Hi, I beleive I deleted the J2Se earlier in the thread when you asked me to. To be sure, I checked under Add/Remove Programs in Control Panel, Program Files in C drive, and then ran Search looking for any file or folder with J2SE Runtime in it. I'm not sure where else to look for it, but clearly its shown in the DDS log you asked me to create. Here is the Combo log, thanks
ComboFix 09-10-16.09 - R 10/16/2009 23:38.4.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.608 [GMT -5:00]
Running from: c:\documents and settings\R\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\R\Desktop\CFScript.txt
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall Plus *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\spybot - search & destroy
c:\program files\spybot - search & destroy\SDUpdate.exe
c:\program files\spybot - search & destroy\SpybotSD.exe
c:\program files\spybot - search & destroy\XASMBADJGQONFAQ.scr
.
((((((((((((((((((((((((( Files Created from 2009-09-17 to 2009-10-17 )))))))))))))))))))))))))))))))
.
2009-10-14 17:23 . 2009-10-14 17:23 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-10-06 14:33 . 2009-09-10 19:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-06 14:33 . 2009-10-06 14:34 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-06 14:33 . 2009-09-10 19:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-02 02:37 . 2009-10-02 02:37 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-02 01:59 . 2009-10-02 01:59 -------- d-----w- c:\documents and settings\R\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-10-02 01:55 . 2009-10-02 01:55 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-10-02 01:53 . 2009-10-02 02:34 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-10-01 10:50 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\proquota.exe
2009-10-01 10:50 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\dllcache\proquota.exe
2009-09-28 09:21 . 2009-09-28 09:21 -------- d-----w- c:\documents and settings\R\DoctorWeb
2009-09-28 02:24 . 2009-09-28 02:24 -------- d-----w- c:\program files\ESET
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-14 19:28 . 2009-06-15 23:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-10-03 00:50 . 2006-05-10 23:28 -------- d-----w- c:\program files\Java
2009-10-02 02:04 . 2006-05-18 08:58 -------- d-----w- c:\program files\Common Files\Adobe
2009-09-14 12:15 . 2008-02-09 20:33 -------- d-----w- c:\program files\Lavasoft
2009-09-14 12:15 . 2009-09-14 12:15 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-09-14 04:46 . 2009-09-14 04:46 -------- d-----w- c:\program files\Trend Micro
2009-08-09 05:53 . 2007-02-20 08:02 56 --sh--r- c:\windows\system32\5DAA50A8B0.sys
2009-08-09 05:53 . 2006-07-03 06:11 7518 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-08-07 00:24 . 2005-08-16 09:40 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-07 00:24 . 2005-08-16 09:40 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-07 00:24 . 2005-08-16 09:40 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-07 00:24 . 2005-05-26 09:16 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-07 00:24 . 2005-08-16 09:40 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-08-07 00:24 . 2005-08-16 09:18 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-07 00:23 . 2005-08-16 09:40 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-07 00:23 . 2005-08-16 09:40 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-08-05 09:01 . 2005-08-16 09:18 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2006-11-23 17:05 . 2006-07-03 06:11 88 --sh--r- c:\windows\system32\B0A850AA5D.sys
.
((((((((((((((((((((((((((((( SnapShot@2009-10-01_10.53.33 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-10-07 02:30 . 2009-08-07 00:24 44768 c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.4.7600.226\wups2.dll
+ 2009-10-07 02:30 . 2009-08-07 00:24 35552 c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.4.7600.226\wups.dll
+ 2005-08-16 09:40 . 2009-08-07 00:24 35552 c:\windows\system32\dllcache\wups.dll
+ 2005-08-16 09:40 . 2009-08-07 00:24 53472 c:\windows\system32\dllcache\wuauclt.exe
+ 2005-08-16 09:18 . 2009-08-07 00:24 96480 c:\windows\system32\dllcache\cdm.dll
+ 2009-10-02 01:55 . 2009-10-02 01:55 21504 c:\windows\Installer\80d60.msi
+ 2009-10-02 01:55 . 2009-10-02 01:55 27648 c:\windows\Installer\80d5b.msi
+ 2009-10-02 02:37 . 2009-10-02 02:37 149280 c:\windows\system32\javaws.exe
+ 2009-10-02 02:37 . 2009-10-02 02:37 145184 c:\windows\system32\javaw.exe
+ 2009-10-02 02:37 . 2009-10-02 02:37 145184 c:\windows\system32\java.exe
+ 2005-08-16 09:40 . 2009-08-07 00:24 209632 c:\windows\system32\dllcache\wuweb.dll
+ 2005-08-16 09:40 . 2009-08-07 00:24 327896 c:\windows\system32\dllcache\wucltui.dll
+ 2005-08-16 09:40 . 2009-08-07 00:23 575704 c:\windows\system32\dllcache\wuapi.dll
