Followed your directions and ran CF. No longer receiving error messages and below is the CF log; hopefully this fixed the problem on the first run. It gave me a warning that my CA anti-virus was still enabled, but took all the necessary steps to disable. The only program that may have been running was CA's PureSight, of which the icon no longer shows in the tab. Nonetheless, looking forward to your feedback...
ComboFix 09-11-08.03 - Kyle 11/09/2009 21:16.1.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.420 [GMT -6:00]
Running from: c:\documents and settings\Kyle\Desktop\ComboFix.exe
AV: CA Anti-Virus *On-access scanning enabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}
FW: CA Personal Firewall *disabled* {14CB4B80-8E52-45EA-905E-67C1267B4160}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\usowuwul.dll
Infected copy of c:\windows\system32\imm32.dll was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\imm32.dll
.
((((((((((((((((((((((((( Files Created from 2009-10-10 to 2009-11-10 )))))))))))))))))))))))))))))))
.
2009-11-09 21:51 . 2009-11-09 21:51 -------- dc----w- c:\program files\ESET
2009-11-08 22:59 . 2009-11-09 02:57 152576 -c--a-w- c:\documents and settings\Kyle\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-08 19:47 . 2009-11-08 19:47 -------- dc----w- c:\documents and settings\Kyle\Application Data\Malwarebytes
2009-11-08 19:46 . 2009-09-10 20:54 38224 -c--a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-08 19:46 . 2009-11-08 19:46 -------- dc----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-11-08 19:46 . 2009-11-08 21:31 -------- dc----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-08 19:46 . 2009-09-10 20:53 19160 -c--a-w- c:\windows\system32\drivers\mbam.sys
2009-11-08 01:39 . 2009-11-08 01:39 -------- dc----w- c:\program files\Trend Micro
2009-11-08 01:38 . 2009-11-08 01:38 396288 -c--a-w- C:\HijackThis.exe
2009-11-07 23:18 . 2009-11-07 23:18 -------- dc----w- c:\windows\system32\XPSViewer
2009-11-07 23:18 . 2009-11-07 23:18 -------- dc----w- c:\program files\MSBuild
2009-11-07 23:18 . 2009-11-07 23:18 -------- dc----w- c:\program files\Reference Assemblies
2009-11-07 23:16 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-11-07 23:16 . 2008-07-06 12:06 117760 -c----w- c:\windows\system32\prntvpt.dll
2009-11-07 23:16 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\xpsshhdr.dll
2009-11-07 23:16 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-11-07 23:16 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-11-07 23:16 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\xpssvcs.dll
2009-11-07 23:16 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2009-11-06 13:51 . 2009-09-01 03:04 52224 -c--a-w- c:\documents and settings\Kyle\Application Data\Mozilla\Firefox\Profiles\zzn8hrzf.default\extensions\{e4878b45-e2c0-4307-b6e8-734922f92f5b}\components\FFExternalAlert.dll
2009-11-06 13:51 . 2009-09-01 03:04 114688 -c--a-w- c:\documents and settings\Kyle\Application Data\Mozilla\Firefox\Profiles\zzn8hrzf.default\extensions\{e4878b45-e2c0-4307-b6e8-734922f92f5b}\components\npmozax.dll
2009-11-05 22:15 . 2009-11-05 22:15 -------- dc----w- c:\documents and settings\Kyle\Application Data\pdf995
2009-10-13 13:32 . 2009-10-13 13:32 739752 -c--a-w- c:\windows\system32\drivers\vetefile.sys
2009-10-13 13:32 . 2009-10-13 13:32 133576 -c--a-w- c:\windows\system32\drivers\veteboot.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-10 03:26 . 2007-10-31 03:15 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k7
2009-11-10 03:26 . 2007-10-31 03:15 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k6
2009-11-10 03:26 . 2007-10-31 03:15 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k5
2009-11-10 03:26 . 2007-10-31 03:15 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k4
2009-11-10 03:26 . 2007-10-31 03:15 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k3
2009-11-10 03:26 . 2007-10-31 03:15 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k2
2009-11-10 03:26 . 2007-10-31 03:15 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k1
2009-11-10 03:26 . 2007-10-31 03:15 315608 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k0
2009-11-08 23:04 . 2006-08-17 06:44 -------- dc----w- c:\program files\Java
2009-11-08 19:44 . 2009-04-08 12:32 0 -c--a-w- c:\windows\Iseginaqafotoc.bin
2009-11-05 22:17 . 2007-02-10 22:07 -------- dc----w- c:\documents and settings\All Users\Application Data\pdf995
2009-11-05 22:15 . 2008-02-12 03:04 -------- dc----w- c:\documents and settings\Kyle\Application Data\TaxCut
