Hello again, Judy!
It's nice to hear that Malwarebytes got rid of the viruses. Start-up has become noticeable faster now. Here is the ComboFix log file you asked for.
Does it show anything that I need to deal with?
Thank you so much!
ComboFix 08-09-10.04 - Carla 2008-09-11 22:43:06.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.559 [GMT 8:00]
Running from: C:\Documents and Settings\Carla\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
C:\WINDOWS\setup.exe
C:\WINDOWS\system32\lsprst7.dll
C:\WINDOWS\system32\nsprs.dll
C:\WINDOWS\system32\ssprs.dll
.
((((((((((((((((((((((((( Files Created from 2008-08-11 to 2008-09-11 )))))))))))))))))))))))))))))))
.
2008-09-11 20:10 . 2008-09-11 20:53 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-11 20:10 . 2008-09-11 20:10 d-------- C:\Documents and Settings\Carla\Application Data\Malwarebytes
2008-09-11 20:10 . 2008-09-11 20:10 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-11 20:10 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-11 20:10 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-10 22:15 . 2008-09-10 22:15 1,024 --a------ C:\WINDOWS\system32\clauth2.dll
2008-09-10 22:15 . 2008-09-10 22:15 1,024 --a------ C:\WINDOWS\system32\clauth1.dll
2008-09-10 22:15 . 2008-09-10 22:34 14 --a------ C:\WINDOWS\system32\ssprs.tgz
2008-09-10 22:15 . 2008-09-10 22:15 0 --a------ C:\WINDOWS\system32\nsprs.tgz
2008-09-10 22:13 . 2008-09-10 22:34 d-------- C:\Program Files\SPSS Evaluation
2008-09-10 22:13 . 2008-09-10 22:13 1,025 --a------ C:\WINDOWS\system32\sysprs7.tgz
2008-09-10 22:13 . 2008-09-10 22:13 1,025 --a------ C:\WINDOWS\system32\sysprs7.dll
2008-09-10 22:13 . 2008-09-10 22:34 219 --a------ C:\WINDOWS\system32\lsprst7.tgz
2008-09-10 22:13 . 2008-09-10 22:34 16 ---h----- C:\WINDOWS\system32\servdat.slm
2008-08-26 17:29 . 2008-08-26 17:29 d-------- C:\Documents and Settings\All Users\Application Data\Trymedia
2008-08-23 21:05 . 2008-08-23 21:05 d-------- C:\Documents and Settings\Carla\Application Data\GlarySoft
2008-08-23 20:40 . 2008-08-23 20:40 d-------- C:\Documents and Settings\Carla\Application Data\Uniblue
2008-08-23 19:40 . 2008-08-23 19:44 d-------- C:\Program Files\Windows Live Safety Center
2008-08-14 20:38 . 2008-08-23 20:27 d-------- C:\WINDOWS\BDOSCAN8
2008-08-14 20:37 . 2008-05-01 22:30 331,776 -----c--- C:\WINDOWS\system32\dllcache\msadce.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-11 12:15 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-09-10 14:40 --------- d-----w C:\Program Files\Trend Micro
2008-08-23 11:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-07-26 14:26 --------- d-----w C:\Program Files\Norton Internet Security
2008-07-15 09:16 229,376 ----a-w C:\Documents and Settings\Carla\cwshredder.dll
2008-07-12 11:36 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-07-12 11:36 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2008-07-12 11:36 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-07-12 11:36 10,671 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-07-12 11:36 --------- d-----w C:\Program Files\Symantec
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 15:38 659,456 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-14 1694208]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-06-23 171448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VAIOCameraUtility"="C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe" [2005-12-01 69632]
"VAIO Update 2"="C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" [2005-10-12 151552]
"VAIO Recovery"="C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-20 28672]
"URLLSTCK.exe"="C:\Program Files\Norton Internet Security\UrlLstCk.exe" [2007-01-16 23168]
"SonyPowerCfg"="C:\Program Files\Sony\VAIO Power Management\SPMgr.exe" [2005-10-20 184320]
"PartSeal"="C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-20 28672]
