Here's the logs

Status
Not open for further replies.
I would go into Safe Mode after updating MBAM and ComboFix and run scans again. Post up the logs from all 3. ComboFix, MBAM and HiJack This.

I am not seeing anything in HJT at all. So maybe the logs from the others might provide some further insight.
 
ComboFix 11-05-11.04 - Matt 05/12/2011 20:26:21.3.2 - x86 MINIMAL
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2046.1539 [GMT -6:00]
Running from: c:\av stuff\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-- Previous Run --
.
Infected copy of c:\windows\system32\kernel32.dll was found and disinfected
Restored copy from - c:\windows\ERDNT\cache\kernel32.dll
.
--------
.
.
((((((((((((((((((((((((( Files Created from 2011-04-13 to 2011-05-13 )))))))))))))))))))))))))))))))
.
.
2011-05-13 02:37 . 2011-05-13 02:37 -------- d-----w- c:\users\Rachelle\AppData\Local\temp
2011-05-13 02:37 . 2011-05-13 02:37 -------- d-----w- c:\users\Mcx1-MILLERFAMILYPC\AppData\Local\temp
2011-05-13 02:37 . 2011-05-13 02:37 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-05-13 01:09 . 2011-04-18 15:15 7071056 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{4E2F899A-F258-4AD2-A670-C2CFCB1768C6}\mpengine.dll
2011-05-11 03:29 . 2011-05-11 03:29 -------- d-----w- c:\program files\LSoft Technologies
2011-05-08 20:39 . 2011-05-08 20:44 -------- d-----w- c:\programdata\MFAData
2011-05-07 20:16 . 2011-05-12 03:08 -------- d-----w- c:\program files\Trend Micro
2011-05-07 20:16 . 2011-05-07 20:16 388096 ----a-r- c:\users\Matt\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-05-07 20:06 . 2011-05-07 20:06 -------- d--h--w- c:\windows\msdownld.tmp
2011-05-07 17:13 . 2011-05-13 02:37 -------- d-----w- c:\users\Matt\AppData\Local\temp
2011-05-07 15:39 . 2011-05-13 02:16 -------- d-----w- C:\AV Stuff
2011-05-07 03:15 . 2011-05-07 03:15 190032 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2011-05-07 03:15 . 2011-05-07 03:15 -------- d-----w- c:\windows\system32\log
2011-05-04 20:03 . 2011-05-07 16:31 -------- d-----w- c:\users\Raya
2011-04-30 17:49 . 2011-04-30 17:49 -------- d-----w- c:\program files\SystemRequirementsLab
2011-04-27 20:26 . 2011-02-18 05:39 31232 ----a-w- c:\windows\system32\prevhost.exe
2011-04-27 20:25 . 2011-03-11 05:33 1699328 ----a-w- c:\windows\system32\esent.dll
2011-04-27 20:25 . 2011-03-11 05:39 148864 ----a-w- c:\windows\system32\drivers\storport.sys
2011-04-27 20:25 . 2011-03-11 05:39 1211264 ----a-w- c:\windows\system32\drivers\ntfs.sys
2011-04-27 20:25 . 2011-03-11 05:39 143744 ----a-w- c:\windows\system32\drivers\nvstor.sys
2011-04-27 20:25 . 2011-03-11 05:39 117120 ----a-w- c:\windows\system32\drivers\nvraid.sys
2011-04-27 20:25 . 2011-03-11 05:38 332160 ----a-w- c:\windows\system32\drivers\iaStorV.sys
2011-04-27 20:25 . 2011-03-11 05:38 80256 ----a-w- c:\windows\system32\drivers\amdsata.sys
2011-04-27 20:25 . 2011-03-11 05:38 22400 ----a-w- c:\windows\system32\drivers\amdxata.sys
2011-04-27 20:25 . 2011-03-11 05:31 74240 ----a-w- c:\windows\system32\fsutil.exe
2011-04-27 20:25 . 2011-03-12 11:23 870912 ----a-w- c:\windows\system32\XpsPrint.dll
2011-04-27 20:24 . 2011-02-25 05:30 2616320 ----a-w- c:\windows\explorer.exe
2011-04-14 09:07 . 2011-04-14 09:10 -------- d-----w- C:\5fd82fde9e25584e468d260c0386ea7f
2011-04-14 04:58 . 2011-04-14 04:58 -------- d-----w- c:\program files\iPod
2011-04-13 15:40 . 2011-02-23 04:48 311808 ----a-w- c:\windows\system32\drivers\srv.sys
2011-04-13 15:40 . 2011-02-23 04:48 310272 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-04-13 15:40 . 2011-02-23 04:47 114176 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-04-13 15:40 . 2011-03-03 05:38 132608 ----a-w- c:\windows\system32\dnsrslvr.dll
