OTL became stalled so I did the combofix instead, around step 3 or 4 it came up with a message: "PEV.exe application error. The instruction at 0x0039a6a7 referenced memory at 0x78393aa7. The memory could not be "written" click ok to terminate or click cancel to debug" I left this message up and it eventually went away. Here is the log file from combofix:
ComboFix 10-07-16.02 - Bartholow 07/18/2010 15:59:25.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2303.1727 [GMT -4:00]
Running from: c:\documents and settings\Bartholow\desktop\commy.exe
Command switches used :: /stepdel
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\version.txt
c:\windows\Install.txt
c:\windows\system32\Install.txt
Infected copy of c:\windows\system32\drivers\atapi.sys was found and disinfected
Restored copy from - Kitty had a snack :p
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IAS
-------\Service_Ias
((((((((((((((((((((((((( Files Created from 2010-06-18 to 2010-07-18 )))))))))))))))))))))))))))))))
.
2010-07-18 17:11 . 2010-07-18 17:11 -------- d-----w- C:\_OTL
2010-07-16 20:03 . 2010-06-14 14:31 744448 ------w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-06 10:33 . 2010-07-06 10:33 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2010-07-06 10:33 . 2010-07-06 10:33 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Apple Computer
2010-07-02 22:08 . 2010-07-02 22:08 -------- d-----w- c:\program files\iPod
2010-07-02 22:08 . 2010-07-02 22:09 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-07-02 22:04 . 2010-07-02 22:05 -------- d-----w- c:\program files\QuickTime
2010-07-02 21:59 . 2010-07-02 21:59 -------- d-----w- c:\program files\Bonjour
2010-07-02 19:14 . 2010-07-02 19:14 -------- d-----w- c:\program files\ESET
2010-07-02 18:38 . 2010-07-02 18:38 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-07-02 18:37 . 2010-07-02 18:38 -------- d-----w- c:\documents and settings\Bartholow\Local Settings\Application Data\Adobe
2010-07-02 18:29 . 2010-04-12 21:29 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-02 02:09 . 2010-07-02 02:09 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Help
2010-07-02 00:01 . 2010-07-02 00:01 141 ----a-w- c:\program files\drv_30282781.bat
2010-07-01 15:24 . 2010-07-01 15:24 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\vphhsuiyk
2010-06-29 15:10 . 2010-05-06 10:41 743424 ------w- c:\windows\system32\dllcache\iedvtool.dll
2010-06-29 14:55 . 2010-06-29 14:55 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-06-29 14:51 . 2010-06-29 14:51 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-02 22:09 . 2005-12-31 05:07 -------- d-----w- c:\program files\iTunes
2010-07-02 22:08 . 2009-04-10 22:24 -------- d-----w- c:\program files\Common Files\Apple
2010-07-02 18:55 . 2009-07-21 21:31 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-07-02 18:43 . 2003-11-22 19:30 -------- d-----w- c:\program files\Common Files\Adobe
2010-07-02 18:32 . 2003-11-03 12:37 -------- d-----w- c:\program files\Java
2010-07-02 18:30 . 2003-11-03 12:37 -------- d-----w- c:\program files\Common Files\Java
2010-07-02 11:24 . 2006-09-06 20:00 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-07-01 15:40 . 2005-06-03 00:51 -------- d-----w- c:\program files\McAfee
2010-06-29 14:55 . 2009-10-09 23:51 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-06-29 14:54 . 2009-08-08 20:02 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-06-29 14:51 . 2004-01-09 19:28 -------- d-----w- c:\program files\Lavasoft
2010-06-16 05:42 . 2010-06-16 05:42 -------- d-----w- c:\documents and settings\NetworkService\Application Data\AdobeUM
2010-06-03 17:56 . 2003-11-22 20:59 -------- d-----w- c:\documents and settings\Bartholow\Application Data\AdobeUM
2010-05-18 20:35 . 2010-05-18 20:35 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-05-18 20:35 . 2010-05-18 20:35 197920 ----a-w- c:\windows\system32\dnssdX.dll
2010-05-18 20:35 . 2010-05-18 20:35 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-05-06 10:41 . 2006-06-23 15:33 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2002-08-29 11:00 1851264 ----a-w- c:\windows\system32\win32k.sys
