Before I could follow your instructions I found that ComboFix had been deleted by my McAfee. It alerted me this morning that a suspicious program had been found but I didn't have my glasses on and couldn't read which program. Anyway, after I reinstalled ComboFix by following your previous directions, I followed the current instructions for CFScript. My computer was running fine but I went ahead and rebooted a couple of times as you directed and now it seems to have slowed down again. It may be because I didn't give everything time to load before trying to get to this forum. Anyway, here is my latest ComboFix log:
ComboFix 09-05-08.03 - Dell 05/08/2009 21:13.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2559.2023 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Dell\Desktop\CFScript.txt
AV: McAfee VirusScan Enterprise *On-access scanning disabled* (Updated)
AV: Sunbelt VIPRE *On-access scanning disabled* (Updated)
file zipped: c:\documents and settings\Dell\Application Data\sdra64.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Dell\Application Data\sdra64.exe
.
((((((((((((((((((((((((( Files Created from 2009-04-09 to 2009-05-09 )))))))))))))))))))))))))))))))
.
2009-05-06 22:53 . 2009-05-06 22:55 -------- d-sh--w c:\documents and settings\Dell\Application Data\lowsec
2009-04-27 07:00 . 2009-04-27 07:00 -------- d-----w c:\program files\MSXML 4.0
2009-04-26 02:33 . 2009-04-26 02:33 -------- d-----w c:\program files\Trend Micro
2009-04-26 01:13 . 2009-03-05 03:30 69936 ----a-w c:\windows\system32\drivers\sbapifs.sys
2009-04-26 01:12 . 2008-09-12 13:38 13360 ----a-w c:\windows\system32\drivers\sbaphd.sys
2009-04-25 16:57 . 2009-04-25 16:57 -------- d-----w c:\documents and settings\All Users\Application Data\Sunbelt
2009-04-25 16:56 . 2009-04-25 16:56 -------- d-----w c:\documents and settings\Dell\Application Data\Sunbelt
2009-04-25 16:54 . 2008-10-09 14:21 202928 ----a-w c:\windows\system32\drivers\sbtis.sys
2009-04-25 16:53 . 2009-04-25 16:53 -------- d-----w c:\program files\Sunbelt Software
2009-04-19 00:10 . 2009-04-19 00:10 -------- d-----w c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-04-19 00:10 . 2009-04-19 00:10 -------- d-----w c:\windows\system32\IOSUBSYS
2009-04-16 04:13 . 2009-03-06 14:22 284160 -c----w c:\windows\system32\dllcache\pdh.dll
2009-04-16 04:13 . 2009-02-09 12:10 401408 -c----w c:\windows\system32\dllcache\rpcss.dll
2009-04-16 04:13 . 2009-02-06 11:11 110592 -c----w c:\windows\system32\dllcache\services.exe
2009-04-16 04:13 . 2009-02-09 12:10 473600 -c----w c:\windows\system32\dllcache\fastprox.dll
2009-04-16 04:13 . 2009-02-06 10:10 227840 -c----w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-16 04:13 . 2009-02-09 12:10 453120 -c----w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-16 04:13 . 2009-02-09 12:10 729088 -c----w c:\windows\system32\dllcache\lsasrv.dll
2009-04-16 04:13 . 2009-02-09 12:10 617472 -c----w c:\windows\system32\dllcache\advapi32.dll
2009-04-16 04:13 . 2009-02-09 12:10 714752 -c----w c:\windows\system32\dllcache\ntdll.dll
2009-04-16 04:02 . 2008-05-03 11:55 2560 ------w c:\windows\system32\xpsp4res.dll
2009-04-16 04:02 . 2008-04-21 12:08 215552 -c----w c:\windows\system32\dllcache\wordpad.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-08 00:26 . 2007-06-22 02:43 -------- d-----w c:\program files\Java
2009-04-19 00:10 . 2008-06-19 03:54 -------- d-----w c:\program files\Google
2009-04-11 09:11 . 2007-06-10 23:24 -------- d-----w c:\program files\AOL 9.0
2009-03-29 05:28 . 2009-03-13 22:42 -------- d-----w c:\program files\DeductionPro 2008
2009-03-17 17:26 . 2009-03-17 17:26 65320 ----a-w c:\windows\system32\sbbd.exe
2009-03-13 22:42 . 2004-09-17 19:25 -------- d--h--w c:\program files\InstallShield Installation Information
2009-03-13 22:40 . 2009-03-13 22:37 -------- d-----w c:\program files\TaxCut08
2009-03-09 09:19 . 2008-11-23 12:19 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-06 14:22 . 2002-06-25 21:44 284160 ----a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2002-03-05 12:56 826368 ----a-w c:\windows\system32\wininet.dll
2009-02-20 18:09 . 2004-08-04 07:56 78336 ----a-w c:\windows\system32\ieencode.dll
2009-02-09 12:10 . 2002-06-25 21:40 729088 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2004-09-17 20:51 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 12:10 . 2002-06-25 21:43 714752 ----a-w c:\windows\system32\ntdll.dll
