The infection comes back when I am browsing the internet. It appears to be random and not related to any certain site. I have not inserted any usb or downloaded any other programs other than instructed by you.
Of note, when I run Combo fix it warns me that Microsoft Security Essentials is running and could interfere with the scan, however as far as I know it is no longer installed. Thank you so much for your help with this I hope we can beat it!
ComboFix 11-12-21.02 - Chris 12/21/2011 19:11:52.3.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3002.1648 [GMT -6:00]
Running from: c:\users\Chris\Desktop\ComboFix.exe
AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116}
AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB}
SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\$NtUninstallKB62280$\3801381427
c:\windows\$NtUninstallKB62280$\485945278\@
c:\windows\$NtUninstallKB62280$\485945278\bckfg.tmp
c:\windows\$NtUninstallKB62280$\485945278\cfg.ini
c:\windows\$NtUninstallKB62280$\485945278\Desktop.ini
c:\windows\$NtUninstallKB62280$\485945278\keywords
c:\windows\$NtUninstallKB62280$\485945278\kwrd.dll
c:\windows\$NtUninstallKB62280$\485945278\L\qnbwvoto
c:\windows\$NtUninstallKB62280$\485945278\U\00000001.@
c:\windows\$NtUninstallKB62280$\485945278\U\00000002.@
c:\windows\$NtUninstallKB62280$\485945278\U\00000004.@
c:\windows\$NtUninstallKB62280$\485945278\U\80000000.@
c:\windows\$NtUninstallKB62280$\485945278\U\80000004.@
c:\windows\$NtUninstallKB62280$\485945278\U\80000032.@
c:\windows\system32\asw43CF.tmp
.
.
((((((((((((((((((((((((( Files Created from 2011-11-22 to 2011-12-22 )))))))))))))))))))))))))))))))
.
.
2011-12-22 01:39 . 2011-12-22 01:39 -------- d-----w- c:\users\Chris\AppData\Local\temp
2011-12-22 01:39 . 2011-12-22 01:39 -------- d-----w- c:\users\Freenet\AppData\Local\temp
2011-12-22 01:39 . 2011-12-22 01:39 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-12-21 02:13 . 2011-12-21 02:13 29904 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F96A5E7E-859C-4727-808A-92ECD7C44E5C}\MpKsl12e0b3a2.sys
2011-12-20 01:50 . 2011-12-20 01:50 -------- d-----w- c:\programdata\Kaspersky Lab
2011-12-20 01:45 . 2011-12-22 01:09 56200 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F96A5E7E-859C-4727-808A-92ECD7C44E5C}\offreg.dll
2011-12-20 01:45 . 2011-11-21 10:47 6823496 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F96A5E7E-859C-4727-808A-92ECD7C44E5C}\mpengine.dll
2011-12-20 00:36 . 2011-12-20 00:36 -------- d-----w- C:\_OTL
2011-12-14 06:25 . 2008-01-21 02:23 54784 ----a-w- c:\windows\system32\drivers\i8042prt.sys
2011-12-11 05:03 . 2011-12-15 00:56 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-12-11 05:03 . 2011-08-31 23:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-21 10:47 . 2010-09-23 01:23 6823496 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-10-23 18:55 . 2011-10-23 18:55 232512 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys
2011-10-20 16:42 . 2009-08-18 16:30 564632 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\wlidui.dll
2011-10-20 16:42 . 2009-08-18 16:24 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-10-11 06:25 . 2011-10-11 06:25 703824 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C6E2FD54-3561-48AE-A1F9-9C261107AD3D}\gapaengine.dll
2011-09-30 23:06 . 2011-10-13 03:38 916480 ----a-w- c:\windows\system32\wininet.dll
2011-09-30 23:02 . 2011-10-13 03:38 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-09-30 23:01 . 2011-10-13 03:38 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-09-30 23:01 . 2011-10-13 03:38 71680 ----a-w- c:\windows\system32\iesetup.dll
2011-09-30 23:01 . 2011-10-13 03:38 109056 ----a-w- c:\windows\system32\iesysprep.dll
2011-09-30 22:07 . 2011-10-13 03:38 385024 ----a-w- c:\windows\system32\html.iec
2011-09-30 21:29 . 2011-10-13 03:38 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2011-09-30 21:28 . 2011-10-13 03:38 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2011-11-26 02:40 . 2011-04-23 01:05 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 4"="c:\program files\IObit\Advanced SystemCare 4\ASCTray.exe" [2011-04-14 402832]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2011-08-02 4910912]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-17 1049896]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-09-24 468264]
"UpdateLBPShortCut"="c:\program files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"UpdatePSTShortCut"="c:\program files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2008-10-07 210216]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-08-01 202032]
"UpdateP2GoShortCut"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"UpdatePDIRShortCut"="c:\program files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2009-11-18 54576]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-26 136216]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-26 171032]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-26 170520]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-07-05 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-10-09 421736]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-28 207424]
.
