I had suspected malware on my computer causing redirects mostly from search engine pages such as Google. When I did a typical Google search to generate potential links.....when I chose and clicked a link it would not take me to the associated URL, rather redirect me to a different website, alternate search engine, advertisement, etc.
At that point I started researching online a bit and discovered that 'rootkit' issues typically cause redirects, but am in no way computer saavy. With that said, I ran the Combofix from Bleepingcomputer.com download and generated the Log Report below.
I am asking that an experienced helper please review the Log Report, and let me know if any other infections are left over that need to be analyzed further.
Thank you in advance!
LOG REPORT GENERATED BY COMBOFIX:
ComboFix 10-06-07.04 - HP_Administrator 06/08/2010 12:02:03.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.958.638 [GMT -4:00]
Running from: c:\documents and settings\HP_Administrator.YOUR-4DACD0EA75\Desktop\ComboFix.exe
AV: CA Anti-Virus *On-access scanning disabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}
FW: CA Personal Firewall *enabled* {14CB4B80-8E52-45EA-905E-67C1267B4160}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\FunWebProducts
c:\program files\FunWebProducts\ScreenSaver\Cache\5B3A64AB
c:\program files\FunWebProducts\ScreenSaver\Cache\5B3D0F78.jpg
c:\program files\FunWebProducts\ScreenSaver\Cache\5B41DA47
c:\program files\FunWebProducts\ScreenSaver\Cache\5B42C93A.jpg
c:\program files\FunWebProducts\ScreenSaver\Cache\5B437FAA.swf
c:\program files\FunWebProducts\ScreenSaver\Cache\5B43BBA9.swf
c:\program files\FunWebProducts\ScreenSaver\Cache\5B4D4D9C.jpg
c:\program files\FunWebProducts\ScreenSaver\Cache\files.ini
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21ACBADC.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21ACE9AC.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21ACEB23.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21AD16C7.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21AD1909.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21ADD729.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21ADDB40.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21AE00E9.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21AE053E.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21AE2AF6.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21AE30E2.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21AE6020.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21AE63F8.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21AE8952.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21AF028A.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21AF4792.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21AF6A5C.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21AF6ED0.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21AF9851.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21B16BF8.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21B16E88.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21B2AB3F.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21B30D15.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21B30FB5.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21B34C22.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21B3500A.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21B38CC5.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21B393D9.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21B3986D.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21B3C068.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21B3C402.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21B404E3.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21B40909.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21B42636.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21B4277E.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21B53FF3.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21B55DCC.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21B586EF.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21B58A99.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21B5A91D.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21B5ABCD.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21B5DA20.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21B5DDAA.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21B5FD96.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21B6019D.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21B62199.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\21B628DC.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B3D2736.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B3D572F.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B3D839E.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B3DB463.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B3DEC5B.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B3E1782.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B3E4A2B.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B3E790B.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B3EE13A.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B426967.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B42951B.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B42C8CD.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B42CBFA.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B42F626.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B431641.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B431900.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B4346B7.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B434928.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B436FEA.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B44BC60.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B44DB90.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B44F7C3.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B4516E4.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B451A2F.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B455227.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B455479.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B45DCF3.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B45E08D.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B461808.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B46360F.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B463CD6.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B4679EE.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B4681AF.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B46DB58.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B4722C1.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B47289D.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B474DF7.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B475422.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B47A280.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B47D344.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B47D855.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B481176.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B4815FB.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B4858E0.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B48CB8F.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B48D0A0.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B496F32.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B4B0F07.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B4B133D.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B4B3AE9.