After following your instructions, I was able to get DDS to run and also ran ComboFix. Logs are pasted below. (I believe the infection occurred around April 4th - looking at the logs, the event logging shows only one week.)
Thanks for your help
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_31
Run by Me at 9:51:48 on 2012-04-21
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1447 [GMT -6:00]
.
.
============== Running Processes ===============
.
D:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
D:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
D:\WINDOWS\system32\spoolsv.exe
svchost.exe
D:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Bonjour\mDNSResponder.exe
d:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
D:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
D:\Program Files\Java\jre6\bin\jqs.exe
D:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
D:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
D:\WINDOWS\system32\svchost.exe -k imgsvc
D:\Program Files\PowerISO\PWRISOVM.EXE
D:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
D:\Program Files\iTunes\iTunesHelper.exe
D:\Program Files\Common Files\Java\Java Update\jusched.exe
D:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe
D:\Program Files\MSI\Common\RaUI.exe
D:\Program Files\Rainmeter\Rainmeter.exe
D:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
D:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
D:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
D:\Program Files\iPod\bin\iPodService.exe
D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
D:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe
D:\Program Files\Common Files\Apple\Mobile Device Support\SyncServer.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: SfcDisable=-99 (0xffffff9d)
BHO: ContributeBHO Class: {074c1dc5-9320-4a9a-947d-c042949c6216} - d:\program files\adobe\/Adobe Contribute CS3/contributeieplugin.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - d:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - d:\program files\java\jre6\bin\ssv.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - d:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - d:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
TB: Contribute Toolbar: {517bdde4-e3a7-4570-b21e-2b52b6139fc7} - d:\program files\adobe\/Adobe Contribute CS3/contributeieplugin.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
uRun: [ctfmon.exe] d:\windows\system32\ctfmon.exe
mRun: [Adobe ARM] "d:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [HDAudDeck] d:\program files\via\viaudioi\hdadeck\HDeck.exe 1
mRun: [PWRISOVM.EXE] d:\program files\poweriso\PWRISOVM.EXE
mRun: [Acrobat Assistant 8.0] "d:\program files\adobe\acrobat 8.0\acrobat\Acrotray.exe"
mRun: [<NO NAME>]
mRun: [Adobe_ID0EYTHM] d:\progra~1\common~1\adobe\adobev~1\server\bin\VERSIO~2.EXE
mRun: [APSDaemon] "d:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [iTunesHelper] "d:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "d:\program files\common files\java\java update\jusched.exe"
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [Malwarebytes' Anti-Malware] "d:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
StartupFolder: d:\docume~1\me\startm~1\programs\startup\openof~1.lnk - d:\program files\openoffice.org 3\program\quickstart.exe
StartupFolder: d:\docume~1\me\startm~1\programs\startup\rainme~1.lnk - d:\program files\rainmeter\Rainmeter.exe
StartupFolder: d:\docume~1\alluse~1\startm~1\programs\startup\autoca~1.lnk - d:\program files\common files\autodesk shared\acstart16.exe
StartupFolder: d:\docume~1\alluse~1\startm~1\programs\startup\hpaiod~1.lnk - d:\program files\hewlett-packard\aio\hp officejet 7100 series\bin\hpogrp07.exe
StartupFolder: d:\docume~1\alluse~1\startm~1\programs\startup\msiwir~1.lnk - d:\program files\msi\common\RaUI.exe
IE: Append to existing PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - d:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - d:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - d:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - d:\progra~1\micros~2\office12\REFIEBAR.DLL
LSP: mswsock.dll
Trusted Zone: intuit.com\ttlc
Trusted Zone: turbotax.com
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - d:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - d:\program files\windows desktop search\MSNLNamespaceMgr.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - d:\documents and settings\me\application data\mozilla\firefox\profiles\vugw0kov.default\
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&q=
FF - plugin: d:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: d:\program files\java\jre6\bin\plugin2\npdeployJava1.dll
FF - plugin: d:\program files\java\jre6\bin\plugin2\npjp2.dll
FF - plugin: d:\program files\microsoft silverlight\4.1.10111.0\npctrlui.dll
FF - plugin: d:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: d:\program files\mozilla firefox\plugins\npwachk.dll
FF - plugin: d:\windows\system32\macromed\flash\NPSWF32_11_2_202_228.dll
.
============= SERVICES / DRIVERS ===============
.
