By George, I think you've got it. It seems like everything is working again.
One more quick question; I have an annoying beep or ring on the computer. It seems to come at no particular time and for no particular reason. Any quick ideas?
The two logs you ask for are posted below.
Thanks for ALL of your help.
Gar (Dad)
@@@@@@@@@@@@@@@@@@@@@@@
C:\Documents and Settings\Dad\Desktop\Folders\New Folder (5)\oi_avg_avwt_stb_all_9_117.exe a variant of Win32/OpenInstall application cleaned by deleting - quarantined
C:\Documents and Settings\Dad\Desktop\Folders\New Folder (5)\oi_bitdefender_isecurity_tucows.exe a variant of Win32/OpenInstall application cleaned by deleting - quarantined
C:\Documents and Settings\Dad\Desktop\Folders\New Folder (5)\oi_Coranti2010_AntiVirusAntiSpyware_setup.exe a variant of Win32/OpenInstall application cleaned by deleting - quarantined
C:\Documents and Settings\Dad\Desktop\programs\photopospro_setup.exe Win32/Toolbar.Zugo application deleted - quarantined
C:\Documents and Settings\Dad\My Documents\PosPanoramaPro_SetUp.exe Win32/Toolbar.Zugo application deleted - quarantined
C:\Documents and Settings\Gar Feathers\My Documents\Uninstall\Uninstall.exe a variant of Win32/InstallCore.D application cleaned by deleting - quarantined
C:\System Volume Information\_restore{47D88953-2E7D-4913-AD5F-2ABD1A2236E2}\RP875\A0295233.exe Win32/Adware.WintionalityChecker.AD application cleaned by deleting - quarantined
C:\System Volume Information\_restore{47D88953-2E7D-4913-AD5F-2ABD1A2236E2}\RP876\A0297086.exe a variant of Win32/OpenInstall application cleaned by deleting - quarantined
C:\System Volume Information\_restore{47D88953-2E7D-4913-AD5F-2ABD1A2236E2}\RP876\A0297087.exe a variant of Win32/OpenInstall application cleaned by deleting - quarantined
C:\System Volume Information\_restore{47D88953-2E7D-4913-AD5F-2ABD1A2236E2}\RP876\A0297088.exe a variant of Win32/OpenInstall application cleaned by deleting - quarantined
C:\System Volume Information\_restore{47D88953-2E7D-4913-AD5F-2ABD1A2236E2}\RP876\A0297089.exe Win32/Toolbar.Zugo application deleted - quarantined
@@@@@@@@@@@@@@@@@@@
ComboFix 12-05-07.01 - Dad 05/07/2012 3:15.1.2 - x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2031.1545 [GMT -7:00]
Running from: c:\documents and settings\Dad\Desktop\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: PC Cleaner Pro *Disabled/Updated* {737A8864-C2D9-4337-B49A-B5E35815B9BB}
FW: McAfee Firewall *Enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\Dad\System
c:\documents and settings\Dad\System\win_qs8.jqx
c:\documents and settings\Dad\WINDOWS
c:\program files\Internet Explorer\SET620.tmp
c:\program files\Internet Explorer\SET621.tmp
C:\Windows Restore
c:\windows\system32\_000005_.tmp.dll
c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\_000007_.tmp.dll
c:\windows\system32\SET107.tmp
c:\windows\system32\SET39.tmp
c:\windows\system32\SET3A.tmp
c:\windows\system32\SET3B.tmp
c:\windows\system32\SET3F.tmp
c:\windows\system32\SET40.tmp
c:\windows\system32\SET41.tmp
c:\windows\system32\SET43.tmp
c:\windows\system32\SET45.tmp
c:\windows\system32\SET46.tmp
c:\windows\system32\SET47.tmp
c:\windows\system32\SET5BA.tmp
c:\windows\system32\SET615.tmp
c:\windows\system32\SET616.tmp
c:\windows\system32\SET617.tmp
c:\windows\system32\SET618.tmp
c:\windows\system32\SET619.tmp
c:\windows\system32\SET61A.tmp
c:\windows\system32\SET61B.tmp
c:\windows\system32\SET61D.tmp
c:\windows\system32\SET61E.tmp
c:\windows\system32\SET61F.tmp
c:\windows\system32\SET79C.tmp
c:\windows\system32\syoepk_lib0.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_MYWEBSEARCHSERVICE
.
.
