Here is a new combofix log with the latest version (by the way, should I be running this on both computers or just this one?)
ComboFix 09-07-14.08 - Jeremy Hay 17/07/2009 20:37.3.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1534 [GMT 12:00]
Running from: c:\my documents\Downloads\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((( Files Created from 2009-06-17 to 2009-07-17 )))))))))))))))))))))))))))))))
.
2009-07-13 02:42 . 2009-07-13 02:43 -------- d-----w- e:\documents and settings\Jeremy Hay\.SunDownloadManager
2009-07-12 11:04 . 2009-07-12 11:04 -------- d-----w- e:\documents and settings\Jeremy Hay\Application Data\Malwarebytes
2009-07-12 11:04 . 2009-06-16 23:27 38160 ----a-w- e:\windows\system32\drivers\mbamswissarmy.sys
2009-07-12 11:04 . 2009-07-12 11:04 -------- d-----w- e:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-12 11:04 . 2009-06-16 23:27 19096 ----a-w- e:\windows\system32\drivers\mbam.sys
2009-07-12 11:04 . 2009-07-12 11:04 -------- d-----w- e:\program files\Malwarebytes' Anti-Malware
2009-07-09 23:44 . 2009-06-29 05:19 327688 ----a-w- e:\documents and settings\All Users\Application Data\avg8\update\backup\avgldx86.sys
2009-07-09 23:44 . 2009-06-29 05:19 2052376 ----a-w- e:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-07-09 23:44 . 2009-06-29 05:19 906520 ----a-w- e:\documents and settings\All Users\Application Data\avg8\update\backup\avgemc.exe
2009-07-09 23:44 . 2009-06-29 05:19 493336 ----a-w- e:\documents and settings\All Users\Application Data\avg8\update\backup\avgtbapi.dll
2009-07-09 23:44 . 2009-06-29 05:19 3402008 ----a-w- e:\documents and settings\All Users\Application Data\avg8\update\backup\avgui.exe
2009-07-09 23:44 . 2009-06-29 05:19 2167576 ----a-w- e:\documents and settings\All Users\Application Data\avg8\update\backup\avgresf.dll
2009-07-09 23:44 . 2009-06-29 05:19 1204504 ----a-w- e:\documents and settings\All Users\Application Data\avg8\update\backup\avgabout.dll
2009-07-09 23:43 . 2009-06-29 05:19 337176 ----a-w- e:\documents and settings\All Users\Application Data\avg8\update\backup\avglogx.dll
2009-07-09 23:43 . 2009-06-29 05:19 829208 ----a-w- e:\documents and settings\All Users\Application Data\avg8\update\backup\avgcfgx.dll
2009-07-09 23:43 . 2009-06-29 05:19 3298072 ----a-w- e:\documents and settings\All Users\Application Data\avg8\update\backup\setup.exe
2009-07-09 23:42 . 2009-06-29 05:15 1454360 ----a-w- e:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.dll
2009-07-09 23:42 . 2009-06-29 05:15 1085208 ----a-w- e:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.exe
2009-07-07 05:54 . 2009-07-11 01:51 -------- d-----w- e:\documents and settings\Jeremy Hay\Application Data\Canon
2009-07-07 03:00 . 2009-07-15 03:57 -------- d-----w- E:\Dane
2009-07-06 21:54 . 2008-04-14 01:11 21504 ----a-w- e:\windows\system32\drivers\hidserv.dll
2009-07-04 23:41 . 2009-07-04 23:41 -------- d-----w- e:\program files\Trend Micro
2009-07-03 00:10 . 2006-01-15 23:45 360288 ----a-w- e:\windows\system32\drivers\ar5523.sys
2009-07-03 00:10 . 2006-01-15 23:45 360288 ----a-w- e:\windows\system32\ar5523.sys
2009-07-03 00:10 . 2005-07-27 09:16 44160 ----a-w- e:\windows\system32\athfmwdl.sys
2009-07-03 00:10 . 2005-07-27 09:15 149392 ----a-w- e:\windows\system32\drivers\ar5523.bin
