Kevin, thank you so much for your time! Here is my combofix log:
ComboFix 11-05-22.02 - johnheiderscheit 05/23/2011 13:47:05.1.1 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.1.1033.18.1915.1233 [GMT -5:00]
Running from: c:\users\johnheiderscheit\Desktop\gotcha.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\johnheiderscheit\g2mdlhlpx.exe
.
Infected copy of c:\windows\system32\drivers\volsnap.sys was found and disinfected
Restored copy from - Kitty had a snack
.
((((((((((((((((((((((((( Files Created from 2011-04-23 to 2011-05-23 )))))))))))))))))))))))))))))))
.
.
2011-05-23 19:07 . 2011-05-23 19:08 -------- d-----w- c:\users\johnheiderscheit\AppData\Local\temp
2011-05-23 19:07 . 2011-05-23 19:07 -------- d-----w- c:\users\Guest\AppData\Local\temp
2011-05-23 19:07 . 2011-05-23 19:07 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-05-23 13:40 . 2011-05-23 13:40 -------- d-----w- c:\users\johnheiderscheit\AppData\Local\Mozilla
2011-05-23 01:59 . 2011-05-23 01:59 -------- d-----w- c:\users\johnheiderscheit\AppData\Local\Adobe
2011-05-23 00:16 . 2010-12-20 23:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-22 20:15 . 2010-11-30 16:43 439632 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{0CC0125C-7533-4F1D-B6F9-84BBAF5241B4}\gapaengine.dll
2011-05-22 20:14 . 2011-05-18 17:37 6962000 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8C801A44-6730-43FC-A568-2A870D5D4508}\mpengine.dll
2011-05-22 19:32 . 2011-05-22 19:32 -------- d-----w- c:\program files\Microsoft Security Client
2011-05-22 19:31 . 2010-04-05 20:00 221568 ----a-w- c:\windows\system32\drivers\netio.sys
2011-05-22 18:54 . 2011-05-22 19:20 -------- d-----w- c:\users\johnheiderscheit\AppData\Roaming\Sammsoft
2011-05-22 16:47 . 2011-05-09 20:46 6962000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{60114CE3-0F03-4905-90B5-76F6139AE7B3}\mpengine.dll
2011-05-21 20:14 . 2011-05-21 20:14 -------- d-----w- c:\program files\Kaspersky Lab
2011-05-21 20:14 . 2011-05-22 11:27 -------- d-----w- c:\programdata\Kaspersky Lab
2011-05-21 16:18 . 2011-05-21 16:18 -------- d-----w- C:\$AVG
2011-05-21 13:00 . 2011-05-21 13:00 -------- d--h--w- c:\programdata\Common Files
2011-05-21 12:56 . 2011-05-21 13:01 -------- d-----w- c:\programdata\AVG10
2011-05-21 12:55 . 2011-05-21 12:55 -------- d-----w- c:\program files\AVG
2011-05-21 12:18 . 2011-05-21 13:02 -------- d-----w- c:\programdata\MFAData
2011-05-21 03:35 . 2011-05-21 03:35 -------- d-----w- c:\program files\Sophos
2011-05-21 03:16 . 2011-05-21 03:16 -------- d-----w- c:\users\johnheiderscheit\AppData\Roaming\Malwarebytes
2011-05-21 03:16 . 2011-05-21 03:16 -------- d-----w- c:\programdata\Malwarebytes
2011-05-21 03:16 . 2011-05-23 00:16 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-05-20 22:12 . 2011-05-20 22:12 -------- d-----w- c:\program files\Trend Micro
2011-05-07 23:45 . 2011-05-22 16:28 -------- d-----w- C:\Jts
2011-05-04 13:21 . 2011-05-22 16:28 -------- d-----w- c:\program files\Common Files\Roxio Shared
2011-05-04 13:21 . 2011-05-22 16:28 -------- d-----w- c:\program files\Common Files\PX Storage Engine
2011-05-04 13:21 . 2011-05-22 16:28 -------- d-----w- c:\program files\Common Files\Napster Shared
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-10 17:03 . 2011-04-15 19:48 1162240 ----a-w- c:\windows\system32\mfc42u.dll
2011-03-10 17:03 . 2011-04-15 19:48 1136640 ----a-w- c:\windows\system32\mfc42.dll
2011-03-03 15:42 . 2011-04-15 19:48 739328 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-03 13:25 . 2011-04-15 19:48 2041856 ----a-w- c:\windows\system32\win32k.sys
2011-03-02 15:44 . 2011-04-15 19:48 86528 ----a-w- c:\windows\system32\dnsrslvr.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-06-25 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-06-25 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-06-25 145944]
