Okay. Got to computer tonight, and ran combofix. I have the log here, which I will paste below. I can attach it if you'd prefer... just say the word. Thanks. Please let me know where we go/what we do from here. Thanks again.
ComboFix 09-12-26.05 - Jnanama 12/30/2009 1:50.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.479 [GMT -5:00]
Running from: c:\documents and settings\Jnanama\Desktop\ComboFix.exe
AV: Norton Internet Security *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\recycler\S-1-5-21-346308534-839334332-2326838845-1003
c:\windows\Tasks\ucjmxjra.job
.
((((((((((((((((((((((((( Files Created from 2009-11-28 to 2009-12-30 )))))))))))))))))))))))))))))))
.
2009-12-30 06:58 . 2009-08-26 00:09 165240 ----a-r- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
2009-12-30 01:54 . 2009-12-20 09:00 84912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20091229.025\NAVENG.SYS
2009-12-30 01:54 . 2009-12-20 09:00 177520 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20091229.025\NAVENG32.DLL
2009-12-30 01:54 . 2009-12-20 09:00 1647984 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20091229.025\NAVEX32A.DLL
2009-12-30 01:54 . 2009-12-20 09:00 1323568 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20091229.025\NAVEX15.SYS
2009-12-30 01:54 . 2009-12-20 09:00 371248 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20091229.025\EECTRL.SYS
2009-12-30 01:54 . 2009-12-20 09:00 2747440 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20091229.025\CCERASER.DLL
2009-12-30 01:54 . 2009-12-20 09:00 259440 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20091229.025\ECMSVR32.DLL
2009-12-30 01:54 . 2009-12-20 09:00 102448 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20091229.025\ERASER.SYS
2009-12-26 22:44 . 2009-12-26 22:44 -------- d-----w- c:\documents and settings\Jnanama\DoctorWeb
2009-12-26 22:18 . 2009-12-27 23:15 52224 ----a-w- c:\documents and settings\Jnanama\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2009-12-26 22:18 . 2009-12-27 23:15 117760 ----a-w- c:\documents and settings\Jnanama\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-12-26 22:17 . 2009-12-26 22:17 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-12-26 22:16 . 2009-12-26 22:16 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-12-26 22:16 . 2009-12-26 22:16 -------- d-----w- c:\documents and settings\Jnanama\Application Data\SUPERAntiSpyware.com
2009-12-26 22:16 . 2009-12-26 22:16 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-12-26 20:00 . 2009-12-26 20:00 -------- d-----w- c:\documents and settings\Jnanama\Application Data\Malwarebytes
2009-12-26 19:59 . 2009-12-26 19:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-25 20:29 . 2009-12-25 20:29 -------- d-----w- c:\windows\Sun
2009-12-25 20:28 . 2009-12-25 20:27 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-25 20:27 . 2009-12-25 20:27 -------- d-----w- c:\program files\Java
2009-12-25 20:26 . 2009-12-25 20:26 152576 ----a-w- c:\documents and settings\Jnanama\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-12-25 20:24 . 2009-12-25 20:24 79488 ----a-w- c:\documents and settings\Jnanama\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-12-24 02:31 . 2009-12-24 02:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-12-22 17:14 . 2008-04-14 12:00 26624 ----a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2009-12-21 00:42 . 2009-11-05 06:30 811896 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091217.002\Scxpx86.dll
2009-12-21 00:42 . 2009-11-05 06:30 488312 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091217.002\IDSxpx86.dll
2009-12-21 00:42 . 2009-11-05 06:30 466992 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091217.002\IDSviA64.sys
2009-12-21 00:42 . 2009-11-05 06:30 343088 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091217.002\IDSvix86.sys
2009-12-21 00:42 . 2009-11-05 06:30 329592 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091217.002\IDSXpx86.sys
2009-12-20 22:50 . 2009-12-22 15:50 554352 ----a-r- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
2009-12-20 22:39 . 2009-12-23 03:16 -------- d-----w- c:\windows\system32\drivers\NIS
2009-12-20 22:39 . 2009-12-20 22:39 -------- d-----w- c:\program files\Windows Sidebar
2009-12-20 22:39 . 2009-12-20 22:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2009-12-20 22:39 . 2009-12-20 22:39 -------- d-----w- c:\program files\NortonInstaller