((((((((((((((((((((((((( Files Created from 2012-04-07 to 2012-05-07 )))))))))))))))))))))))))))))))
.
.
2012-05-05 18:43 . 2003-09-03 16:55 53352 ----a-w- c:\windows\system32\jpicpl32.cpl
2012-05-04 06:32 . 2012-05-04 06:32 -------- d-----w- c:\documents and settings\Dad\Local Settings\Application Data\visi_coupon
2012-05-02 20:37 . 2012-05-02 21:14 -------- d-----w- c:\documents and settings\Dad 2
2012-05-02 17:51 . 2012-05-02 17:52 -------- d-----w- c:\documents and settings\Administrator
2012-05-02 08:43 . 2012-05-02 08:43 -------- d-----w- c:\program files\Common Files\PC Tools
2012-05-02 08:43 . 2012-05-02 08:43 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2012-05-02 08:43 . 2012-05-02 08:43 -------- d-----w- c:\documents and settings\Dad\Application Data\searchcom_001
2012-05-02 08:43 . 2012-05-02 08:43 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2012-05-02 08:42 . 2012-05-02 08:43 -------- d-----w- c:\windows\4E0C6314A8B84026AC15084E8B63AFB5.TMP
2012-05-02 08:42 . 2012-05-02 08:43 -------- d-----w- c:\program files\Enigma Software Group
2012-05-02 08:42 . 2012-05-02 08:42 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2012-05-02 08:42 . 2012-05-02 08:42 -------- d-----w- c:\program files\Common Files\xing shared
2012-05-02 08:42 . 2012-05-02 08:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2012-05-02 08:42 . 2012-05-02 08:42 -------- d-----w- c:\documents and settings\Dad\Local Settings\Application Data\Apple
2012-05-02 08:42 . 2012-05-02 08:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
2012-05-02 06:57 . 2012-02-24 17:36 185560 ----a-w- c:\windows\system32\drivers\PCTSD.sys
2012-05-02 06:56 . 2012-05-02 08:39 -------- d-----w- c:\program files\PC Tools
2012-05-01 16:59 . 2012-05-02 08:39 -------- d-----w- c:\documents and settings\Dad\Application Data\searchcom_003
2012-05-01 16:59 . 2012-05-02 08:39 -------- d-----w- c:\program files\searchcom_003
2012-05-01 16:59 . 2012-05-01 16:59 -------- d-----w- c:\documents and settings\Dad\Local Settings\Application Data\searchcom_003
2012-05-01 16:39 . 2012-05-02 08:43 -------- d-----w- c:\documents and settings\Dad\Application Data\searchcom_004
2012-04-29 08:09 . 2012-05-02 07:52 -------- d-----w- C:\sh4ldr
2012-04-29 07:11 . 2012-05-05 06:47 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-04-29 07:11 . 2012-05-05 06:47 419488 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-04-29 06:07 . 2012-05-02 08:42 -------- d-----w- c:\program files\SMPlayer
2012-04-29 04:57 . 2012-04-29 04:57 -------- d-----w- c:\documents and settings\Dad\Application Data\Apple Computer
2012-04-29 04:48 . 2012-04-29 04:49 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin7.dll
2012-04-29 04:48 . 2012-04-29 04:49 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin6.dll
2012-04-29 04:48 . 2012-04-29 04:49 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin5.dll
2012-04-29 04:48 . 2012-04-29 04:49 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin4.dll
2012-04-29 04:48 . 2012-04-29 04:49 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin3.dll
2012-04-29 04:48 . 2012-04-29 04:49 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin2.dll
2012-04-29 04:48 . 2012-04-29 04:49 159744 ----a-w- c:\program files\Internet Explorer\PLUGINS\npqtplugin.dll
2012-04-29 04:47 . 2012-05-02 08:41 -------- d-----w- c:\program files\QuickTime
2012-04-29 04:47 . 2012-04-29 04:47 -------- d-----w- c:\program files\Common Files\Apple
2012-04-29 04:46 . 2012-05-02 08:41 -------- d-----w- c:\program files\Apple Software Update
2012-04-29 04:46 . 2012-04-29 04:46 -------- d-----w- c:\documents and settings\Dad\Local Settings\Application Data\Apple Computer
2012-04-29 04:28 . 2012-05-02 08:41 -------- d-----w- c:\documents and settings\Dad\.smplayer
2012-04-29 03:39 . 2012-05-02 08:42 -------- d-----w- c:\program files\Real
2012-04-12 09:58 . 2012-02-29 14:10 148480 -c----w- c:\windows\system32\dllcache\imagehlp.dll
2012-04-11 09:11 . 2008-03-02 06:41 196608 ----a-w- c:\windows\system32\EasySoap.dll
2012-04-11 09:11 . 2008-03-02 06:40 147456 ----a-w- c:\windows\system32\libexpat.dll
2012-04-11 09:11 . 2008-03-02 06:40 73728 ----a-w- c:\windows\system32\zlib1.dll
