Computer is running much better. Dramatic improvement.
ComboFix 11-12-16.03 - Dani 12/16/2011 23:43:59.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.607 [GMT -7:00]
Running from: C:\Documents and Settings\Dani\My Documents\Downloads\ComboFix.exe
AV: Norton AntiVirus *Disabled/Outdated* {E10A9785-9598-4754-B552-92431C1C35F8}
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Documents and Settings\All Users\Application Data\TEMP
C:\WINDOWS\$NtUninstallKB54362$
C:\WINDOWS\$NtUninstallKB54362$\152707132
C:\WINDOWS\$NtUninstallKB54362$\3584426492\@
C:\WINDOWS\$NtUninstallKB54362$\3584426492\bckfg.tmp
C:\WINDOWS\$NtUninstallKB54362$\3584426492\cfg.ini
C:\WINDOWS\$NtUninstallKB54362$\3584426492\Desktop.ini
C:\WINDOWS\$NtUninstallKB54362$\3584426492\keywords
C:\WINDOWS\$NtUninstallKB54362$\3584426492\kwrd.dll
C:\WINDOWS\$NtUninstallKB54362$\3584426492\L\odetmngk
C:\WINDOWS\$NtUninstallKB54362$\3584426492\lsflt7.ver
C:\WINDOWS\$NtUninstallKB54362$\3584426492\U\00000001.@
C:\WINDOWS\$NtUninstallKB54362$\3584426492\U\00000002.@
C:\WINDOWS\$NtUninstallKB54362$\3584426492\U\00000004.@
C:\WINDOWS\$NtUninstallKB54362$\3584426492\U\80000000.@
C:\WINDOWS\$NtUninstallKB54362$\3584426492\U\80000004.@
C:\WINDOWS\$NtUninstallKB54362$\3584426492\U\80000032.@
C:\WINDOWS\Downloaded Installations\BMP
C:\WINDOWS\Downloaded Installations\BMP\{61C062D5-7A00-44BC-BC16-125BDF22EA65}\1033.MST
C:\WINDOWS\Downloaded Installations\BMP\{61C062D5-7A00-44BC-BC16-125BDF22EA65}\BACS.msi
C:\WINDOWS\system32\A1D7EB923C.dll
((((((((((((((((((((((((( Files Created from 2011-11-17 to 2011-12-17 )))))))))))))))))))))))))))))))
2011-12-16 23:40:12 . 2011-12-16 23:51:55 -------- d-----w- C:\Documents and Settings\Administrator
2011-12-16 22:57:39 . 2011-12-16 22:57:39 -------- d-----w- C:\Documents and Settings\Dani\Application Data\FixTDSS
2011-12-16 22:57:34 . 2011-12-16 23:10:51 26872 ----a-w- C:\WINDOWS\system32\drivers\FixTDSS.sys
2011-12-07 20:49:25 . 2011-12-07 20:49:25 -------- d-sh--w- C:\Documents and Settings\NetworkService\IETldCache
2011-12-06 08:58:20 . 2011-11-21 10:47:38 6823496 ----a-w- C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{850E7524-25CD-4D6E-8AD7-A3F2B6FB1CD9}\mpengine.dll
2011-12-04 14:34:07 . 2011-12-04 14:34:07 -------- d-----w- C:\Program Files\iPod
2011-12-04 14:33:41 . 2011-12-04 14:35:19 -------- d-----w- C:\Program Files\iTunes
2011-12-04 14:26:59 . 2011-12-04 14:26:59 -------- d-----w- C:\Documents and Settings\LocalService\Application Data\Apple Computer
2011-12-04 14:25:50 . 2011-12-04 14:25:51 -------- d-----w- C:\Program Files\Bonjour
2011-11-21 15:37:59 . 2011-11-21 15:37:59 -------- d-----w- C:\Documents and Settings\All Users\Application Data\McAfee Security Scan
2011-11-21 15:37:50 . 2011-11-29 17:56:36 -------- d-----w- C:\Program Files\McAfee Security Scan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2011-12-17 04:05:10 . 2004-08-10 18:51:12 456320 ----a-w- C:\WINDOWS\system32\drivers\mrxsmb.sys
2011-11-21 10:47:38 . 2006-12-31 20:11:24 6823496 ----a-w- C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2011-11-03 17:48:36 . 2011-05-21 01:17:49 414368 ----a-w- C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2011-10-24 21:29:02 . 2011-10-24 21:29:02 94208 ----a-w- C:\WINDOWS\system32\QuickTimeVR.qtx
2011-10-24 21:29:02 . 2011-10-24 21:29:02 69632 ----a-w- C:\WINDOWS\system32\QuickTime.qts
2011-10-10 14:22:41 . 2004-08-10 19:02:25 692736 ----a-w- C:\WINDOWS\system32\inetcomm.dll
2011-09-28 07:06:50 . 2004-08-10 18:50:55 599040 ----a-w- C:\WINDOWS\system32\crypt32.dll
2011-09-26 18:41:20 . 2008-07-30 02:59:58 611328 ----a-w- C:\WINDOWS\system32\uiautomationcore.dll
2011-09-26 18:41:20 . 2004-08-10 18:51:19 220160 ----a-w- C:\WINDOWS\system32\oleacc.dll
2011-09-26 18:41:14 . 2004-08-10 18:51:19 20480 ----a-w- C:\WINDOWS\system32\oleaccrc.dll
2011-11-09 03:44:25 . 2011-05-08 21:36:30 134104 ----a-w- C:\Program Files\mozilla firefox\components\browsercomps.dll
