Hello,
Thank you for all the help. I did what you said. The ESET said therewere no infected files found. Below are the combofix and DDS logs.
Thanks!
ComboFix 11-05-19.02 - herecomesyourbride 05/21/2011 14:12:50.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.1013.394 [GMT -4:00]
Running from: c:\users\herecomesyourbride\Desktop\ComboFix.exe
Command switches used :: c:\users\herecomesyourbride\Desktop\CFScript.txt
AV: avast! antivirus *Disabled/Outdated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
SP: avast! antivirus *Disabled/Outdated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((( Files Created from 2011-04-21 to 2011-05-21 )))))))))))))))))))))))))))))))
.
.
2011-05-21 18:30 . 2011-05-21 18:31 -------- d-----w- c:\users\herecomesyourbride\AppData\Local\temp
2011-05-21 18:30 . 2011-05-21 18:31 -------- d-----w- c:\users\HERECO~1\AppData\Local\temp
2011-05-21 18:30 . 2011-05-21 18:30 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-05-19 01:11 . 2011-05-19 01:11 -------- d-sh--w- c:\users\herecomesyourbride\%APPDATA%
2011-05-19 00:06 . 2011-05-19 00:06 -------- d-----w- C:\%APPDATA%
2011-05-18 01:43 . 2011-04-18 13:15 7071056 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{595F2E56-6067-48E5-AFB2-2B280DB56BB3}\mpengine.dll
2011-05-11 12:33 . 2011-05-11 12:33 -------- d-----w- C:\968538762a2e98f29148d99eea6e7a
2011-05-11 12:33 . 2011-05-11 12:33 -------- d-----w- C:\1128504acd42e1c326b3
2011-05-11 12:33 . 2011-05-11 12:33 -------- d-----w- C:\_961618_
2011-05-11 12:18 . 2011-04-07 12:01 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-05-07 21:15 . 2011-03-12 21:55 876032 ----a-w- c:\windows\system32\XpsPrint.dll
2011-05-07 01:14 . 2011-03-03 15:40 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2011-05-07 01:14 . 2011-03-03 13:35 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2011-05-06 21:13 . 2011-05-06 21:13 -------- d-----w- c:\windows\en
2011-05-06 21:12 . 2010-09-23 04:21 39272 ----a-w- c:\windows\system32\drivers\fssfltr.sys
2011-05-06 21:08 . 2009-09-04 21:44 69464 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2011-05-06 21:08 . 2009-09-04 21:44 515416 ----a-w- c:\windows\system32\XAudio2_5.dll
2011-05-06 21:08 . 2009-09-04 21:29 453456 ----a-w- c:\windows\system32\d3dx10_42.dll
2011-05-06 14:30 . 2011-05-06 14:30 15712 ----a-w- c:\program files\Common Files\Windows Live\.cache\1a9595501cc0bfa1f\MeshBetaRemover.exe
2011-05-06 14:29 . 2011-05-06 14:29 94040 ----a-w- c:\program files\Common Files\Windows Live\.cache\f8de5b901cc0bf918\DSETUP.dll
2011-05-06 14:29 . 2011-05-06 14:29 525656 ----a-w- c:\program files\Common Files\Windows Live\.cache\f8de5b901cc0bf918\DXSETUP.exe
2011-05-06 14:29 . 2011-05-06 14:29 1691480 ----a-w- c:\program files\Common Files\Windows Live\.cache\f8de5b901cc0bf918\dsetup32.dll
2011-05-06 14:29 . 2011-05-06 14:29 94040 ----a-w- c:\program files\Common Files\Windows Live\.cache\f76642501cc0bf917\DSETUP.dll
2011-05-06 14:29 . 2011-05-06 14:29 525656 ----a-w- c:\program files\Common Files\Windows Live\.cache\f76642501cc0bf917\DXSETUP.exe
2011-05-06 14:29 . 2011-05-06 14:29 1691480 ----a-w- c:\program files\Common Files\Windows Live\.cache\f76642501cc0bf917\dsetup32.dll
2011-05-06 14:26 . 2011-05-06 14:26 -------- d-----w- c:\users\herecomesyourbride\AppData\Local\Windows Live
2011-05-06 14:26 . 2011-05-06 14:26 -------- d-----w- c:\users\HERECO~1\AppData\Local\Windows Live
2011-05-06 14:25 . 2009-08-04 08:02 754688 ----a-w- c:\windows\system32\webservices.dll
2011-05-06 14:13 . 2011-05-06 14:13 -------- d-----w- C:\b5392d0d3685782584a3c867805e
2011-05-06 13:56 . 2009-10-09 21:56 2048 ----a-w- c:\windows\system32\winrsmgr.dll
2011-05-06 13:56 . 2009-10-09 21:56 12800 ----a-w- c:\windows\system32\wsmprovhost.exe
2011-05-06 13:56 . 2009-10-09 21:56 20480 ----a-w- c:\windows\system32\winrshost.exe