2009-07-03 00:10 . 2005-07-27 09:15 149392 ----a-w- e:\windows\system32\ar5523.bin
2009-07-02 12:31 . 2009-07-02 12:31 -------- d-----w- e:\documents and settings\Jeremy Hay\Local Settings\Application Data\AVG Security Toolbar
2009-06-30 12:22 . 2009-06-30 12:22 -------- d-----w- e:\windows\usb-audio.deTascam
2009-06-30 10:28 . 2009-06-30 10:28 -------- d-----w- e:\program files\Common Files\Adobe Systems Shared
2009-06-29 23:17 . 2009-07-04 01:56 -------- d-----w- E:\Audition files
2009-06-29 05:19 . 2009-06-29 05:19 832144 ----a-w- e:\documents and settings\All Users\Application Data\avg8\update\backup\AVGToolbarInstall.exe
2009-06-29 05:19 . 2009-06-29 05:19 -------- d-----w- e:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-06-29 05:19 . 2009-06-29 05:19 -------- d-----w- e:\documents and settings\LocalService\Application Data\AVGTOOLBAR
2009-06-27 05:18 . 2004-05-20 20:04 79622 ----a-w- e:\windows\system32\EBPMON24.DLL
2009-06-27 05:18 . 2004-02-17 16:10 98304 ----a-w- e:\windows\system32\E_SAGSET.DLL
2009-06-27 05:18 . 2003-07-16 04:14 31744 ----a-w- e:\windows\system32\E_DCINST.DLL
2009-06-27 05:18 . 2003-05-20 17:27 64000 ----a-w- e:\windows\system32\ECBTEG.DLL
2009-06-27 05:18 . 2000-06-06 16:01 34304 ----a-w- e:\windows\system32\EBPCHP.DLL
2009-06-27 05:18 . 2008-04-13 19:47 25856 -c--a-w- e:\windows\system32\dllcache\usbprint.sys
2009-06-27 05:18 . 2008-04-13 19:47 25856 ----a-w- e:\windows\system32\drivers\usbprint.sys
2009-06-27 05:11 . 2009-06-27 05:11 -------- d-----w- e:\program files\Canon
2009-06-27 05:10 . 2009-06-27 05:10 -------- d-----w- e:\documents and settings\Jeremy Hay\Application Data\ScanSoft
2009-06-27 05:10 . 2009-06-27 05:10 -------- d-----w- e:\documents and settings\All Users\Application Data\SSScanWizard
2009-06-27 05:10 . 2009-06-27 05:10 -------- d-----w- e:\documents and settings\All Users\Application Data\SSScanAppDataDir
2009-06-27 05:10 . 2009-06-27 05:10 -------- d-----w- e:\program files\Common Files\ScanSoft Shared
2009-06-27 05:10 . 2009-06-27 05:10 -------- d-----w- e:\program files\ScanSoft
2009-06-27 05:09 . 2002-05-23 15:04 389180 ----a-w- e:\windows\system32\UCS32P.DLL
2009-06-27 05:09 . 2002-09-27 02:56 69632 ----a-w- e:\windows\system32\CNQU70.DLL
2009-06-27 05:09 . 2002-04-12 08:23 339968 ----a-w- e:\windows\system32\N124UFW.dll
2009-06-27 05:09 . 2009-06-27 05:09 -------- d--h--w- E:\CanoScan
2009-06-27 04:34 . 2004-11-30 04:00 286720 ----a-r- e:\windows\878RMT.exe
2009-06-27 04:34 . 2009-06-27 04:34 -------- d-----w- e:\windows\MyInstall
2009-06-27 04:33 . 2009-06-27 04:33 -------- d-----w- e:\program files\honestech
2009-06-27 04:33 . 2001-05-16 04:54 309616 ----a-w- e:\windows\system32\wmv8dmod.dll
2009-06-27 04:33 . 2001-05-11 00:18 420240 ----a-w- e:\windows\system32\mpg4c32.dll
2009-06-27 04:32 . 2005-01-28 04:00 9216 ----a-r- e:\windows\system32\drivers\BtTuner.sys
2009-06-27 04:32 . 2005-01-28 04:00 8448 ----a-r- e:\windows\system32\drivers\BtXbar.sys
2009-06-27 04:32 . 2005-01-28 04:00 196736 ----a-r- e:\windows\system32\drivers\Bt878.sys
2009-06-27 04:30 . 2009-06-27 04:31 -------- d-----w- e:\windows\MustRead
2009-06-27 04:17 . 2009-06-27 04:17 8 ----a-w- e:\windows\system32\nvModes.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-16 22:25 . 2007-04-17 20:59 -------- d-----w- e:\documents and settings\Jeremy Hay\Application Data\Orbit
