Wow
!!!
Thank you everyone for all of your replies to my questions. SD here is the log for ComboFix-
ComboFix 10-01-04.01 - Owner 01/08/2010 22:45:24.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.428 [GMT -5:00]
Running from: c:\documents and settings\Owner.Renee\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\All Users\Start Menu\HP Image Zone .lnk
c:\recycler\S-1-5-21-2686083136-3325934572-2218231352-500
c:\windows\COUPON~1.OCX
c:\windows\CouponPrinter.ocx
c:\windows\kb913800.exe
D:\Autorun.inf
----- BITS: Possible infected sites -----
hxxp://updates.swarmcast.net
.
((((((((((((((((((((((((( Files Created from 2009-12-09 to 2010-01-09 )))))))))))))))))))))))))))))))
.
2010-01-04 22:31 . 2010-01-04 22:31 1437720 ----a-w- c:\documents and settings\Owner.Renee\Application Data\Move Networks\MoveMediaPlayerWinSilent_071503000010.exe
2010-01-04 04:44 . 2010-01-04 04:50 -------- d-----w- c:\program files\Trend Micro
2010-01-04 04:17 . 2010-01-04 04:17 152576 ----a-w- c:\documents and settings\Owner.Renee\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-01-04 04:17 . 2010-01-04 04:17 79488 ----a-w- c:\documents and settings\Owner.Renee\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-01-04 03:01 . 2010-01-04 03:01 -------- d-----w- c:\documents and settings\Owner.Renee\Application Data\Malwarebytes
2010-01-04 03:00 . 2009-12-30 19:55 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-04 03:00 . 2010-01-04 03:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-04 03:00 . 2009-12-30 19:54 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-04 03:00 . 2010-01-04 03:01 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-03 16:27 . 2010-01-03 16:27 52224 ----a-w- c:\documents and settings\Owner.Renee\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-01-03 16:27 . 2010-01-03 16:27 117760 ----a-w- c:\documents and settings\Owner.Renee\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-01-03 16:26 . 2010-01-03 16:26 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-01-03 16:25 . 2010-01-03 16:25 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-01-03 16:25 . 2010-01-03 16:25 -------- d-----w- c:\documents and settings\Owner.Renee\Application Data\SUPERAntiSpyware.com
2010-01-03 15:59 . 2010-01-03 15:59 -------- d-----w- c:\program files\CCleaner
2010-01-03 01:28 . 2010-01-03 16:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-01-02 20:18 . 2008-05-02 15:41 3493888 ---ha-w- c:\documents and settings\Owner.Renee\Application Data\U3\temp\Launchpad Removal.exe
2010-01-02 03:55 . 2010-01-03 15:21 -------- d-----w- C:\$AVG
2010-01-02 03:48 . 2010-01-02 03:48 -------- d-----w- c:\program files\AVG
2010-01-02 03:48 . 2010-01-03 15:25 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-01-02 03:30 . 2009-09-30 17:11 288096 ----a-r- c:\documents and settings\Owner.Renee\Application Data\McAfee\Supportability\MVTLogs\Results\detect.dll
2010-01-02 03:25 . 2010-01-02 03:25 -------- d-----w- c:\documents and settings\Owner.Renee\Application Data\McAfee
2010-01-02 01:36 . 2010-01-02 01:36 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-01-01 22:53 . 2010-01-01 22:53 -------- d--h--w- c:\windows\system32\GroupPolicy
2010-01-01 17:37 . 2007-10-23 14:27 110592 ----a-w- c:\documents and settings\Administrator\Application Data\U3\temp\cleanup.exe
2010-01-01 16:24 . 2008-05-02 15:41 3493888 ---ha-w- c:\documents and settings\Administrator\Application Data\U3\temp\Launchpad Removal.exe
2010-01-01 01:20 . 2010-01-01 22:42 -------- d-----w- c:\documents and settings\Administrator\Application Data\U3
2009-12-26 20:32 . 2009-12-26 20:33 28696928 ----a-w- c:\documents and settings\All Users\Application Data\Leapfrog\LeapFrog Connect\Updates\UPCInstaller.exe
2009-12-26 20:29 . 2009-12-26 20:29 6106960 ----a-w- c:\documents and settings\All Users\Application Data\Leapfrog\LeapFrog Connect\Updates\TagPlugin.exe
2009-12-13 23:07 . 2009-12-13 23:07 -------- d-----w- c:\program files\Yahoo!
