Ok, here is the copy and pasted version of my second (most recent) log for combofix. Internet explorer still freezes whenever I try and copy and paste my first log - I am guessing because that one is too large. It is still attached in my post before this one.
ComboFix 10-01-27.06 - Ralph 01/28/2010 15:48:16.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.767.321 [GMT -5:00]
Running from: c:\documents and settings\Ralph\Desktop\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Ralph\Application Data\ibunuqul.inf
c:\documents and settings\Ralph\Start Menu\Programs\AVI Codec Pack +
c:\documents and settings\Ralph\Start Menu\Programs\AVI Codec Pack +\Check For Updates.lnk
c:\documents and settings\Ralph\Start Menu\Programs\AVI Codec Pack +\Uninstall.lnk
c:\program files\AVI Codec Pack
c:\program files\AVI Codec Pack\AC3\ac3filter.ax
c:\program files\AVI Codec Pack\AC3\dialog_patch.exe
c:\program files\AVI Codec Pack\DivX 3.11\DivX.inf
c:\program files\AVI Codec Pack\DivX 3.11\DIVX_c32.ax
c:\program files\AVI Codec Pack\DivX 3.11\DivXa32.acm
c:\program files\AVI Codec Pack\DivX 3.11\DivXc32.dll
c:\program files\AVI Codec Pack\DivX 3.11\DivXc32f.dll
c:\program files\AVI Codec Pack\DivX 3.11\L3codeca.acm
c:\program files\AVI Codec Pack\divx.chm
c:\program files\AVI Codec Pack\ffdhow\ffdshow.ax
c:\program files\AVI Codec Pack\ffdhow\ffdshow.ax.manifest
c:\program files\AVI Codec Pack\ffdhow\libavcodec.dll
c:\program files\AVI Codec Pack\ffdhow\libmpeg2_ff.dll
c:\program files\AVI Codec Pack\ffdhow\libmplayer.dll
c:\program files\AVI Codec Pack\ffdhow\TomsMoComp_ff.dll
c:\program files\AVI Codec Pack\LAYER-3\L3CODECP.ACM
c:\program files\AVI Codec Pack\LAYER-3\RaMp3Cfg.exe
c:\program files\AVI Codec Pack\uninstall.exe
C:\s
c:\windows\cycoku.scr
c:\windows\system32\_003819_.tmp.dll
c:\windows\system32\_003820_.tmp.dll
c:\windows\system32\_003821_.tmp.dll
c:\windows\system32\_003822_.tmp.dll
c:\windows\system32\_003829_.tmp.dll
c:\windows\system32\_003830_.tmp.dll
c:\windows\system32\_003831_.tmp.dll
c:\windows\system32\_003833_.tmp.dll
c:\windows\system32\_003834_.tmp.dll
c:\windows\system32\_003837_.tmp.dll
c:\windows\system32\_003838_.tmp.dll
c:\windows\system32\_003840_.tmp.dll
c:\windows\system32\_003841_.tmp.dll
c:\windows\system32\_003842_.tmp.dll
c:\windows\system32\_003844_.tmp.dll
c:\windows\system32\_003847_.tmp.dll
c:\windows\system32\_003848_.tmp.dll
c:\windows\system32\_003852_.tmp.dll
c:\windows\system32\_003853_.tmp.dll
c:\windows\system32\_003855_.tmp.dll
c:\windows\system32\_003858_.tmp.dll
c:\windows\system32\_003860_.tmp.dll
c:\windows\system32\_003861_.tmp.dll
c:\windows\system32\_003862_.tmp.dll
c:\windows\system32\_003863_.tmp.dll
c:\windows\system32\_003866_.tmp.dll
c:\windows\system32\_003867_.tmp.dll
c:\windows\system32\_003868_.tmp.dll
c:\windows\system32\_003869_.tmp.dll
c:\windows\system32\_003870_.tmp.dll
c:\windows\system32\_003875_.tmp.dll
c:\windows\system32\_003877_.tmp.dll
c:\windows\system32\camenot.vbs
c:\windows\ygunoqe._sy
.
((((((((((((((((((((((((( Files Created from 2009-12-28 to 2010-01-28 )))))))))))))))))))))))))))))))
.
