Finally got combofix to run with no issues. Here is the attached log. Only problem I had was with The recovery COnsole was not on my computer and failed to download. Let me know where to go from here. Thanks again.
ComboFix 11-10-04.04 - benjamin 10/05/2011 21:18:44.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.718 [GMT -4:00]
Running from: c:\documents and settings\benjamin\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\benjamin\Application Data\alot
c:\program files\avg_free_stf_en_85_285a1462.exe
c:\windows\$NtUninstallKB57888$\1057956560\@
c:\windows\$NtUninstallKB57888$\1057956560\bckfg.tmp
c:\windows\$NtUninstallKB57888$\1057956560\cfg.ini
c:\windows\$NtUninstallKB57888$\1057956560\Desktop.ini
c:\windows\$NtUninstallKB57888$\1057956560\keywords
c:\windows\$NtUninstallKB57888$\1057956560\kwrd.dll
c:\windows\$NtUninstallKB57888$\1057956560\L\ymtdkmmj
c:\windows\$NtUninstallKB57888$\1057956560\lsflt7.ver
c:\windows\$NtUninstallKB57888$\1057956560\U\00000001.@
c:\windows\$NtUninstallKB57888$\1057956560\U\00000002.@
c:\windows\$NtUninstallKB57888$\1057956560\U\80000000.@
c:\windows\$NtUninstallKB57888$\1057956560\U\80000032.@
c:\windows\$NtUninstallKB57888$\328467387
c:\windows\$NtUninstallKB57888$ . . . . Failed to delete
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Service_3f0f22d0
.
.
((((((((((((((((((((((((( Files Created from 2011-09-06 to 2011-10-06 )))))))))))))))))))))))))))))))
.
.
2011-09-28 15:41 . 2011-10-06 01:33 -------- d-----w- c:\documents and settings\benjamin\Local Settings\Application Data\Htc
2011-09-27 13:25 . 2011-09-27 13:25 -------- d-----w- c:\documents and settings\benjamin\Application Data\UyyycA1ivD2
2011-09-27 13:25 . 2011-09-27 13:25 -------- d-----w- c:\documents and settings\benjamin\Application Data\uRRL9hhTXjUCItz
2011-09-27 12:48 . 2011-09-27 12:48 -------- d-----w- c:\documents and settings\benjamin\Application Data\wHH66sWKfELgTqY
2011-09-27 12:48 . 2011-09-27 12:48 -------- d-----w- c:\documents and settings\benjamin\Application Data\deekkIBrzNyx
2011-09-27 11:55 . 2011-09-27 11:55 -------- d-----w- c:\documents and settings\benjamin\Application Data\ZlBPy1b3oG4aHsK
2011-09-27 11:55 . 2011-09-27 11:55 -------- d-----w- c:\documents and settings\benjamin\Application Data\xSS2obpG5Qd8g9X
2011-09-27 11:46 . 2011-09-27 11:46 -------- d-----w- c:\documents and settings\benjamin\Application Data\CcAi24m5W7E8TqY
2011-09-27 11:46 . 2011-09-27 11:46 -------- d-----w- c:\documents and settings\benjamin\Application Data\bibbD3nG47UN1ms
2011-09-27 11:39 . 2011-09-27 11:39 118590 ----a-w- C:\sdasetup_revwire207.exe
2011-09-27 11:36 . 2011-09-27 11:36 -------- d-----w- c:\documents and settings\benjamin\Application Data\eQQHH6sWK7RLgT
2011-09-27 11:36 . 2011-09-27 11:36 -------- d-----w- c:\documents and settings\benjamin\Application Data\QYCCekVNob5sJdK
2011-09-27 11:24 . 2011-09-27 11:24 -------- d-----w- c:\documents and settings\benjamin\Application Data\C7fLgZjCkVzNx0v
2011-09-27 11:24 . 2011-09-27 11:24 -------- d-----w- c:\documents and settings\benjamin\Application Data\aiib355a6d
2011-09-27 11:21 . 2011-09-27 11:22 -------- d-----w- c:\documents and settings\Administrator
2011-09-27 11:09 . 2011-09-27 11:09 -------- d-----w- c:\documents and settings\benjamin\Application Data\sOOBtxxP0cS1b3o
2011-09-27 11:09 . 2011-09-27 11:09 -------- d-----w- c:\documents and settings\benjamin\Application Data\XmH66sWJ7fL9TZj
2011-09-27 03:58 . 2011-09-27 03:58 -------- d-----w- c:\documents and settings\benjamin\Application Data\pggTTZqhYCkIrlN
2011-09-27 03:58 . 2011-09-27 03:58 -------- d-----w- c:\documents and settings\benjamin\Application Data\bppnnG5aQJdW8R9
