I completed Step 1.
For Step 2, when I try to click the link to download OTL onto my desktop, the link says that "File Not Found", so I'm stuck there. What should I do?
Step 3 is completed.
Here are the scan results for Step 1: ComboFix 09-07-13.01 - Jaime 07/15/2009 16:58.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1699 [GMT -5:00]
Running from: c:\documents and settings\Jaime\Desktop\Combo-Fix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\kb913800.exe
c:\windows\system32\drivers\SKYNETjejtydey.sys
c:\windows\system32\mfc45.dll
c:\windows\system32\SKYNETbfoqlxet.dll
c:\windows\system32\SKYNETdgmmjgwy.dat
c:\windows\system32\SKYNETfsodemqs.dll
c:\windows\system32\SKYNETonrevyuu.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_SKYNETaicrmsoi
-------\Service_SKYNETaicrmsoi
((((((((((((((((((((((((( Files Created from 2009-06-15 to 2009-07-15 )))))))))))))))))))))))))))))))
.
2009-07-14 21:03 . 2009-07-14 21:08 -------- d-----w- c:\documents and settings\Jaime\Incomplete
2009-07-14 04:26 . 2009-07-15 22:06 117760 ----a-w- c:\documents and settings\Jaime\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-07-14 04:25 . 2009-07-14 04:25 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-07-14 04:24 . 2009-07-14 04:24 65024 ----a-r- c:\documents and settings\Jaime\Application Data\Microsoft\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
2009-07-14 04:24 . 2009-07-14 04:24 18944 ----a-r- c:\documents and settings\Jaime\Application Data\Microsoft\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
2009-07-14 04:24 . 2009-07-14 04:24 -------- d-----w- c:\program files\SUPERAntiSpyware
2009-07-14 04:24 . 2009-07-14 04:24 -------- d-----w- c:\documents and settings\Jaime\Application Data\SUPERAntiSpyware.com
2009-07-13 23:43 . 2009-07-13 23:43 -------- d-----w- c:\documents and settings\Jaime\Application Data\Malwarebytes
2009-07-13 23:43 . 2009-07-13 18:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-13 23:43 . 2009-07-13 23:43 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-13 23:43 . 2009-07-13 23:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-13 23:43 . 2009-07-13 18:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-13 23:26 . 2009-07-13 23:26 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-07-12 21:27 . 2009-07-12 21:27 61224 ----a-w- c:\documents and settings\Jaime\GoToAssistDownloadHelper.exe
2009-07-10 21:35 . 2009-07-10 21:35 552 ----a-w- c:\windows\system32\d3d8caps.dat
2009-07-08 20:20 . 2007-10-23 14:27 110592 ----a-w- c:\documents and settings\Jaime\Application Data\U3\temp\cleanup.exe
2009-07-08 19:04 . 2008-05-02 15:41 3493888 ---ha-w- c:\documents and settings\Jaime\Application Data\U3\temp\Launchpad Removal.exe
2009-07-08 19:04 . 2009-07-08 20:20 -------- d-----w- c:\documents and settings\Jaime\Application Data\U3
2009-06-27 23:15 . 2009-06-27 23:15 49152 ----a-r- c:\documents and settings\Jaime\Application Data\Microsoft\Installer\{FCC07EEA-FA18-4A21-9105-9666603C6885}\IconFCC07EEA1.exe
2009-06-27 23:15 . 2009-06-27 23:15 49152 ----a-r- c:\documents and settings\Jaime\Application Data\Microsoft\Installer\{FCC07EEA-FA18-4A21-9105-9666603C6885}\IconFCC07EEA.exe
2009-06-27 18:41 . 2009-06-27 18:41 -------- d-----w- c:\windows\system32\XPSViewer
2009-06-27 18:41 . 2009-06-27 18:41 -------- d-----w- c:\program files\MSBuild
2009-06-27 18:41 . 2009-06-27 18:41 -------- d-----w- c:\program files\Reference Assemblies
