I am now back and posting a combo fix log as requested by Rorschach112.
ComboFix 09-01-21.04 - Owner 2009-01-24 15:16:56.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.510.236 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated)
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\c.cgm
c:\documents and settings\Owner\Local Settings\Temporary Internet Files\fbk.sts
c:\program files\GamesBar\oberontb.dll
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\cpjsehhp.ini
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\roemvjlm.ini
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
c:\windows\wiaserviv.log
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_TDSSSERV.SYS
——-\Service_TDSSserv.sys
((((((((((((((((((((((((( Files Created from 2008-12-24 to 2009-01-24 )))))))))))))))))))))))))))))))
.
2009-01-14 10:41 . 2009-01-14 10:41 d——– c:\documents and settings\Owner\Application Data\CyberLink
2009-01-13 17:37 . 2009-01-13 19:55 d——– C:\SDFix
2009-01-11 18:16 . 2009-01-11 18:16 d——– c:\program files\Trend Micro
2009-01-11 16:27 . 2009-01-11 16:27 d——– c:\program files\Malwarebytes' Anti-Malware
2009-01-11 16:27 . 2009-01-04 18:39 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-11 16:27 . 2009-01-04 18:39 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-01-11 11:30 . 2009-01-11 11:30 d——– c:\windows\system32\config\systemprofile\Application Data\GetModule
2009-01-10 13:02 . 2002-03-18 06:00 147,512 –a—— c:\windows\system32\hpzlnt05.dll
2009-01-09 18:52 . 2009-01-09 18:52 d——– c:\program files\Hp
2009-01-09 18:22 . 2008-10-16 15:38 6,066,176 —–c— c:\windows\system32\dllcache\ieframe.dll
2009-01-09 18:22 . 2007-04-17 04:32 2,455,488 —–c— c:\windows\system32\dllcache\ieapfltr.dat
2009-01-09 18:22 . 2007-03-08 00:10 991,232 —–c— c:\windows\system32\dllcache\ieframe.dll.mui
2009-01-09 18:22 . 2008-10-16 15:38 459,264 —–c— c:\windows\system32\dllcache\msfeeds.dll
2009-01-09 18:22 . 2008-10-16 15:38 383,488 —–c— c:\windows\system32\dllcache\ieapfltr.dll
2009-01-09 18:22 . 2008-10-16 15:38 267,776 —–c— c:\windows\system32\dllcache\iertutil.dll
2009-01-09 18:22 . 2008-10-16 15:38 63,488 —–c— c:\windows\system32\dllcache\icardie.dll
2009-01-09 18:22 . 2008-10-16 15:38 52,224 —–c— c:\windows\system32\dllcache\msfeedsbs.dll
2009-01-09 18:22 . 2008-10-16 08:11 13,824 —–c— c:\windows\system32\dllcache\ieudinit.exe
2009-01-09 17:18 . 2009-01-09 17:18 0 –a—— c:\windows\vpc32.INI
2009-01-09 17:04 . 2009-01-24 14:58 d——– c:\program files\Symantec AntiVirus
2009-01-09 09:48 . 2009-01-09 09:48 d——– c:\documents and settings\Owner\Application Data\Malwarebytes
2009-01-08 20:23 . 2009-01-08 20:23 d——– c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-01-08 20:22 . 2009-01-08 20:22 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-08 19:03 . 2009-01-08 19:03 d——– c:\windows\ERUNT
2009-01-08 18:11 . 2009-01-08 18:11 1,529,241 –a—— c:\program files\SDFix.exe
2009-01-08 17:47 . 2009-01-11 17:08 d——– c:\program files\SmitfraudFix
2009-01-08 16:56 . 2009-01-08 16:57 2,697,344 –a—— c:\program files\mbam-setup.exe
2009-01-07 09:40 . 2009-01-07 09:40 43,008 –a—— c:\windows\system32\aj32.dll
2009-01-07 09:40 . 2009-01-07 09:40 1,264 –a—— c:\windows\system32\lp
2009-01-06 17:45 . 2009-01-11 17:52 d——– c:\documents and settings\Administrator\Application Data\Yahoo!
