.3.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.64.1033.18.1982.1121 [GMT 13:00]
Running from: c:\users\Ryan\Desktop\commy.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Free *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programdata.\documents\settings
c:\programdata\.wtav
c:\users\Ryan\AppData\Roaming\avdrn.dat
c:\users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnVi
c:\users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnVi\About.lnk
c:\users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnVi\Activate.lnk
c:\users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnVi\Antivirus Support.lnk
c:\users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnVi\Antivirus.lnk
c:\users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnVi\Buy.lnk
c:\users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnVi\Scan.lnk
c:\users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnVi\Settings.lnk
c:\users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnVi\Update.lnk
c:\users\Ryan\oashdihasidhasuidhiasdhiashdiuasdhasd
c:\windows\PRAGMAyrtxnwrcjt
c:\windows\PRAGMAyrtxnwrcjt\PRAGMAc.dll
c:\windows\PRAGMAyrtxnwrcjt\PRAGMAcfg.ini
c:\windows\PRAGMAyrtxnwrcjt\PRAGMAsrcr.dat
Infected copy of c:\windows\system32\drivers\AGP440.sys was found and disinfected
Restored copy from - c:\windows\system32\drivers\agp440.sys.bak
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_userinit
((((((((((((((((((((((((( Files Created from 2010-09-22 to 2010-10-22 )))))))))))))))))))))))))))))))
.
2010-10-22 11:20 . 2010-10-22 11:27 -------- d-----w- c:\users\Ryan\AppData\Local\temp
2010-10-22 11:20 . 2010-10-22 11:20 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-10-22 11:20 . 2010-10-22 11:20 -------- d-----w- c:\users\Guest\AppData\Local\temp
2010-10-22 11:20 . 2010-10-22 11:20 -------- d-----w- c:\users\Guest(56)\AppData\Local\temp
2010-10-22 11:20 . 2010-10-22 11:20 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-10-22 08:08 . 2010-10-07 23:21 6146896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A15205D0-8851-4AAD-B675-A6BFC9825264}\mpengine.dll
2010-10-18 02:01 . 2010-04-29 02:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-18 02:01 . 2010-04-29 02:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-17 08:31 . 2010-10-17 08:41 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2010-10-17 08:31 . 2010-10-17 08:41 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-10-17 08:30 . 2010-10-17 08:41 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-10-17 08:30 . 2010-10-17 08:43 -------- d-----w- c:\windows\system32\drivers\Avg
2010-10-15 09:47 . 2010-09-13 13:56 168960 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2010-10-15 09:47 . 2010-09-13 13:56 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2010-10-15 09:47 . 2010-09-06 16:20 125952 ----a-w- c:\windows\system32\srvsvc.dll
2010-10-15 09:47 . 2010-09-06 13:45 304128 ----a-w- c:\windows\system32\drivers\srv.sys
2010-10-15 09:47 . 2010-09-06 13:45 145408 ----a-w- c:\windows\system32\drivers\srv2.sys
2010-10-15 09:47 . 2010-09-06 13:45 102400 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-10-15 09:47 . 2010-09-06 16:19 17920 ----a-w- c:\windows\system32\netevent.dll
2010-10-14 10:29 . 2010-10-14 10:29 -------- d-----w- c:\program files\Trend Micro
2010-10-10 02:38 . 2010-10-10 02:38 -------- d-----w- c:\program files\Giant Crocodile
2010-10-08 08:58 . 2010-10-08 08:58 -------- dc----w- C:\$AVG
2010-10-08 06:08 . 2010-10-08 06:08 -------- dc----w- C:\AVG10
2010-10-08 06:06 . 2010-10-08 06:06 -------- d--h--w- c:\programdata\Common Files
2010-10-08 06:03 . 2010-10-14 08:43 -------- d-----w- c:\programdata\AVG10
2010-10-08 05:51 . 2010-10-08 06:01 -------- d-----w- c:\programdata\MFAData
2010-10-08 05:39 . 2010-10-18 19:05 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-30 08:28 . 2010-09-30 08:28 -------- d-----w- c:\windows\Profiles
2010-09-29 07:54 . 2010-06-22 13:30 2048 ----a-w- c:\windows\system32\tzres.dll
2010-09-28 11:31 . 2010-09-28 11:31 -------- d-----w- c:\program files\iPod
2010-09-28 11:24 . 2010-09-28 11:24 -------- d-----w- c:\program files\Bonjour
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-18 22:41 . 2010-02-11 13:33 222080 ------w- c:\windows\system32\MpSigStub.exe
2010-09-13 03:27 . 2010-09-13 03:27 25680 ----a-w- c:\windows\system32\drivers\AVGIDSEH.sys
2010-09-07 22:17 . 2010-09-07 22:17 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-09-07 22:17 . 2010-09-07 22:17 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-08-17 14:11 . 2010-09-16 08:10 128000 ----a-w- c:\windows\system32\spoolsv.exe
2010-07-27 05:44 . 2010-07-27 05:44 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-07-27 05:44 . 2010-07-27 05:44 107808 ----a-w- c:\windows\system32\dns-sd.exe
2009-01-27 01:34 . 2009-01-27 01:34 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-01-27 01:34 . 2009-01-27 01:34 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
