Ran combofix. Here's the log:
ComboFix 09-07-08.04 - Anna Cardozo 07/08/2009 21:37.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1014.594 [GMT -4:00]
Running from: c:\documents and settings\Anna Cardozo\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\SKYNETmgxwjmpa.sys
c:\windows\system32\Ijl11.dll
c:\windows\system32\SKYNETdrkuytuf.dll
c:\windows\system32\SKYNETeyobsstb.dll
c:\windows\system32\SKYNETopplkvlf.dat
c:\windows\system32\SKYNETpdajxibm.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_SKYNETkdvbrcbw
((((((((((((((((((((((((( Files Created from 2009-06-09 to 2009-07-09 )))))))))))))))))))))))))))))))
.
2009-07-08 02:26 . 2009-07-08 02:26 -------- d-----w- c:\program files\Trend Micro
2009-07-08 01:48 . 2009-07-08 01:48 23 --sha-w- c:\windows\system32\edacded0.dat
2009-07-08 01:48 . 2009-07-08 01:48 -------- d-----w- c:\program files\jv16 PowerTools 2009
2009-07-08 01:29 . 2009-07-08 01:35 -------- d-----w- C:\fixwareout
2009-07-08 01:12 . 2009-07-08 01:12 -------- d-----w- c:\documents and settings\Anna Cardozo\Application Data\Malwarebytes
2009-07-08 00:50 . 2009-07-08 00:50 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-07-08 00:50 . 2009-06-17 15:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-08 00:50 . 2009-07-08 00:50 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-07 16:41 . 2009-07-07 16:40 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-07-07 16:41 . 2009-07-08 12:45 -------- dc----w- c:\windows\system32\DRVSTORE
2009-07-07 16:41 . 2009-07-07 16:41 314712 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-07-07 16:41 . 2009-07-07 16:41 25440 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\savapibridge.dll
2009-07-07 16:41 . 2009-07-07 16:41 15688 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-07-07 16:41 . 2009-07-07 16:41 348496 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
2009-07-07 16:41 . 2009-07-07 16:41 169312 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-07-07 16:41 . 2009-07-07 16:41 84832 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-07-07 16:41 . 2009-07-07 16:41 298336 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2009-07-07 16:40 . 2009-07-07 16:40 1630560 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2009-07-07 16:40 . 2009-07-07 16:40 40288 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-07-07 16:40 . 2009-07-07 16:40 246128 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-07-07 16:40 . 2009-07-07 16:40 64160 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
2009-07-07 16:40 . 2009-07-07 16:40 85352 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\AAWDriverTool.exe
2009-07-07 16:40 . 2009-07-07 16:40 664424 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-07-07 16:40 . 2009-07-07 16:40 563064 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-07-07 16:40 . 2009-07-07 16:40 566632 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-07-07 16:40 . 2009-07-07 16:40 2353480 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-07-07 16:40 . 2009-07-07 16:40 629072 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWWSC.exe
2009-07-07 16:40 . 2009-07-07 16:40 520024 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-07-07 16:40 . 2009-07-07 16:40 1029456 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-07-07 16:19 . 2009-07-07 16:19 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-07-07 16:19 . 2009-03-12 08:17 2902048 -c--a-w- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}\Ad-AwareAE.exe
2009-07-07 16:19 . 2009-07-07 16:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-07-07 16:19 . 2009-07-07 16:19 -------- d-----w- c:\program files\Lavasoft
2009-07-07 15:57 . 2009-06-14 20:07 1004800 ----a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-07-02 13:25 . 2009-06-29 12:27 327688 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgldx86.sys
2009-07-02 13:24 . 2009-06-29 12:27 829208 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcfgx.dll
2009-07-02 13:24 . 2009-06-29 12:27 3298072 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\setup.exe
2009-07-02 13:24 . 2009-06-29 12:26 1085208 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.exe
2009-07-02 13:24 . 2009-06-29 12:26 1454360 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgupd.dll
2009-06-29 20:56 . 2009-06-29 20:56 -------- d-----w- c:\documents and settings\Anna Cardozo\Local Settings\Application Data\AVG Security Toolbar
2009-06-29 12:27 . 2009-06-29 12:27 832144 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\AVGToolbarInstall.exe
2009-06-29 12:27 . 2009-07-07 15:57 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-06-29 12:27 . 2009-06-29 12:27 -------- d-----w- c:\documents and settings\LocalService\Application Data\AVGTOOLBAR
2009-06-23 21:47 . 2009-02-12 09:35 38208 ----a-w- c:\documents and settings\Anna Cardozo\Application Data\Macromedia\Flash Player\
http://www.macromedia.com\bin\airapp...pinstaller.exe
2009-06-23 21:47 . 2009-06-23 21:47 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-06-23 21:46 . 2009-06-23 21:46 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-06-23 21:46 . 2009-07-07 16:47 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-06-23 21:46 . 2009-07-07 16:47 -------- d-----w- c:\program files\NOS
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2009-07-08 02:00 . 2006-09-04 18:42 65584 ----a-w- c:\documents and settings\Anna Cardozo\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-08 01:55 . 2007-01-28 23:16 -------- d-----w- c:\program files\Finale NotePad 2007
2009-07-08 00:50 . 2009-07-08 00:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-07 23:55 . 2006-08-12 14:23 -------- d-----w- c:\program files\WildTangent
2009-07-07 16:41 . 2009-07-07 23:53 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-07-07 16:13 . 2006-08-12 14:20 -------- d-----w- c:\documents and settings\All Users\Application Data\GTek
2009-07-07 16:12 . 2006-08-12 14:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-07-07 16:11 . 2006-08-12 14:16 -------- d-----w- c:\program files\Dell
2009-07-07 16:10 . 2006-08-12 14:16 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-07 16:06 . 2007-02-10 18:43 -------- d-----w- c:\program files\IrfanView