2010-09-11 14:29:42 . 2007-08-12 08:23:38 119808 ----a-w- C:\Program Files\mozilla firefox\components\GoogleDesktopMozilla.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\Dell Support\DSAgnt.exe" [2006-08-29 03:57:12 395776]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-06 02:13:04 68856]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 17:55:32 206064]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 00:12:16 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-06-16 14:39:00 7323648]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 09:12:00 94208]
"SigmatelSysTrayApp"="stsystra.exe" [2006-08-15 09:00:20 282624]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 11:20:00 122940]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 22:50:42 221184]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 22:50:18 81920]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-09-11 14:29:42 30192]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [2005-12-07 10:55:00 131072]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2005-07-08 04:55:00 176128]
"HPHUPD05"="C:\Program Files\Hewlett-Packard\\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe" [2005-07-08 04:55:02 49152]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 22:18:56 241664]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2003-12-05 22:41:44 49152]
"HPHmon05"="C:\WINDOWS\system32\hphmon05.exe" [2005-07-08 04:55:02 491520]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-10-10 01:57:14 16384]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 17:55:32 206064]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-03-17 04:58:34 47392]
"hpbdfawep"="C:\Program Files\HP\Dfawep\bin\hpbdfawep.exe" [2007-04-25 21:28:34 954368]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" [2004-09-22 15:00:00 94208]
"Seagate Dashboard"="C:\Program Files\Seagate\Seagate Dashboard\MemeoLauncher.exe" [2010-07-06 19:32:04 79112]
"KodakShareButtonApp"="C:\Program Files\Kodak\KODAK Share Button App\Listener.exe" [2011-03-07 19:21:00 107008]
"TkBellExe"="C:\program files\real\realplayer\update\realsched.exe" [2011-06-27 05:41:29 273544]
"Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 19:55:28 937920]
"APSDaemon"="C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 14:22:28 59240]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2011-11-13 07:24:58 421736]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2011-10-24 21:28:52 421888]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-23 02:29:28 39264]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
McAfee Security Scan Plus.lnk - C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Network Associates\\Common Framework\\FrameworkService.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Hewlett-Packard\\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\\hphver05.exe"=
"C:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R0 FixTDSS;TDSS Fixtool driver;C:\WINDOWS\system32\drivers\FixTDSS.sys [12/16/2011 3:57:34 PM 26872]
R0 SymDS;Symantec Data Store;C:\WINDOWS\system32\drivers\NAV\1206000.01D\symds.sys [5/9/2011 3:58:39 PM 340088]
R0 SymEFA;Symantec Extended File Attributes;C:\WINDOWS\system32\drivers\NAV\1206000.01D\symefa.sys [5/9/2011 3:58:40 PM 744568]
R1 BHDrvx86;BHDrvx86;C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\BASHDefs\20111210.003\BHDrvx86.sys [12/14/2011 3:50:14 PM 819320]
R1 NaiAvTdi1;NaiAvTdi1;C:\WINDOWS\system32\drivers\mvstdi5x.sys [11/1/2010 5:37:45 PM 58464]
R1 SymIRON;Symantec Iron Driver;C:\WINDOWS\system32\drivers\NAV\1206000.01D\ironx86.sys [5/9/2011 3:58:38 PM 136312]
R2 NAV;Norton AntiVirus;C:\Program Files\Norton AntiVirus\Engine\18.6.0.29\ccsvchst.exe [5/9/2011 3:57:58 PM 130008]
R2 SeagateDashboardService;Seagate Dashboard Service;C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe [7/6/2010 12:32:04 PM 14088]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [12/7/2011 4:25:11 PM 106104]
R3 IDSxpx86;IDSxpx86;C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\IPSDefs\20111216.001\IDSXpx86.sys [12/16/2011 9:26:58 PM 356280]
