Hi Gabethebabe:
Thanks for your help. I ran ComboFix but I'll be away from my computer for a few days so no particular rush.
ComboFix 11-09-01.03 - Megan 02/09/2011 1:22.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.959.446 [GMT -7:00]
Running from: c:\documents and settings\Megan\Desktop\ComboFix.exe
AV: Shaw Secure 9.01 *Disabled/Updated* {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66}
FW: Norton Internet Worm Protection *Disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
FW: Shaw Secure 9.01 *Disabled* {D4747503-0346-49EB-9262-997542F79BF4}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Gordon\Desktop\AV Care.lnk
c:\documents and settings\Gordon\Start Menu\Programs\AV Care
c:\documents and settings\Gordon\Start Menu\Programs\AV Care\AV Care.lnk
c:\documents and settings\Megan\Application Data\master
c:\documents and settings\Megan\Desktop\[Torrentsworld.net] - Supernatural S05E11 Sam, Interrupted HDTV XviD FQM.torrent
c:\documents and settings\Megan\Desktop\[Torrentsworld.net] - Supernatural S05E11 Sam, Interrupted HDTV XviD FQM.torrent
c:\documents and settings\Megan\My Documents\86d.pdf
c:\documents and settings\Megan\My Documents\86ed.pdf
c:\documents and settings\Megan\WINDOWS
c:\program files\AV Care
c:\program files\AV Care\avc.ico
c:\program files\FunWebProducts
c:\program files\Internet Explorer\SET52F.tmp
c:\program files\Internet Explorer\SET530.tmp
c:\program files\Internet Explorer\SET532.tmp
c:\program files\Internet Explorer\SET593.tmp
c:\program files\Internet Explorer\SET594.tmp
c:\program files\Internet Explorer\SET595.tmp
c:\program files\MyWebSearch
c:\program files\MyWebSearch\bar\Settings\s_pid.dat
c:\temp\1cb
c:\temp\1cb\syscheck.log
.
Infected copy of c:\windows\system32\clipsrv.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\clipsrv.exe
.
Infected copy of c:\windows\system32\accwiz.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\accwiz.exe
.
Infected copy of c:\windows\system32\alg.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\alg.exe
.
Infected copy of c:\windows\system32\calc.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\calc.exe
.
Infected copy of c:\windows\system32\charmap.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\charmap.exe
.
Infected copy of c:\windows\system32\cleanmgr.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\cleanmgr.exe
.
Infected copy of c:\windows\system32\cmd.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\cmd.exe
.
Infected copy of c:\windows\system32\dmadmin.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\dmadmin.exe
.
Infected copy of c:\windows\system32\freecell.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\freecell.exe
.
Infected copy of c:\windows\system32\imapi.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\imapi.exe
.
Infected copy of c:\windows\system32\locator.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\locator.exe
.
Infected copy of c:\windows\system32\magnify.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\magnify.exe
.
Infected copy of c:\windows\system32\mnmsrvc.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\mnmsrvc.exe
.
Infected copy of c:\windows\system32\mobsync.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\mobsync.exe
.
Infected copy of c:\windows\system32\msdtc.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\msdtc.exe
.
Infected copy of c:\windows\system32\mshearts.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\mshearts.exe
.
Infected copy of c:\windows\system32\msiexec.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\msiexec.exe
.
Infected copy of c:\windows\system32\mspaint.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\mspaint.exe
.
Infected copy of c:\windows\system32\mstsc.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\mstsc.exe
.
Infected copy of c:\windows\system32\narrator.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\narrator.exe
.
Infected copy of c:\windows\system32\netdde.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\netdde.exe
.
Infected copy of c:\windows\system32\notepad.exe was found and disinfected
Restored copy from - c:\windows\notepad.exe
.
Infected copy of c:\windows\system32\odbcad32.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\odbcad32.exe
.
Infected copy of c:\windows\system32\osk.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\osk.exe
.
Infected copy of c:\windows\system32\rcimlby.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\rcimlby.exe
.
Infected copy of c:\windows\system32\rsvp.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\rsvp.exe
.