2011-04-13 15:40 . 2011-03-03 05:36 28672 ----a-w- c:\windows\system32\dnscacheugc.exe
2011-04-13 15:40 . 2011-02-19 06:30 34304 ----a-w- c:\windows\system32\atmlib.dll
2011-04-13 15:40 . 2011-02-19 04:34 294912 ----a-w- c:\windows\system32\atmfd.dll
2011-04-13 15:39 . 2011-03-03 03:42 2333184 ----a-w- c:\windows\system32\win32k.sys
2011-04-13 15:39 . 2011-02-12 05:35 191488 ----a-w- c:\windows\system32\FXSCOVER.exe
2011-04-13 15:39 . 2011-02-24 05:38 288256 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-04-13 15:39 . 2011-03-08 05:28 741376 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-13 15:39 . 2011-03-11 05:33 1164288 ----a-w- c:\windows\system32\mfc42u.dll
2011-04-13 15:39 . 2011-03-11 05:33 1137664 ----a-w- c:\windows\system32\mfc42.dll
2011-04-13 15:39 . 2011-02-23 04:47 123904 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-13 15:39 . 2011-02-23 04:47 69632 ----a-w- c:\windows\system32\drivers\bowser.sys
2011-04-13 15:39 . 2011-02-23 04:47 223232 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-04-13 15:39 . 2011-02-23 04:47 96768 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-04-13 04:34 . 2011-04-13 04:34 3707144 ----a-w- c:\programdata\Microsoft\BingBar\BBSvc\7.0.614.0oemBingBarSetup-Partner.EXE
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-06 00:54 . 2009-07-14 02:05 152576 ----a-w- c:\windows\system32\msclmd.dll
2011-03-09 22:43 . 2010-06-24 17:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-02-23 14:27 . 2011-02-23 14:27 941160 ----a-w- c:\windows\system32\nvdispco322090.dll
2011-02-23 14:27 . 2011-02-23 14:27 837736 ----a-w- c:\windows\system32\nvgenco322040.dll
2011-02-23 14:27 . 2011-02-23 14:27 57960 ----a-w- c:\windows\system32\OpenCL.dll
2011-02-23 14:27 . 2011-02-23 14:27 4942952 ----a-w- c:\windows\system32\nvcuda.dll
2011-02-23 14:27 . 2011-02-23 14:27 2895976 ----a-w- c:\windows\system32\nvcuvid.dll
2011-02-23 14:27 . 2011-02-23 14:27 2251368 ----a-w- c:\windows\system32\nvcuvenc.dll
2011-02-23 14:27 . 2011-02-23 14:27 15047272 ----a-w- c:\windows\system32\nvoglv32.dll
2011-02-23 14:27 . 2011-02-23 14:27 13011560 ----a-w- c:\windows\system32\nvcompiler.dll
2011-02-23 14:27 . 2011-02-23 14:27 10920 ----a-w- c:\windows\system32\drivers\nvBridge.kmd
2011-02-23 14:27 . 2011-02-23 14:27 10468360 ----a-w- c:\windows\system32\drivers\nvlddmkm.sys
2011-02-23 14:27 . 2011-02-23 14:27 10079336 ----a-w- c:\windows\system32\nvd3dum.dll
2011-02-23 14:27 . 2010-04-04 04:55 1965672 ----a-w- c:\windows\system32\nvapi.dll
2011-02-23 14:27 . 2009-07-13 22:09 5654120 ----a-w- c:\windows\system32\nvwgf2um.dll
2011-02-19 06:30 . 2011-03-08 18:40 805376 ----a-w- c:\windows\system32\FntCache.dll
2011-02-19 06:30 . 2011-03-08 18:40 1076736 ----a-w- c:\windows\system32\DWrite.dll
2011-02-19 06:30 . 2011-03-08 18:40 739840 ----a-w- c:\windows\system32\d2d1.dll
2011-02-18 23:36 . 2011-02-18 23:36 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2011-02-18 23:36 . 2011-02-18 23:36 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-05-07_16.54.48 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-05-07 20:02 . 2011-05-07 20:02 86528 c:\windows\winsxs\x86_microsoft-windows-ie-sysprep_31bf3856ad364e35_9.4.8112.16421_none_3411bc8ed442d7a8\iesysprep.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 78848 c:\windows\winsxs\x86_microsoft-windows-ie-setup_31bf3856ad364e35_9.4.8112.16421_none_b1befe64620e9eb3\inseng.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 74752 c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_9.4.8112.16421_none_de5057e278bf9ae3\iesetup.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 31744 c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_9.4.8112.16421_none_de5057e278bf9ae3\iernonce.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 74240 c:\windows\winsxs\x86_microsoft-windows-ie-setup-support_31bf3856ad364e35_9.4.8112.16421_none_de5057e278bf9ae3\ie4uinit.exe
