Thank you once again. Here's the log from ComboFix.
ComboFix 10-06-30.02 - Lillian 06/30/2010 21:29:30.1.1 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.1.1033.18.1915.1224 [GMT -4:00]
Running from: c:\users\Lillian\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Files Created from 2010-06-01 to 2010-07-01 )))))))))))))))))))))))))))))))
.
2010-07-01 01:40 . 2010-07-01 01:41 -------- d-----w- c:\users\Lillian\AppData\Local\temp
2010-07-01 01:40 . 2010-07-01 01:40 -------- d-----w- c:\users\s\AppData\Local\temp
2010-07-01 01:40 . 2010-07-01 01:40 -------- d-----w- c:\users\Guest\AppData\Local\temp
2010-07-01 01:40 . 2010-07-01 01:40 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-06-29 16:02 . 2010-06-29 16:02 -------- d-----w- c:\program files\Trend Micro
2010-06-28 04:00 . 2010-06-28 04:00 -------- d-----w- C:\7d5341a17ef6849de81c9abb1dd5
2010-06-27 07:00 . 2010-06-27 07:00 -------- d-----w- C:\55b67a2855b21e3ee9b56f709adc
2010-06-27 03:12 . 2010-06-27 03:12 52224 --sha-r- c:\users\Lillian\AppData\Roaming\msxml3J.dll
2010-06-26 22:57 . 2010-06-26 22:57 45056 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimwmp.dll
2010-06-26 22:57 . 2010-06-26 22:57 45056 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimswf.dll
2010-06-26 22:57 . 2010-06-26 22:57 45056 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimrp.dll
2010-06-26 22:57 . 2010-06-26 22:57 45056 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\ThinShims\rpnpshimqt.dll
2010-06-26 22:57 . 2010-06-26 22:57 49152 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\Components\nprpffbrowserrecordext.dll
2010-06-26 22:57 . 2010-06-26 22:57 308808 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Common\rpmainbrowserrecordplugin.dll
2010-06-26 22:57 . 2010-06-26 22:57 14848 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
2010-06-26 22:57 . 2010-06-26 22:57 40960 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
2010-06-26 22:57 . 2010-06-26 22:57 341600 ----a-w- c:\programdata\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
2010-06-26 22:54 . 2010-06-26 22:54 -------- d-----w- c:\program files\Common Files\xing shared
2010-06-26 22:51 . 2010-06-26 22:51 348160 ----a-w- c:\windows\system32\pnup0.dll
2010-06-23 21:39 . 2009-11-08 14:55 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-06-23 21:39 . 2009-11-08 14:55 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-06-23 21:39 . 2009-11-08 14:55 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-06-23 21:39 . 2009-11-08 14:55 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-06-23 21:39 . 2009-11-08 14:55 1130824 ----a-w- c:\windows\system32\dfshim.dll
2010-06-23 16:10 . 2010-04-16 16:43 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2010-06-23 16:10 . 2010-04-16 14:39 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2010-06-18 01:37 . 2010-06-18 01:37 -------- d-----w- c:\programdata\AIM
2010-06-18 01:36 . 2010-06-18 01:37 -------- d-----w- c:\program files\AIM
2010-06-18 01:36 . 2010-06-18 01:36 -------- d-----w- c:\program files\Common Files\Software Update Utility
2010-06-14 05:28 . 2010-06-14 05:28 -------- d-----w- c:\programdata\Adobe Systems
2010-06-14 05:12 . 2010-06-14 05:12 -------- d-----w- c:\program files\Common Files\Adobe Systems Shared
2010-06-10 21:38 . 2010-04-05 17:01 67072 ----a-w- c:\windows\system32\asycfilt.dll
2010-06-10 21:34 . 2010-05-26 14:47 289792 ----a-w- c:\windows\system32\atmfd.dll
2010-06-10 21:34 . 2010-05-26 17:06 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-06-10 21:34 . 2010-05-01 14:13 2037248 ----a-w- c:\windows\system32\win32k.sys
2010-06-10 15:57 . 2010-06-10 15:57 -------- d-----w- c:\users\Lillian\New Folder
2010-06-04 04:23 . 2010-06-04 04:23 -------- d-----w- c:\windows\system32\Adobe
2010-06-03 23:41 . 2010-06-03 23:41 50354 ----a-w- c:\users\Lillian\AppData\Roaming\Facebook\uninstall.exe
2010-06-03 23:41 . 2010-06-03 23:41 -------- d-----w- c:\users\Lillian\AppData\Roaming\Facebook
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-01 01:16 . 2009-09-12 12:20 -------- d-----w- c:\programdata\Viewpoint
2010-06-30 01:46 . 2010-02-10 22:24 -------- d-----w- c:\users\Lillian\AppData\Roaming\vlc
2010-06-28 22:53 . 2010-02-14 04:23 -------- d-----w- c:\program files\Microsoft Security Essentials
2010-06-28 22:50 . 2009-08-28 16:15 -------- d-----w- c:\program files\Microsoft.NET
