Here is the log for ComboFix:
ComboFix 10-01-04.01 - kanderson 01/09/2010 19:59:20.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3572.2911 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: Total Protection for Small Business *On-access scanning enabled* (Updated) {8C354827-2F54-4E28-90DC-AD391E77808C}
* Resident AV is active
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\41.exe
.
((((((((((((((((((((((((( Files Created from 2009-12-10 to 2010-01-10 )))))))))))))))))))))))))))))))
.
2010-01-09 13:01 . 2010-01-09 13:01 ——– d—–w- c:\documents and settings\kanderson\Application Data\Malwarebytes
2010-01-09 13:01 . 2010-01-07 21:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-09 13:01 . 2010-01-09 13:01 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-09 13:01 . 2010-01-09 13:01 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-09 13:01 . 2010-01-07 21:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-01-09 12:59 . 2010-01-09 12:59 ——– d—–w- c:\program files\ERUNT
2010-01-09 01:49 . 2010-01-09 01:49 140288 —-a-w- C:\vcleaner.exe
2010-01-09 00:32 . 2010-01-09 12:48 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-01-08 21:37 . 2010-01-08 21:37 ——– d—–w- c:\program files\AVG
2010-01-08 19:59 . 2010-01-08 19:58 33792 —-a-w- c:\windows\system32\winlogon32.exe
2010-01-08 19:59 . 2010-01-08 19:58 33792 —-a-w- c:\windows\system32\smss32.exe
2010-01-07 19:30 . 2010-01-07 19:31 ——– d—–w- c:\documents and settings\kanderson\Local Settings\Application Data\Swag_Bucks
2010-01-07 19:30 . 2010-01-07 19:30 ——– d—–w- c:\program files\Conduit
2010-01-07 19:30 . 2010-01-07 19:30 ——– d—–w- c:\documents and settings\kanderson\Local Settings\Application Data\Conduit
2010-01-07 19:30 . 2010-01-07 19:30 ——– d—–w- c:\program files\Swag_Bucks
2009-12-17 11:11 . 2009-12-17 11:12 ——– d—–w- c:\program files\WhoCrashed
2009-12-11 15:26 . 2009-12-11 15:26 ——– d—–r- C:\Sandbox
2009-12-11 15:26 . 2009-12-11 15:26 ——– d—–w- c:\program files\Sandboxie
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-10 00:43 . 2008-11-19 15:02 0 —-a-w- c:\documents and settings\kanderson\Local Settings\Application Data\WavXMapDrive.bat
2010-01-09 20:24 . 2008-11-19 12:48 ——– d—–w- c:\documents and settings\All Users\Application Data\VMware
2010-01-09 20:24 . 2008-11-19 12:50 ——– d—–w- c:\documents and settings\LocalService\Application Data\VMware
2010-01-09 00:27 . 2008-11-11 16:42 112247 —-a-w- c:\windows\system32\nvModes.dat
2010-01-08 20:12 . 2008-11-19 15:03 ——– d—–w- c:\documents and settings\kanderson\Application Data\VMware
2009-12-01 18:53 . 2009-01-08 19:20 ——– d—–w- c:\program files\Common Files\Adobe
2009-11-11 08:20 . 2008-11-11 17:13 12912 —-a-w- c:\documents and settings\NetworkService\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-06 20:01 . 2008-11-11 17:06 12912 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-29 07:46 . 2008-04-25 16:16 832512 ——w- c:\windows\system32\wininet.dll
2009-10-29 07:46 . 2008-04-25 16:16 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-10-29 07:46 . 2008-04-25 16:16 17408 —-a-w- c:\windows\system32\corpol.dll
2009-10-21 05:38 . 2008-04-25 16:16 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2008-04-25 16:16 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2008-04-14 00:23 265728 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2008-04-25 16:16 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2008-04-25 16:16 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2008-04-25 16:16 79872 —-a-w- c:\windows\system32\raschap.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}"= "c:\program files\Swag_Bucks\tbSwag.dll" [2009-12-31 2349080]
[HKEY_CLASSES_ROOT\clsid\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}]
2009-12-31 16:53 2349080 —-a-w- c:\program files\Swag_Bucks\tbSwag.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}"= "c:\program files\Swag_Bucks\tbSwag.dll" [2009-12-31 2349080]
[HKEY_CLASSES_ROOT\clsid\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{8BDEA9D6-6F62-45EB-8EE9-8A81AF0D2F94}"= "c:\program files\Swag_Bucks\tbSwag.dll" [2009-12-31 2349080]
[HKEY_CLASSES_ROOT\clsid\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\EnabledUnlockedFDEIconOverlay]
@="{022F2F51-CDDA-4873-8A29-72C66C808A3F}"
[HKEY_CLASSES_ROOT\CLSID\{022F2F51-CDDA-4873-8A29-72C66C808A3F}]
