Getting there
I disabled the Comodo anti-virus program, got my computer offline, and finally was able to run the Combofix. While some things on the computer seem to be running better, and that big red circle with the white X in the bottom right corner is GONE, along with that pesty message that kept popping up, all last night and this morning, the computer kept restarting on its own. It took quite a few attempts to finally have Combofix run all the way through, but it finally did. I'll paste the log here:
ComboFix 08-08-14.02 - Owner 2008-08-15 8:22:11.2 - NTFSx86
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\dllcache\npptools.dll
C:\WINDOWS\system32\npptools.dll
.
---- Previous Run -------
.
C:\Documents and Settings\Betsy.YOUR-US67PI6LUV\Application Data\macromedia\Flash Player\#SharedObjects\DJZ22NXW\interclick.com
C:\Documents and Settings\Betsy.YOUR-US67PI6LUV\Application Data\macromedia\Flash Player\#SharedObjects\DJZ22NXW\interclick.com\ud.sol
C:\Documents and Settings\Betsy.YOUR-US67PI6LUV\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Betsy.YOUR-US67PI6LUV\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\WINDOWS\g32.txt
C:\WINDOWS\jestertb.dll
C:\WINDOWS\system32\dllcache\npptools.dll
C:\WINDOWS\system32\k86.bin
C:\WINDOWS\system32\karina.dat
C:\WINDOWS\system32\msssc.dll
C:\WINDOWS\system32\npptools.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ASPIMGR
-------\Legacy_ASPIMGR
((((((((((((((((((((((((( Files Created from 2008-07-15 to 2008-08-15 )))))))))))))))))))))))))))))))
.
2008-08-14 23:31 . 2008-08-14 23:31 50,688 --a------ C:\Program Files\ATF-Cleaner.exe
2008-08-14 12:49 . 2008-08-14 12:49 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-14 12:10 . 2001-08-18 08:00 4,224 --a------ C:\WINDOWS\system32\drivers\beep.sys
2008-08-14 12:10 . 2001-08-18 08:00 4,224 --a--c--- C:\WINDOWS\system32\dllcache\beep.sys
2008-08-14 09:09 . 2008-08-14 09:09 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-08-14 09:07 . 2008-08-14 09:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-14 09:07 . 2008-07-30 20:07 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-14 09:07 . 2008-07-30 20:07 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-08-14 09:05 . 2008-08-14 09:07 <DIR> d-------- C:\Program Files\Malwarebytes
2008-08-08 22:41 . 2008-08-08 22:42 382,352 --a------ C:\Program Files\jre-6u7-windows-i586-p-iftw.exe
2008-08-08 07:23 . 2008-08-08 07:23 42,496 --a------ C:\Fixing computer instructions.doc
2008-08-08 07:12 . 2008-08-08 07:12 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Motive
2008-08-06 20:52 . 2008-08-06 20:52 15,083,520 --a------ C:\Program Files\spybotsd160.exe
2008-08-06 07:48 . 2008-08-14 21:37 7 --a------ C:\WINDOWS\system32\ngxt.bin
2008-08-05 22:10 . 2008-08-07 19:26 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Spyware Terminator
2008-08-05 20:30 . 2008-08-05 20:30 8,560 --a------ C:\WINDOWS\system32\core3.sys
2008-08-04 21:23 . 2008-08-04 21:23 <DIR> d-------- C:\Program Files\New Folder
2008-07-31 11:03 . 2008-07-31 11:03 <DIR> d-------- C:\Program Files\Disney
2008-07-29 23:01 . 2008-07-29 23:01 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Yahoo!