2007-08-25 01:52 . 2008-06-05 11:59 300400 ----a-w- c:\program files\mozilla firefox\components\coFFPlgn.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2007-07-09 159744]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-10-01 181544]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-09-19 202032]
"OnScreenDisplay"="c:\program files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe" [2007-09-04 554320]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-08-17 218408]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-09-13 480560]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-08 311296]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-02-05 849280]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-03 36352]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-03-16 47392]
"VirtualCloneDrive"="c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2009-01-29 52392]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-23 13601312]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-06-23 92704]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-03-24 202256]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-17 248040]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-07 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-23 421160]
"Malwarebytes Anti-Malware (rootkit-scan)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]
c:\users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2009-08-10 133104]
R2 Nakido;Nakido;c:\program files\Nakido\nakido.exe
R3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\System32\DRIVERS\ASPI32.sys [2002-07-17 84832]
R3 cxru92a1;Virtual Bus for Microsoft ACPI-Compliant System;
R3 DFBCFDBA;DFBCFDBA;
R3 iscFlash;iscFlash;c:\swsetup\sp42533\iscflash.sys [2008-08-05 11520]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2008-04-29 717296]
S0 AVGIDSEH;AVGIDSEH;c:\windows\system32\DRIVERS\AVGIDSEH.Sys [2010-09-13 25680]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2010-10-17 335240]
S2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [2009-12-16 375296]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
2010-10-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-10 23:39]
2010-10-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-10 23:39]
2010-10-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-753018427-1233051673-1299658189-1003Core.job
- c:\users\Ryan\AppData\Local\Google\Update\GoogleUpdate.exe [2010-04-10 04:59]
2010-10-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-753018427-1233051673-1299658189-1003UA.job
- c:\users\Ryan\AppData\Local\Google\Update\GoogleUpdate.exe [2010-04-10 04:59]
2010-10-22 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-753018427-1233051673-1299658189-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 09:09]
2010-10-22 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-753018427-1233051673-1299658189-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-02-24 09:09]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_nz&c=81&bd=Presario&pf=laptop
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_nz&c=81&bd=Presario&pf=laptop
uInternet Settings,ProxyServer = proxy.student.otago.ac.nz:3128
uInternet Settings,ProxyOverride = <local>
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: {32C3FEAE-0877-4767-8C20-62A5829A0945} - hxxp://static.ak.facebook.com/fbplugin/win32/axfbootloader.cab
FF - ProfilePath - c:\users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\
FF - component: c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - component: c:\users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\5isep8bi.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\programdata\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
BHO-{9DFE2FE9-CF99-4ADF-A28E-9B5ADB8DC74F} - (no file)
HKLM-Run-hpqSRMon - (no file)
HKLM-Run-AVG8_TRAY - c:\progra~1\AVG\AVG8\avgtray.exe
AddRemove-Antivirus - c:\program files\AnVi\Pklkvqdii+`}`
AddRemove-AVG8Uninstall - c:\program files\AVG\AVG8\setup.exe
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(4816)
c:\program files\Nokia\Nokia PC Suite 6\phonebrowser.dll
c:\program files\Nokia\Nokia PC Suite 6\PCSCM.dll
c:\program files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_eng-us.nlr
c:\program files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\WLANExt.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\windows\system32\DRIVERS\xaudio.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\rundll32.exe
c:\windows\System32\rundll32.exe
c:\program files\Windows Media Player\wmpnscfg.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Apoint2K\ApMsgFwd.exe
c:\program files\Apoint2K\Apntex.exe
c:\program files\Hewlett-Packard\Shared\HpqToaster.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe
.
**************************************************************************
.
Completion time: 2010-10-23 00:35:43 - machine was rebooted
ComboFix-quarantined-files.txt 2010-10-22 11:35
Pre-Run: 6,880,415,744 bytes free
Post-Run: 7,537,274,880 bytes free
- - End Of File - - DA41FB2AD76064205DDCCAAABE2D398C