c:\users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
OpenOffice.org 3.3.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
_uninst_56415290.lnk - c:\users\Chris\AppData\Local\temp\_uninst_56415290.bat [N/A]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-11-18 275072]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2010-1-27 323584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux3"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivX Download Manager]
2010-12-08 21:15 63360 ----a-w- c:\program files\DivX\DivX Plus Web Player\DDMService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-12-09 19:28 1226608 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPAdvisor]
2008-09-30 23:56 972080 ----a-w- c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2011-10-09 23:06 421736 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2008-06-09 17:16 2363392 ----a-w- c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2011-07-05 23:36 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zune Launcher]
2009-09-04 19:16 158448 ----a-w- c:\program files\Zune\ZuneLauncher.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiSpywareOverride"=dword:00000001
.
R1 MpKsl0450a567;MpKsl0450a567;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{73A3333A-CC5A-4578-81AA-1F73438DE7B8}\MpKsl0450a567.sys [x]
R1 MpKsl04ad696c;MpKsl04ad696c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{33CED062-425D-4950-9D9A-CB0B0EFDAAE1}\MpKsl04ad696c.sys [x]
R1 MpKsl054eedf1;MpKsl054eedf1;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{5F78D488-E291-45B6-9F70-F5ED37A004A4}\MpKsl054eedf1.sys [x]
R1 MpKsl072c5605;MpKsl072c5605;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{055B01A1-A737-4413-A2E0-8F12893E4C44}\MpKsl072c5605.sys [x]
R1 MpKsl07e2723b;MpKsl07e2723b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F12D0D83-F092-4E58-A388-5E8F8013E06D}\MpKsl07e2723b.sys [x]
R1 MpKsl091b0f5e;MpKsl091b0f5e;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B2C6EC87-716A-4860-8F5C-D73DBCDE0DED}\MpKsl091b0f5e.sys [x]
R1 MpKsl0ab04352;MpKsl0ab04352;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C451466F-6DE2-45E8-BA0B-EA8C507CD7CA}\MpKsl0ab04352.sys [x]
R1 MpKsl11bae039;MpKsl11bae039;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C2C424BE-C27A-4CB9-BEAF-F302925C4E4D}\MpKsl11bae039.sys [x]
R1 MpKsl13cbeab6;MpKsl13cbeab6;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{15068510-A221-4582-B8E3-B171E427B6C4}\MpKsl13cbeab6.sys [x]
R1 MpKsl14587726;MpKsl14587726;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{FCFC3B5E-D6D7-458C-8209-A96554F22227}\MpKsl14587726.sys [x]
R1 MpKsl145df352;MpKsl145df352;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{4D29DEF5-CCFB-4811-BA9D-E97151E26F21}\MpKsl145df352.sys [x]
R1 MpKsl17d1ffef;MpKsl17d1ffef;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{33CED062-425D-4950-9D9A-CB0B0EFDAAE1}\MpKsl17d1ffef.sys [x]
R1 MpKsl1a6d9eee;MpKsl1a6d9eee;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{231A49B1-80EF-452A-833D-B6F3762DE435}\MpKsl1a6d9eee.sys [x]
R1 MpKsl1ec972f2;MpKsl1ec972f2;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2AAB2646-6523-41ED-87E4-C4C79DA10567}\MpKsl1ec972f2.sys [x]
