I began Combofix before I found the forum. I just looked at a forum of a similar issue, hoping that it would solve the problem. Guess I'll leave it to the knowledgeable next time.
Here's the combofix log:
ComboFix 09-10-30.01 - Administrator 10/31/2009 16:23.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1178 [GMT -4:00]
Running from: c:\documents and settings\Administrator.OUR-43318166B08\Desktop\ComboFix.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
FW: Sunbelt Personal Firewall *enabled* {82B1150E-9B37-49FC-83EB-D52197D900D0}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Mozilla Firefox\extensions\{821A3F2B-49DF-4213-8F11-4DFA91DB2DBF}
c:\program files\Mozilla Firefox\extensions\{821A3F2B-49DF-4213-8F11-4DFA91DB2DBF}\chrome.manifest
c:\program files\Mozilla Firefox\extensions\{821A3F2B-49DF-4213-8F11-4DFA91DB2DBF}\chrome\content\overlay.xul
c:\program files\Mozilla Firefox\extensions\{821A3F2B-49DF-4213-8F11-4DFA91DB2DBF}\install.rdf
c:\recycler\S-1-5-21-796845957-884357618-839522115-1003
c:\recycler\S-1-5-21-796845957-884357618-839522115-1004
c:\windows\System32\BSTIeprintctl1.dll
c:\windows\system32\ctfmon .exe
c:\windows\system32\hkcmd .exe
c:\windows\system32\igfxpers .exe
c:\windows\system32\igfxtray .exe
c:\windows\system32\inf
J:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-09-28 to 2009-10-31 )))))))))))))))))))))))))))))))
.
2009-10-31 19:47 . 2009-10-31 19:47 -------- d-----w- c:\program files\Trend Micro
2009-10-26 07:08 . 2009-10-26 07:08 -------- d-----w- c:\program files\Microsoft Works
2009-10-26 07:04 . 2009-10-26 07:04 -------- d-----w- c:\documents and settings\Default User.WINDOWS\Local Settings\Application Data\Microsoft Help
2009-10-25 02:06 . 2009-10-25 02:06 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\IObit
2009-10-25 02:06 . 2009-10-25 02:06 -------- d-----w- c:\program files\IObit
2009-10-19 03:36 . 2009-10-19 03:36 -------- d-----w- c:\program files\Dearborn
2009-10-18 03:08 . 2008-06-21 08:54 65576 ----a-w- c:\windows\system32\drivers\SbFwIm.sys
2009-10-18 03:08 . 2008-10-31 11:09 270888 ----a-r- c:\windows\system32\drivers\SbFw.sys
2009-10-18 03:08 . 2009-10-18 03:08 -------- d-----w- c:\program files\Sunbelt Software
2009-10-18 02:58 . 2009-10-18 02:58 -------- d-----w- c:\documents and settings\Administrator.OUR-43318166B08\Application Data\Malwarebytes
2009-10-18 02:58 . 2009-09-10 18:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-18 02:58 . 2009-10-18 03:27 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-18 02:58 . 2009-10-18 02:58 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2009-10-18 02:58 . 2009-09-10 18:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-05 19:00 . 2009-10-05 19:00 -------- d-sh--w- c:\documents and settings\NetworkService.NT AUTHORITY\IETldCache
2009-10-05 19:00 . 2009-10-05 19:00 -------- d-----w- c:\documents and settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Apple
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-31 20:15 . 2006-04-11 22:00 -------- d-----w- c:\program files\Symantec AntiVirus
2009-10-31 15:59 . 2006-05-24 22:02 -------- d-----w- c:\program files\Common Files\Adobe
2009-10-30 05:26 . 2009-10-16 07:15 4904 ----a-w- c:\windows\system32\PerfStringBackup.TMP
2009-10-27 07:09 . 2009-08-18 13:04 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft Help
2009-10-26 12:38 . 2009-06-18 04:46 69232 ----a-w- c:\documents and settings\Administrator.OUR-43318166B08\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-19 03:36 . 2006-04-11 21:18 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-18 07:32 . 2009-01-04 05:05 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-10-15 22:21 . 2009-07-12 06:11 -------- d-----w- c:\documents and settings\Administrator.OUR-43318166B08\Application Data\vlc
2009-10-08 04:28 . 2009-10-01 03:55 -------- d-----w- c:\documents and settings\Administrator.OUR-43318166B08\Application Data\Move Networks
2009-09-21 00:07 . 2009-09-21 00:07 -------- d-----w- c:\documents and settings\Administrator.OUR-43318166B08\Application Data\MathWorks
2009-09-18 12:35 . 2009-08-15 15:09 -------- d-----w- c:\documents and settings\Administrator.OUR-43318166B08\Application Data\Apple Computer
2009-09-11 14:18 . 2004-08-04 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:03 . 2004-08-04 12:00 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 08:08 . 2004-08-04 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-26 08:00 . 2004-08-04 12:00 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-18 03:33 . 2009-08-18 03:33 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-06 23:24 . 2009-06-18 03:15 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-06 23:24 . 2009-06-18 03:15 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-06 23:24 . 2009-06-18 03:14 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-06 23:24 . 2008-10-16 18:09 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-06 23:24 . 2009-06-18 03:14 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-08-06 23:24 . 2004-08-04 12:00 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-06 23:23 . 2009-06-18 03:14 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-06 23:23 . 2009-09-14 14:25 274288 ----a-w- c:\windows\system32\mucltui.dll
2009-08-06 23:23 . 2009-09-14 14:25 215920 ----a-w- c:\windows\system32\muweb.dll
