Combofix log from family pc....I left flash drive in and noticed E:Recycler\Desktop.ini during scan if that is relevant...did previously disinfect flash drive. Work pc unplugged.
ComboFix 09-03-29.02 - Visitor 2009-03-29 22:28:35.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1337 [GMT -4:00]
Running from: c:\documents and settings\Visitor\Desktop\ComboFix.exe
AV: CA Anti-Virus *On-access scanning disabled* (Updated)
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
e:\recycler\Desktop.ini
.
((((((((((((((((((((((((( Files Created from 2009-02-28 to 2009-03-30 )))))))))))))))))))))))))))))))
.
2009-03-29 12:24 . 2009-03-29 12:24 410,984 --a------ c:\windows\SYSTEM32\deploytk.dll
2009-03-29 12:24 . 2009-03-29 12:24 73,728 --a------ c:\windows\SYSTEM32\javacpl.cpl
2009-03-28 18:38 . 2009-03-28 19:11 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-03-28 18:38 . 2009-03-26 16:49 38,496 --a------ c:\windows\SYSTEM32\DRIVERS\mbamswissarmy.sys
2009-03-28 18:38 . 2009-03-26 16:49 15,504 --a------ c:\windows\SYSTEM32\DRIVERS\mbam.sys
2009-03-26 16:09 . 2009-03-26 16:09 200,613 --a------ C:\caisslog.txt.encrypt
2009-03-26 16:09 . 2009-03-26 16:09 35,175 --a------ C:\caavsetupLog.txt.encrypt
2009-03-26 16:07 . 2009-03-29 19:42 0 --a------ c:\windows\SYSTEM32\DRIVERS\c1002347.sys
2009-03-26 16:06 . 2009-03-26 16:06 2 --a------ C:\-200506787
2009-03-26 14:52 . 2009-03-26 14:52 <DIR> d-------- c:\documents and settings\Visitor\Application Data\Malwarebytes
2009-03-25 19:57 . 2009-03-25 19:57 54,156 --ah----- c:\windows\QTFont.qfn
2009-03-25 19:57 . 2009-03-25 19:57 1,409 --a------ c:\windows\QTFont.for
2009-03-02 16:52 . 2009-03-02 16:52 <DIR> d-------- c:\program files\Smilebox
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-30 00:22 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2009-03-29 16:24 --------- d-----w c:\program files\Java
2009-03-29 13:14 --------- d-----w c:\program files\Viewpoint
2009-03-29 13:14 --------- d-----w c:\documents and settings\All Users\Application Data\Viewpoint
2009-03-25 11:46 1,212,416 ----a-w c:\windows\SYSTEM32\mdmcls32.exe
2009-03-12 21:15 --------- d-----w c:\program files\Zune
2009-02-11 22:36 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-09 11:13 1,846,784 ----a-w c:\windows\SYSTEM32\win32k.sys
2009-02-09 11:13 1,846,784 ------w c:\windows\SYSTEM32\DLLCACHE\win32k.sys
2009-01-31 21:51 921,632 ----a-w C:\PA7302.DAT
2009-01-17 02:35 3,594,752 ------w c:\windows\SYSTEM32\DLLCACHE\mshtml.dll
2008-12-19 09:10 70,656 ------w c:\windows\SYSTEM32\DLLCACHE\ie4uinit.exe
2008-12-19 09:10 13,824 ------w c:\windows\SYSTEM32\DLLCACHE\ieudinit.exe
2008-12-19 05:25 634,024 ------w c:\windows\SYSTEM32\DLLCACHE\iexplore.exe
2008-12-19 05:23 161,792 ------w c:\windows\SYSTEM32\DLLCACHE\ieakui.dll
2008-12-11 10:57 333,952 ------w c:\windows\SYSTEM32\DLLCACHE\srv.sys
2008-12-05 06:54 144,896 ----a-w c:\windows\SYSTEM32\schannel.dll
2008-12-05 06:54 144,896 ------w c:\windows\SYSTEM32\DLLCACHE\schannel.dll
2008-06-10 23:10 30,720 --sha-w c:\windows\rnapxs\rnapxs.dat
2008-11-07 00:44 952 --sha-w c:\windows\SYSTEM32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( SnapShot@2009-03-29_10.00.29.46 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-03-29 13:53:30 2,297,856 ----a-w c:\windows\rnapxs\CSDK\urlcache\domainNames.dat
+ 2009-03-29 17:20:11 2,301,952 ----a-w c:\windows\rnapxs\CSDK\urlcache\domainNames.dat
- 2009-03-29 13:53:30 28,966,912 ----a-w c:\windows\rnapxs\CSDK\urlcache\urlCacheDb.dat
+ 2009-03-29 22:17:23 28,966,912 ----a-w c:\windows\rnapxs\CSDK\urlcache\urlCacheDb.dat
- 2008-02-22 05:23:35 135,168 ----a-w c:\windows\SYSTEM32\java.exe
+ 2009-03-29 16:24:06 144,792 ----a-w c:\windows\SYSTEM32\java.exe
- 2008-02-22 05:23:39 135,168 ----a-w c:\windows\SYSTEM32\javaw.exe
+ 2009-03-29 16:24:06 144,792 ----a-w c:\windows\SYSTEM32\javaw.exe
- 2008-02-22 06:33:32 139,264 ----a-w c:\windows\SYSTEM32\javaws.exe
+ 2009-03-29 16:24:06 148,888 ----a-w c:\windows\SYSTEM32\javaws.exe