R1 MpKsl24bb53be;MpKsl24bb53be;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3FCC7023-DBE0-4A67-A85D-E07B38757632}\MpKsl24bb53be.sys [x]
R1 MpKsl2653b5af;MpKsl2653b5af;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7EB1DC3F-16FA-45E0-87BC-782ABD2F9273}\MpKsl2653b5af.sys [x]
R1 MpKsl296d9f62;MpKsl296d9f62;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{04FB81EC-5F26-4710-A342-93A5305E6E83}\MpKsl296d9f62.sys [x]
R1 MpKsl29890513;MpKsl29890513;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B19CBD82-9D3D-44CB-B675-F42AC35BEDE7}\MpKsl29890513.sys [x]
R1 MpKsl29f73266;MpKsl29f73266;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{0AA1E284-CB69-4C87-A20F-8C56F0E01F68}\MpKsl29f73266.sys [x]
R1 MpKsl2ae3661f;MpKsl2ae3661f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{78015E95-CDA3-4363-ACDA-061A77A290C9}\MpKsl2ae3661f.sys [x]
R1 MpKsl2e676c18;MpKsl2e676c18;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9A80888C-9BCC-4B5A-91D2-A9C8B2B73610}\MpKsl2e676c18.sys [x]
R1 MpKsl34a24807;MpKsl34a24807;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{8E1C70B5-8806-46C6-97D9-31C963697847}\MpKsl34a24807.sys [x]
R1 MpKsl35b95aa8;MpKsl35b95aa8;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E98B6733-7D44-4563-841B-8FF0EEFF28E9}\MpKsl35b95aa8.sys [x]
R1 MpKsl3618fc94;MpKsl3618fc94;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3C1DE2E4-DDE4-4C36-93C3-23CA38DD93CF}\MpKsl3618fc94.sys [x]
R1 MpKsl37beff20;MpKsl37beff20;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{05797F2A-283A-4D55-A491-B2A464695D3A}\MpKsl37beff20.sys [x]
R1 MpKsl3a7eeb65;MpKsl3a7eeb65;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{DBF2B626-6D42-4A80-9B2C-A3E0DA73D4C9}\MpKsl3a7eeb65.sys [x]
R1 MpKsl3c8de7c2;MpKsl3c8de7c2;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{0C53135E-CC22-4D2E-A5E9-273E9594015F}\MpKsl3c8de7c2.sys [x]
R1 MpKsl3cf5a160;MpKsl3cf5a160;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{42856969-046F-4B84-8FB1-224C9CD8FEF9}\MpKsl3cf5a160.sys [x]
R1 MpKsl439c4d58;MpKsl439c4d58;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{002264BC-07EC-44CA-A038-93E26A8A5568}\MpKsl439c4d58.sys [x]
R1 MpKsl442ca00f;MpKsl442ca00f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{05797F2A-283A-4D55-A491-B2A464695D3A}\MpKsl442ca00f.sys [x]
R1 MpKsl446d8a4f;MpKsl446d8a4f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7160DB5C-7DE0-4204-BACA-78FD25EC3A68}\MpKsl446d8a4f.sys [x]
R1 MpKsl469ca24f;MpKsl469ca24f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{31DF6C0A-6A04-404D-B2F7-1325609A9426}\MpKsl469ca24f.sys [x]
R1 MpKsl476cffeb;MpKsl476cffeb;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{E4C64134-5339-4F39-87DD-0AA86B2BCD32}\MpKsl476cffeb.sys [x]
R1 MpKsl4a0be4b5;MpKsl4a0be4b5;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{04FB81EC-5F26-4710-A342-93A5305E6E83}\MpKsl4a0be4b5.sys [x]
R1 MpKsl4bb5891a;MpKsl4bb5891a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BB367FEC-34FD-4D30-82DA-4D2F5399066C}\MpKsl4bb5891a.sys [x]
R1 MpKsl4f7e35d6;MpKsl4f7e35d6;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{42856969-046F-4B84-8FB1-224C9CD8FEF9}\MpKsl4f7e35d6.sys [x]
R1 MpKsl5209c373;MpKsl5209c373;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CCC89A97-FE9A-4B04-8DE3-47576D9D01E3}\MpKsl5209c373.sys [x]