2009-08-06 23:23 . 2009-06-18 03:14 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-08-06 02:09 . 2009-08-06 02:09 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-08-05 09:01 . 2004-08-04 12:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-05 00:44 . 2004-08-04 12:00 2189184 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-08-04 14:20 . 2004-08-03 22:59 2066048 ----a-w- c:\windows\system32\ntkrnlpa.exe
2005-10-12 19:04 . 2005-10-12 19:04 131072 ----a-w- c:\program files\internet explorer\plugins\LV80ActiveXControl.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-05-29 52840]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2007-01-09 68640]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2007-01-09 52256]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"IObit Security 360"="c:\program files\IObit\IObit Security 360\IS360tray.exe" [2009-09-29 1241872]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
c:\documents and settings\Administrator.OUR-43318166B08\Start Menu\Programs\Startup\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2008-10-7 576000]
c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-4-14 596584]
NETGEAR WG111v3 Smart Wizard.lnk - c:\program files\NETGEAR\WG111v3\WG111v3.exe [2008-12-11 2322432]
c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\AutorunsDisabled
USB Manager.lnk - c:\program files\Belkin\Belkin Wireless USB Adapter Manager\WlanMonitor.exe [2008-10-2 122880]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\WINDOWS\\system32\\spoolsv.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\MATLAB7\\bin\\win32\\MATLAB.exe"=
"c:\\Program Files\\Sunbelt Software\\Personal Firewall\\SbPFCl.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Glob allyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R1 SbFw;SbFw;c:\windows\system32\drivers\SbFw.sys [10/17/2009 11:08 PM 270888]
R1 sbhips;Sunbelt HIPS Driver;c:\windows\system32\drivers\sbhips.sys [6/21/2008 4:54 AM 66600]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [10/9/2007 1:13 PM 38144]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [10/2/2009 8:02 PM 102448]
R3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\system32\drivers\wg111v3.sys [12/28/2007 3:02 PM 287232]
R3 SBFWIMCL;Sunbelt Software Firewall NDIS IM Filter Miniport;c:\windows\system32\drivers\SbFwIm.sys [10/17/2009 11:08 PM 65576]
S2 IS360service;IS360service;c:\program files\IObit\IObit Security 360\is360srv.exe [10/24/2009 10:06 PM 309008]
S2 SbPF.Launcher;SbPF.Launcher;c:\program files\Sunbelt Software\Personal Firewall\SbPFLnch.exe [10/31/2008 7:24 AM 95528]
S2 SPF4;Sunbelt Personal Firewall 4;c:\program files\Sunbelt Software\Personal Firewall\SbPFSvc.exe [10/31/2008 7:24 AM 1365288]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [10/7/2007 8:48 PM 116664]
S3 USBFVNETR;Belkin 11Mbps Wireless USB Network Adapter;c:\windows\system32\drivers\vnetusbr.sys [6/18/2009 12:22 AM 69632]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - CLASSPNP_2
*NewlyCreated* - MBR
*Deregistered* - CLASSPNP_2
*Deregistered* - mbr
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
2009-10-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\documents and settings\Administrator.OUR-43318166B08\Application Data\Mozilla\Firefox\Profiles\1m6s4yuf.default\
FF - plugin: c:\documents and settings\Administrator.OUR-43318166B08\Application Data\Move Networks\plugins\npqmp071505000010.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPcol308.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPLV80Win32.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-igfxhkcmd - c:\windows\system32\hkcmd.exe
HKLM-Run-igfxpers - c:\windows\system32\igfxpers.exe
HKLM-Run-igfxtray - c:\windows\system32\igfxtray.exe
HKLM-Run-vptray - c:\progra~1\SYMANT~1\VPTray.exe
AddRemove-Astroburn Toolbar - c:\program files\Astroburn Toolbar\uninst.exe
AddRemove-DAEMON Tools Toolbar - c:\program files\DAEMON Tools Toolbar\uninst.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-10-31 16:36
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
? [32480]
? [31844]
? [31772]
? [5272]
? [23740]
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe catchme.sys CLASSPNP.SYS disk.sys atapi.sys spuo.sys hal.dll >>UNKNOWN [0x89BB0938]<<
kernel: MBR read successfully
user & kernel MBR OK
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
atapi.sys @ 0x0 0x0 bytes
\Driver\atapi [ IRP_MJ_CREATE ] 0xA6F2 != 0xF7978B40 atapi.sys
\Driver\atapi [ IRP_MJ_CLOSE ] 0xA6F2 != 0xF7978B40 atapi.sys
\Driver\atapi [ IRP_MJ_DEVICE_CONTROL ] 0xA712 != 0xF7978B40 atapi.sys
\Driver\atapi [ IRP_MJ_INTERNAL_DEVICE_CONTROL ] 0x6852 != 0xF7978B40 atapi.sys
\Driver\atapi [ IRP_MJ_POWER ] 0xA73C != 0xF7978B40 atapi.sys
\Driver\atapi [ IRP_MJ_SYSTEM_CONTROL ] 0x11336 != 0xF7978B40 atapi.sys
\Driver\atapi IRP hooks detected !
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-790525478-413027322-725345543-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01 ,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,d7,3f,8d,0c,c4,4c,ec,43,be,8d,03, \
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01 ,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,42,1d,80,0b,14,43,0c,43,b0,63,8a, \
.
Completion time: 2009-10-31 16:40
ComboFix-quarantined-files.txt 2009-10-31 20:40
Pre-Run: 1,621,585,920 bytes free
Post-Run: 3,284,238,336 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - 29CFD82AA07750CDE5B0C4AC2CBD9DB4