R2 MBAMService;MBAMService;d:\program files\malwarebytes' anti-malware\mbamservice.exe [2012-4-4 654408]
R2 nvUpdatusService;NVIDIA Update Service Daemon;d:\program files\nvidia corporation\nvidia update core\daemonu.exe [2012-1-6 2348864]
R3 MBAMProtector;MBAMProtector;d:\windows\system32\drivers\mbam.sys [2012-4-4 22344]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;d:\windows\system32\drivers\viahduaa.sys [2012-1-6 993280]
S2 webrootcommagentservice;Btserial;d:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;d:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-3 253600]
S3 cpudrv;cpudrv;d:\program files\systemrequirementslab\cpudrv.sys [2011-6-2 11336]
S3 WDC_SAM;WD SCSI Pass Thru driver;d:\windows\system32\drivers\wdcsam.sys [2012-3-15 11520]
.
=============== Created Last 30 ================
.
2012-04-21 06:08:15 148480 ------w- d:\windows\system32\dllcache\imagehlp.dll
2012-04-05 00:14:51 -------- d-----w- d:\documents and settings\me\application data\Malwarebytes
2012-04-05 00:14:37 -------- d-----w- d:\documents and settings\all users\application data\Malwarebytes
2012-04-05 00:14:36 22344 ----a-w- d:\windows\system32\drivers\mbam.sys
2012-04-05 00:14:36 -------- d-----w- d:\program files\Malwarebytes' Anti-Malware
2012-04-04 23:30:44 388096 ----a-r- d:\documents and settings\me\application data\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2012-04-04 04:17:15 0 --sha-w- d:\windows\system32\dds_trash_log.cmd
2012-04-04 02:51:37 73728 ----a-w- d:\windows\system32\javacpl.cpl
2012-04-04 02:51:37 476904 ----a-w- d:\program files\mozilla firefox\plugins\npdeployJava1.dll
2012-04-04 02:47:09 418464 ----a-w- d:\windows\system32\FlashPlayerApp.exe
2012-03-25 19:03:07 753664 ----a-w- d:\program files\common files\installshield\professional\runtime\11\00\intel32\iKernel.dll
2012-03-25 19:03:07 69714 ----a-w- d:\program files\common files\installshield\professional\runtime\11\00\intel32\ctor.dll
2012-03-25 19:03:07 5632 ----a-w- d:\program files\common files\installshield\professional\runtime\11\00\intel32\DotNetInstaller.exe
2012-03-25 19:03:07 274432 ----a-w- d:\program files\common files\installshield\professional\runtime\11\00\intel32\iscript.dll
2012-03-25 19:03:07 200836 ----a-w- d:\program files\common files\installshield\professional\runtime\11\00\intel32\iGdi.dll
2012-03-25 19:03:07 184320 ----a-w- d:\program files\common files\installshield\professional\runtime\11\00\intel32\iuser.dll
2012-03-25 19:03:06 331908 ----a-w- d:\program files\common files\installshield\professional\runtime\11\00\intel32\setup.dll
2012-03-25 17:08:39 -------- d-----w- d:\documents and settings\me\local settings\application data\IsolatedStorage
2012-03-23 03:36:19 733184 ----a-w- d:\program files\common files\installshield\professional\runtime\10\00\intel32\iKernel.dll
2012-03-23 03:36:19 69715 ----a-w- d:\program files\common files\installshield\professional\runtime\10\00\intel32\ctor.dll
2012-03-23 03:36:19 5632 ----a-w- d:\program files\common files\installshield\professional\runtime\10\00\intel32\DotNetInstaller.exe
2012-03-23 03:36:19 266240 ----a-w- d:\program files\common files\installshield\professional\runtime\10\00\intel32\iscript.dll
2012-03-23 03:36:19 172032 ----a-w- d:\program files\common files\installshield\professional\runtime\10\00\intel32\iuser.dll
2012-03-23 03:36:18 303236 ----a-w- d:\program files\common files\installshield\professional\runtime\10\00\intel32\setup.dll
2012-03-23 03:36:18 180356 ----a-w- d:\program files\common files\installshield\professional\runtime\10\00\intel32\iGdi.dll
2012-03-23 03:18:55 110592 ----a-w- d:\windows\system32\tsccvid.dll
.
==================== Find3M ====================
.