+ 2011-05-07 20:02 . 2011-05-07 20:02 83456 c:\windows\winsxs\x86_microsoft-windows-ie-pdm_31bf3856ad364e35_9.4.8112.16421_none_05f58d6b02d23b61\PDMSetup.exe
+ 2011-05-07 20:02 . 2011-05-07 20:02 49664 c:\windows\winsxs\x86_microsoft-windows-ie-jsprofilercore_31bf3856ad364e35_9.4.8112.16421_none_23273f2d4ba58c6b\JSProfilerCore.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 66048 c:\windows\winsxs\x86_microsoft-windows-ie-infocard_31bf3856ad364e35_9.4.8112.16421_none_731b22247e84589a\icardie.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 22016 c:\windows\winsxs\x86_microsoft-windows-ie-impexp-extexport_31bf3856ad364e35_9.4.8112.16421_none_467d635eddcbe7c3\ExtExport.exe
+ 2011-05-07 20:02 . 2011-05-07 20:02 35840 c:\windows\winsxs\x86_microsoft-windows-ie-imagesupport_31bf3856ad364e35_9.4.8112.16421_none_56746b920d54cd22\imgutil.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 48640 c:\windows\winsxs\x86_microsoft-windows-ie-htmleditingsupport_31bf3856ad364e35_9.4.8112.16421_none_0bed293ed46cedb6\mshtmler.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 72704 c:\windows\winsxs\x86_microsoft-windows-ie-htmlediting_31bf3856ad364e35_9.4.8112.16421_none_60a88c255dab1669\mshtmled.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 11776 c:\windows\winsxs\x86_microsoft-windows-ie-htmlapplication_31bf3856ad364e35_9.4.8112.16421_none_71d991ff23a3e055\mshta.exe
+ 2011-05-07 20:02 . 2011-05-07 20:02 74752 c:\windows\winsxs\x86_microsoft-windows-ie-gc-registeriepkeys_31bf3856ad364e35_9.4.8112.16421_none_406878db3e15ac14\RegisterIEPKEYs.exe
+ 2011-05-07 20:02 . 2011-05-07 20:02 10752 c:\windows\winsxs\x86_microsoft-windows-ie-feedsbs_31bf3856ad364e35_9.4.8112.16421_none_14cd91c7f508553a\msfeedssync.exe
+ 2011-05-07 20:02 . 2011-05-07 20:02 41472 c:\windows\winsxs\x86_microsoft-windows-ie-feedsbs_31bf3856ad364e35_9.4.8112.16421_none_14cd91c7f508553a\msfeedsbs.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 23552 c:\windows\winsxs\x86_microsoft-windows-ie-controls_31bf3856ad364e35_9.4.8112.16421_none_e260faa86a390a42\licmgr10.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 66048 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.16421_none_1a68963bbc19635b\WininetPlugin.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 65024 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.16421_none_1a68963bbc19635b\jsproxy.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 97280 c:\windows\winsxs\x86_microsoft-windows-i..eoptionalcomponents_31bf3856ad364e35_9.4.8112.16421_none_1a39851f718708ff\ConfigureIEOptionalComponents.exe
+ 2011-05-07 20:02 . 2011-05-07 20:02 54272 c:\windows\winsxs\x86_microsoft-windows-i..ablenetworkgraphics_31bf3856ad364e35_9.4.8112.16421_none_064611e72dafc564\pngfilt.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 76800 c:\windows\winsxs\x86_microsoft-windows-i..-setieinstalleddate_31bf3856ad364e35_9.4.8112.16421_none_20f6a468db4fac99\SetIEInstalledDate.exe
+ 2010-10-12 19:27 . 2011-05-08 03:16 95942 c:\windows\System32\wdi\SuspendPerformanceDiagnostics_SystemData_S4.bin
+ 2010-08-05 06:08 . 2011-05-13 01:09 31250 c:\windows\System32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 04:55 . 2011-05-13 01:09 31020 c:\windows\System32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2011-05-07 20:02 . 2011-05-07 20:02 76800 c:\windows\System32\SetIEInstalledDate.exe
+ 2011-05-07 20:02 . 2011-05-07 20:02 74752 c:\windows\System32\RegisterIEPKEYs.exe