2009-06-27 18:41 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-06-27 18:41 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-06-27 18:41 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-06-27 18:41 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-06-27 18:41 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-06-27 18:41 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2009-06-27 18:41 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-06-27 18:41 . 2009-06-27 18:41 -------- d-----w- C:\1c1eb82dd82a04c467d64d45f1
2009-06-22 05:38 . 2009-06-22 05:38 -------- d-----w- c:\windows\system32\vmm32
2009-06-20 09:15 . 2009-06-20 09:15 518 ----a-w- c:\documents and settings\Jaime\Application Data\iolo\Registry\Last\restore.bat
2009-06-20 09:15 . 2009-06-20 09:15 1479 ----a-w- c:\documents and settings\Jaime\Application Data\iolo\restore.bat
2009-06-20 06:50 . 2009-06-20 06:50 -------- d-----w- c:\documents and settings\LocalService\Application Data\iolo
2009-06-20 06:50 . 2009-04-27 20:47 933208 ----a-w- c:\windows\system32\Incinerator.dll
2009-06-20 06:50 . 2009-03-09 21:04 8192 ----a-w- c:\windows\system32\smrgdf.exe
2009-06-20 06:50 . 2009-03-09 21:04 28672 ----a-w- c:\windows\system32\iolobtdfg.exe
2009-06-20 06:50 . 2009-06-20 06:50 -------- d-----w- c:\program files\iolo
2009-06-20 06:48 . 2009-04-28 16:22 16430856 ----a-w- c:\documents and settings\Jaime\Application Data\iolo\Installers\PCTuneUp2.exe
2009-06-20 06:41 . 2009-06-20 08:49 -------- d-----w- c:\documents and settings\Jaime\Application Data\iolo
2009-06-20 06:41 . 2009-06-20 08:49 -------- d-----w- c:\documents and settings\All Users\Application Data\iolo
2009-06-16 14:36 . 2009-06-16 14:36 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2009-06-16 14:36 . 2009-06-16 14:36 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-15 22:03 . 2008-10-25 05:19 -------- d-----w- c:\program files\DNA
2009-07-15 22:03 . 2008-10-25 05:19 -------- d-----w- c:\documents and settings\Jaime\Application Data\DNA
2009-07-15 08:06 . 2009-01-30 01:35 -------- d-----w- c:\documents and settings\Jaime\Application Data\FrostWire
2009-07-14 21:58 . 2008-05-22 06:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-07-14 21:10 . 2008-10-25 05:17 -------- d-----w- c:\documents and settings\Jaime\Application Data\BitTorrent
2009-07-14 21:06 . 2008-07-03 00:31 -------- d-----w- c:\program files\Java
2009-07-14 21:04 . 2008-07-03 00:34 -------- d-----w- c:\documents and settings\Jaime\Application Data\LimeWire
2009-07-13 23:30 . 2008-12-31 07:23 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2009-07-09 17:01 . 2008-09-11 21:50 56 --sh--r- c:\windows\system32\80EAD07259.sys
2009-07-09 17:01 . 2008-09-11 21:50 1682 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-06-29 18:55 . 2008-06-17 20:51 34760 ----a-w- c:\documents and settings\Jaime\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-27 23:15 . 2008-04-21 18:25 -------- d-----w- c:\program files\McAfee
2009-06-27 03:50 . 2008-04-20 17:44 -------- d-----w- c:\program files\Dell
2009-06-16 14:36 . 2004-08-10 11:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2004-08-10 11:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-12 23:16 . 2009-06-12 23:16 152576 ----a-w- c:\documents and settings\Jaime\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-06-03 19:09 . 2004-08-10 11:00 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-05-22 07:09 . 2009-05-22 07:09 -------- d-----w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-22 07:09 . 2009-05-22 07:09 -------- d-----w- c:\program files\iTunes
2009-05-22 07:09 . 2009-05-22 07:09 -------- d-----w- c:\program files\iPod
2009-05-22 07:09 . 2008-04-21 23:54 -------- d-----w- c:\program files\Common Files\Apple
2009-05-22 07:07 . 2009-05-22 07:07 -------- d-----w- c:\program files\Bonjour
2009-05-22 07:06 . 2009-05-22 07:06 -------- d-----w- c:\program files\QuickTime
