Combofix worked! Here is the log:
ComboFix 10-05-16.06 - Lauren R 05/21/2010 14:22:09.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.502.276 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: McAfee VirusScan Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\AKM Antivirus 2010 Pro
c:\program files\scdata
.
((((((((((((((((((((((((( Files Created from 2010-04-21 to 2010-05-21 )))))))))))))))))))))))))))))))
.
2010-05-18 03:58 . 2010-05-18 03:58 ——– d—–w- c:\documents and settings\All Users\Application Data\PopCap Games
2010-05-17 21:21 . 2010-05-20 16:37 14 —-a-w- c:\windows\popcinfot.dat
2010-05-17 21:21 . 2010-05-17 21:21 0 —-a-w- c:\windows\popcreg.dat
2010-05-17 21:21 . 2010-05-17 21:21 ——– d—–w- c:\program files\PopCap Games
2010-05-14 15:26 . 2010-05-19 15:31 ——– d—–w- c:\windows\system32\MpEngineStore
2010-05-09 19:33 . 2010-05-09 19:33 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\uhwljrple
2010-05-09 18:00 . 2010-05-09 18:00 ——– d—–w- c:\program files\Coupons
2010-05-09 07:50 . 2010-05-09 07:50 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-05-03 20:01 . 2010-05-03 20:01 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2010-05-01 00:10 . 2010-05-01 00:10 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Apple
2010-04-23 04:33 . 2010-04-23 04:33 ——– d—–w- c:\documents and settings\NetworkService\Application Data\AdobeUM
2010-04-23 04:32 . 2010-04-28 09:52 55296 —-a-w- c:\windows\system32\o.dat
2010-04-23 04:32 . 2010-04-23 04:32 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-20 16:21 . 2009-12-01 13:44 ——– d—–w- c:\documents and settings\Lauren R\Application Data\LimeWire
2010-05-19 21:12 . 2006-02-15 14:02 5888 —-a-w- c:\windows\system32\drivers\dmload.sys
2010-05-18 16:02 . 2010-04-01 13:45 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-05-17 16:35 . 2010-01-28 01:06 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-05-17 15:58 . 2009-11-17 03:24 ——– d—–w- c:\documents and settings\Lauren R\Application Data\Apple Computer
2010-05-14 14:58 . 2009-11-18 18:55 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-04-29 19:39 . 2010-04-01 13:46 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 19:39 . 2010-04-01 13:45 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-04-07 15:32 . 2010-01-28 01:06 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-04-04 20:18 . 2010-01-29 19:49 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-04-04 00:53 . 2010-04-04 00:52 ——– d—–w- c:\program files\QuickTime
2010-04-03 22:56 . 2010-04-03 22:56 ——– d—–w- c:\documents and settings\All Users\Application Data\TEMP
2010-04-03 22:55 . 2010-04-03 22:54 ——– d—–w- c:\program files\SpywareBlaster
2010-04-03 18:23 . 2010-04-03 16:23 ——– d—–w- c:\program files\Puran Defrag
2010-03-10 06:15 . 2006-02-15 14:04 420352 —-a-w- c:\windows\system32\vbscript.dll
2010-02-25 06:24 . 2006-02-15 14:04 916480 —-a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 2006-02-15 14:03 455680 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-12-20 19:50 . 2009-12-20 19:48 2828 –sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TFncKy"="TFncKy.exe" [BU]
"TDispVol"="TDispVol.exe" [2005-03-11 73728]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-11-28 118784]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"THotkey"="c:\program files\Toshiba\Toshiba Applet\thotkey.exe" [2006-01-05 352256]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-12-16 82009]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-12-16 761945]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2004-08-18 184320]
"AGRSMMSG"="AGRSMMSG.exe" [2005-10-15 88203]
"NDSTray.exe"="NDSTray.exe" [BU]
"Tvs"="c:\program files\Toshiba\Tvs\TvsTray.exe" [2005-11-30 73728]
"TPSMain"="TPSMain.exe" [2005-06-01 282624]
"dla"="c:\windows\system32\dla\DLACTRLW.exe" [2005-10-06 122940]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-05 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-11-28 602182]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\udaterui.exe" [2008-03-14 136512]
"RTHDCPL"="RTHDCPL.EXE" [2006-05-05 16206848]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-18 421888]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
McAfee Security Scan.lnk - c:\program files\McAfee Security Scan\1.0.150\SSScheduler.exe [2009-7-27 199184]
RAMASST.lnk - c:\windows\system32\RAMASST.exe [2006-2-15 155648]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\McAfeeEngineService]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"CanonSolutionMenu"=c:\program files\Canon\SolutionMenu\CNSLMAIN.exe /logon
"CanonMyPrinter"=c:\program files\Canon\MyPrinter\BJMyPrt.exe /logon
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"c:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"= c:\\TOSHIBA\\IVP\\ISM\\pinger.exe
"c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\WINDOWS\\system32\\wscntfy.exe"=
"c:\\Program Files\\Intel\\Wireless\\Bin\\ZCfgSvc.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R2 McAfeeEngineService;McAfee Engine Service;c:\program files\McAfee\VirusScan Enterprise\engineserver.exe [9/1/2009 12:07 AM 21256]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [11/13/2009 5:25 PM 70728]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [11/13/2009 5:25 PM 65448]
S4 PuranDefrag;PuranDefrag;c:\windows\system32\PuranDefragS.exe [4/3/2010 12:24 PM 229376]
.
Contents of the 'Scheduled Tasks' folder
2010-05-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 20:34]
2009-11-13 c:\windows\Tasks\Registration reminder 2.job
- c:\windows\system32\OOBE\oobebaln.exe [2006-02-15 00:12]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.toshibadirect.com/dpdstart
uInternet Connection Wizard,ShellNext = hxxp://www.toshibadirect.com/dpdstart
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: {2D7C6435-749A-4811-9DEB-C39DB8FF080D} = 8.8.8.8
TCP: {A91626BE-FE7F-41E6-A26D-D0D4E8E668B8} = 8.8.8.8
TCP: {E72C10B8-0326-4E84-99C0-3A61BC04B7E5} = 8.8.8.8
FF - ProfilePath - c:\documents and settings\Lauren R\Application Data\Mozilla\Firefox\Profiles\h84jzdei.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?hl=en&source=iglk
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - ORPHANS REMOVED - - - -
BHO-{7ab39fa9-e866-48b5-8c13-2c55c009a731} - (no file)
HKLM-Run-faborolor - c:\windows\system32\mejonunu.dll
HKLM-Run-ladowetobo - nojoredu.dll
SSODL-jujiyovah-{3e288f7d-2353-4088-b41f-48a76795d167} - (no file)
SSODL-vedimasug-{15fa1b56-13a5-4fb3-a638-b98c092591e6} - (no file)
SafeBoot-klmdb.sys
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-05-21 14:32
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'explorer.exe'(3888)
c:\windows\system32\WININET.dll
c:\windows\system32\TDispVol.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\TPwrCfg.DLL
c:\windows\system32\TPwrReg.dll
c:\windows\system32\TPSTrace.DLL
.
Completion time: 2010-05-21 14:37:11
ComboFix-quarantined-files.txt 2010-05-21 18:37
Pre-Run: 8,057,032,704 bytes free
Post-Run: 8,500,264,960 bytes free
- - End Of File - - 1F85CDC833EC16B1AA64FBB521BE1CC1