2010-01-28 01:09 . 2010-01-19 11:42 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-01-28 01:09 . 2010-01-19 13:13 162640 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-01-28 01:09 . 2010-01-19 11:43 23248 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-01-28 01:09 . 2010-01-19 11:46 46544 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-01-28 01:09 . 2010-01-19 11:43 100304 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-01-28 01:09 . 2010-01-19 11:43 94672 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-01-28 01:09 . 2010-01-19 11:42 28240 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-01-28 01:09 . 2010-01-19 11:57 38848 ----a-w- c:\windows\system32\avastSS.scr
2010-01-28 01:09 . 2010-01-19 11:57 152672 ----a-w- c:\windows\system32\aswBoot.exe
2010-01-28 01:09 . 2010-01-28 01:09 -------- d-----w- c:\program files\Alwil Software
2010-01-28 01:09 . 2010-01-28 01:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-01-27 20:18 . 2010-01-27 20:18 -------- d-----w- c:\program files\Common Files\Java
2010-01-27 18:33 . 2010-01-27 18:33 578560 ----a-w- c:\windows\system32\dllcache\user32.dll
2010-01-27 18:29 . 2010-01-27 18:29 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2010-01-17 22:57 . 2009-11-21 15:51 471552 ------w- c:\windows\system32\dllcache\aclayers.dll
2010-01-17 21:05 . 2010-01-17 21:05 -------- d-----w- c:\program files\Windows Resource Kits
2010-01-17 20:28 . 2009-02-09 12:10 617472 ----a-w- c:\windows\system32\advapi32.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-28 20:57 . 2004-11-19 19:35 -------- d-----w- c:\documents and settings\All Users\Application Data\DIGStream
2010-01-28 20:41 . 2010-01-26 22:39 52224 ----a-w- c:\documents and settings\Ralph\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-01-28 20:41 . 2009-03-28 21:36 117760 ----a-w- c:\documents and settings\Ralph\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-01-28 20:40 . 2008-05-11 16:23 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-01-28 14:31 . 2009-09-19 02:29 -------- d-----w- c:\program files\SpywareBlaster
2010-01-27 20:18 . 2010-01-27 20:18 61440 ----a-w- c:\documents and settings\Ralph\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-48cdcd29-n\decora-sse.dll
2010-01-27 20:18 . 2010-01-27 20:18 503808 ----a-w- c:\documents and settings\Ralph\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-40458530-n\msvcp71.dll
2010-01-27 20:18 . 2010-01-27 20:18 499712 ----a-w- c:\documents and settings\Ralph\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-40458530-n\jmc.dll
2010-01-27 20:18 . 2010-01-27 20:18 348160 ----a-w- c:\documents and settings\Ralph\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-40458530-n\msvcr71.dll
2010-01-27 20:18 . 2010-01-27 20:18 12800 ----a-w- c:\documents and settings\Ralph\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-48cdcd29-n\decora-d3d.dll
2010-01-27 20:17 . 2008-12-27 04:50 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-01-17 23:17 . 2009-09-30 13:37 3695616 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\AutoLaunch.exe
2010-01-17 23:17 . 2009-09-30 13:37 2353992 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\update\Ad-Aware.exe
2010-01-17 23:13 . 2008-12-26 23:40 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-17 23:12 . 2010-01-17 23:12 5115824 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-17 21:24 . 2003-04-19 00:40 143712 ----a-w- c:\documents and settings\Ralph\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-08 23:16 . 2003-04-14 22:52 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-07 21:07 . 2009-09-19 02:33 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 21:07 . 2009-09-19 02:33 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-04 22:19 . 2006-06-05 01:50 4700 ----a-w- c:\documents and settings\Ralph\Application Data\ViewerApp.dat
2009-12-23 04:49 . 2009-06-10 16:15 256 ----a-w- c:\windows\system32\pool.bin
2009-12-23 04:34 . 2009-12-23 04:34 -------- d-----w- c:\documents and settings\Ralph\Application Data\Blackberry Desktop
2009-12-03 19:45 . 2007-11-28 01:25 -------- d-----w- c:\documents and settings\Ralph\Application Data\LimeWire
2009-12-03 19:37 . 2008-09-24 00:14 -------- d-----w- c:\program files\Incomplete
2009-12-03 19:37 . 2007-11-28 01:17 -------- d-----w- c:\program files\LimeWire
2009-12-02 23:26 . 2007-11-28 01:18 -------- d-----w- c:\program files\Java