2008-07-27 17:36 . 2004-08-03 14:04 185,624 --a------ C:\WINDOWS\system32\iuengine.dll
2008-07-27 17:36 . 2004-08-03 14:04 185,624 --a--c--- C:\WINDOWS\system32\dllcache\iuengine.dll
2008-07-27 17:26 . 2008-07-27 17:26 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Microsoft Web Folders
2008-07-25 23:31 . 2008-07-25 23:31 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\Aim
2008-07-25 21:56 . 2001-08-17 22:24 135,040 --a------ C:\WINDOWS\system32\drivers\portcls.sys
2008-07-25 21:56 . 2001-08-17 22:24 134,144 --a------ C:\WINDOWS\system32\drivers\ks.sys
2008-07-25 21:56 . 2001-08-17 22:37 117,248 --a------ C:\WINDOWS\system32\ksproxy.ax
2008-07-25 21:56 . 2001-08-17 14:01 57,344 --a------ C:\WINDOWS\system32\drivers\drmk.sys
2008-07-25 21:56 . 2001-08-17 14:01 42,752 --a------ C:\WINDOWS\system32\drivers\stream.sys
2008-07-25 21:56 . 2001-08-17 22:37 22,016 --a------ C:\WINDOWS\system32\wdmaud.drv
2008-07-25 21:56 . 2001-08-17 22:36 4,096 --a------ C:\WINDOWS\system32\ksuser.dll
2008-07-22 20:55 . 2008-07-22 20:55 <DIR> d-------- C:\Documents and Settings\Betsy.YOUR-US67PI6LUV.000\Application Data\FUJIFILM
2008-07-21 20:47 . 2008-07-21 20:47 <DIR> d-------- C:\Documents and Settings\Betsy.YOUR-US67PI6LUV.000\Application Data\ACD Systems
2008-07-21 08:27 . 2008-07-21 08:27 <DIR> d-------- C:\Documents and Settings\Betsy.YOUR-US67PI6LUV.000\Application Data\Microsoft Web Folders
2008-07-20 23:34 . 2008-07-21 16:40 <DIR> d-------- C:\Documents and Settings\Betsy.YOUR-US67PI6LUV.000\Application Data\Spyware Terminator
2008-07-20 23:33 . 2008-07-20 23:33 <DIR> d-------- C:\TBR5LanguageAct
2008-07-20 23:33 . 2008-07-20 23:33 <DIR> d-------- C:\Languages
2008-07-20 23:10 . 2002-07-27 00:24 <DIR> d-------- C:\Documents and Settings\Betsy.YOUR-US67PI6LUV.000\WINDOWS
2008-07-20 23:10 . 2008-07-21 21:15 <DIR> d-------- C:\Documents and Settings\Betsy.YOUR-US67PI6LUV.000\Application Data\VERITAS
2008-07-20 23:10 . 2002-07-27 00:23 <DIR> d-------- C:\Documents and Settings\Betsy.YOUR-US67PI6LUV.000\Application Data\Symantec
2008-07-20 23:10 . 2002-07-27 00:23 <DIR> d-------- C:\Documents and Settings\Betsy.YOUR-US67PI6LUV.000\Application Data\Share-to-Web Upload Folder
2008-07-20 23:10 . 2002-07-27 00:23 <DIR> d-------- C:\Documents and Settings\Betsy.YOUR-US67PI6LUV.000\Application Data\InterTrust
2008-07-20 23:10 . 2008-07-21 08:44 <DIR> d-------- C:\Documents and Settings\Betsy.YOUR-US67PI6LUV.000
2008-07-20 21:40 . 2004-07-15 15:44 18,939 --a------ C:\WINDOWS\hpbvspst.hi2
2008-07-20 21:40 . 2004-07-15 15:44 478 --a------ C:\WINDOWS\hpbvspst.bu2
2008-07-20 21:39 . 2001-07-21 14:40 3,144 --a--c--- C:\WINDOWS\system32\dllcache\srgb.icm
2008-07-19 21:36 . 2008-07-19 22:07 <DIR> d-------- C:\Program Files\Crawler
2008-07-19 17:49 . 2008-08-07 19:26 <DIR> d-------- C:\Program Files\Spyware Terminator
2008-07-19 17:49 . 2008-07-19 22:01 <DIR> d-------- C:\Documents and Settings\Betsy.YOUR-US67PI6LUV\Application Data\Spyware Terminator