2009-12-20 22:39 . 2009-12-20 22:39 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-12-20 22:28 . 2009-12-20 22:28 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2009-12-20 22:27 . 2008-04-14 05:15 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2009-12-20 22:27 . 2008-04-14 05:15 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2009-12-20 22:27 . 2009-12-20 22:27 -------- d-----w- c:\program files\HP
2009-12-20 22:18 . 2009-12-20 22:29 103509 ----a-w- c:\windows\hpoins04.dat
2009-12-20 22:18 . 2004-06-22 15:04 17176 ------w- c:\windows\hpomdl04.dat
2009-12-20 22:18 . 2004-06-22 15:05 51088 ----a-w- c:\windows\system32\drivers\hpzid412.sys
2009-12-20 22:18 . 2004-06-22 15:05 21744 ----a-w- c:\windows\system32\drivers\HPZius12.sys
2009-12-20 22:18 . 2004-06-22 15:05 16496 ----a-w- c:\windows\system32\drivers\HPZipr12.sys
2009-12-20 22:18 . 2004-06-22 15:05 90112 ----a-w- c:\windows\system32\hpovst08.dll
2009-12-20 22:18 . 2004-06-22 15:05 581632 ----a-w- c:\windows\system32\hpotscl.dll
2009-12-20 22:18 . 2004-06-22 15:05 278528 ----a-w- c:\windows\system32\hpgwiamd.dll
2009-12-20 22:18 . 2004-06-22 15:04 270336 ----a-w- c:\windows\system32\HPZc3212.dll
2009-12-20 22:18 . 2004-06-22 15:05 135249 ----a-w- c:\windows\system32\hpzlnt10.dll
2009-12-20 22:18 . 2004-06-22 15:05 196608 ----a-w- c:\windows\system32\hpzcoi10.dll
2009-12-20 22:18 . 2004-06-22 15:05 344064 ----a-w- c:\windows\system32\hpzcon10.dll
2009-12-20 20:15 . 2009-12-20 20:15 -------- d-sh--w- c:\documents and settings\Jnanama\PrivacIE
2009-12-18 06:25 . 2009-12-18 06:25 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-12-18 02:19 . 2009-12-18 02:19 -------- d-sh--w- c:\documents and settings\Jnanama\IETldCache
2009-12-17 04:15 . 2009-10-29 07:45 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-12-17 04:15 . 2009-10-29 07:45 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-12-17 04:14 . 2009-12-20 19:29 -------- d-----w- c:\windows\ie8updates
2009-12-17 04:14 . 2009-10-02 04:44 92160 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-12-17 04:14 . 2009-12-17 04:14 -------- dc-h--w- c:\windows\ie8
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-25 05:04 . 2009-06-23 03:51 -------- d-----w- c:\program files\Common Files\Adobe
2009-12-23 02:37 . 2009-11-15 02:30 862040 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2009-12-23 02:37 . 2009-11-15 02:30 206944 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2009-12-23 02:37 . 2009-11-15 02:30 390288 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
2009-12-23 02:37 . 2009-11-15 02:30 537576 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\aawapi.dll
2009-12-23 02:37 . 2009-11-15 02:30 370744 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2009-12-23 02:37 . 2009-11-15 02:30 163728 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\ShellExt.dll
2009-12-23 02:37 . 2009-11-15 02:30 194104 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Savapibridge.dll
2009-12-23 02:35 . 2009-11-15 02:30 6296864 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2009-12-23 02:35 . 2009-11-15 02:30 327000 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\RPAPI.dll
2009-12-23 02:35 . 2009-11-15 02:30 87496 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\PrivacyClean.dll
2009-12-23 02:35 . 2009-11-15 02:29 933120 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2009-12-23 02:34 . 2009-11-15 02:29 641632 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2009-12-23 02:34 . 2009-11-15 02:29 816272 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2009-12-23 02:34 . 2009-11-15 02:29 822904 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2009-12-23 02:34 . 2009-11-15 02:29 1643272 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2009-12-23 02:34 . 2009-11-15 02:29 788880 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2009-12-23 02:34 . 2009-11-15 02:29 1181328 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2009-12-22 15:50 . 2009-12-20 22:40 -------- d-----w- c:\program files\Symantec
2009-12-22 15:50 . 2009-12-20 22:40 806 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
2009-12-22 15:50 . 2009-12-20 22:40 7456 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2009-12-22 15:50 . 2009-12-20 22:40 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
