ComboFix was able to run (Windows restore was downloaded first). The log is below:
ComboFix 10-06-01.01 - Brandon Miles 06/02/2010 15:23:02.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.767.391 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: CA Anti-Virus *On-access scanning enabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}
FW: CA Personal Firewall *enabled* {14CB4B80-8E52-45EA-905E-67C1267B4160}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Readme.txt
c:\windows\system\oeminfo.ini
C:\zip.exe
.
((((((((((((((((((((((((( Files Created from 2010-05-02 to 2010-06-02 )))))))))))))))))))))))))))))))
.
2010-06-02 18:17 . 2010-06-02 18:17 0 —-a-w- C:\backup.reg
2010-06-02 18:17 . 2010-06-02 18:17 574 —-a-w- C:\cleanup.bat
2010-06-02 17:16 . 2010-06-02 17:16 61440 —-a-w- c:\documents and settings\Brandon Miles\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-1366c09b-n\decora-sse.dll
2010-06-02 17:16 . 2010-06-02 17:16 503808 —-a-w- c:\documents and settings\Brandon Miles\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-76076f38-n\msvcp71.dll
2010-06-02 17:16 . 2010-06-02 17:16 499712 —-a-w- c:\documents and settings\Brandon Miles\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-76076f38-n\jmc.dll
2010-06-02 17:16 . 2010-06-02 17:16 348160 —-a-w- c:\documents and settings\Brandon Miles\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-76076f38-n\msvcr71.dll
2010-06-02 17:16 . 2010-06-02 17:16 12800 —-a-w- c:\documents and settings\Brandon Miles\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-1366c09b-n\decora-d3d.dll
2010-06-02 17:15 . 2010-06-02 17:15 411368 —-a-w- c:\windows\system32\deployJava1.dll
2010-06-02 17:15 . 2010-06-02 17:15 ——– d—–w- c:\program files\Java
2010-06-02 16:54 . 2010-06-02 16:54 0 —-a-w- c:\windows\nsreg.dat
2010-06-02 16:54 . 2010-06-02 16:54 ——– d—–w- c:\documents and settings\Brandon Miles\Local Settings\Application Data\Mozilla
2010-06-02 07:08 . 2010-06-02 07:08 ——– d—–w- c:\program files\MSXML 4.0
2010-06-02 02:16 . 2010-06-02 02:16 ——– d—–w- c:\program files\ESET
2010-06-02 01:31 . 2010-06-02 01:31 ——– d—–w- c:\documents and settings\Brandon Miles\Application Data\Malwarebytes
2010-06-02 01:31 . 2010-04-29 19:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-02 01:31 . 2010-06-02 01:31 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-02 01:31 . 2010-06-02 01:31 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-06-02 01:31 . 2010-04-29 19:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-06-02 01:16 . 2010-06-02 01:16 ——– d—–w- C:\_OTL
2010-06-01 17:40 . 2010-06-01 17:40 388096 —-a-r- c:\documents and settings\Brandon Miles\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-06-01 14:31 . 2010-06-01 14:20 1541416 —-a-w- c:\documents and settings\All Users\Application Data\CA\Consumer\AV\tmp\vete_tmp.dll
2010-06-01 13:56 . 2010-06-01 14:20 739696 —-a-w- c:\windows\system32\drivers\vetefile.sys
2010-06-01 13:56 . 2010-06-01 14:20 133520 —-a-w- c:\windows\system32\drivers\veteboot.sys
2010-06-01 13:31 . 2010-06-01 13:56 32240 —-a-w- c:\windows\system32\drivers\vetmonnt.sys
2010-06-01 13:31 . 2010-06-01 13:56 26352 —-a-w- c:\windows\system32\drivers\vet-filt.sys
2010-06-01 13:31 . 2010-06-01 13:56 21488 —-a-w- c:\windows\system32\drivers\vetfddnt.sys
2010-06-01 13:31 . 2010-06-01 13:56 21104 —-a-w- c:\windows\system32\drivers\vet-rec.sys
2010-06-01 13:31 . 2007-08-20 17:37 75016 —-a-w- c:\windows\system32\isafprod.dll
2010-06-01 13:31 . 2007-08-20 17:37 99592 —-a-w- c:\windows\system32\isafeif.dll
2010-06-01 13:31 . 2007-08-20 17:26 79424 —-a-w- c:\windows\system32\vetredir.dll
2010-06-01 13:31 . 2010-06-01 13:31 ——– d—–w- c:\program files\Common Files\Scanner
