HERE'S THE COMBO FIX LOG, I'M USING LOGMEIN TO WORK ON THIS PC SO I GUESS IT DID THE SCAN AFTER IT BOOTED ME, THEN I FOUND THE LOG, NOW IT JUST SAYS "PREPARING LOG REPORT, DON'T RUN ANY PROGRAMS UNTIL FINISHED" AND IS SITTING ON THAT SCREEN.
ComboFix 09-11-02.05 - kenya 11/03/2009 11:21:10.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.510.160 [GMT -6:00]
Running from: C:\Documents and Settings\kenya\Desktop\Nate's files\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Program Files\FunWebProducts
C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\MyFunCardsIMBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html
C:\Program Files\FunWebProducts\Shared\Cache\WebfettiBtn.html
C:\Program Files\gamevance\gamevancelib32.dll
C:\Program Files\Gamevance\gvtl.dll
C:\Program Files\MyWebSearch
C:\Program Files\MyWebSearch\bar\1.bin\F3BKGERR.JPG
C:\Program Files\MyWebSearch\bar\1.bin\F3CJpeg.dll
C:\Program Files\MyWebSearch\bar\1.bin\F3DTactl.dll
C:\Program Files\MyWebSearch\bar\1.bin\F3HISTSW.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3HKSTUB.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3HTmlmu.dll
C:\Program Files\MyWebSearch\bar\1.bin\F3HTTPCT.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3POPSWT.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR
C:\Program Files\MyWebSearch\bar\1.bin\F3REGHK.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3REPROX.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3RESTUB.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3SCHMON.EXE
C:\Program Files\MyWebSearch\bar\1.bin\F3SCRCTR.DLL
C:\Program Files\MyWebSearch\bar\1.bin\F3SPACER.WMV
C:\Program Files\MyWebSearch\bar\1.bin\F3WALLPP.DAT
C:\Program Files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL
C:\Program Files\MyWebSearch\bar\1.bin\FWPBUDDY.PNG
C:\Program Files\MyWebSearch\bar\1.bin\M3AUXSTB.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3DLGHK.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR
C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.MANIFEST
C:\Program Files\MyWebSearch\bar\1.bin\M3HIGHIN.EXE
C:\Program Files\MyWebSearch\bar\1.bin\M3HTml.dll
C:\Program Files\MyWebSearch\bar\1.bin\M3IDLE.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE
C:\Program Files\MyWebSearch\bar\1.bin\M3MEDINT.EXE
C:\Program Files\MyWebSearch\bar\1.bin\M3MSG.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR
C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.MANIFEST
C:\Program Files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3SKIN.DLL
C:\Program Files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE
C:\Program Files\MyWebSearch\bar\1.bin\M3SLSRCH.EXE
C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL
C:\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL
C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
C:\Program Files\MyWebSearch\bar\1.bin\MWSSVC.EXE
C:\Program Files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL
C:\Program Files\MyWebSearch\bar\Avatar\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Cache\0059EED3
C:\Program Files\MyWebSearch\bar\Cache\00821312
C:\Program Files\MyWebSearch\bar\Cache\00822523
C:\Program Files\MyWebSearch\bar\Cache\00822AA1.bin
C:\Program Files\MyWebSearch\bar\Cache\00823010.bin
