Here is the combofix log. Under "FF - prefs.js: browser.startup.homepage" and "FF - prefs.js: keyword.URL" I removed the "h t t p : / / w w w ." Since I am not allowed to post external links. Those were the only changes made.
ComboFix 11-09-26.03 - ANguyen Home 09/26/2011 21:17:15.1.4 - x64
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.4095.2958 [GMT -7:00]
Running from: c:\users\ANguyen Home\Desktop\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
FW: COMODO Firewall *Enabled* {4D6F75E0-14AF-2E9E-AACD-24CDCF08AA2A}
SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
c:\users\ANguyen Home\AppData\Local\Adobe\AdobeUpdate\Adobeupdt32.dll
c:\users\ANguyen Home\AppData\Roaming\BITS
c:\users\ANguyen Home\AppData\Roaming\BITS\BITS.ini
c:\users\ANguyen Home\AppData\Roaming\BITS\P2PCfg.ini
c:\users\ANguyen Home\Taskmgr.exe
c:\users\ANguyen Home\wevtapi.dll
.
.
((((((((((((((((((((((((( Files Created from 2011-08-27 to 2011-09-27 )))))))))))))))))))))))))))))))
.
.
2011-09-25 00:53 . 2011-09-25 00:53 388096 ----a-r- c:\users\ANguyen Home\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-09-25 00:53 . 2011-09-25 00:53 -------- d-----w- c:\program files (x86)\Trend Micro
2011-09-24 22:47 . 2006-06-19 20:01 69632 ----a-w- c:\windows\SysWow64\ztvcabinet.dll
2011-09-24 22:47 . 2006-05-25 22:52 162304 ----a-w- c:\windows\SysWow64\ztvunrar36.dll
2011-09-24 22:47 . 2005-08-26 08:50 77312 ----a-w- c:\windows\SysWow64\ztvunace26.dll
2011-09-24 22:47 . 2003-02-03 03:06 153088 ----a-w- c:\windows\SysWow64\UNRAR3.dll
2011-09-24 22:47 . 2002-03-06 08:00 75264 ----a-w- c:\windows\SysWow64\unacev2.dll
2011-09-24 22:47 . 2011-09-24 22:47 -------- d-----w- c:\program files (x86)\Trojan Remover
2011-09-24 22:47 . 2011-09-24 22:47 -------- d-----w- c:\users\ANguyen Home\AppData\Roaming\Simply Super Software
2011-09-24 22:47 . 2011-09-24 22:47 -------- d-----w- c:\programdata\Simply Super Software
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-24 05:45 . 2010-08-08 06:37 215128 ----a-w- c:\windows\SysWow64\PnkBstrB.xtr
2011-09-24 05:45 . 2010-08-08 06:34 215128 ----a-w- c:\windows\SysWow64\PnkBstrB.exe
2011-09-18 20:25 . 2010-08-08 06:34 215128 ----a-w- c:\windows\SysWow64\PnkBstrB.ex0
2011-09-02 00:42 . 2010-04-09 08:26 363560 ----a-w- c:\windows\system32\guard64.dll
2011-09-02 00:42 . 2010-04-09 08:26 285256 ----a-w- c:\windows\SysWow64\guard32.dll
2011-09-02 00:42 . 2010-04-09 08:25 92688 ----a-w- c:\windows\system32\drivers\inspect.sys
2011-09-02 00:42 . 2010-04-09 08:25 41712 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2011-09-02 00:42 . 2010-04-09 08:25 252344 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
2011-09-02 00:42 . 2010-04-09 08:25 16016 ----a-w- c:\windows\system32\drivers\cmderd.sys
2011-09-01 00:00 . 2010-06-08 02:52 25416 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-27 07:11 . 2011-08-27 07:11 40960 ----a-r- c:\users\ANguyen Home\AppData\Roaming\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\NewShortcut1_9559F7CA5E344237A2D9D856464AD727.exe
2011-08-27 07:11 . 2011-08-27 07:11 40960 ----a-r- c:\users\ANguyen Home\AppData\Roaming\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\ARPPRODUCTICON.exe
2011-06-30 19:19 . 2010-06-08 02:49 88288 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-06-30 19:19 . 2010-06-08 02:49 123784 ----a-w- c:\windows\system32\drivers\avipbb.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files (x86)\Steam\steam.exe" [2011-08-02 1242448]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1475072]
"Aim"="c:\program files (x86)\AIM\aim.exe" [2010-05-21 3824472]
"AnyDVD"="c:\program files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe" [2010-12-17 4763256]
"AutoStartNPSAgent"="c:\program files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe" [2010-07-05 95576]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2010-11-03 281768]
"TkBellExe"="c:\program files (x86)\Common Files\Real\Update_OB\realsched.exe" [2010-06-22 202256]
"DivXUpdate"="c:\program files (x86)\DivX\DivX Update\DivXUpdate.exe" [2010-06-03 1144104]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"MaxMenuMgr"="c:\program files (x86)\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2009-09-26 185640]
"TrojanScanner"="c:\program files (x86)\Trojan Remover\Trjscan.exe" [2011-05-19 1233856]
.
