Hi! Thank you so much for your help. I did not end up running CCleaner. Here is the log from Combofix. I will run TDSSKiller shortly and post any logfiles from that. Thanks again for your help. Oh, do you know of Clamvirus? Is it something that I need or is it safe to uninstall? Thanks!
ComboFix 11-07-11.02 - User 07/11/2011 10:26:25.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.407 [GMT -4:00]
Running from: c:\documents and settings\User\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Play Pickle\plAYpicklelib32.dll
c:\program files\Play Pickle\ppTL.dll
.
.
((((((((((((((((((((((((( Files Created from 2011-06-11 to 2011-07-11 )))))))))))))))))))))))))))))))
.
.
2011-07-07 14:43 . 2011-07-07 14:43 -------- d-sh--w- c:\documents and settings\User\IECompatCache
2011-07-04 16:06 . 2011-07-04 16:06 -------- d-----w- c:\program files\Common Files\Real
2011-07-04 16:02 . 2002-11-12 16:22 569397 ----a-w- c:\program files\Internet Explorer\PLUGINS\RichFX\Player\nprfxins.dll
2011-07-04 16:02 . 2011-07-04 16:06 -------- d-----w- c:\program files\Rhapsody
2011-07-01 23:17 . 2011-07-04 04:32 -------- d-----w- c:\documents and settings\User\Application Data\vlc
2011-06-26 22:45 . 2011-06-26 22:45 -------- d-----w- c:\documents and settings\User\Application Data\Wave Systems Corp
2011-06-26 17:26 . 2011-06-26 17:26 -------- d-----w- c:\documents and settings\User\Application Data\Unity
2011-06-26 12:32 . 2011-06-26 12:32 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\Unity
2011-06-24 23:32 . 2011-06-24 23:32 -------- d-----w- c:\program files\Common Files\Adobe
2011-06-24 23:29 . 2011-06-24 23:29 -------- d-----w- c:\program files\Common Files\Adobe AIR
2011-06-24 23:29 . 2011-06-24 23:38 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\Adobe
2011-06-24 17:08 . 2011-06-24 23:38 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\Temp
2011-06-24 16:20 . 2011-06-24 16:20 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2011-06-24 14:03 . 2011-06-24 14:03 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2011-06-24 14:03 . 2011-06-24 23:18 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\Google
2011-06-24 14:03 . 2011-06-26 22:52 -------- d-----w- c:\program files\Google
2011-06-24 14:02 . 2011-06-24 14:10 -------- d-----w- c:\windows\system32\Adobe
2011-06-23 20:19 . 2011-06-25 00:07 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\AskToolbar
2011-06-23 20:19 . 2011-06-23 20:20 -------- d-----w- c:\program files\Ask.com
2011-06-23 20:19 . 2011-06-23 20:19 -------- d-----w- C:\Firefox
2011-06-23 20:18 . 2011-06-23 20:18 -------- d-----w- c:\program files\The Weather Channel FW
2011-06-23 20:18 . 2011-06-23 20:18 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\The Weather Channel
2011-06-23 20:17 . 2011-07-11 14:28 -------- d-----w- c:\program files\Play Pickle
2011-06-19 17:22 . 2011-06-19 17:22 -------- d-----w- c:\program files\Microsoft Encarta
2011-06-19 17:20 . 2011-06-19 17:21 -------- d-----w- c:\program files\Microsoft Picture It! 2002
2011-06-19 17:16 . 2011-06-19 17:19 -------- d-----w- c:\program files\Microsoft Streets & Trips
2011-06-19 17:14 . 2011-06-19 17:16 -------- d-----w- c:\program files\Microsoft Money
2011-06-19 17:12 . 2011-06-19 17:12 -------- d-----w- c:\program files\Microsoft ActiveSync
2011-06-19 17:12 . 2011-06-19 17:12 -------- d-----w- c:\windows\ShellNew
2011-06-19 17:11 . 2011-06-19 17:13 -------- d-----w- c:\program files\Microsoft Works
2011-06-19 17:10 . 2011-06-19 17:10 -------- d-----w- c:\program files\Microsoft Works Suite 2002
2011-06-17 23:04 . 2011-06-17 23:04 -------- d-----w- c:\documents and settings\All Users\Application Data\WEBREG
2011-06-17 23:03 . 2011-06-17 23:03 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\HP
2011-06-17 23:02 . 2011-06-17 23:05 -------- d-----w- c:\documents and settings\User\Application Data\HP
2011-06-17 23:02 . 2009-04-16 18:08 123904 ----a-w- c:\windows\system32\hpf3l70v.dll
2011-06-17 23:02 . 2009-04-16 18:08 312832 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\hpfpp70v.dll
2011-06-17 22:58 . 2011-06-17 23:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2011-06-17 22:58 . 2011-06-17 22:58 -------- d-----w- c:\documents and settings\User\Application Data\Yahoo!