2012-04-11 09:11 . 2012-04-11 09:11 -------- d-----w- c:\program files\Etresoft Decoder 4.0
2012-04-11 08:55 . 2012-04-11 08:55 -------- d-----w- c:\documents and settings\Dad\Application Data\DriverCure
2012-04-11 08:55 . 2012-04-11 08:55 -------- d-----w- c:\documents and settings\Dad\Application Data\SpeedyPC Software
2012-04-11 08:55 . 2012-05-02 08:42 -------- d-----w- c:\documents and settings\All Users\Application Data\SpeedyPC Software
2012-04-09 07:17 . 2012-04-09 07:17 -------- d-----w- c:\documents and settings\Dad\Application Data\FrmMain
2012-04-09 07:15 . 2012-04-09 07:15 -------- d-----w- c:\documents and settings\Dad\Application Data\EmailNotifier
2012-04-09 07:15 . 2012-04-09 07:15 -------- d-----w- c:\documents and settings\Dad\Application Data\searchcom_002
2012-04-09 07:14 . 2002-08-01 02:55 96 ------w- c:\windows\WSYS049.SYS
2012-04-09 07:13 . 2012-04-09 07:14 -------- d-----w- c:\documents and settings\All Users\Application Data\EmailNotifier
2012-04-09 07:13 . 2012-04-09 07:38 -------- d-----w- c:\documents and settings\Dad\Application Data\Photopos
2012-04-09 07:13 . 2012-04-09 07:14 119777 ----a-w- c:\windows\Pos Panorama Pro Uninstaller.exe
2012-04-09 07:13 . 2012-04-09 07:13 -------- d-----w- c:\program files\Pos Panorama Pro
2012-04-09 07:06 . 2012-05-02 07:50 -------- d-----w- c:\documents and settings\All Users\Application Data\blekko toolbars
2012-04-09 07:06 . 2012-04-09 07:06 -------- d-----w- c:\documents and settings\Dad\Local Settings\Application Data\searchcom_004
2012-04-09 03:41 . 2012-04-09 07:03 -------- d-----w- c:\documents and settings\Dad\Application Data\photopostb
2012-04-09 03:41 . 2012-04-09 03:41 204005 ----a-w- c:\windows\Photo Pos Pro Uninstaller.exe
2012-04-09 03:40 . 2012-04-09 03:40 -------- d-----w- c:\program files\Common Files\Thraex Software
2012-04-09 03:40 . 2012-04-09 03:41 -------- d-----w- c:\program files\Photo Pos Pro
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-29 05:55 . 2012-02-14 00:00 4107024 ----a-w- c:\windows\uninst.exe
2012-03-29 21:51 . 2012-03-29 21:51 12952 ----a-w- c:\windows\system32\drivers\PSVolAcc.sys
2012-03-29 21:51 . 2012-03-29 21:51 16024 ----a-w- c:\windows\system32\drivers\pssnap.sys
2012-03-29 21:51 . 2012-03-29 21:51 47256 ----a-w- c:\windows\system32\drivers\psmounter.sys
2012-03-21 03:44 . 2010-03-26 05:30 171064 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2012-03-01 11:01 . 2003-03-31 12:00 916992 ----a-w- c:\windows\system32\wininet.dll
2012-03-01 11:01 . 2003-03-31 12:00 43520 ------w- c:\windows\system32\licmgr10.dll
2012-03-01 11:01 . 2003-03-31 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2012-02-29 14:10 . 2003-03-31 12:00 177664 ----a-w- c:\windows\system32\wintrust.dll
2012-02-29 14:10 . 2003-03-31 12:00 148480 ----a-w- c:\windows\system32\imagehlp.dll
2012-02-29 12:17 . 2009-08-09 00:07 385024 ------w- c:\windows\system32\html.iec
2012-02-23 21:25 . 2012-02-13 11:31 21336 ----a-w- c:\windows\system32\RegistryDefragBootTime.exe
2012-02-19 01:38 . 2010-05-15 00:22 472808 ----a-w- c:\windows\system32\deployJava1.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EPSON Stylus CX3800 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE" [2005-02-08 98304]
"cdloader"="c:\documents and settings\Dad\Application Data\mjusbsp\cdloader2.exe" [2011-08-23 50592]
"LogitechSoftwareUpdate"="c:\program files\LOGITECH\VIDEO\ManifestEngine.exe" [2005-06-08 196608]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-04-05 94208]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-04-05 77824]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"EPSON Stylus CX3800 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIACA.EXE" [2005-02-08 98304]
"YMailAdvisor"="c:\program files\Yahoo!\Common\YMailAdvisor.exe" [2009-05-08 174424]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]
"WFXSwtch"="c:\progra~1\WinFax\WFXSWTCH.exe" [2001-09-11 27648]
"WinFaxAppPortStarter"="wfxsnt40.exe" [2001-09-11 45568]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2011-10-24 421888]
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2012-04-29 296056]
"TraySantaCruz"="c:\windows\system32\tbctray.exe" [2002-05-18 290816]
.
