Hey,
Funny, ComboFix only seems to work after midnight! Sorry it took so long, but here is the new ComboFix log. Thanks for the patience.
ComboFix 09-12-04.02 - The Coppola's 12/05/2009 0:11.38.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1014.433 [GMT -5:00]
Running from: c:\users\The Coppola's\Desktop\ComboFix.exe
SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\programdata\Microsoft\WLSetup
c:\programdata\Microsoft\WLSetup\Logs\2009-04-08_20-41_14b4-cxj3timt.log
c:\programdata\Microsoft\WLSetup\wlt5BBA.tmp
.
((((((((((((((((((((((((( Files Created from 2009-11-05 to 2009-12-05 )))))))))))))))))))))))))))))))
.
2009-12-05 05:27 . 2009-12-05 05:33 -------- d-----w- c:\users\The Coppola's\AppData\Local\temp
2009-12-05 05:27 . 2009-12-05 05:27 -------- d-----w- c:\users\Public\AppData\Local\temp
2009-12-05 05:27 . 2009-12-05 05:27 -------- d-----w- c:\users\Mcx2\AppData\Local\temp
2009-12-05 05:27 . 2009-12-05 05:27 -------- d-----w- c:\users\Mcx1\AppData\Local\temp
2009-12-05 05:27 . 2009-12-05 05:27 -------- d-----w- c:\users\IUSR_NMPR\AppData\Local\temp
2009-12-05 05:27 . 2009-12-05 05:27 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-12-02 05:42 . 2009-12-05 04:57 -------- d-----w- c:\program files\Common Files\PC Tools
2009-11-29 13:58 . 2009-11-29 13:58 -------- d-----w- c:\users\The Coppola's\AppData\Local\Apps
2009-11-27 07:15 . 2009-11-03 01:42 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-11-25 08:01 . 2009-10-29 09:41 2048 ----a-w- c:\windows\system32\tzres.dll
2009-11-24 21:21 . 2009-08-10 11:01 1399296 ----a-w- c:\windows\system32\msxml6.dll
2009-11-24 21:21 . 2009-08-10 11:00 1257472 ----a-w- c:\windows\system32\msxml3.dll
2009-11-20 01:50 . 2009-11-20 01:56 4096 d-----w- c:\program files\ERUNT
2009-11-20 01:14 . 2009-11-20 01:14 -------- d-----w- c:\users\The Coppola's\AppData\Local\PackageAware
2009-11-20 01:07 . 2001-10-04 05:14 184320 ----a-w- c:\windows\system32\wzcsvc.dll
2009-11-19 14:55 . 2009-11-19 14:55 439816 ----a-w- c:\users\The Coppola's\AppData\Roaming\Real\Update\recsetup\setup.exe
2009-11-19 14:55 . 2009-11-19 14:55 118784 ----a-w- c:\users\The Coppola's\AppData\Roaming\Real\Update\recsetup\install.dll
2009-11-16 21:21 . 2009-11-16 21:21 -------- d-----w- c:\programdata\IObit
2009-11-16 21:21 . 2009-11-16 21:21 -------- d-----w- c:\program files\IObit
2009-11-16 21:03 . 2009-11-16 21:03 -------- d-----w- c:\program files\Trend Micro
2009-11-11 04:19 . 2009-08-14 13:53 2035712 ----a-w- c:\windows\system32\win32k.sys
2009-11-11 04:19 . 2009-08-10 13:05 351232 ----a-w- c:\windows\system32\WSDApi.dll
2009-11-05 14:09 . 2009-11-05 14:12 4096 d-----w- c:\program files\TweakNow PowerPack 2009
2009-11-05 14:09 . 2009-11-05 14:09 -------- d-----w- c:\users\The Coppola's\AppData\Roaming\TweakNow PowerPack 2009
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-04 19:55 . 2008-11-26 04:33 4096 d-----w- c:\programdata\Google Updater
2009-12-04 14:32 . 2008-11-26 04:33 4096 d-----w- c:\program files\Google
2009-11-27 02:31 . 2007-10-17 21:01 4096 d-----w- c:\programdata\McAfee
2009-11-27 02:27 . 2007-03-09 11:38 8192 d--h--w- c:\program files\InstallShield Installation Information
2009-11-27 02:26 . 2007-03-09 12:04 16384 d-----w- c:\program files\Common Files\Symantec Shared
2009-11-27 02:26 . 2007-03-09 12:04 4096 d-----w- c:\programdata\Symantec
2009-11-27 02:21 . 2007-06-08 00:09 12288 d-----w- c:\program files\Spybot - Search & Destroy
2009-11-27 02:20 . 2007-06-08 00:09 4096 d-----w- c:\programdata\Spybot - Search & Destroy
2009-11-27 02:14 . 2007-06-08 00:16 4096 d-----w- c:\programdata\Lavasoft
2009-11-11 08:20 . 2006-11-02 11:18 4096 d-----w- c:\program files\Windows Mail
2009-11-11 08:04 . 2009-04-08 21:59 12288 d-----w- c:\programdata\Microsoft Help