C:\Program Files\MyWebSearch\bar\Cache\0082339A.bin
C:\Program Files\MyWebSearch\bar\Cache\008237B1.bin
C:\Program Files\MyWebSearch\bar\Cache\00823976.bin
C:\Program Files\MyWebSearch\bar\Cache\00823B99.bin
C:\Program Files\MyWebSearch\bar\Cache\00823D00.bin
C:\Program Files\MyWebSearch\bar\Cache\00827508.bin
C:\Program Files\MyWebSearch\bar\Cache\00827892.bin
C:\Program Files\MyWebSearch\bar\Cache\00827BEE.bin
C:\Program Files\MyWebSearch\bar\Cache\00827DF1.bin
C:\Program Files\MyWebSearch\bar\Cache\00827F97
C:\Program Files\MyWebSearch\bar\Cache\012E0AC1
C:\Program Files\MyWebSearch\bar\Cache\012E0E5A
C:\Program Files\MyWebSearch\bar\Cache\files.ini
C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S
C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S
C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S
C:\Program Files\MyWebSearch\bar\History\search3
C:\Program Files\MyWebSearch\bar\icons\CM.ICO
C:\Program Files\MyWebSearch\bar\icons\MFC.ICO
C:\Program Files\MyWebSearch\bar\icons\PSS.ICO
C:\Program Files\MyWebSearch\bar\icons\SMILEY.ICO
C:\Program Files\MyWebSearch\bar\icons\WB.ICO
C:\Program Files\MyWebSearch\bar\icons\ZWINKY.ICO
C:\Program Files\MyWebSearch\bar\Message\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Message\COMMON\ask_logo.gif
C:\Program Files\MyWebSearch\bar\Message\COMMON\autoup.gif
C:\Program Files\MyWebSearch\bar\Message\COMMON\autoup.htm
C:\Program Files\MyWebSearch\bar\Message\COMMON\center.htm
C:\Program Files\MyWebSearch\bar\Message\COMMON\index.htm
C:\Program Files\MyWebSearch\bar\Message\COMMON\mid_dots.gif
C:\Program Files\MyWebSearch\bar\Message\COMMON\mws_logo.gif
C:\Program Files\MyWebSearch\bar\Message\COMMON\protect.htm
C:\Program Files\MyWebSearch\bar\Message\COMMON\shocked.gif
C:\Program Files\MyWebSearch\bar\Message\COMMON\stop.gif
C:\Program Files\MyWebSearch\bar\Message\COMMON\systray.htm
C:\Program Files\MyWebSearch\bar\Message\COMMON\systrayp.htm
C:\Program Files\MyWebSearch\bar\Message\COMMON\tp_grad.gif
C:\Program Files\MyWebSearch\bar\Message\COMMON\warn.gif
C:\Program Files\MyWebSearch\bar\Notifier\COMMON.F3S
C:\Program Files\MyWebSearch\bar\Notifier\DOG.F3S
C:\Program Files\MyWebSearch\bar\Notifier\FISH.F3S
C:\Program Files\MyWebSearch\bar\Notifier\KUNGFU.F3S
C:\Program Files\MyWebSearch\bar\Notifier\LIFEGARD.F3S
C:\Program Files\MyWebSearch\bar\Notifier\MAID.F3S
C:\Program Files\MyWebSearch\bar\Notifier\MAILBOX.F3S
C:\Program Files\MyWebSearch\bar\Notifier\OPERA.F3S
C:\Program Files\MyWebSearch\bar\Notifier\ROBOT.F3S
C:\Program Files\MyWebSearch\bar\Notifier\SEDUCT.F3S
C:\Program Files\MyWebSearch\bar\Notifier\SURFER.F3S
C:\Program Files\MyWebSearch\bar\Settings\prevcfg2.htm
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat
C:\Program Files\MyWebSearch\bar\Settings\setting2.htm
C:\Program Files\MyWebSearch\bar\Settings\settings.dat
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\f3PSSavr.scr
C:\WINDOWS\Tasks\uupjlbdj.job
----- BITS: Possible infected sites -----
hxxp://82.98.231.99
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MYWEBSEARCHSERVICE
-------\Service_MyWebSearchService
((((((((((((((((((((((((( Files Created from 2009-10-03 to 2009-11-03 )))))))))))))))))))))))))))))))
.