2009-01-06 17:35 . 2009-01-06 17:35 d——– c:\documents and settings\Administrator
2009-01-05 08:12 . 2009-01-05 08:12 d——– c:\windows\qozw
2009-01-05 08:12 . 2009-01-07 18:06 d——– c:\program files\Common Files\qozw
2009-01-04 22:54 . 2009-01-09 09:40 d——– c:\documents and settings\Owner\Application Data\Twain
2009-01-04 15:43 . 2009-01-09 19:51 d——– c:\program files\Auslogics
2009-01-04 15:43 . 2009-01-09 19:52 d——– c:\documents and settings\Owner\Application Data\Auslogics
2009-01-04 15:42 . 2009-01-04 15:42 1,651,248 –a—— c:\program files\disk-defrag-setup.exe
2009-01-04 15:32 . 2009-01-04 15:32 d——– c:\documents and settings\Owner\Application Data\GlarySoft
2009-01-04 15:17 . 2009-01-06 08:06 d——– c:\program files\AskBarDis
2009-01-04 15:16 . 2009-01-04 15:25 d——– c:\program files\Glary Utilities
2009-01-04 15:15 . 2009-01-04 15:15 5,632,896 –a—— c:\program files\gusetupnew.exe
2009-01-04 15:09 . 2009-01-04 15:09 50,688 –a—— c:\program files\ATF-Cleaner.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-24 20:17 ——— d—–w c:\program files\GamesBar
2009-01-24 19:56 ——— d—–w c:\program files\Symantec
2009-01-24 19:56 ——— d—–w c:\program files\Common Files\Symantec Shared
2009-01-24 19:56 ——— d—–w c:\documents and settings\All Users\Application Data\Symantec
2009-01-11 11:15 6,656 —-a-w c:\windows\system32\drivers\aeaudio.sys
2009-01-10 18:15 ——— d—–w c:\program files\Google
2009-01-10 18:03 ——— d—–w c:\program files\hp deskjet 5550 series
2009-01-09 15:19 ——— d—–w c:\documents and settings\Owner\Application Data\Intuit
2009-01-07 23:30 ——— d—–w c:\program files\Viewpoint
2009-01-07 23:30 ——— d—–w c:\documents and settings\All Users\Application Data\Viewpoint
2009-01-06 21:40 ——— d—–w c:\program files\Verizon Online
2009-01-06 21:37 ——— d–h–w c:\program files\InstallShield Installation Information
2009-01-06 21:37 ——— d—–w c:\program files\Infogrames Interactive
2009-01-06 21:35 ——— d—–w c:\program files\Common Files\Oberon Media
2009-01-04 12:24 ——— d—–w c:\documents and settings\All Users\Application Data\GamesBar
2008-12-08 19:20 63,488 —-a-w c:\windows\xobglu16.dll
2008-12-08 19:20 23,552 —-a-w c:\windows\xobglu32.dll
2008-12-08 16:32 ——— d—–w c:\program files\Picasa2
2008-04-01 18:13 69,400 —-a-w c:\documents and settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
2006-07-04 21:24 774,144 —-a-w c:\program files\RngInterstitial.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-07-17 279944]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-07-17 279944]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"Yahoo! Pager"="c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2006-10-30 4662776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ymetray"="c:\program files\Yahoo!\Yahoo! Music Engine\ymetray.exe" [2006-10-03 54776]
"YOP"="c:\progra~1\Yahoo!\YOP\yop.exe" [2005-06-16 401408]
"Motive SmartBridge"="c:\progra~1\Verizon\SMARTB~1\MotiveSB.exe" [2006-06-23 438359]
"YBrowser"="c:\progra~1\Yahoo!\browser\ybrwicon.exe" [2006-07-21 129536]
"Verizon_McciTrayApp"="c:\program files\Verizon\McciTrayApp.exe" [2007-03-11 936960]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb05.exe" [2002-03-18 188416]
c:\documents and settings\Owner\Start Menu\Programs\Startup\
HotSync Manager.lnk - c:\program files\Palm\HOTSYNC.EXE [2003-09-25 299008]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Dataviz Messenger.lnk - c:\windows\DvzCommon\DvzMsgr.exe [2003-07-01 24576]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=fjhjek.dll lzpsfe.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Windows.hta]
backup=c:\windows\pss\Microsoft Windows.htaCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ymetray.lnk]
backup=c:\windows\pss\ymetray.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
–a—— 2004-12-19 10:58 684032 c:\program files\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
–a—— 2005-06-06 23:46 57344 c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
–a—— 2005-10-19 07:59 126976 c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
–a—— 2005-10-19 07:59 155648 c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Picasa Media Detector]
–a—— 2006-09-14 14:38 249927 c:\program files\Picasa2\PicasaMediaDetector.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2004-12-27 10:33 98304 c:\program files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
–a—— 2004-12-27 10:33 26112 c:\program files\Real\RealPlayer\realplay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
–a—— 2003-08-29 04:59 122880 c:\windows\BCMSMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Palm\\HOTSYNC.EXE"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\PROGRA~1\\Yahoo!\\MESSEN~1\\Yserver.exe"= c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe
"c:\\Program Files\\Yahoo!\\Yahoo! Music Engine\\YahooMusicEngine.exe"=
"c:\\Program Files\\Yahoo!\\browser\\ybrowser.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\OuterBound Games\\Demolition Derby & Figure 8\\Game\\DemoDerby\\DemoDerby.exe"=
R0 PQV2i;PQV2i;c:\windows\system32\drivers\PQV2i.sys [2004-02-17 138118]
R1 PQIMount;PQIMount;c:\windows\system32\drivers\PQIMount.sys [2004-02-17 46773]
.
Contents of the 'Scheduled Tasks' folder
2009-01-24 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2008-12-01 09:38]
2009-01-24 c:\windows\Tasks\irhebylm.job
- c:\windows\system32\qoMffdDt.dll []
2007-02-22 c:\windows\Tasks\MP Scheduled Quick Scan.job
- c:\program files\Microsoft Windows OneCare Live\Antivirus\MpCmdRun.exe []
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = 127.0.0.1
IE: &AIM Search - c:\program files\AIM Toolbar\AIMBar.dll/aimsearch.htm
IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
Trusted Zone: symantec.com
Trusted Zone: symantec.com\liveupdate
Trusted Zone: turbotax.com
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-24 15:20:45
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'winlogon.exe'(784)
c:\windows\system32\COMRes.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\gearsec.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\windows\system32\wdfmgr.exe
c:\program files\PowerQuest\V2i Protector 2.0\Agent\PQV2iSvc.exe
c:\progra~1\Yahoo!\browser\ycommon.exe
c:\windows\system32\wscntfy.exe
c:\progra~1\Yahoo!\MESSEN~1\Ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2009-01-24 15:27:45 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-24 20:27:09
Pre-Run: 47,957,733,376 bytes free
Post-Run: 48,004,976,640 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect
226 — E O F — 2009-01-11 16:11:15