Here are the two new logs you asked for, as far as the Norton my girlfriend said she thought she uninstalled it whenever her free trial period was over so she does not use that program anymore. Thank you very much for you time and help. I will try to reply as soon as possible today but I will be at work later so my replies this evening may be non existent until tonight.
ComboFix 10-02-09.03 - Brittany R Belcher 02/10/2010 9:16.2.2 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.1.1033.18.1917.1323 [GMT -6:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Brittany R Belcher\Desktop\CFScript.txt
SP: AVG Anti-Spyware *disabled* (Outdated) {48F2E28D-ED66-4646-9C11-B3055B0AF604}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
file zipped: c:\users\Brittany R Belcher\AppData\Roaming\schtml\dbsinit.exe
file zipped: c:\users\Brittany R Belcher\AppData\Roaming\skynet.dat
file zipped: c:\users\Brittany R Belcher\AppData\Roaming\wp3.dat
file zipped: c:\users\Brittany R Belcher\AppData\Roaming\wp4.dat
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programdata\kemowisu
c:\programdata\kemowisu\kemowisu.dll
c:\users\Brittany R Belcher\AppData\Roaming\schtml
c:\users\Brittany R Belcher\AppData\Roaming\schtml\dbsinit.exe
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\i1.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\i2.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\i3.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\j1.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\j2.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\j3.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\jj1.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\jj2.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\jj3.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\l1.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\l2.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\l3.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\pix.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\t1.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\t2.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\Thumbs.db
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\up1.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\up2.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\w1.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\w11.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\w2.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\w3.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\w3.jpg
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\word.doc
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\wt1.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\wt2.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\images\wt3.gif
c:\users\Brittany R Belcher\AppData\Roaming\schtml\wispex.html
c:\users\Brittany R Belcher\AppData\Roaming\skynet.dat
c:\users\Brittany R Belcher\AppData\Roaming\wp3.dat
c:\users\Brittany R Belcher\AppData\Roaming\wp4.dat
c:\users\Brittany R Belcher\AppData\Roaming\Your PC Protector
.
((((((((((((((((((((((((( Files Created from 2010-01-10 to 2010-02-10 )))))))))))))))))))))))))))))))
.
2010-02-10 15:23 . 2010-02-10 15:23 ——– d—–w- c:\users\Public\AppData\Local\temp
2010-02-10 15:23 . 2010-02-10 15:23 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-02-10 14:59 . 2010-02-10 14:59 ——– d—–w- C:\32788R22FWJFW
2010-02-10 04:41 . 2010-02-10 15:24 ——– d—–w- c:\users\Brittany R Belcher\AppData\Local\temp
2010-02-10 04:05 . 2010-02-10 04:05 ——– d—–w- C:\_OTL
2010-02-09 21:40 . 2010-02-09 21:41 ——– d—–w- c:\program files\ERUNT
2010-02-08 13:31 . 2010-02-08 13:31 ——– d—–w- c:\users\Brittany R Belcher\AppData\Roaming\Malwarebytes
2010-02-08 13:31 . 2010-01-07 22:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-08 13:31 . 2010-02-08 13:31 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-02-08 13:31 . 2010-02-08 13:31 ——– d—–w- c:\programdata\Malwarebytes
2010-02-08 13:31 . 2010-01-07 22:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-13 01:45 . 2009-10-19 14:27 156672 —-a-w- c:\windows\system32\t2embed.dll
2010-01-13 01:45 . 2009-10-19 14:24 72704 —-a-w- c:\windows\system32\fontsub.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-10 09:20 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail
2010-02-10 09:03 . 2007-08-28 01:44 ——– d—–w- c:\programdata\Microsoft Help
2010-01-14 17:12 . 2009-10-03 00:12 181120 ——w- c:\windows\system32\MpSigStub.exe
2009-12-28 12:35 . 2010-02-09 21:22 11776 —-a-w- c:\windows\system32\tsbyuv.dll
2009-12-28 12:35 . 2010-02-09 21:22 1314816 —-a-w- c:\windows\system32\quartz.dll
2009-12-28 12:32 . 2010-02-09 21:22 22528 —-a-w- c:\windows\system32\msyuv.dll
2009-12-28 12:32 . 2010-02-09 21:22 31744 —-a-w- c:\windows\system32\msvidc32.dll
2009-12-28 12:32 . 2010-02-09 21:22 123904 —-a-w- c:\windows\system32\msvfw32.dll
