Hi OCD - Here is the log.txt file after running ComboFix: The machine seemed like it took longer to reboot than normal, but it seems to be running ok now…
ComboFix 09-05-31.02 - Carrie Ann 05/31/2009 18:16.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1012.659 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090530-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((( Files Created from 2009-04-28 to 2009-05-31 )))))))))))))))))))))))))))))))
.
2009-05-30 03:53 . 2009-05-30 03:53 ——– d—–w- c:\documents and settings\Carrie Ann\Local Settings\Application Data\Adobe
2009-05-30 03:53 . 2009-05-30 03:53 ——– d—–w- c:\documents and settings\Carrie Ann\Local Settings\Application Data\Identities
2009-05-30 03:53 . 2009-05-30 03:53 ——– d—–w- c:\documents and settings\Carrie Ann\Local Settings\Application Data\Google
2009-05-30 03:52 . 2009-05-30 03:52 ——– d—–w- c:\documents and settings\Carrie Ann\Local Settings\Application Data\Mozilla
2009-05-30 03:35 . 2009-05-30 03:35 ——– d-sh–w- c:\documents and settings\Carrie Ann\IETldCache
2009-05-30 03:23 . 2009-05-30 03:23 ——– d-sh–w- c:\documents and settings\TEMP.CAD\IETldCache
2009-05-30 03:20 . 2009-05-30 03:20 ——– d—–w- c:\documents and settings\TEMP
2009-05-30 02:57 . 2009-05-30 02:57 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2009-05-29 02:18 . 2009-05-29 02:18 ——– d—–w- C:\_OTListIt
2009-05-24 05:15 . 2009-05-24 05:15 ——– d—–w- c:\windows\SHELLNEW
2009-05-24 00:12 . 2009-05-24 00:12 ——– d-sh–w- c:\documents and settings\Carrie\IETldCache
2009-05-24 00:09 . 2009-05-24 00:09 ——– d—–w- c:\windows\ie8updates
2009-05-24 00:08 . 2009-04-25 05:30 102400 -c—-w- c:\windows\system32\dllcache\iecompat.dll
2009-05-24 00:06 . 2009-05-24 00:08 ——– dc-h–w- c:\windows\ie8
2009-05-23 04:32 . 2009-05-23 04:32 ——– d—–w- c:\program files\Trend Micro
2009-05-16 03:31 . 2009-05-16 03:31 2967799 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-05-16 00:19 . 2009-05-16 00:19 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2009-05-15 12:07 . 2007-10-23 14:27 110592 —-a-w- c:\documents and settings\Administrator\Application Data\U3\temp\cleanup.exe
2009-05-15 12:04 . 2008-05-02 15:41 3493888 —ha-w- c:\documents and settings\Administrator\Application Data\U3\temp\Launchpad Removal.exe
2009-05-15 12:04 . 2009-05-15 12:04 ——– d—–w- c:\documents and settings\Administrator\Application Data\U3
2009-05-15 02:20 . 2009-05-15 02:20 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-05-15 02:20 . 2009-04-06 20:32 15504 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-05-15 02:20 . 2009-04-06 20:32 38496 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-15 02:20 . 2009-05-16 03:31 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-05-15 02:20 . 2009-05-15 02:20 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-15 01:56 . 2008-04-14 05:10 57600 -c–a-w- c:\windows\system32\dllcache\redbook.sys
2009-05-15 01:56 . 2008-04-14 05:10 57600 —-a-w- c:\windows\system32\drivers\redbook.sys
2009-05-03 15:27 . 2008-04-14 20:00 26624 —-a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2009-05-03 15:22 . 2009-05-03 15:22 ——– d—–w- c:\program files\Windows Media Connect 2
2009-05-03 15:20 . 2009-05-03 15:21 ——– d—–w- c:\windows\system32\drivers\UMDF
2009-05-03 15:20 . 2009-05-03 15:20 ——– d—–w- c:\windows\system32\LogFiles
2009-05-03 15:07 . 2009-05-03 15:09 ——– d—–w- C:\Music
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-30 03:42 . 2009-05-30 03:42 ——– d—–w- c:\documents and settings\Carrie Ann\Application Data\GetRightToGo
2009-05-30 03:42 . 2009-05-30 03:42 ——– d—–w- c:\documents and settings\Carrie Ann\Application Data\Malwarebytes
2009-05-30 03:42 . 2009-05-30 03:42 ——– d—–w- c:\documents and settings\Carrie Ann\Application Data\Template
2009-05-30 03:42 . 2009-05-30 03:42 ——– d—–w- c:\documents and settings\Carrie Ann\Application Data\U3
2009-05-24 05:16 . 2009-01-20 19:19 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-05-24 04:54 . 2009-01-20 19:28 ——– d—–w- c:\program files\eSobi
2009-05-23 01:57 . 2009-05-30 03:42 300 —-a-w- c:\documents and settings\Carrie Ann\Application Data\wklnhst.dat
2009-05-12 00:16 . 2009-01-20 18:45 ——– d—–w- c:\program files\Common Files\Adobe
2009-04-29 22:05 . 2009-01-20 18:10 76487 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-29 05:07 . 2009-04-29 05:03 139554 —-a-w- c:\windows\hpoins21.dat
