I ran Combofix in safemode. I hope that's OK. I can only access the internet in safemode with networking. The other two scans were done in normal mode. Also, Combofix displayed this message: "Access denied. Administrator permissions are needed to use the selected options: Use an administrator command prompt to complete these tasks." I don't use Vista too often & forgot to run this as the administrator. It did run and create a log (see below). Let me know if I need to run it again.
ComboFix 10-12-23.02 - Ben 12/23/2010 18:51:36.1.2 - x86 NETWORK
Microsoftยฎ Windows Vistaโข Home Premium 6.0.6001.1.1252.1.1033.18.2941.2502 [GMT -6:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((( Files Created from 2010-11-24 to 2010-12-24 )))))))))))))))))))))))))))))))
.
2010-12-24 00:56 . 2010-12-24 00:56 โโโ dโโw- c:\users\Ben\AppData\Local\temp
2010-12-24 00:56 . 2010-12-24 00:56 โโโ dโโw- c:\users\Default\AppData\Local\temp
2010-12-23 20:43 . 2010-12-23 20:43 โโโ dโโw- c:\windows\Sun
2010-12-23 20:38 . 2010-12-23 20:38 472808 โ-a-w- c:\windows\system32\deployJava1.dll
2010-12-23 19:54 . 2010-12-23 19:54 388096 โ-a-r- c:\users\Ben\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-12-23 15:07 . 2010-12-21 00:09 38224 โ-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-23 15:07 . 2010-12-21 00:08 20952 โ-a-w- c:\windows\system32\drivers\mbam.sys
2010-12-23 13:55 . 2010-12-23 13:55 โโโ dโโw- C:\85fae879bc2c681552a9c8880211
2010-12-23 05:05 . 2010-12-23 05:31 โโโ dโโw- c:\programdata\Spybot - Search & Destroy
2010-12-23 04:18 . 2010-12-23 20:39 โโโ dโโw- C:\Program Files
2010-12-22 23:59 . 2010-12-22 23:59 โโโ dโโw- C:\found.000
2010-12-18 01:28 . 2010-11-16 18:01 6273872 โ-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{85C879DA-FFDC-4212-9118-B87D33B87937}\mpengine.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-19 16:41 . 2010-02-15 04:58 222080 โโw- c:\windows\system32\MpSigStub.exe
2010-09-26 00:20 . 2008-06-06 18:41 266455793 โ-a-w- c:\windows\DUMP4f47.tmp
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AROReminder"="c:\found.000\dir0001.chk\Advanced Registry Optimizer\ARO.exe" [2010-01-20 2137600]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-30 4911104]
"NDSTray.exe"="NDSTray.exe" [BU]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-21 963976]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]
c:\users\Ben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
FrostWire On Startup.lnk - c:\found.000\dir0001.chk\FrostWire\FrostWire.exe [2010-2-10 114688]
OpenOffice.org 3.0.lnk - c:\found.000\dir0001.chk\OpenOffice.org 3\program\quickstart.exe [2008-12-15 384000]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [x]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
R2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [x]
R3 IO_Memory;IO_Memory;c:\windows\SYSTEM32\SYSPREP\Drivers\ioport.sys [x]
R3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\Jumpstart\jswpsapi.exe [x]
R3 SVRPEDRV;SVRPEDRV;c:\windows\System32\sysprep\UP_date\PEDrv.sys [x]
S1 jswpslwf;JumpStart Wireless Filter Driver;c:\windows\system32\DRIVERS\jswpslwf.sys [2007-09-01 20352]
S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [2006-11-20 7168]
โ Other Services/Drivers In Memory โ
*NewlyCreated* - ECACHE
.
.
