Nasdaq,
I tried the fix it tool and it did not work.
As instructed I downloaded combofix and ran it.
Here is the log:
ComboFix 12-06-28.01 - Scott 06/28/2012 11:12:35.1.4 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3326.1637 [GMT -7:00]
Running from: c:\users\Scott\Desktop\ComboFix.exe
AV: BullGuard Antivirus *Disabled/Outdated* {504FFF66-3028-EB7E-2E60-62B19ADD791C}
FW: BullGuard Firewall *Enabled* {68747E43-7A47-EA26-053F-CB84640E3E67}
SP: BullGuard Antispyware *Disabled/Outdated* {EB2E1E82-1612-E4F0-14D0-59C3E15A33A1}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\SPLB38C.tmp
c:\users\Scott\AppData\Local\._Revolution_
c:\windows\Downloaded Program Files\popcaploader.inf
.
.
((((((((((((((((((((((((( Files Created from 2012-05-28 to 2012-06-28 )))))))))))))))))))))))))))))))
.
.
2012-06-28 18:20 . 2012-06-28 18:21 -------- d-----w- c:\users\Scott\AppData\Local\temp
2012-06-28 18:20 . 2012-06-28 18:20 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-06-28 14:48 . 2012-05-31 03:41 6762896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A5A548BB-0603-4F10-A7D8-8B39CB8C5E06}\mpengine.dll
2012-06-21 16:31 . 2012-06-21 16:31 -------- d-----w- c:\program files\ESET
2012-06-19 03:26 . 2012-06-19 03:31 -------- d-----w- c:\users\Scott\SecurityScans
2012-06-19 03:26 . 2012-06-19 03:26 -------- d-----w- c:\program files\Microsoft Baseline Security Analyzer 2
2012-06-05 00:02 . 2012-06-05 00:02 -------- d-----w- c:\users\Scott\AppData\Roaming\SUPERAntiSpyware.com
2012-06-05 00:00 . 2012-06-05 00:02 -------- d-----w- c:\program files\SUPERAntiSpyware
2012-06-05 00:00 . 2012-06-05 00:00 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2012-06-03 13:44 . 2008-05-08 05:03 303616 ----a-w- C:\SetACL.exe
2012-06-03 13:09 . 2004-06-11 23:33 290304 ----a-w- C:\subinacl.exe
2012-06-03 13:04 . 2012-06-04 03:21 181064 ----a-w- c:\windows\PSEXESVC.EXE
2012-06-03 13:04 . 2012-06-04 03:02 -------- d-----w- C:\Reg_Backup
2012-06-03 13:02 . 2012-06-04 03:21 -------- d-----w- C:\Tweaking.com_Windows_Repair_Logs
2012-06-03 13:02 . 2012-06-03 13:02 -------- d-----w- c:\program files\Tweaking.com
2012-06-01 14:31 . 2012-06-01 14:31 -------- d-----w- c:\users\Scott\AppData\Local\ElevatedDiagnostics
2012-06-01 01:08 . 2012-06-01 01:08 -------- d-----w- c:\program files\Oracle
2012-06-01 01:07 . 2012-04-05 01:47 772504 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-06-01 00:47 . 2012-06-01 00:47 -------- d-----w- c:\program files\VS Revo Group
2012-06-01 00:20 . 2012-06-01 00:20 -------- d-----w- c:\program files\CCleaner
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-22 14:33 . 2009-03-23 12:07 33920 ----a-r- c:\windows\system32\drivers\Afw.sys
2012-06-22 14:33 . 2009-03-23 12:07 339584 ----a-r- c:\windows\system32\drivers\AfwCore.sys
2012-06-17 19:22 . 2012-04-06 22:25 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-06-17 19:22 . 2011-05-19 18:43 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-05-01 16:36 . 2012-05-01 16:36 140376 ----a-w- c:\windows\system32\MicrosoftUpdateCatalogWebControl.dll
2012-04-21 21:24 . 2010-04-19 12:16 53088 ----a-w- c:\windows\system32\BGLsp.dll
2012-04-21 21:12 . 2012-04-21 21:12 51716 ----a-w- c:\windows\system32\pdf995mon.dll
2012-04-21 21:12 . 2012-04-21 21:12 249856 ----a-w- c:\windows\system32\pdfmona.dll
2012-04-06 19:05 . 2011-02-09 17:49 20040 ----a-w- c:\windows\system32\drivers\NSNetmon.sys
2012-04-06 19:05 . 2010-03-18 16:03 100216 ----a-w- c:\windows\system32\BgGamingMonitor.dll
2012-04-06 19:05 . 2011-02-09 17:49 216136 ----a-w- c:\windows\system32\drivers\NSKernel.sys