2012-04-04 04:38:23 70304 ----a-w- d:\windows\system32\FlashPlayerCPLApp.cpl
2012-04-04 02:51:27 472808 ----a-w- d:\windows\system32\deployJava1.dll
2012-03-16 03:39:59 28672 ----a-w- d:\windows\system32\qttask.exe
2012-03-01 11:01:32 916992 ----a-w- d:\windows\system32\wininet.dll
2012-03-01 11:01:32 43520 ----a-w- d:\windows\system32\licmgr10.dll
2012-03-01 11:01:32 1469440 ----a-w- d:\windows\system32\inetcpl.cpl
2012-02-29 14:08:49 178176 ----a-w- d:\windows\system32\wintrust.dll
2012-02-29 14:08:49 148480 ----a-w- d:\windows\system32\imagehlp.dll
2012-02-29 12:17:40 385024 ----a-w- d:\windows\system32\html.iec
2012-02-29 04:20:55 127 ----a-w- d:\windows\sophos.tmp
2012-02-15 17:01:50 4547944 ----a-w- d:\windows\system32\usbaaplrc.dll
2012-02-15 17:01:50 43520 ----a-w- d:\windows\system32\drivers\usbaapl.sys
2012-02-07 17:02:40 1070352 ----a-w- d:\windows\system32\MSCOMCTL.OCX
2012-02-03 09:26:17 1869184 ----a-w- d:\windows\system32\win32k.sys
.
============= FINISH: 9:52:15.18 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 12/6/2011 9:57:26 AM
System Uptime: 4/21/2012 9:38:46 AM (0 hours ago)
.
Motherboard: ASRock | | G41M-LE
Processor: Pentium(R) Dual-Core CPU E5200 @ 2.50GHz | CPUSocket | 2500/200mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 244 GiB total, 111.716 GiB free.
D: is FIXED (NTFS) - 73 GiB total, 3.662 GiB free.
E: is FIXED (NTFS) - 148 GiB total, 16.518 GiB free.
F: is CDROM ()
Q: is Removable
.
==== Disabled Device Manager Items =============
.
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: 802.11g PCI Turbo Wireless Adapter
Device ID: PCI\VEN_1814&DEV_0301&SUBSYS_B8341462&REV_00\4&CF81C54&0&08F0
Manufacturer: Ralink Technology, Inc.
Name: 802.11g PCI Turbo Wireless Adapter
PNP Device ID: PCI\VEN_1814&DEV_0301&SUBSYS_B8341462&REV_00\4&CF81C54&0&08F0
Service: RT61
.
==== System Restore Points ===================
.
RP178: 4/2/2012 10:42:48 PM - System Checkpoint
RP179: 4/3/2012 3:00:14 AM - Software Distribution Service 3.0
RP180: 4/3/2012 8:50:51 PM - Removed Java(TM) 6 Update 22
RP181: 4/3/2012 11:11:36 PM - Software Distribution Service 3.0
RP182: 4/4/2012 5:30:42 PM - Installed HiJackThis
RP183: 4/5/2012 3:00:45 AM - Software Distribution Service 3.0
RP184: 4/6/2012 3:00:14 AM - Software Distribution Service 3.0
RP185: 4/7/2012 3:00:14 AM - Software Distribution Service 3.0
RP186: 4/8/2012 3:00:13 AM - Software Distribution Service 3.0
RP187: 4/9/2012 3:00:14 AM - Software Distribution Service 3.0
RP188: 4/10/2012 3:00:15 AM - Software Distribution Service 3.0
RP189: 4/11/2012 3:00:14 AM - Software Distribution Service 3.0
RP190: 4/12/2012 3:00:14 AM - Software Distribution Service 3.0
RP191: 4/13/2012 3:00:15 AM - Software Distribution Service 3.0
RP192: 4/14/2012 3:00:14 AM - Software Distribution Service 3.0
RP193: 4/15/2012 3:00:14 AM - Software Distribution Service 3.0
RP194: 4/16/2012 3:00:15 AM - Software Distribution Service 3.0
RP195: 4/17/2012 3:00:21 AM - Software Distribution Service 3.0
RP196: 4/18/2012 3:00:14 AM - Software Distribution Service 3.0
RP197: 4/19/2012 3:00:14 AM - Software Distribution Service 3.0
RP198: 4/20/2012 3:00:16 AM - Software Distribution Service 3.0
RP199: 4/21/2012 1:12:12 AM - Software Distribution Service 3.0
.
==== Installed Programs ======================
.
.
