Thanks a million for all of your help these last three days Ken. I for sure thought her computer was totally messed up and would need a reinstall. I am glad you volenteer your time here helping out. I will reinstall Spybot without the teatimer and spywareblaster and firefox 3. I will also have her read the links you provided about infections. The log below is the last Combofix run before I ran OTC.
Thanks again, and I will check your reply after I post the log. I will also post on the other forum you gave me about the user in safe mode.
Kyle
ComboFix 10-10-12.03 - User 10/15/2010 18:52:43.5.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.511.246 [GMT -4:00]
Running from: c:\documents and settings\User\Desktop\Combo-Fix.exe
Command switches used :: /unistall
.
((((((((((((((((((((((((( Files Created from 2010-09-15 to 2010-10-15 )))))))))))))))))))))))))))))))
.
2010-10-15 17:09 . 2010-10-15 17:09 -------- d-----w- c:\program files\ESET
2010-10-14 17:15 . 2010-10-14 17:55 -------- d-----w- C:\Combo-Fix
2010-10-12 02:34 . 2010-10-12 02:34 -------- d-----w- c:\program files\ERUNT
2010-10-10 00:25 . 2010-10-10 00:25 -------- d-sh--w- c:\documents and settings\LocalService\PrivacIE
2010-10-10 00:23 . 2010-10-10 00:23 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\Yahoo!
2010-10-10 00:23 . 2010-10-10 00:23 -------- d-----w- c:\documents and settings\LocalService\Application Data\Yahoo!
2010-10-08 22:36 . 2010-10-09 10:49 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-10-08 22:36 . 2010-10-09 01:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((( SnapShot@2010-10-14_17.49.40 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-10-15 22:49 . 2010-10-15 22:49 16384 c:\windows\temp\Perflib_Perfdata_e4.dat
+ 2010-10-14 17:53 . 2010-10-14 17:53 1550 c:\windows\SoftwareDistribution\EventCache\{495F3796-97B5-4F07-8821-6083693DE133}.bin
+ 2010-10-15 16:13 . 2010-10-15 16:13 192512 c:\windows\ERDNT\10-15-2010\Users\00000002\UsrClass.dat
+ 2010-10-15 16:13 . 2005-10-20 16:02 163328 c:\windows\ERDNT\10-15-2010\ERDNT.EXE
+ 2010-10-15 16:13 . 2010-10-15 16:13 7921664 c:\windows\ERDNT\10-15-2010\Users\00000001\ntuser.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-12-10 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-10-26 4632576]
"nwiz"="c:\windows\system32\nwiz.exe" [2004-10-26 921600]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2004-08-22 155648]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 385024]
"DVDSentry"="c:\windows\system32\DSentry.exe" [2002-07-17 28672]
"AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2005-02-08 684032]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-05 417792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-27 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-09-07 22:08 110592 ----a-w- c:\program files\Intel\Wireless\Bin\LgNotify.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R3 GTICARD;GTICARD;c:\windows\system32\drivers\gticard.sys [1/26/2005 10:55 PM 59328]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2/15/2010 10:29 PM 135664]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - BASFND
.
Contents of the 'Scheduled Tasks' folder
2010-02-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2010-10-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-16 02:28]
2010-10-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-16 02:28]
2010-10-15 c:\windows\Tasks\User_Feed_Synchronization-{0FA48CAD-70F5-43AA-998D-BE8715FA0925}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 08:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://my.yahoo.com/
uInternet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
Trusted Zone: tenderfoot.com
.
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1060)
c:\program files\Intel\Wireless\Bin\LgNotify.dll
- - - - - - - > 'explorer.exe'(2828)
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-10-15 19:01:08
ComboFix-quarantined-files.txt 2010-10-15 23:01
ComboFix2.txt 2010-10-15 22:47
ComboFix3.txt 2010-10-15 16:35
ComboFix4.txt 2010-10-15 00:43
ComboFix5.txt 2010-10-15 22:51
Pre-Run: 71,529,140,224 bytes free
Post-Run: 71,510,388,736 bytes free
- - End Of File - - 051C85F3EB267D825A16B442E34E024B