Not sure if I've downloaded combofix correctly- I'm using firefox so can only press save, then when I double clicked it from the downloads, I didn't get an option to save to my desktop so unlike the other things I've downloaded, it hasn't got a shortcut/quick launch icon there...
I disabled my anti-virus and spyware real-time checkers, however when it was running a brief pop-up notification came up from McAfee that it had found a virus and removed it... not sure why that is, I definitely disabled it as I got the warning bubble that my computer was not secure... anyway. Here's the log files- thank you for the quick response again.
MBR:
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows XP Home Edition
Windows Information: Service Pack 3 (build 2600)
Logical Drives Mask: 0x0000000c
Kernel Drivers (total 124):
0x804D7000 \WINDOWS\system32\ntkrnlpa.exe
0x806E4000 \WINDOWS\system32\hal.dll
0xF7ABD000 \WINDOWS\system32\KDCOM.DLL
0xF79CD000 \WINDOWS\system32\BOOTVID.dll
0xF75BD000 szkg.sys
0xF7493000 szkgfs.sys
0xF7465000 ACPI.sys
0xF7ABF000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
0xF7454000 pci.sys
0xF75DD000 isapnp.sys
0xF79D1000 compbatt.sys
0xF79D5000 \WINDOWS\system32\DRIVERS\BATTC.SYS
0xF7B85000 pciide.sys
0xF783D000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
0xF75ED000 MountMgr.sys
0xF7435000 ftdisk.sys
0xF7845000 PartMgr.sys
0xF79D9000 ACPIEC.sys
0xF7B86000 \WINDOWS\system32\DRIVERS\OPRGHDLR.SYS
0xF75FD000 VolSnap.sys
0xF741D000 atapi.sys
0xF7342000 iaStor.sys
0xF760D000 disk.sys
0xF761D000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
0xF7322000 fltMgr.sys
0xF762D000 PxHelp20.sys
0xF730B000 KSecDD.sys
0xF727E000 Ntfs.sys
0xF7251000 NDIS.sys
0xF784D000 TVALZ_O.SYS
0xF7AC1000 Thpevm.SYS
0xF7855000 thpdrv.sys
0xF7237000 Mup.sys
0xF774D000 \SystemRoot\system32\DRIVERS\intelppm.sys
0xF593F000 \SystemRoot\system32\DRIVERS\igxpmp32.sys
0xF592B000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0xF5903000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0xF5793000 \SystemRoot\system32\DRIVERS\athw.sys
0xF5775000 \SystemRoot\system32\DRIVERS\Rtenicxp.sys
0xF78B5000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0xF5751000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0xF78BD000 \SystemRoot\system32\DRIVERS\usbehci.sys
0xF71F3000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0xF71EF000 \SystemRoot\system32\DRIVERS\tosrfec.sys
0xF775D000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0xF78C5000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0xF5725000 \SystemRoot\system32\DRIVERS\Apfiltr.sys
0xF776D000 \SystemRoot\system32\DRIVERS\WDFLDR.SYS
0xF56AA000 \SystemRoot\system32\DRIVERS\Wdf01000.sys
0xF78CD000 \SystemRoot\system32\DRIVERS\mouclass.sys
0xF7C17000 \SystemRoot\system32\DRIVERS\audstub.sys
0xF777D000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0xF71DA000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0xF5693000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0xF778D000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0xF779D000 \SystemRoot\system32\DRIVERS\raspptp.sys
0xF78D5000 \SystemRoot\system32\DRIVERS\TDI.SYS
0xF5682000 \SystemRoot\system32\DRIVERS\psched.sys
0xF77AD000 \SystemRoot\system32\DRIVERS\msgpc.sys
0xF78DD000 \SystemRoot\system32\DRIVERS\ptilink.sys
0xF78E5000 \SystemRoot\system32\DRIVERS\raspti.sys
0xF77BD000 \SystemRoot\system32\DRIVERS\termdd.sys
0xF7AFD000 \SystemRoot\system32\DRIVERS\swenum.sys
