Ah, I didn't see your latest post until after I ran Combofix - but I never had it installed before so it was a "fresh" copy. It ran without problems (no need to rename) and here is the log:
ComboFix 09-09-01.04 - Owner 09/01/2009 22:47.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.766.466 [GMT -4:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\INSTALL.LOG
c:\recycler\NPROTECT
c:\recycler\S-1-5-21-515967899-861567501-682003330-1005
c:\windows\Downloaded Program Files\popcaploader.dll
c:\windows\Downloaded Program Files\popcaploader.inf
c:\windows\Downloaded Program Files\RdxIE.dll
c:\windows\Installer\156fd.msi
c:\windows\Palace.reg
c:\windows\system32\config\systemprofile\Start Menu\Programs\Windows Antivirus Pro
c:\windows\system32\config\systemprofile\Start Menu\Programs\Windows Antivirus Pro\Windows Antivirus Pro.lnk
c:\windows\system32\drivers\kbiwkmthxwbuth.sys
c:\windows\system32\images
c:\windows\system32\images\i1.gif
c:\windows\system32\images\i2.gif
c:\windows\system32\images\i3.gif
c:\windows\system32\images\j1.gif
c:\windows\system32\images\j2.gif
c:\windows\system32\images\j3.gif
c:\windows\system32\images\jj1.gif
c:\windows\system32\images\jj2.gif
c:\windows\system32\images\jj3.gif
c:\windows\system32\images\l1.gif
c:\windows\system32\images\l2.gif
c:\windows\system32\images\l3.gif
c:\windows\system32\images\pix.gif
c:\windows\system32\images\t1.gif
c:\windows\system32\images\t2.gif
c:\windows\system32\images\up1.gif
c:\windows\system32\images\up2.gif
c:\windows\system32\images\w1.gif
c:\windows\system32\images\w11.gif
c:\windows\system32\images\w2.gif
c:\windows\system32\images\w3.gif
c:\windows\system32\images\w3.jpg
c:\windows\system32\images\wt1.gif
c:\windows\system32\images\wt2.gif
c:\windows\system32\images\wt3.gif
c:\windows\system32\kbiwkmewbfalqp.dll
c:\windows\system32\kbiwkmqqmcnupk.dat
c:\windows\system32\kbiwkmsexeooby.dll
c:\windows\system32\kbiwkmtsppdrch.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_kbiwkmnrerxnmf
-------\Legacy_kbiwkmnrerxnmf
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
((((((((((((((((((((((((( Files Created from 2009-08-02 to 2009-09-02 )))))))))))))))))))))))))))))))
.
2009-09-02 03:04 . 2009-09-02 03:04 -------- d-----w- c:\windows\LastGood
2009-09-01 04:59 . 2009-09-01 05:00 -------- d-----w- c:\program files\Windows Live Safety Center
2009-09-01 04:36 . 2009-09-01 04:05 -------- d-----w- C:\KILLBAD
2009-09-01 04:17 . 2009-09-01 04:17 27656 ----a-w- c:\windows\system32\drivers\pxsec.sys
2009-09-01 04:17 . 2009-09-01 04:17 22024 ----a-w- c:\windows\system32\drivers\pxscan.sys
2009-09-01 04:17 . 2009-09-01 04:17 -------- d-----w- c:\program files\Prevx
2009-09-01 04:17 . 2009-09-01 04:18 -------- d-----w- c:\documents and settings\All Users\Application Data\PrevxCSI
2009-09-01 03:53 . 2008-06-19 21:24 28544 ----a-w- c:\windows\system32\drivers\pavboot.sys
2009-09-01 03:52 . 2009-09-01 03:52 -------- d-----w- c:\program files\Panda Security
2009-09-01 02:49 . 2009-09-01 04:54 -------- d-----w- c:\documents and settings\All Users\Application Data\SITEguard
2009-09-01 02:43 . 2009-09-01 02:43 -------- d-----w- c:\program files\STOPzilla!