%WS4_ARP_DISPLAY%
µTorrent
Add or Remove Adobe Creative Suite 3 Master Collection
Adobe Acrobat 8 Professional
Adobe After Effects CS3
Adobe After Effects CS3 Presets
Adobe AIR
Adobe Anchor Service CS3
Adobe Asset Services CS3
Adobe Bridge CS3
Adobe Bridge Start Meeting
Adobe BridgeTalk Plugin CS3
Adobe Camera Raw 4.0
Adobe CMaps
Adobe Color - Photoshop Specific
Adobe Color Common Settings
Adobe Color EU Extra Settings
Adobe Color JA Extra Settings
Adobe Color NA Recommended Settings
Adobe Contribute CS3
Adobe Creative Suite 3 Master Collection
Adobe Default Language CS3
Adobe Device Central CS3
Adobe Dreamweaver CS3
Adobe Encore CS3
Adobe Encore CS3 Codecs
Adobe ExtendScript Toolkit 2
Adobe Extension Manager CS3
Adobe Fireworks CS3
Adobe Flash CS3
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Flash Video Encoder
Adobe Fonts All
Adobe Help Viewer CS3
Adobe Illustrator CS3
Adobe InDesign CS3
Adobe InDesign CS3 Icon Handler
Adobe Linguistics CS3
Adobe MotionPicture Color Files
Adobe PDF Library Files
Adobe Photoshop CS3
Adobe Premiere Pro CS3
Adobe Premiere Pro CS3 Functional Content
Adobe Premiere Pro CS3 Third Party Content
Adobe Reader X (10.1.2)
Adobe Setup
Adobe SING CS3
Adobe Soundbooth CS3
Adobe Soundbooth CS3 Codecs
Adobe Stock Photos CS3
Adobe Type Support
Adobe Update Manager CS3
Adobe Version Cue CS3 Client
Adobe Version Cue CS3 Server
Adobe Video Profiles
Adobe WAS CS3
Adobe WinSoft Linguistics Plugin
Adobe XMP DVA Panels CS3
Adobe XMP Panels CS3
AHV content for Acrobat and Flash
AnswerWorks 4.0 Runtime - English
AnswerWorks 5.0 English Runtime
Apple Application Support
Apple Mobile Device Support
Apple Software Update
AutoCAD Architecture 2010
AutoCAD Architecture 2010 Language Pack - English
Autodesk Architectural Desktop 2005
Autodesk Design Review 2010
Autodesk DWF Viewer
Bonjour
DVDFab 7.0.9.2 (05/08/2010)
EVGA Precision 2.1.1
Higher Score on the SAT/PSAT
HiJackThis
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB2570791)
Hotfix for Windows XP (KB2633952)
Hotfix for Windows XP (KB954550-v5)
hp officejet 7100 series
iTunes
Java Auto Updater
Java(TM) 6 Update 31
Magic ISO Maker v5.4 (build 0251)
Malwarebytes Anti-Malware version 1.61.0.1400
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2656353)
Microsoft .NET Framework 1.1 Service Pack 1
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office File Validation Add-In
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional Plus 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft Software Update for Web Folders (English) 12
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Mozilla Firefox 11.0 (x86 en-US)
MSI Wireless LAN Card
MSXML 4.0 SP3 Parser
MSXML 4.0 SP3 Parser (KB973685)
NVIDIA Control Panel 290.53
NVIDIA Display Control Panel
NVIDIA Drivers
NVIDIA Graphics Driver 290.53
NVIDIA Install Application
NVIDIA nView 136.02
NVIDIA nView Desktop Manager
NVIDIA PhysX
NVIDIA PhysX System Software 9.11.1107
NVIDIA Update 1.6.24
NVIDIA Update Components
OpenOffice.org 3.3
PDF Settings
Platform
PowerISO
QuickTime
Rainmeter
REALTEK GbE & FE Ethernet PCI-E NIC Driver
Recover Keys
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)
Security Update for Microsoft Office 2007 suites (KB2596785) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition
Security Update for Microsoft Office 2007 suites (KB2598041) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition
Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition
Security Update for Microsoft Office Publisher 2007 (KB2596705) 32-Bit Edition
Security Update for Microsoft Windows (KB2564958)
Security Update for Windows Internet Explorer 8 (KB2510531)
Security Update for Windows Internet Explorer 8 (KB2544521)
Security Update for Windows Internet Explorer 8 (KB2586448)
Security Update for Windows Internet Explorer 8 (KB2618444)
Security Update for Windows Internet Explorer 8 (KB2647516)
Security Update for Windows Internet Explorer 8 (KB2675157)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Search 4 - KB963093
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2393802)
Security Update for Windows XP (KB2412687)
Security Update for Windows XP (KB2419632)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2443105)
Security Update for Windows XP (KB2476490)
Security Update for Windows XP (KB2478960)
Security Update for Windows XP (KB2478971)
Security Update for Windows XP (KB2479943)