2010-06-28 01:21 . 2010-02-13 04:07 -------- d-----w- c:\program files\Spyware Doctor
2010-06-27 19:42 . 2010-04-19 00:01 -------- d-----w- c:\programdata\PC Tools
2010-06-26 22:56 . 2009-09-14 03:20 -------- d-----w- c:\program files\Common Files\Real
2010-06-26 22:55 . 2009-09-14 03:20 -------- d-----w- c:\program files\Real
2010-06-26 06:06 . 2010-02-14 00:01 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-26 05:50 . 2009-12-04 00:50 1 ----a-w- c:\users\Lillian\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-06-24 02:21 . 2010-03-07 02:34 439816 ----a-w- c:\users\Lillian\AppData\Roaming\Real\Update\setup3.10\setup.exe
2010-06-14 21:41 . 2009-09-11 21:13 121392 ----a-w- c:\users\Lillian\AppData\Local\GDIPFONTCACHEV1.DAT
2010-06-14 05:13 . 2010-04-22 22:52 -------- d-----w- c:\program files\Common Files\Adobe
2010-06-12 11:46 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-06-12 03:06 . 2009-08-28 16:14 -------- d-----w- c:\programdata\Microsoft Help
2010-06-06 15:27 . 2009-09-12 06:14 -------- d-----w- c:\program files\Microsoft Silverlight
2010-06-01 17:37 . 2009-10-03 12:27 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-05-31 17:38 . 2010-01-15 00:30 -------- d-----w- c:\users\Lillian\AppData\Roaming\Corel
2010-05-31 17:02 . 2010-05-31 17:02 -------- d-----w- c:\users\Lillian\AppData\Roaming\PC-FAX TX
2010-05-29 18:55 . 2010-05-29 18:55 -------- d-----w- c:\users\Guest\AppData\Roaming\Malwarebytes
2010-05-29 18:54 . 2010-05-29 18:54 -------- d-----w- c:\users\Guest\AppData\Roaming\Symantec
2010-05-29 18:54 . 2010-05-29 18:54 121392 ----a-w- c:\users\Guest\AppData\Local\GDIPFONTCACHEV1.DAT
2010-05-29 02:17 . 2010-04-01 14:59 765952 ----a-w- c:\programdata\NexonUS\NGM\NGMDll.dll
2010-05-19 03:49 . 2010-02-14 04:21 -------- d-----w- c:\program files\Windows Live Safety Center
2010-05-09 02:43 . 2010-05-09 02:43 -------- d-----w- c:\program files\Windows Live SkyDrive
2010-05-09 02:34 . 2010-05-09 02:34 -------- d-----w- c:\program files\Common Files\Windows Live
2010-05-05 05:36 . 2010-05-05 05:36 -------- d-----w- c:\users\Lillian\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2010-05-04 05:59 . 2010-06-10 21:33 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-04 05:55 . 2010-06-10 21:33 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-05-04 05:55 . 2010-06-10 21:33 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-05-04 04:31 . 2010-06-10 21:33 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2010-05-04 01:41 . 2009-10-14 23:44 50 ----a-w- c:\windows\system32\bridf08b.dat
2010-05-04 01:40 . 2009-09-19 02:02 -------- d-----w- c:\program files\Brother
2010-05-04 01:38 . 2008-09-30 18:58 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-05-04 01:28 . 2010-05-04 01:26 -------- d-----w- c:\program files\Canon
2010-05-04 01:26 . 2010-05-04 01:26 -------- d-----w- c:\programdata\ZoomBrowser
2010-05-04 01:24 . 2010-05-04 01:24 -------- d-----w- c:\program files\Common Files\Canon
2010-04-29 19:39 . 2010-02-14 00:01 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 19:39 . 2010-02-14 00:01 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-23 14:13 . 2010-05-26 00:21 2048 ----a-w- c:\windows\system32\tzres.dll
2010-04-19 06:49 . 2010-04-19 06:49 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-04-16 16:43 . 2010-06-23 16:10 173056 ----a-w- c:\windows\AppPatch\AcXtrnal.dll
2010-04-16 16:43 . 2010-06-23 16:10 458752 ----a-w- c:\windows\AppPatch\AcSpecfc.dll
2010-04-16 16:43 . 2010-06-23 16:10 542720 ----a-w- c:\windows\AppPatch\AcLayers.dll
2010-04-16 16:43 . 2010-06-23 16:10 2159616 ----a-w- c:\windows\AppPatch\AcGenral.dll
2008-06-30 17:44 . 2009-09-12 13:02 324976 ----a-w- c:\program files\mozilla firefox\components\coFFPlgn.dll
2009-09-11 21:12 . 2009-09-11 21:12 13 --sh--r- c:\windows\System32\drivers\fbd.sys
2009-09-11 21:12 . 2009-09-11 21:12 4 --sh--r- c:\windows\System32\drivers\taishop.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim"="c:\program files\AIM\aim.exe" [2010-05-21 3824472]
"SLFHVNU"="c:\users\Lillian\AppData\Roaming\msxml3J.dll" [2010-06-27 52224]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-06-25 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-06-25 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-06-25 145944]