0xF565F000 \SystemRoot\system32\DRIVERS\ks.sys
0xF52DB000 \SystemRoot\system32\DRIVERS\update.sys
0xF71C2000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0xF5F25000 \SystemRoot\system32\DRIVERS\wsimd.sys
0xF5F15000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xF0FD1000 \SystemRoot\system32\DRIVERS\usbhub.sys
0xF7B53000 \SystemRoot\system32\DRIVERS\USBD.SYS
0xAA2C3000 \SystemRoot\system32\drivers\RtkHDAud.sys
0xAA29F000 \SystemRoot\system32\drivers\portcls.sys
0xF0FC1000 \SystemRoot\system32\drivers\drmk.sys
0xA78DC000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xA65CC000 \SystemRoot\System32\Drivers\Null.SYS
0xA78DA000 \SystemRoot\System32\Drivers\Beep.SYS
0xA6AFD000 \SystemRoot\System32\drivers\vga.sys
0xA78D8000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xA78D6000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xA6AF5000 \SystemRoot\System32\Drivers\Msfs.SYS
0xA6AED000 \SystemRoot\System32\Drivers\Npfs.SYS
0xA69FC000 \SystemRoot\system32\DRIVERS\rasacd.sys
0xA566F000 \SystemRoot\system32\DRIVERS\ipsec.sys
0xA5616000 \SystemRoot\system32\DRIVERS\tcpip.sys
0xA55EF000 \SystemRoot\System32\Drivers\Mpfp.sys
0xA55C9000 \SystemRoot\system32\DRIVERS\ipnat.sys
0xA6624000 \SystemRoot\system32\DRIVERS\ipfltdrv.sys
0xA615B000 \SystemRoot\System32\Drivers\UVCFTR_S.SYS
0xA6614000 \SystemRoot\System32\Drivers\cec_uvc.sys
0xA5EFF000 \SystemRoot\System32\Drivers\STREAM.SYS
0xA55A1000 \SystemRoot\system32\DRIVERS\netbt.sys
0xA557F000 \SystemRoot\System32\drivers\afd.sys
0xA5EEF000 \SystemRoot\system32\DRIVERS\netbios.sys
0xA69EC000 \??\C:\WINDOWS\system32\drivers\TPwSav.sys
0xA555D000 \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
0xA6153000 \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
0xA5532000 \SystemRoot\system32\DRIVERS\rdbss.sys
0xA54C2000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xA548F000 \SystemRoot\system32\drivers\mfehidk.sys
0xA5ECF000 \SystemRoot\System32\Drivers\Fips.SYS
0xA53B4000 \SystemRoot\System32\Drivers\dump_iaStor.sys
0xA587C000 \SystemRoot\system32\DRIVERS\wanarp.sys
0xBF800000 \SystemRoot\System32\win32k.sys
0xA5E6B000 \SystemRoot\System32\drivers\Dxapi.sys
0xA6143000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xF7CA4000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF024000 \SystemRoot\System32\igxpgd32.dll
0xBF012000 \SystemRoot\System32\igxprd32.dll
0xBF04F000 \SystemRoot\System32\igxpdv32.DLL
0xBF1E7000 \SystemRoot\System32\igxpdx32.DLL
0xBFFA0000 \SystemRoot\System32\ATMFD.DLL
0xA789C000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0xA7898000 \SystemRoot\system32\DRIVERS\netdevio.sys
0xA530F000 \SystemRoot\system32\DRIVERS\mrxdav.sys
0xA5240000 \SystemRoot\system32\DRIVERS\srv.sys
0xA4FFB000 \SystemRoot\system32\drivers\wdmaud.sys
0xF2024000 \SystemRoot\system32\drivers\sysaudio.sys
0xF1FD8000 \SystemRoot\system32\drivers\mfebopk.sys
0xA47F1000 \SystemRoot\system32\drivers\mfeavfk.sys
0xA4738000 \SystemRoot\System32\Drivers\HTTP.sys
0xA490B000 \SystemRoot\system32\drivers\mfesmfk.sys
0xA3CB4000 \SystemRoot\system32\drivers\kmixer.sys
0x7C900000 \WINDOWS\system32\ntdll.dll
Processes (total 69):
0 System Idle Process
4 System
528 C:\WINDOWS\system32\smss.exe
872 csrss.exe
896 C:\WINDOWS\system32\winlogon.exe
940 C:\WINDOWS\system32\services.exe
952 C:\WINDOWS\system32\lsass.exe
1108 C:\WINDOWS\system32\svchost.exe
1144 C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
1192 svchost.exe
