The scan finally finished! See the results below.
Note - it asked me if I wanted to update the version of Combo fix -- I did update the application.
Sprtn262
_________
Combo Fix
_______________-
ComboFix 09-12-09.04 - Melissa France 12/09/2009 17:06:14.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2558.1826 [GMT -5:00]
Running from: c:\documents and settings\Melissa France\Desktop\comfix.exe
Command switches used :: c:\documents and settings\Melissa France\Desktop\CFScript.txt
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
* Resident AV is active
file zipped: c:\program files\Common Files\ugysocuda.com
file zipped: c:\program files\Common Files\uwuraner.lib
file zipped: c:\windows\icebipoxoq.com
file zipped: c:\windows\kozalis.sys
file zipped: c:\windows\Ldocomorabu.dat
file zipped: c:\windows\Oroliwesonoce.bin
file zipped: c:\windows\seveziful.sys
file zipped: c:\windows\system32\evodywy.exe
file zipped: c:\windows\system32\idobugyciz.scr
file zipped: c:\windows\system32\necijywas.com
file zipped: c:\windows\system32\nohodis.bin
file zipped: c:\windows\system32\syqo.exe
file zipped: c:\windows\system32\yranoxyn.com
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Common Files\ugysocuda.com
c:\program files\Common Files\uwuraner.lib
c:\windows\icebipoxoq.com
c:\windows\kozalis.sys
c:\windows\Ldocomorabu.dat
c:\windows\Oroliwesonoce.bin
c:\windows\seveziful.sys
c:\windows\system32\evodywy.exe
c:\windows\system32\idobugyciz.scr
c:\windows\system32\necijywas.com
c:\windows\system32\nohodis.bin
c:\windows\system32\syqo.exe
c:\windows\system32\yranoxyn.com
F:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2009-11-09 to 2009-12-09 )))))))))))))))))))))))))))))))
.
2009-12-09 01:36 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\proquota.exe
2009-12-09 01:36 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\dllcache\proquota.exe
2009-12-08 21:52 . 2009-12-08 21:52 34816 ----a-w- c:\windows\system32\drivers\rootrepeal.sys
2009-11-30 21:46 . 2009-11-19 16:48 872960 ----a-w- c:\documents and settings\Melissa France\Application Data\Mozilla\Firefox\Profiles\4pt4h7lg.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2009-11-30 21:46 . 2009-11-19 16:48 43008 ----a-w- c:\documents and settings\Melissa France\Application Data\Mozilla\Firefox\Profiles\4pt4h7lg.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2009-11-30 21:46 . 2009-11-19 16:48 340480 ----a-w- c:\documents and settings\Melissa France\Application Data\Mozilla\Firefox\Profiles\4pt4h7lg.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2009-11-30 21:46 . 2009-11-19 16:48 346624 ----a-w- c:\documents and settings\Melissa France\Application Data\Mozilla\Firefox\Profiles\4pt4h7lg.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2009-11-29 18:43 . 2009-11-29 18:43 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-11-29 18:29 . 2008-05-13 23:08 49904 ----a-r- c:\windows\system32\drivers\BVRPMPR5.SYS
2009-11-29 18:27 . 2009-11-29 19:05 -------- d-----w- C:\Netgear
2009-11-25 01:44 . 2009-11-25 01:44 -------- d-----w- c:\documents and settings\Melissa France\Application Data\Malwarebytes
2009-11-25 01:44 . 2009-09-10 19:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-25 01:44 . 2009-11-25 01:44 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-25 01:44 . 2009-11-25 01:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-11-25 01:44 . 2009-09-10 19:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-14 16:09 . 2009-11-14 16:09 -------- d-----w- c:\documents and settings\Melissa France\Application Data\Picaboo
2009-11-14 16:01 . 2009-11-14 16:09 -------- d-----w- c:\program files\Picaboo
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-09 21:56 . 2009-10-13 16:16 -------- d-----w- c:\documents and settings\All Users\Application Data\STOPzilla!
2009-12-09 20:04 . 2008-08-11 21:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-12-09 11:17 . 2005-06-22 02:17 -------- d-----w- c:\program files\Juno
2009-12-09 11:03 . 2009-12-09 11:03 336 ----a-w- c:\windows\system32\drivers\kgpfr2.cfg
2009-12-09 11:03 . 2009-12-09 11:02 1264 ----a-w- c:\windows\system32\drivers\kgpcpy.cfg
2009-12-09 10:59 . 2008-12-19 14:20 720 ----a-w- c:\documents and settings\All Users\Application Data\ArcSoft\kodak-printcreations-22-080812-oem\acforall.dll
2009-12-07 11:30 . 2009-11-08 19:19 79488 ----a-w- c:\documents and settings\Melissa France\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-11-20 11:04 . 2007-03-13 11:49 -------- d-----w- c:\program files\McAfee
2009-11-14 16:10 . 2005-06-21 22:43 131392 ----a-w- c:\documents and settings\Melissa France\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-10 23:54 . 2009-09-27 15:42 -------- d-----w- c:\program files\SmartMusic 2010
2009-10-25 15:50 . 2005-06-17 04:17 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-10-25 15:50 . 2005-12-30 18:53 -------- d-----w- c:\program files\iPod
2009-10-23 23:35 . 2009-09-12 01:10 74036 ---ha-w- c:\windows\system32\mlfcache.dat
2009-10-13 18:35 . 2009-10-13 16:17 -------- d-----w- c:\documents and settings\All Users\Application Data\SITEguard
2009-10-13 16:16 . 2009-10-13 16:16 -------- d-----w- c:\program files\STOPzilla!