2011-09-27 03:44 . 2011-09-27 03:44 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2011-09-27 03:33 . 2011-09-27 11:06 -------- d-----w- c:\documents and settings\benjamin\Application Data\VwwwjUVVelBtz0c
2011-09-27 03:33 . 2011-09-27 03:33 -------- d-----w- c:\documents and settings\benjamin\Application Data\pKK88fRZ9
2011-09-27 03:33 . 2011-09-27 03:33 -------- d-----w- c:\documents and settings\benjamin\Application Data\wZZqhYXwUVrlB
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-09 09:12 . 2009-01-16 23:18 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-08-31 21:00 . 2011-01-26 15:12 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-09 02:02 . 2011-08-09 02:00 13685936 ----a-w- C:\Firefox Setup 5.0.1.exe
2011-07-19 15:28 . 2011-01-19 23:16 13312 ----a-w- c:\windows\system32\drivers\pneteth.sys
2011-07-15 13:29 . 2009-01-16 23:18 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-08 14:02 . 2009-01-16 23:18 10496 ------w- c:\windows\system32\drivers\ndistapi.sys
2009-04-10 22:47 . 2009-04-10 22:47 174207416 -c--a-w- c:\program files\rw2_021_w02_enu.exe
2009-04-10 21:42 . 2009-04-10 21:42 3938520 -c--a-w- c:\program files\hpDriverDetective.exe
2009-04-06 01:31 . 2009-04-06 01:27 10553792 -c--a-w- c:\program files\Vuze_Installer.exe
2011-09-07 21:26 . 2011-08-09 02:02 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"MaxMenuMgr"="c:\program files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2009-09-26 185640]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-02-15 417792]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
"HTC Sync Loader"="c:\program files\HTC\HTC Sync 3.0\htcUPCTLoader.exe" [2011-08-22 593920]
.
c:\documents and settings\benjamin\Start Menu\Programs\Startup\
PdaNet Desktop.lnk - c:\program files\PdaNet for Android\PdaNetPC.exe [2011-10-2 480880]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acer VCM.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Acer VCM.lnk
backup=c:\windows\pss\Acer VCM.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hp psc 1000 series.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hp psc 1000 series.lnk
backup=c:\windows\pss\hp psc 1000 series.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hpoddt01.exe.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk
backup=c:\windows\pss\hpoddt01.exe.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^benjamin^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\documents and settings\benjamin\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^benjamin^Start Menu^Programs^Startup^Microsoft Find Fast.lnk]
path=c:\documents and settings\benjamin\Start Menu\Programs\Startup\Microsoft Find Fast.lnk
backup=c:\windows\pss\Microsoft Find Fast.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^benjamin^Start Menu^Programs^Startup^Office Startup.lnk]
path=c:\documents and settings\benjamin\Start Menu\Programs\Startup\Office Startup.lnk
backup=c:\windows\pss\Office Startup.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-30 04:59 937920 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-09-07 22:58 37296 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2008-06-19 08:20 57344 -c--a-w- c:\windows\ALCMTR.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service]
2009-10-10 17:32 203264 -c--a-w- c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
2010-07-08 23:02 2048352 ----a-w- c:\progra~1\AVG\AVG8\avgtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel]
