NoodleTech-
I apologize for posting a separate issue with my machine with this thread. In thinking about it and the number of issues you are dealing with at any one time that more than likely adds to a degree of confusion for you. That issue is now being dealt with in another thread so I will make sure to keep these issues separate going forward. I have followed your instructions above and the ComboFix log is below.
I still have not had any luck in tracking down a CD for this machine so if you could think of a workaround in this area I would be most grateful.
Thanks again for your assistance and for the wonderful help offered on this GREAT forum!
ComboFix 11-01-08.05 - Jess 01/13/2011 20:13:21.3.2 - x86
Microsoftยฎ Windows Vistaโข Home Premium 6.0.6002.2.1252.1.1033.18.1013.365 [GMT -6:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Jess\Desktop\CFScript.txt
AV: BitDefender Antivirus *Disabled/Updated* {50909708-FF80-02AF-F814-B28405891E92}
FW: BitDefender Firewall *Enabled* {68AB162D-B5EF-03F7-D34B-1BB1FB5A59E9}
SP: BitDefender Antispyware *Disabled/Updated* {EBF176EC-D9BA-0D21-C2A4-89F67E0E542F}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\users\Jess\AppData\Roaming\kzcuhh
.
((((((((((((((((((((((((( Files Created from 2010-12-14 to 2011-01-14 )))))))))))))))))))))))))))))))
.
2011-01-14 02:31 . 2011-01-14 02:31 โโโ dโโw- c:\users\Jess\AppData\Local\temp
2011-01-14 02:31 . 2011-01-14 02:31 โโโ dโโw- c:\users\Guest\AppData\Local\temp
2011-01-14 02:31 . 2011-01-14 02:31 โโโ dโโw- c:\users\Default\AppData\Local\temp
2011-01-08 21:43 . 2010-12-21 00:09 38224 โ-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-08 21:43 . 2011-01-08 21:43 โโโ dโโw- c:\program files\Malwarebytes' Anti-Malware
2011-01-08 21:43 . 2010-12-21 00:08 20952 โ-a-w- c:\windows\system32\drivers\mbam.sys
2011-01-04 23:07 . 2011-01-04 23:07 โโโ dโโw- c:\users\Jess\AppData\Roaming\IObit
2011-01-04 23:07 . 2011-01-04 23:07 โโโ dโโw- c:\program files\IObit
2011-01-04 19:21 . 2011-01-04 19:21 โโโ dโโw- c:\programdata\bdch
2011-01-03 20:40 . 2011-01-03 20:40 โโโ dโโw- c:\users\Jess\AppData\Roaming\BitDefender
2011-01-03 20:39 . 2011-01-03 20:39 โโโ dโโw- c:\program files\BitDefender
2011-01-03 20:27 . 2011-01-03 20:27 โโโ dโโw- c:\users\Jess\AppData\Roaming\QuickScan
2011-01-03 20:26 . 2011-01-03 20:39 โโโ dโโw- c:\program files\Common Files\BitDefender
2011-01-03 20:25 . 2011-01-03 20:43 โโโ dโโw- c:\programdata\BitDefender
2011-01-03 20:24 . 2011-01-03 21:57 306104 โ-a-w- c:\windows\system32\drivers\trufos.sys
2011-01-03 20:24 . 2011-01-03 21:42 327368 โ-a-w- c:\windows\system32\drivers\bdfsfltr.sys
2011-01-01 13:42 . 2010-11-10 04:33 6273872 โ-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{14CC78D0-E001-4F03-B7CA-7115E7846B3E}\mpengine.dll
2010-12-25 18:36 . 2010-12-25 18:36 โโโ dโโw- c:\users\Jess\AppData\Roaming\Malwarebytes
2010-12-25 18:36 . 2010-12-25 18:36 โโโ dโโw- c:\programdata\Malwarebytes
2010-12-16 00:50 . 2010-11-03 10:51 2409784 โ-a-w- c:\program files\Windows Mail\OESpamFilter.dat
2010-12-16 00:49 . 2010-10-12 15:53 33280 โ-a-w- c:\program files\Windows Mail\wabfind.dll
2010-12-16 00:49 . 2010-10-12 13:41 66048 โ-a-w- c:\program files\Windows Mail\wabmig.exe
2010-12-16 00:49 . 2010-10-12 13:41 515584 โ-a-w- c:\program files\Windows Mail\wab.exe