2009-07-16 22:24 . 2007-12-14 03:40 -------- d-----w- e:\documents and settings\All Users\Application Data\Google Updater
2009-07-16 22:24 . 2007-12-17 20:56 -------- d-----w- e:\documents and settings\Jeremy Hay\Application Data\WTablet
2009-07-13 03:15 . 2008-10-04 21:50 410984 ----a-w- e:\windows\system32\deploytk.dll
2009-07-09 23:43 . 2008-06-16 21:02 335752 ----a-w- e:\windows\system32\drivers\avgldx86.sys
2009-07-09 04:06 . 2008-02-05 01:27 -------- d-----w- e:\documents and settings\Jeremy Hay\Application Data\dvdcss
2009-07-08 04:49 . 2007-04-20 09:56 12884 --sha-w- e:\windows\system32\KGyGaAvL.sys
2009-07-07 23:07 . 2008-10-22 21:13 -------- d-----w- e:\documents and settings\LocalService\Application Data\WTablet
2009-07-06 21:55 . 2009-07-06 21:55 0 ---ha-w- e:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2009-07-06 21:55 . 2009-07-06 21:55 0 ---ha-w- e:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-07-03 23:15 . 2009-03-10 12:17 664 ----a-w- e:\windows\system32\d3d9caps.dat
2009-07-03 22:29 . 2007-04-16 04:39 -------- d--h--w- e:\program files\InstallShield Installation Information
2009-06-30 12:10 . 2007-04-16 06:06 26040 ----a-w- e:\documents and settings\Jeremy Hay\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-30 11:33 . 2007-04-16 04:41 -------- d-----w- e:\program files\Common Files\Adobe
2009-06-30 10:29 . 2009-06-30 10:29 -------- d-----w- e:\documents and settings\All Users\Application Data\Adobe Systems
2009-06-30 00:06 . 2008-09-12 04:13 -------- d-----w- e:\program files\Belkin
2009-06-29 05:19 . 2008-06-16 21:02 11952 ----a-w- e:\windows\system32\avgrsstx.dll
2009-06-29 05:19 . 2007-04-23 05:10 27784 ----a-w- e:\windows\system32\drivers\avgmfx86.sys
2009-06-27 05:16 . 2007-04-21 02:14 -------- d-----w- e:\program files\EPSON
2009-06-24 10:33 . 2009-06-14 12:27 -------- d-----w- e:\program files\TP-LINK
2009-06-14 12:39 . 2009-06-14 10:42 146976 ----a-w- e:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-06-14 12:07 . 2009-06-14 12:07 -------- d-----w- e:\program files\PC Drivers HeadQuarters
2009-06-14 12:07 . 2009-06-14 12:07 -------- d-----w- e:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2009-06-14 12:07 . 2007-04-17 09:44 -------- d-----w- e:\documents and settings\Jeremy Hay\Application Data\GetRightToGo
2009-06-14 10:14 . 2009-06-14 10:12 -------- d-----w- e:\documents and settings\All Users\Application Data\Linksys
2009-06-14 10:13 . 2009-06-14 10:13 -------- d-----w- e:\program files\WebEx
2009-06-14 10:12 . 2007-04-28 02:21 -------- d-----w- e:\program files\Java
2009-05-22 13:39 . 2009-05-20 05:49 -------- d-----w- e:\documents and settings\Jeremy Hay\Application Data\.purple
2009-05-22 13:28 . 2009-05-22 13:28 2087 ----a-w- e:\documents and settings\Jeremy Hay\Application Data\.purple\certificates\x509\tls_peers\omega.contacts.msn.com
2009-05-20 05:52 . 2009-05-20 05:52 1065 ----a-w- e:\documents and settings\Jeremy Hay\Application Data\.purple\certificates\x509\tls_peers\gmail.com
2009-05-20 05:49 . 2009-05-20 05:49 2099 ----a-w- e:\documents and settings\Jeremy Hay\Application Data\.purple\certificates\x509\tls_peers\login.live.com
2009-05-20 05:49 . 2009-05-20 05:49 -------- d-----w- e:\documents and settings\Jeremy Hay\Application Data\gtk-2.0
