Hi
Here is the last log that you requested. You all asked me to run another fresh DDS Log, oooops, I have done so many different things, that I have forgotten how to run another DDS log. Please refresh my memory. It's just not working so well tonight. Thanks
ComboFix 11-08-15.08 - Mom 08/15/2011 20:57:37.3.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1918.1296 [GMT -5:00]
Running from: c:\documents and settings\Mom.DONNA-B101ED461\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Mom.DONNA-B101ED461\Desktop\CFScript.txt
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: BitDefender Antivirus *Disabled/Updated* {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
FW: BitDefender Firewall *Disabled* {4055920F-2E99-48A8-A270-4243D2B8F242}
.
FILE ::
"c:\documents and settings\Ryan\Local Settings\Temporary Internet Files\Content.IE5\09EFS567\.footer_01[1].htm"
"c:\documents and settings\Ryan\Local Settings\Temporary Internet Files\Content.IE5\GXOVG3GZ\.footer_01[1].htm"
"c:\program files\Common Files\BitDefender\SetupInformation\{B6CA7A3C-35FD-401F-9335-FFFD2BCD5FF3}\bdeleven.msi"
"c:\windows\system32\F0D2D00c__.tmp"
"e:\documents and settings\Ryan\Local Settings\Temporary Internet Files\Content.IE5\09EFS567\.footer_01[1].htm"
"e:\documents and settings\Ryan\Local Settings\Temporary Internet Files\Content.IE5\GXOVG3GZ\.footer_01[1].htm"
"e:\windows\system32\093BA00c__.ini"
"e:\windows\system32\18B3C00c__.ini"
"e:\windows\system32\29CEC00c__.ini"
"e:\windows\system32\353EA00c__.ini"
"e:\windows\system32\4CABF00c__.ini"
"e:\windows\system32\6230E00c__.ini"
"e:\windows\system32\6B22E00c__.ini"
"e:\windows\system32\6CD4300c__.ini"
"e:\windows\system32\E842B00c__.ini"
"e:\windows\system32\F0D2D00c__.ini"
"e:\windows\system32\F0D2D00c__.tmp"
"e:\windows\system32\F139100c__.ini"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Ryan\Local Settings\Temporary Internet Files\Content.IE5\09EFS567\.footer_01[1].htm
c:\documents and settings\Ryan\Local Settings\Temporary Internet Files\Content.IE5\GXOVG3GZ\.footer_01[1].htm
c:\program files\Common Files\BitDefender\SetupInformation\{B6CA7A3C-35FD-401F-9335-FFFD2BCD5FF3}\bdeleven.msi
c:\windows\system32\F0D2D00c__.tmp
e:\documents and settings\Ryan\Local Settings\Temporary Internet Files\Content.IE5\09EFS567\.footer_01[1].htm
e:\documents and settings\Ryan\Local Settings\Temporary Internet Files\Content.IE5\GXOVG3GZ\.footer_01[1].htm
e:\windows\system32\093BA00c__.ini
e:\windows\system32\18B3C00c__.ini
e:\windows\system32\29CEC00c__.ini
e:\windows\system32\353EA00c__.ini
e:\windows\system32\4CABF00c__.ini
e:\windows\system32\6230E00c__.ini
e:\windows\system32\6B22E00c__.ini
e:\windows\system32\6CD4300c__.ini
e:\windows\system32\E842B00c__.ini
e:\windows\system32\F0D2D00c__.ini
e:\windows\system32\F0D2D00c__.tmp
e:\windows\system32\F139100c__.ini
.
Infected copy of c:\windows\system32\userinit.exe was found and disinfected
Restored copy from - c:\windows\ERDNT\cache\userinit.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-07-16 to 2011-08-16 )))))))))))))))))))))))))))))))
.
.
