Here is the combo fix log file
ComboFix 08-08-30.01 - Twan 2008-09-01 20:26:48.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.264 [GMT -5:00]
Running from: C:\Documents and Settings\Twan\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Brian\Application Data\inst.exe
C:\Documents and Settings\Brian\Application Data\macromedia\Flash Player\#SharedObjects\J6FH72B9\bin.clearspring.com
C:\Documents and Settings\Brian\Application Data\macromedia\Flash Player\#SharedObjects\J6FH72B9\bin.clearspring.com \clearspring.sol
C:\Documents and Settings\Brian\Application Data\macromedia\Flash Player\#SharedObjects\J6FH72B9\interclick.com
C:\Documents and Settings\Brian\Application Data\macromedia\Flash Player\#SharedObjects\J6FH72B9\interclick.com\ud.s ol
C:\Documents and Settings\Brian\Application Data\macromedia\Flash Player\#SharedObjects\J6FH72B9\static.youku.com
C:\Documents and Settings\Brian\Application Data\macromedia\Flash Player\#SharedObjects\J6FH72B9\static.youku.com\yo ukuSavedVolume.sol
C:\Documents and Settings\Brian\Application Data\macromedia\Flash Player\#SharedObjects\J6FH72B9\
Broadcaster.com | Home | Viral Video Clips, Live Community, News, Software, Movies, Music, Games, Mobile Media & More
C:\Documents and Settings\Brian\Application Data\macromedia\Flash Player\#SharedObjects\J6FH72B9\
www.broadcaster.com\played_list.sol
C:\Documents and Settings\Brian\Application Data\macromedia\Flash Player\#SharedObjects\J6FH72B9\
www.broadcaster.com\video_queue.sol
C:\Documents and Settings\Brian\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin .clearspring.com
C:\Documents and Settings\Brian\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin .clearspring.com\settings.sol
C:\Documents and Settings\Brian\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#int erclick.com
C:\Documents and Settings\Brian\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#int erclick.com\settings.sol
C:\Documents and Settings\Brian\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#sta tic.youku.com
C:\Documents and Settings\Brian\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#sta tic.youku.com\settings.sol
C:\Documents and Settings\Brian\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#
Broadcaster.com | Home | Viral Video Clips, Live Community, News, Software, Movies, Music, Games, Mobile Media & More
C:\Documents and Settings\Brian\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#
www.broadcaster.com\settings.sol
C:\Documents and Settings\Brian\Cookies\brian@2o7[1].txt
C:\Documents and Settings\Brian\Cookies\brian@ad.yieldmanager[2].txt
C:\Documents and Settings\Brian\Cookies\brian@ads.pointroll[2].txt
C:\Documents and Settings\Brian\Cookies\brian@ehg-dig.hitbox[2].txt
C:\Documents and Settings\Brian\Cookies\brian@hb.pcworld[2].txt
C:\Documents and Settings\Brian\Cookies\brian@insightexpressai[2].txt
C:\Documents and Settings\Brian\Cookies\brian@interclick[2].txt
C:\Documents and Settings\Brian\Cookies\brian@media6degrees[2].txt
C:\Documents and Settings\Brian\Cookies\brian@personals.yahoo[2].txt
C:\Documents and Settings\Brian\Cookies\brian@questionmarket[1].txt
C:\Documents and Settings\Brian\Cookies\brian@serving-sys[2].txt
C:\Documents and Settings\Brian\Cookies\brian@trafficmp[1].txt
C:\Documents and Settings\Brian\Cookies\brian@turn[1].txt
C:\Documents and Settings\Brian\Cookies\brian@web.checkm8[2].txt
C:\Documents and Settings\Brian\err.log
C:\Documents and Settings\Guest.TAWANDA\Application Data\macromedia\Flash Player\#SharedObjects\HGBL6THU\bin.clearspring.com
C:\Documents and Settings\Guest.TAWANDA\Application Data\macromedia\Flash Player\#SharedObjects\HGBL6THU\bin.clearspring.com \clearspring.sol
C:\Documents and Settings\Guest.TAWANDA\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin .clearspring.com
C:\Documents and Settings\Guest.TAWANDA\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin .clearspring.com\settings.sol
C:\Documents and Settings\Guest.TAWANDA\Cookies\guest@ad.yieldmanag er[1].txt
C:\Documents and Settings\Guest.TAWANDA\Cookies\guest@ad.yieldmanag er[3].txt
