Michael:
I ran combofix the log is posted below:
ComboFix 12-04-14.02 - Jeff 04/14/2012 10:46:16.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3062.2540 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\Application Data\TEMP\DFC5A2B2.TMP
c:\documents and settings\Jeff\Application Data\completescan
c:\documents and settings\Jeff\Application Data\install
c:\documents and settings\Jeff\dos2usb.tmp
c:\documents and settings\Jeff\g2mdlhlpx.exe
c:\documents and settings\Jeff\GoToAssistDownloadHelper.exe
c:\documents and settings\Jeff\Local Settings\Application Data\{C0FC7898-C632-412D-A685-1BCDD118DFD0}
c:\documents and settings\Jeff\Local Settings\Application Data\{C0FC7898-C632-412D-A685-1BCDD118DFD0}\chrome.manifest
c:\documents and settings\Jeff\Local Settings\Application Data\{C0FC7898-C632-412D-A685-1BCDD118DFD0}\chrome\content\overlay.xul
c:\documents and settings\Jeff\Local Settings\Application Data\{C0FC7898-C632-412D-A685-1BCDD118DFD0}\install.rdf
c:\documents and settings\Jeff\Local Settings\Application Data\assembly\tmp
c:\documents and settings\Jeff\WINDOWS
c:\windows\system32\regobj.dll
c:\windows\Tasks\At1.job
c:\windows\Tasks\At10.job
c:\windows\Tasks\At11.job
c:\windows\Tasks\At12.job
c:\windows\Tasks\At13.job
c:\windows\Tasks\At14.job
c:\windows\Tasks\At15.job
c:\windows\Tasks\At16.job
c:\windows\Tasks\At17.job
c:\windows\Tasks\At18.job
c:\windows\Tasks\At19.job
c:\windows\Tasks\At2.job
c:\windows\Tasks\At20.job
c:\windows\Tasks\At21.job
c:\windows\Tasks\At22.job
c:\windows\Tasks\At23.job
c:\windows\Tasks\At24.job
c:\windows\Tasks\At3.job
c:\windows\Tasks\At4.job
c:\windows\Tasks\At5.job
c:\windows\Tasks\At6.job
c:\windows\Tasks\At7.job
c:\windows\Tasks\At8.job
c:\windows\Tasks\At9.job
.
.
((((((((((((((((((((((((( Files Created from 2012-03-14 to 2012-04-14 )))))))))))))))))))))))))))))))
.
.
2012-04-13 16:08 . 2012-03-13 23:15 6582328 β-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4E245602-07BC-4A49-80BE-F93DD291F844}\mpengine.dll
2012-04-13 12:29 . 2012-04-13 12:29 βββ dββw- c:\documents and settings\Jeff\Local Settings\Application Data\PCHealth
2012-04-03 19:33 . 2012-04-03 19:33 418464 β-a-w- c:\windows\system32\FlashPlayerApp.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-04 19:56 . 2010-08-26 12:41 22344 β-a-w- c:\windows\system32\drivers\mbam.sys
2012-04-03 19:33 . 2011-05-19 11:54 70304 β-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-03-13 23:15 . 2011-06-27 11:58 6582328 β-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-03-01 11:01 . 2008-04-25 16:16 916992 β-a-w- c:\windows\system32\wininet.dll
2012-03-01 11:01 . 2008-04-25 16:16 43520 β-a-w- c:\windows\system32\licmgr10.dll
2012-03-01 11:01 . 2008-04-25 16:16 1469440 β-a-w- c:\windows\system32\inetcpl.cpl
2012-02-29 14:10 . 2008-04-25 16:16 177664 β-a-w- c:\windows\system32\wintrust.dll
2012-02-29 14:10 . 2008-04-25 16:16 148480 β-a-w- c:\windows\system32\imagehlp.dll
2012-02-29 12:17 . 2008-04-25 16:16 385024 β-a-w- c:\windows\system32\html.iec
2012-02-03 09:22 . 2008-04-25 16:16 1860096 β-a-w- c:\windows\system32\win32k.sys
2012-01-31 12:44 . 2011-06-25 15:02 237072 ββw- c:\windows\system32\MpSigStub.exe
2012-01-20 15:33 . 2012-01-20 15:33 255352 β-a-w- c:\windows\system32\awrdscdc.ax
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2012-01-03 1514152]
.