2011-05-06 13:56 . 2009-10-09 21:56 40448 ----a-w- c:\windows\system32\winrs.exe
2011-05-06 13:56 . 2009-10-09 21:56 10240 ----a-w- c:\windows\system32\wsmplpxy.dll
2011-05-06 13:56 . 2009-10-09 21:56 10240 ----a-w- c:\windows\system32\winrssrv.dll
2011-05-06 13:56 . 2009-10-09 21:55 79872 ----a-w- c:\windows\system32\wecutil.exe
2011-05-06 13:56 . 2009-10-09 21:55 54272 ----a-w- c:\windows\system32\WsmRes.dll
2011-05-06 13:56 . 2009-10-09 21:55 146944 ----a-w- c:\windows\system32\wecsvc.dll
2011-05-06 13:56 . 2009-10-09 21:55 81408 ----a-w- c:\windows\system32\wevtfwd.dll
2011-05-06 13:56 . 2009-10-09 21:55 56320 ----a-w- c:\windows\system32\wecapi.dll
2011-05-06 13:56 . 2009-10-09 21:56 41472 ----a-w- c:\windows\system32\pwrshplugin.dll
2011-05-06 13:55 . 2009-08-01 06:27 201184 ----a-w- c:\windows\system32\winrm.vbs
2011-05-06 13:55 . 2009-10-09 21:56 145408 ----a-w- c:\windows\system32\WsmAuto.dll
2011-05-06 13:55 . 2009-10-09 21:56 214016 ----a-w- c:\windows\system32\WsmWmiPl.dll
2011-05-06 13:55 . 2009-10-09 21:56 241152 ----a-w- c:\windows\system32\winrscmd.dll
2011-05-06 13:55 . 2009-10-09 21:56 246272 ----a-w- c:\windows\system32\WSManHTTPConfig.exe
2011-05-06 13:55 . 2009-10-09 21:55 252416 ----a-w- c:\windows\system32\WSManMigrationPlugin.dll
2011-05-06 13:55 . 2009-10-09 21:56 1181696 ----a-w- c:\windows\system32\WsmSvc.dll
2011-05-06 13:08 . 2010-09-13 13:56 168960 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2011-05-06 13:07 . 2010-09-13 13:56 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2011-05-06 13:07 . 2010-09-06 16:20 125952 ----a-w- c:\windows\system32\srvsvc.dll
2011-05-06 13:07 . 2010-09-06 16:19 17920 ----a-w- c:\windows\system32\netevent.dll
2011-05-06 13:07 . 2010-10-12 15:53 33280 ----a-w- c:\program files\Windows Mail\wabfind.dll
2011-05-06 13:07 . 2010-10-12 13:41 66048 ----a-w- c:\program files\Windows Mail\wabmig.exe
2011-05-06 13:07 . 2010-10-12 13:41 515584 ----a-w- c:\program files\Windows Mail\wab.exe
2011-05-06 13:05 . 2011-03-10 17:03 1162240 ----a-w- c:\windows\system32\mfc42u.dll
2011-05-06 13:04 . 2010-10-19 04:27 7680 ----a-w- c:\program files\Internet Explorer\iecompat.dll
2011-05-06 13:04 . 2010-08-26 16:37 157184 ----a-w- c:\windows\system32\t2embed.dll
2011-05-06 13:04 . 2011-03-03 13:25 2041856 ----a-w- c:\windows\system32\win32k.sys
2011-05-06 13:04 . 2010-12-14 14:49 1169408 ----a-w- c:\windows\system32\sdclt.exe
2011-05-06 13:04 . 2010-08-26 16:34 1696256 ----a-w- c:\windows\system32\gameux.dll
2011-05-06 13:02 . 2010-11-04 18:55 601600 ----a-w- c:\windows\system32\schedsvc.dll
2011-05-06 13:02 . 2010-11-04 18:55 352768 ----a-w- c:\windows\system32\taskschd.dll
2011-05-06 13:02 . 2010-11-04 18:56 345600 ----a-w- c:\windows\system32\wmicmiplugin.dll
2011-05-06 13:02 . 2010-11-04 18:55 270336 ----a-w- c:\windows\system32\taskcomp.dll
2011-05-06 13:02 . 2010-11-04 16:34 171520 ----a-w- c:\windows\system32\taskeng.exe
2011-05-06 13:02 . 2010-10-18 13:37 81920 ----a-w- c:\windows\system32\consent.exe
2011-05-06 13:02 . 2010-10-28 13:20 2048 ----a-w- c:\windows\system32\tzres.dll
2011-05-06 13:01 . 2010-12-17 15:45 2067968 ----a-w- c:\windows\system32\mstscax.dll
2011-05-06 13:01 . 2010-12-17 13:54 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-05-06 13:01 . 2010-08-31 15:44 531968 ----a-w- c:\windows\system32\comctl32.dll
2011-05-06 13:01 . 2010-05-04 19:13 231424 ----a-w- c:\windows\system32\msshsq.dll
2011-04-29 18:48 . 2011-04-29 19:46 -------- d-----w- C:\DESKTOP BEFORE FIX
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-06 21:09 . 2010-06-24 15:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-03-03 15:40 . 2011-05-07 01:14 173056 ----a-w- c:\windows\apppatch\AcXtrnal.dll
2011-03-03 15:40 . 2011-05-07 01:14 458752 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2011-03-03 15:40 . 2011-05-07 01:14 542720 ----a-w- c:\windows\apppatch\AcLayers.dll