2009-07-07 16:01 . 2006-08-12 14:16 -------- d-----w- c:\program files\Common Files\Sonic Shared
2009-07-07 15:58 . 2007-05-15 02:42 -------- d-----w- c:\program files\AOL Pictures
2009-07-07 15:58 . 2006-08-12 14:18 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL
2009-07-07 15:58 . 2006-08-12 14:18 -------- d-----w- c:\program files\Common Files\AOL
2009-07-07 15:57 . 2006-08-12 14:18 -------- d-----w- c:\program files\Common Files\aolshare
2009-07-02 13:24 . 2009-05-11 15:03 335752 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-29 12:27 . 2009-05-11 15:03 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-06-29 12:27 . 2009-05-11 15:02 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-24 14:16 . 2006-09-03 23:22 -------- d-----w- c:\program files\Lexmark 1200 Series
2009-06-23 21:55 . 2006-09-13 23:38 -------- d-----w- c:\program files\Common Files\Adobe
2009-06-17 15:27 . 2009-07-08 00:50 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-02 15:46 . 2009-05-11 15:02 -------- d-----w- c:\documents and settings\Anna Cardozo\Application Data\AVGTOOLBAR
2009-05-11 15:02 . 2009-05-11 15:02 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-11 15:02 . 2009-05-11 15:02 -------- d-----w- c:\program files\AVG
2009-05-11 15:02 . 2009-05-11 15:02 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-05-07 15:44 . 2004-08-10 16:51 344064 ----a-w- c:\windows\system32\localspl.dll
2009-04-29 04:31 . 2004-08-10 16:51 668160 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:31 . 2004-08-10 16:51 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-04-17 09:58 . 2004-08-10 16:51 1846656 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 15:11 . 2004-08-10 16:51 584192 ----a-w- c:\windows\system32\rpcrt4.dll
2007-11-23 22:20 . 2007-11-23 22:20 774144 ----a-w- c:\program files\RngInterstitial.dll
2008-08-03 15:10 . 2006-09-04 18:42 88 --sh--r- c:\windows\system32\80144F8BF4.sys
2008-08-03 15:10 . 2006-09-04 18:42 3350 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-14 20:07 1004800 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"Creative WebCam Tray"="c:\program files\Creative\Shared Files\CamTray.exe" [2005-10-27 299008]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"DellTransferAgent"="c:\documents and settings\All Users\Application Data\Dell\TransferAgent\TransferAgent.exe" [2007-11-13 135168]
"eFax 4.4"="c:\program files\eFax Messenger 4.4\J2GDllCmd.exe" [2008-10-07 95744]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-15 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-15 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-15 114688]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-11-01 94208]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"Lexmark 1200 Series"="c:\program files\Lexmark 1200 Series\lxczbmgr.exe" [2006-03-16 57344]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-10-25 282624]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2006-10-30 256576]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 57344]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2006-11-07 1121280]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-29 1948440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-07-07 520024]
c:\documents and settings\Anna Cardozo\Start Menu\Programs\Startup\
eFax 4.4.lnk - c:\program files\eFax Messenger 4.4\J2GTray.exe [2008-10-7 656896]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Ulead Photo Express 4.0 SE Calendar Checker .lnk - c:\program files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe [2007-6-26 69632]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-06-29 12:27 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [7/7/2009 12:41 PM 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/11/2009 11:03 AM 335752]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/11/2009 11:02 AM 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [5/11/2009 11:02 AM 298776]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 3:06 PM 1029456]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe --> c:\program files\NOS\bin\getPlus_HelperSvc.exe [?]
.
Contents of the 'Scheduled Tasks' folder
2009-07-07 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 16:40]
2009-07-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2006-10-10 22:13]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Aim6 - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.aol.com/
mStart Page = hxxp://www.dell.com
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
DPF: {C6D25826-96AE-462F-A852-BB33B882B723} - hxxp://duanereade.storefront.com/images/global/activex/SFImageUpload1_4.CAB
DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} - hxxp://aolsvc.aol.com/onlinegames/dinerdash/DinerDash.1.0.0.93.cab
FF - ProfilePath - c:\documents and settings\Anna Cardozo\Application Data\Mozilla\Firefox\Profiles\yar1uksa.default\
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\compone nts\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\compone nts\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\compone nts\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\compone nts\xpavgtbapi.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava11.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava12.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava13.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava14.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava32.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJPI142_03.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPOJI610.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dl l
.
************************************************** ************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
GMER - Rootkit Detector and Remover
Rootkit scan 2009-07-08 21:44
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
Completion time: 2009-07-09 21:45
ComboFix-quarantined-files.txt 2009-07-09 01:45
Pre-Run: 98,138,804,224 bytes free
Post-Run: 98,727,755,776 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOW S
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Micro soft Windows XP Home Edition" /noexecute=optin /fastdetect
212 --- E O F --- 2009-07-08 07:00