Dear Guestolo,
Thank you for all of your help and for bumping the topic. I'm sorry that I could not get you this log sooner. I unchecked word wrap and here is the combofix log. Please let me know if i should do anything more.
Thanks Again,
Tracy
ComboFix 09-05-16.05 - Ben 05/16/2009 19:48.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.511.258 [GMT -4:00]
Running from: c:\documents and settings\Ben\Desktop\ComboFix.exe
AV: Bitdefender Antivirus *On-access scanning enabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Ben\Application Data\digifast
c:\documents and settings\Ben\Application Data\digifast\config.cfg
c:\documents and settings\Ben\Application Data\digifast\DFUninstall.exe
c:\documents and settings\Ben\Application Data\digifast\digifast.exe
c:\documents and settings\Ben\Application Data\twain\Twain.exe
c:\documents and settings\Ben\Local Settings\Temporary Internet Files\bestwiner.stt
c:\documents and settings\Ben\Local Settings\Temporary Internet Files\CPV.stt
c:\documents and settings\Ben\Local Settings\Temporary Internet Files\fbk.sts
c:\documents and settings\Ben\Start Menu\Antivirus2008
c:\documents and settings\Ben\Start Menu\Antivirus2008\Antivirus 2008.lnk
c:\documents and settings\Ben\Start Menu\Antivirus2008\Uninstall Antivirus.lnk
c:\program files\Common\helper.sig
c:\program files\INSTALL.LOG
c:\program files\Jcore
c:\program files\Jcore\Jcore2.dll
c:\program files\WWShow
c:\program files\WWShow\WWShow.dll
c:\windows\system32\_000000_.tmp.dll
c:\windows\system32\_000001_.tmp.dll
c:\windows\system32\ahtn.htm
c:\windows\system32\drivers\ovfsthmybwwykoiohlgknswabvpwcqpxuruxfi.sys
c:\windows\system32\egenitaj.ini
c:\windows\system32\frmwrk32.exe
c:\windows\system32\loader49.exe
c:\windows\system32\ntdll64.exe
c:\windows\system32\ovfsthcejtplbxxlajteyobntbhsppuxpagyme.dat
c:\windows\system32\ovfstherdabqnrlglxwxaiiaewfwuapbfnweyo.dll
c:\windows\system32\ovfsthielrisilslnfpoqdabqugtfnrtjlrnkx.dll
c:\windows\system32\ovfsthnufnwjkylxcxpttabpeywuklkievppci.dat
c:\windows\system32\ovfsthrirfqjwsgvvkouxpbxholwmklgjgbmma.dll
c:\windows\system32\prnet.tmp
c:\windows\system32\uniq.tll
c:\windows\system32\warning.gif
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_ovfsthnspdixlthemxbqbdmecbvdeuaoqvdbqv
((((((((((((((((((((((((( Files Created from 2009-04-16 to 2009-05-16 )))))))))))))))))))))))))))))))
.