2010-12-16 00:49 . 2010-10-18 13:37 81920 โ-a-w- c:\windows\system32\consent.exe
2010-12-16 00:48 . 2010-10-28 15:44 34304 โ-a-w- c:\windows\system32\atmlib.dll
2010-12-16 00:48 . 2010-10-28 13:27 292352 โ-a-w- c:\windows\system32\atmfd.dll
2010-12-16 00:48 . 2010-06-16 15:30 72704 โ-a-w- c:\windows\system32\fontsub.dll
2010-12-16 00:47 . 2010-10-28 13:20 2048 โ-a-w- c:\windows\system32\tzres.dll
2010-12-16 00:44 . 2010-11-04 18:56 345600 โ-a-w- c:\windows\system32\wmicmiplugin.dll
2010-12-16 00:44 . 2010-11-04 18:55 352768 โ-a-w- c:\windows\system32\taskschd.dll
2010-12-16 00:44 . 2010-11-04 18:55 601600 โ-a-w- c:\windows\system32\schedsvc.dll
2010-12-16 00:44 . 2010-11-04 16:34 171520 โ-a-w- c:\windows\system32\taskeng.exe
2010-12-16 00:44 . 2010-11-04 18:55 270336 โ-a-w- c:\windows\system32\taskcomp.dll
2010-12-16 00:25 . 2010-10-18 13:31 2038272 โ-a-w- c:\windows\system32\win32k.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-03 21:37 . 2010-06-18 22:11 72784 โ-a-w- c:\windows\system32\drivers\bdfndisf6.sys
2010-10-19 16:41 . 2009-11-14 11:59 222080 โโw- c:\windows\system32\MpSigStub.exe
2010-03-30 00:40 . 2010-03-30 00:40 100256 โ-a-w- c:\program files\Common Files\LinkInstaller.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LXBUCATS"="c:\windows\system32\spool\DRIVERS\W32X86\3\LXBUtime.dll" [2007-02-22 73728]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2011\ieshow.exe" [2011-01-03 71216]
"BDAgent"="c:\program files\BitDefender\BitDefender 2011\bdagent.exe" [2011-01-03 1418456]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^w98Eject.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\w98Eject.lnk
backup=c:\windows\pss\w98Eject.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^Jess^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\users\Jess\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
%ProgramFiles%\Windows Defender\MSASCui.exe -hide [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-01-12 03:16 39792 โ-a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2008-01-19 07:33 125952 โ-a-w- c:\windows\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
2009-12-11 19:37 30192 โ-a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2006-11-29 03:17 106496 โ-a-w- c:\windows\System32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HWSetup]
2006-11-01 15:06 413696 โ-a-w- c:\program files\Toshiba\Utilities\HWSetup.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2006-11-29 03:14 98304 โ-a-w- c:\windows\System32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KeNotify]
2006-11-07 00:14 34352 โ-a-w- c:\program files\Toshiba\Utilities\KeNotify.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LtMoh]
2005-12-16 09:41 188416 โ-a-w- c:\program files\ltmoh\ltmoh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LXBUCATS]
2007-02-22 11:12 73728 โ-a-w- c:\windows\System32\spool\drivers\w32x86\3\lxbutime.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2006-11-29 03:13 81920 โ-a-w- c:\windows\System32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-11 05:08 417792 โ-a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
2006-11-09 17:57 3784704 โ-a-w- c:\windows\RtHDVCpl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SVPWUTIL]