2011-06-17 22:58 . 2011-06-17 22:58 -------- d-----w- c:\program files\Yahoo!
2011-06-17 22:58 . 2011-06-17 22:58 -------- d-----w- c:\windows\Cache
2011-06-17 22:58 . 2011-06-17 22:58 -------- d-----w- c:\program files\Coupons
2011-06-17 22:58 . 2011-06-17 22:58 -------- d-----w- c:\program files\HP Photo Creations
2011-06-17 22:58 . 2011-06-17 22:58 -------- d-----w- c:\documents and settings\All Users\Application Data\HP Photo Creations
2011-06-17 22:58 . 2011-07-03 02:33 -------- d-----w- c:\documents and settings\User\Application Data\HpUpdate
2011-06-17 22:57 . 2011-06-17 22:57 -------- d-----w- c:\documents and settings\All Users\Application Data\HP Product Assistant
2011-06-17 22:55 . 2011-06-17 23:03 -------- d-----w- c:\program files\HP
2011-06-17 20:56 . 2011-06-17 20:56 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\Identities
2011-06-12 18:25 . 2011-06-12 18:25 -------- d-----w- c:\documents and settings\User\Application Data\OpenOffice.org
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-25 11:36 . 2009-11-05 12:53 385024 ----a-w- c:\windows\system32\html.iec
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2009-11-05 . 600D58665D16BFBB776EFEFB0E80532D . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-05-17 1490312]
.
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2011-05-17 17:29 1490312 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-05-17 1490312]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-05-17 1490312]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-10-11 14940040]
"DW6"="c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe" [2010-06-04 822384]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-03 7630848]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2009-11-18 54576]
"WorksFUD"="c:\program files\Microsoft Works\wkfud.exe" [2001-10-06 24576]
"Microsoft Works Portfolio"="c:\program files\Microsoft Works\WksSb.exe" [2001-08-23 331830]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2001-08-17 28738]
"MoneyStartUp10.0"="c:\program files\Microsoft Money\System\Activation.exe" [2001-07-25 241714]
"Play Pickle"="c:\program files\Play Pickle\playpickle32.exe" [2011-06-23 109056]
"ApnUpdater"="c:\program files\Ask.com\Updater\Updater.exe" [2011-05-17 395144]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]
"IE8"="advpack.dll" [2009-11-05 128512]
.
c:\documents and settings\User\Start Menu\Programs\Startup\
OpenOffice.org 3.2.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-12-15 384000]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-11-18 275072]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Microsoft Works Calendar Reminders.lnk - c:\program files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2001-8-7 24633]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ClamWin]
2010-04-14 00:14 86016 ----a-w- c:\program files\ClamWin\bin\ClamTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 11:00 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 14:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2006-10-03 18:07 7630848 ----a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2006-10-03 18:07 86016 ----a-w- c:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2006-10-03 18:07 1617920 ----a-w- c:\windows\system32\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
2006-07-27 18:19 282624 ----a-w- c:\windows\stsystra.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 16:44 248552 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfcCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgh.exe"=
"c:\\Program Files\\HP\\HP Software Update\\hpwucli.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\smart web printing\\SmartWebPrintExe.exe"=
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-07-11 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2011-05-17 17:29]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://aol.com/
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.11.1
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, https://www.gmer.net
Rootkit scan 2011-07-11 10:30
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(2340)
c:\windows\system32\WININET.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\IEFRAME.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Wave Systems Corp\Common\DataServer.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\NTRU Cryptosystems\NTRU Hybrid TSS v2.0.25\bin\tcsd_win32.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\windows\system32\wscntfy.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
.
**************************************************************************
.
Completion time: 2011-07-11 10:32:17 - machine was rebooted
ComboFix-quarantined-files.txt 2011-07-11 14:32
.
Pre-Run: 630,148,403,200 bytes free
Post-Run: 630,859,644,928 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 2F2DDD783EAF875BDD9790C8EF9FECE1