Infected copy of c:\windows\system32\scardsvr.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\scardsvr.exe
.
Infected copy of c:\windows\system32\sessmgr.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\sessmgr.exe
.
Infected copy of c:\windows\system32\smlogsvc.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\smlogsvc.exe
.
Infected copy of c:\windows\system32\sndrec32.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\sndrec32.exe
.
Infected copy of c:\windows\system32\sndvol32.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\sndvol32.exe
.
Infected copy of c:\windows\system32\sol.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\sol.exe
.
Infected copy of c:\windows\system32\spider.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\spider.exe
.
Infected copy of c:\windows\system32\tourstart.exe was found and disinfected
Restored copy from - c:\windows\$NtServicePackUninstall$\tourstart.exe
.
Infected copy of c:\windows\system32\utilman.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\utilman.exe
.
Infected copy of c:\windows\system32\vssvc.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\vssvc.exe
.
Infected copy of c:\windows\system32\wiaacmgr.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\wiaacmgr.exe
.
Infected copy of c:\windows\system32\winmine.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\winmine.exe
.
Infected copy of c:\windows\system32\wupdmgr.exe was found and disinfected
Restored copy from - c:\windows\system32\dllcache\wupdmgr.exe
.
Infected copy of c:\windows\system32\Restore\rstrui.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\rstrui.exe
.
Infected copy of c:\windows\system32\usmt\migwiz.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\migwiz.exe
.
Infected copy of c:\windows\system32\wbem\wmiapsrv.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\wmiapsrv.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-08-02 to 2011-09-02 )))))))))))))))))))))))))))))))
.
.
2011-09-01 22:31 . 2011-09-01 22:31 -------- d-----w- c:\program files\iPod
2011-09-01 22:31 . 2011-09-01 22:32 -------- d-----w- c:\program files\iTunes
2011-09-01 22:22 . 2011-09-01 22:23 -------- d-----w- c:\program files\Bonjour
2011-09-01 05:29 . 2011-09-01 05:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Trend Micro
2011-09-01 05:18 . 2011-09-01 05:18 -------- d-----w- c:\program files\WinPcap
2011-09-01 05:14 . 2011-09-01 05:14 388096 ----a-r- c:\documents and settings\Megan\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-09-01 05:14 . 2011-09-01 05:17 -------- d-----w- c:\program files\Trend Micro
2011-08-31 05:53 . 2011-09-02 08:43 120832 ----a-w- c:\windows\system32\msdtc.exe
2011-08-31 05:53 . 2011-09-02 08:43 147968 ----a-w- c:\windows\system32\clipsrv.exe
2011-08-31 05:53 . 2011-09-02 08:43 159232 ----a-w- c:\windows\system32\alg.exe
2011-08-30 18:45 . 2011-09-02 08:45 147456 ----a-w- c:\windows\system32\mnmsrvc.exe
2011-08-28 04:38 . 2011-08-28 05:10 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2011-08-28 02:40 . 2011-09-02 08:43 120320 ----a-w- c:\windows\system32\cisvc.exe
2011-08-24 20:58 . 2011-08-24 20:58 -------- d-----w- c:\documents and settings\LocalService\Application Data\Ahead
2011-08-11 21:12 . 2011-08-11 21:12 -------- d-----w- c:\documents and settings\Megan\Local Settings\Application Data\PCHealth
2011-08-11 04:11 . 2011-06-24 14:10 139656 -c----w- c:\windows\system32\dllcache\rdpwd.sys
2011-08-11 04:11 . 2011-07-08 14:02 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-02 08:49 . 2007-04-28 03:04 150528 ----a-w- c:\windows\system32\rcimlby.exe
2011-09-02 08:48 . 2007-04-28 03:04 461824 ----a-w- c:\windows\system32\tourstart.exe
2011-09-02 08:48 . 2007-04-28 03:04 164864 ----a-w- c:\windows\system32\utilman.exe
2011-09-02 08:48 . 2007-04-28 03:04 330240 ----a-w- c:\windows\system32\osk.exe
2011-09-02 08:48 . 2007-04-28 03:04 183808 ----a-w- c:\windows\system32\notepad.exe
2011-09-02 08:48 . 2007-04-28 03:04 258048 ----a-w- c:\windows\system32\mobsync.exe
2011-09-02 08:48 . 2007-04-28 03:04 503808 ----a-w- c:\windows\system32\cmd.exe
2011-09-02 08:48 . 2007-04-28 03:04 168448 ----a-w- c:\windows\system32\narrator.exe
2011-09-02 08:48 . 2007-04-28 03:04 187392 ----a-w- c:\windows\system32\magnify.exe