2012-04-06 19:05 . 2012-04-06 19:05 308296 ----a-w- c:\windows\system32\drivers\Trufos.sys
2012-04-04 22:56 . 2009-02-13 23:56 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
"VolPanel"="c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" [2007-04-17 184320]
"SPIRunE"="SPIRunE.dll" [2009-03-05 18432]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-06-27 13789728]
"BullGuard"="c:\program files\BullGuard Ltd\BullGuard\BullGuard.exe" [2012-06-19 1756000]
"lxecmon.exe"="c:\program files\Lexmark Pro800-Pro900 Series\lxecmon.exe" [2011-01-24 770728]
"EzPrint"="c:\program files\Lexmark Pro800-Pro900 Series\ezprint.exe" [2011-01-24 148280]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2007-10-09 44168]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\BgGamingMonitor.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BsMain]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BsScanner]
@="Service"
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-01-03 07:37 843712 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2012-04-04 05:53 35736 ----a-w- c:\program files\Adobe\Reader 10.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2011-09-27 15:22 59240 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2008-01-19 07:33 125952 ----a-w- c:\windows\ehome\ehtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2006-12-11 05:52 49152 ----a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
2008-06-03 01:50 178712 ----a-w- c:\program files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-02-16 02:07 141608 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark Pro800-Pro900 Series Fax Server]
2011-01-24 03:47 316072 ----a-w- c:\program files\Lexmark Pro800-Pro900 Series\fm3032.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
2012-04-04 22:56 981680 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
2008-06-08 17:31 2221352 ----a-w- c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-10-24 22:28 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-11 06:28 1233920 ----a-w- c:\program files\Windows Sidebar\sidebar.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateReg]
2007-04-07 09:56 54936 ----a-w- c:\windows\System32\jureg.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-01-17 18:07 252296 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
2008-01-19 07:38 1008184 ----a-w- c:\program files\Windows Defender\MSASCui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2008-01-19 07:33 202240 ----a-w- c:\program files\Windows Media Player\wmpnscfg.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
BullGuard_Main REG_MULTI_SZ BsMain
BullGuard REG_MULTI_SZ BsFileScan BsFire
BullGuard_LowPriv REG_MULTI_SZ BsBrowser
BullGuard_Backup REG_MULTI_SZ BsBackup
BullGuard_Proxy REG_MULTI_SZ BsMailProxy
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=desktop
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-23C3F5C0 - c:\users\scott\appdata\local\micros~1\windows\tempor~1\content.ie5\kosqekin\speedu~1.exe
MSConfigStartUp-HP Health Check Scheduler - [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-06-28 11:20
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
.
c:\users\Scott\AppData\Local\Temp\catchme.dll 53248 bytes executable
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
Completion time: 2012-06-28 11:25:15
ComboFix-quarantined-files.txt 2012-06-28 18:25
.
Pre-Run: 605,604,438,016 bytes free
Post-Run: 605,629,030,400 bytes free
.
- - End Of File - - 1453FF0287CC73E47330FFA3592FDC43
Thank you again for your assistance.
4