โโ- Supplementary Scan โโ-
.
uStart Page = hxxp://www.yahoo.com/?ilc=1
mStart Page = hxxp://www.att.net
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKCU-Run-TOSCDSPD - TOSCDSPD.EXE
HKCU-Run-DW6 - c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe
HKLM-Run-StartCCC - c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
HKLM-Run-TRCMan - c:\program files\TOSHIBA\TRCMan\TRCMan.exe
HKLM-Run-TPwrMain - %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
HKLM-Run-HSON - %ProgramFiles%\TOSHIBA\TBS\HSON.exe
HKLM-Run-SmoothView - %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
HKLM-Run-jswtrayutil - c:\program files\Jumpstart\jswtrayutil.exe
HKLM-Run-ITSecMng - %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe
HKLM-Run-SynTPEnh - c:\program files\Synaptics\SynTP\SynTPEnh.exe
HKLM-Run-PCMAgent - c:\program files\CyberLink\PowerCinema for TOSHIBA\PCMAgent.exe
HKLM-Run-CLMLServer - c:\program files\CyberLink\PowerCinema for TOSHIBA\Kernel\CLML\CLMLSvc.exe
HKLM-Run-00TCrdMain - c:\program files\TOSHIBA\FlashCards\TCrdMain.exe
HKLM-Run-QuickTime Task - c:\program files\QuickTime\QTTask.exe
HKLM-Run-iTunesHelper - c:\program files\iTunes\iTunesHelper.exe
HKLM-RunOnce- - (no file)
AddRemove-Adobe AIR - c:\program files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe
AddRemove-Advanced Registry Optimizer_is1 - c:\program files\Advanced Registry Optimizer\unins000.exe
AddRemove-ALUpdate_is1 - c:\program files\ESTsoft\ALUpdate\unins000.exe
AddRemove-AT&T Yahoo! Browser Configuration - c:\program files\SBC Yahoo!\Connection Manager\uninstATTConfig.exe
AddRemove-FrostWire - c:\program files\FrostWire\Uninstall.exe
AddRemove-Hardware Helper_is1 - c:\program files\Driver-Soft\HardwareHelper\unins000.exe
AddRemove-InstallShield_{03240EBA-04F2-4652-BC7F-B055902BDCD3} - c:\program files\InstallShield Installation Information\{03240EBA-04F2-4652-BC7F-B055902BDCD3}\setup.exe
AddRemove-InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761} - c:\program files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\setup.exe
AddRemove-InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF} - c:\program files\InstallShield Installation Information\{617C36FD-0CBE-4600-84B2-441CEB12FADF}\setup.exe
AddRemove-The Weather Channel Toolbar - c:\progra~1\THEWEA~2\UNWISE.EXE
AddRemove-{12B3A009-A080-4619-9A2A-C6DB151D8D67} - c:\program files\InstallShield Installation Information\{12B3A009-A080-4619-9A2A-C6DB151D8D67}\setup.exe
AddRemove-{37C866E4-AA67-4725-9E95-A39968DD7960} - c:\program files\InstallShield Installation Information\{37C866E4-AA67-4725-9E95-A39968DD7960}\setup.exe
AddRemove-{6C5F3BDC-0A1B-4436-A696-5939629D5C31} - c:\program files\InstallShield Installation Information\{6C5F3BDC-0A1B-4436-A696-5939629D5C31}\setup.exe
AddRemove-{8833FFB6-5B0C-4764-81AA-06DFEED9A476} - c:\program files\InstallShield Installation Information\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}\setup.exe
AddRemove-{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D} - c:\program files\InstallShield Installation Information\{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}\setup.exe
AddRemove-{A644254B-92F6-4970-8635-AB0775371E72} - c:\program files\InstallShield Installation Information\{A644254B-92F6-4970-8635-AB0775371E72}\setup.exe
AddRemove-{B0BCDCBD-863D-4CAB-BF68-8D1F6B1BDC13} - c:\program files\InstallShield Installation Information\{B0BCDCBD-863D-4CAB-BF68-8D1F6B1BDC13}\setup.exe
AddRemove-{FEB650EB-7639-444E-9FC2-C33EE6ED1A37} - c:\program files\InstallShield Installation Information\{FEB650EB-7639-444E-9FC2-C33EE6ED1A37}\setup.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-12-23 18:56
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes โฆ
scanning hidden autostart entries โฆ
scanning hidden files โฆ
scan completed successfully
hidden files: 0
**************************************************************************
.
โโโโโโโ LOCKED REGISTRY KEYS โโโโโโโ
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Completion time: 2010-12-23 18:58:52
ComboFix-quarantined-files.txt 2010-12-24 00:58
Pre-Run: 157,865,172,992 bytes free
Post-Run: 157,781,688,320 bytes free
- - End Of File - - 11599DCB098F8ABEEB8E83F894398702