2009-11-03 01:42 . 2009-12-02 16:51 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-10-14 00:28 . 2009-10-14 00:28 187150 ----a-w- c:\program files\log.txt
2004-07-25 01:46 . 2004-05-17 19:15 0 --sh--r- c:\program files\q330994.exe
2004-05-24 04:32 . 2004-05-23 15:50 0 --sh--r- c:\program files\power scan
2004-07-25 01:46 . 2004-05-17 19:15 0 --sha-r- c:\windows\nem216.dll
2004-07-25 01:46 . 2004-05-28 11:36 0 --sha-r- c:\windows\SYSTEM\wmscrop.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"NvMediaCenter"="c:\windows\System32\NVMCTRAY.DLL" [2003-10-06 49152]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-10-06 5058560]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 122880]
"DVDSentry"="c:\windows\System32\DSentry.exe" [2002-08-14 28672]
"MoneyStartUp10.0"="c:\program files\Microsoft Money\System\Activation.exe" [2001-07-25 241714]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2003-04-14 26112]
"AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-12-17 684032]
"MPTBox"="c:\progra~1\Canon\MULTIP~1\MPTBox.exe" [2002-11-09 172032]
"Omnipage"="c:\program files\ScanSoft\OmniPageSE\opware32.exe" [2002-02-21 49152]
"nwiz"="nwiz.exe" [2003-10-06 741376]
"DIGStream"="c:\program files\DIGStream\digstream.exe" [2005-05-18 282624]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 57344]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-09-11 218032]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-09-11 86960]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2008-03-06 236016]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-01-19 2743104]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Picture Package Menu.lnk - c:\program files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe [2006-6-4 151552]
Picture Package VCD Maker.lnk - c:\program files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe [2006-6-4 106496]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0stera\0lsdelete
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Kinko's\\FPFK\\FPKMain.exe"=
"c:\\Program Files\\Kinko's\\FPFK\\Kinkos.Jupiter.GUI.Queue.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 Lbd;Lbd;c:\windows\SYSTEM32\DRIVERS\Lbd.sys [9/30/2009 8:37 AM 64160]
R1 aswSP;aswSP;c:\windows\SYSTEM32\DRIVERS\aswSP.sys [1/27/2010 8:09 PM 162640]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [12/4/2008 1:50 PM 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12/4/2008 1:50 PM 55024]
R2 aswFsBlk;aswFsBlk;c:\windows\SYSTEM32\DRIVERS\aswFsBlk.sys [1/27/2010 8:09 PM 19024]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/10/2007 1:01 PM 24652]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 6:19 PM 13592]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/3/2009 9:49 AM 1028432]
S3 MTK;Media Technology Kernel Driver;c:\windows\system32\Drivers\mtk.sys --> c:\windows\system32\Drivers\mtk.sys [?]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [12/4/2008 1:50 PM 7408]
.
Contents of the 'Scheduled Tasks' folder
2010-01-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 22:57]
2010-01-28 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]
.
.
------- Supplementary Scan -------
.
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {69432678-2906-2705-1128-068943397621}
DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} - hxxp://us-housecall.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
.
- - - - ORPHANS REMOVED - - - -
AddRemove-AVI Codec Pack - c:\program files\AVI Codec Pack\uninstall.exe
AddRemove-HijackThis - c:\program files\Trend Micro\HijackThis\HijackThis.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-01-28 15:56
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(3728)
c:\windows\system32\WININET.dll
c:\program files\ScanSoft\OmniPageSE\ophook32.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Canon\MultiPASS4\MPSERVIC.EXE
c:\windows\System32\nvsvc32.exe
c:\windows\BCMSMMSG.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\Canon\CAL\CALMAIN.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
c:\program files\Viewpoint\Viewpoint Manager\ViewMgr.exe
.
**************************************************************************
.
Completion time: 2010-01-28 16:05:00 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-28 21:04
ComboFix2.txt 2010-01-27 18:23
ComboFix3.txt 2009-10-14 00:26
ComboFix4.txt 2008-12-27 05:32
Pre-Run: 6,692,040,704 bytes free
Post-Run: 6,607,384,576 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
- - End Of File - - 04B28143226CD4BC3F9B780E7780095A