2009-05-22 07:03 . 2009-05-22 07:03 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
2009-05-22 07:02 . 2008-12-18 19:57 -------- d-----w- c:\program files\Safari
2009-05-21 16:33 . 2008-12-10 19:56 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-05-21 02:47 . 2009-05-21 02:47 -------- d-----w- c:\program files\Digital Line Detect
2009-05-21 02:47 . 2008-04-20 19:42 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-18 00:08 . 2009-05-16 21:08 3344 ----a-w- c:\windows\system32\drivers\sthdae.log
2009-05-17 21:44 . 2008-04-20 19:58 -------- d-----w- c:\program files\Creative
2009-05-17 01:30 . 2008-04-20 20:03 -------- d-----w- c:\documents and settings\Jaime\Application Data\Creative
2009-05-17 01:04 . 2009-05-17 01:04 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2009-05-13 05:15 . 2006-03-04 03:33 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-12 21:08 . 2008-08-18 05:33 266400 ----a-r- c:\documents and settings\Jaime\Application Data\McAfee\Supportability\MVTLogs\Results\detect.dll
2009-05-07 15:32 . 2004-08-10 11:00 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-01 05:31 . 2009-05-01 05:31 1657376 ----a-w- c:\windows\system32\nwiz.exe
2009-05-01 05:31 . 2009-05-01 05:31 449056 ----a-w- c:\windows\system32\nvappbar.exe
2009-05-01 05:31 . 2009-05-01 05:31 436768 ----a-w- c:\windows\system32\keystone.exe
2009-05-01 05:31 . 2009-05-01 05:31 466944 ----a-w- c:\windows\system32\nvshell.dll
2009-05-01 05:31 . 2009-05-01 05:31 1724416 ----a-w- c:\windows\system32\nvwdmcpl.dll
2009-05-01 05:31 . 2009-05-01 05:31 1507328 ----a-w- c:\windows\system32\nview.dll
2009-05-01 05:31 . 2009-05-01 05:31 1101824 ----a-w- c:\windows\system32\nvwimg.dll
2009-05-01 03:02 . 2009-05-01 03:02 806912 ----a-w- c:\windows\system32\nvapi.dll
2009-05-01 03:02 . 2009-05-01 03:02 663552 ----a-w- c:\windows\system32\nvcuvid.dll
2009-05-01 03:02 . 2009-05-01 03:02 1720320 ----a-w- c:\windows\system32\nvcuda.dll
2009-05-01 03:02 . 2009-05-01 03:02 1579630 ----a-w- c:\windows\system32\nvdata.bin
2009-05-01 03:02 . 2009-05-01 03:02 1314816 ----a-w- c:\windows\system32\nvcuvenc.dll
2009-05-01 03:02 . 2008-04-20 19:41 457248 ----a-w- c:\windows\system32\nvudisp.exe
2009-05-01 03:02 . 2008-04-20 19:40 9994240 ----a-w- c:\windows\system32\nvoglnt.dll
2009-05-01 03:02 . 2008-04-20 19:40 143360 ----a-w- c:\windows\system32\nvcodins.dll
2009-05-01 03:02 . 2008-04-20 19:40 143360 ----a-w- c:\windows\system32\nvcod.dll
2009-05-01 03:02 . 2008-04-20 19:40 8055584 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2009-05-01 03:02 . 2008-04-20 19:40 5896320 ----a-w- c:\windows\system32\nv4_disp.dll
2009-04-27 08:14 . 2009-04-27 08:14 5856 --sh--w- c:\windows\system32\rigiwoti.exe
2009-04-27 05:42 . 2009-05-13 23:17 457248 ----a-w- c:\windows\system32\NVUNINST.EXE
2009-04-17 12:26 . 2004-08-10 11:00 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-06-13 01:05 . 2008-09-12 06:51 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-07-15_21.28.08 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-15 22:03 . 2009-07-15 22:03 16384 c:\windows\Temp\Perflib_Perfdata_7f0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-09-09 04:08 279944 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-09-09 279944]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-09-09 279944]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-12-23 143360]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2008-12-16 342848]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-06-23 1830128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"AudioDrvEmulator"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-11-04 49152]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-16 81920]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-02 582992]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-05-01 13750272]