2010-06-01 13:30 . 2010-06-01 13:56 ——– d—–w- c:\documents and settings\All Users\Application Data\CA
2010-06-01 13:30 . 2010-06-01 13:31 ——– d—–w- c:\program files\CA
2010-05-29 14:11 . 2010-05-29 14:11 1152 —-a-w- c:\windows\system32\windrv.sys
2010-05-29 14:10 . 2010-05-29 14:10 ——– d—–w- c:\documents and settings\Brandon Miles\Application Data\GetRightToGo
2010-05-29 12:36 . 2010-05-29 12:36 ——– d—–w- c:\program files\Trend Micro
2010-05-29 11:14 . 2010-05-29 11:14 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-05-28 16:42 . 2010-05-28 16:42 ——– d—–w- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2010-05-28 14:12 . 2010-05-28 13:14 15880 —-a-w- c:\windows\system32\lsdelete.exe
2010-05-28 13:14 . 2010-02-04 15:53 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys
2010-05-28 13:14 . 2010-05-28 13:14 ——– dc—-w- c:\windows\system32\DRVSTORE
2010-05-28 13:14 . 2010-05-28 13:14 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-05-28 13:09 . 2010-02-04 15:53 2954656 -c–a-w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}\Ad-AwareInstaller.exe
2010-05-28 13:08 . 2010-05-28 13:14 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-05-28 13:08 . 2010-05-28 13:09 ——– d—–w- c:\program files\Lavasoft
2010-05-28 12:22 . 2010-05-28 12:22 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2010-05-27 18:42 . 2010-05-28 13:09 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-05-27 13:27 . 2008-04-13 18:45 26368 -c–a-w- c:\windows\system32\dllcache\usbstor.sys
2010-05-27 10:25 . 2010-05-28 16:42 ——– d—–w- c:\program files\TeaTimer (Spybot - Search & Destroy)
2010-05-27 10:25 . 2010-05-27 10:25 ——– d—–w- c:\program files\SDHelper (Spybot - Search & Destroy)
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-02 18:18 . 2010-06-02 01:21 64 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k7
2010-06-02 18:18 . 2010-06-02 01:21 64 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k6
2010-06-02 18:18 . 2010-06-02 01:21 64 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k5
2010-06-02 18:18 . 2010-06-02 01:21 64 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k4
2010-06-02 18:18 . 2010-06-02 01:21 64 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k3
2010-06-02 18:18 . 2010-06-02 01:21 64 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k2
2010-06-02 18:18 . 2010-06-02 01:21 64 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k1
2010-06-02 18:18 . 2010-06-02 01:21 54726 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k0
2010-06-02 17:38 . 2007-02-24 23:51 ——– d—–w- c:\program files\Morpheus
2010-06-02 17:17 . 2006-07-13 21:38 ——– d—–w- c:\program files\Common Files\Java
2010-06-01 21:12 . 2001-08-18 12:00 3328 —-a-w- c:\windows\system32\drivers\pciide.sys
2010-05-27 18:30 . 2004-12-12 18:05 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-05-27 16:22 . 2004-12-12 18:05 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-03-11 12:38 . 2004-01-08 20:23 832512 —-a-w- c:\windows\system32\wininet.dll
2010-03-11 12:38 . 2004-08-04 07:56 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-03-11 12:38 . 2001-08-18 12:00 17408 —-a-w- c:\windows\system32\corpol.dll
2010-03-09 11:09 . 2002-02-26 20:58 430080 —-a-w- c:\windows\system32\vbscript.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LTWinModem1"="ltmsg.exe 9" [X]
"Dell|Alert"="c:\program files\Dell\Support\Alert\bin\DAMon.exe" [2002-04-03 282624]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-02-10 155648]
"QOELOADER"="c:\program files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe" [2010-06-01 14088]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2001-08-17 28738]
"cctray"="c:\program files\CA\CA Internet Security Suite\cctray\cctray.exe" [2010-06-01 177392]