2009-10-13 13:32 . 2008-04-13 07:04 1541416 -c--a-w- c:\documents and settings\All Users\Application Data\CA\Consumer\AV\tmp\vete_tmp.dll
2009-10-11 10:17 . 2008-12-09 01:30 411368 -c--a-w- c:\windows\system32\deploytk.dll
2009-10-06 23:14 . 2006-08-26 19:38 -------- dc----w- c:\documents and settings\Kyle\Application Data\Apple Computer
2009-10-06 00:35 . 2009-10-06 00:33 -------- dc----w- c:\program files\iTunes
2009-10-06 00:35 . 2009-10-06 00:33 -------- dc----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-10-06 00:34 . 2006-08-26 19:36 -------- dc----w- c:\program files\iPod
2009-10-06 00:34 . 2007-07-08 17:48 -------- dc----w- c:\program files\Common Files\Apple
2009-10-06 00:21 . 2009-10-06 00:21 -------- dc----w- c:\program files\Bonjour
2009-10-06 00:20 . 2009-10-06 00:19 -------- dc----w- c:\program files\QuickTime
2009-10-06 00:05 . 2009-10-06 00:05 79144 -c--a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.1.8\SetupAdmin.exe
2009-10-04 16:28 . 2009-10-04 16:28 -------- dc----w- c:\documents and settings\Lynn\Application Data\pdf995
2009-09-29 22:09 . 2008-08-24 18:57 -------- dc----w- c:\program files\Microsoft Silverlight
2009-09-11 14:18 . 2004-08-10 17:51 136192 -c--a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:03 . 2004-08-10 17:51 58880 -c--a-w- c:\windows\system32\msasn1.dll
2009-08-29 08:08 . 2004-08-10 17:51 916480 -c--a-w- c:\windows\system32\wininet.dll
2009-08-26 08:00 . 2004-08-10 17:51 247326 -c--a-w- c:\windows\system32\strmdll.dll
2006-10-06 02:00 . 2006-10-06 02:00 774144 -c--a-w- c:\program files\RngInterstitial.dll
2007-06-08 23:09 . 2007-06-08 23:09 10240 -csha-w- c:\windows\rnapxs\rnapxs.dat
2008-05-29 22:23 . 2006-08-27 19:25 88 -csh--r- c:\windows\system32\3879F53CEC.sys
2008-05-29 22:23 . 2006-08-27 19:25 3350 -csha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-15 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-15 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-15 114688]
"cctray"="c:\program files\CA\CA Internet Security Suite\cctray\cctray.exe" [2009-07-31 177392]
"dvHighMem"="c:\windows\cfgmng32.exe" [2006-10-15 10870784]
"CAVRID"="c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2009-10-15 230664]
"cafwc"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe" [2008-07-31 1193200]
"capfasem"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe" [2008-07-31 173296]
"capfupgrade"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe" [2008-07-31 259312]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"MMTray"="c:\program files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2005-09-09 110592]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-05 417792]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil10a.exe" [2008-10-05 235936]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-8-17 24576]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
2007-05-18 19:30 79368 ----a-w- c:\windows\system32\UmxWNP.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\CA Personal Firewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Sony\\Station\\LaunchPad\\LaunchPad.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 KmxStart;KmxStart;c:\windows\system32\drivers\KmxStart.sys [6/24/2008 6:08 PM 93712]
R1 KmxAgent;KmxAgent;c:\windows\system32\drivers\KmxAgent.sys [6/24/2008 6:08 PM 63504]
R1 KmxFile;KmxFile;c:\windows\system32\drivers\KmxFile.sys [6/24/2008 6:08 PM 45584]
R1 KmxFw;KmxFw;c:\windows\system32\drivers\KmxFw.sys [6/24/2008 6:08 PM 115216]
R2 KmxCF;KmxCF;c:\windows\system32\drivers\KmxCF.sys [6/24/2008 6:08 PM 134648]
R2 KmxSbx;KmxSbx;c:\windows\system32\drivers\KmxSbx.sys [6/24/2008 6:08 PM 66576]
R2 UmxAgent;HIPS Event Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxAgent.exe [10/4/2007 8:23 AM 1010192]
R2 UmxCfg;HIPS Configuration Interpreter;c:\program files\CA\SharedComponents\HIPSEngine\UmxCfg.exe [10/18/2007 8:39 AM 801296]
R2 UmxPol;HIPS Policy Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxPol.exe [6/24/2008 6:10 PM 281104]
R2 WinSock Extention Manager;WinSock Extention Manager;c:\windows\system32\mdmcls32.exe [6/8/2007 5:09 PM 1032192]
R3 KmxCfg;KmxCfg;c:\windows\system32\drivers\KmxCfg.sys [6/24/2008 6:08 PM 88816]
R3 PPCtlPriv;PPCtlPriv;c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe [8/16/2007 8:10 PM 189704]
S3 MR97310_VGA_DUAL_CAMERA;VGA Dual-Mode Camera;c:\windows\system32\drivers\mr97310v.sys [7/18/2006 1:40 PM 99840]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - MBR
*Deregistered* - mbr
.