2011-08-14 16:56 . 2011-08-14 16:56 -------- d-----w- c:\program files\ESET
2011-08-14 16:30 . 2011-08-14 16:30 -------- d-----w- c:\documents and settings\Mom.DONNA-B101ED461\Application Data\Malwarebytes
2011-08-14 16:30 . 2011-07-07 00:52 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-08-14 16:30 . 2011-08-14 16:30 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2011-08-14 16:30 . 2011-08-14 16:30 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-08-14 16:30 . 2011-07-07 00:52 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-14 15:31 . 2011-07-04 11:36 309848 ----a-w- c:\windows\system32\drivers\aswSP.sys
2011-08-14 15:31 . 2011-07-04 11:32 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-08-14 15:31 . 2011-07-04 11:32 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2011-08-14 15:31 . 2011-07-04 11:36 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-08-14 15:31 . 2011-07-04 11:35 43608 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2011-08-14 15:31 . 2011-07-04 11:35 102616 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2011-08-14 15:31 . 2011-07-04 11:35 96344 ----a-w- c:\windows\system32\drivers\aswmon.sys
2011-08-14 15:31 . 2011-07-04 11:32 30808 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2011-08-14 15:31 . 2011-07-04 11:43 40112 ----a-w- c:\windows\avastSS.scr
2011-08-14 15:31 . 2011-07-04 11:43 199304 ----a-w- c:\windows\system32\aswBoot.exe
2011-08-14 15:31 . 2011-08-14 15:31 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\AVAST Software
2011-08-14 14:48 . 2011-08-14 15:31 -------- d-----w- c:\program files\AVAST Software
2011-08-14 14:48 . 2011-08-14 14:48 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Alwil Software
2011-08-12 00:55 . 2011-08-12 00:55 -------- d-----w- c:\documents and settings\Mom.DONNA-B101ED461\Local Settings\Application Data\PCHealth
2011-08-10 22:08 . 2011-07-08 14:02 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys
2011-08-10 22:08 . 2011-06-24 14:10 139656 -c----w- c:\windows\system32\dllcache\rdpwd.sys
2011-08-08 04:03 . 2011-08-08 04:03 0 ----a-w- c:\windows\system32\bda142E.tmp
2011-08-01 14:51 . 2011-08-01 14:51 -------- d-----w- c:\documents and settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\bdch
2011-07-20 18:31 . 2009-08-07 00:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2011-07-20 14:17 . 2011-07-20 14:17 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\bdch
2011-07-20 03:35 . 2011-07-20 03:35 -------- d-----w- c:\documents and settings\NetworkService.NT AUTHORITY\Application Data\QuickScan
2011-07-20 03:27 . 2011-07-20 03:27 -------- d-----w- c:\documents and settings\Mom.DONNA-B101ED461\Application Data\BitDefender
2011-07-20 03:26 . 2011-07-20 03:26 -------- d-----w- c:\program files\BitDefender
2011-07-20 03:05 . 2011-07-20 03:29 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\BitDefender
2011-07-20 03:05 . 2011-07-20 03:26 -------- d-----w- c:\program files\Common Files\BitDefender
2011-07-20 03:05 . 2011-07-20 04:09 306320 ----a-w- c:\windows\system32\drivers\trufos.sys
2011-07-20 03:05 . 2010-05-13 22:02 12960 ----a-w- c:\windows\system32\drivers\bdrawpr.sys
2011-07-20 03:05 . 2011-07-20 03:29 986979 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\bdinstall.bin
2011-07-20 03:05 . 2011-03-24 20:36 353096 ----a-w- c:\windows\system32\drivers\bdfsfltr.sys
2011-07-20 02:24 . 2011-07-20 02:43 -------- d-----w- c:\documents and settings\Mom.DONNA-B101ED461\Application Data\QuickScan
2011-07-20 00:20 . 2011-07-20 05:05 -------- d--h--w- c:\windows\update.tray-14-0-lnk
2011-07-20 00:20 . 2011-07-20 03:38 -------- d--h--w- c:\windows\update.tray-14-0
2011-07-20 00:17 . 2011-07-20 00:17 -------- d-sh--w- c:\documents and settings\NetworkService.NT AUTHORITY\IETldCache
2011-07-20 00:17 . 2011-07-20 00:24 -------- d-----w- c:\program files\Microsoft Security Client
2011-07-19 23:07 . 2011-07-19 23:07 -------- d-----w- c:\windows\ufa
2011-07-19 23:07 . 2011-07-20 00:22 -------- d-----w- c:\windows\av_ico
2011-07-19 22:42 . 2011-07-19 22:42 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\SEAGATE
2011-07-17 22:51 . 2011-07-17 22:51 -------- d-sh--w- c:\documents and settings\TJ.DONNA-B101ED461\PrivacIE
2011-07-17 21:53 . 2011-07-17 21:53 246272 ----a-w- c:\windows\unrar.exe
2011-07-17 21:26 . 2011-07-20 05:05 -------- d--h--w- c:\windows\update.tray-9-0-lnk
2011-07-17 21:26 . 2011-07-20 05:05 -------- d--h--w- c:\windows\update.tray-7-0-lnk
2011-07-17 21:26 . 2011-07-20 03:38 -------- d--h--w- c:\windows\update.tray-7-0
2011-07-17 21:26 . 2011-07-20 03:38 -------- d--h--w- c:\windows\update.tray-9-0
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-20 04:04 . 2010-04-22 18:19 153440 ----a-w- c:\windows\system32\drivers\bdfm.sys
2011-07-15 13:29 . 2004-08-04 10:00 456320 ------w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 14:02 . 2004-08-04 10:00 10496 ------w- c:\windows\system32\drivers\ndistapi.sys
2011-06-30 00:55 . 2011-06-02 00:25 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-24 14:10 . 2011-02-05 04:54 139656 ------w- c:\windows\system32\drivers\rdpwd.sys
2011-06-23 18:36 . 2006-03-04 03:33 916480 ----a-w- c:\windows\system32\wininet.dll
2011-06-23 18:36 . 2004-08-04 10:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-06-23 18:36 . 2004-08-04 10:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-06-23 12:05 . 2004-08-04 10:00 385024 ----a-w- c:\windows\system32\html.iec
2011-06-20 17:44 . 2004-08-04 10:00 293376 ----a-w- c:\windows\system32\winsrv.dll
2011-06-02 14:02 . 2004-08-04 10:00 1858944 ------w- c:\windows\system32\win32k.sys
2010-07-08 15:37 . 2010-07-08 15:37 101544 ----a-w- c:\program files\Common Files\LinkInstaller.exe