2011-09-02 08:45 . 2007-04-28 03:04 265216 ----a-w- c:\windows\system32\imapi.exe
2011-09-02 08:43 . 2011-08-31 05:00 404480 ----a-w- c:\windows\system32\vssvc.exe
2011-09-02 08:43 . 2011-08-31 05:53 210432 ----a-w- c:\windows\system32\scardsvr.exe
2011-09-02 08:43 . 2007-04-28 03:04 204288 ----a-w- c:\windows\system32\smlogsvc.exe
2011-09-02 08:43 . 2007-04-28 03:04 189952 ----a-w- c:\windows\system32\locator.exe
2011-09-02 08:43 . 2007-04-28 03:04 225792 ----a-w- c:\windows\system32\netdde.exe
2011-09-02 00:33 . 2007-04-28 03:08 278528 ----a-w- c:\windows\system32\nvsvc32.exe
2011-08-19 05:05 . 2009-02-02 23:11 42672 ----a-w- c:\windows\system32\drivers\fsbts.sys
2011-07-15 13:29 . 2007-04-28 03:04 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-12 18:20 . 2011-07-12 18:20 83816 ----a-w- c:\windows\system32\dns-sd.exe
2011-07-12 18:20 . 2011-07-12 18:20 73064 ----a-w- c:\windows\system32\dnssd.dll
2011-07-08 14:02 . 2007-04-28 03:04 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys
2011-07-06 01:37 . 2011-07-06 01:37 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2011-07-06 01:37 . 2011-07-06 01:37 69632 ----a-w- c:\windows\system32\QuickTime.qts
2011-06-24 14:10 . 2007-04-28 03:31 139656 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2011-06-23 18:36 . 2007-04-28 03:04 916480 ----a-w- c:\windows\system32\wininet.dll
2011-06-23 18:36 . 2007-04-28 03:04 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-06-23 18:36 . 2007-04-28 03:04 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-06-23 12:05 . 2007-04-28 03:04 385024 ----a-w- c:\windows\system32\html.iec
2011-06-20 17:44 . 2007-04-28 03:04 293376 ----a-w- c:\windows\system32\winsrv.dll
2011-09-01 02:08 . 2011-05-03 01:18 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\documents and settings\Megan\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\documents and settings\Megan\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\documents and settings\Megan\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\documents and settings\Megan\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="c:\program files\Steam\Steam.exe" [2011-08-02 1242448]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2010-04-17 3872080]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-20 39408]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-11-13 323392]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"nwiz"="nwiz.exe" [2006-10-22 1622016]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-02-05 849280]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-10 16126464]
"SkyTel"="SkyTel.EXE" [2007-04-04 1822720]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-06 54832]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-11-25 185632]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-30 583048]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"F-Secure Manager"="c:\program files\Shaw Secure\Common\FSM32.EXE" [2009-08-05 199264]
"F-Secure TNB"="c:\program files\Shaw Secure\FSGUI\TNBUtil.exe" [2009-08-05 2349664]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"StxTrayMenu"="c:\program files\Seagate\SystemTray\StxMenuMgr.exe" [2007-01-04 187496]
"DiscWizardMonitor.exe"="c:\program files\Seagate\DiscWizard\DiscWizardMonitor.exe" [2008-06-25 1325848]
"AcronisTimounterMonitor"="c:\program files\Seagate\DiscWizard\TimounterMonitor.exe" [2008-06-25 904768]
"Seagate Scheduler2 Service"="c:\program files\Common Files\Seagate\Schedule2\schedhlp.exe" [2008-06-25 136472]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2009-06-10 136472]
"D-Link RangeBooster G WUA-2340"="c:\program files\D-Link\RangeBooster G WUA-2340\AirPlusCFG.exe" [2008-09-24 1667072]
"ANIWZCS2Service"="c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2007-01-19 49152]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2009-03-23 1983816]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2009-03-17 767312]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2011-04-20 58656]
"Trend Micro RUBotted V2.0 Beta"="c:\program files\Trend Micro\RUBotted\RUBottedGUI.exe" [2010-12-17 1103184]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-07-06 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-08-19 421736]
.