1232 C:\WINDOWS\system32\svchost.exe
1384 svchost.exe
1432 svchost.exe
1740 C:\WINDOWS\system32\spoolsv.exe
1788 C:\WINDOWS\system32\acs.exe
1836 svchost.exe
1880 C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe
1952 C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
1996 C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
176 C:\PROGRA~1\COMMON~1\McAfee\MNA\McNASvc.exe
252 C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
292 C:\PROGRA~1\McAfee\VIRUSS~1\Mcshield.exe
412 C:\Program Files\McAfee\MPF\MpfSrv.exe
700 C:\Program Files\McAfee\MSK\msksrver.exe
1276 C:\WINDOWS\system32\svchost.exe
828 C:\WINDOWS\explorer.exe
1404 C:\WINDOWS\system32\ThpSrv.exe
2124 C:\WINDOWS\system32\TODDSrv.exe
2356 C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
2708 C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
2768 wdfmgr.exe
2800 C:\WINDOWS\system32\searchindexer.exe
3080 C:\WINDOWS\system32\igfxtray.exe
3116 C:\WINDOWS\system32\hkcmd.exe
3124 C:\WINDOWS\system32\igfxpers.exe
3136 C:\WINDOWS\RTHDCPL.EXE
3148 C:\Program Files\Toshiba\E-KEY\CeEKey.exe
3172 C:\WINDOWS\system32\TDispVol.exe
3192 C:\Program Files\Toshiba\TOSHIBA Zooming Utility\SmoothView.exe
3216 C:\WINDOWS\system32\ZoomingHook.exe
3228 C:\Program Files\Toshiba\TouchPad\TPTray.exe
3236 C:\WINDOWS\system32\igfxsrvc.exe
3288 C:\WINDOWS\system32\TPSMain.exe
3384 C:\Program Files\Apoint2K\Apoint.exe
3432 C:\WINDOWS\system32\ctfmon.exe
3444 C:\Program Files\Toshiba\Toshiba Online Product Information\TOPI.exe
3460 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
3472 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
3524 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
3588 C:\WINDOWS\system32\TPSBattM.exe
3604 C:\Program Files\Windows Desktop Search\WindowsSearch.exe
3880 C:\Program Files\Apoint2K\ApntEx.exe
2304 alg.exe
3348 C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
232 C:\Program Files\STOPzilla!\STOPzilla.exe
3096 C:\Program Files\Mozilla Firefox\firefox.exe
1852 C:\Program Files\Mozilla Firefox\plugin-container.exe
3696 C:\WINDOWS\system32\wuauclt.exe
840 C:\WINDOWS\system32\wuauclt.exe
5608 C:\WINDOWS\system32\wuauclt.exe
3792 C:\WINDOWS\system32\msiexec.exe
608 wmiprvse.exe
2524 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
2056 C:\WINDOWS\system32\wbem\wmiadap.exe
5020 C:\WINDOWS\SoftwareDistribution\Download\Install\NDP30SP2-KB982168-x86.exe
5480 D:\f1a0a840538cc274ad98\HotFixInstaller.exe
5844 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
4548 C:\WINDOWS\system32\msiexec.exe
1044 C:\Documents and Settings\Laura\My Documents\Downloads\MBRCheck.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`007d8200 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000012`a1c98200 (NTFS)
PhysicalDrive0 Model Number: HitachiHTS545016B9A300, Rev: PBBOC64G
Size Device Name MBR Status
--------------------------------------------
149 GB \\.\PhysicalDrive0 Windows XP MBR code detected
SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A
Done!
ComboFix:
ComboFix 11-01-25.05 - Laura 26/01/2011 19:55:04.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1014.292 [GMT 0:00]
Running from: c:\documents and settings\Laura\My Documents\Downloads\ComboFix.exe
AV: McAfee VirusScan *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *Enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\xp
.
((((((((((((((((((((((((( Files Created from 2010-12-26 to 2011-01-26 )))))))))))))))))))))))))))))))
.