2006-01-18 23:06 421888 โ-a-w- c:\program files\Toshiba\Utilities\SVPWUTIL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2006-10-27 20:50 815104 โ-a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
R1 SASDIFSV;SASDIFSV;c:\users\Jess\AppData\Local\Temp\SAS_SelfExtract\SASDIFSV.SYS [x]
R1 SASKUTIL;SASKUTIL;c:\users\Jess\AppData\Local\Temp\SAS_SelfExtract\SASKUTIL.SYS [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2009-12-11 30192]
R3 PTDWBus;Curitel PC Card Composite Device driver (UDP);c:\windows\system32\DRIVERS\PTDWBus.sys [2007-04-06 27392]
R3 PTDWMdm;Curitel PC Card Drivers (UDP);c:\windows\system32\DRIVERS\PTDWMdm.sys [2007-04-06 41728]
R3 PTDWVsp;Curitel PC Card Diagnostic Serial Port (UDP);c:\windows\system32\DRIVERS\PTDWVsp.sys [2007-04-06 39808]
R3 PWCTLDRV;The NECHostController Filter Driver; [x]
R3 pwi_bus;Curitel PC Card Composite Device driver (WDM);c:\windows\system32\DRIVERS\pwi_bus.sys [x]
R3 pwi_mdfl;Curitel PC Card Filter;c:\windows\system32\DRIVERS\pwi_mdfl.sys [x]
R3 pwi_mdm;Curitel PC Card Drivers;c:\windows\system32\DRIVERS\pwi_mdm.sys [x]
R3 pwi_oflt;Curitel PC Card OHCI Filter;c:\windows\system32\DRIVERS\pwi_oflt.sys [x]
R3 pwi_serd;Curitel PC Card Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\pwi_serd.sys [x]
R3 SASENUM;SASENUM;c:\users\Jess\AppData\Local\Temp\SAS_SelfExtract\SASENUM.SYS [x]
R3 SMSIVZAM5;SMSIVZAM5 NDIS Protocol Driver;c:\progra~1\VERIZO~1\VZACCE~1\SMSIVZAM5.SYS [2009-05-25 32408]
R3 Update Server;BitDefender Update Server v2;c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe [2011-01-03 307544]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 avc3;avc3;c:\windows\system32\DRIVERS\avc3.sys [2010-06-28 633424]
R4 avckf;avckf;c:\windows\system32\DRIVERS\avckf.sys [2010-06-28 970320]
S1 Bdfndisf;BitDefender Firewall NDIS 6 Filter Driver;c:\program files\common files\bitdefender\bitdefender firewall\bdfndisf6.sys [2011-01-03 72784]
S2 Updatesrv;BitDefender Desktop Update Service;c:\program files\BitDefender\BitDefender 2011\updatesrv.exe [2011-01-03 43424]
S3 BDFM;BDFM;c:\windows\system32\DRIVERS\bdfm.sys [2010-05-13 152528]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
2011-01-14 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2006-09-27 22:39]
.
.
โโ- Supplementary Scan โโ-
.
uStart Page = hxxp://www.google.com/
mStart Page = about:blank
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: {47C00A50-53CB-4FA4-94AC-3A61BB20BCC2} = 69.78.96.14 66.174.92.14
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-01-13 20:31
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes โฆ
scanning hidden autostart entries โฆ
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXBUCATS = rundll32 c:\windows\system32\spool\DRIVERS\W32X86\3\LXBUtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files โฆ
scan completed successfully
hidden files: 0
**************************************************************************
.
โโโโโโโ LOCKED REGISTRY KEYS โโโโโโโ
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-01-13 20:38:28
ComboFix-quarantined-files.txt 2011-01-14 02:38
ComboFix2.txt 2011-01-10 22:09
Pre-Run: 65,749,237,760 bytes free
Post-Run: 65,719,988,224 bytes free
- - End Of File - - 4D1016E350617803A30E4CE8F30384D4