Hi Gringo - here's the combofix log.
ComboFix 11-07-15.03 - mike & katie 07/16/2011 13:18:20.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.572 [GMT -7:00]
Running from: c:\documents and settings\mike & katie\Desktop\ComboFix.exe
FW: ZoneAlarm Extreme Security Firewall *Disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\mike & katie\Application Data\Mozilla\Firefox\Profiles\i4frxn74.default\extensions\{d3e859d7-6ca9-4ce9-9aac-474002deca3c}
c:\documents and settings\mike & katie\Application Data\Mozilla\Firefox\Profiles\i4frxn74.default\extensions\{d3e859d7-6ca9-4ce9-9aac-474002deca3c}\chrome.manifest
c:\documents and settings\mike & katie\Application Data\Mozilla\Firefox\Profiles\i4frxn74.default\extensions\{d3e859d7-6ca9-4ce9-9aac-474002deca3c}\chrome\xulcache.jar
c:\documents and settings\mike & katie\Application Data\Mozilla\Firefox\Profiles\i4frxn74.default\extensions\{d3e859d7-6ca9-4ce9-9aac-474002deca3c}\defaults\preferences\xulcache.js
c:\documents and settings\mike & katie\Application Data\Mozilla\Firefox\Profiles\i4frxn74.default\extensions\{d3e859d7-6ca9-4ce9-9aac-474002deca3c}\install.rdf
c:\program files\Common Files\zacaceb.dl
c:\windows\XSxS
.
.
((((((((((((((((((((((((( Files Created from 2011-06-16 to 2011-07-16 )))))))))))))))))))))))))))))))
.
.
2011-07-01 15:16 . 2011-07-01 15:16 -------- d-----w- c:\documents and settings\mike & katie\Application Data\CyberScrub
2011-06-26 17:48 . 2011-06-26 17:48 -------- d-----w- c:\program files\Resource Kit
2011-06-26 16:00 . 2011-06-26 16:00 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\TEMP
2011-06-20 12:23 . 2011-06-20 12:23 0 ---ha-w- c:\documents and settings\mike & katie\bawydyekbg.tmp
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-04 16:00 . 2011-06-04 16:00 109216 ----a-w- c:\windows\system32\EasyHook64.dll
2011-06-04 16:00 . 2011-06-04 16:00 90784 ----a-w- c:\windows\system32\EasyHook32.dll
2011-06-02 14:02 . 2004-08-10 12:00 1858944 ----a-w- c:\windows\system32\win32k.sys
2011-05-29 16:11 . 2010-07-24 22:47 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-29 16:11 . 2010-07-24 22:47 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-05-02 15:31 . 2010-07-24 22:04 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-29 17:25 . 2004-08-10 12:00 151552 ----a-w- c:\windows\system32\schannel.dll
2011-04-29 16:19 . 2004-08-10 12:00 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-26 11:07 . 2004-08-10 12:00 33280 ----a-w- c:\windows\system32\csrsrv.dll
2011-04-26 11:07 . 2004-08-10 12:00 293376 ----a-w- c:\windows\system32\winsrv.dll
2011-04-25 16:11 . 2004-08-10 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2011-04-25 16:11 . 2004-08-10 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-04-25 16:11 . 2004-08-10 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-04-25 12:01 . 2004-08-10 12:00 385024 ----a-w- c:\windows\system32\html.iec
2011-04-21 13:37 . 2004-08-10 12:00 105472 ----a-w- c:\windows\system32\drivers\mup.sys
2009-10-24 23:00 . 2009-10-24 23:00 18862 ----a-w- c:\program files\Common Files\letacux.bat
2009-10-24 23:00 . 2009-10-24 23:00 14431 ----a-w- c:\program files\Common Files\megi.com
2009-10-24 23:00 . 2009-10-24 23:00 13653 ----a-w- c:\program files\Common Files\towu.sys
2009-10-24 22:52 . 2009-10-24 22:52 15081 ----a-w- c:\program files\Common Files\tuca.dll
2009-10-24 22:52 . 2009-10-24 22:52 14576 ----a-w- c:\program files\Common Files\madaty.dll
2009-10-24 21:46 . 2009-10-24 21:46 18657 ----a-w- c:\program files\Common Files\ymyz.sys
2009-10-24 21:20 . 2009-10-24 21:20 18992 ----a-w- c:\program files\Common Files\mazebupit.com
2009-10-24 20:45 . 2009-10-24 20:45 16942 ----a-w- c:\program files\Common Files\xezekikyzu.bin
2009-10-24 20:45 . 2009-10-24 20:45 12168 ----a-w- c:\program files\Common Files\nopycoju.vbs
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2004-08-10 59392]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-23 339968]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-07-21 1038848]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-30 421888]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-05-29 449584]
.
