Neal, here is log from ComboFix, per your request Hope I'll be able to download Service Pack 2 without it freezing. Let me know the results of log. Thanks
ComboFix 07-11-05.2 - ward puckett 2007-11-05 16:41:49.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.235 [GMT -5:00]
Running from: C:\Documents and Settings\ward puckett\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\findfast.exe
C:\Program Files\popupwithcast
C:\Program Files\popupwithcast\CastGen\h45168b0529.dat
C:\Program Files\popupwithcast\CastGen\u45168b074ae1.dat
C:\Program Files\popupwithcast\CastGen\ward puckett\f45168b134d06.dat
C:\Program Files\popupwithcast\CastStat\cast.dat
C:\Program Files\popupwithcast\CastSys\log.txt
C:\Program Files\popupwithcast\cload.dat
C:\Program Files\popupwithcast\cp.dat
C:\Program Files\popupwithcast\csys.dat
C:\WINDOWS\system32\_002587_.tmp.dll
C:\WINDOWS\system32\_002593_.tmp.dll
C:\WINDOWS\system32\_002601_.tmp.dll
C:\WINDOWS\system32\_002604_.tmp.dll
C:\WINDOWS\system32\_002609_.tmp.dll
C:\WINDOWS\system32\_002612_.tmp.dll
C:\WINDOWS\system32\_002617_.tmp.dll
C:\WINDOWS\system32\_002625_.tmp.dll
C:\WINDOWS\system32\_002633_.tmp.dll
C:\WINDOWS\system32\_002641_.tmp.dll
C:\WINDOWS\system32\_002649_.tmp.dll
C:\WINDOWS\system32\_002652_.tmp.dll
C:\WINDOWS\system32\_002655_.tmp.dll
C:\WINDOWS\system32\_002767_.tmp.dll
C:\WINDOWS\system32\_002768_.tmp.dll
C:\WINDOWS\system32\_002769_.tmp.dll
C:\WINDOWS\system32\_002770_.tmp.dll
C:\WINDOWS\system32\_002773_.tmp.dll
C:\WINDOWS\system32\_002774_.tmp.dll
C:\WINDOWS\system32\_002775_.tmp.dll
C:\WINDOWS\system32\_002776_.tmp.dll
C:\WINDOWS\system32\_002781_.tmp.dll
C:\WINDOWS\system32\_002782_.tmp.dll
C:\WINDOWS\system32\_002783_.tmp.dll
C:\WINDOWS\system32\_002784_.tmp.dll
C:\WINDOWS\system32\_002789_.tmp.dll
C:\WINDOWS\system32\_002790_.tmp.dll
C:\WINDOWS\system32\_002791_.tmp.dll
C:\WINDOWS\system32\_002792_.tmp.dll
C:\WINDOWS\system32\_002797_.tmp.dll
C:\WINDOWS\system32\_002798_.tmp.dll
C:\WINDOWS\system32\_002799_.tmp.dll
C:\WINDOWS\system32\_002800_.tmp.dll
C:\WINDOWS\system32\_002805_.tmp.dll
C:\WINDOWS\system32\_002806_.tmp.dll
C:\WINDOWS\system32\_002807_.tmp.dll
C:\WINDOWS\system32\_002808_.tmp.dll
C:\WINDOWS\system32\_002813_.tmp.dll
C:\WINDOWS\system32\_002814_.tmp.dll
C:\WINDOWS\system32\_002815_.tmp.dll
C:\WINDOWS\system32\_002816_.tmp.dll
C:\WINDOWS\system32\_002821_.tmp.dll
C:\WINDOWS\system32\_002822_.tmp.dll
C:\WINDOWS\system32\_002823_.tmp.dll
C:\WINDOWS\system32\_002824_.tmp.dll
C:\WINDOWS\system32\_002829_.tmp.dll
C:\WINDOWS\system32\_002830_.tmp.dll
C:\WINDOWS\system32\_002831_.tmp.dll
C:\WINDOWS\system32\_002832_.tmp.dll
C:\WINDOWS\system32\_002839_.tmp.dll
C:\WINDOWS\system32\_002840_.tmp.dll
C:\WINDOWS\system32\_002841_.tmp.dll
C:\WINDOWS\system32\_002843_.tmp.dll
C:\WINDOWS\system32\_002844_.tmp.dll
C:\WINDOWS\system32\_002847_.tmp.dll
C:\WINDOWS\system32\_002848_.tmp.dll
C:\WINDOWS\system32\_002850_.tmp.dll
C:\WINDOWS\system32\_002851_.tmp.dll
C:\WINDOWS\system32\_002852_.tmp.dll
C:\WINDOWS\system32\_002854_.tmp.dll
C:\WINDOWS\system32\_002855_.tmp.dll
C:\WINDOWS\system32\_002857_.tmp.dll
C:\WINDOWS\system32\_002861_.tmp.dll
C:\WINDOWS\system32\_002862_.tmp.dll
C:\WINDOWS\system32\_002864_.tmp.dll
C:\WINDOWS\system32\_002865_.tmp.dll
C:\WINDOWS\system32\_002867_.tmp.dll
C:\WINDOWS\system32\_002869_.tmp.dll
C:\WINDOWS\system32\_002870_.tmp.dll
C:\WINDOWS\system32\_002871_.tmp.dll
C:\WINDOWS\system32\_002872_.tmp.dll
