Hi Jeff,
Here are the other two logs your requested. Looking forward to your response. Thank you.
Jen
aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software
Run date: 2011-06-08 16:25:11
—————————–
16:25:11.500 OS Version: Windows 5.1.2600 Service Pack 3
16:25:11.500 Number of processors: 1 586 0x207
16:25:11.500 ComputerName: HOME-6OMCXJZ23I UserName: Owner
16:25:12.359 Initialize success
16:25:17.390 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdePort0
16:25:17.390 Disk 0 Vendor: WDC_WD400BB-75DEA0 05.03E05 Size: 38146MB BusType: 3
16:25:17.390 Device \Device\Ide\IdeDeviceP0T0L0-3 -> \??\IDE#DiskWDC_WD400BB-75DEA0______________________05.03E05#4457572d414d3144393739303633_034_0_0_0_0#{5
3f56307-b6bf-11d0-94f2-00a0c91efb8b} not found
16:25:17.390 Device \Driver\atapi -> DriverStartIo 8afe327f
16:25:19.406 Disk 0 MBR read successfully
16:25:19.406 Disk 0 MBR scan
16:25:19.406 Disk 0 TDL4@MBR code has been found
16:25:19.406 Disk 0 Windows XP default MBR code found via API
16:25:19.406 Disk 0 MBR hidden
16:25:19.406 Disk 0 MBR [TDL4] **ROOTKIT**
16:25:19.406 Disk 0 trace - called modules:
16:25:19.421 ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8afe3439]<<
16:25:19.421 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8b01aab8]
16:25:19.421 3 CLASSPNP.SYS[f7637fd7] -> nt!IofCallDriver -> [0x8af4d860]
16:25:19.421 \Driver\atapi[0x8b043bd8] -> IRP_MJ_CREATE -> 0x8afe3439
16:25:19.421 Scan finished successfully
16:25:42.078 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Owner\Desktop\MBR.dat"
16:25:42.078 The log file has been saved successfully to "C:\Documents and Settings\Owner\Desktop\aswMBR.txt"
aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software
Run date: 2011-06-10 16:54:34
—————————–
16:54:34.453 OS Version: Windows 5.1.2600 Service Pack 3
16:54:34.453 Number of processors: 1 586 0x207
16:54:34.453 ComputerName: HOME-6OMCXJZ23I UserName: Owner
16:54:35.062 Initialize success
16:55:04.156 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
16:55:04.156 Disk 0 Vendor: WDC_WD400BB-75DEA0 05.03E05 Size: 38146MB BusType: 3
16:55:06.171 Disk 0 MBR read successfully
16:55:06.171 Disk 0 MBR scan
16:55:06.171 Disk 0 Windows XP default MBR code
16:55:08.171 Disk 0 scanning sectors +78108030
16:55:08.187 Disk 0 scanning C:\WINDOWS\system32\drivers
16:55:27.359 Service scanning
16:55:28.718 Disk 0 trace - called modules:
16:55:28.718 ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS
16:55:28.718 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8afecab8]
16:55:28.718 3 CLASSPNP.SYS[f7637fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8aff9d98]
16:55:28.718 Scan finished successfully
16:55:55.750 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Owner\Desktop\MBR.dat"
16:55:55.750 The log file has been saved successfully to "C:\Documents and Settings\Owner\Desktop\aswMBR.txt"