2009-04-29 05:07 . 2009-04-29 05:07 ——– d—–w- c:\program files\Common Files\HP
2009-04-29 05:07 . 2009-04-29 05:07 ——– d—–w- c:\program files\Common Files\Hewlett-Packard
2009-04-29 05:07 . 2009-04-29 05:07 ——– d—–w- c:\program files\Hewlett-Packard
2009-04-29 05:06 . 2009-04-29 05:06 ——– d—–w- c:\documents and settings\All Users\Application Data\Hewlett-Packard
2009-04-29 05:04 . 2009-04-29 05:04 ——– d—–w- c:\program files\HP
2009-04-26 13:49 . 2009-05-30 03:35 60592 —-a-w- c:\documents and settings\Carrie Ann\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-20 14:12 . 2009-04-20 14:12 0 —-a-w- c:\windows\nsreg.dat
2009-04-06 12:48 . 2009-04-06 12:48 ——– d—–w- c:\program files\MSBuild
2009-04-06 12:48 . 2009-04-06 12:48 ——– d—–w- c:\program files\Reference Assemblies
2009-04-06 12:19 . 2009-01-20 19:05 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2009-04-06 12:19 . 2009-01-20 20:16 ——– d—–w- c:\program files\McAfee
2009-04-06 12:17 . 2009-01-20 19:22 ——– d—–w- c:\program files\Google
2009-04-06 12:16 . 2009-04-06 12:16 ——– d—–w- c:\program files\Alwil Software
2009-04-06 11:54 . 2009-04-06 11:54 ——– d—–w- c:\program files\Common Files\SNP2UVC
2009-04-06 11:54 . 2009-01-20 20:05 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-03-08 09:34 . 2008-10-16 20:38 914944 —-a-w- c:\windows\system32\wininet.dll
2009-03-08 09:34 . 2007-08-14 02:44 43008 —-a-w- c:\windows\system32\licmgr10.dll
2009-03-08 09:33 . 2008-04-14 20:00 18944 —-a-w- c:\windows\system32\corpol.dll
2009-03-08 09:33 . 2008-05-09 10:53 420352 —-a-w- c:\windows\system32\vbscript.dll
2009-03-08 09:32 . 2007-08-14 02:39 72704 —-a-w- c:\windows\system32\admparse.dll
2009-03-08 09:32 . 2007-08-14 02:39 71680 —-a-w- c:\windows\system32\iesetup.dll
2009-03-08 09:31 . 2007-08-14 02:36 34816 —-a-w- c:\windows\system32\imgutil.dll
2009-03-08 09:31 . 2007-08-14 02:01 48128 —-a-w- c:\windows\system32\mshtmler.dll
2009-03-08 09:31 . 2007-08-14 02:32 45568 —-a-w- c:\windows\system32\mshta.exe
2009-03-08 09:22 . 2007-08-14 02:54 156160 —-a-w- c:\windows\system32\msls31.dll
2009-03-06 14:22 . 2008-04-14 20:00 284160 —-a-w- c:\windows\system32\pdh.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-28 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-28 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-28 137752]
"AzMixerSel"="c:\program files\Realtek\Audio\Drivers\AzMixerSel.exe" [2006-07-18 53248]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-25 1044480]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2008-05-14 821768]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"CarboniteSetupLite"="c:\program files\Carbonite\CarbonitePreinstaller.exe" [2008-10-03 294544]
"PLFSetL"="c:\windows\PLFSetL.exe" [2007-07-05 94208]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\eRAgent.exe" [2008-09-04 425984]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2008-12-30 18082304]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
InterVideo WinCinema Manager.lnk - c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe [2008-6-4 114688]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [4/6/2009 7:16 AM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [4/6/2009 7:16 AM 20560]
S3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [7/8/2008 12:16 PM 96856]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\77.tmp –> c:\windows\system32\77.tmp [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-snp2uvc - c:\windows\vsnp2uvc.exe
SafeBoot-procexp90.Sys
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://global.acer.com
FF - ProfilePath - c:\documents and settings\Carrie Ann\Application Data\Mozilla\Firefox\Profiles\cga6bqxj.default\
FF - prefs.js: browser.startup.homepage - www.yahoo.com
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-05-31 18:19
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\77.tmp"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(712)
c:\windows\system32\igfxdev.dll
- - - - - - - > 'explorer.exe'(3416)
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-05-31 18:21
ComboFix-quarantined-files.txt 2009-05-31 23:21
Pre-Run: 140,315,709,440 bytes free
Post-Run: 140,305,846,272 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
167 — E O F — 2009-05-14 18:23