I apologize. I am still in need of your assistance. Work has delayed me. I believe this is what you asked for.
ComboFix 09-12-29.06 - HP_Administrator 12/30/2009 20:34:21.6.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.601 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\HP_Administrator\Desktop\CFScript.txt
AV: a-squared Anti-Malware *On-access scanning disabled* (Updated) {0F8591BB-342B-4493-91C3-4E948ED21255}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
file zipped: c:\windows\system32\bofavoju.dll
file zipped: c:\windows\system32\jadebaji.dll
file zipped: c:\windows\system32\vizisida.dll
file zipped: c:\windows\system32\yekikewa.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\HP_Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Internet Security 2010.lnk
c:\windows\system32\bofavoju.dll
c:\windows\system32\jadebaji.dll
c:\windows\system32\vizisida.dll
c:\windows\system32\yekikewa.dll
.
((((((((((((((((((((((((( Files Created from 2009-11-28 to 2009-12-31 )))))))))))))))))))))))))))))))
.
2009-12-26 06:09 . 2009-12-28 04:27 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-23 03:49 . 2009-12-23 03:49 ——– d—–w- c:\documents and settings\HP_Administrator\Application Data\Malwarebytes
2009-12-23 03:49 . 2009-12-23 03:49 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-19 20:55 . 2009-12-19 20:55 0 —-a-w- c:\documents and settings\HP_Administrator\settings.dat
2009-12-19 20:49 . 2009-12-19 20:50 ——– d—–w- c:\program files\ERUNT
2009-12-19 20:33 . 2009-12-29 20:52 52224 —-a-w- c:\documents and settings\HP_Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2009-12-11 23:03 . 2009-12-29 20:34 ——– d—–w- c:\program files\Norton Security Scan
2009-12-09 09:00 . 2009-12-09 09:00 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-31 01:41 . 2008-10-17 19:51 ——– d—–w- c:\documents and settings\HP_Administrator\Application Data\DNA
2009-12-29 20:52 . 2009-06-11 22:49 117760 —-a-w- c:\documents and settings\HP_Administrator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2009-12-29 20:48 . 2008-10-17 19:51 ——– d—–w- c:\program files\DNA
2009-12-29 20:34 . 2009-08-09 06:29 ——– d—–w- c:\documents and settings\All Users\Application Data\Norton
2009-12-29 20:34 . 2006-07-31 23:52 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-12-24 23:57 . 2007-02-06 22:01 ——– d—–w- c:\documents and settings\HP_Administrator\Application Data\BitTorrent
2009-12-11 23:03 . 2009-08-09 06:29 ——– d—–w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-12-09 08:11 . 2008-08-29 20:52 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-10-29 07:45 . 2004-08-10 04:00 916480 ——w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2004-08-10 04:00 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-10 04:00 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-10 04:00 265728 ——w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2004-08-10 04:00 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2004-08-10 04:00 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2004-08-10 04:00 79872 —-a-w- c:\windows\system32\raschap.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2009-12-09 323392]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-05-26 1830128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-30 67584]
"ftutil2"="ftutil2.dll" [2004-06-07 106496]
"RTHDCPL"="RTHDCPL.EXE" [2006-06-14 16239616]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 77312]
"DMAScheduler"="c:\program files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-04-13 90112]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-23 237568]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-16 249856]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2005-02-16 221184]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-07-31 180269]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]
"nwiz"="nwiz.exe" [2006-05-09 1519616]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-16 86016]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"a-squared"="c:\program files\A-SQUARED ANTI-MALWARE\a2guard.exe" [2009-02-25 2799760]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-10-25 282624]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]
c:\documents and settings\HP_Administrator\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Updates From HP.lnk - c:\program files\Updates from HP\9972322\Program\Updates from HP.exe [2006-7-31 36903]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 16:05 356352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2006-10-25 23:58 282624 —-a-w- c:\program files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DISC\\DISCover.exe"=
"c:\\Program Files\\DISC\\DiscStreamHub.exe"=
"c:\\Program Files\\DISC\\myFTP.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\a-squared Anti-Malware\\a2guard.exe"=
"c:\\hp\\KBD\\kbd.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [5/26/2009 9:05 AM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/26/2009 9:05 AM 72944]
R2 a2AntiMalware;a-squared Anti-Malware Service;c:\program files\a-squared Anti-Malware\a2service.exe [3/14/2009 11:54 PM 425080]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [5/26/2009 9:05 AM 7408]
.
Contents of the 'Scheduled Tasks' folder
2009-12-31 c:\windows\Tasks\User_Feed_Synchronization-{84B2B653-5DBF-4B0E-A1A8-9B78EA3FD5EE}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 08:31]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-12-30 20:40
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(768)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
.