2011-01-26 19:36 . 2011-01-26 19:36 12568 ----a-w- c:\windows\system32\drivers\PROCEXP113.SYS
2011-01-26 18:40 . 2010-03-10 06:15 420352 ----a-w- c:\windows\system32\SET2EB.tmp
2011-01-26 18:38 . 2009-06-22 06:44 726528 ----a-w- c:\windows\system32\SET1CA.tmp
2011-01-26 18:27 . 2009-08-06 19:23 215920 ----a-w- c:\windows\system32\muweb.dll
2011-01-26 18:27 . 2009-08-06 19:23 274288 ----a-w- c:\windows\system32\mucltui.dll
2011-01-26 18:27 . 2011-01-26 18:37 -------- d-----w- c:\windows\LastGood
2011-01-26 14:31 . 2011-01-26 14:31 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2011-01-26 11:09 . 2010-12-20 18:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-26 11:09 . 2011-01-26 11:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-01-26 11:09 . 2011-01-26 11:09 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-01-26 11:09 . 2010-12-20 18:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-01-26 10:44 . 2011-01-26 10:44 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2011-01-26 10:43 . 2011-01-26 10:44 -------- d-----w- c:\program files\CCleaner
2011-01-26 10:42 . 2011-01-26 10:44 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-01-26 00:37 . 2011-01-26 10:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2011-01-26 00:37 . 2011-01-26 00:58 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-01-26 00:31 . 2011-01-26 00:31 -------- d-----w- c:\documents and settings\All Users\Application Data\TEMP
2011-01-26 00:31 . 2011-01-26 00:31 -------- d-----w- c:\program files\SpywareBlaster
2011-01-26 00:24 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2011-01-26 00:24 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2011-01-26 00:24 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2011-01-26 00:24 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2011-01-25 23:59 . 2011-01-25 23:59 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2011-01-25 23:07 . 2010-10-18 11:10 7680 -c----w- c:\windows\system32\dllcache\iecompat.dll
2011-01-25 23:05 . 2010-11-06 00:26 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2011-01-25 23:05 . 2010-11-06 00:26 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2011-01-25 23:05 . 2010-11-06 00:26 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2011-01-25 23:02 . 2011-01-25 23:04 -------- dc-h--w- c:\windows\ie8
2011-01-25 22:39 . 2011-01-25 22:39 -------- d-----w- c:\documents and settings\All Users\Application Data\SITEguard
2011-01-25 22:38 . 2011-01-25 22:38 -------- d-----w- c:\program files\STOPzilla!
2011-01-25 22:38 . 2011-01-25 22:38 -------- d-----w- c:\program files\Common Files\iS3
2011-01-25 22:37 . 2011-01-26 20:03 -------- d-----w- c:\documents and settings\All Users\Application Data\STOPzilla!
2011-01-25 21:54 . 2011-01-25 21:54 -------- d-----w- c:\program files\Trend Micro
2011-01-25 21:41 . 2011-01-25 21:45 16968 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2011-01-25 21:41 . 2011-01-25 21:41 -------- d-----w- c:\program files\Hitman Pro 3.5
2011-01-25 21:40 . 2011-01-25 21:44 134464 ----a-w- c:\windows\system32\LnkProtect.dll
2011-01-25 21:39 . 2011-01-25 21:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Hitman Pro
2011-01-25 21:35 . 2010-09-18 06:53 954368 -c----w- c:\windows\system32\dllcache\mfc40.dll
2011-01-25 21:35 . 2010-09-18 06:53 974848 -c----w- c:\windows\system32\dllcache\mfc42.dll
2011-01-25 21:35 . 2010-09-18 06:53 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2011-01-25 21:35 . 2010-06-21 15:27 354304 -c----w- c:\windows\system32\dllcache\srv.sys
2011-01-25 21:34 . 2010-08-23 16:12 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2011-01-25 21:33 . 2010-02-24 13:11 455680 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2011-01-25 21:32 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2011-01-25 21:32 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2011-01-25 21:30 . 2010-11-02 15:17 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
2011-01-25 21:30 . 2010-08-27 08:02 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2011-01-25 21:30 . 2009-10-15 16:28 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2011-01-25 21:30 . 2009-03-08 04:33 759296 -c--a-w- c:\windows\system32\dllcache\VGX.dll