2008-07-25 15:16 282112 —-a-w- c:\windows\system32\mscoree.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UninitializedFdeIconOverlay]
@="{661963C1-99A1-44e7-A671-1CF3768AE9D4}"
[HKEY_CLASSES_ROOT\CLSID\{661963C1-99A1-44e7-A671-1CF3768AE9D4}]
2008-07-25 15:16 282112 —-a-w- c:\windows\system32\mscoree.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2007-08-30 205480]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-01-29 4363504]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Google Update"="c:\documents and settings\kanderson\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-04-02 133104]
"SandboxieControl"="c:\program files\Sandboxie\SbieCtrl.exe" [2009-12-01 389120]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-07-01 196608]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-06-30 442467]
"AESTFltr"="c:\windows\system32\AESTFltr.exe" [2008-06-30 466944]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-08-28 13537280]
"nwiz"="nwiz.exe" [2008-08-28 1630208]
"NVHotkey"="nvHotkey.dll" [2008-08-28 90112]
"NvMediaCenter"="NvMCTray.dll" [2008-08-28 86016]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-06-15 178712]
"ChangeTPMAuth"="c:\program files\Wave Systems Corp\Common\ChangeTPMAuth.exe" [2008-05-30 180224]
"WavXMgr"="c:\program files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe" [2008-05-14 105472]
"SecureUpgrade"="c:\program files\Wave Systems Corp\SecureUpgrade.exe" [2008-06-24 243000]
"EmbassySecurityCheck"="c:\program files\Wave Systems Corp\EMBASSY Security Setup\EMBASSYSecurityCheck.exe" [2008-06-24 79160]
"DellControlPoint"="c:\program files\Dell\Dell ControlPoint\Dell.ControlPoint.exe" [2008-05-30 593920]
"DCPstrApp"="c:\program files\Dell\Dell ControlPoint\Security Manager\SecurityDeviceInfoSetRegistryString.exe" [2008-08-04 6656]
"DellConnectionManager"="c:\program files\Dell\Dell ControlPoint\Connection Manager\Dell.UCM.exe" [2008-09-09 1486848]
"IntelZeroConfig"="c:\program files\Intel\WiFi\bin\ZCfgSvc.exe" [2008-07-11 1351680]
"IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2008-07-11 1191936]
"picon"="c:\program files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe" [2008-06-03 367128]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2008-02-26 17920]
"Dell Webcam Central"="c:\program files\Dell Webcam\Dell Webcam Central\WebcamDellB.exe" [2008-04-11 372736]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-02-26 128296]
"vmware-tray"="c:\program files\VMware\VMware Workstation\vmware-tray.exe" [2008-09-19 84528]
"MVS Splash"="c:\program files\McAfee\Managed VirusScan\Agent\Splash.exe" [2009-09-14 468288]
"McAfee Managed Services Tray"="c:\program files\McAfee\Managed VirusScan\Agent\StartMyagtTry.exe" [2009-09-14 87360]
"DWPersistentQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\DWTRIG20.EXE" [2007-02-26 437160]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"smss32.exe"="c:\windows\system32\smss32.exe" [2010-01-08 33792]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Dell ControlPoint System Manager.lnk - c:\program files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe [2008-8-18 1205528]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 wvauth
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\McAfee\\Managed VirusScan\\Agent\\myAgtSvc.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"59152:UDP"= 59152:UDP:SonicWALL Anti-Virus Compliance Port 59152
"59153:UDP"= 59153:UDP:SonicWALL Anti-Virus Compliance Port 59153
R1 vcdrom;Virtual CD-ROM Device Driver;c:\windows\system32\drivers\VCdRom.sys [2/5/2009 10:14 PM 8576]
R2 ASFAgent;ASF Agent;c:\program files\Intel\ASF Agent\ASFAgent.exe [4/19/2007 6:56 AM 133968]
R2 buttonsvc32;Dell ControlPoint Button Service;c:\program files\Dell\Dell ControlPoint\DCPButtonSvc.exe [6/3/2008 4:28 PM 386328]
R2 Credential Vault Host Control Service;Credential Vault Host Control Service;c:\program files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe [7/31/2008 10:41 PM 808296]
R2 Credential Vault Host Storage;Credential Vault Host Storage;c:\program files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe [7/31/2008 10:41 PM 21352]
R2 dcpsysmgrsvc;Dell ControlPoint System Manager;c:\program files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe [8/18/2008 11:39 AM 455960]