2009-02-09 12:10 . 2002-06-25 21:36 617472 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 11:13 . 2002-06-25 21:50 1846784 ----a-w c:\windows\system32\win32k.sys
2008-12-02 04:07 . 2008-12-02 03:50 27462344 ----a-w c:\program files\setupeng.exe
2008-11-30 06:06 . 2008-11-30 06:06 23804784 ----a-w c:\program files\aaw2008.exe
2008-09-18 03:01 . 2008-09-18 03:01 15327629 ----a-w c:\program files\My birthday DVD.vpc
2008-09-14 02:37 . 2008-09-14 02:37 10367496 ----a-w c:\program files\vsophotodvd_setup.exe
2008-01-20 03:48 . 2008-01-20 01:59 32213504 ----a-w c:\program files\virusscan85i_troy.exe
.
((((((((((((((((((((((((((((( SnapShot@2009-05-07_02.32.57 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-05-08 00:18 . 2009-05-08 00:18 16384 c:\windows\temp\Perflib_Perfdata_3f0.dat
+ 2004-09-17 19:08 . 2009-05-08 06:29 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2004-09-17 19:08 . 2008-12-14 08:06 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2004-09-17 19:08 . 2009-05-08 06:29 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2004-09-17 19:08 . 2008-12-14 08:06 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2004-09-17 19:08 . 2009-05-08 06:29 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2004-09-17 19:08 . 2008-12-14 08:06 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"AOL Fast Start"="c:\program files\AOL 9.0\AOL.EXE" [2007-04-18 50736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-12-17 684032]
"HostManager"="c:\program files\Common Files\AOL\1124679661\ee\AOLSoftware.exe" [2008-06-24 41824]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 57344]
"Dell Photo AIO Printer 922"="c:\program files\Dell Photo AIO Printer 922\dlbtbmgr.exe" [2004-03-29 290816]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2003-07-28 4841472]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
"McAfeeUpdaterUI"="c:\common framework\UdaterUI.exe" [2006-12-19 136768]
"ShStatEXE"="c:\mcafee\SHSTAT.EXE" [2007-02-23 112216]
"SBAMTray"="c:\program files\Sunbelt Software\VIPRE\SBAMTray.exe" [2009-03-17 955688]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2003-07-28 323584]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 39264]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave"= serwvdrv.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0SsiEfr.e
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1124679661\\ee\\AOLServiceHost.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\acs\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\acs\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\1124679661\\ee\\aolsoftware.exe"=
"c:\\Program Files\\AOL 9.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Common Framework\\FrameworkService.exe"=
R1 sbaphd;sbaphd;c:\windows\system32\drivers\sbaphd.sys [4/25/2009 9:12 PM 13360]
R1 sbtis;sbtis;c:\windows\system32\drivers\sbtis.sys [4/25/2009 12:54 PM 202928]
R2 SBAMSvc;VIPRE Antivirus + Antispyware;c:\program files\Sunbelt Software\VIPRE\SBAMSvc.exe [3/17/2009 1:26 PM 894248]
R2 sbapifs;sbapifs;c:\windows\system32\drivers\sbapifs.sys [4/25/2009 9:13 PM 69936]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 8:19 PM 13592]
S3 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [10/22/2008 5:08 PM 92464]
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://msn.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uInternet Connection Wizard,ShellNext = iexplore
IE: &AIM Search - c:\program files\AIM Toolbar\AIMBar.dll/aimsearch.htm
IE: &Search - ?p=ZUxdm265YYUS
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: colonialchem.com\colonialchem2
TCP: {F84C6EDD-ABEC-4007-91FE-D1F2F87F8136} = 4.2.2.2,4.2.2.3
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-08 21:14
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-05-09 21:17
ComboFix-quarantined-files.txt 2009-05-09 01:17
ComboFix2.txt 2009-05-07 02:35
Pre-Run: 63,323,787,264 bytes free
Post-Run: 63,395,381,248 bytes free
155 --- E O F --- 2009-04-29 07:06
Upload was successful
ComboFix 09-05-08.03 - Dell 05/08/2009 21:13.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2559.2023 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Dell\Desktop\CFScript.txt
AV: McAfee VirusScan Enterprise *On-access scanning disabled* (Updated)
AV: Sunbelt VIPRE *On-access scanning disabled* (Updated)
file zipped: c:\documents and settings\Dell\Application Data\sdra64.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Dell\Application Data\sdra64.exe
.