2011-01-25 21:29 . 2010-04-27 13:59 2146304 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2011-01-25 21:29 . 2010-04-28 02:25 2189952 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2011-01-25 21:29 . 2010-04-27 13:05 2024448 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2011-01-25 21:29 . 2010-04-27 13:05 2066816 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2011-01-25 21:29 . 2009-06-21 21:44 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2011-01-25 21:29 . 2011-01-25 21:29 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2011-01-25 21:25 . 2011-01-25 21:25 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2011-01-25 21:23 . 2009-03-06 14:22 284160 -c----w- c:\windows\system32\dllcache\pdh.dll
2011-01-25 21:23 . 2009-02-09 12:10 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2011-01-25 21:23 . 2009-02-06 10:39 35328 -c----w- c:\windows\system32\dllcache\sc.exe
2011-01-25 21:23 . 2009-02-06 11:11 110592 -c----w- c:\windows\system32\dllcache\services.exe
2011-01-25 21:23 . 2009-02-09 12:10 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2011-01-25 21:23 . 2009-02-06 10:10 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2011-01-25 21:23 . 2009-02-09 12:10 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2011-01-25 21:23 . 2009-02-09 12:10 714752 -c----w- c:\windows\system32\dllcache\ntdll.dll
2011-01-25 21:23 . 2009-02-09 12:10 617472 -c----w- c:\windows\system32\dllcache\advapi32.dll
2011-01-25 21:21 . 2010-06-14 07:41 1172480 -c----w- c:\windows\system32\dllcache\msxml3.dll
2011-01-25 21:21 . 2010-07-12 12:55 218112 -c----w- c:\windows\system32\dllcache\wordpad.exe
2011-01-25 21:21 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2011-01-25 21:19 . 2010-06-18 13:36 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
2011-01-25 21:16 . 2011-01-25 21:16 -------- d-----w- c:\windows\Sun
2011-01-25 21:15 . 2009-06-22 06:44 726528 -c--a-w- c:\windows\system32\dllcache\jscript.dll
2011-01-25 21:15 . 2010-10-11 14:59 45568 -c----w- c:\windows\system32\dllcache\wab.exe
2011-01-25 21:15 . 2010-08-16 08:45 590848 -c----w- c:\windows\system32\dllcache\rpcrt4.dll
2011-01-25 21:15 . 2010-08-13 12:53 5120 ------w- c:\windows\system32\xpsp4res.dll
2011-01-25 21:11 . 2011-01-25 21:11 -------- d-----w- c:\documents and settings\LocalService\Application Data\SACore
2011-01-25 20:05 . 2009-03-27 21:45 599040 ----a-w- c:\windows\system32\TUSBSleepCharge.cpl
2011-01-25 20:04 . 2011-01-25 20:04 -------- d-----w- c:\program files\DIFX
2011-01-25 20:04 . 2009-03-18 20:10 17960 ----a-w- c:\windows\system32\drivers\UVCFTR_S.SYS
2011-01-25 20:04 . 2009-03-18 20:10 48176 ----a-w- c:\windows\system32\drivers\cec_uvc.sys
2011-01-25 20:03 . 2011-01-25 20:04 -------- d-----w- c:\program files\Camera Assistant Software for Toshiba
2011-01-25 20:02 . 2011-01-25 20:03 -------- d-----w- c:\program files\Apoint2K
2011-01-25 20:02 . 2008-02-06 23:23 166448 ----a-w- c:\windows\system32\drivers\Apfiltr.sys
2011-01-25 20:02 . 2006-11-02 07:09 1419232 ----a-w- c:\windows\system32\WdfCoinstaller01005.dll
2011-01-25 20:02 . 2008-01-19 15:53 100546 ----a-w- c:\windows\system32\Vxdif.dll
2011-01-25 19:59 . 2009-02-13 18:00 1503840 ----a-w- c:\windows\system32\drivers\athw.sys
2011-01-25 19:57 . 2011-01-25 19:57 -------- d-----w- C:\Intel
2011-01-25 19:57 . 2011-01-26 16:15 -------- d-----w- c:\documents and settings\Laura
2011-01-25 19:56 . 2009-04-08 21:00 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\toshiba
2011-01-25 19:56 . 2009-04-08 20:55 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\InstallShield
2011-01-25 19:56 . 2009-04-06 04:45 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Windows Desktop Search
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-18 18:12 . 2009-04-06 04:05 81920 ----a-w- c:\windows\system32\isign32.dll
2010-11-09 14:52 . 2009-04-03 11:32 249856 ----a-w- c:\windows\system32\odbc32.dll
2010-11-06 00:26 . 2009-04-03 11:33 916480 ----a-w- c:\windows\system32\wininet.dll
2010-11-06 00:26 . 2009-04-03 11:32 43520 ------w- c:\windows\system32\licmgr10.dll
2010-11-06 00:26 . 2009-04-03 11:32 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-11-03 12:25 . 2009-04-03 11:32 385024 ------w- c:\windows\system32\html.iec
2010-11-02 15:17 . 2009-04-03 11:32 40960 ----a-w- c:\windows\system32\drivers\ndproxy.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSHIBA Online Product Information"="c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2009-03-16 6158240]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-08 39408]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-01-13 2424560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-02-17 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-02-17 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-02-17 137752]