Completion time: 2009-12-30 20:43:45
ComboFix-quarantined-files.txt 2009-12-31 01:43
ComboFix2.txt 2009-12-29 20:59
ComboFix3.txt 2009-12-28 05:03
ComboFix4.txt 2009-12-25 17:30
ComboFix5.txt 2009-12-31 01:33
Pre-Run: 26,259,488,768 bytes free
Post-Run: 26,219,847,680 bytes free
- - End Of File - - E4944793F291A3FCB4F124C183A15208
Upload was successful
C:\hp\bin\wbug\HPPavillion_Spring06.exe a variant of Win32/Toolbar.MyWebSearch application
C:\Qoobox\Quarantine\[4]-Submit_2009-12-27_23.31.42.zip multiple threats
C:\Qoobox\Quarantine\[4]-Submit_2009-12-30_20.34.14.zip multiple threats
C:\Qoobox\Quarantine\C\Documents and Settings\HP_Administrator\protect.dll.vir Win32/Rootkit.Agent.NIZ trojan
C:\Qoobox\Quarantine\C\Documents and Settings\HP_Administrator\Start Menu\Programs\Startup\ChkDisk.dll.vir Win32/Rootkit.Agent.NIZ trojan
C:\Qoobox\Quarantine\C\Documents and Settings\LocalService\protect.dll.vir Win32/Rootkit.Agent.NIZ trojan
C:\Qoobox\Quarantine\C\Documents and Settings\NetworkService\protect.dll.vir Win32/Rootkit.Agent.NIZ trojan
C:\Qoobox\Quarantine\C\Program Files\InternetSecurity2010\IS2010.exe.vir Win32/Adware.AdvancedVirusRemover.B application
C:\Qoobox\Quarantine\C\WINDOWS\system32\292.exe.vir a variant of Win32/Kryptik.AZD trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\2995.exe.vir a variant of Win32/Kryptik.AZD trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\autochk.dll.vir Win32/Rootkit.Agent.NIZ trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\critical_warning.html.vir Win32/TrojanDownloader.FakeAlert.AED virus
C:\Qoobox\Quarantine\C\WINDOWS\system32\dezuwabi.dll.vir a variant of Win32/Kryptik.BOP trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\foyugujo.dll.vir a variant of Win32/Kryptik.BOP trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\kivihude.dll.vir a variant of Win32/Kryptik.BOP trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\mohugeze.dll.vir a variant of Win32/Kryptik.BOP trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\pagapobo.dll.vir a variant of Win32/Kryptik.BOP trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\voyutepu.dll.vir a variant of Win32/Kryptik.BOP trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\winlogon86.exe.vir Win32/TrojanDownloader.FakeAlert.AED trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\winupdate86.exe.vir Win32/TrojanDownloader.FakeAlert.AED trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\zupijulo.dll.vir a variant of Win32/Kryptik.BOP trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\_logon_.exe.zip a variant of Win32/Kryptik.BNH trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\config\systemprofile\protect.dll.vir Win32/Rootkit.Agent.NIZ trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\config\systemprofile\Start Menu\Programs\Startup\ChkDisk.dll.vir Win32/Rootkit.Agent.NIZ trojan
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\atapi.sys.vir Win32/Olmarik.SJ virus
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1004\A0069360.exe Win32/TrojanDownloader.FakeAlert.AED trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1004\A0070356.exe a variant of Win32/Kryptik.BNH trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1005\A0073375.dll Win32/Rootkit.Agent.NIZ trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1005\A0074377.dll Win32/Rootkit.Agent.NIZ trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1006\A0074383.dll Win32/Rootkit.Agent.NIZ trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1006\A0075551.dll Win32/Rootkit.Agent.NIZ trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1006\A0075686.dll Win32/Rootkit.Agent.NIZ trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1006\A0075687.dll Win32/Rootkit.Agent.NIZ trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1006\A0075689.dll Win32/Rootkit.Agent.NIZ trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1006\A0075690.dll Win32/Rootkit.Agent.NIZ trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1006\A0075691.exe a variant of Win32/Kryptik.BLS trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1006\A0075706.exe a variant of Win32/Kryptik.AZD trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1006\A0075717.dll Win32/Rootkit.Agent.NIZ trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1006\A0075719.dll Win32/Rootkit.Agent.NIZ trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1006\A0075720.dll Win32/Rootkit.Agent.NIZ trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1006\A0075726.dll a variant of Win32/Kryptik.AQY trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1006\A0075727.exe Win32/TrojanDownloader.FakeAlert.AED trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1009\A0077126.exe Win32/TrojanDownloader.FakeAlert.AED trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1009\A0077133.exe Win32/TrojanDownloader.FakeAlert.AED trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1009\A0077135.exe Win32/Adware.AdvancedVirusRemover.B application
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1010\A0078128.exe Win32/TrojanDownloader.FakeAlert.AED trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1010\A0078320.exe Win32/Adware.AdvancedVirusRemover.B application
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1010\A0078332.exe a variant of Win32/Kryptik.AZD trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1010\A0078341.dll a variant of Win32/Kryptik.BOP trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1010\A0078342.dll a variant of Win32/Kryptik.BOP trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1010\A0078344.exe Win32/TrojanDownloader.FakeAlert.AED trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1011\A0078574.dll a variant of Win32/Kryptik.BOQ trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1013\A0078704.dll a variant of Win32/Kryptik.BOP trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1013\A0078705.dll a variant of Win32/Kryptik.BOP trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1013\A0078706.dll a variant of Win32/Kryptik.BOP trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1013\A0078709.dll a variant of Win32/Kryptik.BOP trojan
C:\System Volume Information\_restore{106CF321-99A3-4E3A-9103-1BD027606A99}\RP1013\A0078713.dll a variant of Win32/Kryptik.BOP trojan
C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Internet Explorer\Desktop.htt Win32/TrojanDownloader.FakeAlert.AED virus
D:\I386\APPS\APP23880\src\CompaqPresario_Spring06.exe a variant of Win32/Toolbar.MyWebSearch application
D:\I386\APPS\APP23880\src\HPPavillion_Spring06.exe a variant of Win32/Toolbar.MyWebSearch application
Computer is running well but I couldn't tell you at this point if there is a threat. I've submitted the file you asked me to send. I appreciate your continued assistance, time, and patience.