2009-09-01 02:43 . 2009-09-01 20:06 -------- d-----w- c:\documents and settings\All Users\Application Data\STOPzilla!
2009-09-01 02:43 . 2009-09-01 02:43 -------- d-----w- c:\program files\Common Files\iS3
2009-08-31 18:15 . 2009-08-31 18:15 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2009-08-31 17:42 . 2009-08-31 17:42 36168 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-31 17:39 . 2009-08-31 17:39 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache
2009-08-31 17:27 . 2009-08-31 17:27 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-08-30 23:29 . 2009-08-30 23:29 -------- d-----w- c:\program files\PopCap Games
2009-08-29 19:13 . 2009-08-29 19:13 -------- d-----w- c:\program files\DinerTown Detective Agency
2009-08-29 04:24 . 2009-08-29 04:24 -------- d-----w- c:\program files\Diner Dash Flo Through Time
2009-08-29 04:24 . 2009-08-29 04:24 -------- d-----w- c:\windows\Diner Dash Flo Through Time
2009-08-28 16:44 . 2005-10-19 12:59 163840 ----a-w- c:\windows\system32\igfxres.dll
2009-08-27 19:34 . 2009-08-27 19:34 -------- dc-h--w- c:\windows\ie8
2009-08-27 03:47 . 2009-08-03 17:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-27 03:47 . 2009-09-01 20:39 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-27 03:47 . 2009-08-03 17:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-27 03:36 . 2009-08-27 03:36 -------- d-----w- c:\documents and settings\Owner\Application Data\Malwarebytes
2009-08-27 03:36 . 2009-08-27 03:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-26 02:29 . 2009-08-26 02:29 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-08-25 15:09 . 2009-08-25 15:09 -------- d-----w- c:\windows\Diner Dash Seasonal Snack Pack
2009-08-23 15:01 . 2009-08-23 15:01 -------- d-----w- c:\documents and settings\Owner\Application Data\TigerPlayer
2009-08-23 14:58 . 2009-08-23 14:59 -------- d-----w- c:\program files\MpcStar
2009-08-21 00:11 . 2009-08-21 00:11 -------- d-sh--w- c:\documents and settings\Owner\PrivacIE
2009-08-20 23:45 . 2009-08-20 23:45 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-08-20 23:45 . 2009-08-20 23:45 -------- d-sh--w- c:\documents and settings\Owner\IETldCache
2009-08-20 23:41 . 2009-08-27 18:46 -------- d-----w- c:\windows\ie8updates
2009-08-20 23:35 . 2009-07-03 17:09 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-08-20 23:35 . 2009-07-03 17:09 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-08-20 23:34 . 2009-07-01 07:08 101376 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-08-19 18:28 . 2009-08-19 18:28 -------- d-----w- c:\program files\Wedding Dash - Ready Aim Love
2009-08-19 18:28 . 2009-08-19 18:28 -------- d-----w- c:\windows\Wedding Dash - Ready Aim Love
2009-08-18 15:17 . 2009-08-18 15:17 -------- d-----w- c:\windows\Cooking Dash - DinerTown Studios
2009-08-18 15:17 . 2009-08-18 15:17 -------- d-----w- c:\program files\Cooking Dash - DinerTown Studios
2009-08-18 14:57 . 2009-08-18 14:57 1032192 ----a-w- c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\p65m119r.Default User\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
2009-08-18 14:57 . 2009-08-31 15:15 -------- d-----w- c:\program files\BitComet
2009-08-18 14:52 . 2009-04-01 07:03 634880 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\cookingdash\cookingdash.exe
2009-08-18 14:52 . 2009-04-01 07:03 1425408 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\cookingdash\game\cookingdash.exe
2009-08-18 14:52 . 2009-02-09 22:28 57344 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\cookingdash\pfinstall.dll
2009-08-18 14:52 . 2002-07-26 21:02 153088 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\cookingdash\UNWISE.EXE
2009-08-17 02:31 . 2009-08-11 21:34 2203648 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\cooking-dash-2\game\cookingdash2.exe
2009-08-17 02:31 . 2009-08-11 21:34 1376256 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\cooking-dash-2\cookingdash2.exe
2009-08-17 02:31 . 2009-06-12 20:23 57344 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\cooking-dash-2\pfinstall.dll