ComboFix 11-06-09.04 - Owner 06/10/2011 16:07:20.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1504 [GMT -4:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
AV: AVG Anti-Virus Free *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Owner\Recent\Thumbs.db
c:\documents and settings\Owner\WINDOWS
c:\program files\Mozilla Firefox\plugins\NPMorpBr.dll
c:\program files\Search Toolbar
c:\program files\Search Toolbar\icon.ico
c:\program files\Search Toolbar\SearchToolbarUninstall.exe
c:\program files\Search Toolbar\SearchToolbarUpdater.exe
c:\program files\SelectRebates
c:\program files\SelectRebates\FFToolbar\chrome.manifest
c:\program files\SelectRebates\FFToolbar\chrome\sahtoolbar.jar
c:\program files\SelectRebates\FFToolbar\defaults\preferences\sahtoolbar.js
c:\program files\SelectRebates\FFToolbar\install.rdf
c:\program files\SelectRebates\SahImages\alert.png
c:\program files\SelectRebates\SahImages\check.png
c:\program files\SelectRebates\SahImages\close.png
c:\program files\SelectRebates\SelectAlerts.dat
c:\program files\SelectRebates\SelectRebates .exe
c:\program files\SelectRebates\SelectRebates.ini
c:\program files\SelectRebates\SelectRebatesA.dat
c:\program files\SelectRebates\SelectRebatesApi.exe
c:\program files\SelectRebates\SelectRebatesB.dat
c:\program files\SelectRebates\SelectRebatesBT.dat
c:\program files\SelectRebates\SelectRebatesDownload.exe
c:\program files\SelectRebates\SelectRebatesH.dat
c:\program files\SelectRebates\SelectRebatesUninstall.exe
c:\program files\SelectRebates\SRebates.dll
c:\program files\SelectRebates\SRFF3.dll
c:\program files\SelectRebates\Toolbar\AddtoList.bmp
c:\program files\SelectRebates\Toolbar\basis.xml
c:\program files\SelectRebates\Toolbar\Basis.xml.dym
c:\program files\SelectRebates\Toolbar\Blank.bmp
c:\program files\SelectRebates\Toolbar\CashBack.bmp
c:\program files\SelectRebates\Toolbar\Coupons.bmp
c:\program files\SelectRebates\Toolbar\GroceryCoupon.bmp
c:\program files\SelectRebates\Toolbar\i_magnifying.bmp
c:\program files\SelectRebates\Toolbar\icons.bmp
c:\program files\SelectRebates\Toolbar\logo.bmp
c:\program files\SelectRebates\Toolbar\logo_24.bmp
c:\program files\SelectRebates\Toolbar\logo_HotSpots.bmp
c:\program files\SelectRebates\Toolbar\ReviewSite.bmp
c:\program files\SelectRebates\Toolbar\RightControls.dym
c:\program files\SelectRebates\Toolbar\sahtb-alert.bmp
c:\program files\SelectRebates\Toolbar\sahtb-go.bmp
c:\program files\SelectRebates\Toolbar\sahtb-grocerycoupons.bmp
c:\program files\SelectRebates\Toolbar\sahtb-icons.bmp
c:\program files\SelectRebates\Toolbar\sahtb-restaurant.bmp
c:\program files\SelectRebates\Toolbar\sahtb-wishlist.bmp
c:\program files\SelectRebates\Toolbar\Scissors.bmp
C:\Thumbs.db
c:\windows\command
c:\windows\command\EXTRACT.PIF
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_RPCPATCH
——-\Legacy_RPCTFTPD
——-\Legacy_SVCPROC
.
.
((((((((((((((((((((((((( Files Created from 2011-05-10 to 2011-06-10 )))))))))))))))))))))))))))))))
.
.
