I did as instructed. Here is the log:
ComboFix 10-03-02.02 - HH 03/02/2010 22:49:25.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.552 [GMT -5:00]
Running from: c:\documents and settings\HH\Desktop\Hajera netbook fix\Combo-Fix.exe
Command switches used :: c:\documents and settings\HH\Desktop\Hajera netbook fix\CFScript.txt
.
((((((((((((((((((((((((( Files Created from 2010-02-03 to 2010-03-03 )))))))))))))))))))))))))))))))
.
2010-03-02 20:25 . 2010-03-02 20:27 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Temp
2010-03-02 20:24 . 2010-03-02 20:24 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Bytemobile
2010-03-02 20:22 . 2010-03-02 20:22 -------- d-----w- c:\documents and settings\HH\Application Data\Bytemobile
2010-03-02 20:22 . 2010-03-02 20:22 -------- d-----w- c:\documents and settings\HH\Application Data\DBUpdater
2010-03-02 20:22 . 2008-11-21 02:59 27072 ----a-w- c:\windows\system32\drivers\PCASp50.sys
2010-03-02 20:22 . 2010-03-02 20:22 -------- d-----w- c:\documents and settings\HH\Application Data\AT&T
2010-03-02 20:21 . 2008-08-22 17:05 26760 ----a-w- c:\windows\system32\drivers\swmsflt.sys
2010-03-02 20:16 . 2007-01-18 15:24 26496 ----a-r- c:\windows\system32\drivers\RimSerial.sys
2010-03-02 20:15 . 2010-03-02 20:15 -------- d-----w- c:\program files\Common Files\Motorola Shared
2010-03-02 20:15 . 2010-03-02 20:15 -------- d-----w- C:\Research in Motion
2010-03-02 20:15 . 2010-03-02 20:15 -------- d-----w- c:\program files\Common Files\Research in Motion
2010-03-02 20:15 . 2010-03-02 20:15 -------- d-----w- c:\program files\AT&T
2010-03-02 20:15 . 2010-03-02 20:15 -------- d-----w- c:\documents and settings\All Users\Application Data\AT&T
2010-03-02 20:14 . 2010-03-02 20:14 -------- d-----w- c:\program files\Option
2010-03-02 19:49 . 2010-03-02 19:49 -------- d-----w- c:\program files\Sierra Wireless Inc
2010-03-02 19:49 . 2010-03-02 19:49 -------- d-----w- c:\documents and settings\HH\Application Data\Sierra Wireless
2010-03-02 18:48 . 2010-03-02 22:18 -------- d-----w- c:\documents and settings\HH\Application Data\Malwarebytes
2010-03-02 18:48 . 2010-03-02 22:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-26 05:29 . 2010-02-26 05:29 -------- d-----w- c:\windows\Sun
2010-02-08 07:10 . 2010-02-08 07:10 -------- d-----w- c:\program files\AVG
2010-02-08 06:50 . 2010-02-08 06:50 -------- d-----w- c:\program files\IrfanView
2010-02-05 23:28 . 2010-02-05 23:36 -------- d-----w- c:\documents and settings\HH\Praat
2010-02-05 15:39 . 2010-02-05 15:39 251376 ----a-w- c:\documents and settings\HH\Application Data\Mozilla\plugins\npgoogletalk.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-02 23:01 . 2009-12-02 19:11 -------- d-----w- c:\documents and settings\HH\Application Data\U3
2010-03-02 19:53 . 2009-12-23 07:27 -------- d-----w- c:\documents and settings\HH\Application Data\skypePM
2010-02-10 14:41 . 2009-12-08 19:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-01-28 21:47 . 2009-11-16 23:17 -------- d-----w- c:\program files\Google
2010-01-19 19:00 . 2009-12-23 07:25 -------- d-----w- c:\documents and settings\HH\Application Data\Skype
2010-01-05 10:00 . 2007-08-14 09:54 832512 ------w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2008-04-15 04:00 78336 ------w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2008-04-15 04:00 17408 ------w- c:\windows\system32\corpol.dll
2009-12-31 16:50 . 2008-04-15 04:00 353792 ------w- c:\windows\system32\drivers\srv.sys
2009-12-23 07:27 . 2009-12-23 07:27 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-12-16 18:43 . 2008-04-15 04:00 343040 ------w- c:\windows\system32\mspaint.exe
2009-12-14 17:53 . 2009-11-15 23:01 85384 ----a-w- c:\documents and settings\HH\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-14 07:08 . 2008-04-15 04:00 33280 ------w- c:\windows\system32\csrsrv.dll
2009-12-09 03:07 . 2009-11-15 19:37 1626 ----a-w- c:\documents and settings\HH\Application Data\wklnhst.dat
2009-12-08 22:13 . 2009-12-08 22:13 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-12-08 19:26 . 2008-04-15 04:00 2145280 ------w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:43 . 2008-04-15 04:00 2023936 ------w- c:\windows\system32\ntkrnlpa.exe
2009-12-04 18:22 . 2008-04-15 04:00 455424 ------w- c:\windows\system32\drivers\mrxsmb.sys
2006-10-12 03:09 . 2009-12-26 10:18 94208 --sh--w- c:\windows\system32\SalaatTime.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\HH\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-11-15 135664]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-11-16 39408]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
"SalaatTime"="c:\program files\Salaat Time\SalaatTime.exe" [2008-05-16 13496320]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-15 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-15 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-15 131072]
"IDTSysTrayApp"="sttray.exe" [2008-08-30 442477]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-08-30 442477]
"AESTFltr"="c:\windows\system32\AESTFltr.exe" [2008-08-28 471040]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-07-31 1343488]
"HP Mobile Broadband"="c:\swsetup\HPQWWAN\HPMobileBroadband.exe" [2008-07-08 439600]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"AT&T Communication Manager"="c:\program files\AT&T\Communication Manager\ATTCM.exe" [2008-12-01 33280]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\HH\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\HH\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [10/5/2008 11:41 PM 112128]
R3 SWNC8U80;Sierra Wireless MUX NDIS Driver (UMTS80);c:\windows\system32\drivers\swnc8u80.sys [8/20/2008 1:35 PM 168192]
R3 SWUMX80;Sierra Wireless USB MUX Driver (UMTS80);c:\windows\system32\drivers\swumx80.sys [8/20/2008 1:36 PM 142976]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1/28/2010 4:47 PM 135664]
S3 ATTRcAppSvc;AT&T RcAppSvc;c:\program files\AT&T\Communication Manager\RcAppSvc.exe [11/20/2008 10:07 PM 113152]
.
Contents of the 'Scheduled Tasks' folder
2009-11-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2010-03-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore1caba46efd00086.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-28 21:47]
2010-02-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2853163502-4067377615-73162678-1006Core1cab6497254320e.job
- c:\documents and settings\HH\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-11-15 23:01]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.cnn.com/IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
LSP: bmnet.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-03-02 22:53
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(800)
c:\windows\system32\igfxdev.dll
- - - - - - - > 'lsass.exe'(856)
c:\windows\system32\bmnet.dll
- - - - - - - > 'explorer.exe'(3772)
c:\windows\system32\WININET.dll
c:\windows\system32\btmmhook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-03-02 22:55:10
ComboFix-quarantined-files.txt 2010-03-03 03:55
ComboFix2.txt 2010-03-02 23:12
Pre-Run: 46,593,519,616 bytes free
Post-Run: 46,576,713,728 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
- - End Of File - - D0DCE0E65A6429B27E4C6FD7BA5868FC