R1 MpKsl55efaf91;MpKsl55efaf91;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2A5489D6-DBAD-47E3-AF73-86119C1E8837}\MpKsl55efaf91.sys [x]
R1 MpKsl57350dbc;MpKsl57350dbc;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{825718BB-C0E0-47BF-929A-82C842D0D327}\MpKsl57350dbc.sys [x]
R1 MpKsl5739cf65;MpKsl5739cf65;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3006A176-E208-4B2B-B824-F79A3CDA50CC}\MpKsl5739cf65.sys [x]
R1 MpKsl5bf8ed06;MpKsl5bf8ed06;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{4DD80D68-1504-4228-8795-82750472FFD0}\MpKsl5bf8ed06.sys [x]
R1 MpKsl5ddccabc;MpKsl5ddccabc;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6BC30767-DAD6-4A6D-88BA-5B06D59EF051}\MpKsl5ddccabc.sys [x]
R1 MpKsl5f9e99b0;MpKsl5f9e99b0;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2F356C71-42BF-4B32-9F2B-5F279774E848}\MpKsl5f9e99b0.sys [x]
R1 MpKsl60da120f;MpKsl60da120f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{EF041027-BF65-4FAD-A5F2-AAD159FC4711}\MpKsl60da120f.sys [x]
R1 MpKsl63ababa2;MpKsl63ababa2;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F9BE7CD0-4C11-4F65-8B33-0FE534914ABE}\MpKsl63ababa2.sys [x]
R1 MpKsl63c68757;MpKsl63c68757;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{73A3333A-CC5A-4578-81AA-1F73438DE7B8}\MpKsl63c68757.sys [x]
R1 MpKsl649653eb;MpKsl649653eb;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3959439A-FD09-4DC3-AEED-3F23B0E9E68B}\MpKsl649653eb.sys [x]
R1 MpKsl66e834a6;MpKsl66e834a6;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{231A49B1-80EF-452A-833D-B6F3762DE435}\MpKsl66e834a6.sys [x]
R1 MpKsl6907c979;MpKsl6907c979;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F0314A68-6D35-4ABD-A967-791963B6E608}\MpKsl6907c979.sys [x]
R1 MpKsl6a8a2abc;MpKsl6a8a2abc;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CE891397-F174-43EB-A370-E184295817AA}\MpKsl6a8a2abc.sys [x]
R1 MpKsl6ad5b5b6;MpKsl6ad5b5b6;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D23B9EC6-8450-477B-ADCB-FB0628E27C94}\MpKsl6ad5b5b6.sys [x]
R1 MpKsl6b2745f9;MpKsl6b2745f9;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F2A0BF71-34B9-4E5D-8BB5-CCB7A3B1816B}\MpKsl6b2745f9.sys [x]
R1 MpKsl70a0409b;MpKsl70a0409b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2EFCFD4E-9CFA-4808-B842-E730AAE02541}\MpKsl70a0409b.sys [x]
R1 MpKsl70dade98;MpKsl70dade98;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A8ABB109-E205-4327-AA5B-6815BCB22927}\MpKsl70dade98.sys [x]
R1 MpKsl72935daa;MpKsl72935daa;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{700105C8-1B6D-4E2B-93AE-72FA9B6412C5}\MpKsl72935daa.sys [x]
R1 MpKsl7577ff9f;MpKsl7577ff9f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{76488854-E3E4-4540-B4A7-B8D4E5845D00}\MpKsl7577ff9f.sys [x]
R1 MpKsl75ed7439;MpKsl75ed7439;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B220448C-EF10-4E19-BF5B-2B69E4F6C90E}\MpKsl75ed7439.sys [x]
R1 MpKsl792ce7c3;MpKsl792ce7c3;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F7A718D3-043F-4671-848C-909D2DA60910}\MpKsl792ce7c3.sys [x]
R1 MpKsl797875c7;MpKsl797875c7;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F12D0D83-F092-4E58-A388-5E8F8013E06D}\MpKsl797875c7.sys [x]