"RtHDVCpl"="RtHDVCpl.exe" [2008-04-08 6037504]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-16 178712]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-08-14 1348904]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2008-02-06 431456]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2007-11-01 54608]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2008-06-02 505720]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2008-05-09 716800]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"NDSTray.exe"="NDSTray.exe" [BU]
"ToshibaServiceStation"="c:\program files\TOSHIBA\TOSHIBA Service Station\TSS.exe" [2008-08-04 1242424]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="c:\program files\Norton 360\osCheck.exe" [2008-02-26 988512]
"Skytel"="Skytel.exe" [2007-11-21 1826816]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2009-01-19 1150976]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2009-01-09 114688]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2008-07-10 29984]
"PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-08-31 328992]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-06-01 1093208]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-06-26 202256]
c:\users\Lillian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndexSearch]
2008-07-10 03:05 46368 ----a-w- c:\program files\ScanSoft\PaperPort\IndexSearch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
2010-04-29 19:39 1090952 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):8c,13,25,d0,d5,34,ca,01
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [x]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [x]
R1 Avgfwfd;AVG network filter service;c:\windows\system32\DRIVERS\avgfwd6x.sys [2010-02-13 24856]
R3 COH_Mon;COH_Mon;c:\windows\system32\Drivers\COH_Mon.sys [2008-07-30 23888]
R3 IO_Memory;IO_Memory;c:\windows\SYSTEM32\SYSPREP\Drivers\ioport.sys [x]
R3 SVRPEDRV;SVRPEDRV;c:\windows\System32\sysprep\PEDrv.sys [2008-01-18 9216]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [x]
S1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\ipsdefs\20091105.001\IDSvix86.sys [2009-08-26 272432]
S1 RtlProt;Realtke RtlProt WLAN Utility Protocol Driver;c:\windows\system32\DRIVERS\rtlprot.sys [2007-04-23 25896]
S2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [2008-04-17 40960]
S2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352]
S2 TMachInfo;TMachInfo;c:\program files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2008-08-04 46392]
S2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [2007-12-04 126976]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-08-27 102448]
S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [2006-11-20 7168]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-03-26 42368]
S3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8187B.sys [2009-06-10 347648]
S3 SYMNDISV;SYMNDISV;c:\windows\System32\Drivers\SYMNDISV.SYS [2009-02-19 41008]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - COMHOST
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSHB&bmod=TSHB
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride = <local>
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Lillian\AppData\Roaming\Mozilla\Firefox\Profiles\sug9qjae.default\
FF - component: c:\program files\Mozilla Firefox\components\coFFPlgn.dll
FF - component: c:\programdata\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\programdata\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\programdata\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: c:\users\Lillian\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: network.protocol-handler.warn-external.dnupdate - falsec:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-TOSCDSPD - TOSCDSPD.EXE
HKCU-Run-msnmsgr - c:\program files\Windows Live\Messenger\msnmsgr.exe
HKLM-Run-cfFncEnabler.exe - cfFncEnabler.exe
MSConfigStartUp-Aim6 - c:\program files\AIM6\aim6.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-06-30 21:41
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(4368)
c:\program files\Common Files\Symantec Shared\AppCore\AppMgr32.dll
c:\windows\System32\netshell.dll
.
Completion time: 2010-06-30 21:46:26
ComboFix-quarantined-files.txt 2010-07-01 01:46
Pre-Run: 95,250,165,760 bytes free
Post-Run: 95,215,603,712 bytes free
- - End Of File - - 93E7B68A7C8B9A262D5E9CAB75109731