Security Update for Windows XP (KB2483185)
Security Update for Windows XP (KB2485663)
Security Update for Windows XP (KB2506212)
Security Update for Windows XP (KB2507618)
Security Update for Windows XP (KB2507938)
Security Update for Windows XP (KB2508272)
Security Update for Windows XP (KB2508429)
Security Update for Windows XP (KB2509553)
Security Update for Windows XP (KB2535512)
Security Update for Windows XP (KB2536276-v2)
Security Update for Windows XP (KB2544893-v2)
Security Update for Windows XP (KB2562937)
Security Update for Windows XP (KB2566454)
Security Update for Windows XP (KB2567053)
Security Update for Windows XP (KB2567680)
Security Update for Windows XP (KB2570222)
Security Update for Windows XP (KB2570947)
Security Update for Windows XP (KB2584146)
Security Update for Windows XP (KB2585542)
Security Update for Windows XP (KB2592799)
Security Update for Windows XP (KB2598479)
Security Update for Windows XP (KB2603381)
Security Update for Windows XP (KB2618451)
Security Update for Windows XP (KB2619339)
Security Update for Windows XP (KB2620712)
Security Update for Windows XP (KB2621440)
Security Update for Windows XP (KB2624667)
Security Update for Windows XP (KB2631813)
Security Update for Windows XP (KB2633171)
Security Update for Windows XP (KB2639417)
Security Update for Windows XP (KB2641653)
Security Update for Windows XP (KB2646524)
Security Update for Windows XP (KB2647518)
Security Update for Windows XP (KB2653956)
Security Update for Windows XP (KB2660465)
Security Update for Windows XP (KB2661637)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982665)
SES Driver
SpeedyPC
System Requirements Lab for Intel
TurboTax 2008
TurboTax 2008 WinPerFedFormset
TurboTax 2008 WinPerProgramHelp
TurboTax 2008 WinPerReleaseEngine
TurboTax 2008 WinPerTaxSupport
TurboTax 2008 WinPerUserEducation
TurboTax 2008 wnmiper
TurboTax 2008 wrapper
TurboTax 2009
TurboTax 2009 WinPerFedFormset
TurboTax 2009 WinPerReleaseEngine
TurboTax 2009 WinPerTaxSupport
TurboTax 2009 wnmiper
TurboTax 2009 wrapper
TurboTax 2010
TurboTax 2010 WinPerFedFormset
TurboTax 2010 WinPerReleaseEngine
TurboTax 2010 WinPerTaxSupport
TurboTax 2010 wnmiper
TurboTax 2010 wrapper
TurboTax Deluxe 2007
TurboTax Deluxe Deduction Maximizer 2006
TurboTax Home & Business 2006
TurboTax ItsDeductible 2006
TurboTax Premier 2004
TurboTax Premier 2005
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 suites (KB2596651) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596789) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2598306) 32-Bit Edition
Update for Microsoft Office Excel 2007 (KB2596596) 32-Bit Edition
Update for Windows XP (KB2345886)
Update for Windows XP (KB2541763)
Update for Windows XP (KB2641690)
Update for Windows XP (KB955759)
Update for Windows XP (KB968389)
Update for Windows XP (KB971029)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
VIA Platform Device Manager
VLC media player 1.1.11
WebFldrs XP
WexTech AnswerWorks
Winamp
Winamp Detector Plug-in
Windows Rights Management Client Backwards Compatibility SP2
Windows Rights Management Client with Service Pack 2
WinRAR 4.01 (32-bit)
.
==== Event Viewer Messages From Past Week ========
.
4/19/2012 4:56:29 AM, error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume C:.
4/18/2012 12:33:30 PM, error: Service Control Manager [7023] - The Network Location Awareness (NLA) service terminated with the following error: The specified procedure could not be found.
4/18/2012 10:31:46 AM, error: Service Control Manager [7023] - The Btserial service terminated with the following error: Access is denied.
4/18/2012 10:31:35 AM, error: Service Control Manager [7023] - The Sp_clamsrv service terminated with the following error: Access is denied.
4/18/2012 10:31:35 AM, error: Service Control Manager [7023] - The Pdlnecfg service terminated with the following error: The specified module could not be found.
4/18/2012 10:31:35 AM, error: Service Control Manager [7023] - The Mksvirmonsvc service terminated with the following error: The specified module could not be found.
4/18/2012 10:31:35 AM, error: Service Control Manager [7023] - The GoProto service terminated with the following error: The specified module could not be found.
4/18/2012 10:29:48 AM, error: dmboot [3] - dmboot: Failed to start volume Volume4 (N

4/17/2012 3:01:15 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x8007f0f4: Security Update for Windows XP (KB2481109).
.