2009-12-22 15:50 . 2009-12-20 22:40 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2009-12-21 00:37 . 2009-12-20 22:40 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-12-20 22:40 . 2009-12-20 22:40 1294680 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\SyKnAppS.dll
2009-12-20 22:40 . 2009-12-20 22:40 136840 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\patch25.dll
2009-12-20 22:40 . 2009-12-20 22:40 791920 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\CLT\cltLMSx.dll
2009-12-20 22:40 . 2009-12-20 22:40 288104 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\CPDOEM\CPDOEM.dll
2009-12-20 22:39 . 2009-06-23 04:03 -------- d-----w- c:\program files\Norton Internet Security
2009-12-20 19:41 . 2009-06-23 04:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-20 19:38 . 2009-11-13 16:33 60664 ----a-w- c:\documents and settings\Jnanama\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-15 17:37 . 2009-06-23 03:51 -------- d-----w- c:\program files\Microsoft Works
2009-11-24 22:29 . 2009-11-16 02:05 -------- d-----w- c:\documents and settings\Jnanama\Application Data\U3
2009-11-16 02:07 . 2009-11-16 02:07 -------- d-----w- c:\documents and settings\All Users\Application Data\TEMP
2009-11-15 02:40 . 2009-11-15 02:40 -------- d-----w- c:\documents and settings\Jnanama\Application Data\AVG8
2009-11-15 02:30 . 2009-11-15 02:31 93360 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2009-11-15 02:30 . 2009-11-15 02:30 93360 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\SBREDrv.sys
2009-11-15 02:30 . 2009-11-15 02:30 554280 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\sbap.dll
2009-11-15 02:30 . 2009-11-15 02:47 15880 ----a-w- c:\windows\system32\lsdelete.exe
2009-11-15 02:30 . 2009-11-15 02:30 15880 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lsdelete.exe
2009-11-15 02:30 . 2009-11-15 02:30 212480 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\VipreBridge.dll
2009-11-15 02:30 . 2009-11-15 02:30 283944 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Vipre.dll
2009-11-15 02:30 . 2009-11-15 02:30 1223976 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\SBTE.dll
2009-11-15 02:30 . 2009-11-15 02:30 242984 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\SBRE.dll
2009-11-15 02:28 . 2009-11-15 02:28 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}
2009-11-15 02:27 . 2009-11-15 02:27 -------- d-----w- c:\program files\Lavasoft
2009-11-15 02:27 . 2009-11-15 02:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-11-15 02:19 . 2009-11-15 02:19 -------- d-----w- c:\program files\AskBarDis
2009-11-15 02:19 . 2009-11-15 02:19 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2009-11-15 02:19 . 2009-11-15 02:19 -------- d-----w- c:\program files\Zone Labs
2009-11-15 02:17 . 2009-11-15 02:17 -------- d-----w- c:\documents and settings\Jnanama\Application Data\Sammsoft
2009-11-15 02:17 . 2009-11-15 02:17 -------- d-----w- c:\program files\MemTurbo 4
2009-11-15 02:17 . 2009-11-15 02:17 -------- d-----w- c:\program files\Advanced Registry Optimizer
2009-11-15 01:42 . 2009-11-15 01:42 0 ----a-w- c:\windows\nsreg.dat
2009-11-13 16:37 . 2009-11-13 16:37 0 ----a-w- c:\documents and settings\Jnanama\Application Data\wklnhst.dat
2009-11-05 06:30 . 2009-12-20 22:40 466992 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSviA64.sys
2009-11-05 06:30 . 2009-12-20 22:40 343088 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSvix86.sys
2009-11-05 06:30 . 2009-12-20 22:40 329592 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSXpx86.sys
2009-11-05 06:30 . 2009-12-20 22:40 811896 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\Scxpx86.dll
2009-11-05 06:30 . 2009-12-20 22:40 488312 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSxpx86.dll
2009-10-29 07:45 . 2009-05-20 19:07 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2009-05-20 19:07 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2009-05-20 19:07 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2008-04-14 00:23 265728 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2009-05-20 19:07 270336 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2009-05-20 19:07 149504 ----a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2009-05-20 19:07 79872 ----a-w- c:\windows\system32\raschap.dll