2010-04-29 19:39 . 2010-05-06 00:50 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 19:39 . 2010-05-06 00:50 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-26 00:12 . 2003-11-05 22:45 47808 ----a-w- c:\documents and settings\Bartholow\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-20 05:30 . 2002-08-29 11:00 285696 ----a-w- c:\windows\system32\atmfd.dll
2010-04-20 00:47 . 2009-04-10 22:25 3062048 ----a-w- c:\windows\system32\usbaaplrc.dll
2010-04-20 00:47 . 2009-04-10 22:25 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTSyncU.exe"="c:\program files\Creative\Sync Manager Unicode\CTSyncU.exe" [2006-06-12 700416]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2003-11-03 151597]
"StorageGuard"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-02-13 155648]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2003-08-27 204800]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-04-24 4616192]
"mswspl"="c:\program files\Dell AIO Printer A940\dlbabmgr.exe" [2003-02-17 86102]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-09-13 49152]
"FaxCenterServer"="c:\program files\Lexmark Fax Solutions\fm3032.exe" [2007-02-08 295856]
"DVDSentry"="c:\windows\System32\DSentry.exe" [2003-08-13 28672]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2003-08-06 114741]
"Dell AIO Printer A940"="c:\program files\Dell AIO Printer A940\dlbabmgr.exe" [2003-02-17 86102]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"mmtask"="c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe" [2004-07-01 53248]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-05-14 177472]
"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-12-12 642856]
"Motive SmartBridge"="c:\progra~1\VIRTUA~2\SMARTB~1\SprintDSLAlert.exe" [2010-01-07 483415]
"lxczbmgr.exe"="c:\program files\Lexmark 1200 Series\lxczbmgr.exe" [2007-02-08 74672]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-04-02 1180976]
"Malwarebytes Anti-Malware (rootkit-scan)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-19 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SWHelper"="c:\windows\system32\Macromed\Shockwave 8\PostUpdate.exe" [2010-06-24 53248]
c:\documents and settings\Bartholow\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2008-3-9 344064]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
America Online 9.0 Tray Icon.lnk - c:\program files\America Online 9.0\aoltray.exe [2003-11-3 36953]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2003-11-3 24576]
EMBARQ Help.lnk - c:\program files\Virtual Assistant\bin\matcli.exe [2009-10-9 217088]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-4 258048]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-4 53248]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\SYSTEM32\\lxczcoms.exe"=
"c:\\Program Files\\Common Files\\Mcafee\\McSvcHost\\McSvHost.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP:DHCP Discovery Service
R0 Lbd;Lbd;c:\windows\SYSTEM32\DRIVERS\Lbd.sys [8/8/2009 4:02 PM 64288]
R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\SYSTEM32\DRIVERS\mfetdi2k.sys [5/9/2010 3:51 PM 82952]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2/4/2010 11:52 AM 1352832]
R2 LinksysUpdater;Linksys Updater;c:\program files\Linksys\Linksys Updater\bin\LinksysUpdater.exe [11/13/2008 3:43 PM 204800]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [5/9/2010 3:51 PM 271480]
R2 McMPFSvc;McAfee Personal Firewall;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [5/9/2010 3:51 PM 271480]
R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [5/9/2010 3:51 PM 271480]
R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\Mcafee\SystemCore\mfefire.exe [5/9/2010 3:52 PM 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\Mcafee\SystemCore\mfevtps.exe [5/9/2010 3:51 PM 141792]
R3 cfwids;McAfee Inc. cfwids;c:\windows\SYSTEM32\DRIVERS\cfwids.sys [5/9/2010 3:51 PM 55456]
R3 mfefirek;McAfee Inc. mfefirek;c:\windows\SYSTEM32\DRIVERS\mfefirek.sys [5/9/2010 3:51 PM 312616]
R3 mfendiskmp;mfendiskmp;c:\windows\SYSTEM32\DRIVERS\mfendisk.sys [5/9/2010 3:51 PM 88480]
S3 jfdcd;jfdcd;\??\c:\docume~1\BARTHO~1\LOCALS~1\Temp\jfdcd.sys --> c:\docume~1\BARTHO~1\LOCALS~1\Temp\jfdcd.sys [?]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\SYSTEM32\DRIVERS\mfendisk.sys [5/9/2010 3:51 PM 88480]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\SYSTEM32\DRIVERS\mferkdet.sys [5/9/2010 3:51 PM 83496]
--- Other Services/Drivers In Memory ---
*Deregistered* - mfeavfk01
.