+ 2011-05-07 20:02 . 2011-05-07 20:02 54272 c:\windows\System32\pngfilt.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 48640 c:\windows\System32\mshtmler.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 72704 c:\windows\System32\mshtmled.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 11776 c:\windows\System32\mshta.exe
+ 2011-05-07 20:02 . 2011-05-07 20:02 10752 c:\windows\System32\msfeedssync.exe
+ 2011-05-07 20:02 . 2011-05-07 20:02 41472 c:\windows\System32\msfeedsbs.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 66048 c:\windows\System32\migration\WininetPlugin.dll
- 2011-04-29 00:22 . 2011-05-05 02:31 67584 c:\windows\System32\LogFiles\Srt\bootstat.dat
+ 2011-04-29 00:22 . 2011-05-13 00:55 67584 c:\windows\System32\LogFiles\Srt\bootstat.dat
+ 2011-05-07 20:02 . 2011-05-07 20:02 23552 c:\windows\System32\licmgr10.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 65024 c:\windows\System32\jsproxy.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 78848 c:\windows\System32\inseng.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 35840 c:\windows\System32\imgutil.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 86528 c:\windows\System32\iesysprep.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 74752 c:\windows\System32\iesetup.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 31744 c:\windows\System32\iernonce.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 74240 c:\windows\System32\ie4uinit.exe
+ 2011-05-07 20:02 . 2011-05-07 20:02 66048 c:\windows\System32\icardie.dll
+ 2010-08-05 03:57 . 2011-05-13 01:09 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-08-05 03:57 . 2011-05-04 23:34 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-08-05 03:57 . 2011-05-13 01:09 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2010-08-05 03:57 . 2011-05-04 23:34 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:41 . 2011-05-13 01:09 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:41 . 2011-05-04 23:34 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:34 . 2011-05-13 01:11 91392 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
- 2010-08-05 04:06 . 2011-05-07 16:16 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2010-08-05 04:06 . 2011-05-08 00:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2010-08-05 04:06 . 2011-05-07 16:16 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2010-08-05 04:06 . 2011-05-08 00:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-08-10 08:00 . 2011-04-28 19:50 3784 c:\windows\System32\wdi\ERCQueuedResolutions.dat
+ 2010-08-10 08:00 . 2011-05-13 01:18 3784 c:\windows\System32\wdi\ERCQueuedResolutions.dat
+ 2010-08-05 04:06 . 2011-05-13 01:09 5266 c:\windows\System32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3488713131-3594135876-2419172442-1001_UserData.bin
+ 2011-05-13 01:19 . 2011-05-13 01:59 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-05-07 16:09 . 2011-05-07 16:09 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2011-05-07 16:09 . 2011-05-07 16:09 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-05-13 01:19 . 2011-05-13 01:59 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2011-05-07 20:02 . 2011-05-07 20:02 420864 c:\windows\winsxs\x86_microsoft-windows-scripting-vbscript_31bf3856ad364e35_9.4.8112.16421_none_60d9a60d482d54be\vbscript.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 716800 c:\windows\winsxs\x86_microsoft-windows-scripting-jscript_31bf3856ad364e35_9.4.8112.16421_none_9b5f8b55116aa882\jscript.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 161792 c:\windows\winsxs\x86_microsoft-windows-msls31_31bf3856ad364e35_9.4.8112.16421_none_e47f7674bcba0f60\msls31.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 104448 c:\windows\winsxs\x86_microsoft-windows-js-debuggeride_31bf3856ad364e35_9.4.8112.16421_none_5377da1a18fb28e4\jsdebuggeride.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 466432 c:\windows\winsxs\x86_microsoft-windows-ieinstal_31bf3856ad364e35_9.4.8112.16421_none_011b7bdcabe8aef6\ieinstal.exe