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2012-01-03 21:31 1514152 β-a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2012-01-03 1514152]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2012-01-03 1514152]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2007-08-30 205480]
"DellAutomatedPCTuneUp"="c:\program files\DellAutomatedPCTuneUp\PTAgnt.exe" [2007-10-11 465136]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-02-21 159744]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-21 16855552]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-22 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-22 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-22 137752]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-06-30 2220032]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2008-02-22 1245184]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2008-02-28 17920]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-02-26 128296]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"ApnUpdater"="c:\program files\Ask.com\Updater\Updater.exe" [2012-01-03 1391272]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Dell Network Assistant.lnk - c:\windows\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe [2008-9-4 7168]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=
"c:\\WINDOWS\\system32\\dkabcoms.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
"10426:UDP"= 10426:UDP:SingleClick ICC
.
R2 dkab_device;dkab_device;c:\windows\system32\DKabcoms.exe -service β> c:\windows\system32\DKabcoms.exe -service [?]
R3 O2MDRDR;O2MDRDR;c:\windows\system32\drivers\o2media.sys [9/4/2008 3:25 PM 48472]
R3 O2SDRDR;O2SDRDR;c:\windows\system32\drivers\o2sd.sys [9/4/2008 3:25 PM 43480]
S1 bbyljlnw;bbyljlnw;\??\c:\windows\system32\drivers\bbyljlnw.sys β> c:\windows\system32\drivers\bbyljlnw.sys [?]
S1 bgtrgkhs;bgtrgkhs;\??\c:\windows\system32\drivers\bgtrgkhs.sys β> c:\windows\system32\drivers\bgtrgkhs.sys [?]
S1 clzpbvlb;clzpbvlb;\??\c:\windows\system32\drivers\clzpbvlb.sys β> c:\windows\system32\drivers\clzpbvlb.sys [?]
S1 cufczslm;cufczslm;\??\c:\windows\system32\drivers\cufczslm.sys β> c:\windows\system32\drivers\cufczslm.sys [?]
S1 eiuvmzcq;eiuvmzcq;\??\c:\windows\system32\drivers\eiuvmzcq.sys β> c:\windows\system32\drivers\eiuvmzcq.sys [?]
S1 erkjgnif;erkjgnif;\??\c:\windows\system32\drivers\erkjgnif.sys β> c:\windows\system32\drivers\erkjgnif.sys [?]
S1 fhttknqq;fhttknqq;\??\c:\windows\system32\drivers\fhttknqq.sys β> c:\windows\system32\drivers\fhttknqq.sys [?]
S1 fimufhfu;fimufhfu;\??\c:\windows\system32\drivers\fimufhfu.sys β> c:\windows\system32\drivers\fimufhfu.sys [?]
S1 futndtiw;futndtiw;\??\c:\windows\system32\drivers\futndtiw.sys β> c:\windows\system32\drivers\futndtiw.sys [?]
S1 gclurjnt;gclurjnt;\??\c:\windows\system32\drivers\gclurjnt.sys β> c:\windows\system32\drivers\gclurjnt.sys [?]
S1 hqaubcrq;hqaubcrq;\??\c:\windows\system32\drivers\hqaubcrq.sys β> c:\windows\system32\drivers\hqaubcrq.sys [?]
S1 hthncqvz;hthncqvz;\??\c:\windows\system32\drivers\hthncqvz.sys β> c:\windows\system32\drivers\hthncqvz.sys [?]
S1 hyenzaut;hyenzaut;\??\c:\windows\system32\drivers\hyenzaut.sys β> c:\windows\system32\drivers\hyenzaut.sys [?]
S1 jbiwfqbk;jbiwfqbk;\??\c:\windows\system32\drivers\jbiwfqbk.sys β> c:\windows\system32\drivers\jbiwfqbk.sys [?]