c:\users\ANguyen Home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.2.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2009-12-15 384000]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\SysWOW64\guard32.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CLPSLS]
@="Service"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 dump_wmimmc;dump_wmimmc;c:\ijji\ENGLISH\u_sf\GameGuard\dump_wmimmc.sys [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x]
R3 hcw72ADFilter;WinTV HVR-950 USB Audio Filter Driver;c:\windows\system32\DRIVERS\hcw72ADFilter.sys [x]
R3 hcw72ATV;WinTV HVR-950 NTSC;c:\windows\system32\DRIVERS\hcw72ATV.sys [x]
R3 hcw72DTV;WinTV HVR-950 ATSC/QAM;c:\windows\system32\DRIVERS\hcw72DTV.sys [x]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
R3 sscebus;SAMSUNG USB Composite Device V2 driver (WDM);c:\windows\system32\DRIVERS\sscebus.sys [x]
R3 sscemdfl;SAMSUNG Mobile Modem V2 Filter;c:\windows\system32\DRIVERS\sscemdfl.sys [x]
R3 sscemdm;SAMSUNG Mobile Modem V2 Drivers;c:\windows\system32\DRIVERS\sscemdm.sys [x]
R3 TFsExDisk;TFsExDisk;c:\windows\System32\Drivers\TFsExDisk.sys [2010-06-14 16448]
R4 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-09-01 366152]
S1 BS_I2cIo;BS_I2cIo;c:\windows\system32\drivers\BS_I2cIo.sys [2008-06-17 15408]
S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [x]
S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 27136]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-05-02 136360]
S2 CLPSLS;COMODO livePCsupport Service;c:\program files (x86)\COMODO\COMODO livePCsupport\CLPSLS.exe [2010-02-20 148744]
S2 FreeAgentGoNext Service;Seagate Service;c:\program files (x86)\Seagate\SeagateManager\Sync\FreeAgentService.exe [2009-09-26 189736]
S2 HMuKstE;Kensington TrackballWorks Expert USB HID Device Filter Driver;c:\windows\system32\DRIVERS\HMuKstE.sys [x]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S3 netr28ux;RT2870 USB Extensible Wireless LAN Card Driver;c:\windows\system32\DRIVERS\netr28ux.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder
.
2011-09-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3467924077-2809153651-3563722403-1000Core.job
- c:\users\ANguyen Home\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-02 05:44]
.
2011-09-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3467924077-2809153651-3563722403-1000UA.job
- c:\users\ANguyen Home\AppData\Local\Google\Update\GoogleUpdate.exe [2010-09-02 05:44]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2011-09-02 9048392]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x1
"AppInit_DLLs"=c:\windows\System32\guard64.dll
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SYSTEM32\blank.htm
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\ANguyen Home\AppData\Roaming\Mozilla\Firefox\Profiles\1bkod1k4.default\
FF - prefs.js: browser.search.selectedEngine - Amazon.com
FF - prefs.js: browser.startup.homepage - google.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF - prefs.js: keyword.URL - google.com/search?ie=UTF-8&sourceid=navclient&gfns=1&q=
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 57192
FF - prefs.js: network.proxy.type - 0
FF - user.js: network.protocol-handler.warn-external.dnupdate - false
.
- - - - ORPHANS REMOVED - - - -
.
Wow6432Node-HKCU-Run-JavaTrayOnline - (no file)
Wow6432Node-HKLM-Run-NPSStartup - (no file)
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc_bc2.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-3467924077-2809153651-3563722403-1000\Software\SecuROM\License information*]
"datasecu"=hex:b5,c8,98,6f,81,fd,0b,46,15,05,e8,b0,dc,d5,1f,60,42,0e,40,bd,5c,
5c,c0,e9,83,1a,56,14,85,fe,d9,81,76,42,e4,14,b0,07,08,6a,93,45,c0,9c,14,e6,\
"rkeysecu"=hex:bc,63,5d,ce,d1,79,5d,4a,23,6c,04,12,dc,4f,6d,dc
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\OpenOffice.org 3\program\soffice.exe
c:\program files (x86)\OpenOffice.org 3\program\soffice.bin
c:\program files (x86)\Common Files\Steam\SteamService.exe
.
**************************************************************************
.
Completion time: 2011-09-26 21:28:44 - machine was rebooted
ComboFix-quarantined-files.txt 2011-09-27 04:28
.
Pre-Run: 202,207,985,664 bytes free
Post-Run: 201,825,427,456 bytes free
.
- - End Of File - - D9183BE614140D67753BCD52A42F726F