Hi Satchfan.
Here is CF log:
ComboFix 12-11-06.03 - nurse 11/15/2012 19:31:29.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2012.1136 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\nurse\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
FILE ::
"c:\windows\vfgbelkj.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\arr-next.gif
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\b-sep.gif
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\btn-sq.gif
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\btn.png
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\card.jpg
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\green-l.png
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\green-r.png
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\ie7.css
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\larr.gif
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\lock.png
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\locked-text-en.png
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\logo-img.png
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\logo-text.gif
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\main.html
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\mainbg.gif
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\mcafee-lock.png
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\money.gif
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\moneypak.png
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\payments-en.png
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\side-block.png
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\step.gif
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\step.png
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\style.css
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\wait.html
c:\documents and settings\All Users\Application Data\kighwaojvcanqgq\webcam.swf
c:\documents and settings\nurse\Local Settings\Application Data\assembly\tmp
.
c:\windows\system32\drivers\i8042prt.sys . . . is missing!!
.
.
((((((((((((((((((((((((( Files Created from 2012-10-16 to 2012-11-16 )))))))))))))))))))))))))))))))
.
.
2012-11-16 01:29 . 2012-11-16 01:29 29904 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{FE5F6D23-9541-426E-B6CA-5538135EB061}\MpKslef224626.sys
2012-11-15 09:40 . 2012-10-12 05:56 6918632 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{FE5F6D23-9541-426E-B6CA-5538135EB061}\mpengine.dll
2012-11-14 13:23 . 2012-11-14 13:23 ——– d—–w- c:\documents and settings\nurse\Local Settings\Application Data\PCHealth
2012-11-14 04:09 . 2012-10-12 05:56 6918632 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-11-06 03:06 . 2012-11-06 03:06 40776 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2012-11-05 00:27 . 2012-11-05 00:27 ——– d—–w- c:\documents and settings\administrator.AFC\Application Data\Malwarebytes
2012-11-05 00:20 . 2012-11-05 00:20 ——– d—–w- c:\windows\system32\Wave Systems Corp
2012-11-04 23:45 . 2012-11-04 23:45 ——– d—–w- c:\documents and settings\nurse\Application Data\Malwarebytes
2012-11-04 23:44 . 2012-11-04 23:44 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2012-11-04 23:44 . 2012-11-04 23:46 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2012-11-04 23:44 . 2012-09-30 01:54 22856 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-11-04 22:38 . 2012-11-04 22:38 ——– d-sh–w- c:\documents and settings\administrator.AFC\IECompatCache
2012-11-04 22:37 . 2012-11-04 22:37 73656 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-11-04 22:37 . 2012-11-04 22:37 696760 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-11-04 22:34 . 2012-11-04 22:34 ——– d—–w- c:\documents and settings\administrator.AFC\Application Data\ScanSoft
2012-11-04 22:25 . 2012-11-04 22:25 388096 —-a-r- c:\documents and settings\administrator.AFC\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-11-04 22:12 . 2012-11-04 22:12 ——– d—–w- c:\program files\Trend Micro
2012-11-04 22:05 . 2012-11-05 00:31 ——– d—–w- c:\documents and settings\administrator.AFC\Application Data\Nico Mak Computing
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-11-14 13:19 . 2010-03-02 20:29 0 —-a-w- c:\documents and settings\nurse\Local Settings\Application Data\WavXMapDrive.bat
2012-11-06 23:53 . 2010-03-01 23:26 0 —-a-w- c:\documents and settings\administrator.AFC\Local Settings\Application Data\WavXMapDrive.bat
2012-10-29 19:33 . 2011-07-20 20:38 52648 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\LMIproc.dll
2012-10-29 19:33 . 2011-07-20 20:38 83912 —-a-w- c:\windows\system32\LMIRfsClientNP.dll
2012-10-29 19:33 . 2011-07-20 20:38 31144 —-a-w- c:\windows\system32\LMIport.dll
2012-10-29 19:33 . 2011-07-20 20:38 92072 —-a-w- c:\windows\system32\LMIinit.dll
2012-10-22 08:43 . 2008-04-25 16:16 1875328 —-a-w- c:\windows\system32\win32k.sys
2012-10-02 18:04 . 2008-04-25 16:16 58368 —-a-w- c:\windows\system32\synceng.dll