2009-08-17 02:31 . 2002-07-26 21:02 153088 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\cooking-dash-2\UNWISE.EXE
2009-08-14 15:49 . 2009-08-14 16:02 -------- d-----w- c:\program files\support.com
2009-08-14 15:48 . 2009-08-14 15:48 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\SupportSoft
2009-08-14 15:48 . 2009-08-14 15:48 -------- d-----w- c:\program files\Common Files\SupportSoft
2009-08-13 12:46 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2009-08-13 03:19 . 2009-08-13 03:47 -------- d-----w- c:\documents and settings\Owner\Application Data\LimeWire
2009-08-06 04:41 . 2009-08-06 04:41 -------- d-----w- c:\windows\system32\XPSViewer
2009-08-06 04:41 . 2009-08-06 04:41 -------- d-----w- c:\program files\MSBuild
2009-08-06 04:40 . 2009-08-06 04:40 -------- d-----w- c:\program files\Reference Assemblies
2009-08-06 04:40 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-06 04:40 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-08-06 04:40 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-06 04:40 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-06 04:40 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-08-06 04:40 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-06 04:40 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-08-06 04:40 . 2009-08-06 04:40 -------- d-----w- C:\8fdd0779ed77368804d5908c87c1629c
2009-08-06 04:40 . 2009-09-01 20:17 -------- d-----w- c:\windows\SxsCaPendDel
2009-08-05 09:01 . 2009-08-05 09:01 204800 -c----w- c:\windows\system32\dllcache\mswebdvd.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-01 18:10 . 2007-03-06 18:25 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-01 05:24 . 2004-01-31 01:27 43 -c--a-w- c:\windows\popcinfo.dat
2009-09-01 02:28 . 2008-10-07 20:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-29 19:19 . 2007-03-13 14:14 -------- d-----w- c:\documents and settings\All Users\Application Data\PlayFirst
2009-08-29 19:19 . 2005-11-20 04:35 -------- d-----w- c:\documents and settings\Owner\Application Data\PlayFirst
2009-08-27 19:21 . 2005-10-09 04:37 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2009-08-26 13:06 . 2009-06-02 12:40 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-08-26 13:06 . 2009-06-02 12:40 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-26 13:06 . 2009-06-02 12:40 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-22 03:49 . 2007-03-13 14:33 -------- d-----w- c:\program files\PlayFirst
2009-08-21 00:11 . 2009-06-29 14:28 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-08-17 02:31 . 2009-03-24 17:40 466944 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\pfHarness\pfHarness.dll
2009-08-13 03:19 . 2005-08-20 07:21 -------- d-----w- c:\program files\LimeWire
2009-08-06 17:17 . 2008-10-07 20:50 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-06 11:54 . 2003-12-18 03:12 36168 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-05 17:45 . 2005-10-09 04:37 -------- d-----w- c:\program files\World of Warcraft
2009-08-05 09:01 . 2004-09-13 00:39 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-26 02:48 . 2009-06-02 12:58 -------- d-----w- c:\program files\Sony Online Entertainment
2009-07-24 17:24 . 2003-12-18 02:17 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-24 17:24 . 2009-07-24 17:24 -------- d-----w- c:\program files\Sony
2009-07-21 13:03 . 2009-07-21 04:35 -------- d-----w- c:\documents and settings\All Users\Application Data\BigFishGamesCache
2009-07-21 04:35 . 2009-07-21 04:35 -------- d-----w- c:\program files\bfgclient
2009-07-20 20:09 . 2009-07-24 15:28 282624 ----a-w- c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\p65m119r.Default User\extensions\NPDyyno@dyyno.com\Plugins\npDyyno.dll
2009-07-20 18:57 . 2009-07-20 18:57 17408 ----a-r- c:\windows\system32\SZIO5.dll
2009-07-20 18:56 . 2009-07-20 18:56 311296 ----a-r- c:\windows\system32\SZBase5.dll
2009-07-20 18:56 . 2009-07-20 18:56 540672 ----a-r- c:\windows\system32\SZComp5.dll