"CTDVDDET"="c:\program files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE" [2003-06-18 45056]
"VolPanel"="c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" [2005-10-14 122880]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-05-01 1657376]
"CTHelper"="CTHELPER.EXE" - c:\windows\system32\CtHelper.exe [2006-12-12 19456]
"CTxfiHlp"="CTXFIHLP.EXE" - c:\windows\system32\CTXFIHLP.EXE [2005-11-08 18944]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2009-5-20 24576]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 17:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn ]
2008-04-14 00:12 92672 ----a-w- c:\windows\system32\wlnotify.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mfehidk.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mferkdk.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\nexon\Combat Arms\CombatArms.exe"= c:\nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"c:\nexon\Combat Arms\Engine.exe"= c:\nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
"c:\\Nexon\\Combat Arms\\NMService.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\McAfee\\VirusScan\\mcods.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [6/23/2009 11:01 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [6/23/2009 11:01 AM 72944]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [6/23/2009 11:01 AM 7408]
S3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\system32\drivers\CT20XUT.sys [10/8/2008 1:21 AM 171032]
S3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.sys [10/8/2008 1:21 AM 171032]
S3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\system32\drivers\CTEXFIFX.sys [10/8/2008 1:21 AM 1324056]
S3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.sys [10/8/2008 1:21 AM 1324056]
S3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\system32\drivers\CTHWIUT.sys [10/8/2008 1:21 AM 72728]
S3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.sys [10/8/2008 1:21 AM 72728]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-07-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2009-07-15 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-05-22 05:09]
2009-07-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2008-04-21 18:32]
2009-07-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2008-04-21 18:32]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.comcast.net/
uInternet Settings,ProxyOverride = *.local
Trusted Zone: internet
Trusted Zone: mcafee.com
FF - ProfilePath - c:\documents and settings\Jaime\Application Data\Mozilla\Firefox\Profiles\0bakc5pi.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - hxxp://yahoo.com/
FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
.
.
------- File Associations -------
.
JSEFile=NOTEPAD.EXE %1
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-07-15 17:06
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(736)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
- - - - - - - > 'explorer.exe'(3820)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\CTSVCCDA.EXE
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\CTXFISPI.EXE
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\windows\system32\dllhost.exe
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
c:\windows\ehome\ehmsas.exe
.
**************************************************************************
.
Completion time: 2009-07-15 17:08 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-15 22:08
ComboFix2.txt 2009-07-15 21:34
Pre-Run: 446,119,624,704 bytes free
