Thanks for all your help. Here's the file:
ComboFix 09-10-25.01 - HarveyB 10/25/2009 20:07.5.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2037.1552 [GMT -4:00]
Running from: c:\documents and settings\HarveyB\My Documents\Combo-Fix.exe
Command switches used :: c:\documents and settings\HarveyB\My Documents\CFScript.txt
AV: McAfee VirusScan *On-access scanning disabled* (Outdated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
--------------- FCopy ---------------
c:\windows\ServicePackFiles\i386\eventlog.dll --> c:\windows\System32\eventlog.dll
.
((((((((((((((((((((((((( Files Created from 2009-09-26 to 2009-10-26 )))))))))))))))))))))))))))))))
.
2009-10-25 23:59 . 2008-04-14 00:11 56320 ----a-w- c:\windows\system32\eventlog.dll
2009-10-25 23:59 . 2008-04-14 00:11 56320 ----a-w- c:\windows\system32\dllcache\eventlog.dll
2009-10-25 23:58 . 2009-10-26 00:03 -------- d-----w- C:\Combo-Fix
2009-10-22 15:15 . 2009-10-22 15:15 -------- d-----w- c:\documents and settings\All Users\Application Data\LightScribe
2009-10-15 02:15 . 2009-10-15 02:15 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-10-11 03:23 . 2009-10-11 03:23 -------- d-----w- c:\documents and settings\HarveyB\Application Data\Malwarebytes
2009-10-11 03:23 . 2009-09-10 18:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-11 03:23 . 2009-10-11 03:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-10-11 03:23 . 2009-09-10 18:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-11 03:23 . 2009-10-11 03:23 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-11 00:29 . 2009-07-08 17:44 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-10-11 00:29 . 2009-07-08 17:44 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-10-11 00:29 . 2009-07-08 17:44 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-10-11 00:28 . 2009-07-16 16:32 120136 ----a-w- c:\windows\system32\drivers\Mpfp.sys
2009-10-11 00:28 . 2009-10-11 00:28 -------- d-----w- c:\program files\Common Files\McAfee
2009-10-11 00:28 . 2009-10-11 00:28 -------- d-----w- c:\program files\McAfee.com
2009-10-11 00:27 . 2009-10-25 22:20 -------- d-----w- c:\program files\McAfee
2009-10-11 00:23 . 2009-07-08 17:43 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys
2009-10-11 00:15 . 2009-10-11 03:36 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-09-27 02:19 . 2009-10-09 02:19 -------- d-----w- c:\documents and settings\HarveyB\Local Settings\Application Data\Temp
2009-09-27 02:00 . 2009-09-27 02:00 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2009-09-27 01:58 . 2009-04-03 15:18 130936 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-09-27 01:58 . 2008-12-18 16:16 73840 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-09-27 01:58 . 2008-12-10 15:36 64392 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2009-09-27 01:57 . 2009-09-27 01:57 -------- d-----w- c:\documents and settings\HarveyB\Application Data\PC Tools
2009-09-27 01:57 . 2009-09-27 01:57 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2009-09-27 01:56 . 2009-09-27 01:56 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-09-27 01:55 . 2009-10-11 03:08 -------- d-----w- c:\program files\Google
2009-09-27 01:38 . 2009-10-18 23:10 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-09-27 01:38 . 2009-09-27 02:00 -------- d-----w- c:\program files\Common Files\PC Tools
2009-09-27 01:38 . 2009-10-16 07:36 -------- d-----w- c:\program files\Spyware Doctor
2009-09-27 01:35 . 2009-09-27 01:35 -------- d-----w- c:\program files\Trend Micro
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-15 14:53 . 2009-01-19 14:38 -------- d-----w- c:\program files\Brother's Keeper 6
2009-09-27 02:03 . 2009-03-08 20:27 -------- d-----w- c:\program files\Lavasoft
2009-09-27 02:03 . 2009-03-08 20:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-09-11 19:52 . 2008-04-30 23:23 54968 ----a-w- c:\documents and settings\John\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-11 14:18 . 2004-08-10 16:51 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-06 03:53 . 2009-09-06 03:53 129 ----a-w- c:\documents and settings\Maggie\Local Settings\Application Data\fusioncache.dat
2009-09-06 03:53 . 2008-05-12 22:15 54968 ----a-w- c:\documents and settings\Maggie\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-06 02:08 . 2009-09-06 01:28 272 ----a-w- c:\documents and settings\John\Application Data\wklnhst.dat