2012-08-31 03:03 . 2011-04-18 18:18 193552 —-a-w- c:\windows\system32\drivers\MpFilter.sys
2012-08-28 15:14 . 2008-04-25 16:16 916992 —-a-w- c:\windows\system32\wininet.dll
2012-08-28 15:14 . 2008-04-25 16:16 43520 ——w- c:\windows\system32\licmgr10.dll
2012-08-28 15:14 . 2008-04-25 16:16 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-08-28 12:07 . 2008-04-25 16:16 385024 ——w- c:\windows\system32\html.iec
2012-08-24 13:53 . 2008-04-25 16:16 177664 —-a-w- c:\windows\system32\wintrust.dll
2012-08-21 13:52 . 2008-04-25 16:16 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-08-21 13:05 . 2008-04-14 00:01 2027520 —-a-w- c:\windows\system32\ntkrnlpa.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\EnabledUnlockedFDEIconOverlay]
@="{30D3C2AF-9709-4D05-9CF4-13335F3C1E4A}"
[HKEY_CLASSES_ROOT\CLSID\{30D3C2AF-9709-4D05-9CF4-13335F3C1E4A}]
2009-06-12 00:41 49152 —-a-w- c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmIconOverlay.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UninitializedFdeIconOverlay]
@="{CF08DA3E-C97D-4891-A66B-E39B28DD270F}"
[HKEY_CLASSES_ROOT\CLSID\{CF08DA3E-C97D-4891-A66B-E39B28DD270F}]
2009-06-12 00:41 49152 —-a-w- c:\program files\Wave Systems Corp\Trusted Drive Manager\TdmIconOverlay.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTDCPL.EXE" [2009-08-26 2691072]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-07-28 141336]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-07-28 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-07-28 142872]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-02-24 149280]
"ChangeTPMAuth"="c:\program files\Wave Systems Corp\Common\ChangeTPMAuth.exe" [2009-06-03 184320]
"WavXMgr"="c:\program files\Wave Systems Corp\Services Manager\Docmgr\bin\WavXDocMgr.exe" [2009-05-18 145920]
"DellControlPoint"="c:\program files\Dell\Dell ControlPoint\Dell.ControlPoint.exe" [2009-06-12 656384]
"USCService"="c:\program files\Dell\Dell ControlPoint\Security Manager\BcmDeviceAndTaskStatusService.exe" [2009-07-05 15872]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-02-05 128232]
"DBRMTray"="c:\dell\DBRM\Reminder\DbrmTrayIcon.exe" [2009-11-12 203776]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2011-01-12 63048]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-09-12 947176]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2007-10-18 29984]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2007-10-18 46368]
"PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-02-01 255528]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"DBRMTray"="c:\dell\DBRM\Reminder\TrayApp.exe" [2009-10-18 7168]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-4-14 596584]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2012-10-29 19:33 92072 —-a-w- c:\windows\system32\LMIinit.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 wvauth
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
R1 MpKslef224626;MpKslef224626;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{FE5F6D23-9541-426E-B6CA-5538135EB061}\MpKslef224626.sys [11/15/2012 7:29 PM 29904]
R2 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\SeaPort.EXE [10/13/2011 5:21 PM 249648]
R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [7/6/2011 3:32 PM 374704]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [1/11/2011 6:04 PM 12856]
R2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [11/4/2012 5:46 PM 399432]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [11/4/2012 5:44 PM 676936]
R3 k57w2k;Broadcom NetLink ™ Gigabit Ethernet;c:\windows\system32\drivers\k57xp32.sys [2/23/2010 10:54 PM 209960]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [11/4/2012 5:44 PM 22856]
S2 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [10/21/2011 3:23 PM 196176]
S2 SSPORT;SSPORT;\??\c:\windows\system32\Drivers\SSPORT.sys –> c:\windows\system32\Drivers\SSPORT.sys [?]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [11/5/2012 9:06 PM 40776]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSLEF224626
*NewlyCreated* - WS2IFSL
.
Contents of the 'Scheduled Tasks' folder
.
2012-11-14 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2012-09-12 22:25]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/?ilc=5
IE: E&xport; to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
IE: Send to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: myonlinereports.com
TCP: Interfaces\{F368150C-E683-42C5-A7EF-03B2654F1DC3}: NameServer = 192.168.77.10
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2012-11-15 19:37
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(740)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
.
- - - - - - - > 'lsass.exe'(796)
c:\windows\system32\wvauth.dll
c:\windows\system32\WININET.dll
.
Completion time: 2012-11-15 19:38:44
ComboFix-quarantined-files.txt 2012-11-16 01:38
ComboFix2.txt 2012-11-08 01:02
.
Pre-Run: 225,271,693,312 bytes free
Post-Run: 225,377,800,192 bytes free
.
- - End Of File - - B52D18088B047CEDEE8323D45818703F