==== End Of File ===========================
ComboFix 12-04-20.03 - Me 04/21/2012 10:24:06.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1677 [GMT -6:00]
Running from: d:\documents and settings\Me\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
d:\documents and settings\Me\Application Data\inst.exe
D:\setup.exe
d:\windows\$NtUninstallKB14012$
d:\windows\$NtUninstallKB14012$\1514368255\@
d:\windows\$NtUninstallKB14012$\1514368255\cfg.ini
d:\windows\$NtUninstallKB14012$\1514368255\Desktop.ini
d:\windows\$NtUninstallKB14012$\1514368255\L\syjvwjii
d:\windows\$NtUninstallKB14012$\1514368255\oemid
d:\windows\$NtUninstallKB14012$\1514368255\U\00000001.@
d:\windows\$NtUninstallKB14012$\1514368255\U\00000002.@
d:\windows\$NtUninstallKB14012$\1514368255\U\00000004.@
d:\windows\$NtUninstallKB14012$\1514368255\U\80000000.@
d:\windows\$NtUninstallKB14012$\1514368255\U\80000004.@
d:\windows\$NtUninstallKB14012$\1514368255\U\80000032.@
d:\windows\$NtUninstallKB14012$\1514368255\version
d:\windows\$NtUninstallKB14012$\4175661304
d:\windows\dasetup.log
d:\windows\system\VB40032.DLL
d:\windows\system32\dds_trash_log.cmd
.
.
((((((((((((((((((((((((( Files Created from 2012-03-21 to 2012-04-21 )))))))))))))))))))))))))))))))
.
.
2012-04-21 16:33 . 2012-04-21 16:33 -------- d-----w- d:\windows\system32\wbem\snmp
2012-04-21 16:33 . 2012-04-21 16:33 -------- d-----w- d:\windows\system32\xircom
2012-04-21 16:33 . 2012-04-21 16:33 -------- d-----w- d:\program files\microsoft frontpage
2012-04-21 06:08 . 2012-02-29 14:08 148480 ------w- d:\windows\system32\dllcache\imagehlp.dll
2012-04-13 16:28 . 2012-04-13 16:28 -------- d-----w- d:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2012-04-05 00:14 . 2012-04-05 00:14 -------- d-----w- d:\documents and settings\Me\Application Data\Malwarebytes
2012-04-05 00:14 . 2012-04-05 00:14 -------- d-----w- d:\documents and settings\All Users\Application Data\Malwarebytes
2012-04-05 00:14 . 2012-04-21 06:03 -------- d-----w- d:\program files\Malwarebytes' Anti-Malware
2012-04-05 00:14 . 2012-04-04 21:56 22344 ----a-w- d:\windows\system32\drivers\mbam.sys
2012-04-05 00:08 . 2012-04-05 00:08 -------- d-----w- d:\documents and settings\Administrator
2012-04-04 23:30 . 2012-04-04 23:30 388096 ----a-r- d:\documents and settings\Me\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-04-04 04:37 . 2012-04-04 04:37 -------- d-sh--w- d:\documents and settings\NetworkService\PrivacIE
2012-04-04 02:53 . 2012-04-04 02:53 -------- d-----w- d:\program files\Common Files\Java
2012-04-04 02:51 . 2012-04-04 02:51 73728 ----a-w- d:\windows\system32\javacpl.cpl
2012-04-04 02:51 . 2012-04-04 02:51 476904 ----a-w- d:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
2012-04-04 02:47 . 2012-04-04 04:38 418464 ----a-w- d:\windows\system32\FlashPlayerApp.exe
2012-03-25 19:03 . 2012-03-25 19:03 200836 ----a-w- d:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iGdi.dll
2012-03-25 19:03 . 2005-04-04 05:02 753664 ----a-w- d:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iKernel.dll
2012-03-25 19:03 . 2005-04-04 05:02 69714 ----a-w- d:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\ctor.dll
2012-03-25 19:03 . 2005-04-04 05:01 274432 ----a-w- d:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iscript.dll
2012-03-25 19:03 . 2005-04-04 05:00 184320 ----a-w- d:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iuser.dll
2012-03-25 19:03 . 2005-04-04 04:59 5632 ----a-w- d:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\DotNetInstaller.exe
2012-03-25 19:03 . 2012-03-25 19:03 331908 ----a-w- d:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\setup.dll
2012-03-25 17:24 . 2012-03-25 17:24 -------- d-----w- d:\documents and settings\LocalService\Local Settings\Application Data\IsolatedStorage
2012-03-25 17:08 . 2012-03-25 17:08 -------- d-----w- d:\documents and settings\Me\Local Settings\Application Data\IsolatedStorage
2012-03-23 03:36 . 2004-04-19 05:42 733184 ----a-w- d:\program files\Common Files\InstallShield\Professional\RunTime\10\00\Intel32\iKernel.dll
2012-03-23 03:36 . 2004-04-19 05:40 69715 ----a-w- d:\program files\Common Files\InstallShield\Professional\RunTime\10\00\Intel32\ctor.dll
2012-03-23 03:36 . 2004-04-19 05:39 266240 ----a-w- d:\program files\Common Files\InstallShield\Professional\RunTime\10\00\Intel32\iscript.dll
