Ran combofix last night without much trouble until the step that reloads windows. The computer froze up during the step: "Preparing Log Report" I had to reboot the computer this morning and try again.
The second attempt ran with no problems. However, Internet Explorer browser still runs slow. First reboot of pc after saving the combofix log still froze up when I tried to load yahoo.com.
Log follows:
ComboFix 10-05-20.A0 - Owner 05/21/2010 6:34.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2037.1536 [GMT -4:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
AV: Trend Micro AntiVirus *On-access scanning disabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\service
c:\windows\system32\service\21052010_TIS17_SfFniAU.log
c:\windows\Tasks.\nqnhaqiw.job
c:\windows\Tasks.\nqnhaqiw.job . . . . failed to delete
.
---- Previous Run -------
.
c:\documents and settings\Owner\Recent\Thumbs.db
c:\program files\Internet Explorer\SET109.tmp
c:\program files\Internet Explorer\SET10A.tmp
c:\program files\Internet Explorer\SET10C.tmp
c:\program files\Internet Explorer\SET2BE.tmp
c:\program files\Internet Explorer\SET2BF.tmp
c:\program files\Internet Explorer\SET2C1.tmp
c:\windows\Downloaded Program Files\f3initialsetup1.0.1.1.inf
c:\windows\system32\service\01042010_TIS17_SfFniAU.log
c:\windows\system32\service\02042010_TIS17_SfFniAU.log
c:\windows\system32\service\02082009_TIS17_SfFniAU.log
c:\windows\system32\service\02092009_TIS17_SfFniAU.log
c:\windows\system32\service\04042010_TIS17_SfFniAU.log
c:\windows\system32\service\04072009_TIS17_SfFniAU.log
c:\windows\system32\service\04092009_TIS17_SfFniAU.log
c:\windows\system32\service\05082009_TIS17_SfFniAU.log
c:\windows\system32\service\06032010_TIS17_SfFniAU.log
c:\windows\system32\service\06092009_TIS17_SfFniAU.log
c:\windows\system32\service\07072009_TIS17_SfFniAU.log
c:\windows\system32\service\07082009_TIS17_SfFniAU.log
c:\windows\system32\service\08012010_TIS17_SfFniAU.log
c:\windows\system32\service\08052010_TIS17_SfFniAU.log
c:\windows\system32\service\08082009_TIS17_SfFniAU.log
c:\windows\system32\service\09022010_TIS17_SfFniAU.log
c:\windows\system32\service\09122009_TIS17_SfFniAU.log
c:\windows\system32\service\10072009_TIS17_SfFniAU.log
c:\windows\system32\service\11032010_TIS17_SfFniAU.log
c:\windows\system32\service\13042010_TIS17_SfFniAU.log
c:\windows\system32\service\14042010_TIS17_SfFniAU.log
c:\windows\system32\service\14052010_TIS17_SfFniAU.log
c:\windows\system32\service\14072009_TIS17_SfFniAU.log
c:\windows\system32\service\15032010_TIS17_SfFniAU.log
c:\windows\system32\service\16092009_TIS17_SfFniAU.log
c:\windows\system32\service\17052010_TIS17_SfFniAU.log
c:\windows\system32\service\18042010_TIS17_SfFniAU.log
c:\windows\system32\service\18072009_TIS17_SfFniAU.log
c:\windows\system32\service\19012010_TIS17_SfFniAU.log
c:\windows\system32\service\19092009_TIS17_SfFniAU.log
c:\windows\system32\service\21012010_TIS17_SfFniAU.log
c:\windows\system32\service\21022010_TIS17_SfFniAU.log
c:\windows\system32\service\22082009_TIS17_SfFniAU.log
c:\windows\system32\service\23072009_TIS17_SfFniAU.log
c:\windows\system32\service\24032010_TIS17_SfFniAU.log
c:\windows\system32\service\24072009_TIS17_SfFniAU.log
c:\windows\system32\service\24082009_TIS17_SfFniAU.log
c:\windows\system32\service\25102009_TIS17_SfFniAU.log
c:\windows\system32\service\27062009_TIS17_SfFniAU.log
c:\windows\system32\service\27102009_TIS17_SfFniAU.log
c:\windows\system32\service\28062009_TIS17_SfFniAU.log
c:\windows\system32\service\28072009_TIS17_SfFniAU.log
c:\windows\system32\service\28092009_TIS17_SfFniAU.log
c:\windows\system32\service\30082009_TIS17_SfFniAU.log
c:\windows\system32\service\31082009_TIS17_SfFniAU.log
c:\windows\Tasks.\nqnhaqiw.job
c:\windows\wiaserviv.log
D:\Autorun.inf
c:\windows\Tasks.\nqnhaqiw.job . . . . failed to delete
-- Previous Run --
c:\windows\system32\proquota.exe was missing
Restored copy from - c:\windows\ServicePackFiles\i386\proquota.exe
--------
.
((((((((((((((((((((((((( Files Created from 2010-04-21 to 2010-05-21 )))))))))))))))))))))))))))))))
.
