Hi jpshortstuff, thank you for responding so fast. Sorry for the delayed response on my end but the holidays held me up.
Here is everything that you requested.
I started off by running ATF cleaner. It freed up 171.934MBs.
Here is my combo fix log:
ComboFix 08-11-30.02 - nodonnell 2008-12-01 14:07:41.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.640 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\temp\1cb
c:\temp\1cb\syscheck.log
c:\windows\system32\bezayedo.dll
c:\windows\system32\evuhemum.ini
c:\windows\system32\mumehuve.dll
c:\windows\system32\onaviror.ini
.
((((((((((((((((((((((((( Files Created from 2008-11-01 to 2008-12-01 )))))))))))))))))))))))))))))))
.
2008-11-26 10:41 . 2008-11-26 10:41 d——– C:\VundoFix Backups
2008-11-21 10:46 . 2008-11-21 10:46 d——– c:\documents and settings\Administrator\Application Data\Share-to-Web Upload Folder
2008-11-21 09:25 . 2008-11-21 09:25 d——– c:\program files\Trend Micro
2008-11-20 13:28 . 2008-11-20 13:28 d——– c:\program files\Malwarebytes' Anti-Malware
2008-11-20 13:28 . 2008-11-20 13:28 d——– c:\documents and settings\nodonnell\Application Data\Malwarebytes
2008-11-20 13:28 . 2008-11-20 13:28 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-20 13:28 . 2008-10-22 16:10 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-20 13:28 . 2008-10-22 16:10 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-11-18 10:38 . 2008-11-18 10:38 d——– c:\windows\system32\vim
2008-11-18 10:38 . 2008-11-18 10:38 d——– c:\windows\system32\ip
2008-11-18 10:38 . 2008-11-18 10:38 d——– c:\windows\system32\hdx
2008-11-18 10:38 . 2008-11-18 10:38 d——– c:\windows\system32\d
2008-11-18 10:38 . 2008-12-01 14:07 d——– C:\Temp
2008-11-13 14:35 . 2008-11-13 14:35 d——– c:\documents and settings\nodonnell\TOSHIBA
2008-11-06 13:01 . 2008-11-06 13:01 d——– c:\program files\Common Files\Nero
2008-11-06 13:00 . 2008-11-06 13:00 d——– c:\program files\Common Files\Ahead
2008-11-06 13:00 . 2008-11-06 13:00 d——– c:\program files\Ahead
2008-11-06 13:00 . 2004-07-26 17:16 1,568,768 ——— c:\windows\system32\ImagX7.dll
2008-11-06 13:00 . 2004-07-26 17:16 476,320 ——— c:\windows\system32\ImagXpr7.dll
2008-11-06 13:00 . 2004-07-26 17:16 471,040 ——— c:\windows\system32\ImagXRA7.dll
2008-11-06 13:00 . 2004-07-09 09:43 364,544 ——— c:\windows\system32\TwnLib4.dll
2008-11-06 13:00 . 2004-07-26 17:16 262,144 ——— c:\windows\system32\ImagXR7.dll
2008-11-06 13:00 . 2001-07-09 11:50 155,648 –a—— c:\windows\system32\NeroCheck.exe
2008-11-06 13:00 . 2000-06-26 11:45 106,496 –a—— c:\windows\system32\TwnLib20.dll
2008-11-06 12:57 . 2008-11-06 12:57 556 –a—— c:\windows\system32\mapisvc.inf
2008-11-06 12:57 . 2008-11-06 12:57 258 –a—— c:\windows\system32\BDEMERGE.INI
2008-11-06 12:56 . 2008-11-06 12:56 d——– c:\program files\Common Files\Borland Shared
2008-11-06 12:55 . 2008-11-06 12:56 d——– c:\program files\WordPerfect Office 11
2008-11-06 12:55 . 2008-11-06 12:56 d——– c:\program files\Common Files\Corel
2008-11-06 12:52 . 2004-08-03 22:58 15,104 –a—— c:\windows\system32\drivers\usbscan.sys