2009-07-17 22:51 . 2009-03-24 17:39 139264 ----a-w- c:\documents and settings\All Users\Application Data\PlayFirst\Games\PlayFirst.EXE
2009-07-17 19:01 . 2004-09-13 00:39 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-15 17:02 . 2009-07-15 17:01 -------- d-----w- c:\program files\WebEx
2009-07-15 17:01 . 2009-07-15 17:01 8892928 ----a-w- c:\documents and settings\All Users\Application Data\atscie.msi
2009-07-14 17:40 . 2008-11-05 00:38 -------- d-----w- c:\program files\Hawking
2009-07-14 17:38 . 2008-11-05 00:39 20747 ----a-w- c:\windows\system32\drivers\AegisP.sys
2009-07-14 17:38 . 2009-07-14 17:38 -------- d-----w- c:\program files\Compact Wireless-G USB Adapter Wireless Network Monitor
2009-07-14 03:43 . 2004-09-13 00:41 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-09 19:52 . 2009-07-09 19:52 126976 ----a-r- c:\windows\system32\IS3HTUI5.dll
2009-07-09 19:52 . 2009-07-09 19:52 393216 ----a-r- c:\windows\system32\IS3DBA5.dll
2009-07-09 19:51 . 2009-07-09 19:51 385024 ----a-r- c:\windows\system32\IS3UI5.dll
2009-07-09 19:51 . 2009-07-09 19:51 61440 ----a-r- c:\windows\system32\IS3Hks5.dll
2009-07-09 19:51 . 2009-07-09 19:51 23040 ----a-r- c:\windows\system32\IS3XDat5.dll
2009-07-09 19:50 . 2009-07-09 19:50 225280 ----a-r- c:\windows\system32\IS3Win325.dll
2009-07-09 19:50 . 2009-07-09 19:50 94208 ----a-r- c:\windows\system32\IS3Inet5.dll
2009-07-09 19:50 . 2009-07-09 19:50 90112 ----a-r- c:\windows\system32\IS3Svc5.dll
2009-07-09 19:47 . 2009-07-09 19:47 724992 ----a-r- c:\windows\system32\IS3Base5.dll
2009-07-03 17:09 . 2004-08-24 01:32 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-25 08:25 . 2004-09-13 00:39 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:25 . 2004-09-13 00:39 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2004-09-13 00:38 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2004-09-13 00:38 730112 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2004-09-13 00:38 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:25 . 2004-09-13 00:38 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-24 11:18 . 2004-09-13 00:38 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:36 . 2004-09-13 00:38 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2001-08-18 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-14 20:07 . 2009-07-15 17:19 1004800 ----a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-06-12 12:31 . 2004-09-13 00:38 76288 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 14:13 . 2004-09-13 00:39 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 13:19 . 2004-09-13 00:39 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2004-09-13 00:38 132096 ----a-w- c:\windows\system32\wkssvc.dll
2005-11-24 01:46 . 2005-11-24 01:47 774144 ----a-w- c:\program files\RngInterstitial.dll
2006-11-14 16:31 . 2006-11-14 16:31 34384 ----a-w- c:\program files\mozilla firefox\plugins\atgpcdec.dll
2006-11-14 16:31 . 2006-11-14 16:31 93848 ----a-w- c:\program files\mozilla firefox\plugins\atgpcext.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-07-24 13:55 1090816 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-10-19 126976]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-12 98304]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-26 2007832]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - c:\windows\system32\narrator.exe [2008-04-14 53760]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-26 13:06 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^GoBack.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\GoBack.lnk
backup=c:\windows\pss\GoBack.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk
backup=c:\windows\pss\Microsoft Works Calendar Reminders.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Broadband Networking\\MSBNUpdate.exe"=
"c:\\Program Files\\Microsoft Broadband Networking\\MSBNUtil.exe"=
"c:\\Program Files\\Microsoft Broadband Networking\\MSBNTray.exe"=