2012-03-23 03:36 . 2004-04-19 05:39 172032 ----a-w- d:\program files\Common Files\InstallShield\Professional\RunTime\10\00\Intel32\iuser.dll
2012-03-23 03:36 . 2004-04-19 05:39 5632 ----a-w- d:\program files\Common Files\InstallShield\Professional\RunTime\10\00\Intel32\DotNetInstaller.exe
2012-03-23 03:36 . 2012-03-23 03:36 303236 ----a-w- d:\program files\Common Files\InstallShield\Professional\RunTime\10\00\Intel32\setup.dll
2012-03-23 03:36 . 2012-03-23 03:36 180356 ----a-w- d:\program files\Common Files\InstallShield\Professional\RunTime\10\00\Intel32\iGdi.dll
2012-03-23 03:18 . 2003-04-16 07:10 110592 ----a-w- d:\windows\system32\tsccvid.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-04 04:38 . 2011-12-06 18:25 70304 ----a-w- d:\windows\system32\FlashPlayerCPLApp.cpl
2012-04-04 02:51 . 2011-12-17 07:55 472808 ----a-w- d:\windows\system32\deployJava1.dll
2012-03-20 23:33 . 2012-03-20 23:33 40960 ----a-r- d:\documents and settings\Me\Application Data\Microsoft\Installer\{AFF1EA96-9C23-4249-B7D4-CD4B54D4582F}\NewShortcut3_2E7595EC4FB14E2993D49083C8A9B107.exe
2012-03-16 03:39 . 2012-03-16 03:39 28672 ----a-w- d:\windows\system32\qttask.exe
2012-03-01 11:01 . 2009-03-08 02:34 916992 ----a-w- d:\windows\system32\wininet.dll
2012-03-01 11:01 . 2009-03-08 02:34 1469440 ----a-w- d:\windows\system32\inetcpl.cpl
2012-03-01 11:01 . 2009-03-08 02:34 43520 ----a-w- d:\windows\system32\licmgr10.dll
2012-02-29 14:08 . 2008-11-13 13:18 178176 ----a-w- d:\windows\system32\wintrust.dll
2012-02-29 14:08 . 2008-04-14 11:00 148480 ----a-w- d:\windows\system32\imagehlp.dll
2012-02-29 12:17 . 2009-03-08 02:35 385024 ----a-w- d:\windows\system32\html.iec
2012-02-29 04:20 . 2012-02-29 04:20 127 ----a-w- d:\windows\sophos.tmp
2012-02-15 17:01 . 2012-03-15 22:36 4547944 ----a-w- d:\windows\system32\usbaaplrc.dll
2012-02-15 17:01 . 2012-03-15 22:36 43520 ----a-w- d:\windows\system32\drivers\usbaapl.sys
2012-02-07 17:02 . 2012-02-07 17:02 1070352 ----a-w- d:\windows\system32\MSCOMCTL.OCX
2012-02-03 09:26 . 2009-02-09 10:08 1869184 ----a-w- d:\windows\system32\win32k.sys
2012-03-18 05:21 . 2011-12-06 18:11 97208 ----a-w- d:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2009-03-26 . 25A740D70E8007814A48D3FA1B34FA34 . 361600 . . [5.1.2600.5649] . . d:\windows\system32\drivers\tcpip.sys
[7] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . d:\windows\system32\dllcache\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="d:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"HDAudDeck"="d:\program files\VIA\VIAudioi\HDADeck\HDeck.exe" [2009-01-09 33570816]
"PWRISOVM.EXE"="d:\program files\PowerISO\PWRISOVM.EXE" [2009-03-15 180224]
"Acrobat Assistant 8.0"="d:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2007-05-11 624248]
"APSDaemon"="d:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"iTunesHelper"="d:\program files\iTunes\iTunesHelper.exe" [2012-03-07 421736]
"SunJavaUpdateSched"="d:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"Malwarebytes' Anti-Malware"="d:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]
.
d:\documents and settings\Me\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - d:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
Rainmeter.lnk - d:\program files\Rainmeter\Rainmeter.exe [2012-1-8 105160]
.
d:\documents and settings\All Users\Start Menu\Programs\Startup\
AutoCAD Startup Accelerator.lnk - d:\program files\Common Files\Autodesk Shared\acstart16.exe [2004-2-25 10872]
HPAiODevice(hp officejet 7100 series) - 1.lnk - d:\program files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe [2003-6-25 495682]
MSI Wireless Utility.lnk - d:\program files\MSI\Common\RaUI.exe [2011-12-6 425984]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "d:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0d:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\NVIDIA Corporation\\NVIDIA Update Core\\daemonu.exe"=
"d:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"d:\\Program Files\\uTorrent\\uTorrent.exe"=
"d:\\Documents and Settings\\Me\\My Documents\\Downloads\\utorrent.exe"=
"d:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"d:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"d:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\Program Files\\iTunes\\iTunes.exe"=
"d:\\Program Files\\Mozilla Firefox\\firefox.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server
.