2008-07-19 17:49 . 2008-08-07 19:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2008-07-19 17:49 . 2008-07-19 17:49 141,312 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-07-19 17:46 . 2008-07-19 17:46 8,160,016 --a------ C:\Program Files\SpywareTerminatorSetup.exe
2008-07-19 13:33 . 2008-07-19 13:34 <DIR> d--h-c--- C:\WINDOWS\$xpsp1hfm$
2008-07-17 23:34 . 2004-09-20 15:20 16,121,856 --------- C:\WINDOWS\system32\alsndmgr.cpl
2008-07-17 23:34 . 2004-09-21 11:13 9,196,032 --------- C:\WINDOWS\system32\RTLCPL.exe
2008-07-17 23:34 . 2004-10-01 10:24 2,279,424 --------- C:\WINDOWS\system32\drivers\alcxwdm.sys
2008-07-17 23:34 . 2004-09-10 10:12 208,896 --------- C:\WINDOWS\alcupd.exe
2008-07-17 23:34 . 2004-09-07 14:23 156,672 --------- C:\WINDOWS\system32\RtlCPAPI.dll
2008-07-17 23:34 . 2002-02-05 13:54 141,016 --------- C:\WINDOWS\system32\alsndmgr.wav
2008-07-17 23:34 . 2004-09-01 20:04 139,264 --------- C:\WINDOWS\alcrmv.exe
2008-07-17 23:34 . 2004-09-16 20:39 69,632 --------- C:\WINDOWS\soundman.exe
2008-07-17 23:34 . 2004-09-07 13:47 57,344 --------- C:\WINDOWS\Alcxmntr.exe
2008-07-17 23:34 . 2004-02-25 18:00 40,448 --------- C:\WINDOWS\system32\ChCfg.exe
2008-07-17 21:55 . 2008-07-17 21:55 2,369,474 --a------ C:\Project1.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-08 02:36 --------- d---a-w C:\Program Files\WildTangent
2008-08-06 21:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-06 00:29 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-08-05 02:03 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-04 21:40 --------- d-----w C:\Program Files\PicturesToExe
2008-07-31 13:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-07-29 23:51 --------- d-----w C:\Program Files\Common Files\ACD Systems
2008-07-29 23:48 --------- d-----w C:\Program Files\ACD Systems
2008-07-28 11:45 73,728 ----a-w C:\WINDOWS\system32\CavEmLSP.dll
2008-07-28 11:45 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-07-28 11:45 434,252 ----a-w C:\WINDOWS\system32\MSVCRTD.DLL
2008-07-28 11:45 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-07-28 11:45 216,576 ----a-w C:\WINDOWS\system32\monln.dll
2008-07-28 11:45 102,400 ----a-w C:\WINDOWS\system32\drivers\cavasm.sys
2008-07-28 11:45 1,060,864 ----a-w C:\WINDOWS\system32\MFC71.dll
2008-07-27 21:25 --------- d-----w C:\Program Files\microsoft frontpage
2008-07-23 00:55 --------- d-----w C:\Program Files\FinePixViewer
2008-07-21 12:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\BOC426
2008-07-21 03:38 --------- d-----w C:\Program Files\SymNetDrv
2008-07-19 22:34 --------- d-----w C:\Program Files\FileSubmit
2008-07-19 21:55 --------- d-----w C:\Program Files\Viewpoint
2008-07-19 21:55 --------- d-----w C:\Program Files\Lycos
2008-07-14 15:56 --------- d-----w C:\Program Files\WildGames
2008-07-12 20:38 --------- d-----w C:\Documents and Settings\Betsy.YOUR-US67PI6LUV\Application Data\Viewpoint
2008-07-11 01:25 --------- d-----w C:\Program Files\Coupons
2008-07-11 01:23 1,277,680 ----a-w C:\Program Files\CouponPrinter.exe
2008-07-10 01:57 --------- d-----w C:\Program Files\AIM6
2008-07-10 01:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-07-10 01:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