+ 2009-03-30 00:21:04 16,384 ----atw c:\windows\temp\Perflib_Perfdata_724.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"AIM"="c:\program files\AIM\aim.exe" [2004-12-08 67160]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-06-30 1388544]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 221184]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-11 290816]
"MMTray"="c:\program files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe" [2005-03-15 135168]
"UpdateManager"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-07 110592]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-08-13 122939]
"Dell Photo AIO Printer 922"="c:\program files\Dell Photo AIO Printer 922\dlbtbmgr.exe" [2004-06-18 290816]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2005-04-30 180269]
"mmtask"="c:\program files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe" [2005-03-15 53248]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-03-14 257088]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-01-31 385024]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2008-11-10 157312]
"cctray"="c:\program files\CA\CA Internet Security Suite\cctray\cctray.exe" [2009-01-23 181488]
"dvHighMem"="c:\windows\cfgmng32.exe" [2007-11-14 11333632]
"CAVRID"="c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2008-09-09 234736]
"PAC7302_Monitor"="c:\windows\PixArt\PAC7302\Monitor.exe" [2006-11-03 319488]
"PNSMax4PNP"="c:\program files\Analog Devices\SoundMAX\PNSMax4PNP.exe" [2009-03-26 45056]
"PNdMAX\PNSMax4PNP"="c:\program files\Analog Devices\SoundMAX\PNSMax4PNP.exe" [2009-03-26 45056]
"PNoundMAX\PNSMax4PNP"="c:\program files\Analog Devices\SoundMAX\PNSMax4PNP.exe" [2009-03-26 45056]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-29 148888]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-13 c:\windows\SYSTEM32\narrator.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
MA111 Configuration Utility.lnk - c:\program files\NETGEAR\MA111 Configuration Utility\wlancfg4.exe [2004-12-11 1158144]
Ralink Wireless Utility.lnk - c:\program files\RALINK\Common\RaUI.exe [2009-01-03 1527808]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.3IV2"= 3ivxVfWCodec_dec.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\taskmgr.exe]
"Debugger"=7AB65E
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Games\\Rise of Nations\\rise.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield Vietnam\\bfvietnam.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 1942\\BF1942.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\RALINK\\Common\\ApUI.exe"=
"c:\\Program Files\\CA\\CA Internet Security Suite\\CA Anti-Virus\\isafe.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
R2 WinSvchostManager;WinSock Svchost Manager;c:\windows\SYSTEM32\svcprs32.exe [2008-06-10 823296]
R3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;c:\windows\SYSTEM32\DRIVERS\rt2870.sys [2009-01-03 560896]
S1 c1002347;c1002347;c:\windows\SYSTEM32\DRIVERS\c1002347.sys [2009-03-26 0]
S3 PAC7302;PAC7302 VGA USB Camera;c:\windows\SYSTEM32\DRIVERS\PAC7302.SYS [2009-01-02 457856]
S3 WlanUIB;NETGEAR 802.11b USB Driver;c:\windows\SYSTEM32\DRIVERS\MA111nd5.sys [2004-12-11 666624]
.
Contents of the 'Scheduled Tasks' folder
2009-03-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 13:34]
2009-03-30 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-20 17:08]
2009-03-30 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com
mStart Page = hxxp://www.yahoo.com
uInternet Connection Wizard,ShellNext = hxxp://www.dell4me.com/mywaybiz
LSP: c:\windows\system32\winsflt.dll
LSP: c:\windows\system32\VetRedir.dll
FF - ProfilePath - c:\documents and settings\Visitor\Application Data\Mozilla\Firefox\Profiles\72rmwta6.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-29 22:33:17
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(892)
c:\windows\system32\winsflt.dll
.
Completion time: 2009-03-29 22:36:26
ComboFix-quarantined-files.txt 2009-03-30 02:35:40
ComboFix2.txt 2009-03-29 14:01:21
Pre-Run: 8,513,957,888 bytes free
Post-Run: 8,576,999,424 bytes free
177 --- E O F --- 2009-03-19 21:46:29
Thanks again
Mark