2009-10-03 08:15 . 2009-11-15 02:28 2924848 -c--a-w- c:\documents and settings\All Users\Application Data\{CFBD8779-FAAB-4357-84F2-1EC8619FADA6}\Ad-AwareInstallation.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-10-16 23:22 333192 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-10-16 333192]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayIconExtension1]
@="{fe25455d-b4c2-4e32-97d2-92632ec1c224}"
[HKEY_CLASSES_ROOT\CLSID\{fe25455d-b4c2-4e32-97d2-92632ec1c224}]
2005-09-23 14:28 270848 ----a-w- c:\windows\system32\mscoree.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayIconExtension2]
@="{1fae2d88-a78e-4f03-909f-be818a3c1ce6}"
[HKEY_CLASSES_ROOT\CLSID\{1fae2d88-a78e-4f03-909f-be818a3c1ce6}]
2005-09-23 14:28 270848 ----a-w- c:\windows\system32\mscoree.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-12-16 2002160]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AsusACPIServer"="c:\program files\EeePC\ACPI\AsAcpiSvr.exe" [2009-04-17 630784]
"AsusEPCMonitor"="c:\program files\EeePC\ACPI\AsEPCMon.exe" [2009-03-13 98304]
"AsusTray"="c:\program files\EeePC\ACPI\AsTray.exe" [2009-04-17 118784]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-03-06 1434920]
"SynAsusAcpi"="c:\program files\Synaptics\SynTP\SynAsusAcpi.exe" [2009-03-06 79144]
c:\documents and settings\Jnanama\Start Menu\Programs\Startup\
MemTurbo.lnk - c:\program files\MemTurbo 4\MemTurbo.exe [2009-11-14 3121760]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
SuperHybridEngine.lnk - c:\program files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe [2009-6-22 376832]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-10-15 06:04 39792 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AROReminder]
2008-08-22 21:33 2084480 ----a-w- c:\program files\Advanced Registry Optimizer\ARO.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS Screen Saver Protector]
2009-07-08 07:10 3054136 ----a-w- c:\windows\AsScrPro.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LiveUpdate]
2009-08-27 21:53 735208 ----a-w- c:\program files\ASUS\LiveUpdate\LiveUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2009-02-07 01:51 3885408 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]
2008-04-14 12:00 59392 ----a-w- c:\windows\system32\IME\PINTLGNT\IMSCINST.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
2008-04-14 12:00 455168 ----a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
2008-04-14 12:00 455168 ----a-w- c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2009-03-27 03:22 17567744 ----a-w- c:\windows\RTHDCPL.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-12-25 20:27 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ASKService"=2 (0x2)
"btwdins"=2 (0x2)
"TapiSrv"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)
"odserv"=3 (0x3)
"ose"=3 (0x3)
"fsssvc"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [11/14/2009 9:31 PM 64288]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1007020.00B\SymEFA.sys [12/22/2009 10:50 AM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NIS\1007020.00B\BHDrvx86.sys [12/22/2009 10:50 AM 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1007020.00B\cchpx86.sys [12/22/2009 10:50 AM 482432]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20091217.002\IDSXpx86.sys [12/20/2009 7:42 PM 329592]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [12/16/2009 4:26 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12/16/2009 4:26 PM 74480]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [6/22/2009 11:03 PM 55152]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [9/24/2009 6:17 AM 1181328]
R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Norton Internet Security\Engine\16.7.2.11\ccSvcHst.exe [12/22/2009 10:50 AM 117640]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [12/20/2009 7:42 PM 102448]
R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sys [6/1/2009 2:26 AM 38912]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [12/16/2009 4:27 PM 7408]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [6/22/2009 10:49 PM 1684736]
S3 uvclf;uvclf;c:\windows\system32\drivers\uvclf.sys [6/1/2009 2:26 AM 39040]
S4 ASKService;ASKService;c:\program files\AskBarDis\bar\bin\AskService.exe [11/14/2009 9:19 PM 464264]
S4 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [2/6/2009 8:08 PM 533360]
.