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B4B424C.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B4B6B8E.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B4B6F57.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B4B929E.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B4B97AF.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B4BBC9C.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B4BC075.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B4CFFBB.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B4D05D5.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B4D40DB.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B4D4D5E.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B4D5424.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B4D78F2.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B4D7DE4.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B4DA4E4.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B4DAF54.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B4DB56F.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B4DDB17.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B4DE633.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B4DEF0D.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B4E166B.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B4E1BE9.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B4E428C.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B4E4C11.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B4E76F9.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B4E7EAA.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\101x135\5B4EA4D0.jpg
c:\program files\FunWebProducts\ScreenSaver\Images\21ACBADC.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21ACE9AC.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21ACEB23.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21AD16C7.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21AD1909.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21AD43A3.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21AD44DC.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21AD75FE.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21AD76D9.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21ADA4CE.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21ADA617.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21ADD729.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21ADDB40.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21AE00E9.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21AE053E.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21AE2AF6.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21AE30E2.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21AE6020.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21AE63F8.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21AE8952.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21AF028A.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21AF1304.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21AF4158.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21AF4792.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21AF6A5C.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21AF6ED0.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21AF9851.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21AFA041.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21B16BF8.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21B16E88.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21B2AB3F.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21B30D15.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21B30FB5.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21B34C22.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21B3500A.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21B38CC5.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21B393D9.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21B3986D.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21B3C068.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21B3C402.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21B404E3.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21B40909.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21B42636.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21B4277E.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21B53FF3.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21B55DCC.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21B586EF.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21B58A99.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21B5A91D.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21B5ABCD.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21B5DA20.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21B5DDAA.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21B5FD96.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21B6019D.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21B62199.dat
c:\program files\FunWebProducts\ScreenSaver\Images\21B628DC.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B39FD75.urr
c:\program files\FunWebProducts\ScreenSaver\Images\5B3A60A4.urr
c:\program files\FunWebProducts\ScreenSaver\Images\5B3A8775.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B3C12C9.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B3CE21F.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B3D2736.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B3D572F.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B3D839E.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B3DB463.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B3DEC5B.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B3E1782.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B3E4A2B.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B3E790B.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B3EACAD.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B3EE13A.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B41D9CA.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B41DB21.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B420E47.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4239BC.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4242B5.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B426967.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B428E06.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B42951B.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B42C8CD.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B42CBFA.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B42F626.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B431641.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B431900.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4346B7.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B434928.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B436FEA.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B44B962.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B44BC60.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B44DB90.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B44F7C3.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4516E4.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B451A2F.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B455227.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B455479.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B45DCF3.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B45E08D.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B461808.