2009-09-06 01:28 . 2009-09-06 01:28 -------- d-----w- c:\documents and settings\John\Application Data\Template
2009-09-04 21:03 . 2004-08-10 16:51 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 08:08 . 2004-08-10 16:51 916480 ------w- c:\windows\system32\wininet.dll
2009-08-26 08:00 . 2004-08-10 16:51 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-09 11:58 . 2008-04-26 21:00 54968 ----a-w- c:\documents and settings\HarveyB\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-05 09:01 . 2004-08-10 16:51 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 23:52 . 2009-08-04 23:52 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-04 15:13 . 2004-08-10 16:51 2145280 ------w- c:\windows\system32\ntoskrnl.exe
2009-08-04 14:20 . 2004-08-04 02:59 2023936 ------w- c:\windows\system32\ntkrnlpa.exe
.
(((((((((((((((((((((((((((((
SnapShot@2009-10-19_01.02.17 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-04-26 20:55 . 2009-10-25 22:21 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-04-26 20:55 . 2009-10-18 23:01 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-04-26 20:55 . 2009-10-25 22:21 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-04-26 20:55 . 2009-10-18 23:01 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-02-25 2387968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-07-16 142104]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-07-16 162584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-07-16 138008]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2007-09-17 124200]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb06.exe" [2002-06-04 188416]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-09-17 645328]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2007-07-16 16132608]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ \0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Audible Download Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Audible Download Manager.lnk
backup=c:\windows\pss\Audible Download Manager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"helpsvc"=2 (0x2)
"gusvc"=3 (0x3)
"gupdate1ca3f15c46a0128"=2 (0x2)
"AOL ACS"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\1213228256\\ee\\aolsoftware.exe"=
"c:\\Program Files\\AOL 9.1\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\McAfee\\MBK\\McAfeeDataBackup.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [9/26/2009 9:58 PM 130936]
R2 IntuitUpdateService;Intuit Update Service;c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe [10/10/2008 6:45 AM 13088]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;"c:\program files\Lavasoft\Ad-Aware\AAWService.exe" --> c:\program files\Lavasoft\Ad-Aware\AAWService.exe [?]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [9/26/2009 9:57 PM 348752]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - MBR
*Deregistered* - mbr
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
2009-10-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2009-10-11 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-11 16:22]
2009-10-11 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-11 16:22]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.aol.com/IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Crawler Search - tbr:iemenu
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\HarveyB\Application Data\Mozilla\Firefox\Profiles\9ewi5swf.default\
FF - prefs.js: browser.search.selectedEngine - Creative Commons
FF - prefs.js: browser.startup.homepage -
hxxp://www.aol.comFF - prefs.js: keyword.URL -
hxxp://toolbar.inbox.com/search/dispatcher.aspx?tp=sf&tmpl=1&qkw=FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF - plugin: c:\program files\Java\jre1.5.0_06\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - hȋdden: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-25 20:10
Windows 5.1.2600 Service Pack 3 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
scan completed successfully
hȋdden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(704)
c:\windows\system32\igfxdev.dll
- - - - - - - > 'explorer.exe'(2800)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-10-26 20:11
ComboFix-quarantined-files.txt 2009-10-26 00:11
ComboFix2.txt 2009-10-25 22:41
ComboFix3.txt 2009-10-19 01:03
Pre-Run: 301,946,499,072 bytes free
Post-Run: 301,936,365,568 bytes free
- - End Of File - - AB29D322295B7BCE22990BAB2259F3A1