2009-10-13 16:16 . 2009-10-13 16:16 -------- d-----w- c:\program files\Common Files\iS3
2009-09-20 18:39 . 2009-09-20 18:39 17807 ----a-w- c:\documents and settings\Melissa France\Local Settings\Application Data\isevix.sys
2009-09-16 14:22 . 2007-03-13 11:51 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-09-16 14:22 . 2007-03-13 11:51 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-09-16 14:22 . 2007-03-13 11:51 214664 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-09-16 14:22 . 2007-03-13 11:51 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-09-16 14:22 . 2007-03-13 11:51 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys
2009-09-11 14:18 . 2004-08-04 10:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-25 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup" [X]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe -start" [X]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe -atboottime" [X]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-25 339968]
"DeviceDiscovery"="c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe" [2003-05-21 229437]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-07-28 188416]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2005-02-17 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-10-23 233472]
"HostManager"="c:\program files\Common Files\AOL\1127748615\ee\AOLHostManager.exe" [2005-08-02 159832]
"SiteAdvisor"="c:\program files\SiteAdvisor\6028\SiteAdv.exe" [2007-02-09 36904]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2005-03-16 127037]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-06-29 32768]
"MaxtorOneTouch"="c:\program files\Maxtor\ManagerApp\Onetouch.exe" [2006-08-11 712704]
"mxomssmenu"="c:\program files\Maxtor\OneTouch Status\maxmenumgr.exe" [2006-08-11 81920]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008]
"Motive SmartBridge"="c:\progra~1\VIRTUA~1\SMARTB~1\SprintDSLAlert.exe" [2006-04-21 438359]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2009-10-10 203264]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-07 148888]
"EEventManager"="c:\progra~1\EPSONS~1\EVENTM~1\EEventManager.exe" [2009-01-12 669520]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-09 305440]
c:\documents and settings\Melissa France\Start Menu\Programs\Startup\
Picaboo.lnk - c:\program files\Picaboo\Picaboo\PicabooMain.exe [2009-7-10 606208]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\1127748615\\ee\\AOLServiceHost.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Juno\\bin\\juno.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Epson Software\\Event Manager\\EEventManager.exe"=
"c:\\Program Files\\EpsonNet\\EpsonNet Setup\\tool09\\ENEasyApp.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 szkg5;szkg;c:\windows\SYSTEM32\DRIVERS\SZKG.sys [5/12/2009 1:13 PM 61328]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [3/16/2007 1:57 PM 24652]
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.nytimes.com/
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = 127.0.0.1;*.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
Trusted Zone: turbotax.com
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Melissa France\Application Data\Mozilla\Firefox\Profiles\4pt4h7lg.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.nytimes.com/
FF - component: c:\documents and settings\Melissa France\Application Data\Mozilla\Firefox\Profiles\4pt4h7lg.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\program files\SiteAdvisor\6066\FF\components\FFHook.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-12-09 17:14
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1115760850-618011297-1412726674-1006\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:e5,93,d5,db,8f,f3,ae,4e,24,7d,15,69,7b,46,04,1d,20,55,bb,5c,a1,22,67,
dc,51,32,86,52,15,17,3a,1a,92,db,8b,b1,70,08,7b,67,1c,0b,89,d2,f2,fb,cd,c0,\
"??"=hex:c4,04,98,d5,63,5c,35,4b,56,bf,96,c6,48,fe,da,3c
[HKEY_USERS\S-1-5-21-1115760850-618011297-1412726674-1006\Software\SecuROM\License information*]
"datasecu"=hex:d5,f3,3f,b4,d8,5c,bf,44,5f,c5,aa,6c,ff,9b,cd,d1,4e,63,33,c1,b5,
a5,86,4f,c2,2c,c1,57,e8,ea,3b,46,af,c4,93,4f,3e,90,42,c1,dd,9f,0f,bd,27,d5,\
"rkeysecu"=hex:3e,80,9e,c4,40,b4,90,83,87,8e,33,49,64,ac,f8,d9
.
Completion time: 2009-12-09 17:17:28
ComboFix-quarantined-files.txt 2009-12-09 22:17
ComboFix2.txt 2009-12-09 01:51
Pre-Run: 15,687,815,168 bytes free
Post-Run: 15,722,692,608 bytes free
- - End Of File - - 5642CDA577361544384DD4C6ED560C79
Upload was successful
____________
MBAB
_________
Malwarebytes' Anti-Malware 1.42
Database version: 3334
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
12/9/2009 8:50:42 PM
mbam-log-2009-12-09 (20-50-42).txt
Scan type: Full Scan (C:\|F:\|)
Objects scanned: 388461
Time elapsed: 3 hour(s), 14 minute(s), 13 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 22
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Qoobox\Quarantine\C\Program Files\Common Files\ugysocuda.com.vir (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\Program Files\Common Files\uwuraner.lib.vir (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\icebipoxoq.com.vir (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\kozalis.sys.vir (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\seveziful.sys.vir (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\evodywy.exe.vir (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\idobugyciz.scr.vir (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\necijywas.com.vir (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\nohodis.bin.vir (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\syqo.exe.vir (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\yranoxyn.com.vir (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1524\A0189447.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1524\A0189532.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1524\A0189614.com (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1524\A0189615.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1524\A0189616.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1524\A0189617.exe (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1524\A0189618.scr (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1524\A0189619.com (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1524\A0189620.exe (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1524\A0189621.com (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1524\A0189702.sys (Rootkit.Agent) -> Quarantined and deleted successfully.