2008-11-06 12:52 . 2004-08-03 22:58 15,104 –a–c— c:\windows\system32\dllcache\usbscan.sys
2008-11-06 12:51 . 2008-11-06 12:51 d——– c:\program files\Common Files\Hewlett-Packard
2008-11-06 12:51 . 2008-11-06 12:51 d——– c:\documents and settings\nodonnell\Application Data\Share-to-Web Upload Folder
2008-11-06 12:50 . 2008-11-06 12:50 d——– C:\sj668
2008-11-06 11:20 . 2004-08-03 23:01 25,856 –a—— c:\windows\system32\drivers\usbprint.sys
2008-11-06 11:20 . 2004-08-03 23:01 25,856 –a–c— c:\windows\system32\dllcache\usbprint.sys
2008-11-06 11:19 . 2008-11-06 12:51 d——– c:\program files\Hewlett-Packard
2008-11-06 11:19 . 2005-06-02 17:26 102,400 –a—— c:\windows\scrub2k.exe
2008-11-06 11:19 . 2005-05-10 16:18 37,376 –a—— c:\windows\system32\hpz3l3xt.dll
2008-11-06 11:19 . 2005-06-02 17:26 397 –a—— c:\windows\hpw9800k.ini
2008-11-06 11:18 . 2008-11-06 11:20 2,803 –a—— c:\windows\mariner.his
2008-11-06 11:18 . 2008-11-06 11:20 1,467 –a—— c:\windows\mariner.ini
2008-11-06 11:18 . 2008-11-06 11:20 92 –a—— c:\windows\hpdj9800.ini
2008-11-06 11:18 . 2008-11-06 11:18 79 –a—— c:\windows\hpdj9800.his
2008-11-06 11:06 . 2006-03-06 15:29 152,624 –a—— c:\windows\system32\WIN2PDFS.DLL
2008-11-06 11:06 . 2006-03-19 15:15 15,360 –a—— c:\windows\system32\WIN2PDFM.DLL
2008-11-06 11:06 . 2008-12-01 10:24 2,559 –a—— c:\windows\1way.ini
2008-11-06 11:03 . 2007-07-24 16:25 62,608 –a—— c:\windows\eSTWFD.chm
2008-11-06 11:03 . 2007-07-24 16:16 62,221 –a—— c:\windows\eSTWLD.chm
2008-11-06 11:03 . 2000-06-27 15:05 1,078 –a—— c:\windows\Object Installerh.ico
2008-11-06 11:02 . 2008-11-06 11:02 d——– c:\program files\TOSHIBA
2008-11-06 11:02 . 2008-11-06 11:02 d——– c:\documents and settings\nodonnell\Application Data\InstallShield
2008-11-06 11:02 . 2007-06-04 10:35 286,720 –a—— c:\windows\system32\eSTsnmp.dll
2008-11-06 11:02 . 2008-11-06 11:02 286,720 –a—— c:\windows\eSTsnmp.dll
2008-11-06 11:02 . 2008-11-06 11:02 147,456 –a—— c:\windows\eSINLD.dll
2008-11-06 11:02 . 2008-11-06 11:02 24,576 –a—— c:\windows\SPortLG.dll
2008-11-06 11:02 . 2008-11-06 11:02 20,480 –a—— c:\windows\eSINLDLG.dll
2008-11-06 11:02 . 2008-11-06 11:02 17,505 –a—— c:\windows\K2_9.ini
2008-11-06 11:02 . 2008-11-06 11:02 1,110 –a—— c:\windows\V_eS3510c.ini
2008-11-06 10:59 . 2008-11-24 15:40 123,952 –a—— c:\windows\system32\drivers\SYMEVENT.SYS
2008-11-06 10:59 . 2008-11-24 15:40 60,800 –a—— c:\windows\system32\S32EVNT1.DLL
2008-11-06 10:59 . 2008-11-24 15:40 10,563 –a—— c:\windows\system32\drivers\SYMEVENT.CAT
2008-11-06 10:59 . 2008-11-24 15:40 805 –a—— c:\windows\system32\drivers\SYMEVENT.INF
2008-11-06 10:58 . 2008-11-24 15:40 d——– c:\program files\Symantec
2008-11-06 10:58 . 2008-11-24 15:41 d——– c:\program files\Common Files\Symantec Shared
2008-11-06 10:58 . 2008-11-24 15:41 d——– c:\documents and settings\All Users\Application Data\Symantec
2008-11-06 10:58 . 2007-03-21 20:39 1,060,864 –a—— c:\windows\system32\MFC71.DLL
2008-11-06 10:58 . 2007-03-21 20:33 503,808 –a—— c:\windows\system32\MSVCP71.DLL
