Thank you so much for the help And my apologies on the all caps! I have a question, I notice after running all this that my Automatic Updates on my computer are turned "off". Can I turn this back on now??? And under Malware Protection it says : Windows did not find Antivirus software on this computer.....Okay, here is my log for you:ComboFix 08-05-15.3 - Martha 2008-05-18 13:25:13.1 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.1.1033.18.419 [GMT -4:00]
Running from: C:\Users\Martha\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\AntiSpywareMaster
C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat
C:\Users\Martha\FAVORI~1\Online Security Test.url
C:\Users\Martha\Favorites\Online Security Test.url
C:\Windows\system32\AutoRun.inf
----- BITS: Possible infected sites -----
hxxp://h30155.www3.hp.com
.
((((((((((((((((((((((((( Files Created from 2008-04-18 to 2008-05-18 )))))))))))))))))))))))))))))))
.
2008-05-17 07:46 . 2008-05-17 07:46 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-17 00:10 . 2008-05-17 00:10 197 --a------ C:\Windows\System32\MRT.INI
2008-05-16 18:14 . 2008-05-16 18:15 <DIR> d-------- C:\Program Files\Registry Defender Platinum
2008-05-11 15:24 . 2008-05-11 15:24 <DIR> d-------- C:\Users\All Users\HP Product Assistant
2008-05-11 15:24 . 2008-05-11 15:24 <DIR> d-------- C:\ProgramData\HP Product Assistant
2008-05-11 15:21 . 2008-05-11 15:21 <DIR> d-------- C:\Program Files\Hewlett-Packard
2008-05-11 14:57 . 2008-05-11 15:42 141,162 --a------ C:\Windows\hpoins14.dat
2008-05-11 14:57 . 2007-09-19 21:14 2,000 --------- C:\Windows\hpomdl14.dat
2008-05-07 19:36 . 2008-05-07 19:36 <DIR> dr------- C:\Windows\System32\config\systemprofile\Documents
2008-05-04 14:55 . 2008-05-04 15:41 <DIR> d-------- C:\Users\Martha\AppData\Roaming\ICAClient
2008-05-04 10:32 . 2008-05-04 16:13 <DIR> d-------- C:\Users\Martha\AppData\Roaming\SmartDraw
2008-05-04 10:30 . 2008-05-04 10:32 <DIR> d-------- C:\Program Files\SmartDraw 2008
2008-05-03 20:39 . 2008-05-16 07:54 <DIR> d-------- C:\Users\Martha\New Folder
2008-04-28 11:35 . 2008-04-28 11:35 <DIR> d-------- C:\Program Files\Windows Live Toolbar
2008-04-28 11:35 . 2008-04-28 11:35 <DIR> d-------- C:\Program Files\Windows Live Favorites
2008-04-28 11:26 . 2008-04-28 11:33 <DIR> d-------- C:\Program Files\Windows Live
2008-04-28 11:26 . 2008-04-28 11:32 <DIR> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-04-28 11:25 . 2008-04-28 11:33 <DIR> d-------- C:\Users\All Users\WLInstaller
2008-04-28 11:25 . 2008-04-28 11:33 <DIR> d-------- C:\ProgramData\WLInstaller
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-17 00:16 --------- d---a-w C:\ProgramData\TEMP
2008-05-17 00:15 --------- d-----w C:\Program Files\SpywareBlaster
2008-05-14 00:01 --------- d-----w C:\Program Files\Windows Mail
2008-05-11 19:24 --------- d-----w C:\ProgramData\HP
2008-05-11 09:17 --------- d-----w C:\Users\Martha\AppData\Roaming\LimeWire
2008-04-27 21:50 --------- d-----w C:\Users\Martha\AppData\Roaming\HP
2008-04-05 18:11 --------- d-----w C:\ProgramData\WEBREG
2008-04-05 18:10 --------- d-----w C:\Users\Martha\AppData\Roaming\HPAppData
2008-04-05 18:10 --------- d-----w C:\ProgramData\HPSSUPPLY
2008-04-05 18:10 --------- d-----w C:\Program Files\HP
2008-04-05 18:08 --------- d-----w C:\Program Files\Common Files\Hewlett-Packard
2008-04-05 18:05 --------- d-----w C:\ProgramData\Hewlett-Packard
2008-04-02 02:52 --------- d-----w C:\Program Files\MSECache
2008-03-29 14:31 --------- d-----w C:\Users\Martha\AppData\Roaming\Yahoo!