c:\documents and settings\Megan\Start Menu\Programs\Startup\
Dropbox.lnk - c:\documents and settings\Megan\Application Data\Dropbox\bin\Dropbox.exe [2011-5-25 24176560]
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-12-15 498688]
.
c:\documents and settings\Gordon\Start Menu\Programs\Startup\
OpenOffice.org 2.3.lnk - c:\program files\OpenOffice.org 2.3\program\quickstart.exe [N/A]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
NkbMonitor.exe.lnk - c:\program files\Nikon\PictureProject\NkbMonitor.exe [2008-3-9 233472]
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Documents and Settings\\Megan\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\audiosurf\\engine\\QuestViewer.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
.
R0 fsbts;fsbts;c:\windows\system32\drivers\fsbts.sys [02/02/2009 4:11 PM 42672]
R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [02/02/2009 3:54 PM 82120]
R0 m5289;m5289;c:\windows\system32\drivers\m5289.sys [30/04/2007 10:35 AM 51840]
R1 F-Secure HIPS;F-Secure HIPS Driver;c:\program files\Shaw Secure\HIPS\drivers\fshs.sys [02/02/2009 3:53 PM 68064]
R2 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\D-Link\RangeBooster G WUA-2340\JSWUtil\jswpsapi.exe [04/12/2009 5:04 PM 475136]
R2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [20/10/2009 11:19 AM 50704]
R2 RUBotSrv;Trend Micro RUBotted Service;c:\program files\Trend Micro\RUBotted\RUBotSrv.exe [31/08/2011 10:17 PM 439632]
R2 SgtSch2Svc;Seagate Scheduler2 Service;c:\program files\Common Files\Seagate\Schedule2\schedul2.exe [24/06/2008 7:56 PM 431384]
R3 A5AGU;D-Link USB Wireless Network Adapter Service;c:\windows\system32\drivers\A5AGU.sys [04/12/2009 5:04 PM 386784]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\Shaw Secure\Anti-Virus\minifilter\fsgk.sys [02/02/2009 3:53 PM 148648]
R3 FSORSPClient;F-Secure ORSP Client;c:\program files\Shaw Secure\ORSP Client\fsorsp.exe [02/02/2009 3:53 PM 61088]
R3 JSWSCIMD;jswscimd Service;c:\windows\system32\drivers\jswscimd.sys [04/12/2009 5:04 PM 57440]
S0 iteraid;ITERAID_Service_Install;c:\windows\system32\drivers\iteraid.sys [30/04/2007 10:35 AM 24971]
S0 m5287;m5287;c:\windows\system32\drivers\m5287.sys [30/04/2007 10:35 AM 85888]
S0 mv614x;mv614x;c:\windows\system32\drivers\mv614x.sys [30/04/2007 10:36 AM 61184]
S0 Si3112r;Silicon Image SiI 3112 SATARaid Controller;c:\windows\system32\drivers\Si3112r.sys [30/04/2007 10:36 AM 89610]
S0 SiSRaid1;SiSRaid1;c:\windows\system32\drivers\sisraid1.sys [30/04/2007 10:36 AM 45568]
S0 viasraid;viasraid;c:\windows\system32\drivers\viasraid.sys [30/04/2007 10:36 AM 77056]
S2 gupdate1c9d98c28cb7fa6;Google Update Service (gupdate1c9d98c28cb7fa6);c:\program files\Google\Update\GoogleUpdate.exe [20/05/2009 1:47 PM 133104]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [20/05/2009 1:47 PM 133104]
S4 F-Secure Filter;F-Secure File System Filter;c:\program files\Shaw Secure\Anti-Virus\win2k\fsfilter.sys [02/02/2009 3:53 PM 39776]
S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\Shaw Secure\Anti-Virus\win2k\fsrec.sys [02/02/2009 3:53 PM 25184]
.