"c:\\Program Files\\Microsoft Broadband Networking\\MSBNCfg.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.1.2.9901-to-3.1.3.9947-enUS-downloader.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\ATI Technologies\\ATI.ACE\\CLI.exe"=
"c:\\Documents and Settings\\Owner\\Local Settings\\Application Data\\Dyyno Receiver\\DPPM.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"7476:TCP"= 7476:TCP:BitComet 7476 TCP
"7476:UDP"= 7476:UDP:BitComet 7476 UDP
"14749:TCP"= 14749:TCP:BitComet 14749 TCP
"14749:UDP"= 14749:UDP:BitComet 14749 UDP
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [8/31/2009 11:53 PM 28544]
R0 pxscan;pxscan;c:\windows\system32\drivers\pxscan.sys [9/1/2009 12:17 AM 22024]
R0 pxsec;pxsec;c:\windows\system32\drivers\pxsec.sys [9/1/2009 12:17 AM 27656]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/2/2009 8:40 AM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [6/2/2009 8:40 AM 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [6/29/2009 10:27 AM 297752]
R2 szkg5;szkg;c:\windows\system32\drivers\SZKG.sys [5/12/2009 2:13 PM 61328]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [6/29/2009 10:27 AM 908056]
S2 CSIScanner;CSIScanner;c:\program files\Prevx\prevx.exe [9/1/2009 12:17 AM 4368952]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 8:19 PM 13592]
S3 MN130;Microsoft(R) PCI Adapter MN-130;c:\windows\system32\drivers\MN130-51.sys [5/29/2002 2:25 PM 38400]
S3 UNDPX2K;UNDPX2K;\??\c:\windows\system32\drivers\UNDPX2K.SYS --> c:\windows\system32\drivers\UNDPX2K.SYS [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - GTNDIS5
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-08-31 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]
.
- - - - ORPHANS REMOVED - - - -
Toolbar-SITEguard - (no file)
WebBrowser-{9D69F5EE-E293-4834-8587-4B94296E84E6} - (no file)
ShellExecuteHooks-{6809e580-a3a7-11d1-9a00-00a0c945b006} - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*
http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*
http://www.yahoo.com
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: { - c:\documents and settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
LSP: c:\program files\Common Files\iS3\Anti-Spyware\iS3lsp.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {5D1E3FA5-64FF-4387-9418-F1D67AFB2247} - hxxp://thesims.ea.com/teleport/superstar/MaxisSuperstarTeleX.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\p65m119r.Default User\
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\p65m119r.Default User\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\p65m119r.Default User\extensions\NPDyyno@dyyno.com\plugins\npDyyno.dll
FF - plugin: c:\progra~1\SONYON~1\npsoe.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npatgpc.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npqtplugin8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npracplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\MpcStar\Codecs\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\MpcStar\Codecs\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-01 23:05
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-515967899-861567501-682003330-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(632)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'lsass.exe'(688)
c:\program files\Common Files\iS3\Anti-Spyware\iS3lsp.dll
- - - - - - - > 'explorer.exe'(3368)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\windows\system32\ati2evxx.exe
c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
c:\program files\Roxio\GoBack\GBPoll.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
c:\program files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
.
**************************************************************************
.
Completion time: 2009-09-02 23:10 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-02 03:10
Pre-Run: 68,243,374,080 bytes free
Post-Run: 68,216,741,888 bytes free
Current=3 Default=3 Failed=2 LastKnownGood=4 Sets=,1,2,3,4,5,6,7,8,9
375 --- E O F --- 2009-09-02 02:31