Hello SuperDave
Thank you very much for taking the time to help me.
While I was waiting for a response I went to the Topic Starter Self help - Use the Computer Hope HijackThis process tool and I followed some of the recommendations given so I did not have all the things you wrote to delete but I still had some this time around. Anyways, Here it goes the requested stuff:
http://virusscan.jotti.org/en/scanresult/34f2157a1134a707e832c5f2175e2a7b1b71121a Results of screen317's Security Check version 0.99.5
Windows Vista Service Pack 1 (UAC is enabled)
Out of date service pack!![/b]
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check: Windows Firewall Enabled!
avast! Free Antivirus
WMI entry may not exist for antivirus; attempting automatic update. ```````````````````````````````
Anti-malware/Other Utilities Check: Malwarebytes' Anti-Malware
HijackThis 2.0.2
CCleaner
Java(TM) 6 Update 21
Java(TM) 6 Update 2
Java(TM) 6 Update 3
Out of date Java installed! Adobe Flash Player 10.0.32.18
Adobe Reader 7.0
Out of date Adobe Reader installed! ````````````````````````````````
Process Check:
objlist.exe by Laurent Windows Defender MSASCui.exe
Windows Defender MSASCui.exe
Alwil Software Avast5 AvastSvc.exe
Alwil Software Avast5 AvastUI.exe
````````````````````````````````
DNS Vulnerability Check: GREAT! (Not vulnerable to DNS cache poisoning)
``````````End of Log```````````` ComboFix 10-08-12.02 - el pelon 08/13/2010 20:39:10.1.1 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6001.1.1252.1.1033.18.501.160 [GMT -7:00]
Running from: c:\users\el pelon\Desktop\ComboFix.exe
SP: SUPERAntiSpyware *enabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\CyberDefender
c:\program files\CyberDefender\Registry Cleaner\BeforeUninstall.exe
c:\program files\CyberDefender\Registry Cleaner\CDRC.dll
c:\program files\CyberDefender\Registry Cleaner\CDregclean.exe
c:\program files\CyberDefender\Registry Cleaner\cdswx.exe
c:\program files\CyberDefender\Registry Cleaner\KillCDRCProcesses.exe
c:\program files\CyberDefender\Registry Cleaner\startcdrc.exe
c:\program files\CyberDefender\Registry Cleaner\unins000.exe
c:\programdata\Microsoft\Windows\Start Menu\Programs\CyberDefender
c:\programdata\Microsoft\Windows\Start Menu\Programs\CyberDefender\Registry Cleaner\CyberDefender Registry Cleaner.lnk
c:\programdata\Microsoft\Windows\Start Menu\Programs\CyberDefender\Registry Cleaner\Uninstall CyberDefender Registry Cleaner.lnk
c:\users\el pelon\AppData\Roaming\CyberDefender
c:\users\el pelon\AppData\Roaming\CyberDefender\Registry Cleaner\lastresults.cdr
.
((((((((((((((((((((((((( Files Created from 2010-07-14 to 2010-08-14 )))))))))))))))))))))))))))))))
.
2010-08-14 03:49 . 2010-08-14 03:50 -------- d-----w- c:\users\el pelon\AppData\Local\temp
2010-08-14 03:49 . 2010-08-14 03:49 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-08-12 02:39 . 2010-08-12 02:39 -------- d-----w- c:\program files\Trend Micro
2010-08-12 02:25 . 2010-08-12 02:24 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-08-11 21:29 . 2010-08-11 21:29 -------- d-----w- c:\program files\CCleaner
2010-08-11 18:57 . 2010-06-28 20:37 165456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-08-11 18:57 . 2010-06-28 20:32 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-08-11 18:57 . 2010-06-28 20:33 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-08-11 18:57 . 2010-06-28 20:37 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-08-11 18:57 . 2010-06-28 20:32 50256 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2010-08-11 18:55 . 2010-06-28 20:57 38848 ----a-w- c:\windows\avastSS.scr
2010-08-11 18:55 . 2010-06-28 20:57 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-08-11 18:54 . 2010-08-11 18:54 -------- d-----w- c:\programdata\Alwil Software
2010-08-11 18:54 . 2010-08-11 18:54 -------- d-----w- c:\program files\Alwil Software
2010-08-11 10:25 . 2010-08-11 10:25 -------- d-----w- C:\PerfLogs
2010-08-10 19:54 . 2010-08-10 19:54 -------- d-----w- c:\users\el pelon\AppData\Roaming\Malwarebytes
2010-08-10 19:53 . 2010-04-29 22:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-10 19:52 . 2010-08-10 19:52 -------- d-----w- c:\programdata\Malwarebytes