2009-12-10 21:23 . 2010-01-04 22:31 4183416 ----a-w- c:\documents and settings\Owner.Renee\Application Data\Move Networks\plugins\npqmp071503000010.dll
2009-12-10 19:27 . 2009-12-10 19:27 97144 ----a-w- c:\documents and settings\Owner.Renee\Application Data\Move Networks\ie_bin\MovePlayerUpgrade.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-04 22:32 . 2008-03-17 00:51 -------- d-----w- c:\documents and settings\Owner.Renee\Application Data\U3
2010-01-04 22:31 . 2009-05-31 03:05 -------- d-----w- c:\documents and settings\Owner.Renee\Application Data\Move Networks
2010-01-04 22:31 . 2009-05-31 03:05 144160 ----a-w- c:\documents and settings\Owner.Renee\Application Data\Move Networks\uninstall.exe
2010-01-04 04:59 . 2009-03-24 12:19 -------- d-----w- c:\documents and settings\LocalService\Application Data\SACore
2010-01-04 04:35 . 2008-03-12 00:28 -------- d-----w- c:\program files\Java
2010-01-03 16:23 . 2009-10-24 22:16 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-01-02 03:24 . 2008-03-12 00:38 -------- d-----w- c:\program files\McAfee
2010-01-02 03:24 . 2008-03-12 00:38 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-12-05 04:56 . 2009-03-23 13:21 -------- d-----w- c:\documents and settings\Owner.Renee\Application Data\Apple Computer
2009-11-02 01:20 . 2008-03-16 21:44 13928 ----a-w- c:\documents and settings\Owner.Renee\Application Data\wklnhst.dat
2009-10-29 07:46 . 2006-04-03 19:40 832512 ----a-w- c:\windows\system32\wininet.dll
2009-10-29 07:46 . 2006-04-03 19:34 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-10-29 07:46 . 2006-04-03 19:32 17408 ----a-w- c:\windows\system32\corpol.dll
2009-10-21 05:38 . 2006-04-03 19:39 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2006-04-03 19:34 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2006-04-03 19:34 265728 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2006-04-03 19:38 270336 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2006-04-03 19:39 149504 ----a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2006-04-03 19:39 79872 ----a-w- c:\windows\system32\raschap.dll
2009-10-11 09:17 . 2009-10-06 02:51 411368 ----a-w- c:\windows\system32\deploytk.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY" [X]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-13 344064]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-08-16 236016]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"PhotoExplosionCalCheck"="c:\program files\Nova Development\Photo Explosion Deluxe 3.0\calcheck.exe" [2006-05-10 69632]
"Monitor"="c:\program files\LeapFrog\LeapFrog Connect\Monitor.exe" [2009-11-10 443728]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
autobahn.lnk - c:\program files\Autobahn\autobahn.exe [2008-7-9 708824]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2005-5-11 73728]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 19:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BigFix.lnk
backup=c:\windows\pss\BigFix.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-07-13 18:03 292128 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKDetectorExe]
2005-08-13 00:16 1121792 ----a-w- c:\program files\McAfee\SpamKiller\MSKDetct.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NapsterShell]
2008-05-29 21:18 323216 ----a-w- c:\program files\Napster\napster.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 19:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
2002-09-14 07:42 212992 ----a-w- c:\windows\SMINST\Recguard.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder]
2005-02-25 08:24 966656 ----a-w- c:\windows\creator\remind_xp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2004-11-03 04:24 32768 ----a-w- c:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-10-11 09:17 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2004-11-05 15:47 688218 ----a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
2004-11-05 15:47 98394 ----a-w- c:\program files\Synaptics\SynTP\SynTPLpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Autobahn\\autobahn.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [12/16/2009 4:26 PM 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [12/16/2009 4:26 PM 74480]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [3/23/2009 9:59 PM 210216]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [3/11/2008 6:11 PM 200576]
S3 el575nd5;3Com Megahertz 10/100 LAN CardBus PC Card Driver;c:\windows\system32\drivers\el575ND5.sys [3/11/2008 6:08 PM 69692]
S3 FlyUsb;FLY Fusion;c:\windows\system32\drivers\FlyUsb.sys [10/24/2009 5:17 PM 18560]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [12/16/2009 4:27 PM 7408]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - JAVAQUICKSTARTERSERVICE
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2009-11-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2008-03-12 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\system32\OOBE\oobebaln.exe [2006-04-03 00:12]
2009-11-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-03-24 16:22]
2009-03-24 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-03-24 16:22]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: internet
Trusted Zone: mcafee.com
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-68893943 - c:\docume~1\ALLUSE~1\APPLIC~1\68893943\68893943.exe
MSConfigStartUp-MSMSGS - c:\program files\Messenger\msmsgs.exe
AddRemove-HijackThis - c:\program files\Trend Micro\HijackThis\HijackThis.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-01-08 22:54
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(972)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\WININET.dll
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2010-01-08 22:59:31
ComboFix-quarantined-files.txt 2010-01-09 03:59
Pre-Run: 39,735,357,440 bytes free
Post-Run: 40,168,771,584 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
- - End Of File - - F090676D0815A526F13AB35B32B7997A
I will post the new HJ one in a moment. Again Thank you very much.