+ 2011-05-07 20:02 . 2011-05-07 20:02 176640 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_9.4.8112.16421_none_7d220f5dc8655abe\ieui.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 231936 c:\windows\winsxs\x86_microsoft-windows-ie-winsockautodialstub_31bf3856ad364e35_9.4.8112.16421_none_08aa74047810b205\url.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 766976 c:\windows\winsxs\x86_microsoft-windows-ie-vgx_31bf3856ad364e35_9.4.8112.16421_none_05b6b429030148f7\VGX.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 141104 c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_9.4.8112.16421_none_60234d17a6ca81b8\sqmapi.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 162304 c:\windows\winsxs\x86_microsoft-windows-ie-ratings_31bf3856ad364e35_9.4.8112.16421_none_e011e11277018c3c\msrating.dll
+ 2009-06-10 21:14 . 2009-06-10 21:14 355832 c:\windows\winsxs\x86_microsoft-windows-ie-pdm_31bf3856ad364e35_9.4.8112.16421_none_05f58d6b02d23b61\pdm.dll
+ 2009-07-13 21:59 . 2009-06-10 21:14 265720 c:\windows\winsxs\x86_microsoft-windows-ie-pdm_31bf3856ad364e35_9.4.8112.16421_none_05f58d6b02d23b61\msdbg2.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 203776 c:\windows\winsxs\x86_microsoft-windows-ie-offlinefavorites_31bf3856ad364e35_9.4.8112.16421_none_79ab85b66bffe20a\webcheck.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 123392 c:\windows\winsxs\x86_microsoft-windows-ie-objectcontrolviewer_31bf3856ad364e35_9.4.8112.16421_none_4fa60aea2e696726\occache.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 301056 c:\windows\winsxs\x86_microsoft-windows-ie-networkinspection_31bf3856ad364e35_9.4.8112.16421_none_8d7c2d276e46f322\networkinspection.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 149504 c:\windows\winsxs\x86_microsoft-windows-ie-jsprofilerui_31bf3856ad364e35_9.4.8112.16421_none_0b7e9c65e8794902\jsprofilerui.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 386560 c:\windows\winsxs\x86_microsoft-windows-ie-jscriptdebugui_31bf3856ad364e35_9.4.8112.16421_none_d2ebf19be7eb8e44\jsdbgui.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 142848 c:\windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_9.4.8112.16421_none_47e1a2c73444d23e\ieUnatt.exe
+ 2011-05-07 20:02 . 2011-05-07 20:02 152064 c:\windows\winsxs\x86_microsoft-windows-ie-iexpress_31bf3856ad364e35_9.4.8112.16421_none_7cfb7f9f58f84355\wextract.exe
+ 2011-05-07 20:02 . 2011-05-07 20:02 150528 c:\windows\winsxs\x86_microsoft-windows-ie-iexpress_31bf3856ad364e35_9.4.8112.16421_none_7cfb7f9f58f84355\iexpress.exe
+ 2011-05-07 20:02 . 2011-05-07 20:02 194048 c:\windows\winsxs\x86_microsoft-windows-ie-ieshims_31bf3856ad364e35_9.4.8112.16421_none_600cd2b3b47f5448\IEShims.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 193536 c:\windows\winsxs\x86_microsoft-windows-ie-ieproxy_31bf3856ad364e35_9.4.8112.16421_none_a8ae871d64d6edda\ieproxy.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 222720 c:\windows\winsxs\x86_microsoft-windows-ie-ielowutil_31bf3856ad364e35_9.4.8112.16421_none_1ef5aee48b810ba0\ielowutil.exe
+ 2011-05-07 20:02 . 2011-05-07 20:02 307200 c:\windows\winsxs\x86_microsoft-windows-ie-iediag_31bf3856ad364e35_9.4.8112.16421_none_2f5fcfbaab97b79b\iediagcmd.exe
+ 2011-05-07 20:02 . 2011-05-07 20:02 107008 c:\windows\winsxs\x86_microsoft-windows-ie-iecleanup_31bf3856ad364e35_9.4.8112.16421_none_d665f7f6aed43c56\iecleanup.exe