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B46360F.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B463CD6.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4679EE.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4681AF.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B46DB58.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B46E77D.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B46F19F.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4722C1.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B47289D.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B474DF7.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B475422.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B47A280.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B47D344.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B47D855.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B481176.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4815FB.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4858E0.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B48954C.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4896B4.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B48CB8F.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B48D0A0.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B494FD2.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B496F32.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4B0F07.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4B133D.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4B3AE9.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4B424C.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4B6B8E.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4B6F57.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4B929E.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4B97AF.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4BBC9C.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4BC075.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4CFFBB.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4D05D5.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4D40DB.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4D4D5E.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4D5424.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4D78F2.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4D7DE4.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4DA4E4.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4DAF54.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4DB56F.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4DDB17.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4DE633.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4DEF0D.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4E166B.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4E1BE9.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4E428C.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4E4C11.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4E76F9.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4E7EAA.dat
c:\program files\FunWebProducts\ScreenSaver\Images\5B4EA4D0.dat
c:\program files\FunWebProducts\ScreenSaver\Images\wrkparam.lst
c:\program files\FunWebProducts\Shared\Cache\AvatarSmallBtn-new.html
c:\program files\FunWebProducts\Shared\Cache\AvatarSmallBtn.html
c:\program files\FunWebProducts\Shared\Cache\CursorManiaBtn.html
c:\program files\FunWebProducts\Shared\Cache\FunBuddyIconBtn-new.html
c:\program files\FunWebProducts\Shared\Cache\FunBuddyIconBtn.html
c:\program files\FunWebProducts\Shared\Cache\MailStampBtn.html
c:\program files\FunWebProducts\Shared\Cache\MyFunCardsIMBtn-new.html
c:\program files\FunWebProducts\Shared\Cache\MyFunCardsIMBtn.html
c:\program files\FunWebProducts\Shared\Cache\MyStationeryBtn.html
c:\program files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html
c:\program files\Internet Explorer\msimg32.dll
c:\program files\MyWebSearch
c:\program files\MyWebSearch\bar\1.bin\F3BKGERR.JPG
c:\program files\MyWebSearch\bar\1.bin\F3BROVLY.DLL
c:\program files\MyWebSearch\bar\1.bin\F3CJPEG.DLL
c:\program files\MyWebSearch\bar\1.bin\F3DTACTL.DLL
c:\program files\MyWebSearch\bar\1.bin\F3HISTSW.DLL
c:\program files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL
c:\program files\MyWebSearch\bar\1.bin\F3HTTPCT.DLL
c:\program files\MyWebSearch\bar\1.bin\F3IMSTUB.DLL
c:\program files\MyWebSearch\bar\1.bin\F3POPSWT.DLL
c:\program files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR
c:\program files\MyWebSearch\bar\1.bin\F3REPROX.DLL
c:\program files\MyWebSearch\bar\1.bin\F3RESTUB.DLL
c:\program files\MyWebSearch\bar\1.bin\F3SCHMON.EXE
c:\program files\MyWebSearch\bar\1.bin\F3SCRCTR.DLL
c:\program files\MyWebSearch\bar\1.bin\F3SHLLVW.DLL
c:\program files\MyWebSearch\bar\1.bin\F3SPACER.WMV
c:\program files\MyWebSearch\bar\1.bin\F3WALLPP.DAT
c:\program files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL
c:\program files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR
c:\program files\MyWebSearch\bar\1.bin\M3FFXTBR.MANIFEST
c:\program files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR
c:\program files\MyWebSearch\bar\1.bin\M3NTSTBR.MANIFEST
c:\program files\MyWebSearch\bar\Avatar\COMMON.F3S
c:\program files\MyWebSearch\bar\Cache\014656A9.bin
c:\program files\MyWebSearch\bar\Cache\01465811.bin
c:\program files\MyWebSearch\bar\Cache\01466417.bin
c:\program files\MyWebSearch\bar\Cache\01466484.bin
c:\program files\MyWebSearch\bar\Cache\0CC68878
c:\program files\MyWebSearch\bar\Cache\148FAB44
c:\program files\MyWebSearch\bar\Cache\2BD59F2B
c:\program files\MyWebSearch\bar\Cache\51438FF9
c:\program files\MyWebSearch\bar\Cache\5B39F0C3
c:\program files\MyWebSearch\bar\Cache\5B39F288.bin
c:\program files\MyWebSearch\bar\Cache\5B39F78A.bin
c:\program files\MyWebSearch\bar\Cache\5B39FA97.bin
c:\program files\MyWebSearch\bar\Cache\5B39FB91.bin
c:\program files\MyWebSearch\bar\Cache\6151D529.bin
c:\program files\MyWebSearch\bar\Cache\6151EA47.bin
c:\program files\MyWebSearch\bar\Cache\6151EBCE.bin
c:\program files\MyWebSearch\bar\Cache\6151ECF7.bin
c:\program files\MyWebSearch\bar\Cache\files.ini
c:\program files\MyWebSearch\bar\Game\CHECKERS.F3S
c:\program files\MyWebSearch\bar\Game\CHESS.F3S
c:\program files\MyWebSearch\bar\Game\REVERSI.F3S
c:\program files\MyWebSearch\bar\History\search2
c:\program files\MyWebSearch\bar\icons\CM.ICO
c:\program files\MyWebSearch\bar\icons\MFC.ICO
c:\program files\MyWebSearch\bar\icons\PSS.ICO
c:\program files\MyWebSearch\bar\icons\SMILEY.ICO
c:\program files\MyWebSearch\bar\icons\WB.ICO
c:\program files\MyWebSearch\bar\icons\ZWINKY.ICO
c:\program files\MyWebSearch\bar\Message\COMMON.F3S
c:\program files\MyWebSearch\bar\Notifier\COMMON.F3S
c:\program files\MyWebSearch\bar\Notifier\DOG.F3S
c:\program files\MyWebSearch\bar\Notifier\FISH.F3S
c:\program files\MyWebSearch\bar\Notifier\KUNGFU.F3S
c:\program files\MyWebSearch\bar\Notifier\LIFEGARD.F3S
c:\program files\MyWebSearch\bar\Notifier\MAID.F3S
c:\program files\MyWebSearch\bar\Notifier\MAILBOX.F3S
c:\program files\MyWebSearch\bar\Notifier\OPERA.F3S
c:\program files\MyWebSearch\bar\Notifier\ROBOT.F3S
c:\program files\MyWebSearch\bar\Notifier\SEDUCT.F3S
c:\program files\MyWebSearch\bar\Notifier\SURFER.F3S
c:\program files\MyWebSearch\bar\Settings\prevcfg2.htm
c:\program files\MyWebSearch\bar\Settings\s_pid.dat
c:\program files\MyWebSearch\bar\Settings\setting2.htm
c:\program files\MyWebSearch\bar\Settings\settings.dat
D:\Autorun.inf
Infected copy of c:\windows\system32\drivers\mouclass.sys was found and disinfected
Restored copy from - Kitty had a snack

.