2009-11-05 01:11 . 2009-11-05 01:11 93360 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2009-10-20 21:46 . 2009-10-09 03:47 7 ----a-w- c:\windows\sbacknt.bin
2009-10-20 18:07 . 2009-10-20 15:31 -------- d-----w- c:\program files\adnqbh
2009-10-16 07:07 . 2007-03-09 11:57 24576 d-----w- c:\program files\Microsoft Works
2009-10-09 03:47 . 2009-10-09 03:47 152904 ----a-w- c:\windows\system32\vghd.scr
2009-09-14 09:44 . 2009-10-16 03:05 144896 ----a-w- c:\windows\system32\drivers\srv2.sys
2009-09-10 17:30 . 2009-10-16 03:06 213504 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-10 15:21 . 2009-10-28 02:35 8147456 ----a-w- c:\windows\system32\wmploc.DLL
2009-09-10 15:21 . 2009-10-28 02:35 310784 ----a-w- c:\windows\system32\unregmp2.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CCUTRAYICON"="FactoryMode" [X]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2006-09-28 65536]
"KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-02-05 849280]
"Monitor"="c:\program files\LeapFrog\LeapFrog Connect\Monitor.exe" [2009-05-07 380928]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-06-19 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-06-19 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-06-19 133656]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-01-15 4874240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-25 44136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
R2 DQLWinService;DQLWinService;c:\program files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [9/3/2006 1:32 PM 208896]
S2 gupdate1c9e122120b6107;Google Update Service (gupdate1c9e122120b6107);c:\program files\Google\Update\GoogleUpdate.exe [5/30/2009 7:27 AM 133104]
S2 IntelDHSvcConf;Intel DH Service;c:\program files\Intel\IntelDH\Intel Media Server\tools\IntelDHSvcConf.exe [5/10/2006 12:13 PM 29696]
S3 FlyUsb;FLY Fusion;c:\windows\System32\drivers\FlyUsb.sys [11/25/2008 12:39 PM 19456]
S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [4/8/2009 7:50 PM 55280]
S3 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [2/6/2009 5:08 PM 533360]
.
Contents of the 'Scheduled Tasks' folder
2009-12-05 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-11-26 22:35]
2009-12-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-30 12:27]
2009-12-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-30 12:27]
2009-12-04 c:\windows\Tasks\User_Feed_Synchronization-{9F21EFA2-5087-4B5C-8230-A912354043C1}.job
- c:\windows\system32\msfeedssync.exe [2009-10-16 03:41]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
Trusted Zone: turbotax.com
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-12-05 00:30
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x844D450C]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0x861a3322
\Driver\ACPI -> acpi.sys @ 0x8069dd4c
\Driver\atapi -> ataport.SYS @ 0x828d79a8
\Driver\iaStor -> iastor.sys @ 0x8283ed94
IoDeviceObjectType ->\Device\Harddisk0\DR0 ->user & kernel MBR OK
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'Explorer.exe'(3772)
c:\program files\Hewlett-Packard\HP Advisor\Pillars\Market\MLDeskBand.dll
c:\windows\system32\ieframe.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Google\Update\1.2.183.13\GoogleCrashHandler.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\ehome\ehmsas.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\program files\Windows Media Player\wmpnscfg.exe
c:\program files\Windows Media Player\wmpnetwk.exe
.
**************************************************************************
.
Completion time: 2009-12-05 00:41 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-05 05:41
Pre-Run: 95,390,457,856 bytes free
Post-Run: 95,339,704,320 bytes free
- - End Of File - - BAADF4E2C548029ECD550E695D3C1E37