This is the log file from Combofix. The first time I ran it, the commputer was at the opening screen. Thiis time, I was able to get a logfile.
Thank you.
Gary Ryan
ComboFix 12-03-16.05 - Gary 03/17/2012 22:41:27.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2045.593 [GMT -4:00]
Running from: c:\users\Gary\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2012 *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {61CDFD9D-3CAC-9270-C6FC-52325ACB795B}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\program files\WeatherBlink
c:\program files\WeatherBlink\bar\1.bin\CHROME.MANIFEST
c:\program files\WeatherBlink\bar\1.bin\chrome\gcffxtbr.jar
c:\program files\WeatherBlink\bar\1.bin\INSTALL.RDF
c:\program files\WeatherBlink\bar\1.bin\LOGO.BMP
c:\program files\WeatherBlink\bar\IE9Mesg\COMMON.T8S
c:\program files\WeatherBlink\bar\Message\COMMON.T8S
c:\program files\WeatherBlink\bar\Settings\s_pid.dat
c:\program files\WeatherBlinkEI
c:\users\Gary\AppData\Local\WeatherBlink Installer(0050eda9).exe
c:\users\Gary\AppData\Local\WeatherBlink Installer(0060d106).exe
c:\users\Gary\AppData\Local\WeatherBlink Installer(00a5b0da).exe
c:\users\Gary\AppData\Local\WeatherBlink Installer(00b7f089).exe
c:\users\Gary\AppData\Local\WeatherBlink Installer(0106bfab).exe
c:\users\Gary\AppData\Local\WeatherBlink Installer(013b5b9d).exe
c:\users\Gary\AppData\Local\WeatherBlink Installer(013fea54).exe
c:\users\Gary\AppData\Local\WeatherBlink Installer(01a255a6).exe
c:\users\Gary\AppData\Local\WeatherBlink Installer(021f13e8).exe
c:\users\Gary\AppData\Local\WeatherBlink Installer(02b2cd1c).exe
c:\users\Gary\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Check
c:\windows\~GLC0000.TMP
c:\windows\~GLC0001.TMP
.
.
((((((((((((((((((((((((( Files Created from 2012-02-18 to 2012-03-18 )))))))))))))))))))))))))))))))
.
.
2012-03-18 03:00 . 2012-03-18 03:00 -------- d-----w- c:\users\TEMP\AppData\Local\temp
2012-03-18 03:00 . 2012-03-18 03:00 -------- d-----w- c:\users\RYANPC-PC\AppData\Local\temp
2012-03-18 03:00 . 2012-03-18 03:00 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-03-17 07:20 . 2012-03-18 04:38 -------- d-----w- c:\users\Gary\AppData\Local\temp
2012-03-17 00:57 . 2012-03-17 00:57 -------- d-----w- c:\users\Gary\AppData\Roaming\SpeedyPC Software
2012-03-17 00:57 . 2012-03-17 00:57 -------- d-----w- c:\users\Gary\AppData\Roaming\DriverCure
2012-03-17 00:56 . 2012-03-17 05:20 -------- d-----w- c:\programdata\SpeedyPC Software
2012-03-15 16:29 . 2012-03-15 16:29 319456 ----a-w- c:\windows\DIFxAPI.dll
2012-03-13 22:05 . 2012-02-02 15:16 2044416 ----a-w- c:\windows\system32\win32k.sys
2012-03-13 22:05 . 2012-02-14 15:45 219648 ----a-w- c:\windows\system32\d3d10_1core.dll
2012-03-13 22:05 . 2012-02-14 15:45 160768 ----a-w- c:\windows\system32\d3d10_1.dll
2012-03-13 22:05 . 2012-02-13 14:12 1172480 ----a-w- c:\windows\system32\d3d10warp.dll
2012-03-13 22:05 . 2012-02-13 13:47 683008 ----a-w- c:\windows\system32\d2d1.dll
2012-03-13 22:05 . 2012-02-13 13:44 1068544 ----a-w- c:\windows\system32\DWrite.dll
2012-03-13 22:05 . 2012-01-31 10:59 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2012-03-13 22:04 . 2012-01-09 15:54 613376 ----a-w- c:\windows\system32\rdpencom.dll
2012-03-13 22:04 . 2012-01-09 13:58 180736 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-03-13 04:30 . 2012-03-13 04:32 -------- d-----w- c:\users\Gary\MusicUntitled - 03-13-12
2012-03-08 18:53 . 2012-03-08 18:53 -------- dc----w- C:\_OTM
2012-03-07 18:20 . 2012-03-07 18:20 -------- d-----w- c:\program files\ESET
2012-02-28 05:10 . 2012-02-28 05:10 -------- d-----w- c:\users\Gary\AppData\Roaming\Malwarebytes
2012-02-28 05:09 . 2012-02-28 05:09 -------- d-----w- c:\programdata\Malwarebytes
2012-02-28 05:09 . 2011-12-10 20:24 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-02-28 05:09 . 2012-02-28 05:10 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-17 20:04 . 2011-05-18 17:01 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-16 04:17 . 2011-06-26 05:46 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2010-08-30 23:47 . 2008-01-30 04:06 119808 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5}]
2010-08-26 10:43 349624 ----a-w- c:\progra~1\SITERA~1\SiteRank.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2012-01-18 23:21 1811296 ----a-w- c:\program files\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a7347e8c-1ca6-469b-951e-4a23c4437935}]
2010-02-23 01:55 2349080 ----a-w- c:\program files\TV_Center\tbTV_1.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{4E7BD74F-2B8D-469E-C0FF-FD7FA18DBF33}"= "c:\progra~1\NexusBar\nexusbar.dll" [2006-11-06 1823744]
"{a7347e8c-1ca6-469b-951e-4a23c4437935}"= "c:\program files\TV_Center\tbTV_1.dll" [2010-02-23 2349080]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\10.0.0.7\AVG Secure Search_toolbar.dll" [2012-01-18 1811296]
.