+ 2009-10-02 02:15 . 2009-10-02 02:15 802304 c:\windows\Installer\80e1b.msi
+ 2009-10-02 02:15 . 2009-10-02 02:15 295606 c:\windows\Installer\{AC76BA86-7AD7-5464-3428-900000000004}\ARPPRODUCTICON.exe
+ 2006-04-10 18:00 . 2008-03-20 23:06 1480232 c:\windows\system32\LegitCheckControl.dll
+ 2005-08-16 09:40 . 2009-08-07 00:23 1929952 c:\windows\system32\dllcache\wuaueng.dll
+ 2009-10-17 04:25 . 2009-10-17 04:25 3940352 c:\windows\Installer\d39bf7.msi
+ 2009-10-02 02:37 . 2009-10-02 02:37 1757696 c:\windows\Installer\39031.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="c:\program files\NetWaiting\netWaiting.exe" [2003-09-10 20480]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"Universal Installer"="c:\program files\ComcastUI\Universal Installer\uinstaller.exe" [2008-03-18 984616]
"PcSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 1449984]
"Desktop Software"="c:\program files\ComcastUI\Universal Installer\uinstaller.exe" [2008-03-18 984616]
"AOL Fast Start"="c:\program files\AOL 9.1\AOL.EXE" [2008-06-03 50528]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShowLOMControl"="1 (0x1)" [X]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-14 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-14 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-14 118784]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2005-12-19 1347584]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2005-12-06 839680]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-11-29 761947]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-10 49152]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"VSOCheckTask"="c:\progra~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 151552]
"OASClnt"="c:\program files\McAfee.com\VSO\oasclnt.exe" [2005-08-12 53248]
"MCAgentExe"="c:\progra~1\mcafee.com\agent\mcagent.exe" [2005-09-22 303104]
"MCUpdateExe"="c:\progra~1\mcafee.com\agent\mcupdate.exe" [2006-01-11 212992]
"MSKDetectorExe"="c:\progra~1\McAfee\SPAMKI~1\MSKDetct.exe" [2005-08-12 1121792]
"MSKAGENTEXE"="c:\progra~1\McAfee\SPAMKI~1\MskAgent.exe" [2005-09-26 110592]
"VirusScan Online"="c:\program files\McAfee.com\VSO\mcvsshld.exe" [2005-08-10 163840]
"MPFExe"="c:\progra~1\McAfee.com\PERSON~1\MpfTray.exe" [2005-11-11 1005096]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-05-10 98304]
"AOLDialer"="c:\program files\Common Files\AOL\ACS\AOLDial.exe" [2006-10-23 71216]
"HostManager"="c:\program files\Common Files\AOL\1170845904\ee\AOLSoftware.exe" [2008-06-24 41824]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"ddoctorv2"="c:\program files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2008-04-24 202560]
"PCSuiteTrayApplication"="c:\program files\Nokia\Nokia PC Suite 6\LaunchApplication.exe" [2006-06-15 229376]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-02 149280]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2005-11-17 397312]
c:\documents and settings\R\Start Menu\Programs\Startup\
RT-Updater.lnk - c:\ross-tech\VCDS\VCDS.exe [2008-8-14 1046016]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-5-10 24576]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2003-6-25 614531]
KODAK Software Updater.lnk - c:\program files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe [2003-6-8 16432]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Common Files\\AOL\\1170845904\\ee\\aolsoftware.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\backWeb-7288971.exe"=
"c:\\Program Files\\AOL 9.1\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
S3 RT-USB;Ross-Tech USB driver;c:\windows\system32\drivers\RT-USB.SYS [2/23/2008 5:00 AM 54400]
S3 VAGUSB;VAGUSB.SYS USB Driver;c:\windows\system32\drivers\VAGUSB.sys [12/15/2005 9:27 AM 34639]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - ATWPKT2
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
BtwSrv
.
Contents of the 'Scheduled Tasks' folder
2009-10-17 c:\windows\Tasks\McAfee.com Scan for Viruses - My Computer (1BRR9A1-R).job
- c:\program files\mcafee.com\vso\mcmnhdlr.exe [2006-05-10 23:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://google.com/
uInternet Connection Wizard,ShellNext = hxxp://www.dell.com/
uInternet Settings,ProxyOverride = localhost
Trusted Zone: musicmatch.com\online
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-SpybotSD TeaTimer - c:\program files\Spybot - Search & Destroy\TeaTimer.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-10-16 23:42
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(892)
c:\windows\System32\BCMLogon.dll
.
Completion time: 2009-10-17 23:44
ComboFix-quarantined-files.txt 2009-10-17 04:44
ComboFix2.txt 2009-10-03 01:01
ComboFix3.txt 2009-10-02 01:29
ComboFix4.txt 2009-10-01 11:00
Pre-Run: 16,715,857,920 bytes free
Post-Run: 16,666,382,336 bytes free
190 --- E O F --- 2009-09-10 20:48