S1 jwwrvecv;jwwrvecv;\??\c:\windows\system32\drivers\jwwrvecv.sys β> c:\windows\system32\drivers\jwwrvecv.sys [?]
S1 kwuqfndo;kwuqfndo;\??\c:\windows\system32\drivers\kwuqfndo.sys β> c:\windows\system32\drivers\kwuqfndo.sys [?]
S1 laegbejf;laegbejf;\??\c:\windows\system32\drivers\laegbejf.sys β> c:\windows\system32\drivers\laegbejf.sys [?]
S1 mzspbfes;mzspbfes;\??\c:\windows\system32\drivers\mzspbfes.sys β> c:\windows\system32\drivers\mzspbfes.sys [?]
S1 njmqufaa;njmqufaa;\??\c:\windows\system32\drivers\njmqufaa.sys β> c:\windows\system32\drivers\njmqufaa.sys [?]
S1 nplalqix;nplalqix;\??\c:\windows\system32\drivers\nplalqix.sys β> c:\windows\system32\drivers\nplalqix.sys [?]
S1 ntkkulmb;ntkkulmb;\??\c:\windows\system32\drivers\ntkkulmb.sys β> c:\windows\system32\drivers\ntkkulmb.sys [?]
S1 ntrsrote;ntrsrote;\??\c:\windows\system32\drivers\ntrsrote.sys β> c:\windows\system32\drivers\ntrsrote.sys [?]
S1 obqyotvj;obqyotvj;\??\c:\windows\system32\drivers\obqyotvj.sys β> c:\windows\system32\drivers\obqyotvj.sys [?]
S1 ofbhwhoy;ofbhwhoy;\??\c:\windows\system32\drivers\ofbhwhoy.sys β> c:\windows\system32\drivers\ofbhwhoy.sys [?]
S1 ofeqbixu;ofeqbixu;\??\c:\windows\system32\drivers\ofeqbixu.sys β> c:\windows\system32\drivers\ofeqbixu.sys [?]
S1 pijyljkw;pijyljkw;\??\c:\windows\system32\drivers\pijyljkw.sys β> c:\windows\system32\drivers\pijyljkw.sys [?]
S1 piqtlxcr;piqtlxcr;\??\c:\windows\system32\drivers\piqtlxcr.sys β> c:\windows\system32\drivers\piqtlxcr.sys [?]
S1 rcuvekjg;rcuvekjg;\??\c:\windows\system32\drivers\rcuvekjg.sys β> c:\windows\system32\drivers\rcuvekjg.sys [?]
S1 rsngpasp;rsngpasp;\??\c:\windows\system32\drivers\rsngpasp.sys β> c:\windows\system32\drivers\rsngpasp.sys [?]
S1 sqsglmpd;sqsglmpd;\??\c:\windows\system32\drivers\sqsglmpd.sys β> c:\windows\system32\drivers\sqsglmpd.sys [?]
S1 tbpgyhib;tbpgyhib;\??\c:\windows\system32\drivers\tbpgyhib.sys β> c:\windows\system32\drivers\tbpgyhib.sys [?]
S1 tdctjwfr;tdctjwfr;\??\c:\windows\system32\drivers\tdctjwfr.sys β> c:\windows\system32\drivers\tdctjwfr.sys [?]
S1 tdnzoxvi;tdnzoxvi;\??\c:\windows\system32\drivers\tdnzoxvi.sys β> c:\windows\system32\drivers\tdnzoxvi.sys [?]
S1 twmxhavm;twmxhavm;\??\c:\windows\system32\drivers\twmxhavm.sys β> c:\windows\system32\drivers\twmxhavm.sys [?]
S1 udngpust;udngpust;\??\c:\windows\system32\drivers\udngpust.sys β> c:\windows\system32\drivers\udngpust.sys [?]
S1 ugkhxqdo;ugkhxqdo;\??\c:\windows\system32\drivers\ugkhxqdo.sys β> c:\windows\system32\drivers\ugkhxqdo.sys [?]
S1 uufpnfar;uufpnfar;\??\c:\windows\system32\drivers\uufpnfar.sys β> c:\windows\system32\drivers\uufpnfar.sys [?]