+ 2011-05-07 20:02 . 2011-05-07 20:02 110592 c:\windows\winsxs\x86_microsoft-windows-ie-ieadvpack_31bf3856ad364e35_9.4.8112.16421_none_e771ed32e8d4ec48\IEAdvpack.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 580608 c:\windows\winsxs\x86_microsoft-windows-ie-feeds-platform_31bf3856ad364e35_9.4.8112.16421_none_78662d0a54bcb613\msfeeds.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 223232 c:\windows\winsxs\x86_microsoft-windows-ie-directxtransforms_31bf3856ad364e35_9.4.8112.16421_none_b045f1cd9bea63dc\dxtrans.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 353792 c:\windows\winsxs\x86_microsoft-windows-ie-directxtransforms_31bf3856ad364e35_9.4.8112.16421_none_b045f1cd9bea63dc\dxtmsft.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 678912 c:\windows\winsxs\x86_microsoft-windows-ie-devtools_31bf3856ad364e35_9.4.8112.16421_none_5424af8e5a1caf9c\iedvtool.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 118784 c:\windows\winsxs\x86_microsoft-windows-ie-behaviors_31bf3856ad364e35_9.4.8112.16421_none_5543276d0c542bbd\iepeers.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 434176 c:\windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_9.4.8112.16421_none_1411b9158604ddae\ieapfltr.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 163840 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_9.4.8112.16421_none_c6b1c48b210c3b01\ieakui.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 227840 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_9.4.8112.16421_none_c6b1c48b210c3b01\ieaksie.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 101888 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_9.4.8112.16421_none_c6b1c48b210c3b01\admparse.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 130560 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitengine_31bf3856ad364e35_9.4.8112.16421_none_bc95d8ede279e757\ieakeng.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 353584 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitbranding_31bf3856ad364e35_9.4.8112.16421_none_8cd00f3771c38422\iedkcs32.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 748336 c:\windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_b135ff17c80c1949\iexplore.exe
+ 2011-05-07 20:02 . 2011-05-07 20:02 152064 c:\windows\System32\wextract.exe
+ 2011-05-07 20:02 . 2011-05-07 20:02 203776 c:\windows\System32\webcheck.dll
+ 2010-08-05 17:01 . 2011-05-11 02:31 216508 c:\windows\System32\wdi\SuspendPerformanceDiagnostics_SystemData_FastS4.bin
+ 2011-05-07 20:02 . 2011-05-07 20:02 420864 c:\windows\System32\vbscript.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 231936 c:\windows\System32\url.dll
+ 2009-07-14 02:05 . 2011-05-13 01:36 623940 c:\windows\System32\perfh009.dat
- 2009-07-14 02:05 . 2011-05-07 16:15 623940 c:\windows\System32\perfh009.dat
+ 2009-07-14 02:05 . 2011-05-13 01:36 106316 c:\windows\System32\perfc009.dat
- 2009-07-14 02:05 . 2011-05-07 16:15 106316 c:\windows\System32\perfc009.dat
+ 2011-05-07 20:02 . 2011-05-07 20:02 123392 c:\windows\System32\occache.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 162304 c:\windows\System32\msrating.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 161792 c:\windows\System32\msls31.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 580608 c:\windows\System32\msfeeds.dll
+ 2010-08-05 04:23 . 2011-02-03 00:11 222080 c:\windows\System32\MpSigStub.exe
- 2011-04-13 15:40 . 2011-02-18 05:41 716800 c:\windows\System32\jscript.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 716800 c:\windows\System32\jscript.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 150528 c:\windows\System32\iexpress.exe