2009-11-03 16:44:35 . 2009-11-03 16:44:35 0 d-----w- C:\Documents and Settings\kenya\Application Data\Malwarebytes
2009-11-03 16:44:28 . 2009-09-10 20:54:06 38224 ----a-w- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2009-11-03 16:44:27 . 2009-11-03 16:44:27 0 d-----w- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-11-03 16:44:27 . 2009-09-10 20:53:50 19160 ----a-w- C:\WINDOWS\system32\drivers\mbam.sys
2009-11-03 16:44:26 . 2009-11-03 16:44:33 0 d-----w- C:\Program Files\Malwarebytes' Anti-Malware
2009-11-03 15:55:52 . 2009-11-03 15:55:52 0 d-----w- C:\Documents and Settings\kenya\Local Settings\Application Data\LogMeIn
2009-11-03 15:55:52 . 2009-11-03 15:55:52 0 d-----w- C:\Documents and Settings\All Users\Application Data\LogMeIn
2009-11-03 15:46:12 . 2009-11-03 15:46:12 0 d-----w- C:\Documents and Settings\LocalService\Local Settings\Application Data\ICS
2009-11-03 15:46:06 . 2009-09-29 01:34:32 28984 ----a-w- C:\WINDOWS\system32\LMIport.dll
2009-11-03 15:46:05 . 2009-09-29 01:34:48 83288 ----a-w- C:\WINDOWS\system32\LMIRfsClientNP.dll
2009-11-03 15:46:05 . 2008-08-11 18:41:00 47640 ----a-w- C:\WINDOWS\system32\drivers\LMIRfsDriver.sys
2009-11-03 15:45:28 . 2009-09-29 01:34:30 87352 ----a-w- C:\WINDOWS\system32\LMIinit.dll
2009-11-03 15:44:52 . 2009-11-03 16:39:36 0 d-----w- C:\Program Files\LogMeIn
2009-11-03 15:14:06 . 2009-11-03 15:14:10 0 d-----w- C:\Program Files\CCleaner
2009-11-03 15:06:20 . 2009-11-03 15:06:20 0 d-----w- C:\Program Files\ShowMyPCService
2009-10-27 18:16:26 . 2009-10-27 18:16:26 0 d-----w- C:\ISS
2009-10-19 19:02:20 . 2009-10-19 19:02:20 0 d-----w- C:\Program Files\The Weather Channel FW
2009-10-19 19:01:29 . 2009-10-19 19:01:29 0 d-----w- C:\Documents and Settings\kenya\Local Settings\Application Data\The Weather Channel
2009-10-19 19:01:20 . 2009-10-19 19:01:20 0 d-----w- C:\Program Files\AskBarDis
2009-10-19 19:00:47 . 2009-11-03 17:25:38 0 d-----w- C:\Program Files\Gamevance
2009-10-09 14:01:04 . 2009-10-09 14:01:04 0 d-sh--w- C:\Documents and Settings\kenya\IECompatCache
2009-10-09 13:52:56 . 2009-10-09 13:52:56 0 d-sh--w- C:\Documents and Settings\kenya\PrivacIE
2009-10-09 13:50:39 . 2009-10-09 13:50:39 0 d-sh--w- C:\Documents and Settings\NetworkService\IETldCache
2009-10-09 13:50:12 . 2009-10-09 13:50:12 0 d-sh--w- C:\Documents and Settings\kenya\IETldCache
2009-10-09 13:47:34 . 2009-08-07 08:48:40 100352 ------w- C:\WINDOWS\system32\dllcache\iecompat.dll
2009-10-09 13:47:14 . 2009-10-09 13:47:14 0 d-----w- C:\WINDOWS\ie8updates
2009-10-09 13:46:39 . 2009-08-29 08:08:21 12800 ------w- C:\WINDOWS\system32\dllcache\xpshims.dll
2009-10-09 13:46:38 . 2009-08-29 08:08:18 594432 ------w- C:\WINDOWS\system32\dllcache\msfeeds.dll
2009-10-09 13:46:38 . 2009-08-29 08:08:18 55296 ------w- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2009-10-09 13:46:37 . 2009-08-29 08:08:18 1985536 ------w- C:\WINDOWS\system32\dllcache\iertutil.dll
2009-10-09 13:46:37 . 2009-08-29 08:08:17 246272 ------w- C:\WINDOWS\system32\dllcache\ieproxy.dll
2009-10-09 13:46:36 . 2009-08-29 08:08:16 11069440 ------w- C:\WINDOWS\system32\dllcache\ieframe.dll
2009-10-09 13:43:59 . 2009-10-09 13:45:18 0 dc-h--w- C:\WINDOWS\ie8
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-03 15:38:27 . 2009-04-27 14:13:21 0 d-----w- C:\Documents and Settings\All Users\Application Data\Google Updater