2011-06-26 23:29 . 2011-05-22 00:32 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-08-14_02.02.38 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-07-12 06:02 . 2009-07-12 06:02 51008 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_f0ccd4aa\vcomp90.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02 51008 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_f0ccd4aa\vcomp90.dll
- 2009-07-12 06:02 . 2009-07-12 06:02 59728 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90rus.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02 59728 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90rus.dll
- 2009-07-12 06:02 . 2009-07-12 06:02 42832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90kor.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02 42832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90kor.dll
- 2009-07-12 06:02 . 2009-07-12 06:02 43344 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90jpn.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02 43344 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90jpn.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02 61264 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90ita.dll
- 2009-07-12 06:02 . 2009-07-12 06:02 61264 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90ita.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02 62800 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90fra.dll
- 2009-07-12 06:02 . 2009-07-12 06:02 62800 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90fra.dll
- 2009-07-12 06:02 . 2009-07-12 06:02 61760 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esp.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02 61760 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esp.dll
- 2009-07-12 06:02 . 2009-07-12 06:02 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esn.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02 61776 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90esn.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02 53568 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90enu.dll
- 2009-07-12 06:02 . 2009-07-12 06:02 53568 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90enu.dll
- 2009-07-12 06:02 . 2009-07-12 06:02 63296 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90deu.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02 63296 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90deu.dll
- 2009-07-12 06:02 . 2009-07-12 06:02 36688 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90cht.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02 36688 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90cht.dll
- 2009-07-12 06:02 . 2009-07-12 06:02 35648 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90chs.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02 35648 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_15fc9313\mfc90chs.dll
+ 2009-07-12 05:05 . 2009-07-12 05:05 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90u.dll
- 2009-07-12 06:05 . 2009-07-12 06:05 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90u.dll
+ 2009-07-12 05:05 . 2009-07-12 05:05 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90.dll
- 2009-07-12 06:05 . 2009-07-12 06:05 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfcm90.dll
- 2009-07-12 06:02 . 2009-07-12 06:02 653120 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02 653120 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll
- 2009-07-12 06:02 . 2009-07-12 06:02 569664 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02 569664 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll
- 2009-07-12 06:05 . 2009-07-12 06:05 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcm90.dll
+ 2009-07-12 05:05 . 2009-07-12 05:05 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcm90.dll
- 2009-07-12 06:02 . 2009-07-12 06:02 159032 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_353599c2\atl90.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02 159032 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_353599c2\atl90.dll
+ 2011-08-14 14:48 . 2011-08-14 14:48 262144 c:\windows\system32\config\systemprofile\NtUser.dat
+ 2009-07-12 05:02 . 2009-07-12 05:02 3780424 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90u.dll
- 2009-07-12 06:02 . 2009-07-12 06:02 3780424 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90u.dll
- 2009-07-12 06:02 . 2009-07-12 06:02 3765048 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90.dll
+ 2009-07-12 05:02 . 2009-07-12 05:02 3765048 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_a57c1f53\mfc90.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 132496]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-15 1404928]
"RTHDCPL"="RTHDCPL.EXE" [2009-10-16 18782720]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2010-11-04 1753192]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2011-01-08 111208]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2011-01-08 13880424]
"mmtask"="c:\program files\Musicmatch\Musicmatch Jukebox\mmtask.exe" [2006-01-17 53248]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"hplampc"="c:\windows\system32\hplampc.exe" [2002-01-17 40448]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-01 49152]
"HP Update 4200C"="c:\downlo~1\PROGRA~1\SCANJE~1\hpupdate.exe" [2002-02-14 32768]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-01-27 86016]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2005-05-31 122941]
"Corel File Shell Monitor"="c:\program files\Corel\Corel Photo Album 7\CorelIOMonitor.exe" [2008-08-22 37888]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2011\ieshow.exe" [2011-07-20 92352]
"BDAgent"="c:\program files\BitDefender\BitDefender 2011\bdagent.exe" [2011-07-20 1451928]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-07 449584]
"Corel Photo Downloader"="c:\program files\Corel\Corel Photo Album 7\Corel Photo Downloader.exe" [2008-08-22 481608]
.