Post-Run: 446,084,075,520 bytes free
300 --- E O F --- 2009-07-15 08:01
Here are the results for step 3: --------------------\\ Lop S&D 4.2.5-0 XP/Vista
"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( Wed 07/15/2009|17:31 )
--------------------\\ Listing folders in APPLIC~1
[05/22/2009|02:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> {8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[06/24/2008|03:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Adobe
[04/21/2008|06:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Apple
[04/21/2008|06:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Apple Computer
[04/20/2008|02:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Citrix
[04/21/2008|07:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> CopyTransControlCenter
[05/10/2009|04:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Creative
[04/20/2008|02:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> DIGStream
[07/19/2008|04:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Google
[07/14/2009|04:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Google Updater
[05/07/2008|05:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> InstallShield
[06/20/2009|03:49] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> iolo
[06/17/2008|03:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> LightScribe
[07/13/2009|06:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Malwarebytes
[08/18/2008|12:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> McAfee
[05/25/2008|01:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Microsoft
[05/05/2008|06:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Nero
[08/21/2008|01:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> NexonUS
[05/16/2009|08:04] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> PC Drivers HeadQuarters
[04/23/2008|03:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Sonic
[07/13/2009|11:25] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> SUPERAntiSpyware.com
[04/19/2009|03:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> TEMP
[04/02/2009|03:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> WildTangent
[04/23/2008|02:53] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Windows Genuine Advantage
[08/07/2008|03:36] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Macromedia
[04/20/2008|02:26] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Microsoft
[07/22/2008|06:44] C:\DOCUME~1\Guest\APPLIC~1\<DIR> Adobe
[05/05/2008|06:51] C:\DOCUME~1\Guest\APPLIC~1\<DIR> Apple Computer
[05/05/2008|06:49] C:\DOCUME~1\Guest\APPLIC~1\<DIR> Identities
[07/22/2008|06:44] C:\DOCUME~1\Guest\APPLIC~1\<DIR> Macromedia
[05/05/2008|06:48] C:\DOCUME~1\Guest\APPLIC~1\<DIR> Microsoft
[09/23/2008|06:42] C:\DOCUME~1\Guest\APPLIC~1\<DIR> Mozilla
[08/05/2008|05:55] C:\DOCUME~1\Guest\APPLIC~1\<DIR> Sun
[04/25/2009|11:57] C:\DOCUME~1\Jaime\APPLIC~1\<DIR> Adobe
[04/26/2009|12:09] C:\DOCUME~1\Jaime\APPLIC~1\<DIR> Ahead
[05/04/2009|06:01] C:\DOCUME~1\Jaime\APPLIC~1\<DIR> Apple Computer
[07/14/2009|04:10] C:\DOCUME~1\Jaime\APPLIC~1\<DIR> BitTorrent
[04/26/2009|12:07] C:\DOCUME~1\Jaime\APPLIC~1\<DIR> CopyTrans
[04/25/2009|11:59] C:\DOCUME~1\Jaime\APPLIC~1\<DIR> CopyTransControlCenter
[04/26/2009|12:03] C:\DOCUME~1\Jaime\APPLIC~1\<DIR> Corel
[05/16/2009|08:30] C:\DOCUME~1\Jaime\APPLIC~1\<DIR> Creative
[07/15/2009|05:23] C:\DOCUME~1\Jaime\APPLIC~1\<DIR> DNA
[07/15/2009|03:06] C:\DOCUME~1\Jaime\APPLIC~1\<DIR> FrostWire
[04/26/2009|12:10] C:\DOCUME~1\Jaime\APPLIC~1\<DIR> funkitron
[04/26/2009|12:06] C:\DOCUME~1\Jaime\APPLIC~1\<DIR> Google
[04/25/2009|11:52] C:\DOCUME~1\Jaime\APPLIC~1\<DIR> Help