"RtHDVCpl"="RtHDVCpl.exe" [2008-04-08 6037504]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-16 178712]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-07 1029416]
"NDSTray.exe"="NDSTray.exe" [BU]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2008-03-26 49152]
"Skytel"="Skytel.exe" [2007-11-21 1826816]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
"NapsterShell"="c:\program files\Napster\napster.exe" [2010-01-19 323280]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-3-25 214360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-11-10 18:49 932288 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NapsterShell]
2010-01-19 17:48 323280 ----a-w- c:\program files\Napster\napster.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
2010-07-19 17:50 2403568 ----a-w- c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 LicCtrlService;LicCtrl Service;c:\windows\runservice.exe [2009-09-08 2560]
R3 IO_Memory;IO_Memory;c:\windows\SYSTEM32\SYSPREP\Drivers\ioport.sys
R3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\Jumpstart\jswpsapi.exe [2008-04-16 954368]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-10-25 43392]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2010-10-25 54144]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2010-11-11 206360]
R3 SVRPEDRV;SVRPEDRV;c:\windows\System32\sysprep\PEDrv.sys [2008-01-18 9216]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S1 jswpslwf;JumpStart Wireless Filter Driver;c:\windows\system32\DRIVERS\jswpslwf.sys [2008-04-29 20384]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-05-10 67656]
S2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [2008-04-17 40960]
S2 TMachInfo;TMachInfo;c:\program files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2008-08-04 46392]
S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [2006-11-20 7168]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-05-23 c:\windows\Tasks\User_Feed_Synchronization-{B4571557-7DF1-4DE2-8574-D354132716C5}.job
- c:\windows\system32\msfeedssync.exe [2011-04-15 04:43]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://yahoo.com/
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSHB&bmod=TSHB
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
Trusted Zone: intuit.com\ttlc
Trusted Zone: loweslink.com\enroll
Trusted Zone: loweslink.com\secure
Trusted Zone: loweslink.com\secure2
Trusted Zone: loweslink.com\tplogin
Trusted Zone: turbotax.com
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKCU-Run-TOSCDSPD - TOSCDSPD.EXE
HKLM-Run-jswtrayutil - c:\program files\Jumpstart\jswtrayutil.exe
HKLM-Run-cfFncEnabler.exe - cfFncEnabler.exe
HKLM-Run-hpqSRMon - (no file)
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe
MSConfigStartUp-MSN Toolbar - c:\program files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-05-23 14:07
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
.
c:\users\JOHNHE~1\AppData\Local\Temp\~DF7E35.tmp 16384 bytes
c:\users\JOHNHE~1\AppData\Local\Temp\~DF7E3E.tmp 512 bytes
.
scan completed successfully
hidden files: 2
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1517136145-1328366619-2469452859-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:f7,71,1a,f6,20,73,ea,a5,37,c3,46,fc,85,ad,ce,15,24,ad,8d,15,a3,07,8b,
d5,39,d3,5f,cf,f4,0c,33,b6,6d,e7,4d,86,cd,1c,95,fd,7d,e0,99,64,31,20,14,45,\
"??"=hex:b2,f5,80,ec,4b,7b,dc,0a,6d,4b,4f,90,bd,8e,3f,45
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-05-23 14:11:47
ComboFix-quarantined-files.txt 2011-05-23 19:11
.
Pre-Run: 79,195,607,040 bytes free
Post-Run: 79,382,962,176 bytes free
.
- - End Of File - - 0D91C8FCE998EF4755162D58D7612F9B