S2 gupdate;Google Update Service (gupdate);C:\Program Files\Google\Update\GoogleUpdate.exe [4/2/2010 10:27:35 PM 135664]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [12/13/2006 11:05:02 AM 30192]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files\Google\Update\GoogleUpdate.exe [4/2/2010 10:27:35 PM 135664]
S3 McComponentHostService;McAfee Security Scan Component Host Service;C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe [1/15/2010 5:49:20 AM 227232]
Contents of the 'Scheduled Tasks' folder
2011-12-15 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-02 00:57:16 . 2011-06-02 00:57:16]
2011-12-17 C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
- C:\Program Files\Google\Update\GoogleUpdate.exe [2010-04-03 05:27:35 . 2010-04-03 05:27:31]
2011-12-17 C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
- C:\Program Files\Google\Update\GoogleUpdate.exe [2010-04-03 05:27:35 . 2010-04-03 05:27:31]
2011-12-16 C:\WINDOWS\Tasks\HP Usg Daily.job
- C:\Program Files\Hewlett-Packard\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\pexpress\hphped05.exe [2007-08-06 03:58:16 . 2005-07-08 04:55:02]
2011-12-16 C:\WINDOWS\Tasks\MP Scheduled Scan.job
- C:\Program Files\Windows Defender\MpCmdRun.exe [2006-11-04 01:20:06 . 2006-11-04 01:20:06]
2011-12-17 C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-3794800269-4273047125-2885643043-1007.job
- C:\Program Files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47:46 . 2011-03-29 17:47:46]
2011-12-17 C:\WINDOWS\Tasks\RealUpgradeLogonTaskS-1-5-21-3794800269-4273047125-2885643043-1008.job
- C:\Program Files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47:46 . 2011-03-29 17:47:46]
2011-12-17 C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-3794800269-4273047125-2885643043-1007.job
- C:\Program Files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47:46 . 2011-03-29 17:47:46]
2011-12-13 C:\WINDOWS\Tasks\RealUpgradeScheduledTaskS-1-5-21-3794800269-4273047125-2885643043-1008.job
- C:\Program Files\Real\RealUpgrade\realupgrade.exe [2011-03-29 17:47:46 . 2011-03-29 17:47:46]
------- Supplementary Scan -------
uStart Page = hxxp://www.bing.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 68.105.28.11 68.105.29.11 68.105.28.12
FF - ProfilePath - C:\Documents and Settings\Dani\Application Data\Mozilla\Firefox\Profiles\l80f9ess.default\
- - - - ORPHANS REMOVED - - - -
HKLM-Run-SunJavaUpdateSched - C:\Program Files\Java\jre6\bin\jusched.exe
SafeBoot-58147492.sys
SafeBoot-WinDefend
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-12-17 00:14:46
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NAV]
"ImagePath"="\"C:\Program Files\Norton AntiVirus\Engine\18.6.0.29\ccSvcHst.exe\" /s \"NAV\" /m \"C:\Program Files\Norton AntiVirus\Engine\18.6.0.29\diMaster.dll\" /prefetch:1"
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2008)
C:\WINDOWS\system32\WININET.dll
C:\WINDOWS\system32\ieframe.dll
C:\WINDOWS\system32\webcheck.dll
C:\WINDOWS\system32\WPDShServiceObj.dll
C:\WINDOWS\system32\PortableDeviceTypes.dll
C:\WINDOWS\system32\PortableDeviceApi.dll
C:\WINDOWS\System32\DLA\DLASHX_W.DLL
C:\WINDOWS\system32\DLAAPI_W.DLL
C:\WINDOWS\System32\DLA\DLACResW.dll
C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
------------------------ Other Running Processes ------------------------
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Network Associates\Common Framework\naPrdMgr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HP1006MC.EXE
C:\WINDOWS\stsystra.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\program files\real\realplayer\RealPlay.exe
c:\program files\real\realplayer\RealPlay.exe
C:\Program Files\Seagate\Seagate Dashboard\MemeoDashboard.exe
C:\Program Files\McAfee Security Scan\2.0.181\McUICnt.exe
**************************************************************************
Completion time: 2011-12-17 00:27:19 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-17 07:27:00
Pre-Run: 98,483,314,688 bytes free
Post-Run: 104,210,632,704 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - B0E8DE91CD3CDB66256574AD2EB33D59