C:\WINDOWS\system32\_002875_.tmp.dll
C:\WINDOWS\system32\_002877_.tmp.dll
C:\WINDOWS\system32\_002878_.tmp.dll
C:\WINDOWS\system32\_002879_.tmp.dll
C:\WINDOWS\system32\_002883_.tmp.dll
C:\WINDOWS\system32\_002886_.tmp.dll
C:\WINDOWS\system32\_003250_.tmp.dll
C:\WINDOWS\system32\_003251_.tmp.dll
C:\WINDOWS\system32\_003252_.tmp.dll
C:\WINDOWS\system32\_003253_.tmp.dll
C:\WINDOWS\system32\_003260_.tmp.dll
C:\WINDOWS\system32\_003261_.tmp.dll
C:\WINDOWS\system32\_003262_.tmp.dll
C:\WINDOWS\system32\_003263_.tmp.dll
C:\WINDOWS\system32\_003264_.tmp.dll
C:\WINDOWS\system32\_003265_.tmp.dll
C:\WINDOWS\system32\_003268_.tmp.dll
C:\WINDOWS\system32\_003269_.tmp.dll
C:\WINDOWS\system32\_003271_.tmp.dll
C:\WINDOWS\system32\_003272_.tmp.dll
C:\WINDOWS\system32\_003273_.tmp.dll
C:\WINDOWS\system32\_003275_.tmp.dll
C:\WINDOWS\system32\_003276_.tmp.dll
C:\WINDOWS\system32\_003278_.tmp.dll
C:\WINDOWS\system32\_003282_.tmp.dll
C:\WINDOWS\system32\_003283_.tmp.dll
C:\WINDOWS\system32\_003285_.tmp.dll
C:\WINDOWS\system32\_003288_.tmp.dll
C:\WINDOWS\system32\_003290_.tmp.dll
C:\WINDOWS\system32\_003291_.tmp.dll
C:\WINDOWS\system32\_003292_.tmp.dll
C:\WINDOWS\system32\_003293_.tmp.dll
C:\WINDOWS\system32\_003294_.tmp.dll
C:\WINDOWS\system32\_003296_.tmp.dll
C:\WINDOWS\system32\_003298_.tmp.dll
C:\WINDOWS\system32\_003299_.tmp.dll
C:\WINDOWS\system32\_003300_.tmp.dll
C:\WINDOWS\system32\_003304_.tmp.dll
C:\WINDOWS\system32\_003429_.tmp.dll
C:\WINDOWS\system32\_003435_.tmp.dll
C:\WINDOWS\system32\_003441_.tmp.dll
C:\WINDOWS\system32\_003609_.tmp.dll
C:\WINDOWS\system32\_003610_.tmp.dll
C:\WINDOWS\system32\_003611_.tmp.dll
C:\WINDOWS\system32\_003612_.tmp.dll
C:\WINDOWS\system32\_003614_.tmp.dll
C:\WINDOWS\system32\_003615_.tmp.dll
C:\WINDOWS\system32\_003616_.tmp.dll
C:\WINDOWS\system32\_003617_.tmp.dll
C:\WINDOWS\system32\_003624_.tmp.dll
C:\WINDOWS\system32\_003625_.tmp.dll
C:\WINDOWS\system32\_003626_.tmp.dll
C:\WINDOWS\system32\_003628_.tmp.dll
C:\WINDOWS\system32\_003629_.tmp.dll
C:\WINDOWS\system32\_003632_.tmp.dll
C:\WINDOWS\system32\_003633_.tmp.dll
C:\WINDOWS\system32\_003635_.tmp.dll
C:\WINDOWS\system32\_003636_.tmp.dll
C:\WINDOWS\system32\_003637_.tmp.dll
C:\WINDOWS\system32\_003639_.tmp.dll
C:\WINDOWS\system32\_003640_.tmp.dll
C:\WINDOWS\system32\_003642_.tmp.dll
C:\WINDOWS\system32\_003646_.tmp.dll
C:\WINDOWS\system32\_003647_.tmp.dll
C:\WINDOWS\system32\_003649_.tmp.dll
C:\WINDOWS\system32\_003652_.tmp.dll
C:\WINDOWS\system32\_003654_.tmp.dll
C:\WINDOWS\system32\_003655_.tmp.dll
C:\WINDOWS\system32\_003656_.tmp.dll
C:\WINDOWS\system32\_003657_.tmp.dll
C:\WINDOWS\system32\_003660_.tmp.dll
C:\WINDOWS\system32\_003662_.tmp.dll
C:\WINDOWS\system32\_003663_.tmp.dll
C:\WINDOWS\system32\_003664_.tmp.dll
C:\WINDOWS\system32\_003668_.tmp.dll
C:\WINDOWS\system32\_003670_.tmp.dll
C:\WINDOWS\system32\guard.tmp
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_POOF
((((((((((((((((((((((((( Files Created from 2007-10-05 to 2007-11-05 )))))))))))))))))))))))))))))))
.
2007-11-05 16:03 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-01 16:52 <DIR> d-------- C:\WINDOWS\ERUNT
2007-11-01 16:44 <DIR> d-------- C:\desktop
2007-10-31 15:49 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\PC Tools
2007-10-30 20:19 <DIR> d-------- C:\Program Files\Trend Micro
2007-10-30 20:17 626,688 --a------ C:\WINDOWS\SYSTEM32\msvcr80.dll
2007-10-30 19:28 <DIR> d-------- C:\Program Files\Common Files\Scanner
