hi in end had to uninstall norton as would not allow me to disable...nightmare so if you have a suggestion for a good free one, let me know. also malwarebyte would not open / run not sure why but here are the logs...
ComboFix 09-06-07.05 - Bradley 08/06/2009 11:10.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.353.1033.18.1790.1009 [GMT 1:00]
Running from: c:\users\Bradley\Desktop\FIX\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
D:\Desktop.ini
.
((((((((((((((((((((((((( Files Created from 2009-05-08 to 2009-06-08 )))))))))))))))))))))))))))))))
.
2009-06-08 09:45 . 2009-06-08 09:45 -------- d-----w- c:\progra~2\Yahoo! Companion
2009-06-08 07:34 . 2009-06-08 10:12 -------- d---a-w- \Qoobox
2009-06-08 07:30 . 2009-06-08 07:30 -------- d-----w- c:\program files\Yahoo!
2009-06-08 07:30 . 2009-06-08 07:31 -------- d-----w- c:\program files\CCleaner
2009-06-08 07:25 . 2009-06-08 07:26 288267 ----a-w- c:\users\Bradley\Fix_download.exe
2009-05-26 18:41 . 2009-06-08 09:49 -------- d-----w- c:\users\Bradley\Tracing
2009-05-26 15:16 . 2009-05-26 15:16 -------- d-----w- c:\program files\Microsoft
2009-05-26 15:16 . 2009-05-26 15:16 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-05-26 15:16 . 2009-05-26 15:16 -------- d-----w- c:\program files\Windows Live
2009-05-26 15:08 . 2009-05-26 15:08 -------- d-----w- c:\program files\Common Files\Windows Live
2009-05-09 17:38 . 2009-05-09 17:38 -------- d-----w- c:\users\Bradley\AppData\Local\Microsoft Help
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-08 10:07 . 2008-05-21 10:37 -------- d-----w- c:\program files\Symantec
2009-06-08 10:07 . 2008-05-21 10:37 -------- d-----w- c:\progra~2\Symantec
2009-06-08 10:07 . 2008-05-21 10:37 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-06-08 10:07 . 2008-05-21 10:38 -------- d-----w- c:\program files\Norton Internet Security
2009-06-08 10:05 . 2009-04-19 00:18 -------- d-----w- c:\users\Bradley\AppData\Roaming\Skype
2009-06-08 09:49 . 2008-07-02 13:13 42749 ----a-w- c:\progra~2\nvModes.dat
2009-06-08 09:47 . 2008-07-02 12:31 1877348352 --sha-w- \hiberfil.sys
2009-06-08 09:47 . 2008-07-02 12:31 2191200256 --sha-w- \pagefile.sys
2009-06-08 09:01 . 2008-11-09 13:06 7592 ----a-w- c:\users\Bradley\AppData\Local\d3d9caps.dat
2009-06-08 08:32 . 2009-04-19 07:03 -------- d-----w- c:\users\Bradley\AppData\Roaming\skypePM
2009-06-08 07:47 . 2008-05-21 10:37 806 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
2009-06-08 07:47 . 2008-05-21 10:37 10635 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2009-05-14 10:58 . 2008-05-21 12:00 -------- d-----w- c:\progra~2\Microsoft Help
2009-05-14 10:57 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-04-22 15:45 . 2009-04-22 15:40 -------- d-----w- c:\program files\Mobile Partner
2009-04-19 07:03 . 2009-04-19 07:03 32 ----a-w- c:\progra~2\ezsid.dat
2009-04-18 19:08 . 2009-04-18 19:08 -------- d-----w- c:\program files\Skype
2009-04-18 19:08 . 2009-04-18 19:08 -------- d-----w- c:\progra~2\Skype
2009-04-18 19:08 . 2009-04-18 19:08 -------- d-----w- c:\program files\Common Files\Skype
2009-04-11 10:40 . 2009-04-11 10:39 88 ----a-w- c:\users\Bradley\AppData\Roaming\wklnhst.dat
2009-04-11 10:39 . 2009-04-11 10:39 -------- d-----w- c:\users\Bradley\AppData\Roaming\Template
2009-04-07 12:45 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-03-17 03:38 . 2009-04-15 09:10 13824 ----a-w- c:\windows\system32\apilogen.dll
2009-03-17 03:38 . 2009-04-15 09:10 24064 ----a-w- c:\windows\system32\amxread.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-02-26 2289664]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-03-27 21898024]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13535776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-03 92704]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-17 1049896]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-12-24 222504]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2008-04-02 468264]
"QlbCtrl.exe"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-03-14 202032]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-04-15 70912]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-09-01 282624]
"EverioService"="c:\program files\CyberLink\PCM4Everio\EverioService.exe" [2007-11-01 151552]
c:\users\Bradley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
LUMIX Simple Viewer.lnk - c:\program files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe [2008-10-21 63696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
"HideFastUserSwitching"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{73DCAADE-7627-4A60-8086-FF24BB17F1EB}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{2F027587-83B6-45B1-BB62-3CA8EF66ABBA}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{5DDEF9C1-480A-4BEB-949F-2426162E634D}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{B6A2E135-1DFB-42C3-BA63-1BAF7B3A59CF}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{D0C40AC4-6AEC-4CB1-8E4D-BB41A513DE82}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
"{B021AD9D-8D77-44D8-BD11-107032582F2A}"= c:\program files\CyberLink\PowerDirector Express\PDX.EXE:CyberLink PowerDirector Express
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe -k netsvcs [21/01/2008 03:23 21504]
R2 Recovery Service for Windows;Recovery Service for Windows;c:\windows\SMINST\BLService.exe [21/05/2008 13:26 361808]
R3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [21/05/2008 12:04 193840]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\System32\drivers\nvhda32v.sys [03/05/2008 13:39 42528]
--- Other Services/Drivers In Memory ---
*Deregistered* - eeCtrl
*Deregistered* - SRTSPX
*Deregistered* - SymIM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
2009-06-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2006-08-29 13:21]
2009-06-07 c:\windows\Tasks\User_Feed_Synchronization-{E1A482F2-213F-4F80-9BAD-0F4211C2CFAF}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 02:24]
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-procexp90.Sys
.
------- Supplementary Scan -------
.
uStart Page = hxxp://mail.live.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_ie&c=83&bd=Presario&pf=cnnb
IE: &AOL Toolbar Search - c:\programdata\AOL\ieToolbar\resources\en-IE\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, https://www.gmer.net
Rootkit scan 2009-06-08 11:13
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\
0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-06-08 11:15
ComboFix-quarantined-files.txt 2009-06-08 10:14
Pre-Run: 82,728,960,000 bytes free
Post-Run: 83,588,714,496 bytes free
168 --- E O F --- 2009-06-05 07:57