2008-03-28 00:28 --------- d-----w C:\Users\Martha\AppData\Roaming\Elluminate
2008-03-20 04:26 --------- d-----w C:\Program Files\Common Files\HP
2008-03-14 20:31 174 --sha-w C:\Program Files\desktop.ini
2008-03-14 20:23 87,040 ----a-w C:\Windows\System32\msoert2.dll
2008-03-14 20:23 704,000 ----a-w C:\Windows\System32\PhotoScreensaver.scr
2008-03-14 20:23 39,424 ----a-w C:\Windows\System32\ACCTRES.dll
2008-03-14 20:23 24,064 ----a-w C:\Windows\System32\wtsapi32.dll
2008-03-14 20:23 205,824 ----a-w C:\Windows\System32\msoeacct.dll
2008-03-14 20:22 67,584 ----a-w C:\Windows\System32\wlanhlp.dll
2008-03-14 20:22 542,720 ----a-w C:\Windows\System32\sysmain.dll
2008-03-14 20:22 502,784 ----a-w C:\Windows\System32\wlansvc.dll
2008-03-14 20:22 47,104 ----a-w C:\Windows\System32\wlanapi.dll
2008-03-14 20:22 297,984 ----a-w C:\Windows\System32\wlansec.dll
2008-03-14 20:22 290,816 ----a-w C:\Windows\System32\wlanmsm.dll
2008-03-14 20:22 2,923,520 ----a-w C:\Windows\explorer.exe
2008-03-14 20:21 194,560 ----a-w C:\Windows\System32\WebClnt.dll
2008-03-14 20:20 49,664 ----a-w C:\Windows\System32\csrsrv.dll
2008-03-14 20:20 376,320 ----a-w C:\Windows\System32\winsrv.dll
2008-03-14 20:14 8,147,968 ----a-w C:\Windows\System32\wmploc.DLL
2008-03-14 20:14 7,680 ----a-w C:\Windows\System32\spwmp.dll
2008-03-14 20:14 414,208 ----a-w C:\Windows\System32\msscp.dll
2008-03-14 20:14 4,096 ----a-w C:\Windows\System32\dxmasf.dll
2008-03-14 20:14 356,864 ----a-w C:\Windows\System32\MediaMetadataHandler.dll
2008-03-14 20:13 86,016 ----a-w C:\Windows\System32\icfupgd.dll
2008-03-14 20:13 61,952 ----a-w C:\Windows\System32\cmifw.dll
2008-03-14 20:13 396,800 ----a-w C:\Windows\System32\MPSSVC.dll
2008-03-14 20:13 392,192 ----a-w C:\Windows\System32\FirewallAPI.dll
2008-03-14 20:13 178,688 ----a-w C:\Windows\System32\iphlpsvc.dll
2008-03-14 20:13 16,896 ----a-w C:\Windows\System32\wfapigp.dll
2008-03-14 20:12 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe
2008-03-14 20:12 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe
2008-03-14 20:11 2,048 ----a-w C:\Windows\System32\msxml3r.dll
2008-03-14 20:11 104,448 ----a-w C:\Windows\System32\DWWIN.EXE
2008-03-14 20:11 1,191,936 ----a-w C:\Windows\System32\msxml3.dll
2008-03-14 20:09 24,064 ----a-w C:\Windows\System32\netcfg.exe
2008-03-14 20:09 22,016 ----a-w C:\Windows\System32\netiougc.exe
2008-03-14 20:09 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
2008-03-14 20:09 1,327,104 ----a-w C:\Windows\System32\quartz.dll
2008-03-14 20:07 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL
2008-03-14 20:07 57,856 ----a-w C:\Windows\System32\SLUINotify.dll
2008-03-14 20:07 566,784 ----a-w C:\Windows\System32\SLCommDlg.dll
2008-03-14 20:07 39,936 ----a-w C:\Windows\System32\slcinst.dll
2008-03-14 20:07 351,232 ----a-w C:\Windows\System32\SLUI.exe