2009-05-20 05:47 . 2009-05-20 05:47 -------- d-----w- e:\program files\Common Files\GTK
2009-05-20 05:11 . 2009-05-20 05:11 -------- d-----w- e:\program files\Microsoft
2009-05-20 05:11 . 2009-05-20 05:11 -------- d-----w- e:\program files\Windows Live SkyDrive
2009-05-20 05:11 . 2008-06-03 22:54 -------- d-----w- e:\program files\Windows Live
2009-05-20 05:09 . 2009-05-20 05:09 -------- d-----w- e:\program files\Common Files\Windows Live
2009-05-08 13:14 . 2009-05-08 13:14 1418120 ----a-w- e:\windows\system32\wdfcoinstaller01005.dll
2009-05-08 13:14 . 2009-05-08 13:14 14736 ----a-w- e:\windows\system32\drivers\nuidfltr.sys
2009-05-07 15:32 . 2004-08-04 12:00 345600 ----a-w- e:\windows\system32\localspl.dll
2009-05-02 22:28 . 2008-06-16 21:02 108552 ----a-w- e:\windows\system32\drivers\avgtdix.sys
2009-04-29 04:56 . 2004-08-04 12:00 827392 ----a-w- e:\windows\system32\wininet.dll
2009-04-29 04:55 . 2004-08-04 12:00 78336 ----a-w- e:\windows\system32\ieencode.dll
2009-05-01 04:44 . 2008-06-17 23:59 134648 ----a-w- e:\program files\mozilla firefox\components\brwsrcmp.dll
2007-01-23 02:07 . 2007-06-08 07:45 1847296 ----a-w- e:\program files\mozilla firefox\plugins\Seadragon.dll
2007-06-04 03:18 . 2007-04-20 09:56 56 --sh--r- e:\windows\system32\72E1C1C693.sys
.
((((((((((((((((((((((((((((( SnapShot@2009-07-10_00.14.52 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-16 22:23 . 2009-07-16 22:23 16384 e:\windows\Temp\Perflib_Perfdata_f4.dat
+ 2009-07-13 03:15 . 2009-07-13 03:15 148888 e:\windows\system32\javaws.exe
+ 2009-07-13 03:15 . 2009-07-13 03:15 144792 e:\windows\system32\javaw.exe
+ 2009-07-13 03:15 . 2009-07-13 03:15 144792 e:\windows\system32\java.exe
+ 2009-07-13 03:15 . 2009-07-13 03:15 1563648 e:\windows\Installer\28e6d3.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-14 04:07 1004800 ----a-w- e:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "e:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-06-14 1004800]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="e:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="e:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-12-14 68856]
"MsnMsgr"="e:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408]
"MSMSGS"="e:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Google Update"="e:\documents and settings\Jeremy Hay\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-03 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TV Card Remote Control Applet"="e:\windows\878RMT.exe" [2004-11-30 286720]
"WinampAgent"="e:\program files\Winamp\winampa.exe" [2007-05-14 35328]
"UpdReg"="e:\windows\UpdReg.EXE" [2000-05-10 90112]
"QuickTime Task"="e:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"PhilipsSA33XXDM"="e:\program files\Philips\SA33XX\Philips Device Manager\Bin\SA33XXDeviceManager.exe" [2007-08-06 892928]
"Omnipage"="e:\program files\ScanSoft\OmniPageSE\opware32.exe" [2002-06-02 49152]
"NvMediaCenter"="e:\windows\system32\NvMcTray.dll" [2009-02-18 86016]
"NvCplDaemon"="e:\windows\system32\NvCpl.dll" [2009-02-18 13680640]
"NeroFilterCheck"="e:\windows\system32\NeroCheck.exe" [2001-07-08 155648]
"IntelliPoint"="e:\program files\Microsoft IntelliPoint\ipoint.exe" [2005-12-04 461584]