c:\documents and settings\Mom.DONNA-B101ED461\Start Menu\Programs\Startup\
TDS Internet Call Manager.LNK - e:\program files\TDS Internet Call Manager\ICM.EXE [2005-8-19 1773568]
ZooskMessenger.lnk - c:\program files\ZooskMessenger\ZooskMessenger.exe [N/A]
.
c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Event Reminder.lnk - c:\program files\PrintMaster 16\pmremind.exe [2004-1-20 339968]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [N/A]
Photo Card Event Planner Reminder.lnk - c:\windows\Installer\{C885990F-A824-41A1-82FB-61E3859B4CE2}\Shortcut_Event_Pla_C885990FA82441A182FB61E3859B4CE2.exe [2009-12-22 1718]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableSecureUIAPaths"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"DisableThumbnailCache"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [8/14/2011 10:31 AM 441176]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [8/14/2011 10:31 AM 309848]
R1 BdRawPr;BdRawPr;c:\windows\system32\drivers\bdrawpr.sys [7/19/2011 10:05 PM 12960]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [8/14/2011 11:30 AM 366640]
R2 Updatesrv;BitDefender Desktop Update Service;c:\program files\BitDefender\BitDefender 2011\updatesrv.exe [3/24/2011 7:46 PM 43936]
R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [4/22/2010 1:19 PM 153440]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\program files\Common Files\BitDefender\BitDefender Firewall\bdfndisf.sys [8/20/2010 3:41 PM 111696]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [8/14/2011 11:30 AM 22712]
S2 aswFsBlk;aswFsBlk;aswFsBlk.sys --> aswFsBlk.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2/5/2011 10:49 PM 1684736]
S3 CFcatchme;CFcatchme;\??\c:\docume~1\MOM~1.DON\LOCALS~1\Temp\CFcatchme.sys --> c:\docume~1\MOM~1.DON\LOCALS~1\Temp\CFcatchme.sys [?]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [8/14/2011 11:30 AM 41272]
S3 McComponentHostService;McAfee Security Scan Component Host Service;"c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe" --> c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [?]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [8/21/2008 11:49 PM 18688]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [8/21/2008 11:49 PM 8320]
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\drivers\motport.sys [6/18/2007 8:18 PM 23680]
S3 Update Server;BitDefender Update Server v2;c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe [11/30/2010 7:19 AM 307544]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
S4 avc3;avc3;c:\windows\system32\drivers\avc3.sys [11/29/2010 2:12 PM 535824]
S4 avckf;avckf;c:\windows\system32\drivers\avckf.sys [11/29/2010 2:12 PM 1066232]
.
Contents of the 'Scheduled Tasks' folder
.
2011-08-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
2011-08-14 c:\windows\Tasks\dfrg.job
- c:\windows\system32\dfrg.msc [2004-08-04 10:00]
.
2011-07-17 c:\windows\Tasks\Disk Cleanup.job
- c:\windows\system32\cleanmgr.exe [2004-08-04 10:42]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
mStart Page = about:blank
Trusted Zone: facebook.com
TCP: DhcpNameServer = 192.168.0.1 216.165.129.157
FF - ProfilePath - c:\documents and settings\Mom.DONNA-B101ED461\Application Data\Mozilla\Firefox\Profiles\x5r4a0l5.default\
FF - prefs.js: browser.startup.homepage - hxxp://portal.tds.net/
FF - prefs.js: network.proxy.type - 0
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-08-15 21:14
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(1048)
c:\windows\system32\adsldpc.dll
.
- - - - - - - > 'explorer.exe'(2976)
c:\windows\system32\WININET.dll
c:\program files\BitDefender\BitDefender 2011\pchook32.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\BitDefender\BitDefender 2011\vsserv.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
c:\windows\system32\PSIService.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
c:\program files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
c:\windows\system32\wscntfy.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\RUNDLL32.EXE
c:\program files\BitDefender\BitDefender 2011\pchooklaunch32.exe
.
**************************************************************************
.
Completion time: 2011-08-15 21:17:37 - machine was rebooted
ComboFix-quarantined-files.txt 2011-08-16 02:17
ComboFix2.txt 2011-08-14 16:14
ComboFix3.txt 2011-08-14 02:06
.
Pre-Run: 383,635,415,040 bytes free
Post-Run: 383,533,486,080 bytes free
.
- - End Of File - - 86616DFBAB3FF8B76C5E526841322147