R1 MpKsl79e86464;MpKsl79e86464;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3959439A-FD09-4DC3-AEED-3F23B0E9E68B}\MpKsl79e86464.sys [x]
R1 MpKsl7c05a715;MpKsl7c05a715;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B19CBD82-9D3D-44CB-B675-F42AC35BEDE7}\MpKsl7c05a715.sys [x]
R1 MpKsl80a3f0c9;MpKsl80a3f0c9;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{78015E95-CDA3-4363-ACDA-061A77A290C9}\MpKsl80a3f0c9.sys [x]
R1 MpKsl820dda1e;MpKsl820dda1e;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3C1DE2E4-DDE4-4C36-93C3-23CA38DD93CF}\MpKsl820dda1e.sys [x]
R1 MpKsl83f1e94b;MpKsl83f1e94b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2F356C71-42BF-4B32-9F2B-5F279774E848}\MpKsl83f1e94b.sys [x]
R1 MpKsl8923db3a;MpKsl8923db3a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D393F828-4B9E-49B2-A5C6-E3E66E251897}\MpKsl8923db3a.sys [x]
R1 MpKsl8a85876a;MpKsl8a85876a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{4D29DEF5-CCFB-4811-BA9D-E97151E26F21}\MpKsl8a85876a.sys [x]
R1 MpKsl8cc0486a;MpKsl8cc0486a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{3006A176-E208-4B2B-B824-F79A3CDA50CC}\MpKsl8cc0486a.sys [x]
R1 MpKsl8fde8f61;MpKsl8fde8f61;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B220448C-EF10-4E19-BF5B-2B69E4F6C90E}\MpKsl8fde8f61.sys [x]
R1 MpKsl90ff8dc6;MpKsl90ff8dc6;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B946628E-6B8E-43E2-9079-D37886C6BEFD}\MpKsl90ff8dc6.sys [x]
R1 MpKsl91c76266;MpKsl91c76266;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{DBF2B626-6D42-4A80-9B2C-A3E0DA73D4C9}\MpKsl91c76266.sys [x]
R1 MpKsl96f9f579;MpKsl96f9f579;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D3274473-3401-4209-8AF6-ED127A45309D}\MpKsl96f9f579.sys [x]
R1 MpKsl98235f0b;MpKsl98235f0b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{04F648A4-8262-4F3D-9C66-B856E71B5B6F}\MpKsl98235f0b.sys [x]
R1 MpKsl990d2912;MpKsl990d2912;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{29B89742-21FC-4301-B3CD-C7F702C4F46E}\MpKsl990d2912.sys [x]
R1 MpKsla0fa3733;MpKsla0fa3733;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{07DD8CA2-392F-4E33-BA8B-72DEFAD914C6}\MpKsla0fa3733.sys [x]
R1 MpKsla59ae932;MpKsla59ae932;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{04F648A4-8262-4F3D-9C66-B856E71B5B6F}\MpKsla59ae932.sys [x]
R1 MpKsla69ca89d;MpKsla69ca89d;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{D23B9EC6-8450-477B-ADCB-FB0628E27C94}\MpKsla69ca89d.sys [x]
R1 MpKsla6eb5529;MpKsla6eb5529;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{42856969-046F-4B84-8FB1-224C9CD8FEF9}\MpKsla6eb5529.sys [x]
R1 MpKsla8bd92e0;MpKsla8bd92e0;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{9A80888C-9BCC-4B5A-91D2-A9C8B2B73610}\MpKsla8bd92e0.sys [x]
R1 MpKslaa7e6e21;MpKslaa7e6e21;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{700105C8-1B6D-4E2B-93AE-72FA9B6412C5}\MpKslaa7e6e21.sys [x]
R1 MpKslac3b066d;MpKslac3b066d;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{C5F32350-1217-4952-80E3-186D08A3498D}\MpKslac3b066d.sys [x]
R1 MpKslac9b8d00;MpKslac9b8d00;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{6A668D94-5376-4165-807A-DC083761217F}\MpKslac9b8d00.sys [x]
R1 MpKslacd27da4;MpKslacd27da4;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{29B89742-21FC-4301-B3CD-C7F702C4F46E}\MpKslacd27da4.sys [x]