+ 2011-05-07 20:02 . 2011-05-07 20:02 142848 c:\windows\System32\ieUnatt.exe
+ 2011-05-07 20:02 . 2011-05-07 20:02 176640 c:\windows\System32\ieui.dll
- 2011-04-13 15:39 . 2011-03-07 05:31 176640 c:\windows\System32\ieui.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 118784 c:\windows\System32\iepeers.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 353584 c:\windows\System32\iedkcs32.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 434176 c:\windows\System32\ieapfltr.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 163840 c:\windows\System32\ieakui.dll
- 2009-07-13 23:42 . 2009-07-14 01:05 163840 c:\windows\System32\ieakui.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 227840 c:\windows\System32\ieaksie.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 130560 c:\windows\System32\ieakeng.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 110592 c:\windows\System32\IEAdvpack.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 223232 c:\windows\System32\dxtrans.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 353792 c:\windows\System32\dxtmsft.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 101888 c:\windows\System32\admparse.dll
+ 2009-07-14 04:47 . 2011-05-13 01:18 382576 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 04:47 . 2011-05-06 23:49 382576 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2011-05-07 20:02 . 2011-05-07 20:02 1797632 c:\windows\winsxs\x86_microsoft-windows-scripting-jscript_31bf3856ad364e35_9.4.8112.16421_none_9b5f8b55116aa882\jscript9.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 9702400 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_9.4.8112.16421_none_7d220f5dc8655abe\ieframe.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 1785344 c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_9.4.8112.16421_none_60234d17a6ca81b8\iertutil.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 3695416 c:\windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_9.4.8112.16421_none_1411b9158604ddae\ieapfltr.dat
+ 2011-05-07 20:02 . 2011-05-07 20:02 1126912 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.16421_none_1a68963bbc19635b\wininet.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 1102336 c:\windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_9.4.8112.16421_none_cd62ba99f1103cc8\urlmon.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 1126912 c:\windows\System32\wininet.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 1102336 c:\windows\System32\urlmon.dll
- 2009-07-14 02:03 . 2011-05-05 04:42 7077888 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2009-07-14 02:03 . 2011-05-08 00:11 7077888 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2011-05-07 20:02 . 2011-05-07 20:02 1797632 c:\windows\System32\jscript9.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 1785344 c:\windows\System32\iertutil.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 9702400 c:\windows\System32\ieframe.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 3695416 c:\windows\System32\ieapfltr.dat
+ 2009-07-14 04:34 . 2011-05-13 01:10 7151340 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
- 2009-07-14 04:34 . 2011-04-28 06:11 7151340 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
+ 2010-11-17 01:14 . 2011-05-13 01:18 1213721 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3488713131-3594135876-2419172442-1001-8192.dat
+ 2011-05-08 03:30 . 2011-05-13 00:42 1079156 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3488713131-3594135876-2419172442-1001-4096.dat
+ 2011-05-08 21:59 . 2011-05-12 03:09 1862800 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-3488713131-3594135876-2419172442-1001-12288.dat
