I have run through about five searches (tried dozens of search results) and tried some links in e-mail, everything seems to be working and the internet seems to have increased in speed. Incredible!
Here are the results;
ComboFix 12-10-22.01 - Gwill 10/22/2012 12:00:32.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2046.1107 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Gwill\Desktop\CFScript.txt
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\$recycle.bin\S-1-5-21-2861772215-3948250270-1845948433-1000\$e4547d5306294d448f43a6a348142b53\@
c:\$recycle.bin\S-1-5-21-2861772215-3948250270-1845948433-1000\$e4547d5306294d448f43a6a348142b53\L\00000004.@
c:\$recycle.bin\S-1-5-21-2861772215-3948250270-1845948433-1000\$e4547d5306294d448f43a6a348142b53\n
c:\$recycle.bin\S-1-5-21-2861772215-3948250270-1845948433-1000\$e4547d5306294d448f43a6a348142b53\U\00000004.@
c:\$recycle.bin\S-1-5-21-2861772215-3948250270-1845948433-1000\$e4547d5306294d448f43a6a348142b53\U\00000008.@
c:\$recycle.bin\S-1-5-21-2861772215-3948250270-1845948433-1000\$e4547d5306294d448f43a6a348142b53\U\000000cb.@
c:\$recycle.bin\S-1-5-21-2861772215-3948250270-1845948433-1000\$e4547d5306294d448f43a6a348142b53\U\80000000.@
c:\$recycle.bin\S-1-5-21-2861772215-3948250270-1845948433-1000\$e4547d5306294d448f43a6a348142b53\U\80000032.@
c:\users\Gwill\ms.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-09-22 to 2012-10-22 )))))))))))))))))))))))))))))))
.
.
2012-10-22 16:07 . 2012-10-22 16:10 ——– d—–w- c:\users\Gwill\AppData\Local\temp
2012-10-22 16:07 . 2012-10-22 16:07 ——– d—–w- c:\users\Default\AppData\Local\temp
2012-10-22 00:17 . 2012-10-22 00:17 ——– d—–w- C:\Apple
2012-10-21 17:16 . 2012-10-21 17:16 ——– d—–w- C:\FRST
2012-10-21 12:53 . 2012-10-12 05:56 6918632 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1D2A4979-F459-4013-B079-4D3A4C7A6183}\mpengine.dll
2012-10-21 12:45 . 2012-08-24 15:53 172544 —-a-w- c:\windows\system32\wintrust.dll
2012-10-21 12:45 . 2012-06-02 00:02 985088 —-a-w- c:\windows\system32\crypt32.dll
2012-10-21 12:45 . 2012-06-02 00:02 98304 —-a-w- c:\windows\system32\cryptnet.dll
2012-10-21 12:45 . 2012-06-02 00:02 133120 —-a-w- c:\windows\system32\cryptsvc.dll
2012-10-21 12:45 . 2012-09-13 13:28 2048 —-a-w- c:\windows\system32\tzres.dll
2012-10-21 12:45 . 2012-08-29 11:27 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-10-21 12:44 . 2012-08-29 11:27 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-10-20 18:09 . 2012-08-21 17:01 26840 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-10-20 18:09 . 2012-10-20 18:09 ——– d—–w- c:\program files\iPod
2012-10-20 18:08 . 2012-10-20 18:09 ——– d—–w- c:\programdata\188F1432-103A-4ffb-80F1-36B633C5C9E1
2012-10-20 18:08 . 2012-10-20 18:09 ——– d—–w- c:\program files\iTunes
2012-10-20 18:04 . 2012-10-20 18:04 ——– d—–w- c:\program files\Bonjour
2012-10-05 17:38 . 2012-10-05 17:38 ——– d—–w- C:\TDSSKiller_Quarantine
2012-10-04 23:46 . 2012-10-04 23:46 ——– d-sh–w- c:\windows\system32\%APPDATA%
2012-10-04 00:19 . 2012-10-22 10:42 ——– d—–w- c:\users\Gwill\AppData\Roaming\vlc
2012-10-04 00:18 . 2012-10-04 00:18 ——– d—–w- c:\program files\VideoLAN
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-11 01:28 . 2012-04-03 19:42 696760 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-11 01:28 . 2011-06-01 17:10 73656 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-10-05 17:40 . 2010-10-09 13:30 66560 —-a-w- c:\windows\system32\drivers\smb.sys
2012-09-19 23:22 . 2012-09-19 23:22 93672 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-09-19 23:21 . 2012-06-04 02:09 821736 —-a-w- c:\windows\system32\npdeployJava1.dll
2012-09-19 23:21 . 2010-08-14 12:38 746984 —-a-w- c:\windows\system32\deployJava1.dll
2012-08-24 06:59 . 2012-09-22 11:02 1800704 —-a-w- c:\windows\system32\jscript9.dll
2012-08-24 06:51 . 2012-09-22 11:02 1129472 —-a-w- c:\windows\system32\wininet.dll
2012-08-24 06:51 . 2012-09-22 11:02 1427968 —-a-w- c:\windows\system32\inetcpl.cpl
2012-08-24 06:47 . 2012-09-22 11:02 142848 —-a-w- c:\windows\system32\ieUnatt.exe
2012-08-24 06:47 . 2012-09-22 11:02 420864 —-a-w- c:\windows\system32\vbscript.dll
2012-08-24 06:43 . 2012-09-22 11:02 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2012-08-21 17:01 . 2012-03-14 16:25 106928 —-a-w- c:\windows\system32\GEARAspi.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"Sidebar"="c:\program files\windows sidebar\sidebar.exe" [2009-04-11 1233920]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"Apple"="c:\users\Gwill\AppData\Local\Apple\reegpadn.dll" [2012-10-22 354304]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-17 4907008]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-09-23 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-23 8429568]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-09-23 81920]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-08-28 59280]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-05-25 17920]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-09-10 421776]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-11-15 50688]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
S2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2012-10-22 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 01:28]
.
2012-10-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-03 23:36]
.
2012-10-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-03 23:36]
.
.
——- Supplementary Scan ——-
.
uStart Page =
https://www.google.com/
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 192.168.2.1
DPF: {3641803B-72A4-4A9A-BA18-F1446F7CCDE4} - hxxp://hnshelby.dyndns.org/UltraHVCamX.cab
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-10-22 12:10
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Apple = rundll32.exe c:\users\Gwill\AppData\Local\Apple\reegpadn.dll,DllUnregisterServer?3456789
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\PCDSRVC{E9D79540-57D5953E-06020200}_0]
"ImagePath"="\??\c:\program files\dell support center\pcdsrvc.pkms"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
———————— Other Running Processes ————————
.
c:\windows\system32\atiesrxx.exe
c:\windows\system32\atieclxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\windows\system32\WUDFHost.exe
c:\windows\RtHDVCpl.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
.
**************************************************************************
.
Completion time: 2012-10-22 12:14:23 - machine was rebooted
ComboFix-quarantined-files.txt 2012-10-22 16:14
ComboFix2.txt 2012-10-20 17:14
.
Pre-Run: 14,439,862,272 bytes free
Post-Run: 14,379,966,464 bytes free
.
- - End Of File - - 579AEEED0D54185B4C99BF3A18E3E393