R1 MpKslaebb185f;MpKslaebb185f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{5F78D488-E291-45B6-9F70-F5ED37A004A4}\MpKslaebb185f.sys [x]
R1 MpKslaef5f872;MpKslaef5f872;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B946628E-6B8E-43E2-9079-D37886C6BEFD}\MpKslaef5f872.sys [x]
R1 MpKslaf814032;MpKslaf814032;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BB8B93BB-0C43-441E-AEB7-98C036F6E7A2}\MpKslaf814032.sys [x]
R1 MpKslafb126a7;MpKslafb126a7;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A1D2791E-5C09-4ECB-8DDB-26947C9CFC1C}\MpKslafb126a7.sys [x]
R1 MpKslb692fd8c;MpKslb692fd8c;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B60C39E8-43E6-49F2-AF18-3343C49204D0}\MpKslb692fd8c.sys [x]
R1 MpKslb77ce85f;MpKslb77ce85f;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CCC89A97-FE9A-4B04-8DE3-47576D9D01E3}\MpKslb77ce85f.sys [x]
R1 MpKslb7dafbde;MpKslb7dafbde;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A0178A7B-BC44-4E02-9709-9F6EFA52B993}\MpKslb7dafbde.sys [x]
R1 MpKslc0a20516;MpKslc0a20516;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{700105C8-1B6D-4E2B-93AE-72FA9B6412C5}\MpKslc0a20516.sys [x]
R1 MpKslc1491461;MpKslc1491461;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{73ADBEF7-C3AC-4470-B4B6-9C3133C1A845}\MpKslc1491461.sys [x]
R1 MpKslc3c3ed30;MpKslc3c3ed30;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{0C53135E-CC22-4D2E-A5E9-273E9594015F}\MpKslc3c3ed30.sys [x]
R1 MpKslc4f8a70b;MpKslc4f8a70b;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{0EAC248B-4EE6-43C4-8CF1-65216F2D37BD}\MpKslc4f8a70b.sys [x]
R1 MpKslca64f92d;MpKslca64f92d;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{0669A564-4BCD-4453-BCA6-6DD53627AC52}\MpKslca64f92d.sys [x]
R1 MpKsld1fc301a;MpKsld1fc301a;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2EFCFD4E-9CFA-4808-B842-E730AAE02541}\MpKsld1fc301a.sys [x]
R1 MpKsld2cd7195;MpKsld2cd7195;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{DD8905B9-A1CA-4DDD-9179-C6F477D0223B}\MpKsld2cd7195.sys [x]
R1 MpKsld37c3ca9;MpKsld37c3ca9;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F0314A68-6D35-4ABD-A967-791963B6E608}\MpKsld37c3ca9.sys [x]
R1 MpKsld96ea051;MpKsld96ea051;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{51D68E54-8F61-448D-B791-15FCDECCF86D}\MpKsld96ea051.sys [x]
R1 MpKsldad5cb0d;MpKsldad5cb0d;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{825718BB-C0E0-47BF-929A-82C842D0D327}\MpKsldad5cb0d.sys [x]
R1 MpKsldd9e3773;MpKsldd9e3773;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B19CBD82-9D3D-44CB-B675-F42AC35BEDE7}\MpKsldd9e3773.sys [x]
R1 MpKsle7c1a914;MpKsle7c1a914;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F2A0BF71-34B9-4E5D-8BB5-CCB7A3B1816B}\MpKsle7c1a914.sys [x]
R1 MpKsle9d5fb17;MpKsle9d5fb17;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{7EB1DC3F-16FA-45E0-87BC-782ABD2F9273}\MpKsle9d5fb17.sys [x]
R1 MpKslea202cbf;MpKslea202cbf;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{CC35ACB1-0E1E-452F-9215-62E7ECA2579D}\MpKslea202cbf.sys [x]
R1 MpKsleb09a783;MpKsleb09a783;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BAB95F0C-CD21-4F7A-A996-4FDA209EFB39}\MpKsleb09a783.sys [x]