2009-12-28 12:32 . 2010-02-09 21:22 13312 —-a-w- c:\windows\system32\msrle32.dll
2009-12-28 12:31 . 2010-02-09 21:22 82944 —-a-w- c:\windows\system32\mciavi32.dll
2009-12-28 12:31 . 2010-02-09 21:22 50176 —-a-w- c:\windows\system32\iyuv_32.dll
2009-12-28 12:28 . 2010-02-09 21:22 91136 —-a-w- c:\windows\system32\avifil32.dll
2009-12-28 12:28 . 2010-02-09 21:22 65024 —-a-w- c:\windows\system32\avicap32.dll
2009-12-18 13:05 . 2010-01-22 01:59 833024 —-a-w- c:\windows\system32\wininet.dll
2009-12-18 13:01 . 2010-01-22 01:59 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-12-18 10:14 . 2010-01-22 01:59 26624 —-a-w- c:\windows\system32\ieUnatt.exe
2009-12-11 12:07 . 2010-02-09 21:22 301568 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-11 12:07 . 2010-02-09 21:22 98304 —-a-w- c:\windows\system32\drivers\srvnet.sys
2009-12-08 20:52 . 2010-02-09 21:22 897624 —-a-w- c:\windows\system32\drivers\tcpip.sys
2009-12-08 20:52 . 2010-02-09 21:22 3597912 —-a-w- c:\windows\system32\ntkrnlpa.exe
2009-12-08 20:52 . 2010-02-09 21:22 3546200 —-a-w- c:\windows\system32\ntoskrnl.exe
2009-12-04 16:12 . 2010-02-09 21:22 212992 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2009-12-04 16:12 . 2010-02-09 21:22 105472 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2007-08-10 19:06 . 2007-08-10 19:02 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WindowsWelcomeCenter"="oobefldr.dll" [2008-01-19 2153472]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-04-28 857648]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-21 1548288]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-04-16 184320]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-11 49152]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-11-29 583048]
"SigmatelSysTrayApp"="sttray.exe" [2007-03-06 303104]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-12-16 2043160]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-01-07 1394000]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-8-10 50688]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]
QuickSet.lnk - c:\windows\Installer\{7F0C4457-8E64-491B-8D7B-991504365D1E}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe [2007-8-10 45056]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [8/23/2009 2:04 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\System32\drivers\avgtdix.sys [8/23/2009 2:04 PM 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [8/23/2009 2:04 PM 297752]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [9/10/2008 9:52 PM 24652]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
.
——- Supplementary Scan ——-
.
IE: &AIM Toolbar Search - c:\programdata\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-02-10 09:24
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aac\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aif\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aifc\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aiff\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flac\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4a\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.midi\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogg\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcm\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pls\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.snd\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.spx\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="YMP.Media"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-02-10 09:26:52
ComboFix-quarantined-files.txt 2010-02-10 15:26
ComboFix2.txt 2010-02-10 04:41
Pre-Run: 95,428,894,720 bytes free
Post-Run: 95,398,387,712 bytes free
- - End Of File - - 3493A713D9DC76E64BBE7F911C4406A1
Upload was successful
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2010/02/10 09:35
Program Version: Version 1.3.5.0
Windows Version: Windows Vista SP1
==================================================
Drivers
——————-
Name: catchme.sys
Image Path: C:\Users\BRITTA~1\AppData\Local\Temp\catchme.sys
Address: 0x997C0000 Size: 31744 File Visible: No Signed: -
Status: -
Name: dump_atapi.sys
Image Path: C:\Windows\System32\Drivers\dump_atapi.sys
Address: 0x8C379000 Size: 32768 File Visible: No Signed: -
Status: -
Name: dump_dumpata.sys
Image Path: C:\Windows\System32\Drivers\dump_dumpata.sys
Address: 0x8C36E000 Size: 45056 File Visible: No Signed: -
Status: -
Name: PROCEXP113.SYS
Image Path: C:\Windows\system32\Drivers\PROCEXP113.SYS
Address: 0x997C8000 Size: 7872 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\Windows\system32\drivers\rootrepeal.sys
Address: 0x997E2000 Size: 49152 File Visible: No Signed: -
Status: -
Processes
——————-
Path: System
PID: 4 Status: Locked to the Windows API!
Path: C:\Windows\System32\audiodg.exe
PID: 1224 Status: Locked to the Windows API!
==EOF==