[04/25/2009|11:49] C:\DOCUME~1\Jaime\APPLIC~1\<DIR> Identities
[06/20/2009|03:49] C:\DOCUME~1\Jaime\APPLIC~1\<DIR> iolo
[07/14/2009|04:04] C:\DOCUME~1\Jaime\APPLIC~1\<DIR> LimeWire
[04/25/2009|11:42] C:\DOCUME~1\Jaime\APPLIC~1\<DIR> Macromedia
[07/13/2009|06:43] C:\DOCUME~1\Jaime\APPLIC~1\<DIR> Malwarebytes
[04/25/2009|11:46] C:\DOCUME~1\Jaime\APPLIC~1\<DIR> McAfee
[06/27/2009|06:15] C:\DOCUME~1\Jaime\APPLIC~1\<DIR> Microsoft
[04/25/2009|11:50] C:\DOCUME~1\Jaime\APPLIC~1\<DIR> Mozilla
[04/26/2009|12:00] C:\DOCUME~1\Jaime\APPLIC~1\<DIR> Smart Recorder
[04/26/2009|12:13] C:\DOCUME~1\Jaime\APPLIC~1\<DIR> SpinTop
[04/25/2009|11:55] C:\DOCUME~1\Jaime\APPLIC~1\<DIR> Sun
[07/13/2009|11:24] C:\DOCUME~1\Jaime\APPLIC~1\<DIR> SUPERAntiSpyware.com
[04/26/2009|12:04] C:\DOCUME~1\Jaime\APPLIC~1\<DIR> Talkback
[07/08/2009|03:20] C:\DOCUME~1\Jaime\APPLIC~1\<DIR> U3
[04/25/2009|11:53] C:\DOCUME~1\Jaime\APPLIC~1\<DIR> WinRAR
[06/20/2009|01:50] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> iolo
[04/20/2008|02:29] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Microsoft
[04/20/2008|02:29] C:\DOCUME~1\NETWOR~1\APPLIC~1\<DIR> Microsoft
--------------------\\ Scheduled Tasks located in C:\WINDOWS\Tasks
[07/15/2009 05:03 PM][--a------] C:\WINDOWS\tasks\Google Software Updater.job
[07/13/2009 11:30 PM][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[07/15/2009 01:30 AM][--a------] C:\WINDOWS\tasks\McDefragTask.job
[07/01/2009 01:00 AM][--a------] C:\WINDOWS\tasks\McQcTask.job
[07/15/2009 05:03 PM][--ah-----] C:\WINDOWS\tasks\SA.DAT
[08/10/2004 06:00 AM][-r-h-----] C:\WINDOWS\tasks\desktop.ini
--------------------\\ Listing Folders in C:\Program Files
[08/05/2008|02:20] C:\Program Files\<DIR> Adobe
[10/07/2008|06:00] C:\Program Files\<DIR> Apple Software Update
[04/25/2009|09:34] C:\Program Files\<DIR> AskBarDis
[10/25/2008|12:19] C:\Program Files\<DIR> BitTorrent
[05/22/2009|02:07] C:\Program Files\<DIR> Bonjour
[04/20/2008|02:37] C:\Program Files\<DIR> Citrix
[07/15/2009|05:00] C:\Program Files\<DIR> Common Files
[04/20/2008|02:22] C:\Program Files\<DIR> ComPlus Applications
[05/16/2009|12:05] C:\Program Files\<DIR> CONEXANT
[05/17/2009|04:44] C:\Program Files\<DIR> Creative
[05/07/2008|04:59] C:\Program Files\<DIR> Cucusoft
[06/26/2009|10:50] C:\Program Files\<DIR> Dell
[05/20/2009|09:47] C:\Program Files\<DIR> Digital Line Detect
[04/20/2008|02:34] C:\Program Files\<DIR> DIGStream
[07/15/2009|05:03] C:\Program Files\<DIR> DNA
[04/20/2008|02:34] C:\Program Files\<DIR> EnglishOtto
[04/20/2008|02:34] C:\Program Files\<DIR> ESPNMotion
[04/19/2009|03:42] C:\Program Files\<DIR> Full Tilt Poker
[04/20/2008|02:34] C:\Program Files\<DIR> GemMaster
[08/07/2008|03:37] C:\Program Files\<DIR> Google
[05/16/2009|04:08] C:\Program Files\<DIR> IDT
[05/20/2009|09:47] C:\Program Files\<DIR> InstallShield Installation Information
[04/20/2008|01:28] C:\Program Files\<DIR> Intel
[04/23/2008|03:22] C:\Program Files\<DIR> InterActual
[06/27/2009|01:39] C:\Program Files\<DIR> Internet Explorer
[06/20/2009|01:50] C:\Program Files\<DIR> iolo
[05/22/2009|02:09] C:\Program Files\<DIR> iPod
[05/22/2009|02:09] C:\Program Files\<DIR> iTunes
[07/14/2009|04:06] C:\Program Files\<DIR> Java
[07/13/2009|06:43] C:\Program Files\<DIR> Malwarebytes' Anti-Malware
[07/23/2008|03:35] C:\Program Files\<DIR> Mario Forever
[06/27/2009|06:15] C:\Program Files\<DIR> McAfee
[04/21/2008|01:26] C:\Program Files\<DIR> McAfee.com
[08/22/2008|01:59] C:\Program Files\<DIR> Messenger
[04/20/2008|02:27] C:\Program Files\<DIR> microsoft frontpage
[08/22/2008|01:51] C:\Program Files\<DIR> Movie Maker
[07/15/2009|05:14] C:\Program Files\<DIR> Mozilla Firefox
[06/27/2009|01:41] C:\Program Files\<DIR> MSBuild