2006-01-25 10:45 53248 ----a-w- c:\program files\Realtek\Audio\Drivers\AzMixerSel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 12:00 15360 ------w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
2011-06-02 03:12 136176 ----atw- c:\documents and settings\benjamin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2008-02-28 01:00 166424 ------w- c:\windows\system32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
2008-04-16 01:54 178712 -c--a-w- c:\program files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2008-02-28 01:00 141848 ------w- c:\windows\system32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
2008-04-14 12:00 208952 -c--a-w- c:\windows\ime\imjp8_1\imjpmig.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KMCONFIG]
2007-03-06 18:51 212992 ----a-w- c:\program files\Keyboard & Mouse Driver\StartAutorun.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager]
2008-12-30 07:09 875016 -c--a-w- c:\progra~1\LAUNCH~1\LManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 13:42 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]
2008-04-14 12:00 59392 -c----w- c:\windows\system32\IME\PINTLGNT\IMSCINST.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NotificationCenterLauncher]
2008-12-22 20:00 225280 -c--a-w- c:\program files\Acer\Acer eRecovery Management\NotificationLauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM2_Monitor]
2008-10-31 16:17 95536 -c----w- c:\program files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2008-02-28 01:00 137752 ------w- c:\windows\system32\igfxpers.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
2008-04-14 12:00 455168 -c----w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
2008-04-14 12:00 455168 -c----w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PLFSetL]
2008-07-03 23:58 94208 -c--a-w- c:\windows\PLFSetL.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-02-15 23:50 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2008-12-26 08:20 18081280 -c--a-w- c:\windows\RTHDCPL.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\snp2uvc]
2008-11-04 03:00 196608 ------w- c:\windows\system32\csnp2uvc.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-05-28 17:25 148888 -c--a-w- c:\program files\Java\jre6\bin\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2008-11-20 09:38 1398056 -c--a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VerizonServicepoint.exe]
2009-11-18 15:50 4269296 ----a-w- c:\program files\Verizon\VSP\VerizonServicepoint.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Verizon_McciTrayApp]
2009-12-28 21:17 1551872 ----a-w- c:\program files\Verizon\McciTrayApp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"RS_Service"=2 (0x2)
"ProtexisLicensing"=2 (0x2)
"Pml Driver HPZ12"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)
"ACDaemon"=2 (0x2)
"ServicepointService"=2 (0x2)
"RoxMediaDB9"=3 (0x3)
"RoxLiveShare9"=2 (0x2)
"Roxio Upnp Server 9"=2 (0x2)
"Roxio UPnP Renderer 9"=3 (0x3)
"gupdate"=2 (0x2)
"ASKUpgrade"=2 (0x2)
"ASKService"=2 (0x2)
"RoxWatch9"=2 (0x2)
"McciCMService"=2 (0x2)
"IDriverT"=3 (0x3)
"avg8wd"=2 (0x2)
"avg8emc"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Acer\\Acer VCM\\VC.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Verizon\\VSP\\ServicepointService.exe"=
"c:\\Program Files\\TVAnts\\Tvants.exe"=
"c:\\Program Files\\StreamTorrent 1.0\\StreamTorrent.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\HTC\\HTC Sync 3.0\\adb.exe"=
"c:\\Program Files\\HTC\\HTC Sync 3.0\\htcUPCTLoader.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8085:TCP"= 8085:TCP:MyOKOPort
"9212:TCP"= 9212:TCP:SkyCaddie Desktop
"9210:UDP"= 9210:UDP:SkyCaddie Desktop
.