"googletalk"="e:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"EPSON Stylus C45 Series"="e:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I3T1.EXE" [2004-01-13 99840]
"CTSysVol"="e:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-02-15 57344]
"AVG8_TRAY"="e:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-29 1948440]
"AppleSyncNotifier"="e:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-30 111936]
"Adobe Reader Speed Launcher"="e:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"Adobe Acrobat Speed Launcher"="e:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2009-02-27 38768]
"Acrobat Assistant 8.0"="e:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2009-02-27 640376]
"SunJavaUpdateSched"="e:\program files\Java\jre6\bin\jusched.exe" [2009-07-13 148888]
"SkyTel"="SkyTel.EXE" - e:\windows\SkyTel.exe [2006-05-16 2879488]
"RTHDCPL"="RTHDCPL.EXE" - e:\windows\RTHDCPL.EXE [2006-11-14 16270848]
"P17Helper"="P17.dll" - e:\windows\system32\P17.dll [2006-03-17 81408]
"nwiz"="nwiz.exe" - e:\windows\system32\nwiz.exe [2009-02-18 1657376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="e:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - e:\windows\system32\narrator.exe [2008-04-14 53760]
e:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma.lnk - e:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
Launchy.lnk - e:\program files\Launchy\Launchy.exe [2007-10-1 274432]
Microsoft Office.lnk - e:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Orbit.lnk - e:\program files\Orbitdownloader\orbitdm.exe [2007-4-18 1690824]
QuickBooks Update Agent.lnk - e:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2007-4-20 972320]
ScheduleTV.lnk - e:\program files\honestech\honestech TVR\scheduleTV.exe [2009-6-27 307200]
TabUserW.exe.lnk - e:\windows\system32\WTablet\TabUserW.exe [2007-4-17 132656]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-06-29 05:19 11952 ----a-w- e:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Bonjour Service"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"e:\\Program Files\\Orbitdownloader\\orbitnet.exe"=
R1 AvgLdx86;AVG AVI Loader Driver x86;e:\windows\system32\drivers\avgldx86.sys [17/06/2008 9:02 a.m. 335752]
R1 AvgTdiX;AVG8 Network Redirector;e:\windows\system32\drivers\avgtdix.sys [17/06/2008 9:02 a.m. 108552]
R2 878TVCard;Bt878 TV Card - Video Capture;e:\windows\system32\drivers\Bt878.sys [27/06/2009 4:32 p.m. 196736]
R2 878TVTuner;Bt878 TV Card - TV Tuner;e:\windows\system32\drivers\BtTuner.sys [27/06/2009 4:32 p.m. 9216]
R2 878Xbar;Bt878 TV Card - Crossbar;e:\windows\system32\drivers\BtXbar.sys [27/06/2009 4:32 p.m. 8448]
R2 avg8emc;AVG Free8 E-mail Scanner;e:\progra~1\AVG\AVG8\avgemc.exe [4/07/2008 9:13 a.m. 907032]
R2 avg8wd;AVG8 WatchDog;e:\progra~1\AVG\AVG8\avgwdsvc.exe [4/07/2008 9:12 a.m. 298776]
R3 p17filt;p17filt;e:\windows\system32\drivers\p17filt.sys [20/03/2006 6:34 p.m. 1452032]
S3 TASCAM_US122144;TASCAM USB 2.0 Audio Device driver;e:\windows\system32\drivers\tascusb2.sys [21/05/2009 3:47 p.m. 396192]
S3 TASCAM_US144_MIDI;TASCAM US-144 WDM MIDI Device;e:\windows\system32\drivers\tscusb2m.sys [21/05/2009 3:47 p.m. 10752]
S3 TASCAM_US144_WDM;TASCAM US-144 WDM;e:\windows\system32\drivers\tscusb2a.sys [21/05/2009 3:47 p.m. 19904]
S3 V0090VID;Creative WebCam Vista Plus;e:\windows\system32\drivers\V0090Vid.sys [31/03/2008 8:17 a.m. 138112]
.