c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-11-18 275072]
hp psc 1000 series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2002-12-2 147456]
hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2002-12-2 40960]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-21 18:37 932288 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-09-23 11:47 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2006-02-10 04:05 344064 ----a-w- c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2009-11-18 23:13 54576 ----a-w- c:\program files\HP\HP Software Update\hpwuschd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-07-21 22:53 141608 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Vid]
2011-01-13 02:01 6129496 ----a-w- c:\program files\Logitech\Vid HD\Vid.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
2009-10-14 21:36 2793304 ----a-w- c:\program files\Logitech\Logitech WebCam Software\LWS.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Monitor]
2010-11-19 21:38 193880 ----a-w- c:\program files\LeapFrog\LeapFrog Connect\Monitor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Qwest Personal Digital Vault]
2009-12-18 20:58 1064808 ----a-w- c:\program files\Qwest Personal Digital Vault\QwestPersonalDigitalVault.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 19:44 248552 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"osppsvc"=3 (0x3)
"ose"=3 (0x3)
"mnmsrvc"=3 (0x3)
"LeapFrog Connect Device Service"=2 (0x2)
"iPod Service"=3 (0x3)
"gusvc"=3 (0x3)
"gupdatem"=3 (0x3)
"gupdate"=2 (0x2)
"Bonjour Service"=2 (0x2)
"ATI Smart"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\vsmon.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Program Files\\LeapFrog\\LeapFrog Connect\\LeapFrogConnect.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqcopy2.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfcCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgm.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqusgh.exe"=
"c:\\Program Files\\HP\\HP Software Update\\hpwucli.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\smart web printing\\SmartWebPrintExe.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Logitech\\Vid HD\\Vid.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58120:TCP"= 58120:TCP:Pando Media Booster
"58120:UDP"= 58120:UDP:Pando Media Booster
.
R2 ISWKL;ZoneAlarm ForceField ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [3/16/2010 1:55 AM 26352]
R2 IswSvc;ZoneAlarm ForceField IswSvc;c:\program files\CheckPoint\ZAForceField\ISWSVC.exe [3/16/2010 1:55 AM 493032]
R2 sprtlisten;SupportSoft Listener Service;c:\program files\Common Files\supportsoft\bin\sprtlisten.exe [1/8/2008 12:02 PM 1213728]
R3 EuMusDesignVirtualAudioCableWdm_s2x;Sound2x Audio Cable (WDM);c:\windows\system32\drivers\vacs2xkd.sys [11/16/2010 10:14 PM 42880]
R3 icsak;icsak;c:\program files\CheckPoint\ZAForceField\AK\icsak.sys [3/16/2010 1:55 AM 35568]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [7/24/2010 3:47 PM 22712]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [1/9/2010 9:37 PM 4640000]
S2 AppMgmt32;Application Management ;c:\windows\system32\atitvo3232.exe --> c:\windows\system32\atitvo3232.exe [?]
S2 EapHost32;Extensible Authentication Protocol Service ;c:\windows\system32\activeds32.exe --> c:\windows\system32\activeds32.exe [?]
S2 FastUserSwitchingCompatibility32;Fast User Switching Compatibility ;c:\windows\system32\tsd3232.exe --> c:\windows\system32\tsd3232.exe [?]
S2 FontCache3.0.0.032;Windows Presentation Foundation Font Cache 3.0.0.0 ;c:\windows\system32\dmutil32.exe --> c:\windows\system32\dmutil32.exe [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [4/16/2010 5:26 AM 136176]
S2 hpqcxs0832;hpqcxs08 ;c:\windows\system32\odbc32gt32.exe --> c:\windows\system32\odbc32gt32.exe [?]
S2 hpqddsvc32;HP CUE DeviceDiscovery Service ;c:\windows\system32\icm3232.exe --> c:\windows\system32\icm3232.exe [?]
S2 hpqddsvc3232;HP CUE DeviceDiscovery Service ;c:\windows\system32\imm3232.exe --> c:\windows\system32\imm3232.exe [?]
S2 IswSvc32;ZoneAlarm ForceField IswSvc ;c:\windows\system32\mtxclu32.exe --> c:\windows\system32\mtxclu32.exe [?]
S2 lanmanserver32;Server ;c:\windows\system32\d3dim32.exe --> c:\windows\system32\d3dim32.exe [?]
S2 LmHosts32;TCP/IP NetBIOS Helper ;c:\windows\system32\dot3gpclnt32.exe --> c:\windows\system32\dot3gpclnt32.exe [?]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [7/24/2010 3:47 PM 366640]
S2 MHN32;MHN ;c:\windows\system32\credssp32.exe --> c:\windows\system32\credssp32.exe [?]