R2 MBAMService;MBAMService;d:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [4/4/2012 6:14 PM 654408]
R2 nvUpdatusService;NVIDIA Update Service Daemon;d:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [1/6/2012 8:56 AM 2348864]
R3 MBAMProtector;MBAMProtector;d:\windows\system32\drivers\mbam.sys [4/4/2012 6:14 PM 22344]
R3 pcouffin;VSO Software pcouffin;d:\windows\system32\drivers\pcouffin.sys [1/8/2012 11:23 AM 47360]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;d:\windows\system32\drivers\viahduaa.sys [1/6/2012 12:28 PM 993280]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;d:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [4/3/2012 8:47 PM 253600]
S3 cpudrv;cpudrv;d:\program files\SystemRequirementsLab\cpudrv.sys [6/2/2011 11:08 AM 11336]
S3 WDC_SAM;WD SCSI Pass Thru driver;d:\windows\system32\drivers\wdcsam.sys [3/15/2012 4:38 PM 11520]
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
lvusbsta
ctljystk
HssSrv
se2Dnd5
cltnetcnservice
nimxdfk
F700imd
dvpapi
pgsql-8.0
us30sys
QPSched
dlbu_device
dcpflics
webrootcommagentservice
tavsvc
firelm01
MTC0001_ESB
IntelC51
vaiomediaplatform-videoserver-appserver
SE27obex
se59obex
winpppoverethernet
quickbooksdb
agnwifi
viagfx
oracleorahome811cman
awecho
regmon701
Si3114r5
gearsecurity
icm10blk
ntsyslog
.
Contents of the 'Scheduled Tasks' folder
.
2012-04-21 d:\windows\Tasks\Adobe Flash Player Updater.job
- d:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-04 04:38]
.
2012-04-20 d:\windows\Tasks\AppleSoftwareUpdate.job
- d:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 23:57]
.
2012-04-20 d:\windows\Tasks\SpeedyPC Program Check.job
- d:\program files\SpeedyPC\SpeedyPC.exe [2010-05-19 23:10]
.
2012-04-19 d:\windows\Tasks\SpeedyPC.job
- d:\program files\SpeedyPC\SpeedyPC.exe [2010-05-19 23:10]
.
.
------- Supplementary Scan -------
.
IE: Append to existing PDF - d:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - d:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - d:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - d:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - d:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - d:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - d:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - d:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - d:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: intuit.com\ttlc
Trusted Zone: turbotax.com
FF - ProfilePath - d:\documents and settings\Me\Application Data\Mozilla\Firefox\Profiles\vugw0kov.default\
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2786678&q=
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-04-21 10:34
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HDAudDeck = d:\program files\VIA\VIAudioi\HDADeck\HDeck.exe 1????????????????????????????????????????????????
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,2c,8e,e0,a8,30,b5,77,42,a1,fd,32,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,2c,8e,e0,a8,30,b5,77,42,a1,fd,32,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(4008)
d:\windows\system32\WININET.dll
d:\windows\system32\msi.dll
d:\windows\system32\ieframe.dll
d:\windows\system32\webcheck.dll
d:\windows\system32\WPDShServiceObj.dll
d:\windows\system32\PortableDeviceTypes.dll
d:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
d:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
d:\program files\Bonjour\mDNSResponder.exe
d:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
d:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
d:\program files\Java\jre6\bin\jqs.exe
d:\program files\OpenOffice.org 3\program\soffice.exe
d:\windows\system32\wscntfy.exe
d:\program files\OpenOffice.org 3\program\soffice.bin
d:\program files\iPod\bin\iPodService.exe
d:\progra~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
d:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
d:\program files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
d:\program files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
.
**************************************************************************
.
Completion time: 2012-04-21 10:38:52 - machine was rebooted
ComboFix-quarantined-files.txt 2012-04-21 16:38
.
Pre-Run: 3,792,707,584 bytes free
Post-Run: 4,777,283,584 bytes free
.
- - End Of File - - 731CEFD1711A401CA2F78354ADAF7337