"RTHDCPL"="RTHDCPL.EXE" [2009-03-12 17531392]
"CeEKEY"="c:\program files\TOSHIBA\E-KEY\CeEKey.exe" [2009-03-18 827392]
"TDispVol"="TDispVol.exe" [2009-04-01 210232]
"SmoothView"="c:\program files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2007-04-09 159744]
"Zooming"="ZoomingHook.exe" [2005-06-06 24576]
"TPNF"="c:\program files\TOSHIBA\TouchPad\TPTray.exe" [2009-04-02 73728]
"TPSMain"="TPSMain.exe" [2009-03-18 266240]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2007-12-15 184320]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2010-11-10 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"TOSHIBA Online Product Information"="c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2009-03-16 6158240]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
R0 szkg5;szkg5;c:\windows\system32\drivers\SZKG.sys [07/12/2009 17:59 61328]
R0 szkgfs;szkgfs;c:\windows\system32\drivers\SZKGFS.sys [24/02/2010 15:06 173328]
R0 Thpdrv;TOSHIBA HDD Protection Driver;c:\windows\system32\drivers\thpdrv.sys [21/08/2008 09:35 28536]
R0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;c:\windows\system32\drivers\Thpevm.sys [04/09/2007 09:14 6528]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [17/02/2010 18:25 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10/05/2010 18:41 67656]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [08/04/2009 21:11 198432]
R3 cecnuvc;Chicony USB 2.0 Camera VD;c:\windows\system32\drivers\cec_uvc.sys [25/01/2011 20:04 48176]
S0 is3srv;is3srv;c:\windows\system32\drivers\is3srv.sys [07/12/2009 17:59 61328]
S2 0100311296041095mcinstcleanup;McAfee Application Installer Cleanup (0100311296041095);c:\windows\TEMP\010031~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service --> c:\windows\TEMP\010031~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [25/01/2011 21:24 136176]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [08/04/2009 20:47 1684736]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys --> c:\windows\system32\Drivers\RtsUStor.sys [?]
S3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys --> c:\windows\system32\DRIVERS\Rts516xIR.sys [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - RSVP
.
Contents of the 'Scheduled Tasks' folder
2011-01-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-01-25 21:24]
2011-01-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-01-25 21:24]
2009-04-08 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-04-08 12:22]
2009-04-08 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-04-08 12:22]
2011-01-25 c:\windows\Tasks\Registration reminder 1.job
- c:\windows\system32\OOBE\oobebaln.exe [2009-04-06 12:00]
2011-01-25 c:\windows\Tasks\Registration reminder 2.job
- c:\windows\system32\OOBE\oobebaln.exe [2009-04-06 12:00]
2011-01-25 c:\windows\Tasks\Registration reminder 3.job
- c:\windows\system32\OOBE\oobebaln.exe [2009-04-06 12:00]
.
.
------- Supplementary Scan -------
.
uStart Page =
www.greatday.com
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/redirectdomain?brand=TSEF&bmod=TSEF
uInternet Settings,ProxyServer = http=127.0.0.1:8992
uInternet Settings,ProxyOverride = <local>
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: {{76577871-04EC-495E-A12B-91F7C3600AFA} -
http://rover.ebay.com/rover/1/710-44557-9400-3/4
FF - ProfilePath - c:\documents and settings\Laura\Application Data\Mozilla\Firefox\Profiles\4fjmej6x.default\
FF - prefs.js: browser.startup.homepage -
www.greatday.com
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?sourceid=navclient&hl=en-GB&q=
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: McAfee SiteAdvisor: {B7082FAA-CB62-4872-9106-E42DD88EDE45} - c:\program files\McAfee\SiteAdvisor
FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - c:\documents and settings\All Users\Application Data\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c}
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-01-26 20:03
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(896)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
Completion time: 2011-01-26 20:06:46
ComboFix-quarantined-files.txt 2011-01-26 20:06
Pre-Run: 66,716,315,648 bytes free
Post-Run: 66,679,468,032 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect /forceresetreg
- - End Of File - - 1ED14220AC1ADDA90C6BD1949E4DC095