2008-11-06 10:58 . 2007-03-21 20:33 348,160 –a—— c:\windows\system32\MSVCR71.DLL
2008-11-06 10:57 . 2008-11-06 10:57 d——– c:\program files\QuickTime
2008-11-06 10:57 . 2008-11-06 10:57 d——– c:\program files\Common Files\Apple
2008-11-06 10:57 . 2008-11-06 10:57 d——– c:\program files\Apple Software Update
2008-11-06 10:57 . 2008-11-06 10:57 d——– c:\documents and settings\All Users\Application Data\Apple Computer
2008-11-06 10:57 . 2008-11-06 10:57 d——– c:\documents and settings\All Users\Application Data\Apple
2008-11-06 10:53 . 2008-11-06 10:53 d——– c:\program files\Common Files\Adobe AIR
2008-11-06 10:53 . 2008-11-06 10:53 d——– c:\program files\Common Files\Adobe
2008-11-06 10:51 . 2008-11-06 11:13 d——– c:\program files\NOS
2008-11-06 10:51 . 2008-11-06 11:13 d——– c:\documents and settings\All Users\Application Data\NOS
2008-11-06 10:47 . 2008-11-28 15:35 d——– C:\SISTERS
2008-11-06 09:51 . 2007-07-30 19:19 271,224 –a—— c:\windows\system32\mucltui.dll
2008-11-06 09:51 . 2007-07-30 19:19 207,736 –a—— c:\windows\system32\muweb.dll
2008-11-06 09:51 . 2007-07-30 19:19 30,072 –a—— c:\windows\system32\mucltui.dll.mui
2008-11-06 09:50 . 2008-11-06 09:50 d——– c:\windows\SchCache
2008-11-06 09:48 . 2008-11-25 17:01 d——– c:\documents and settings\nodonnell
2008-11-06 09:46 . 2008-11-06 09:46 d——– c:\windows\system32\CatRoot_bak
2008-11-06 09:43 . 2008-11-06 09:44 d–h—– c:\windows\$hf_mig$
2008-11-06 09:43 . 2005-02-24 22:35 22,752 –a—— c:\windows\system32\spupdsvc.exe
2008-11-06 09:39 . 2008-11-06 09:39 d——– c:\program files\MSBuild
2008-11-06 09:39 . 2008-11-06 09:39 d——– c:\program files\Microsoft Works
2008-11-06 09:37 . 2008-11-06 12:56 d——– c:\windows\SHELLNEW
2008-11-06 09:36 . 2008-11-06 09:36 dr-h—– C:\MSOCache
2008-11-06 09:36 . 2008-11-28 10:00 d——– c:\documents and settings\All Users\Application Data\Microsoft Help
2008-11-06 09:35 . 2004-08-03 23:08 26,496 –a–c— c:\windows\system32\dllcache\usbstor.sys
2008-11-06 09:34 . 2001-08-17 13:48 12,160 –a—— c:\windows\system32\drivers\mouhid.sys
2008-11-06 09:34 . 2001-08-17 13:48 12,160 –a–c— c:\windows\system32\dllcache\mouhid.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-06 17:56 ——— d—–w c:\program files\Common Files\InstallShield
2008-11-06 17:51 ——— d–h–w c:\program files\InstallShield Installation Information
2008-10-15 18:43 20,747 —-a-w c:\windows\system32\drivers\AegisP.sys
2008-10-15 18:43 ——— d—–w c:\program files\Hawking
2008-10-14 20:04 ——— d—–w c:\program files\VIA
2008-10-14 20:03 ——— d—–w c:\program files\Realtek AC97
2008-10-14 20:02 ——— d—–w c:\program files\AMD
2008-10-14 18:48 ——— d—–w c:\program files\microsoft frontpage
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RaidTool"="c:\program files\VIA\RAID\raid_tool.exe" [2005-04-21 589824]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-11-24 115560]
"HPWQTOOLBOX"="c:\program files\Hewlett-Packard\HP Deskjet 9800 Series\Toolbox\HPWQTBX.exe" [2005-06-03 335872]
"Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2001-07-03 57344]
"QuickFinder Scheduler"="c:\program files\WordPerfect Office 11\Programs\QFSCHD110.EXE" [2003-07-09 77887]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"VTTimer"="VTTimer.exe" [2005-03-07 c:\windows\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [2005-01-11 c:\windows\system32\VTTrayp.exe]
"SoundMan"="SOUNDMAN.EXE" [2006-01-11 c:\windows\soundman.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"disablecad"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-3716463455-1455960275-1856425994-1757\Scripts\Logon\
0\
0]
"Script"=sylinkdrop-sjph.bat
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Symantec\\Symantec Endpoint Protection\\Smc.exe"=
"c:\\Program Files\\Symantec\\Symantec Endpoint Protection\\SNAC.EXE"=
"c:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe"=
"c:\\Program Files\\Hewlett-Packard\\HP Deskjet 9800 Series\\Toolbox\\HPWQTBX.exe"=
S3 Smcinst;Symantec Auto-upgrade Agent;c:\program files\Symantec\Symantec Endpoint Protection\SmcLU\Setup\smcinst.exe []
.
- - - - ORPHANS REMOVED - - - -
BHO-{542c1783-c53a-4a27-bc44-a6b17ef7518b} - c:\windows\system32\morogeti.dll
HKLM-Run-sanoteruhe - c:\windows\system32\zaniwimo.dll
SafeBoot-Symantec Antvirus
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-12-01 14:12:12
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vsdatant]
"ImagePath"="a"
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
c:\program files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
c:\program files\Symantec\Symantec Endpoint Protection\Smc.exe
c:\program files\Symantec\Symantec Endpoint Protection\SmcGui.exe
c:\progra~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
c:\windows\system32\userinit.exe
.
**************************************************************************
.
Completion time: 2008-12-01 14:12:53 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-01 19:12:51
Pre-Run: 70,468,550,656 bytes free
Post-Run: 70,421,393,408 bytes free
198 — E O F — 2008-11-06 14:44:23
And last but not least here is the other HiJackThis log you requested:
Acrobat.com
Acrobat.com
Adobe AIR
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Reader 9
Apple Software Update
Athlon 64 Processor Driver
Hawking Technologies HWPG1 Wireless-G PCI Card
HijackThis 2.0.2
Hotfix for Windows XP (KB952287)
HP Deskjet 9800
HP Deskjet 9800 Series
HP Precisionscan Pro 3.1
HP Share-to-Web
LiveUpdate 3.3 (Symantec Corporation)
Malwarebytes' Anti-Malware
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional Plus 2007
Microsoft Office Professional Plus 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Nero Suite
QuickTime
Realtek AC'97 Audio
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB958644)
Symantec Endpoint Protection
TOSHIBA e-STUDIO3510c Series Client
Update for Windows XP (KB898461)
VIA Platform Device Manager
VIA/S3G Display Driver
Win2PDF 3.10
Windows Installer 3.1 (KB893803)
WordPerfect Office 11
Thank you again for helping me out.