2008-03-14 20:07 33,280 ----a-w C:\Windows\System32\slwmi.dll
2008-03-14 20:07 268,288 ----a-w C:\Windows\System32\mcbuilder.exe
2008-03-14 20:07 223,232 ----a-w C:\Windows\System32\WMASF.DLL
2008-03-14 20:07 223,232 ----a-w C:\Windows\System32\SLC.dll
2008-03-14 20:07 2,605,568 ----a-w C:\Windows\System32\SLsvc.exe
2008-03-14 20:07 2,048 ----a-w C:\Windows\System32\asferror.dll
2008-03-14 20:07 186,368 ----a-w C:\Windows\System32\SLLUA.exe
2008-03-14 20:06 2,048 ----a-w C:\Windows\System32\msxml6r.dll
2008-03-14 20:06 1,335,296 ----a-w C:\Windows\System32\msxml6.dll
2008-03-14 20:04 84,480 ----a-w C:\Windows\System32\INETRES.dll
2008-03-14 20:04 737,792 ----a-w C:\Windows\System32\inetcomm.dll
2008-03-14 20:04 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-03-14 20:04 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-03-14 20:04 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
2008-03-14 20:04 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
2008-03-14 20:04 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-03-14 20:04 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-03-14 20:04 11,776 ----a-w C:\Windows\System32\sbunattend.exe
2008-03-14 20:04 1,686,528 ----a-w C:\Windows\System32\gameux.dll
2008-03-14 20:02 788,992 ----a-w C:\Windows\System32\rpcrt4.dll
2008-03-14 20:01 974,336 ----a-w C:\Windows\System32\crypt32.dll
2008-03-14 20:01 5,120 ----a-w C:\Windows\System32\wmi.dll
2008-03-14 20:01 152,576 ----a-w C:\Windows\System32\imagehlp.dll
2008-03-14 20:00 2,048 ----a-w C:\Windows\System32\tzres.dll
2008-03-14 19:58 633,856 ----a-w C:\Windows\System32\user32.dll
2008-03-14 19:56 750,080 ----a-w C:\Windows\System32\qmgr.dll
2008-03-14 19:36 53,080 ----a-w C:\Windows\System32\wuauclt.exe
2008-03-14 19:36 43,352 ----a-w C:\Windows\System32\wups2.dll
2008-03-14 19:36 1,712,984 ----a-w C:\Windows\System32\wuaueng.dll
2008-03-14 19:36 1,524,224 ----a-w C:\Windows\System32\wucltux.dll
2008-03-14 19:35 80,896 ----a-w C:\Windows\System32\wudriver.dll
2008-03-14 19:35 549,720 ----a-w C:\Windows\System32\wuapi.dll
2008-03-14 19:35 33,624 ----a-w C:\Windows\System32\wups.dll
2008-03-14 19:34 31,232 ----a-w C:\Windows\System32\wuapp.exe
2008-03-14 19:34 163,000 ----a-w C:\Windows\System32\wuwebv.dll
2008-02-29 06:51 19,000 ----a-w C:\Windows\System32\kd1394.dll
2008-02-29 06:39 40,960 ----a-w C:\Windows\System32\srclient.dll
2008-02-29 06:39 371,712 ----a-w C:\Windows\System32\srcore.dll
2008-02-29 06:38 313,856 ----a-w C:\Windows\System32\rstrui.exe
2008-02-29 06:38 16,384 ----a-w C:\Windows\System32\srdelayed.exe
2008-02-29 06:35 6,656 ----a-w C:\Windows\System32\kbd106n.dll
2008-02-29 06:34 7,168 ----a-w C:\Windows\System32\f3ahvoas.dll
2008-02-29 04:16 2,027,008 ----a-w C:\Windows\System32\win32k.sys
.