"CAVRID"="c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2010-06-01 230664]
"capfupgrade"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe" [2010-06-01 259312]
"capfasem"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe" [2010-06-01 173296]
"cafwc"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe" [2010-06-01 1193200]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
2007-05-18 17:30 79368 —-a-w- c:\windows\SYSTEM32\UmxWNP.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager\appcertdlls]
dwwionce REG_SZ
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\CA Personal Firewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R0 KmxStart;KmxStart;c:\windows\SYSTEM32\DRIVERS\KmxStart.sys [6/24/2008 7:08 PM 93712]
R0 Lbd;Lbd;c:\windows\SYSTEM32\DRIVERS\Lbd.sys [5/28/2010 9:14 AM 64288]
R1 KmxAgent;KmxAgent;c:\windows\SYSTEM32\DRIVERS\KmxAgent.sys [6/24/2008 7:08 PM 63504]
R1 KmxFile;KmxFile;c:\windows\SYSTEM32\DRIVERS\KmxFile.sys [6/24/2008 7:08 PM 45584]
R1 KmxFw;KmxFw;c:\windows\SYSTEM32\DRIVERS\KmxFw.sys [6/24/2008 7:08 PM 115216]
R2 KmxCF;KmxCF;c:\windows\SYSTEM32\DRIVERS\KmxCF.sys [6/24/2008 7:08 PM 134648]
R2 KmxSbx;KmxSbx;c:\windows\SYSTEM32\DRIVERS\KmxSbx.sys [6/24/2008 7:08 PM 66576]
R3 KmxCfg;KmxCfg;c:\windows\SYSTEM32\DRIVERS\KmxCfg.sys [6/24/2008 7:08 PM 88816]
R3 PPCtlPriv;PPCtlPriv;c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe [8/16/2007 9:10 PM 189704]
S3 Fadpu16E;Fadpu16E; [x]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2/4/2010 11:52 AM 1314704]
.
Contents of the 'Scheduled Tasks' folder
2010-06-01 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 13:14]
2010-06-01 c:\windows\Tasks\CAAntiSpywareScan_Daily as Brandon Miles at 9 31 AM.job
- c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe [2007-08-17 01:10]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride =
LSP: c:\windows\system32\VetRedir.dll
Trusted Zone: microsoft.com\windowsupdate
FF - ProfilePath - c:\documents and settings\Brandon Miles\Application Data\Mozilla\Firefox\Profiles\p97coiir.default\
FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-klmdb.sys
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-06-02 15:33
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Dell|Alert = c:\program files\Dell\Support\Alert\bin\DAMon.exe?p?o?r?t?\?A?l?e?r?t?\?b?i?n?\?D?A?M?o?n?.?e?x?e???????????x:??????x???`???X??? ???????`???P????(?w'(?w????????????(???}??????w????????????0????$?w7(?w?o?wS??w???w????????????X*@?????????X????????%@?e?????
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-3646499915-954458941-1742551072-1008\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:ef,1f,49,b2,3e,27,67,73,fd,92,f4,7d,cf,b7,80,8d,19,25,86,ac,60,fd,54,
b3,c3,44,0b,47,f2,da,95,14,1f,60,3d,76,e1,41,29,cf,af,90,64,2c,35,01,fb,f8,\
"??"=hex:90,56,a4,4d,49,5d,3a,cb,4f,0e,1e,76,81,1c,49,38
[HKEY_USERS\S-1-5-21-3646499915-954458941-1742551072-1008\Software\SecuROM\License information*]
"datasecu"=hex:61,86,46,5e,5f,a3,00,8f,1d,10,87,35,1e,fa,99,95,47,90,fc,58,bb,
6d,69,75,dd,9b,1b,fe,70,3f,0b,6e,9f,d8,93,c4,b6,0b,1e,6c,11,9a,9d,0f,98,53,\
"rkeysecu"=hex:c3,94,60,b1,4d,bc,d6,c5,f7,57,81,90,6c,b0,8f,5e
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(1216)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\UmxWnp.Dll
c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll
- - - - - - - > 'lsass.exe'(1416)
c:\windows\system32\VetRedir.dll
c:\windows\system32\ISafeIf.dll
.
Completion time: 2010-06-02 15:40:43
ComboFix-quarantined-files.txt 2010-06-02 19:40
Pre-Run: 13,048,393,728 bytes free
Post-Run: 13,021,057,024 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
- - End Of File - - FC6E0100C1BF070CDF5A9E3DBF4BCDD6