2011-06-10 20:23 . 2011-06-10 20:23 ——– d—–w- c:\windows\LastGood
2011-06-09 20:15 . 2011-06-09 20:15 ——– d—–w- c:\program files\VirusTotalUploader2
2011-06-06 20:47 . 2011-06-06 20:47 388096 —-a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-05-24 10:53 . 2004-12-14 16:07 229376 —-a-r- c:\windows\system32\hpovst08.dll
2011-05-24 10:53 . 2004-12-14 16:07 581632 —-a-r- c:\windows\system32\hpotscl.dll
2011-05-22 19:58 . 2011-05-22 19:58 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\ESET
2011-05-22 18:30 . 2011-05-22 18:30 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\ESET
2011-05-22 18:23 . 2011-05-22 18:23 ——– d—–w- c:\program files\ESET
2011-05-22 18:23 . 2011-05-22 18:23 ——– d—–w- c:\documents and settings\All Users\Application Data\ESET
2011-05-22 18:10 . 2011-05-22 18:10 54016 —-a-w- c:\windows\system32\drivers\auqwgxcl.sys
2011-05-22 17:23 . 2011-05-22 18:03 ——– d—–w- c:\documents and settings\Administrator
2011-05-21 01:02 . 2011-05-21 01:03 ——– d—–w- c:\documents and settings\John\Local Settings\Application Data\AskToolbar
2011-05-18 18:26 . 2011-05-18 18:26 ——– d—–w- C:\found.000
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-11 19:26 . 2011-05-11 19:26 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
c:\program files\DropBox\DropBox\DropBox .exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9F9D-3BEFCFBE6E86}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2011-05-17 17:29 1490312 —-a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-05-17 1490312]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-05-17 1490312]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"Performance Center"="c:\program files\Ascentive\Performance Center\ApcMain.exe" [2009-01-23 3231744]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-27 4351216]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-08 68856]
"PlaxoUpdate"="c:\documents and settings\Owner\Local Settings\Application Data\Plaxo\3.26.0.13\PlaxoHelper_en.exe" [2011-04-29 834952]
"PlaxoSysTray"="c:\documents and settings\Owner\Local Settings\Application Data\Plaxo\3.26.0.13\PlaxoSysTray.exe" [2011-04-29 15752]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-09-13 49152]
"DropBoxUtility"="c:\program files\DropBox\DropBox\DropBox.exe" [N/A]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [N/A]
"TkBellExe"="c:\program files\real\realone player\update\realsched.exe" [N/A]
"ApnUpdater"="c:\program files\Ask.com\Updater\Updater.exe" [2011-05-17 395144]
"SelectRebates"="c:\program files\SelectRebates\SelectRebates.exe" [N/A]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-01-12 2219184]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-12-2 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-4 258048]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-4 53248]
Kodak EasyShare software.lnk - c:\program files\KODAK\Kodak EasyShare software\bin\EasyShare.exe [2004-8-11 757760]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PCANotify]
2002-02-15 14:51 24638 —-a-w- c:\windows\system32\PCANotify.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\srvF28]
@="service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Java\\jre1.6.0_05\\bin\\javaws.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [12/21/2010 3:04 PM 115008]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [12/21/2010 1:47 PM 94872]
R1 msikbd2k;Multimedia Keyboard Filter Driver;c:\windows\system32\drivers\Msikbd2k.sys [1/29/2005 2:34 PM 6656]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [1/12/2011 4:41 PM 810144]
R2 nhksrv;Netropa NHK Server;c:\program files\Netropa\Multimedia Keyboard\nhksrv.exe [1/29/2005 2:34 PM 28672]
S0 dsmghm;dsmghm;c:\windows\system32\drivers\xlmrbnhp.sys –> c:\windows\system32\drivers\xlmrbnhp.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [12/22/2009 10:03 PM 135664]
S2 srvF28;srvF28;c:\windows\system32\svchost.exe -k netsvcs [9/3/2002 1:05 PM 14336]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [12/22/2009 10:03 PM 135664]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - WUAUSERV
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
srvF28
.
Contents of the 'Scheduled Tasks' folder
.
2011-06-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 15:50]
.
2011-06-10 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2006-12-11 05:38]
.
2011-06-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-23 02:03]
.
2011-06-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-23 02:03]
.
2011-06-10 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-18.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 16:33]
.
2011-06-10 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1085031214-1343024091-839522115-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 16:33]
.
2011-06-10 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1085031214-1343024091-839522115-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 16:33]
.
2011-06-05 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-18.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 16:33]
.
2011-06-10 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1085031214-1343024091-839522115-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 16:33]
.
