PLEASE IGNORE FIRST REPLY--Requested logs
Okay, I got back on line and here are the requested logs.
ComboFix log:
ComboFix 09-06-28.01 - George 06/28/2009 23:42.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.642 [GMT -4:00]
Running from: c:\documents and settings\George\Desktop\ComboFix.exe
AV: ESET Smart Security 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Pat Adler\Local Settings\Temporary Internet Files\CSC2.1U-EN-561-I.sbr.sgn
c:\documents and settings\Pat Adler\Local Settings\Temporary Internet Files\CSC2.1U-EN-827-F.sbr.sgn
c:\documents and settings\Pat Adler\Local Settings\Temporary Internet Files\CSC2.1U-EN-952-I.sbr.sgn
c:\documents and settings\Pat Adler\Local Settings\Temporary Internet Files\CSC2.1U-EN-952-I.sbr.sgn.unsgn
c:\documents and settings\Pat Adler\nah_log.dat
c:\documents and settings\Visitor\Local Settings\Temporary Internet Files\CSC2.1U-EN-602-F.sbr.sgn
c:\windows\system32\AutoRun.inf
Infected copy of c:\windows\system32\winlogon.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\winlogon.exe
.
((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-06-29 )))))))))))))))))))))))))))))))
.
2009-06-28 16:03 . 2009-06-28 16:03 -------- d-----w- c:\program files\Trend Micro
2009-06-28 03:17 . 2009-06-28 03:17 -------- d-----w- c:\documents and settings\George\Application Data\Malwarebytes
2009-06-28 02:43 . 2009-06-28 02:43 -------- d-----w- c:\documents and settings\Pat Adler\Application Data\Malwarebytes
2009-06-28 02:43 . 2009-06-17 15:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-28 02:43 . 2009-06-28 02:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-28 02:43 . 2009-06-28 02:43 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-28 02:43 . 2009-06-17 15:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-26 02:33 . 2009-06-26 02:33 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\ESET
2009-06-25 12:24 . 2009-06-25 12:24 -------- d-----w- c:\documents and settings\George\Local Settings\Application Data\ESET
2009-06-19 03:34 . 2009-06-19 03:34 -------- d-sh--w- c:\documents and settings\Pat Adler\PrivacIE
2009-06-13 13:35 . 2009-06-13 13:35 -------- d-sh--w- c:\documents and settings\George\PrivacIE
2009-06-11 13:31 . 2009-04-30 21:22 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-06-11 13:31 . 2009-04-30 21:22 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-13 13:54 . 2008-05-31 16:03 43160 ----a-w- c:\documents and settings\George\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-13 12:58 . 2007-08-14 20:38 -------- d-----w- c:\program files\MSN Messenger
2009-06-09 12:37 . 2009-05-15 19:53 988328 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-06-02 01:53 . 2007-09-23 16:01 -------- d-----w- c:\program files\Google
2009-05-15 20:23 . 2006-09-01 20:18 43160 ----a-w- c:\documents and settings\Pat Adler\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-15 20:20 . 2009-05-15 20:20 -------- d-----w- c:\program files\NetLibrary
2009-05-15 19:53 . 2009-05-15 19:53 -------- d-----w- c:\program files\MSBuild
2009-05-15 19:53 . 2009-05-15 19:53 -------- d-----w- c:\program files\Reference Assemblies
2009-05-15 19:26 . 2007-07-16 12:03 -------- d-----w- c:\program files\Windows Media Connect 2
2009-05-13 05:15 . 2004-08-04 12:00 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-11 17:25 . 2009-05-11 02:14 -------- d-----w- c:\documents and settings\Pat Adler\Application Data\Move Networks
2009-05-07 15:32 . 2004-08-04 12:00 345600 ------w- c:\windows\system32\localspl.dll
2009-05-07 10:23 . 2006-09-07 01:54 -------- d-----w- c:\program files\CMS Peripherals
2009-05-07 02:00 . 2009-05-07 02:00 -------- d-----w- c:\program files\Citrix
2009-05-07 02:00 . 2009-05-07 02:00 70984 ----a-w- c:\documents and settings\Pat Adler\g2mdlhlpx.exe
2009-05-06 23:27 . 2009-05-06 23:27 -------- d-----w- c:\program files\Coupons
2009-05-05 19:10 . 2009-05-05 19:10 -------- d-----w- c:\documents and settings\Visitor\Application Data\ESET
2009-05-05 02:29 . 2009-05-05 02:29 -------- d-----w- c:\documents and settings\George\Application Data\ESET
2009-05-05 02:28 . 2006-09-01 19:59 -------- d-----w- c:\program files\ESET
2009-05-05 02:25 . 2009-05-05 02:25 -------- d-----w- c:\documents and settings\Pat Adler\Application Data\ESET
2009-05-05 02:22 . 2009-05-05 02:22 -------- d-----w- c:\documents and settings\All Users\Application Data\ESET
2009-04-17 12:26 . 2004-08-04 12:00 1847168 ------w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-08-04 12:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-04-09 19:21 . 2009-04-09 19:21 55768 ----a-w- c:\windows\system32\drivers\epfwtdi.sys
2009-04-09 19:21 . 2009-04-09 19:21 33096 ----a-w- c:\windows\system32\drivers\epfwndis.sys
2009-04-09 19:21 . 2009-04-09 19:21 133000 ----a-w- c:\windows\system32\drivers\epfw.sys
2009-04-09 19:18 . 2009-04-09 19:18 107256 ----a-w- c:\windows\system32\drivers\ehdrv.sys
2009-04-09 19:10 . 2009-04-09 19:10 113960 ----a-w- c:\windows\system32\drivers\eamon.sys
.