Contents of the 'Scheduled Tasks' folder
2009-07-03 e:\windows\Tasks\AppleSoftwareUpdate.job
- e:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 00:34]
2009-07-17 e:\windows\Tasks\Google Software Updater.job
- e:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-12-14 07:28]
2009-07-16 e:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-220523388-616249376-725345543-1004Core.job
- e:\documents and settings\Jeremy Hay\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-03 10:44]
2009-07-17 e:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-220523388-616249376-725345543-1004UA.job
- e:\documents and settings\Jeremy Hay\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-03 10:44]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &Download by Orbit - e:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - e:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Append Link Target to Existing PDF - e:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - e:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - e:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - e:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Do&wnload selected by Orbit - e:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - e:\program files\Orbitdownloader\orbitmxt.dll/202
IE: E&xport to Microsoft Excel - e:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
TCP: {D86DD133-9159-47B3-B340-588CF0A2828E} = 58.28.4.2,58.28.6.2
FF - ProfilePath - e:\documents and settings\Jeremy Hay\Application Data\Mozilla\Firefox\Profiles\b32aab5b.default\
FF - prefs.js: browser.search.selectedEngine - Dictionary.com
FF - prefs.js: browser.startup.homepage - hxxp://google.com/
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1641676&SearchSource=2&q=
FF - component: e:\documents and settings\Jeremy Hay\Application Data\Mozilla\Firefox\Profiles\b32aab5b.default\extensions\piclens@cooliris. com\components\coolirisstub.dll
FF - component: e:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: e:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils 2.dll
FF - component: e:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils 3.dll
FF - component: e:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils 35.dll
FF - component: e:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: e:\documents and settings\Jeremy Hay\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: e:\program files\eMusic Download Manager\plugin\npemusic.dll
FF - plugin: e:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: e:\program files\Mozilla Firefox\plugins\nppsynth.dll
FF - plugin: e:\windows\system32\Photosynth\nppsynth.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-17 20:44
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
TV Card Remote Control Applet = e:\windows\878RMT.exe?????????????????????????????????????????????????????? ?????????????????????????????????????????????????????6?B~!?B~9???????T???q? @?9????8????@?X???????????????d???9???Bt878 TV Card Remote Control Receiver?@?????????W?SN????:?A~}(@?z????(@
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:06,24,62,cd,bf,cf,1c,af,2a,20,02,ed,16,ea,eb,ea,b7,7d,5b,e1,0 9,
bd,5e,7b,c9,72,93,ab,bd,ef,68,e9,2f,36,c1,fb,23,61,94,1a,bc,37,9d,c2,fa,a4, \
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\User Data\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•A~*]
"5E7CEC10DF0760D4F8DAFB12FDC06CCD"="02:\\Software\\Adobe\\FeatureSubscripti ons\\DVAAdobeDocMeta\\{01CEC7E5-70FD-4D06-8FAD-BF21DF0CC6DC}\\Registered"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\User Data\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•A~*]
"5E7CEC10DF0760D4F8DAFB12FDC06CCD"="02:\\Software\\Adobe\\FeatureSubscripti ons\\DVAAdobeDocMeta\\{01CEC7E5-70FD-4D06-8FAD-BF21DF0CC6DC}\\Registered"
[HKEY_LOCAL_MACHINE\software\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:06,24,62,cd,bf,cf,1c,af,2a,20,02,ed,16,ea,eb,ea,b7,7d,5b,e1,0 9,
bd,5e,7b,c9,72,93,ab,bd,ef,68,e9,2f,36,c1,fb,23,61,94,1a,bc,37,9d,c2,fa,a4, \
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2588)
e:\program files\ScanSoft\OmniPageSE\ophook32.dll
e:\windows\system32\WPDShServiceObj.dll
e:\windows\system32\PortableDeviceTypes.dll
e:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-07-17 20:46
ComboFix-quarantined-files.txt 2009-07-17 08:46
ComboFix2.txt 2009-07-11 00:26
ComboFix3.txt 2009-07-10 00:19
Pre-Run: 116,319,576,064 bytes free
Post-Run: 116,357,439,488 bytes free
277 --- E O F --- 2009-07-06 21:55