c:\documents and settings\Dad\Start Menu\Programs\Startup\
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-5-20 1195008]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegedit"= 0 (0x0)
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{A213B520-C6C2-11d0-AF9D-008029E1027E}"= "c:\program files\WinFax\WfxSeh32.Dll" [1998-07-27 38400]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 19:28 72208 ----a-w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /r \??\H:\0autocheck autochk *
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
2005-06-08 22:24 458752 ----a-w- c:\program files\Logitech\Video\ISStart.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
2005-06-08 22:14 217088 ----a-w- c:\program files\Logitech\Video\LogiTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
2005-07-20 00:32 221184 ----a-w- c:\windows\system32\LVCOMSX.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
2003-09-03 17:27 53248 ----a-w- c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
2003-09-03 17:27 114688 ----a-w- c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2005-04-05 21:23 114688 ----a-w- c:\windows\system32\igfxpers.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PRONoMgr.exe]
2003-03-11 23:24 86016 ----a-w- c:\program files\Intel\NCS\PROSet\PRONoMgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Documents and Settings\\Gar Feathers\\Application Data\\mjusbsp\\magicJack.exe"=
"c:\\Documents and Settings\\Dad\\Application Data\\mjusbsp\\magicJack.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
R0 pssnap;Paramount Software Snapshot Filter;c:\windows\system32\drivers\pssnap.sys [3/29/2012 2:51 PM 16024]
R2 RealNetworks Downloader Resolver Service;RealNetworks Downloader Resolver Service;c:\program files\RealNetworks\RealDownloader\rndlresolversvc.exe [2/9/2012 1:15 PM 31408]
R2 ReflectService.exe;Macrium Reflect Image Mounting Service;c:\program files\Macrium\Reflect\ReflectService.exe [3/29/2012 2:51 PM 224920]
R3 tbcspud;Santa Cruz Driver;c:\windows\system32\drivers\tbcspud.sys [8/14/2009 10:31 PM 148096]
R3 tbcwdm;Santa Cruz WDM Driver;c:\windows\system32\drivers\tbcwdm.sys [8/14/2009 10:31 PM 545984]
S1 MpKsl12a46058;MpKsl12a46058;
S1 MpKsl12ec0305;MpKsl12ec0305;
S1 MpKsl2128245f;MpKsl2128245f;
S1 MpKsl9dc93b03;MpKsl9dc93b03;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{64D0E9DF-C8E3-44DF-9CAA-6286B0E221F8}\MpKsl9dc93b03.sys --> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{64D0E9DF-C8E3-44DF-9CAA-6286B0E221F8}\MpKsl9dc93b03.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [4/28/2012 8:26 PM 136176]
S2 mrtRate;mrtRate;
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [4/29/2012 12:11 AM 257696]
S3 ampa;ampa;c:\windows\system32\ampa.sys [4/3/2012 4:02 PM 10936]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2/17/2012 7:27 PM 13192]
S3 esgiguard;esgiguard;
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2/17/2012 7:27 PM 8456]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [4/28/2012 8:26 PM 136176]
S3 JoinMEPlayUI Assistant Service;JoinMEPlayUI Assistant Service;c:\program files\JoinME Drivers\JoinMEPlayAssistantServices.exe [2/15/2012 6:28 PM 242176]
S3 massfilter_hs;ZTE HandSet Mass Storage Filter Driver;c:\windows\system32\drivers\massfilter_hs.sys [2/15/2012 6:28 PM 9728]
S3 vtdg46xx;vtdg46xx;c:\progra~1\TURTLE~1\SANTAC~1\CONTRO~1\vtdg46xx.sys [8/14/2009 10:31 PM 19232]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [3/31/2003 5:00 AM 14336]
S3 zgwhsdiag;ZTE WCDMA Handset Diagnostic Port;c:\windows\system32\drivers\zgwhsdiag.sys [2/15/2012 6:28 PM 106752]
S3 zgwhsmdm;ZTE WCDMA Handset USB Modem;c:\windows\system32\drivers\zgwhsmdm.sys [2/15/2012 6:28 PM 106752]
S3 zgwhsnmea;WCDMA Handset NMEA Port;c:\windows\system32\drivers\zgwhsnmea.sys [2/15/2012 6:28 PM 106752]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 11:32 128512 ----a-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
.