R1 MpKslec7e53c4;MpKslec7e53c4;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{B8EADAB6-113A-4648-A9B5-24F16169D0C0}\MpKslec7e53c4.sys [x]
R1 MpKsleda90b15;MpKsleda90b15;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BB367FEC-34FD-4D30-82DA-4D2F5399066C}\MpKsleda90b15.sys [x]
R1 MpKslfea38e03;MpKslfea38e03;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{33CED062-425D-4950-9D9A-CB0B0EFDAAE1}\MpKslfea38e03.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 freenet;Freenet background service;c:\program files\Freenet\bin\wrapper-windows-x86-32.exe [x]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2011-09-02 2152152]
R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe [x]
R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [2011-04-23 15232]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2011-04-18 43392]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2011-04-27 65024]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 208944]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2008-01-21 16896]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2010-08-12 64288]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2011-10-23 232512]
S1 MpKsl12e0b3a2;MpKsl12e0b3a2;c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{F96A5E7E-859C-4727-808A-92ECD7C44E5C}\MpKsl12e0b3a2.sys [2011-12-21 29904]
S2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\IObit\Advanced SystemCare 4\ASCService.exe [2011-04-14 352144]
S2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\SMINST\BLService.exe [2008-10-06 365952]
S3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2008-06-29 112128]
S3 pcouffin;VSO Software pcouffin;c:\windows\system32\Drivers\pcouffin.sys [2011-08-01 47360]
.
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - 51847042
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2008-06-09 17:14 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-13 c:\windows\Tasks\HPCeeScheduleForChris.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2008-10-23 18:34]
.
2011-12-22 c:\windows\Tasks\User_Feed_Synchronization-{D3D9B8B4-E29C-47D8-BDC9-D29EFDBAE505}.job
- c:\windows\system32\msfeedssync.exe [2011-10-13 21:29]
.
.
------- Supplementary Scan -------
.
uStart Page = About:Blank
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
uInternet Settings,ProxyOverride = <local>;*.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.1.254
FF - ProfilePath - c:\users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\rk4i2as6.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF - prefs.js: keyword.URL - hxxp://search.bearshare.com/web?src=ffb&systemid=2&q=
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-12-21 19:39
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
.
c:\users\Chris\AppData\Local\Temp\catchme.dll 53248 bytes executable
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Norton Internet Security]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.0.0.125\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-12-21 19:49:07
ComboFix-quarantined-files.txt 2011-12-22 01:49
ComboFix2.txt 2011-12-14 23:56
ComboFix3.txt 2011-12-14 08:18
.
Pre-Run: 128,517,718,016 bytes free
Post-Run: 128,864,231,424 bytes free
.
- - End Of File - - 89D40987E1D668EB7F9646DA519CCECB