2009-10-13 21:43 . 2008-12-13 22:46 -------- d-----w c:\program files\Common Files\Softwin
2009-10-13 20:36 . 2009-10-13 20:36 -------- d-----w c:\documents and settings\All Users\Application Data\Avg8
2009-05-13 04:51 . 2009-05-16 23:49 -------- d-----w c:\documents and settings\Ben\Application Data\Twain
2009-05-13 04:42 . 2009-05-13 04:43 -------- d-----w c:\program files\Trend Micro
2009-05-13 03:17 . 2009-05-13 03:17 -------- d-----w c:\documents and settings\Ben\.housecall6.6
2009-05-12 05:05 . 2009-05-12 05:05 -------- d-----w c:\windows\system32\config\systemprofile\Local Settings\Application Data\Google
2009-05-12 04:34 . 2009-05-12 04:50 -------- d-----w c:\documents and settings\Ben\Application Data\ptidle
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-13 20:20 . 2003-12-27 22:07 -------- d-----w c:\program files\Common Files\Symantec Shared
2009-10-13 20:10 . 2007-08-25 03:43 -------- d-----w c:\program files\Symantec AntiVirus
2009-05-16 23:50 . 2008-12-13 22:52 81984 ----a-w c:\windows\system32\bdod.bin
2009-05-16 23:48 . 2009-04-06 00:07 -------- d-----w c:\program files\Common
2009-03-06 14:44 . 2003-03-31 12:00 283648 ----a-w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2004-02-06 22:05 826368 ----a-w c:\windows\system32\wininet.dll
2009-02-20 18:09 . 2004-08-04 07:56 78336 ----a-w c:\windows\system32\ieencode.dll
2006-07-23 18:18 . 2006-07-23 18:18 388008 -c--a-w c:\program files\essetup.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AFD4AD01-58C1-47DB-A404-FBE00A6C5486}]
2009-05-07 17:48 294924 ----a-w c:\program files\Common\_helper.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2006-10-13 20058152]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-15 68856]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"ptidle"="c:\documents and settings\Ben\Application Data\ptidle\ptidle.exe" [2009-05-12 56832]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2003-05-29 790528]
"IMONTRAY"="c:\program files\Intel\Intel® Active Monitor\imontray.exe" [2003-01-10 32768]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-06-27 4640768]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"IPInSightLAN 01"="c:\program files\Visual Networks\Visual IP InSight\Sympatico Consumer\IPClient.exe" [2002-04-20 364544]
"IPInSightMonitor 01"="c:\program files\Visual Networks\Visual IP InSight\Sympatico Consumer\IPMon32.exe" [2002-04-20 102400]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-02-09 77824]
"BDAgent"="c:\program files\Softwin\BitDefender10\bdagent.exe" [2007-03-26 69632]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2003-06-27 323584]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"HideClock"= 0 (0x0)
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak software updater.lnk
backup=c:\windows\pss\Kodak software updater.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
R3 PRISM_ICB;SMC2802W 2.4GHz 54Mbps Wireless PCI Card;c:\windows\system32\drivers\smc2802w.sys [8/31/2005 7:35 PM 56512]
--- Other Services/Drivers In Memory ---
*Deregistered* - IPVNMon
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
BHO-{15421B84-3488-49A7-AD18-CBF84A3EFAF6} - c:\program files\WWShow\WWShow.dll
BHO-{9d6d6365-e5b2-4739-bc14-ec914d7d5b94} - c:\windows\system32\wozovare.dll
BHO-{D88E1558-7C2D-407A-953A-C044F5607CEA} - c:\program files\Jcore\Jcore2.dll
HKCU-Run-msnmsgr - c:\progra~1\MSNMES~1\msnmsgr.exe
HKCU-Run-DigiFast - c:\documents and settings\Ben\Application Data\digifast\digifast.exe
HKLM-Run-Symantec NetDriver Monitor - c:\progra~1\SYMNET~1\SNDMon.exe
HKLM-Run-hutevawajo - c:\windows\system32\batuviko.dll
HKLM-Run-4c228dfa - c:\windows\system32\jatinege.dll
HKLM-Run-CPM4f11be66 - c:\windows\system32\zatisiwi.dll
SharedTaskScheduler-{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\zatisiwi.dll
Notify-NavLogon - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.gmail.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = 127.0.0.1
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cab.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-05-16 19:52
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\program files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
c:\program files\Intel\Intel® Active Monitor\imonNT.exe
c:\program files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
c:\program files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
c:\program files\Softwin\BitDefender10\vsserv.exe
c:\windows\system32\dwwin.exe
.
**************************************************************************
.
Completion time: 2009-05-16 19:54 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-16 23:54
Pre-Run: 32,008,552,448 bytes free
Post-Run: 32,560,644,096 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
173 --- E O F --- 2009-05-12 04:24