R2 EngineServer;EngineServer;c:\program files\McAfee\Managed VirusScan\VScan\EngineServer.exe [4/24/2009 10:03 AM 14144]
R2 myAgtSvc;McAfee Virus and Spyware Protection Service;c:\program files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe [4/24/2009 10:03 AM 175704]
R2 SMManager;Smith Micro Connection Manager Service;c:\program files\Dell\Dell ControlPoint\Connection Manager\SMManager.exe [9/9/2008 3:21 PM 69632]
R2 SWAGENT;SonicWALL Agent Service;c:\program files\McAfee\Managed VirusScan\Agent\swAgent.exe [4/24/2009 10:04 AM 103744]
R2 UNS;Intel® Active Management Technology User Notification Service;c:\program files\Common Files\Intel\Privacy Icon\UNS\UNS.exe [11/11/2008 12:07 PM 2058776]
R2 Virtual Server;Virtual Server;c:\program files\Microsoft Virtual Server\vssrvc.exe [10/21/2005 12:48 AM 3315064]
R2 vmci;VMware vmci;c:\windows\system32\drivers\vmci.sys [9/18/2008 11:12 PM 54960]
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [11/11/2008 1:34 PM 108160]
R3 cvusbdrv;Broadcom USH CV;c:\windows\system32\drivers\cvusbdrv.sys [11/11/2008 1:35 PM 32808]
R3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\drivers\e1y5132.sys [11/11/2008 1:34 PM 244368]
R3 OA001Afx;Provides a software interface to control audio effects of OA001 camera.;c:\windows\system32\drivers\OA001Afx.sys [11/11/2008 1:34 PM 148056]
R3 OA001Ufd;Creative Camera OA001 Upper Filter Driver;c:\windows\system32\drivers\OA001Ufd.sys [11/11/2008 1:34 PM 144672]
R3 OA001Vid;Creative Camera OA001 Function Driver;c:\windows\system32\drivers\OA001Vid.sys [11/11/2008 1:34 PM 277440]
R3 SbieDrv;SbieDrv;c:\program files\Sandboxie\SbieDrv.sys [12/1/2009 8:55 AM 119296]
R3 vmh;Virtual Machine Helper;c:\program files\Microsoft Virtual Server\vmh.exe [10/21/2005 12:48 AM 175872]
S3 AsfAlrt;AsfAlrt Service;c:\windows\system32\drivers\Asfalrt.sys [4/19/2007 6:28 AM 42832]
.
Contents of the 'Scheduled Tasks' folder
2010-01-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1454471165-492894223-1417001333-2259Core.job
- c:\documents and settings\kanderson\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-04-02 17:21]
2010-01-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1454471165-492894223-1417001333-2259UA.job
- c:\documents and settings\kanderson\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-04-02 17:21]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/webhp?rls=ig
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE: Send to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
LSP: c:\program files\VMware\VMware Workstation\vsocklib.dll
Trusted Zone: //about.htm/
Trusted Zone: //Exclude.htm/
Trusted Zone: //LanguageSelection.htm/
Trusted Zone: //Message.htm/
Trusted Zone: //MyAgttryCmd.htm/
Trusted Zone: //MyAgttryNag.htm/
Trusted Zone: //MyNotification.htm/
Trusted Zone: //NOCLessUpdate.htm/
Trusted Zone: //quarantine.htm/
Trusted Zone: //ScanNow.htm/
Trusted Zone: //strings.vbs/
Trusted Zone: //Template.htm/
Trusted Zone: //Update.htm/
Trusted Zone: //VirFound.htm/
Trusted Zone: mcafee.com\*
Trusted Zone: mcafeeasap.com\betavscan
Trusted Zone: mcafeeasap.com\vs
Trusted Zone: mcafeeasap.com\www
DPF: {7C896371-4B7F-4B34-95B1-24851F5DED24} - hxxp://kanderson.pdsinfo.com/VirtualServer/activex/VMRCActiveXClient.cab
FF - ProfilePath - c:\documents and settings\kanderson\Application Data\Mozilla\Firefox\Profiles\pycz59dp.default\
FF - component: c:\documents and settings\kanderson\Application Data\Mozilla\Firefox\Profiles\pycz59dp.default\extensions\{ca8b7b3d-b6e6-438f-b935-601b3de48d66}\platform\WINNT_x86-msvc\components\FFThrottle.dll
FF - component: c:\documents and settings\kanderson\Application Data\Mozilla\Firefox\Profiles\pycz59dp.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\platform\WINNT_x86-msvc\components\pagespeed.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-09 20:04
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1248)
c:\windows\system32\DNSAPI.dll
- - - - - - - > 'lsass.exe'(1304)
c:\windows\system32\wvauth.dll
c:\windows\system32\biolsp.dll
.
Completion time: 2010-01-09 20:05:36
ComboFix-quarantined-files.txt 2010-01-10 01:05
ComboFix2.txt 2010-01-10 00:48
Pre-Run: 143,092,707,328 bytes free
Post-Run: 143,056,175,104 bytes free
- - End Of File - - 0CE1CFAABE8F3A6A35069CF46020F965