Contents of the 'Scheduled Tasks' folder
2010-07-18 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 14:54]
2010-07-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 16:34]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://myembarq.commSearch Bar =
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java -
file:///C:/WINDOWS/Java/classes/xmldso.cab.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Sonic RecordNow! - (no file)
HKLM-Run-MISAggregator - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-07-18 16:26
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-149151807-4052898740-1945230209-1008\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.* *'*U%\OpenWithList]
@Class="Shell"
[HKEY_USERS\S-1-5-21-149151807-4052898740-1945230209-1008\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*l*h%*%]
@Class="Shell"
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-149151807-4052898740-1945230209-1008\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*l*h%*%\OpenWithList]
@Class="Shell"
[HKEY_USERS\S-1-5-21-149151807-4052898740-1945230209-1008\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.* #ñ*ö*]
@Class="Shell"
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-149151807-4052898740-1945230209-1008\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.* #ñ*ö*\OpenWithList]
@Class="Shell"
[HKEY_USERS\S-1-5-21-149151807-4052898740-1945230209-1008\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:a5,ea,e9,7f,00,9d,0d,a9,d4,1f,69,a6,f4,f1,04,ae,12,74,5a,4d,8f,e5,24,
c5,b8,f0,b2,fa,31,a2,5e,b3,d2,41,f8,ea,25,14,0a,04,4b,8d,ed,65,e8,a3,28,3c,\
"??"=hex:b5,60,ab,13,74,34,3d,76,40,37,43,7c,29,c5,f8,80
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1A68D668-6DF3-702D-2A0852A803C1488D}\{D6F2E9CD-48BA-CDDC-BEA31B576464FCAF}\{421B9E29-5D23-2966-C9D7C1E976BC0884}*]
"PK3IM51V2WPW5YOPIRJ365XEIG1"=hex:01,00,01,00,00,00,00,00,c3,a2,73,89,0b,39,ad,
69,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{48418982-249C-E344-B1C048196FA2EDFD}\{A41EB0B4-3EE0-E472-B7C2AAEB5A9566C4}\{DB4C8A45-FEFF-6FD9-65B4662880A15182}*]
"{3EE4C831-B7E0-4ed1-B9FC-EDC523C9612F}1"=hex:01,00,01,00,0c,00,00,00,1f,f1,4a,
51,1c,86,65,14,87,4c,de,40,12,89,ab,80,31,7e,9a,ab,57,11,78,f9,46,20,33,3d,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1056)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(5692)
c:\windows\system32\WININET.dll
c:\progra~1\VIRTUA~2\SMARTB~1\SBHook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\Ati2evxx.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\progra~1\COMMON~1\AOL\ACS\acsd.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\System32\CTsvcCDA.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\lxczcoms.exe
c:\windows\system32\java.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\Motive\McciCMService.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\System32\PnkBstrA.exe
c:\windows\wanmpsvc.exe
c:\program files\Common Files\McAfee\SystemCore\mcshield.exe
c:\program files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
c:\program files\Dell AIO Printer A940\dlbabmon.exe
c:\program files\Lexmark 1200 Series\lxczbmon.exe
c:\program files\Virtual Assistant\bin\mpbtn.exe
c:\program files\HP\Digital Imaging\bin\hpqgalry.exe
c:\windows\System32\wbem\unsecapp.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2010-07-18 16:44:56 - machine was rebooted
ComboFix-quarantined-files.txt 2010-07-18 20:44
Pre-Run: 8,743,096,320 bytes free
Post-Run: 9,807,826,944 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
- - End Of File - - 371C83C91E8DB254226145344893F4AA