2011-06-09 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1085031214-1343024091-839522115-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 16:33]
.
2011-06-10 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2010-05-19 23:20]
.
2011-06-09 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2010-05-19 23:20]
.
2011-06-09 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2011-05-17 17:29]
.
2011-06-09 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2005-08-12 16:24]
.
2011-06-03 c:\windows\Tasks\WebReg officejet 6200 series.job
- c:\program files\HP\Digital Imaging\bin\hpqwrg.exe [2004-11-05 20:45]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.bing.com/?pc=Z006&form=ZGAPHP
uDefault_Search_URL = hxxp://search.msn.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Crawler Search
IE: RemindU - file://c:\program files\Upromise_RemindU\Sy1050\Tp1050\scri1050a.htm
TCP: DhcpNameServer = 192.168.1.1
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\6oljsjfq.Jen\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - www.yahoo.com
FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=PSI&o=15116&locale=en_US&apn_uid=71267C36-3737-4C69-9F5B-09CA2DA85FF0&apn_ptnrs=L6&apn_sauid=21534966-0C9D-40F4-B73A-00D0006E6084&apn_dtid=&q=
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
.
——- File Associations ——-
.
.txt=
.
- - - - ORPHANS REMOVED - - - -
.
Notify-avgrsstarter - avgrsstx.dll
AddRemove-Blue's 123 Time Activities - c:\hegames\Blues123\Uninst.isu
AddRemove-Little Bear Preschool Thinking Adventures - c:\program files\Creative Wonders\Little Bear Preschool Thinking Adventures\Uninst.isu
AddRemove-Minibug - c:\progra~1\AWS\WEATHE~1\Install\MiniBug.exe
AddRemove-Mr. Potato Head's Activity Pack - c:\mrpotato\DeIsL1.isu
AddRemove-VeggieMysteryIslandDKey - c:\program files\BigIdea\The Mystery of Veggie Island\DeIsL1.isu
AddRemove-Yahoo! Anti-Spy - c:\progra~1\Yahoo!\common\unypsr.exe
AddRemove-Yahoo! Companion - c:\progra~1\Yahoo!\Common\UNYT_W~1.EXE
AddRemove-Yahoo! Messenger - c:\progra~1\Yahoo!\MESSEN~1\UNWISE.EXE
AddRemove-Yahoo! Search Defender - c:\progra~1\Yahoo!\SEARCH~1\UNINST~1.EXE
AddRemove-Yahoo! Software Update - c:\progra~1\Yahoo!\SOFTWA~1\UNINST~1.EXE
AddRemove-Yahoo! Toolbar - c:\progra~1\Yahoo!\Common\UNYT_W~1.EXE
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-06-10 16:27
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet006\Services\srvF28]
"servicedll"="\\?\globalroot\Device\HarddiskVolume1\WINDOWS\TEMP\srvF28.tmp"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(3976)
c:\windows\system32\WININET.dll
c:\documents and settings\Owner\Local Settings\Application Data\Plaxo\3.26.0.13\plx_hook.dll
c:\program files\Windows Media Player\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\drivers\dcfssvc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\drivers\KodakCCS.exe
c:\program files\Network Associates\Common Framework\FrameworkService.exe
c:\windows\System32\HPZipm12.exe
c:\program files\Google\Update\1.3.21.57\GoogleCrashHandler.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\progra~1\NETWOR~1\COMMON~1\naPrdMgr.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\HP\Digital Imaging\bin\hpqgalry.exe
.
**************************************************************************
.
Completion time: 2011-06-10 16:38:10 - machine was rebooted
ComboFix-quarantined-files.txt 2011-06-10 20:37
.
Pre-Run: 10,379,530,240 bytes free
Post-Run: 15,516,286,976 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
.
Current=6 Default=6 Failed=5 LastKnownGood=7 Sets=1,2,3,4,5,6,7
- - End Of File - - DF0102AB1731FC7DD9A4A98E16E27946