2007-10-30 19:28 <DIR> d-------- C:\Program Files\ComcastToolbar
2007-10-30 19:28 <DIR> d-------- C:\Documents and Settings\ward puckett\Application Data\ComcastToolbar
2007-10-30 16:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-10-30 16:13 3,968 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2007-10-09 19:24 10,240 --a------ C:\WINDOWS\fwv9jklc.exe
2007-10-09 19:24 10,240 --a------ C:\WINDOWS\5reeeicf.exe
2007-10-09 18:49 71,496 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mfeavfk.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2007-10-30 21:33 --------- d-----w C:\Program Files\Google
2007-10-29 16:37 --------- d-----w C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2007-10-09 23:56 --------- d-----w C:\Program Files\McAfee
2007-10-04 16:26 --------- d-----w C:\Documents and Settings\ward puckett\Application Data\SiteAdvisor
2007-09-30 17:44 --------- d-----w C:\Program Files\McAfee.com
2007-09-30 17:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee.com
2007-09-30 17:42 --------- d-----w C:\Program Files\SiteAdvisor
2007-09-30 17:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2007-09-30 17:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2007-09-30 17:39 --------- d-----w C:\Program Files\Common Files\McAfee
2007-09-24 00:01 --------- d-----w C:\Program Files\Common Files\Real
2007-09-23 23:59 --------- d-----w C:\Program Files\QuickTime
2007-09-23 23:58 --------- d-----w C:\Program Files\Logitech
2007-09-23 22:55 --------- d-----w C:\Program Files\Startup Optimizer
2007-09-23 21:41 --------- d-----w C:\Program Files\ePrompter
2007-09-23 21:17 --------- d-----w C:\Program Files\KODAK
2007-08-23 23:40 68,480 -c--a-w C:\Documents and Settings\ward puckett\Application Data\GDIPFONTCACHEV1.DAT
2004-06-13 11:36 449 -c--a-w C:\Documents and Settings\ward puckett\UpdateReg.reg
2003-02-04 04:16 784 -c--a-w C:\Documents and Settings\ward puckett\Application Data\mpauth.dat
2003-01-07 15:37 3,330,048 -c--a-w C:\Program Files\all_plugins.exe
2003-01-07 15:26 827,392 -c--a-w C:\Program Files\iview375.exe
2002-12-26 22:02 1,151,712 -c--a-w C:\Program Files\psych45.exe
2002-12-26 21:51 623,840 -c--a-w C:\Program Files\cdsp2002.exe
2004-10-21 16:49:52 12,565,421 -csha-w C:\WINDOWS\vrdcm.bak2
2004-10-12 19:38:00 784,085 -csha-w C:\WINDOWS\ADDINS\gmissv.bak2
2004-10-24 22:06:50 151,704,464 -csha-w C:\WINDOWS\MSAGENT\CHARS\ipatyek.bak1
2004-10-25 15:28:13 606,867,606 -csha-w C:\WINDOWS\MSAGENT\CHARS\ipatyek.bak2
2004-10-24 22:03:28 75,852,448 -csha-w C:\WINDOWS\REPAIR\sbew.bak2
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 03:59 C:\WINDOWS\BCMSMMSG.exe]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2003-08-06 00:04]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-10-30 16:14]
"StorageGuard"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-02-13 00:01]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"Spyware Doctor"="C:\Program Files\Spyware Doctor\swdoctor.exe" [2005-12-13 15:13]
"ctfmon.exe"="C:\WINDOWS\System32\ctfmon.exe" [2002-09-03 11:29]
[HKEY_USERS\.default\software\microsoft\windows\cur rentversion\run]
"Spyware Doctor"="C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\system]
"DisableRegistryTools"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\explorer]
@=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\lsa]
"Notification Packages"= scecli scecli scecli scecli scecli scecli scecli scecli scecli scecli scecli scecli scecli