[03/23/2009|07:30] C:\Program Files\<DIR> MSN
[04/20/2008|02:21] C:\Program Files\<DIR> MSN Gaming Zone
[05/05/2008|06:33] C:\Program Files\<DIR> Nero
[04/26/2009|12:30] C:\Program Files\<DIR> NetMeeting
[04/20/2008|02:22] C:\Program Files\<DIR> Online Services
[05/06/2009|12:44] C:\Program Files\<DIR> OpenAL
[04/26/2009|12:32] C:\Program Files\<DIR> Outlook Express
[12/16/2008|05:24] C:\Program Files\<DIR> PlayNow
[04/13/2009|10:31] C:\Program Files\<DIR> Poker Superstars 3
[05/22/2009|02:06] C:\Program Files\<DIR> QuickTime
[06/27/2009|01:41] C:\Program Files\<DIR> Reference Assemblies
[04/20/2008|02:35] C:\Program Files\<DIR> RGB
[05/22/2009|02:02] C:\Program Files\<DIR> Safari
[04/20/2008|02:42] C:\Program Files\<DIR> SigmaTel
[07/10/2008|12:12] C:\Program Files\<DIR> Sun
[07/13/2009|11:24] C:\Program Files\<DIR> SUPERAntiSpyware
[04/20/2008|02:42] C:\Program Files\<DIR> Uninstall Information
[05/25/2008|12:59] C:\Program Files\<DIR> Windows Media Connect 2
[04/26/2009|12:25] C:\Program Files\<DIR> Windows Media Player
[08/22/2008|01:47] C:\Program Files\<DIR> Windows NT
[04/20/2008|02:21] C:\Program Files\<DIR> Windows Plus
[04/20/2008|02:24] C:\Program Files\<DIR> WindowsUpdate
[04/21/2008|07:15] C:\Program Files\<DIR> WindSolutions
[05/05/2008|11:38] C:\Program Files\<DIR> WinRAR
[03/25/2009|01:18] C:\Program Files\<DIR> WM Converter
[05/07/2008|05:25] C:\Program Files\<DIR> WordPerfect Office 12
[05/07/2008|05:31] C:\Program Files\<DIR> WordPerfect OfficeReady 1.0
[04/20/2008|02:27] C:\Program Files\<DIR> xerox
--------------------\\ Listing Folders in C:\Program Files\Common Files
[04/25/2009|09:56] C:\Program Files\Common Files\<DIR> Adobe
[04/25/2009|09:40] C:\Program Files\Common Files\<DIR> Ahead
[05/22/2009|02:09] C:\Program Files\Common Files\<DIR> Apple
[04/25/2009|09:43] C:\Program Files\Common Files\<DIR> Borland Shared
[04/25/2009|09:49] C:\Program Files\Common Files\<DIR> Corel
[04/25/2009|09:52] C:\Program Files\Common Files\<DIR> InstallShield
[04/25/2009|09:53] C:\Program Files\Common Files\<DIR> Java
[04/25/2009|09:38] C:\Program Files\Common Files\<DIR> LightScribe
[04/25/2009|09:45] C:\Program Files\Common Files\<DIR> McAfee
[05/16/2009|08:00] C:\Program Files\Common Files\<DIR> Microsoft Shared
[04/25/2009|09:46] C:\Program Files\Common Files\<DIR> MSSoap
[04/25/2009|09:44] C:\Program Files\Common Files\<DIR> ODBC
[04/25/2009|09:50] C:\Program Files\Common Files\<DIR> Roxio Shared
[04/25/2009|09:39] C:\Program Files\Common Files\<DIR> Services
[04/25/2009|09:36] C:\Program Files\Common Files\<DIR> Sonic Shared
[04/25/2009|09:48] C:\Program Files\Common Files\<DIR> SpeechEngines
[04/25/2009|09:35] C:\Program Files\Common Files\<DIR> System
[07/13/2009|06:26] C:\Program Files\Common Files\<DIR> Wise Installation Wizard
--------------------\\ Process
( 56 Processes )
... OK !
--------------------\\ Searching with S_Lop
No Lop folder found !
--------------------\\ Searching for Lop Files - Folders
No Lop folder found !
--------------------\\ Searching within the Registry
..... OK !
--------------------\\ Checking the Hosts file
Hosts file CLEAN
--------------------\\ Searching for hidden files with Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net Rootkit scan 2009-07-15 17:34:06
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0
--------------------\\ Searching for other infections
No other infections found !
[F:2][D:1]-> C:\DOCUME~1\Jaime\LOCALS~1\Temp
[F:20][D:0]-> C:\DOCUME~1\Jaime\Cookies
[F:2][D:0]-> C:\DOCUME~1\Jaime\LOCALS~1\TEMPOR~1\content.IE5
1 - "C:\Lop SD\LopR_1.txt" - Wed 07/15/2009|17:34 - Option : [1]
--------------------\\ Scan completed at 17:34:58