((((((((((((((((((((((((( Files Created from 2009-04-09 to 2009-05-09 )))))))))))))))))))))))))))))))
.
2009-05-06 22:53 . 2009-05-06 22:55 -------- d-sh--w c:\documents and settings\Dell\Application Data\lowsec
2009-04-27 07:00 . 2009-04-27 07:00 -------- d-----w c:\program files\MSXML 4.0
2009-04-26 02:33 . 2009-04-26 02:33 -------- d-----w c:\program files\Trend Micro
2009-04-26 01:13 . 2009-03-05 03:30 69936 ----a-w c:\windows\system32\drivers\sbapifs.sys
2009-04-26 01:12 . 2008-09-12 13:38 13360 ----a-w c:\windows\system32\drivers\sbaphd.sys
2009-04-25 16:57 . 2009-04-25 16:57 -------- d-----w c:\documents and settings\All Users\Application Data\Sunbelt
2009-04-25 16:56 . 2009-04-25 16:56 -------- d-----w c:\documents and settings\Dell\Application Data\Sunbelt
2009-04-25 16:54 . 2008-10-09 14:21 202928 ----a-w c:\windows\system32\drivers\sbtis.sys
2009-04-25 16:53 . 2009-04-25 16:53 -------- d-----w c:\program files\Sunbelt Software
2009-04-19 00:10 . 2009-04-19 00:10 -------- d-----w c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-04-19 00:10 . 2009-04-19 00:10 -------- d-----w c:\windows\system32\IOSUBSYS
2009-04-16 04:13 . 2009-03-06 14:22 284160 -c----w c:\windows\system32\dllcache\pdh.dll
2009-04-16 04:13 . 2009-02-09 12:10 401408 -c----w c:\windows\system32\dllcache\rpcss.dll
2009-04-16 04:13 . 2009-02-06 11:11 110592 -c----w c:\windows\system32\dllcache\services.exe
2009-04-16 04:13 . 2009-02-09 12:10 473600 -c----w c:\windows\system32\dllcache\fastprox.dll
2009-04-16 04:13 . 2009-02-06 10:10 227840 -c----w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-16 04:13 . 2009-02-09 12:10 453120 -c----w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-16 04:13 . 2009-02-09 12:10 729088 -c----w c:\windows\system32\dllcache\lsasrv.dll
2009-04-16 04:13 . 2009-02-09 12:10 617472 -c----w c:\windows\system32\dllcache\advapi32.dll
2009-04-16 04:13 . 2009-02-09 12:10 714752 -c----w c:\windows\system32\dllcache\ntdll.dll
2009-04-16 04:02 . 2008-05-03 11:55 2560 ------w c:\windows\system32\xpsp4res.dll
2009-04-16 04:02 . 2008-04-21 12:08 215552 -c----w c:\windows\system32\dllcache\wordpad.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-08 00:26 . 2007-06-22 02:43 -------- d-----w c:\program files\Java
2009-04-19 00:10 . 2008-06-19 03:54 -------- d-----w c:\program files\Google
2009-04-11 09:11 . 2007-06-10 23:24 -------- d-----w c:\program files\AOL 9.0
2009-03-29 05:28 . 2009-03-13 22:42 -------- d-----w c:\program files\DeductionPro 2008
2009-03-17 17:26 . 2009-03-17 17:26 65320 ----a-w c:\windows\system32\sbbd.exe
2009-03-13 22:42 . 2004-09-17 19:25 -------- d--h--w c:\program files\InstallShield Installation Information
2009-03-13 22:40 . 2009-03-13 22:37 -------- d-----w c:\program files\TaxCut08
2009-03-09 09:19 . 2008-11-23 12:19 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-06 14:22 . 2002-06-25 21:44 284160 ----a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2002-03-05 12:56 826368 ----a-w c:\windows\system32\wininet.dll
2009-02-20 18:09 . 2004-08-04 07:56 78336 ----a-w c:\windows\system32\ieencode.dll
2009-02-09 12:10 . 2002-06-25 21:40 729088 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2004-09-17 20:51 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 12:10 . 2002-06-25 21:43 714752 ----a-w c:\windows\system32\ntdll.dll
2009-02-09 12:10 . 2002-06-25 21:36 617472 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 11:13 . 2002-06-25 21:50 1846784 ----a-w c:\windows\system32\win32k.sys
2008-12-02 04:07 . 2008-12-02 03:50 27462344 ----a-w c:\program files\setupeng.exe
2008-11-30 06:06 . 2008-11-30 06:06 23804784 ----a-w c:\program files\aaw2008.exe
2008-09-18 03:01 . 2008-09-18 03:01 15327629 ----a-w c:\program files\My birthday DVD.vpc
2008-09-14 02:37 . 2008-09-14 02:37 10367496 ----a-w c:\program files\vsophotodvd_setup.exe
2008-01-20 03:48 . 2008-01-20 01:59 32213504 ----a-w c:\program files\virusscan85i_troy.exe
.