------- Sigcheck -------
[7] 2004-08-04 12:00 295424 B60C877D16D9C880B952FDA04ADF16E6 c:\windows\$NtServicePackUninstall$\termsrv.dll
[7] 2008-04-14 00:12 295424 FF3477C03BE7201C294C35F684B3479F c:\windows\ServicePackFiles\i386\termsrv.dll
[-] 2008-11-29 01:03 295424 63999D0ABD8DABFD76A9C07F6E104868 c:\windows\system32\termsrv.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PhotoShow Deluxe Media Manager"="c:\progra~1\Nero\data\Xtras\mssysmgr.exe" [2005-02-26 212992]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"IntelAudioStudio"="c:\program files\Intel Audio Studio\IntelAudioStudio.exe" [2006-06-07 9129984]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-06-23 7626752]
"THGuard"="c:\program files\TrojanHunter 4.5\THGuard.exe" [2006-05-31 1120256]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-10-03 185784]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-11-07 196608]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-15 49152]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-04-09 2029640]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-06-23 1519616]
"NvMediaCenter"="NvMCTray.dll" - c:\windows\system32\nvmctray.dll [2006-06-23 86016]
c:\documents and settings\Pat Adler\Start Menu\Programs\Startup\
DING!.lnk - c:\program files\Southwest Airlines\Ding\Ding.exe [2006-6-22 462848]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [4/9/2009 3:18 PM 107256]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [4/9/2009 3:19 PM 731840]
S2 gupdate1c9e324cb036076;Google Update Service (gupdate1c9e324cb036076);c:\program files\Google\Update\GoogleUpdate.exe [6/1/2009 9:52 PM 133104]
S2 portD;CMS PortIO Service;c:\windows\system32\DRIVERS\portd2k.sys --> c:\windows\system32\DRIVERS\portd2k.sys [?]
S3 esihdrv;esihdrv;\??\c:\docume~1\PATADL~1\LOCALS~1\Temp\esihdrv.sys --> c:\docume~1\PATADL~1\LOCALS~1\Temp\esihdrv.sys [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2008-11-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-06-03 17:42]
2009-06-29 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-02 01:52]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-MyWebSearch Plugin - c:\progra~1\MYWEBS~1\bar\2.bin\M3PLUGIN.DLL
HKLM-Run-SigmatelSysTrayApp - sttray.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://mystart.incredimail.com/english/
uInternet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\George\Application Data\Mozilla\Firefox\Profiles\uvlvfgr2.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.dailykos.com/
FF - plugin: c:\program files\Google\Update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-06-28 23:49
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(2556)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\windows\system32\rundll32.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
.
**************************************************************************
.
Completion time: 2009-06-29 23:51 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-29 03:51
Pre-Run: 229,105,733,632 bytes free
Post-Run: 234,596,958,208 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
195 --- E O F --- 2009-06-12 03:04
------------------------------------------------------------------
HiJackThis log:
32 Bit HP CIO Components Installer
Adobe Flash Player 10 Plugin
Adobe Flash Player 9 ActiveX
Adobe Flash Player ActiveX
Adobe Reader 7.1.0
Amazon MP3 Downloader 1.0.3
Apple Software Update
Coupon Printer for Windows
Critical Update for Windows Media Player 11 (KB959772)
DING!
Google Earth
Google Update Helper
High Definition Audio Driver Package - KB888111
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB961118)
HP Customer Participation Program 10.0
HP Imaging Device Functions 10.0
HP Photosmart All-In-One Driver Software 10.0 Rel .2
HP Photosmart Essential 2.5
HP Smart Web Printing
HP Solution Center 10.0
HP Update
Intel Audio Studio 2.0
Intel(R) Active Client Manager 2.0 HECI Driver
Intel(R) PRO Network Connections
J2SE Runtime Environment 5.0 Update 6
Malwarebytes' Anti-Malware
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office XP Small Business
Microsoft User-Mode Driver Framework Feature Pack 1.0
Mozilla Firefox (3.0.11)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
Nero PhotoShow Express
Nero Suite
NetLibrary Media Center
Netscape Browser (remove only)
NVIDIA Drivers
NVIDIA nStant Media
OCR Software by I.R.I.S. 10.0
OverDrive Media Console
Personal License Update Wizard for Windows Media Player
QuickTime
RealPlayer
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB913433)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Shop for HP Supplies
SigmaTel Audio
TrojanHunter 4.5
Update for Windows Internet Explorer 8 (KB968220)
Update for Windows XP (KB942763)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Wallpaper Stationery
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows XP Service Pack 3
ZENcast Organizer
----------------------------------------------------------------