2008-07-10 01:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL Downloads
2008-07-10 01:47 --------- d-----w C:\Documents and Settings\Betsy.YOUR-US67PI6LUV\Application Data\acccore
2008-07-08 11:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\NOS
2008-07-08 11:21 --------- d-----w C:\Program Files\Common Files\Adobe AIR
2008-07-08 11:13 --------- d-----w C:\Program Files\NOS
2008-07-06 21:06 --------- d-----w C:\Documents and Settings\Betsy.YOUR-US67PI6LUV\Application Data\Corel
2008-07-01 02:44 --------- d-----w C:\Documents and Settings\Owner\Application Data\ACD Systems
2008-07-01 02:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\ACD Systems
2008-06-30 14:05 --------- d-----w C:\Program Files\Comodo
2008-06-30 11:30 --------- d-----w C:\Documents and Settings\Betsy.YOUR-US67PI6LUV\Application Data\Snapfish
2008-06-30 01:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Comodo
2008-06-30 00:30 --------- d-----w C:\Documents and Settings\Betsy.YOUR-US67PI6LUV\Application Data\Microsoft Web Folders
2008-06-30 00:27 --------- d-----w C:\Program Files\OpenOffice
2008-06-30 00:16 --------- d-----w C:\Program Files\Comodo Free
2008-06-29 22:05 --------- d-----w C:\Documents and Settings\Betsy.YOUR-US67PI6LUV\Application Data\VERITAS
2008-06-29 03:33 --------- d-----w C:\Documents and Settings\Betsy.YOUR-US67PI6LUV\Application Data\MSN6
2008-06-28 12:41 --------- d-----w C:\Program Files\CCleaner
2008-06-28 11:14 --------- d-----w C:\Program Files\Java
2008-06-26 21:26 --------- d-----w C:\Documents and Settings\Craig\Application Data\WeatherBug
2008-06-26 03:05 --------- d-----w C:\Documents and Settings\Betsy\Application Data\WeatherBug
2008-06-15 10:55 --------- d-----w C:\Documents and Settings\Betsy\Application Data\Roxio
2008-06-15 01:19 --------- d-----w C:\Documents and Settings\Betsy\Application Data\Creative
2008-05-26 10:58 1,470,464 ----a-w C:\Program Files\clipart.exe
2008-04-26 11:06 2,751,368 ----a-w C:\Program Files\ccsetup206.exe
2008-01-21 23:55 119,992 ----a-w C:\Documents and Settings\Betsy\Application Data\GDIPFONTCACHEV1.DAT
2006-09-28 03:04 16,291,424 ----a-w C:\Program Files\Java.exe
2005-01-15 11:13 9,893,152 ----a-w C:\Program Files\PatternViewerInst.exe
2004-07-22 10:39 2,150,574 ----a-w C:\Program Files\Ad-aware.exe
2004-05-23 19:26 2,403,357 ----a-w C:\Program Files\Reg Mechanic Install.exe
2004-05-02 20:17 10,241,609 ----a-w C:\Program Files\Vendio-SMPro.exe
2003-08-13 10:30 1,291,040 ----a-w C:\Program Files\WindowsXP-KB823980-x86-ENU.exe
2003-07-28 11:16 36,864 ----a-w C:\WINDOWS\inf\i386\Vizmicro.dll
2003-07-28 11:16 172,032 ----a-w C:\WINDOWS\inf\i386\viceo.dll
2003-07-28 11:01 36,207 ----a-w C:\WINDOWS\inf\i386\9320FW.bin
2003-07-28 11:01 274,432 ----a-w C:\WINDOWS\inf\i386\9320LLD.dll
2003-07-28 11:01 155,648 ----a-w C:\WINDOWS\inf\i386\rtscan.dll
2003-05-07 01:53 0 ----a-w C:\Program Files\Gevalia.jsp
2003-02-09 22:36 78,516 ----a-w C:\Program Files\AuctionManagerPro.exe
2002-11-30 21:16 1,803,464 ----a-w C:\Program Files\winzip81.exe
2001-08-03 23:29 13,824 ----a-w C:\WINDOWS\inf\i386\Usbscan.sys
.