+ 2011-05-06 23:08 . 2011-05-06 23:08 1402880 c:\windows\Installer\e20f69.msi
+ 2011-05-07 20:02 . 2011-05-07 20:02 12268544 c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.16421_none_2bc2b55a3c6fcc91\mshtml.dll
+ 2011-05-07 20:02 . 2011-05-07 20:02 12268544 c:\windows\System32\mshtml.dll
+ 2010-08-06 01:28 . 2011-05-11 04:30 42829768 c:\windows\System32\MRT.exe
+ 2011-02-08 01:04 . 2011-05-11 03:41 113888768 c:\windows\winsxs\ManifestCache\ee9f676b8aa4122b_blobs.bin
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-09-22 47904]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-03-07 421160]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http:" [X]
"GrpConv"="grpconv -o" [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2011-03-16 183560]
R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4640000]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-08-05 1343400]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 51040]
.
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MIF5BA~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\MIF5BA~1\Office14\ONBttnIE.dll/105
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-RunOnce-<NO NAME> - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-3488713131-3594135876-2419172442-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-3488713131-3594135876-2419172442-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-05-12 20:48:25
ComboFix-quarantined-files.txt 2011-05-13 02:48
ComboFix2.txt 2011-05-11 02:35
ComboFix3.txt 2011-05-07 17:12
.
Pre-Run: 165,799,972,864 bytes free
Post-Run: 165,745,590,272 bytes free
.
- - End Of File - - 79FEC09D904CC6F2502EF47CCC19808E


Malwarebytes' Anti-Malware 1.50.1.1100
Malwarebytes : Free anti-malware, anti-virus and spyware removal download

Database version: 6564

Windows 6.1.7601 Service Pack 1 (Safe Mode)
Internet Explorer 8.0.7601.17514

5/12/2011 9:58:09 PM
mbam-log-2011-05-12 (21-58-09).txt

Scan type: Full scan (C:\|E:\|)
Objects scanned: 427988
Time elapsed: 59 minute(s), 31 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:37:19 PM, on 5/12/2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Safe mode

Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon.exe
K:\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = Thank you for installing Enhanced Internet Explorer 9
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (file missing)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MIF5BA~1\Office14\GROOVEEX.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MIF5BA~1\Office14\URLREDIR.DLL
O2 - BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)
O3 - Toolbar: Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - "C:\Program Files\Microsoft\BingBar\BingExt.dll" (file missing)
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\RunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallation-feedback-app?lic=OQBVAFMAUgAtAE4AMABUADAASgAtAEoARQAzAEIAUwAtADgAWgBOAEEAUgAtAFkAMwA0ADQATQAtADgANwAyADQAWQA"&"inst=NwA2AC0ANQAxADAANwA3ADcANwA3ADYALQBYAE8AMwA2ACsAMQAtAFQAQgA5ACsAMgAtAE4AMQBEACsAMQAtAFAATAArADkA"&"prod=92"&"ver=9.0.894
O4 - HKLM\..\RunOnce: [GrpConv] grpconv -o
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MIF5BA~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MIF5BA~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.10.115.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - LSI Corporation - C:\Program Files\LSI SoftModem\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe

--
End of file - 5813 bytes



Well look at that my old buddy AVG uninstall is back, I zapped that here from safe mode so maybe now it's gone for good? See anything else? Thanks again KSoD
 
Status
Not open for further replies.
Back
Top Bottom