((((((((((((((((((((((((( Files Created from 2010-05-08 to 2010-06-08 )))))))))))))))))))))))))))))))
.
2010-05-26 06:32 . 2010-05-26 06:32 -------- d-----w- c:\windows\system32\wbem\Repository
2010-05-25 01:27 . 2010-05-25 01:27 -------- d-----w- c:\documents and settings\HP_Administrator.YOUR-4DACD0EA75\Local Settings\Application Data\Threat Expert
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-08 16:00 . 2008-05-22 21:40 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k7
2010-06-08 16:00 . 2008-05-22 21:40 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k6
2010-06-08 16:00 . 2008-05-22 21:40 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k5
2010-06-08 16:00 . 2008-05-22 21:40 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k4
2010-06-08 16:00 . 2008-05-22 21:40 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k3
2010-06-08 16:00 . 2008-05-22 21:40 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k2
2010-06-08 16:00 . 2008-05-22 21:40 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k1
2010-06-08 16:00 . 2008-05-22 21:40 172156 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k0
2010-06-03 16:14 . 2008-05-17 00:45 746216 ----a-w- c:\windows\system32\drivers\vetefile.sys
2010-06-03 16:14 . 2008-05-17 00:45 130280 ----a-w- c:\windows\system32\drivers\veteboot.sys
2010-06-03 16:14 . 2008-03-04 07:41 1561896 ----a-w- c:\documents and settings\All Users\Application Data\CA\Consumer\AV\tmp\vete_tmp.dll
2010-06-01 05:41 . 2010-03-14 06:38 439816 ----a-w- c:\documents and settings\HP_Administrator.YOUR-4DACD0EA75\Application Data\Real\Update\setup3.10\setup.exe
2010-05-27 12:40 . 2008-05-17 00:45 91472 ----a-w- c:\windows\system32\isafprod.dll
2010-05-25 05:05 . 2008-03-25 16:33 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-05-18 04:44 . 2010-05-08 22:57 -------- d-----w- c:\documents and settings\HP_Administrator.YOUR-4DACD0EA75\Application Data\Jenkat
2007-07-04 19:02 . 2007-07-04 19:02 774144 ----a-w- c:\program files\RngInterstitial.dll
2008-02-20 00:00 . 2008-02-20 00:00 30720 --sha-w- c:\windows\rnapxs\rnapxs.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-08-21 185896]
"RTHDCPL"="RTHDCPL.EXE" [2006-03-08 16010240]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-23 237568]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
"QOELOADER"="c:\program files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe" [2008-05-17 14088]
"nwiz"="nwiz.exe" [2006-01-25 1519616]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-01-25 7311360]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-02 61440]
"HPHUPD08"="c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-16 249856]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-30 67584]
"DMAScheduler"="c:\program files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-03-20 90112]
"DiscUpdateManager"="c:\program files\DISC\DiscUpdMgr.exe" [2006-03-16 61440]
"DISCover"="c:\program files\DISC\DISCover.exe" [2006-03-16 1077248]
"cctray"="c:\program files\CA\CA Internet Security Suite\cctray\cctray.exe" [2009-05-21 181488]
"CAVRID"="c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2010-05-27 230736]
"capfupgrade"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe" [2008-09-09 259312]
"capfasem"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe" [2008-09-09 173296]
"cafw"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe" [2008-09-09 771312]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 77312]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-05-13 171448]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-10 53760]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-12-15 282624]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