2009-11-03 15:23:58 . 2009-04-27 14:21:02 0 d---a-w- C:\Documents and Settings\All Users\Application Data\TEMP
2009-11-02 16:42:49 . 2009-01-19 15:39:59 24478 ----a-w- C:\Documents and Settings\kenya\Application Data\wklnhst.dat
2009-11-02 15:11:24 . 2009-04-27 14:35:53 0 d-----w- C:\Documents and Settings\All Users\Application Data\avg8
2009-10-13 15:34:14 . 2005-04-28 04:47:27 0 d-----w- C:\Program Files\Jasc Software Inc
2009-09-11 14:18:39 . 2004-08-04 10:00:00 136192 ----a-w- C:\WINDOWS\system32\msv1_0.dll
2009-09-10 17:51:49 . 2009-04-23 18:48:03 0 d-----w- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2009-09-04 21:03:36 . 2004-08-04 10:00:00 58880 ----a-w- C:\WINDOWS\system32\msasn1.dll
2009-08-29 08:08:21 . 2004-08-04 10:00:00 916480 ----a-w- C:\WINDOWS\system32\wininet.dll
2009-08-28 14:31:33 . 2009-04-27 14:36:13 11952 ----a-w- C:\WINDOWS\system32\avgrsstx.dll
2009-08-28 14:31:33 . 2009-04-27 14:36:08 335240 ----a-w- C:\WINDOWS\system32\drivers\avgldx86.sys
2009-08-28 14:31:33 . 2009-04-27 14:36:07 27784 ----a-w- C:\WINDOWS\system32\drivers\avgmfx86.sys
2009-08-26 08:00:21 . 2004-08-04 10:00:00 247326 ----a-w- C:\WINDOWS\system32\strmdll.dll
2009-08-07 00:24:18 . 2004-08-04 10:00:00 327896 ----a-w- C:\WINDOWS\system32\wucltui.dll
2009-08-07 00:24:18 . 2004-08-04 10:00:00 209632 ----a-w- C:\WINDOWS\system32\wuweb.dll
2009-08-07 00:24:10 . 2008-10-16 20:09:44 44768 ----a-w- C:\WINDOWS\system32\wups2.dll
2009-08-07 00:24:10 . 2004-08-04 10:00:00 35552 ----a-w- C:\WINDOWS\system32\WUPS.DLL
2009-08-07 00:24:06 . 2004-08-04 10:00:00 53472 ----a-w- C:\WINDOWS\system32\wuauclt.exe
2009-08-07 00:24:04 . 2004-08-04 10:00:00 96480 ----a-w- C:\WINDOWS\system32\cdm.dll
2009-08-07 00:23:54 . 2004-08-04 10:00:00 575704 ----a-w- C:\WINDOWS\system32\wuapi.dll
2009-08-07 00:23:46 . 2004-08-04 10:00:00 1929952 ----a-w- C:\WINDOWS\system32\wuaueng.dll
2006-04-10 21:06:02 . 2006-04-10 21:06:02 848 --sha-w- C:\WINDOWS\SYSTEM32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 16:58:12 1107200]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-07-17 22:20:16 279944 ----a-w- C:\Program Files\AskBarDis\bar\bin\askBar.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-09-02 16:58:12 1107200 ----a-w- C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 16:58:12 1107200]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "C:\Program Files\AskBarDis\bar\bin\askBar.dll" [2008-07-17 22:20:16 279944]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-09-02 16:58:12 1107200]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "C:\Program Files\AskBarDis\bar\bin\askBar.dll" [2008-07-17 22:20:16 279944]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe" [2007-01-01 21:22:02 3739648]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2009-11-03 15:34:19 2028312]
"LogMeIn GUI"="C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" [2008-08-11 18:41:00 63048]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoActiveDesktop"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-28 14:31:33 11952 ----a-w- C:\WINDOWS\SYSTEM32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2009-09-29 01:34:30 87352 ----a-w- C:\WINDOWS\SYSTEM32\LMIinit.dll