------- Sigcheck -------
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-03-14 16:04 1232896]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 08:34 201728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-03-14 16:16 1006264]
"NeroCheck"="C:\Windows\system32\NeroCheck.exe" [2001-07-09 04:50 155648]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2002-09-12 13:13 1101824]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-01-31 23:13 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 13:10 267048]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 21:34 49152]
C:\Users\Martha\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
RegistryDefender.lnk - C:\Program Files\Registry Defender Platinum\RegistryDefender.exe [2008-04-21 07:03:36 1126400]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 21:26:24 210520]
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2007-09-19 04:33:46 282624]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{494C4DB4-E602-4003-A6DE-CF1A36D9B3B4}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{BCF5C4AB-EFA2-49CF-B7EC-AEEE3574E0FA}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{33007F5B-FAD1-499C-A05B-959A5A0A963A}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{EDFD6145-0AFA-4F21-BED1-592BC279AFFA}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{F4DCCC5B-521C-49E4-ADD1-37441E792D21}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{720B23D7-A05F-45F8-A90D-94C607502DFF}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{41A3831A-B6A9-466A-9EC9-0A9CCAF599C7}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{8AA016DA-4D6F-4108-8E45-2898ABD6EF28}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{850C19C4-10CB-4F64-BAF7-1B078CD84954}"= UDP:C:\Windows\System32\lxbacoms.exe:Lexmark Communications System
"{D48E1DC6-FF80-463B-B718-3AF098CFD7FD}"= TCP:C:\Windows\System32\lxbacoms.exe:Lexmark Communications System
"{62CCD235-E3A0-48B6-8B5C-6658AD93DACE}"= UDP:C:\Windows\System32\spool\drivers\w32x86\3\lxbapswx.exe:Printer Status Window
"{3584B247-BC1C-4A69-AF0B-EC244D356744}"= TCP:C:\Windows\System32\spool\drivers\w32x86\3\lxbapswx.exe:Printer Status Window
"TCP Query User{F70B7500-0BFF-440C-AB3B-278BBCD768B0}C:\\program files\\limewire\\limewire.exe"= UDP:C:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{C5401096-063B-4920-AD9E-B3A01701EC10}C:\\program files\\limewire\\limewire.exe"= TCP:C:\program files\limewire\limewire.exe:LimeWire
"TCP Query User{A93B3189-765A-4035-89FC-43BD310FF46A}C:\\program files\\windows live\\messenger\\msnmsgr.exe"= UDP:C:\program files\windows live\messenger\msnmsgr.exe:Windows Live Messenger
"UDP Query User{8B748D8B-C63B-4963-A5A6-C951D5BF5DD5}C:\\program files\\windows live\\messenger\\msnmsgr.exe"= TCP:C:\program files\windows live\messenger\msnmsgr.exe:Windows Live Messenger
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
R0 BsStor;InCD Storage Helper Driver;C:\Windows\system32\DRIVERS\bsstor.sys [2002-06-05 19:07]
R2 BsUDF;InCD UDF Driver;C:\Windows\system32\drivers\BsUDF.sys [2002-09-13 08:35]
R2 lxba_device;lxba_device;C:\Windows\system32\lxbacoms.exe [2007-04-24 19:24]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-04-28 15:35:48 C:\Windows\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-04-26 23:55:03 C:\Windows\Tasks\EasyShare Registration Task.job"
- C:\Windows\system32\rundll32.exeZC:\PROGRA~2\Kodak\EasyShareSetup\$REGIS~1\Registration_7.4.20.2.sxt _RegistrationOffer@16
"2008-05-17 09:31:28 C:\Windows\Tasks\SDMsgUpdate (TE).job"
- C:\PROGRA~1\SMARTD~1\Messages\SDNotify.exeW-PTE -V900 -SSDU.ini -A -Mhttp://www.smartdraw.com/msgs/messagecheck.aspx -D0 -T -N -X
"2008-05-18 10:17:32 C:\Windows\Tasks\User_Feed_Synchronization-{579E8DBC-AE66-489C-9ADE-2E56E1CBF6CE}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-05-18 13:28:29
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2008-05-18 13:30:28
ComboFix-quarantined-files.txt 2008-05-18 17:29:26
Pre-Run: 118,401,896,448 bytes free
Post-Run: 118,393,393,152 bytes free
217 --- E O F --- 2008-05-17 04:10:45
Edited by mjclark55, 18 May 2008 - 12:37 PM.