S2 NetDDE32;Network DDE ;c:\windows\system32\oleacc32.exe --> c:\windows\system32\oleacc32.exe [?]
S2 Netman32;Network Connections ;c:\windows\system32\capesnpn32.exe --> c:\windows\system32\capesnpn32.exe [?]
S2 Netman3232;Network Connections ;c:\windows\system32\clusapi32.exe --> c:\windows\system32\clusapi32.exe [?]
S2 NetTcpPortSharing32;Net.Tcp Port Sharing Service ;c:\windows\system32\jgpl40032.exe --> c:\windows\system32\jgpl40032.exe [?]
S2 NtmsSvc32;Removable Storage ;c:\windows\system32\dpserial32.exe --> c:\windows\system32\dpserial32.exe [?]
S2 NtmsSvc3232;Removable Storage ;c:\windows\system32\mapistub32.exe --> c:\windows\system32\mapistub32.exe [?]
S2 RemoteAccess32;Routing and Remote Access ;c:\windows\system32\olecli32.exe --> c:\windows\system32\olecli32.exe [?]
S2 RemoteRegistry3232;Remote Registry ;c:\windows\system32\dpnmodem32.exe --> c:\windows\system32\dpnmodem32.exe [?]
S2 Schedule32;Task Scheduler ;c:\windows\system32\icwphbk32.exe --> c:\windows\system32\icwphbk32.exe [?]
S2 ShellHWDetection32;Shell Hardware Detection ;c:\windows\system32\msvcirt32.exe --> c:\windows\system32\msvcirt32.exe [?]
S2 SysmonLog32;Performance Logs and Alerts ;c:\windows\system32\dpnet32.exe --> c:\windows\system32\dpnet32.exe [?]
S2 Themes32;Themes ;c:\windows\system32\mnmdd32.exe --> c:\windows\system32\mnmdd32.exe [?]
S2 TrkWks32;Distributed Link Tracking Client ;c:\windows\system32\iassam32.exe --> c:\windows\system32\iassam32.exe [?]
S2 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\SPEEDB~2\VideoAcceleratorService.exe -start -scm --> c:\progra~1\SPEEDB~2\VideoAcceleratorService.exe -start -scm [?]
S2 W32Time32;Windows Time ;c:\windows\system32\netapi32.exe --> c:\windows\system32\netapi32.exe [?]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\ASPI32.SYS [11/16/2010 10:14 PM 16512]
S3 FlyUsb;FLY Fusion;c:\windows\system32\drivers\FlyUsb.sys [1/11/2011 9:46 PM 18560]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [4/16/2010 5:26 AM 136176]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [7/24/2010 3:47 PM 39984]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [3/25/2010 10:25 AM 30969208]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - BLACKBOX
*Deregistered* - BlackBox
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-07-07 c:\windows\Tasks\FRU Task 2002-12-03 04:38ewlett-Packard2002-12-03 04:38p psc 1200 series84887B468ABA3F57D76752217D5938688025EB21281146478.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2002-12-03 03:38]
.
2011-07-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-16 12:26]
.
2011-07-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-16 12:26]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office14\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
IE: Se&nd to OneNote - c:\progra~1\MICROS~4\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\documents and settings\mike & katie\Application Data\Mozilla\Firefox\Profiles\i4frxn74.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: DivX HiQ: {6904342A-8307-11DF-A508-4AE2DFD72085} - c:\program files\DivX\DivX Plus Web Player\firefox\wpa
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{3017FB3E-9A77-4396-88C5-0EC9548FB42F} - c:\program files\SpeedBit Video Downloader\Toolbar\tbcore3.dll
BHO-{389943B0-C3A2-4E69-82CB-8596A84CB3DC} - c:\progra~1\SEARCH~2\SEARCH~1.DLL
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-07-16 14:30
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(704)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
c:\program files\CheckPoint\ZAForceField\AK\icsak.dll
.
- - - - - - - > 'lsass.exe'(760)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
c:\program files\CheckPoint\ZAForceField\AK\icsak.dll
.
- - - - - - - > 'csrss.exe'(676)
c:\program files\CheckPoint\ZAForceField\AK\akconsole.dll
.
Completion time: 2011-07-16 14:34:12
ComboFix-quarantined-files.txt 2011-07-16 21:34
.
Pre-Run: 124,955,459,584 bytes free
Post-Run: 129,557,577,728 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect /noexecute=optout
.
- - End Of File - - 764EBDA71D54036DBF581B7A08713368