2010-08-10 19:52 . 2010-04-29 22:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-08-10 19:52 . 2010-08-10 19:53 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-08-09 06:57 . 2010-08-09 06:57 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2010-08-07 21:15 . 2010-08-07 21:15 -------- d-----w- c:\users\el pelon\AppData\Roaming\Symantec
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-14 01:38 . 2007-09-09 20:51 -------- d-----w- c:\users\el pelon\AppData\Roaming\LimeWire
2010-08-13 18:22 . 2007-12-18 06:37 -------- d-----w- c:\program files\Common Files\aolshare
2010-08-13 18:22 . 2007-11-27 05:46 -------- d-----w- c:\program files\DivX
2010-08-13 18:22 . 2007-12-18 05:31 -------- d-----w- c:\program files\Common Files\AOL
2010-08-13 17:47 . 2007-04-10 16:29 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-08-13 17:47 . 2008-01-28 06:44 -------- d-----w- c:\users\el pelon\AppData\Roaming\DataCast
2010-08-13 17:43 . 2007-04-10 17:33 -------- d-----w- c:\programdata\Symantec
2010-08-13 17:43 . 2007-04-10 17:32 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-08-12 03:20 . 2007-12-18 05:32 -------- d-----w- c:\programdata\AOL
2010-08-12 03:18 . 2007-12-18 06:45 -------- d-----w- c:\users\el pelon\AppData\Roaming\AOL
2010-08-12 02:27 . 2007-09-09 20:49 -------- d-----w- c:\program files\Common Files\Java
2010-08-12 02:24 . 2007-09-09 20:49 -------- d-----w- c:\program files\Java
2010-08-11 22:20 . 2008-02-18 08:38 -------- d-----w- c:\program files\Google
2010-08-11 17:19 . 2010-04-22 13:42 -------- d-----w- c:\programdata\avg9
2010-08-11 17:15 . 2010-08-11 17:15 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2010-08-11 10:27 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Sidebar
2010-08-11 10:27 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Calendar
2010-08-11 10:27 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-08-11 10:27 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Photo Gallery
2010-08-11 10:27 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Collaboration
2010-08-11 10:27 . 2006-11-02 12:35 -------- d-----w- c:\program files\Windows Defender
2010-08-11 10:25 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2010-08-10 16:28 . 2006-11-02 10:32 101888 ----a-w- c:\windows\system32\ifxcardm.dll
2010-08-10 16:28 . 2006-11-02 10:32 82432 ----a-w- c:\windows\system32\axaltocm.dll
2010-08-10 03:08 . 2008-07-21 20:52 -------- d-----w- c:\program files\Lexmark Toolbar
2010-05-21 21:14 . 2010-01-16 00:40 221568 ------w- c:\windows\system32\MpSigStub.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-16 815104]
"RtHDVCpl"="RtHDVCpl.exe" [2006-12-01 4186112]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-11-06 106496]
"Persistence"="c:\windows\system32\igfxpers.exe" [2006-11-06 81920]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2007-01-11 483328]
"Acer Assist Launcher"="c:\program files\Acer Assist\launcher.exe" [2006-12-07 1261568]
"Acer Product Registration"="c:\program files\Acer Registration\ACE1.exe" [2006-12-13 3166208]
"Acer Tour Reminder"="c:\acer\AcerTour\Reminder.exe" [2007-01-17 151552]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-12-11 286720]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-06-28 2837864]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2007-4-10 528384]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-04-22 135664]
S1 aswSP;aswSP;
S2 aswFsBlk;aswFsBlk;
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-06-28 50256]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
.
Contents of the 'Scheduled Tasks' folder
2010-08-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-22 03:28]
2010-08-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-22 03:28]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Acer Tour Reminder - (no file)
HKLM-Run-Acer Tour - (no file)
HKLM-Run-eRecoveryService - (no file)
HKLM-Run-CyberDefender Registry Cleaner - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-08-13 20:50
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Completion time: 2010-08-13 20:55:17
ComboFix-quarantined-files.txt 2010-08-14 03:55
Pre-Run: 13,473,890,304 bytes free
Post-Run: 13,422,751,744 bytes free
- - End Of File - - 3573C2DD2693CDA3E6E38F6B530B0C84
THANK YOU SO MUCH