Contents of the 'Scheduled Tasks' folder
.
2011-09-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-02 20:34]
.
2011-09-02 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-20 20:46]
.
2011-09-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-20 20:46]
.
2011-09-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-20 20:46]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: c:\program files\Shaw Secure\FSPS\program\FSLSP.DLL
TCP: DhcpNameServer = 192.168.254.254 192.168.254.254
FF - ProfilePath - c:\documents and settings\Megan\Application Data\Mozilla\Firefox\Profiles\x0fuw9qz.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig
FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101757&gct=&gc=1&q=
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-AV Care - c:\program files\AV Care\Uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-09-02 01:44
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2473693306-2600650905-4282620119-1009\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@SACL=
.
[HKEY_USERS\S-1-5-21-2473693306-2600650905-4282620119-1009\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:81,e0,db,fc,79,31,d4,45,dd,13,59,b9,3e,6b,06,2e,aa,e3,ad,4d,b4,89,0a,
11,51,29,ba,a6,fb,db,fe,07,fc,0c,9c,90,43,73,3b,18,00,23,7a,a4,b1,8a,a8,14,\
"??"=hex:ac,2a,f2,3f,1b,2e,30,ef,0e,88,c5,82,9e,3e,b5,bc
.
[HKEY_USERS\S-1-5-21-2473693306-2600650905-4282620119-1009\Software\SecuROM\License information*]
"datasecu"=hex:d1,a2,44,93,8c,f6,9e,57,ba,65,e8,42,ca,1a,dc,b9,9d,d4,8b,ba,ea,
53,01,5f,4c,fc,d2,d5,43,38,43,c9,a3,ed,87,ab,38,c8,a3,c8,cc,ed,1b,fc,5d,fc,\
"rkeysecu"=hex:19,e3,b2,71,9f,04,7b,d4,7e,96,77,02,c8,74,ed,ba
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'lsass.exe'(1112)
c:\program files\Shaw Secure\FSPS\program\FSLSP.DLL
.
- - - - - - - > 'explorer.exe'(6020)
c:\windows\system32\WININET.dll
c:\documents and settings\Megan\Application Data\Dropbox\bin\DropboxExt.14.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Shaw Secure\FSPS\program\FSLSP.DLL
c:\program files\shaw secure\scanner-interface\fsgkiapi.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Shaw Secure\Anti-Virus\fsgk32st.exe
c:\program files\Shaw Secure\Common\FSMA32.EXE
c:\program files\Shaw Secure\Anti-Virus\FSGK32.EXE
c:\program files\Shaw Secure\Common\FSHDLL32.EXE
c:\program files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
c:\program files\Nero\Nero 7\Nero BackItUp\NBService.exe
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\windows\system32\nvsvc32.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\program files\Shaw Secure\FWES\Program\fsdfwd.exe
c:\program files\Shaw Secure\Anti-Virus\fssm32.exe
c:\program files\Shaw Secure\Anti-Virus\fsav32.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\RTHDCPL.EXE
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\iPod\bin\iPodService.exe
c:\program files\Windows Live\Contacts\wlcomm.exe
c:\program files\Java\jre1.6.0_07\bin\jucheck.exe
.
**************************************************************************
.
Completion time: 2011-09-02 01:53:55 - machine was rebooted
ComboFix-quarantined-files.txt 2011-09-02 08:53
.
Pre-Run: 51,910,955,008 bytes free
Post-Run: 52,635,893,760 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 5ECC797225C32EFB7FD4D2607D8B10AC