R2 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe [9/26/2009 12:32 AM 189736]
R2 KMWDSERVICE;Keyboard And Mouse Communication Service;c:\program files\Keyboard & Mouse Driver\KMWDSrv.exe [4/5/2007 10:29 AM 208896]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [1/26/2011 11:12 AM 22216]
R3 pneteth;PdaNet Broadband;c:\windows\system32\drivers\pneteth.sys [1/19/2011 7:16 PM 13312]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [1/26/2011 11:12 AM 366152]
S3 androidusb;ADB Interface Driver;c:\windows\system32\drivers\androidusb.sys [6/9/2011 5:59 PM 31312]
S3 easytether;easytether;c:\windows\system32\DRIVERS\easytthr.sys --> c:\windows\system32\DRIVERS\easytthr.sys [?]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [1/23/2011 10:45 PM 13192]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [1/23/2011 10:45 PM 8456]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [3/20/2010 8:06 PM 136176]
S3 HTCAND32;HTC Device Driver;c:\windows\system32\drivers\androidusb.sys [6/9/2011 5:59 PM 31312]
S3 htcnprot;HTC NDIS Protocol Driver;c:\windows\system32\drivers\htcnprot.sys [6/22/2010 6:01 PM 21248]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 pnetmdm;PdaNet Modem;c:\windows\system32\drivers\pnetmdm.sys [1/19/2011 7:16 PM 9472]
S3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RTS5121.sys [1/16/2009 8:26 PM 160256]
S3 Rts516xIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys --> c:\windows\system32\DRIVERS\Rts516xIR.sys [?]
S4 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [3/20/2010 8:06 PM 136176]
S4 PassThru Service;Internet Pass-Through Service;c:\program files\HTC\Internet Pass-Through\PassThruSvr.exe [8/12/2011 5:13 PM 87040]
S4 RS_Service;Raw Socket Service;c:\program files\Acer\Acer VCM\RS_Service.exe [1/16/2009 9:02 PM 237568]
S4 ServicepointService;ServicepointService;c:\program files\Verizon\VSP\ServicepointService.exe [1/18/2010 4:08 PM 668912]
.
Contents of the 'Scheduled Tasks' folder
.
2009-07-19 c:\windows\Tasks\FRU Task 2003-04-10 00:56ewlett-Packard2003-04-10 00:56p psc 1200 series272A572217594EBCF1CEE215E352B92AD073FDE4239404004.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-09 21:56]
.
2011-10-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-21 00:05]
.
2011-10-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-21 00:05]
.
2011-10-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3588590466-972670786-3454122357-1006Core.job
- c:\documents and settings\benjamin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-07-01 03:12]
.
2011-10-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3588590466-972670786-3454122357-1006UA.job
- c:\documents and settings\benjamin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-07-01 03:12]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride = <local>
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.9.1
FF - ProfilePath - c:\documents and settings\benjamin\Application Data\Mozilla\Firefox\Profiles\k629nd0g.default\
FF - prefs.js: browser.startup.homepage - hxxp://yahoo.com/
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{ce18769b-c7fa-42d2-860d-17c4662c70ad} - c:\program files\Babylon-English\tbBaby.dll
Toolbar-{ce18769b-c7fa-42d2-860d-17c4662c70ad} - c:\program files\Babylon-English\tbBaby.dll
Notify-avgrsstarter - (no file)
MSConfigStartUp-BlackBerryAutoUpdate - c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
MSConfigStartUp-CaddieSyncLauncher - c:\program files\SkyGolf\SkyCaddie Desktop\CaddieSyncLauncher.exe
MSConfigStartUp-ISUSPM - c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
MSConfigStartUp-msnmsgr - c:\program files\Windows Live\Messenger\msnmsgr.exe
MSConfigStartUp-RoxWatchTray - c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
MSConfigStartUp-Search Protection - c:\program files\Yahoo!\Search Protection\SearchProtection.exe
MSConfigStartUp-sysfbtray - c:\windows\bill104.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-10-05 21:33
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
.
c:\docume~1\benjamin\LOCALS~1\Temp\tmp318.tmp1
c:\docume~1\benjamin\LOCALS~1\Temp\tmp569.tmp1
.
scan completed successfully
hidden files: 2
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(1824)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\windows\system32\SearchIndexer.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2011-10-05 21:37:09 - machine was rebooted
ComboFix-quarantined-files.txt 2011-10-06 01:37
.
Pre-Run: 108,490,391,552 bytes free
Post-Run: 109,993,287,680 bytes free
.
- - End Of File - - DF3F38671EDD186CC21186243D35BCA2