2007-05-18 17:30 79368 ----a-w- c:\windows\system32\UmxWNP.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\CA Personal Firewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\DISC\\DISCover.exe"=
"c:\\Program Files\\DISC\\DiscStreamHub.exe"=
"c:\\Program Files\\DISC\\myFTP.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
R0 KmxStart;KmxStart;c:\windows\system32\drivers\KmxStart.sys [6/24/2008 7:08 PM 93712]
R1 KmxAgent;KmxAgent;c:\windows\system32\drivers\KmxAgent.sys [6/24/2008 7:08 PM 63504]
R1 KmxFile;KmxFile;c:\windows\system32\drivers\KmxFile.sys [6/24/2008 7:08 PM 45584]
R1 KmxFw;KmxFw;c:\windows\system32\drivers\KmxFw.sys [6/24/2008 7:08 PM 115216]
R2 KmxCF;KmxCF;c:\windows\system32\drivers\KmxCF.sys [6/24/2008 7:08 PM 134648]
R2 KmxSbx;KmxSbx;c:\windows\system32\drivers\KmxSbx.sys [6/24/2008 7:08 PM 66576]
R2 UmxAgent;HIPS Event Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxAgent.exe [10/18/2007 11:24 AM 1010192]
R2 UmxCfg;HIPS Configuration Interpreter;c:\program files\CA\SharedComponents\HIPSEngine\UmxCfg.exe [10/18/2007 11:24 AM 801296]
R2 UmxPol;HIPS Policy Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxPol.exe [6/24/2008 7:10 PM 281104]
R3 KmxCfg;KmxCfg;c:\windows\system32\drivers\KmxCfg.sys [6/24/2008 7:08 PM 88816]
S2 gupdate1c9b1802c61e274;Google Update Service (gupdate1c9b1802c61e274);c:\program files\Google\Update\GoogleUpdate.exe [3/30/2009 5:40 PM 133104]
S3 PPCtlPriv;PPCtlPriv;c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe [2/19/2008 8:01 PM 185680]
.
Contents of the 'Scheduled Tasks' folder
2010-06-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2010-06-08 c:\windows\Tasks\CAAntiSpywareScan_Daily as HP_Administrator at 3 00 AM.job
- c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\caantispyware.exe [2008-02-20 12:40]
2010-06-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-30 21:40]
2010-06-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-30 21:40]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://google.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=63&bd=PAVILION&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=63&bd=PAVILION&pf=desktop
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride = <local>
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
LSP: c:\windows\system32\VetRedir.dll
Trusted Zone: trymedia.com
DPF: {8C2D1BF0-5364-403C-9968-E6E348C6B4FB} - hxxp://www.iradiopop.com/IRD/pages/VBIRDPlayer.CAB
FF - ProfilePath - c:\documents and settings\HP_Administrator.YOUR-4DACD0EA75\Application Data\Mozilla\Firefox\Profiles\zrfms3bv.default\
FF - prefs.js: browser.startup.homepage - hxxp://google.com/
FF - plugin: c:\documents and settings\HP_Administrator.YOUR-4DACD0EA75\Application Data\VideoEgg\Loader\4665\npvideoegg-loader.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJPI150_05.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPOJI610.dll
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-PCDrProfiler - (no file)
AddRemove-Jenkat Games Arcade - c:\documents and settings\HP_Administrator.YOUR-4DACD0EA75\Application Data\Jenkat\Jenkat Games Arcade\uninst.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-08 12:12
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(752)
c:\windows\system32\UmxWnp.Dll
c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll
.
Completion time: 2010-06-08 12:14:23
ComboFix-quarantined-files.txt 2010-06-08 16:14
Pre-Run: 167,650,426,880 bytes free
Post-Run: 170,180,415,488 bytes free
- - End Of File - - 1A6D8377FEC7E7CB5DB1099C209EFEEB
Thanks much,
-Doug