2010-05-21 04:26 . 2008-04-14 00:12 50176 -c--a-w- c:\windows\system32\dllcache\proquota.exe
2010-05-21 04:26 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\proquota.exe
2010-05-19 03:19 . 2010-05-19 03:19 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-05-19 03:19 . 2010-05-19 03:40 -------- d-----w- c:\program files\SUPERAntiSpyware
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-19 03:43 . 2008-11-22 00:41 -------- d-----w- c:\program files\Windows Live Safety Center
2010-05-19 03:40 . 2010-02-14 05:07 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-05-18 02:46 . 2010-01-09 02:27 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-05-16 03:34 . 2008-12-31 14:36 -------- d-----w- c:\program files\V CAST Music with Rhapsody
2010-05-12 15:21 . 2009-12-04 11:56 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-04-29 19:39 . 2010-01-09 02:27 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 19:39 . 2010-01-09 02:27 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-11 23:54 . 2006-08-08 00:28 -------- d-----w- c:\documents and settings\Owner\Application Data\AdobeUM
2010-03-11 12:38 . 2005-01-09 23:48 832512 ----a-w- c:\windows\system32\wininet.dll
2010-03-11 12:38 . 2005-01-09 23:48 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-03-11 12:38 . 2005-01-09 23:47 17408 ------w- c:\windows\system32\corpol.dll
2010-03-09 11:09 . 2005-01-09 23:48 430080 ----a-w- c:\windows\system32\vbscript.dll
2010-03-07 17:46 . 2010-03-07 17:47 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-02-24 13:11 . 2005-01-09 23:48 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2008-06-26 16:16 . 2008-06-26 16:16 23 --sha-w- c:\windows\system32\acabbfcdfba3_r.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\BackupIconOverlayId]
@="{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}"
[HKEY_CLASSES_ROOT\CLSID\{2EE61E5C-8F94-4AAB-8A80-D2A8CD1FEDAD}]
2009-03-05 21:02 238968 ----a-w- c:\program files\Webroot\Spy Sweeper\Backup\CtxMenu_1_0_0_10.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"AlwaysReady Power Message APP"="c:\windows\ARPWRMSG.EXE" [2005-08-03 77312]
"readericon"="c:\program files\Digital Media Reader\readericon45G.exe" [2005-12-10 139264]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-10-12 139264]
"LXSUPMON"="c:\windows\system32\LXSUPMON.EXE" [2002-08-15 886272]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-09-29 185784]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-04 866584]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2009-10-21 995528]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"SpySweeper"="c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2009-11-06 6515784]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"="NA" [X]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ljJCvTkL]
ljJCvTkL.dll [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tuvUNFVn]
tuvUNFVn.dll [BU]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\EA Games\\Command & Conquer The First Decade\\Command & Conquer Generals\\game.dat"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\EA Games\\Command & Conquer The First Decade\\Command & Conquer Renegade\\Renegade\\Game.exe"=
"c:\\WINDOWS\\system32\\LEXPPS.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Defender\\MSASCui.exe"=
R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\drivers\ssfs0bbc.sys [10/2/2008 4:15 AM 29808]
R2 HPFECP16;HPFECP16;c:\windows\system32\drivers\HPFecp16.sys [7/1/1998 2:55 AM 52800]
R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [6/27/2009 1:48 AM 36368]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 8:19 PM 13592]
R2 WRConsumerService;Webroot Client Service;c:\program files\Webroot\Spy Sweeper\WRConsumerService.exe [10/18/2008 12:37 AM 1201640]
S2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [6/27/2009 1:54 AM 50192]
S2 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [6/27/2009 1:54 AM 677128]
.
Contents of the 'Scheduled Tasks' folder
2010-05-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2006-07-23 c:\windows\Tasks\ISP signup reminder 2.job
- c:\windows\system32\OOBE\oobebaln.exe [2005-01-10 00:12]
2010-05-21 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]
2010-05-21 c:\windows\Tasks\User_Feed_Synchronization-{449BDC8D-DE54-4A69-8C93-89802D5DE41A}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 23:36]
2010-05-17 c:\windows\Tasks\wrSpySweeper_3BAF43EA2FE54F74814B2C76AC6BD9B7.job
- c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe [2006-08-05 20:19]
2010-05-17 c:\windows\Tasks\wrSpySweeper_3BAF43EA2FE54F74814B2C76AC6BD9B7.job
- c:\program files\Webroot\Spy Sweeper\SpySweeperUI.exe [2006-08-05 20:19]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel
Trusted Zone: amazon.com\www
Trusted Zone: ebay.com\www
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-05-21 06:42
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2524)
c:\windows\system32\WININET.dll
c:\program files\Webroot\Spy Sweeper\Backup\CtxMenu_1_0_0_10.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\windows\arservice.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Intel\Intel Matrix Storage Manager\iaantmon.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\SigmaTel\C-Major Audio\WDM\Stacsv.exe
c:\program files\Webroot\Spy Sweeper\SpySweeper.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
c:\windows\system32\dllhost.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\eHome\ehmsas.exe
c:\program files\Real\RealPlayer\RealPlay.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-05-21 06:59:05 - machine was rebooted
ComboFix-quarantined-files.txt 2010-05-21 10:59
Pre-Run: 65,725,636,608 bytes free
Post-Run: 65,377,112,064 bytes free
- - End Of File - - 905C12183ECFE5FF410ED99B48EB8D2C