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk
backup=C:\WINDOWS\pss\Microsoft Works Calendar Reminders.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ward puckett^Start Menu^Programs^Startup^ePrompter.lnk]
path=C:\Documents and Settings\ward puckett\Start Menu\Programs\Startup\ePrompter.lnk
backup=C:\WINDOWS\pss\ePrompter.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^ward puckett^Start Menu^Programs^Startup^Runner.LNK]
path=C:\Documents and Settings\ward puckett\Start Menu\Programs\Startup\Runner.LNK
backup=C:\WINDOWS\pss\Runner.LNKStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
"C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X74-X75]
"C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
C:\Program Files\Logitech\Video\ISStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
C:\Program Files\Logitech\Video\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Location Finder]
"C:\Program Files\Microsoft Location Finder\LocationFinder.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
"C:\Program Files\Microsoft Money\System\Money Express.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\New.net Startup]
rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup -s
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PopUpStopperFreeEdition]
"C:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\System Tray]
C:\Documents and Settings\ward puckett\Local Settings\Temporary Internet Files\Content.IE5\858JWNG7\password[1].pif
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Weather]
C:\Program Files\AWS\WeatherBug\Weather.exe 1
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\rundisabled]
"SiteAdvisor"=C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
"Printer"=C:\WINDOWS\System32\printer.exe
"diagent"="C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
"DVDSentry"=C:\WINDOWS\System32\DSentry.exe
"Microsoft Works Update Detection"=C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
"UpdReg"=C:\WINDOWS\UpdReg.EXE
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.E XE" /Spoil /RemAdvDef /Migration32
"DwlClient"=C:\Program Files\Common Files\Dell\EUSW\Support.exe
"ATIModeChange"=Ati2mdxx.exe
"ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
R3 FVNETusb;Linksys Wireless-B USB Network Adapter v2.8 Driver;C:\WINDOWS\System32\DRIVERS\vnet558x.sys
S2 0073451191973917mcinstcleanup;McAfee Application Installer Cleanup (0073451191973917);C:\WINDOWS\TEMP\
007345~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service
S3 NMSCFG;NIC Management Service Configuration Driver;\??\C:\WINDOWS\System32\drivers\NMSCFG.SYS
S3 NMSSvc;Intel(R) NMS;C:\WINDOWS\System32\NMSSvc.exe
S3 ser2plms;Microsoft USB GPS driver;C:\WINDOWS\System32\DRIVERS\ser2plms.sys
.
Contents of the 'Scheduled Tasks' folder
"2007-11-01 22:55:00 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1091310860.job"
"2007-11-05 21:47:23 C:\WINDOWS\Tasks\McAfee SecurityCenter.job"
"2007-05-31 15:17:13 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
"2007-05-31 15:17:07 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe
.
************************************************** ************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-05 16:48:48
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
************************************************** ************************
.
Completion time: 2007-11-05 16:53:55 - machine was rebooted
.
--- E O F ---
.