((((((((((((((((((((((((((((( SnapShot@2009-05-07_02.32.57 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-05-08 00:18 . 2009-05-08 00:18 16384 c:\windows\temp\Perflib_Perfdata_3f0.dat
+ 2004-09-17 19:08 . 2009-05-08 06:29 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2004-09-17 19:08 . 2008-12-14 08:06 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2004-09-17 19:08 . 2009-05-08 06:29 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2004-09-17 19:08 . 2008-12-14 08:06 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2004-09-17 19:08 . 2009-05-08 06:29 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2004-09-17 19:08 . 2008-12-14 08:06 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"AOL Fast Start"="c:\program files\AOL 9.0\AOL.EXE" [2007-04-18 50736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-12-17 684032]
"HostManager"="c:\program files\Common Files\AOL\1124679661\ee\AOLSoftware.exe" [2008-06-24 41824]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 57344]
"Dell Photo AIO Printer 922"="c:\program files\Dell Photo AIO Printer 922\dlbtbmgr.exe" [2004-03-29 290816]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2003-07-28 4841472]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
"McAfeeUpdaterUI"="c:\common framework\UdaterUI.exe" [2006-12-19 136768]
"ShStatEXE"="c:\mcafee\SHSTAT.EXE" [2007-02-23 112216]
"SBAMTray"="c:\program files\Sunbelt Software\VIPRE\SBAMTray.exe" [2009-03-17 955688]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2003-07-28 323584]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 39264]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave"= serwvdrv.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0SsiEfr.e
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1124679661\\ee\\AOLServiceHost.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\acs\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\acs\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\1124679661\\ee\\aolsoftware.exe"=
"c:\\Program Files\\AOL 9.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Common Framework\\FrameworkService.exe"=
R1 sbaphd;sbaphd;c:\windows\system32\drivers\sbaphd.sys [4/25/2009 9:12 PM 13360]
R1 sbtis;sbtis;c:\windows\system32\drivers\sbtis.sys [4/25/2009 12:54 PM 202928]
R2 SBAMSvc;VIPRE Antivirus + Antispyware;c:\program files\Sunbelt Software\VIPRE\SBAMSvc.exe [3/17/2009 1:26 PM 894248]
R2 sbapifs;sbapifs;c:\windows\system32\drivers\sbapifs.sys [4/25/2009 9:13 PM 69936]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 8:19 PM 13592]
S3 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [10/22/2008 5:08 PM 92464]
.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://msn.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uInternet Connection Wizard,ShellNext = iexplore
IE: &AIM Search - c:\program files\AIM Toolbar\AIMBar.dll/aimsearch.htm
IE: &Search - ?p=ZUxdm265YYUS
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: colonialchem.com\colonialchem2
TCP: {F84C6EDD-ABEC-4007-91FE-D1F2F87F8136} = 4.2.2.2,4.2.2.3
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-08 21:14
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2009-05-09 21:17
ComboFix-quarantined-files.txt 2009-05-09 01:17
ComboFix2.txt 2009-05-07 02:35
Pre-Run: 63,323,787,264 bytes free
Post-Run: 63,395,381,248 bytes free
155 --- E O F --- 2009-04-29 07:06
Upload was successful