2012-05-07 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-29 06:47]
.
2012-04-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-02 00:57]
.
2012-05-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-04-29 03:26]
.
2012-05-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-04-29 03:26]
.
2012-05-07 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1659004503-2025429265-839522115-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-03-30 22:39]
.
2012-05-06 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1659004503-2025429265-839522115-1005.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2012-03-30 22:39]
.
2012-05-07 c:\windows\Tasks\SDMsgUpdate (TE).job
- d:\progra~1\SMARTD~1\Messages\SDNotify.exe [2012-03-28 18:22]
.
.
------- Supplementary Scan -------
.
uStart Page =
https://search.blekko.com/ws/?source=12fe24cf&toolbarid=searchcom_004&u=20120501C3284D25809A6C56D014DF6D&tbp=homepageIE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
Trusted Zone: magicjack.com\my
Trusted Zone: talk4free.com\reg
TCP: DhcpNameServer = 192.168.0.1 192.168.0.1
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - (no file)
BHO-{25f91356-743d-4a72-85bf-c49033ffa72b} - (no file)
BHO-{7DE40473-AE15-3E0A-8D57-BC7CECC9F62A} - (no file)
BHO-{95525BD9-6136-4A26-8263-9CEE295D442D} - (no file)
BHO-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\Ask.com\GenericAskToolbar.dll
Toolbar-Locked - (no file)
Toolbar-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\Ask.com\GenericAskToolbar.dll
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - c:\program files\Ask.com\GenericAskToolbar.dll
WebBrowser-{95080B13-AA71-4EE8-B951-7E98221E1ED5} - (no file)
ShellIconOverlayIdentifiers-{2012DE06-50C0-48BD-ACDE-88F95D4CAD1F} - (no file)
ShellIconOverlayIdentifiers-{C72C6188-BEF2-46E5-A89A-52F0ED75219E} - (no file)
ShellIconOverlayIdentifiers-{C92F6BC2-AF61-4C0E-80E0-939B8282DDB7} - (no file)
ShellIconOverlayIdentifiers-{CB1EFEF8-D5E0-49D1-B768-41B48B1D7803} - (no file)
MSConfigStartUp-ApnUpdater - c:\program files\ask.com\updater\updater.exe
AddRemove-WorksDatabaseConverter - c:\windows\system32\javaws.exe
AddRemove-{79A765E1-C399-405B-85AF-466F52E918B0} - c:\program files\Ask.com\Updater\Updater.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2012-05-07 03:25
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Microsoft\Environment*]
"v5Licence0"="15-TWRD-Z28G-QKT4-8MEB-8RMK-5X2VQZ5"
"Activated"="Y"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(800)
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll
.
- - - - - - - > 'explorer.exe'(1860)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\crypserv.exe
c:\windows\system32\wfxsnt40.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
.
**************************************************************************
.
Completion time: 2012-05-07 03:28:50 - machine was rebooted
ComboFix-quarantined-files.txt 2012-05-07 10:28
.
Pre-Run: 36,671,201,280 bytes free
Post-Run: 34,880,622,592 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
[spybotsd]
timeout.old=30
.
- - End Of File - - 310D0A2557FAC1BD3F8C6D605CD3712A