Contents of the 'Scheduled Tasks' folder
2009-11-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 17:34]
2009-09-19 c:\windows\Tasks\CAAntiSpywareScan_Daily as Kyle at 10 05 PM.job
- c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe [2007-08-17 02:10]
2009-09-27 c:\windows\Tasks\CAAntiSpywareScan_Daily as Kyle at 9 32 PM.job
- c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe [2007-08-17 02:10]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.bing.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
uInternet Connection Wizard,ShellNext = hxxp://127.0.0.1:4664/first_usage&s=Iw7dPBHKDBuTirvfscIT4wfhQ9U
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
LSP: winsflt.dll
LSP: c:\windows\system32\VetRedir.dll
Trusted Zone: musicmatch.com\online
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {59E937ED-AC7E-407D-B40B-6545B1EECDE7} - hxxp://www.weareautobots.com/ww/plugin/DFusionWeb.Installer.exe
FF - ProfilePath - c:\documents and settings\Kyle\Application Data\Mozilla\Firefox\Profiles\zzn8hrzf.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2187784&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.startup.homepage - hxxp://www.rr.com
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2187784&SearchSource=2&q=
FF - component: c:\documents and settings\Kyle\Application Data\Mozilla\Firefox\Profiles\zzn8hrzf.default\extensions\{e4878b45-e2c0-4307-b6e8-734922f92f5b}\components\FFExternalAlert.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\nptidfusionplugin.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF - plugin: c:\program files\Total Immersion\DFusionWeb\nptidfusionplugin.dll
FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: XUL Cache: {7151DB41-B5C9-4EE6-A037-942DFB9B31CA} - c:\documents and settings\Kyle\Local Settings\Application Data\{7151DB41-B5C9-4EE6-A037-942DFB9B31CA}\
FF - HiddenExtension: XUL Cache: {E7C7135D-55B2-4269-8D6E-354AF5495283} - c:\documents and settings\Lynn\Local Settings\Application Data\{E7C7135D-55B2-4269-8D6E-354AF5495283}
FF - HiddenExtension: XUL Cache: {1AB2A261-0336-490B-8698-F88FA82D50A4} - c:\documents and settings\Kyle\Local Settings\Application Data\{1AB2A261-0336-490B-8698-F88FA82D50A4}
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-09 21:30
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(260)
c:\windows\system32\UmxWnp.Dll
c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll
- - - - - - - > 'lsass.exe'(612)
c:\windows\system32\winsflt.dll
c:\windows\system32\VetRedir.dll
c:\windows\system32\ISafeIf.dll
- - - - - - - > 'explorer.exe'(2576)
c:\windows\system32\WININET.dll
c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
c:\program files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Dell Support Center\bin\sprtsvc.exe
c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
c:\program files\Microsoft Office\Office\1033\msoffice.exe
c:\program files\CA\CA Internet Security Suite\ccprovsp.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-11-10 21:43 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-10 03:42
Pre-Run: 13,527,699,456 bytes free
Post-Run: 14,572,449,792 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=AlwaysOff
- - End Of File - - E0F7B6B62043F6C67E4FF3B74E0FEC48