2011-03-03 15:40 . 2011-05-07 01:14 2159616 ----a-w- c:\windows\apppatch\AcGenral.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]
"eFax 4.4"="c:\program files\eFax Messenger 4.4\J2GDllCmd.exe" [2008-10-07 95744]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-03-20 1451304]
"RtHDVCpl"="RtHDVCpl.exe" [2006-11-09 3784704]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2005-12-16 188416]
"NDSTray.exe"="NDSTray.exe" [BU]
"HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2006-11-01 413696]
"SVPWUTIL"="c:\program files\TOSHIBA\Utilities\SVPWUTIL.exe" [2006-01-19 421888]
"KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2006-11-07 34352]
"PINGER"="c:\toshiba\IVP\ISM\pinger.exe" [2006-07-20 151552]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-03-06 29744]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-02-16 282624]
"DACSMiniApp"="c:\program files\Fisher-Price\DACS\MiniApp\DACSMiniApp.exe" [2007-08-24 197888]
"TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2007-10-12 431456]
"HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2007-11-01 54608]
"SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2007-06-16 448080]
"00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2007-10-11 712704]
"ToolBoxFX"="c:\program files\HP\ToolBoxFX\bin\HPTLBXFX.exe" [2007-08-28 53248]
"hpbdfawep"="c:\program files\HP\Dfawep\bin\hpbdfawep.exe" [2007-04-25 954368]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-12 49152]
"HPUsageTracking"="c:\program files\HP\HP UT\bin\hppusg.exe" [2007-05-08 36864]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-12 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-12 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-12 133656]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-03 233304]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
.
c:\users\herecomesyourbride\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
GameSpot Download Manager.lnk - c:\users\herecomesyourbride\GameSpot\GameSpotDownloadManager_Win32.exe [N/A]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 GoogleDesktopManager-022208-143751;Google Desktop Manager 5.7.802.22438;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2008-03-06 29744]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S1 aswSP;avast! Self Protection; [x]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2009-11-24 20560]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\DRIVERS\aswMonFlt.sys [2009-11-24 53328]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2008-11-17 3668480]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2011-05-21 c:\windows\Tasks\HP WEP.job
- c:\program files\HP\Dfawep\bin\hpbdfawep.exe [2007-04-25 19:28]
.
2011-05-21 c:\windows\Tasks\User_Feed_Synchronization-{EA109B87-7A20-427B-AD64-6D7FEB8891C9}.job
- c:\windows\system32\msfeedssync.exe [2011-05-06 04:43]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
Trusted Zone: aim.com\www
Trusted Zone: aol.com\aimexpress
Trusted Zone: aol.com\aimx-vma.aimexpress
Trusted Zone: indwes.edu\blackboard
Trusted Zone: indwes.edu\www.blackboard
DPF: {BCBC9371-9827-11DA-A72B-0800200C9A66} - hxxp://merillat.view22.com/release_3_9_177/View22RTEv4.cab
FF - ProfilePath - c:\users\herecomesyourbride\AppData\Roaming\Mozilla\Firefox\Profiles\bke4vihn.default\
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
FF - user.js: yahoo.homepage.dontask - true
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-05-21 14:30
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Completion time: 2011-05-21 14:41:02
ComboFix-quarantined-files.txt 2011-05-21 18:40
ComboFix2.txt 2011-05-19 00:41
.
Pre-Run: 85,819,224,064 bytes free
Post-Run: 85,155,545,088 bytes free
.
- - End Of File - - 6087511F262B13E087BCED049433FDCC