S1 vqvlilmx;vqvlilmx;\??\c:\windows\system32\drivers\vqvlilmx.sys β> c:\windows\system32\drivers\vqvlilmx.sys [?]
S1 vuxhotuy;vuxhotuy;\??\c:\windows\system32\drivers\vuxhotuy.sys β> c:\windows\system32\drivers\vuxhotuy.sys [?]
S1 waegznlf;waegznlf;\??\c:\windows\system32\drivers\waegznlf.sys β> c:\windows\system32\drivers\waegznlf.sys [?]
S1 xtvuejyq;xtvuejyq;\??\c:\windows\system32\drivers\xtvuejyq.sys β> c:\windows\system32\drivers\xtvuejyq.sys [?]
S1 ygeafpkf;ygeafpkf;\??\c:\windows\system32\drivers\ygeafpkf.sys β> c:\windows\system32\drivers\ygeafpkf.sys [?]
S1 zemqhyyk;zemqhyyk;\??\c:\windows\system32\drivers\zemqhyyk.sys β> c:\windows\system32\drivers\zemqhyyk.sys [?]
S2 elAPIsvc;elAPI - Service Server;c:\program files\DOS2USB\elsvc.exe [10/14/2010 5:08 PM 45056]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [10/18/2011 4:58 PM 136176]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [4/3/2012 3:33 PM 253600]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [10/18/2011 4:58 PM 136176]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 08:32 128512 β-a-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
.
2012-04-13 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 19:33]
.
2012-04-14 c:\windows\Tasks\Free File Viewer Update Checker.job
- c:\program files\FreeFileViewer\FFVCheckForUpdates.exe [2011-02-16 21:50]
.
2012-04-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-18 20:58]
.
2012-04-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-18 20:58]
.
2012-04-14 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 19:39]
.
2012-03-23 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\Dell Support Center\uaclauncher.exe [2010-11-18 15:13]
.
2012-04-14 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2012-01-03 21:31]
.
2012-04-13 c:\windows\Tasks\SystemToolsDailyTest.job
- c:\program files\Dell Support Center\pcdrcui.exe [2010-11-18 15:13]
.
.
ββ- Supplementary Scan ββ-
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = hxxp://partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=5080904
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
Trusted Zone: bxcleve.com\www
Trusted Zone: bxohio.com\www
Trusted Zone: private-planroom.com\subs
Trusted Zone: private-planroom.com\www
TCP: DhcpNameServer = 192.168.254.254 192.168.254.254
TCP: Interfaces\{1335B6E7-E3A1-4A35-B017-7332703EB27C}: NameServer = 166.102.165.11,207.91.5.20
DPF: {4A769165-055C-4566-ABBB-3EA82DD4F8AE} - hxxp://www.ipinviewer.com/binInstall/IVSLite.CAB
.
.
ββ- File Associations ββ-
.
.scr=DWGTrueViewScriptFile
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{C4B8BAB4-1667-11DF-A242-BA9455D89593} - c:\program files\simppulltoolbar\auxi\simppulltoolbAu.dll
BHO-{E4E6BF2A-1667-11DF-A01F-1F9655D89593} - (no file)
HKCU-Run-DellSupportCenter - c:\program files\Dell Support Center\bin\sprtcmd.exe
HKLM-Run-DellSupportCenter - c:\program files\Dell Support Center\bin\sprtcmd.exe
MSConfigStartUp-Pvolago - c:\windows\dpgmsavc.dll
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-04-14 10:54
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes β¦
.
scanning hidden autostart entries β¦
.
scanning hidden files β¦
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
βββββββ DLLs Loaded Under Running Processes βββββββ
.
- - - - - - - > 'winlogon.exe'(944)
c:\windows\System32\BCMLogon.dll
.
Completion time: 2012-04-14 10:55:30
ComboFix-quarantined-files.txt 2012-04-14 14:55
ComboFix2.txt 2010-11-08 13:59
.
Pre-Run: 124,507,447,296 bytes free
Post-Run: 126,002,028,544 bytes free
.
- - End Of File - - 956018A0EC30CEB80B9EA611D18536AC