Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
C:\WINDOWS\_000002_.tmp.dll
C:\WINDOWS\_000005_.tmp.dll
C:\WINDOWS\_000046_.tmp.dll
C:\WINDOWS\inf\_000000_.tmp.dll
C:\WINDOWS\system32\_000001_.tmp.dll
C:\WINDOWS\system32\_000004_.tmp.dll
C:\WINDOWS\system32\_000045_.tmp.dll
C:\WINDOWS\system32\comsa32.sys
.
((((((((((((((((((((((((( Files Created from 2008-07-25 to 2008-08-25 )))))))))))))))))))))))))))))))
.
2008-08-17 20:18 . 2008-08-17 20:18 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\HorizonWimba
2008-08-17 17:47 . 2008-08-17 17:47 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-08-17 17:47 . 2008-08-17 17:47 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-08-17 17:47 . 2008-08-17 17:47 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-17 17:47 . 2008-08-17 15:01 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-17 17:47 . 2008-08-17 15:01 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-08-17 17:45 . 2008-08-17 17:45 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-08-17 17:23 . 2008-08-17 17:23 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-17 14:28 . 2008-08-17 14:38 <DIR> d-------- C:\Program Files\Security Task Manager
2008-08-17 14:28 . 2008-08-17 14:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-08-16 18:22 . 2008-08-14 13:46 22,512 --a------ C:\WINDOWS\system32\drivers\adwarealert.sys
2008-08-16 17:21 . 2008-08-19 16:47 1,917 --a------ C:\WINDOWS\imsins.BAK
2008-08-16 17:09 . 2008-08-16 17:09 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Symantec
2008-08-12 20:02 . 2008-08-12 20:02 <DIR> d-------- C:\Program Files\Ofoto
2008-08-12 20:02 . 2002-10-14 09:56 3,007,488 --------- C:\WINDOWS\system32\OfotoNow.scr
2008-08-12 20:02 . 2002-08-28 10:20 18,102 --------- C:\WINDOWS\system32\OfotoNow.res
2008-07-29 22:07 . 2008-07-29 22:07 <DIR> d-------- C:\Program Files\PassAlong
2008-07-29 22:07 . 2007-10-11 17:41 111,944 --a------ C:\WINDOWS\system32\TPActiveX.dll
2008-07-29 14:28 . 2008-07-29 14:28 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-07-28 19:18 . 2008-07-28 19:18 <DIR> d---s---- C:\Documents and Settings\LocalService\UserData
2008-07-27 14:50 . 2008-08-24 14:01 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-07-27 14:50 . 2008-07-27 14:50 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-07-27 14:50 . 2008-07-27 14:50 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-07-27 14:50 . 2008-07-27 14:50 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-07-27 14:49 . 2008-07-27 14:49 <DIR> d-------- C:\Program Files\AVG
2008-07-26 23:36 . 2008-07-26 23:36 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Skype
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-24 20:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2008-08-13 00:02 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-10 03:03 --------- d-----w C:\Program Files\Java
2008-07-27 18:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg8
2008-07-27 02:20 --------- d-----w C:\Documents and Settings\Owner\Application Data\skypePM
2008-07-16 03:00 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-07-16 02:58 --------- d-----w C:\Program Files\Windows Live Favorites
2008-07-16 02:49 --------- d-----w C:\Program Files\Windows Live
2008-07-16 02:47 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-07-16 02:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-07-16 02:05 --------- d-----w C:\Program Files\Common Files\ArcSoft
2008-07-16 02:04 --------- d-----w C:\Program Files\Philips
2008-07-16 02:04 --------- d-----w C:\Program Files\DIFX
2008-07-16 02:03 --------- d-----w C:\Program Files\Common Files\SPC520NC
2008-07-12 04:17 --------- d-----w C:\Program Files\iTunes
2008-07-12 04:17 --------- d-----w C:\Program Files\iPod
2008-07-12 04:15 --------- d-----w C:\Program Files\Bonjour
2008-07-12 04:14 --------- d-----w C:\Program Files\QuickTime
2008-07-12 04:12 --------- d-----w C:\Program Files\Apple Software Update
2008-07-12 04:11 --------- d-----w C:\Program Files\Common Files\Apple
2008-07-11 01:04 --------- d-----w C:\Documents and Settings\Owner\Application Data\AVGTOOLBAR
2008-07-10 13:35 32,000 ----a-w C:\WINDOWS\system32\drivers\usbaapl.sys
2006-01-13 20:52 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2005-12-25 20:50 0 -c--a-w C:\Documents and Settings\Owner\Application Data\wklnhst.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Gateway Extended Warranty"="C:\Program Files\Gateway\GWCares\GWCares.exe" [2004-02-08 20:30 73728]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-07-18 23:09 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-07-18 23:06 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-07-18 23:10 114688]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe" [2005-09-09 02:18 57344]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-09-13 20:13 185632]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2005-08-12 20:16 1121792]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 09:47 116040]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-05-27 10:50 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-10 10:51 289064]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-27 14:49 1232152]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 19:29 39264]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
VPro520.lnk - C:\WINDOWS\VPro520.exe [2008-07-15 22:03:04 73728]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dllschannel.dlldigest.dllmsnsspc.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
R0 adwarealert;adwarealert;C:\WINDOWS\system32\DRIVERS\adwarealert.sys [2008-08-14 13:46]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-27 14:50]
R2 avg8emc;AVG Free8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-07-27 14:49]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-27 14:49]
R2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-27 14:50]
S3 SPC520;Philips SPC520NC PC Camera;C:\WINDOWS\system32\drivers\SPC520.sys [2007-03-27 21:27]
S3 SPC520m;Philips SPC520NC PC Cameram;C:\WINDOWS\system32\drivers\SPC520m.sys [2007-03-27 21:27]
.
Contents of the 'Scheduled Tasks' folder
2008-08-25 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
2005-11-25 C:\WINDOWS\Tasks\ISP signup reminder 1.job
- C:\WINDOWS\system32\OOBE\oobebaln.exe [2004-08-04 15:00]
2005-11-25 C:\WINDOWS\Tasks\ISP signup reminder 2.job
- C:\WINDOWS\system32\OOBE\oobebaln.exe [2004-08-04 15:00]
2005-11-25 C:\WINDOWS\Tasks\ISP signup reminder 3.job
- C:\WINDOWS\system32\OOBE\oobebaln.exe [2004-08-04 15:00]
2008-08-25 C:\WINDOWS\Tasks\MP Scheduled Scan.job
- C:\Program Files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-24 21:29:14
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINDOWS\TEMP\TMP0000002740A043DF73F6C748
scan completed successfully
hidden files: 1
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-08-24 21:36:43 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-25 01:36:37
ComboFix2.txt 2008-08-24 20:52:39
ComboFix3.txt 2008-08-23 22:08:46
ComboFix4.txt 2008-08-23 00:10:29
Pre-Run: 1,729,499,136 bytes free
Post-Run: 1,710,047,232 bytes free
162 --- E O F --- 2008-08-24 12:41:38
So far my computer seems to be fine. There are no more strange noises coming from it and I've closed it and reopened it and get no pop-ups.
Is is now safe to remove the files that I've downloaded for this ...like ComboFix, Malware Bytes, Hijack This, TaskManager just to free up memory since sometimes when I download a site, I'm told that I don't have enough disk space memory?
Also, should I keep the logs saved or does it matter?
Thanks, Cindy