------- Sigcheck -------
2004-08-04 02:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\ServicePackFiles\i386\ip6fw.sys
2004-08-04 02:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\system32\drivers\ip6fw.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2001-08-02 17:14 1077277]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 19:04 52736]
"CamMonitor"="c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe" [2002-06-18 02:11 69632]
"KBD"="C:\HP\KBD\KBD.EXE" [2001-07-07 00:56 61440]
"StorageGuard"="C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" [2002-05-09 11:01 155648]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2002-07-16 11:03 106549]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2001-12-19 02:39 212992]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2002-05-15 06:29 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2002-05-15 06:20 114688]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2002-06-14 19:39 81920]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [2003-06-25 11:24 49152]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-10-23 19:51 233472]
"HPDJ Taskbar Utility"="C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-09-01 07:42 176128]
"DeviceDiscovery"="C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe" [2003-05-21 18:37 229437]
"cnfgCav"="C:\Program Files\Comodo\Comodo AntiVirus\CMain.exe" [2008-07-28 07:45 110592]
"nwiz"="nwiz.exe" [2002-05-03 20:06 364544 C:\WINDOWS\system32\nwiz.exe]
C:\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\
AutoPlay.exe [2001-09-17 21:22:52 36864]
AutoTBar.exe [2002-05-30 05:58:02 40960]
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\
AutoPlay.exe [2001-09-17 21:22:52 36864]
C:\Documents and Settings\Administrator.YOUR-US67PI6LUV\Start Menu\Programs\Startup\
AutoPlay.exe [2001-09-17 21:22:52 36864]
AutoTBar.exe [2002-05-30 05:58:02 40960]
C:\Documents and Settings\Betsy\Start Menu\Programs\Startup\
Event Reminder.lnk - C:\Program Files\Mindscape\PrintMaster\PMREMIND.EXE [2007-06-04 21:33:41 325632]
PowerReg Scheduler V3.exe [2008-02-23 19:23:15 225280]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2002-11-29 22:45:23 113664]
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2002-11-29 22:45:23 113664]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26 29696]
America Online 7.0 Tray Icon.lnk - C:\Program Files\America Online 7.0\aoltray.exe [2002-11-29 17:24:20 32839]
Exif Launcher.lnk - C:\Program Files\FinePixViewer\QuickDCF.exe [2006-06-22 21:51:56 282624]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2003-01-30 13:03:47 156160]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-03-22 04:00:00 65588]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2003-11-30 15:02:16 106560]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\monln]
2008-07-28 07:45 216576 C:\WINDOWS\system32\monln.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\core3.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
R1 core3;HTCore Controller;C:\WINDOWS\System32\core3.sys [2008-08-05 20:30]
S3 FileObjInfo;STFileDriver;C:\Documents and Settings\All Users\Application Data\Spyware Terminator\FileObjInfo.sys [2008-07-19 17:49]
.
Contents of the 'Scheduled Tasks' folder
2008-07-26 C:\WINDOWS\Tasks\easy Internet sign-up.job
- C:\Program Files\Hewlett-Packard\EZ Internet Signup\HPSdpApp.exe [2002-04-20 00:10]
2002-07-27 C:\WINDOWS\Tasks\Symantec NetDetect.job
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE []
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-BOC-426 - (no file)
Notify-xatcore - xatcore.dll
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.com/
R0 -: HKCU-Main,Default_Search_URL = hxxp://srch-us6.hpwis.com/
R0 -: HKLM-Main,Start Page = hxxp://www.google.com
R0 -: HKLM-Main,Search Bar = hxxp://srch-us6.hpwis.com/
R1 -: HKCU-Internet Settings,ProxyOverride = localhost
O16 -: Microsoft XML Parser for Java - file://C:\WINDOWS\Java\classes\xmldso.cab
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
O16 -: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - hxxp://downloads.ewido.net/ewidoOnlineScan.cab
C:\WINDOWS\Downloaded Program Files\ewidoOnlineScan.dll
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-08-15 08:29:50
Windows 5.1.2600 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\WINDOWS\TEMP\cavbase99 118640 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Comodo\Common\CAVASpy\cavasm.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Program Files\Comodo\Comodo AntiVirus\cavse.exe
C:\Program Files\Comodo\Comodo AntiVirus\cavse.exe
C:\Program Files\Comodo\Comodo AntiVirus\CavAUD.exe
.
**************************************************************************
.
Completion time: 2008-08-15 8:43:06 - machine was rebooted [Owner]
ComboFix-quarantined-files.txt 2008-08-15 12:42:55
Pre-Run: 38,384,062,464 bytes free
Post-Run: 38,321,852,416 bytes free
270