"ISBMgr.exe"="C:\Program Files\Sony\ISB Utility\ISBMgr.exe" [2004-02-21 32768]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-08-06 94208]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-08-06 114688]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-08-06 77824]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-22 52840]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-11-18 118784]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"RTHDCPL"="RTHDCPL.EXE" [2005-08-10 C:\WINDOWS\RTHDCPL.EXE]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Trend Micro Anti-Spyware.lnk - C:\Program Files\Trend Micro\Tmas\Tmas.exe [2008-06-10 1310720]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{03A80B1D-5C6A-42c2-9DFB-81B6005D8023}"= "C:\Program Files\Trend Micro\Tmas\sshook.dll" [2008-06-10 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2005-05-21 09:42 73728 C:\WINDOWS\system32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= C:\PROGRA~1\COMMON~1\SONYSH~1\VideoLib\sonydv.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AzMixerSel]
--a------ 2005-06-12 10:51 53248 C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ExecAfterFirstBoot]
--a------ 2005-03-17 03:22 204800 C:\WINDOWS\SONYSYS\EFlyer\ExecAfterFirstBoot.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
--a------ 2005-11-05 05:25 159832 C:\Program Files\Common Files\AOL\1213081842\ee\AOLHostManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-14 00:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2005-08-27 10:14 36975 C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2008-06-23 15:31 171448 C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VAIOSurvey]
--a------ 2005-06-14 06:42 258048 c:\Program Files\Sony\VAIO Survey\SurveySA.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Sony Pictures Games\\JEOPARDY!\\JEOPARDY!.exe"=
R3 SonyImgF;Sony Image Conversion Filter Driver;C:\WINDOWS\system32\DRIVERS\SonyImgF.sys [2005-12-01 28800]
S3 Image Converter video recording monitor for VAIO Entertainment;Image Converter video recording monitor for VAIO Entertainment;C:\Program Files\Sony\Image Converter 2\IcVzMon.exe [2005-07-15 32768]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{35225c8c-52d6-11dd-acb3-00014af93d20}]
\Shell\AutoRun\command - F:\t.com
\Shell\explore\Command - F:\t.com
\Shell\open\Command - F:\t.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{38718874-5782-11dd-acb9-00014af93d20}]
\Shell\Auto\command - Recycled/dllcache32.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled/dllcache32.exe
\Shell\explore\Command - Recycled/dllcache32.exe
\Shell\open\Command - Recycled/dllcache32.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b864f37a-678d-11dd-accf-00014af93d20}]
\Shell\AutoRun\command - F:\tyktjfww.exe
\Shell\explore\Command - F:\tyktjfww.exe
\Shell\open\Command - F:\tyktjfww.exe
*Newly Created Service* - COMHOST
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Mouse Suite 98 Daemon - ICO.EXE
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.sony.com/vaiopeople
R0 -: HKCU-Main,Search Page = hxxp://www.google.com
R0 -: HKCU-Main,Search Bar = hxxp://www.google.com/ie
R1 -: HKCU-Internet Connection Wizard,ShellNext = hxxp://www.sony.com/vaiopeople
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O16 -: {BDEE1959-AB6B-4745-A29B-F492861102CC} - hxxp://www.amustsoft.com/onlineregistryscan/onlineRegCleaner.cab
C:\WINDOWS\Downloaded Program Files\onlineRegCleaner.inf
C:\WINDOWS\Downloaded Program Files\regengine.dll
C:\WINDOWS\Downloaded Program Files\ignores.dat
C:\WINDOWS\Downloaded Program Files\amguires.ama
C:\WINDOWS\Downloaded Program Files\amControl.dll
C:\WINDOWS\Downloaded Program Files\onlineRegCleaner2.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-11 22:45:11
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-09-11 22:46:14
ComboFix-quarantined-files.txt 2008-09-11 14:46:10
Pre-Run: 83,840,294,912 bytes free
Post-Run: 84,026,474,496 bytes free
166 --- E O F --- 2008-08-23 11:29:17