------- Supplementary Scan -------
.
uStart Page = hxxp://mail.yahoo.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\documents and settings\Jnanama\Application Data\Mozilla\Firefox\Profiles\zbotgoou.default\
FF - prefs.js: browser.startup.homepage - mail.yahoo.com
FF - component: c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.
- - - - ORPHANS REMOVED - - - -
SharedTaskScheduler-{4d637875-854f-4771-9f4c-de41ef49f867} - c:\windows\system32\hinovali.dll
SharedTaskScheduler-{8077a75d-cf61-4fa9-b2d1-cf254b1275b7} - c:\windows\system32\jifafusu.dll
SharedTaskScheduler-{87124200-10fc-4030-8c80-233a0c190f7a} - c:\windows\system32\zimuworo.dll
SharedTaskScheduler-{2c9d0ee2-a784-4825-817c-34fdb5b389f3} - c:\windows\system32\yejedotu.dll
SharedTaskScheduler-{bcbd066f-7783-4c28-be45-61b619cdcd1a} - c:\windows\system32\fomasopi.dll
SharedTaskScheduler-{3fc5f7be-406a-456f-8ff6-ded646501f6b} - (no file)
SharedTaskScheduler-{a1db03a4-ce46-4167-88f4-3cb4bae60d8e} - c:\windows\system32\weyokupi.dll
SharedTaskScheduler-{dc2b5773-e8e1-4687-970c-98c94cea08f8} - c:\windows\system32\vonibusa.dll
SSODL-lugubawek-{4d637875-854f-4771-9f4c-de41ef49f867} - c:\windows\system32\hinovali.dll
SSODL-jumefupul-{8077a75d-cf61-4fa9-b2d1-cf254b1275b7} - c:\windows\system32\jifafusu.dll
SSODL-yudevuziy-{87124200-10fc-4030-8c80-233a0c190f7a} - (no file)
SSODL-jofokuyug-{2c9d0ee2-a784-4825-817c-34fdb5b389f3} - (no file)
SSODL-durudemig-{bcbd066f-7783-4c28-be45-61b619cdcd1a} - c:\windows\system32\fomasopi.dll
SSODL-seriburuh-{3fc5f7be-406a-456f-8ff6-ded646501f6b} - c:\windows\system32\kedohugu.dll
SSODL-dehagewef-{a1db03a4-ce46-4167-88f4-3cb4bae60d8e} - c:\windows\system32\weyokupi.dll
SSODL-kuvazumog-{dc2b5773-e8e1-4687-970c-98c94cea08f8} - (no file)
MSConfigStartUp-banawifep - c:\windows\system32\vonibusa.dll
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-12-30 01:58
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton Internet Security]
"ImagePath"="\"c:\program files\Norton Internet Security\Norton Internet Security\Engine\16.7.2.11\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Norton Internet Security\Engine\16.7.2.11\diMaster.dll\" /prefetch:1"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1128)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(2076)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.1801_x-ww_5eed8217\MSVCR80.dll
c:\program files\ASUS\Eee Storage\XPClient.dll
c:\program files\ASUS\Eee Storage\LogicNP.EZShellExtensions.dll
c:\program files\ASUS\Eee Storage\EcaremeDLL.dll
c:\windows\assembly\GAC_MSIL\SqliteShared\1.0.3390.31024__0d0f4b69e50e559b\SqliteShared.dll
c:\windows\assembly\GAC_32\System.Data.SQLite\1.0.60.0__db937bc2d44ff139\System.Data.SQLite.dll
c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\igfxext.exe
c:\windows\SoftwareDistribution\Download\Install\dotnetfx35_x86.exe
d:\c4d015ec55f41343f5d0f24e20\dotnetfx35setup.exe
d:\997d4469dea42f194fce\setup.exe
c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\MsiExec.exe
.
**************************************************************************
.
Completion time: 2009-12-30 02:06:12 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-30 07:06
Pre-Run: 63,173,906,432 bytes free
Post-Run: 64,098,144,256 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - F3FD9CDEE1754F32F23C9CF4BF17E0B8