[HKEY_CLASSES_ROOT\clsid\{4e7bd74f-2b8d-469e-c0ff-fd7fa18dbf33}]
[HKEY_CLASSES_ROOT\nexusbar.NEXUSBAR]
.
[HKEY_CLASSES_ROOT\clsid\{a7347e8c-1ca6-469b-951e-4a23c4437935}]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{A7347E8C-1CA6-469B-951E-4A23C4437935}"= "c:\program files\TV_Center\tbTV_1.dll" [2010-02-23 2349080]
.
[HKEY_CLASSES_ROOT\clsid\{a7347e8c-1ca6-469b-951e-4a23c4437935}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Logitech BT Wizard"="LBTWiz.exe -silent" [X]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-17 4907008]
"Logitech Hardware Abstraction Layer"="c:\program files\Common Files\Logitech\khalshared\KHALMNPR.EXE" [2007-10-09 100888]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-10-09 100888]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2008-07-10 46368]
"CTPDPSRV"="c:\windows\System32\spool\drivers\w32x86\3\CTpdpsrv.exe" [2001-09-18 45056]
"Bluetooth HCI Monitor"="HCIMNTR.DLL" [2006-12-07 9728]
"Belkin Storage Manager"="c:\program files\Belkin Storage Manager\StorageManager.exe" [2009-02-03 858624]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-01-24 2416480]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-28 207424]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2009-01-09 114688]
"BrStsMon00"="c:\program files\Browny02\Brother\BrStMonW.exe" [2010-02-09 2621440]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-02 59240]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-12-08 421736]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-01-04 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]
"TkBellExe"="c:\program files\Real\realplayer\update\realsched.exe" [2011-04-08 273544]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"AutoLaunch"="c:\program files\Lavasoft\Ad-Aware\AutoLaunch.exe" [2011-06-13 669936]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-2-13 715568]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-9-10 50688]
SetPoint.lnk - c:\program files\SetPoint\SetPoint.exe [2011-11-27 679936]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0autocheck lsdelete\0autocheck lsdelete\0autocheck lsdelete\0autocheck lsdelete\0autocheck lsdelete\0autocheck lsdelete\0autocheck lsdelete\0autocheck lsdelete\0autocheck lsdelete\0autocheck lsdelete\0autocheck lsdelete\0autocheck lsdelete\0autocheck c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ROC_roc_dec12]
2012-01-18 23:21 928096 ----a-w- c:\program files\AVG Secure Search\ROC_roc_dec12.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vProt]
2012-01-18 23:21 939872 ----a-w- c:\program files\AVG Secure Search\vprot.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
.
R4 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [2007-12-05 77824]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2012-03-17 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 17:40]
.
2012-03-17 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-09-21 22:30]
.
2012-03-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-28 21:45]
.
2012-03-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-28 21:45]
.
2012-02-28 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\Dell Support Center\uaclauncher.exe [2012-02-07 23:02]
.
2012-03-17 c:\windows\Tasks\SystemToolsDailyTest.job
- c:\program files\Dell Support Center\uaclauncher.exe [2012-02-07 23:02]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
IE: Crawler Search - tbr:iemenu
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D1E1F7ED622A0E5D.dll/cmsidewiki.html
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
LSP: xfire_lsp_9028.dll
TCP: DhcpNameServer = 192.168.2.1 192.168.2.1
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\Toolbar\ctbr.dll
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\10.0.6\ViProtocol.dll
FF - ProfilePath - c:\users\Gary\AppData\Roaming\Mozilla\Firefox\Profiles\dc0e44lf.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3003485&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT3003485&SearchSource=13
FF - prefs.js: keyword.URL - hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=XNxdm016YYus&ptnrS=XNxdm016YYus&ptb=67E1AB6E-AB04-438F-98F7-9DDF0D8E9C55&psa=&ind=2012021017&st=kwd&n=77ed0119&searchfor=
FF - user.js: yahoo.homepage.dontask - true);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{CCB69577-088B-4004-9ED8-FF5BCC83A039} - (no file)
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
HKCU-Run-Start WingMan Profiler - (no file)
HKU-Default-RunOnce-RealUpgradeHelper - c:\program files\Common Files\Real\Update_OB\upgrdhlp.exe
MSConfigStartUp-unYHREDALK - c:\programdata\unYHREDALK.exe
MSConfigStartUp-WeatherBlink Browser Plugin Loader - c:\progra~1\WEATHE~2\bar\1.bin\gcbrmon.exe
AddRemove-Aim Plugin for QQ Games - c:\program files\Tencent\QQ Games\Plugin\Uninstall.EXE
AddRemove-IL-2 Sturmovik - c:\windows\UbiSoft\SetupUbi.exe
AddRemove-QQ Bubble Arena - c:\program files\Tencent\QQ Games\QQ Bubble Arena\Uninstall.EXE
AddRemove-QQ Games - c:\program files\Tencent\QQ Games\Uninstall.EXE
AddRemove-QQ Pool - c:\program files\Tencent\QQ Games\QQ Pool\Uninstall.EXE
AddRemove-Random House Webster's Unabridged Dictionary - c:\program files\Random House
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2012-03-18 00:37
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2012-03-18 00:56:36
ComboFix-quarantined-files.txt 2012-03-18 04:56
.
Pre-Run: 204,651,622,400 bytes free
Post-Run: 204,589,596,672 bytes free
.
- - End Of File - - 04163E0E5016593D32E3190F6D6B1442