hi, thanks for all your help. here is the report: ComboFix 09-08-10.02 - XP PRO 08/10/2009 23:46.5.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.511.144 [GMT -4:00]
Running from: c:\documents and settings\XP PRO\Desktop\Combo-Fix.exe
AV: *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
Infected copy of c:\windows\system32\netlogon.dll was found and disinfected
Restored copy from - c:\windows\system32\ntelogon.dll
c:\windows\system32\proquota.exe . . . is missing!!
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
((((((((((((((((((((((((( Files Created from 2009-07-11 to 2009-08-11 )))))))))))))))))))))))))))))))
.
2009-08-11 04:10 . 2009-08-11 04:10 -------- d-----w- c:\windows\system32\xircom
2009-08-11 04:10 . 2009-08-11 04:10 -------- d-----w- c:\windows\system32\wbem\snmp
2009-08-11 04:10 . 2009-08-11 04:10 -------- d-----w- c:\program files\microsoft frontpage
2009-08-11 03:55 . 2004-08-04 05:56 407040 ----a-w- c:\windows\system32\netlogon.dll
2009-08-10 11:00 . 2009-08-10 11:00 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-08-10 10:56 . 2009-08-10 10:58 -------- d-----w- c:\documents and settings\XP PRO\Application Data\McAfee.com Personal Firewall
2009-08-10 05:20 . 2009-08-10 05:20 -------- d-----w- c:\documents and settings\LocalService\Application Data\McAfee.com Personal Firewall
2009-08-10 05:12 . 2009-08-11 03:39 -------- d-----w- c:\program files\McAfee
2009-08-10 05:10 . 2009-08-10 10:57 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee.com Personal Firewall
2009-08-10 04:26 . 2009-08-03 17:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-10 04:26 . 2009-08-10 04:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-10 04:26 . 2009-08-03 17:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-07 03:58 . 2009-08-07 03:58 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-08-06 23:45 . 2009-08-06 23:45 -------- d-sh--w- c:\documents and settings\XP PRO\PrivacIE
2009-08-06 23:43 . 2009-08-06 23:43 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-08-06 23:41 . 2009-08-06 23:41 -------- d-sh--w- c:\documents and settings\XP PRO\IETldCache
2009-08-06 23:26 . 2009-08-06 23:30 -------- dc-h--w- c:\windows\ie8
2009-08-01 23:53 . 2009-08-01 23:52 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-07-24 02:55 . 2009-08-01 12:14 0 ----a-w- c:\windows\system32\drivers\f5f3e641.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-11 03:36 . 2007-08-02 22:18 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee.com
2009-08-11 03:35 . 2007-08-02 22:19 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-08-06 03:46 . 2007-03-06 02:14 616760 ----a-w- c:\documents and settings\XP PRO\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-01 23:52 . 2007-03-06 02:18 -------- d-----w- c:\program files\Java
2009-07-03 01:14 . 2009-07-03 01:14 -------- d-----w- c:\documents and settings\XP PRO\Application Data\Malwarebytes
2009-07-03 01:14 . 2009-07-03 01:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-01 12:01 . 2008-10-18 18:26 -------- d-----w- c:\documents and settings\LocalService\Application Data\SACore
2009-06-28 07:17 . 2007-03-06 02:18 -------- d-----w- c:\program files\LimeWire
2009-06-26 04:15 . 2009-06-26 04:10 -------- d-----w- c:\documents and settings\XP PRO\Application Data\Move Networks
2009-06-26 04:12 . 2009-06-26 04:10 34062 ----a-w- c:\documents and settings\XP PRO\Application Data\Move Networks\ie_bin\Uninst.exe
2009-06-26 04:12 . 2009-06-26 04:12 1047224 ----a-w- c:\documents and settings\XP PRO\Application Data\Move Networks\MoveMediaPlayer_071303000005.exe
2009-06-17 09:07 . 2009-04-06 03:17 -------- d-----w- c:\documents and settings\XP PRO\Application Data\Skype
2009-06-16 14:45 . 2006-10-21 08:35 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:45 . 2004-08-04 05:56 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-03 19:24 . 2006-09-26 09:26 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-01-01 18:33 . 2007-03-06 02:23 67688 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2009-01-01 18:33 . 2007-03-06 02:23 54368 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2009-01-01 18:33 . 2007-03-06 02:23 34944 ----a-w- c:\program files\mozilla firefox\components\myspell.dll
2009-01-01 18:34 . 2007-03-06 02:23 46712 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll
2009-01-01 18:34 . 2007-03-06 02:23 172136 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.
------- Sigcheck -------
[-] 2008-04-14 00:12 1614848 9DD07AF82244867CA36681EA2D29CE79 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\sfcfiles.dll
[-] 2006-10-21 08:43 1580544 6BE24F6A7B6B8F45D0A9A168794D36CE c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"STYLEXP"="c:\program files\TGTSoft\StyleXP\StyleXP.exe" [2006-04-04 1368064]
"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2005-06-08 196608]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-07-15 1961984]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-03-27 24103720]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Shockwave Updater"="c:\windows\system32\Adobe\Shockwave 11\SwHelper_1150596.exe" [2009-04-29 468408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-01 148888]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-10-18 802816]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-10-18 696320]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2005-10-07 176128]
"SetDefPrt"="c:\program files\Brother\Brmfl04a\BrStDvPt.exe" [2004-05-25 49152]
"ControlCenter2.0"="c:\program files\Brother\ControlCenter2\brctrcen.exe" [2004-07-20 851968]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-07-19 221184]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-06-08 458752]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nlsf"="move" [X]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-04 44544]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-606747145-776561741-725345543-1003\Scripts\Logoff\0\0]
"Script"=c:\program files\Privacy Shield\xp.cmd
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\InterVideo\\DVD7\\WinDVD.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 NwSapAgent;SAP Agent;c:\windows\system32\svchost.exe -k netsvcs [8/4/2004 1:56 AM 14336]
R2 PDSched;PDScheduler;c:\program files\Raxco\PerfectDisk\PDSched.exe [11/29/2005 12:16 PM 241731]
S1 f5f3e641;f5f3e641;c:\windows\system32\drivers\f5f3e641.sys [7/23/2009 10:55 PM 0]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-07-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2009-08-11 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-05-12 02:18]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Globe7 - c:\program files\Globe7\Globe7.exe
Notify-NavLogon - (no file)
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.yahoo.com/mSearch Bar =
hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.htmluSearchURL,(Default) =
hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.comIE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspxIE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\XP PRO\Application Data\Mozilla\Firefox\Profiles\pqe8343d.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://search.yahoo.com/search?fr=ffsp1&p=FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage -
hxxp://www.yahoo.com/FF - prefs.js: keyword.URL -
hxxp://search.yahoo.com/search?fr=ffds1&p=FF - component: c:\progra~1\MOZILL~1\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-08-11 00:12
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(884)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(2880)
c:\windows\system32\browselc.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\TGTSoft\StyleXP\StyleXPService.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\WLKEEPER.exe
c:\windows\system32\brss01a.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\Brmfrmps.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\ati2evxx.exe
c:\windows\system32\WgaTray.exe
c:\program files\Apoint\hidfind.exe
c:\program files\Logitech\Video\FxSvr2.exe
c:\program files\Apoint\ApntEx.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Intel\Wireless\Bin\Dot1XCfg.exe
.
**************************************************************************
.
Completion time: 2009-08-11 0:22 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-11 04:22
Pre-Run: 31,557,406,720 bytes free
Post-Run: 31,448,072,192 bytes free
204 --- E O F --- 2009-08-06 23:32