C:\Documents and Settings\Guest.TAWANDA\Cookies\guest@insightexpres sai[1].txt
C:\Documents and Settings\Guest.TAWANDA\Cookies\guest@precisionclic k[2].txt
C:\Documents and Settings\Guest.TAWANDA\Cookies\guest@trafficmp[1].txt
C:\Documents and Settings\Guest.TAWANDA\err.log
C:\Documents and Settings\Lil Brian\Application Data\macromedia\Flash Player\#SharedObjects\W3VG5LB7\bin.clearspring.com
C:\Documents and Settings\Lil Brian\Application Data\macromedia\Flash Player\#SharedObjects\W3VG5LB7\bin.clearspring.com \clearspring.sol
C:\Documents and Settings\Lil Brian\Application Data\macromedia\Flash Player\#SharedObjects\W3VG5LB7\interclick.com
C:\Documents and Settings\Lil Brian\Application Data\macromedia\Flash Player\#SharedObjects\W3VG5LB7\interclick.com\ud.s ol
C:\Documents and Settings\Lil Brian\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin .clearspring.com
C:\Documents and Settings\Lil Brian\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin .clearspring.com\settings.sol
C:\Documents and Settings\Lil Brian\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#int erclick.com
C:\Documents and Settings\Lil Brian\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#int erclick.com\settings.sol
C:\Documents and Settings\Lil Brian\Cookies\lil_brian@a.hasbro[2].txt
C:\Documents and Settings\Lil Brian\Cookies\lil_brian@ad.yieldmanager[2].txt
C:\Documents and Settings\Lil Brian\Cookies\lil_brian@ads.pointroll[1].txt
C:\Documents and Settings\Lil Brian\Cookies\lil_brian@advertising[1].txt
C:\Documents and Settings\Lil Brian\Cookies\lil_brian@ehg-dig.hitbox[2].txt
C:\Documents and Settings\Lil Brian\Cookies\lil_brian@insightexpressai[2].txt
C:\Documents and Settings\Lil Brian\Cookies\lil_brian@shopzilla[1].txt
C:\Documents and Settings\Lil Brian\err.log
C:\Documents and Settings\Twan\Application Data\macromedia\Flash Player\#SharedObjects\BZ49SG9J\bin.clearspring.com
C:\Documents and Settings\Twan\Application Data\macromedia\Flash Player\#SharedObjects\BZ49SG9J\bin.clearspring.com \clearspring.sol
C:\Documents and Settings\Twan\Application Data\macromedia\Flash Player\#SharedObjects\BZ49SG9J\interclick.com
C:\Documents and Settings\Twan\Application Data\macromedia\Flash Player\#SharedObjects\BZ49SG9J\interclick.com\ud.s ol
C:\Documents and Settings\Twan\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin .clearspring.com
C:\Documents and Settings\Twan\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin .clearspring.com\settings.sol
C:\Documents and Settings\Twan\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#int erclick.com
C:\Documents and Settings\Twan\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#int erclick.com\settings.sol
C:\Documents and Settings\Twan\err.log
C:\temp\
0b9
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\abW9
C:\Temp\abW9\tPho.log
C:\Temp\fse
C:\WINDOWS\BM9b176ae3.txt
C:\WINDOWS\BM9b176ae3.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system\oeminfo.ini
C:\WINDOWS\system32\aaiouy.dll
C:\WINDOWS\system32\adwuckpe.dll
C:\WINDOWS\system32\c1
C:\WINDOWS\system32\dshuubqi.dll
C:\WINDOWS\system32\dwwmqsow.ini
C:\WINDOWS\system32\f10WtR
C:\WINDOWS\system32\ieucgqwx.dll
C:\WINDOWS\system32\ifcgzd.dll
C:\WINDOWS\system32\itrqvw.dll
C:\WINDOWS\system32\ixvtwvau.ini
C:\WINDOWS\system32\jetocxdt.ini
C:\WINDOWS\system32\jtnmuowf.ini
C:\WINDOWS\system32\kkqpervj.ini
C:\WINDOWS\system32\mdm.exe
C:\WINDOWS\system32\mjekcgvm.dll
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\mxpdgrrw.ini
C:\WINDOWS\system32\nagdwd.dll
C:\WINDOWS\system32\osbpusly.ini
C:\WINDOWS\system32\pqmyrrgg.dll
C:\WINDOWS\system32\rMa02yy
C:\WINDOWS\system32\stera.log
C:\WINDOWS\system32\ufphwwkm.dll
C:\WINDOWS\system32\uiwrjtul.dll
C:\WINDOWS\system32\wktvdk.dll
C:\WINDOWS\SYSTEM32\wslucmmi.ini
C:\WINDOWS\system32\xefpmdba.ini
C:\WINDOWS\system32\xjqprlhj.dll
C:\WINDOWS\system32\yfhjldbo.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_FOPN
-------\Legacy_SYSREST.SYS
((((((((((((((((((((((((( Files Created from 2008-08-02 to 2008-09-02 )))))))))))))))))))))))))))))))
.
2008-08-28 09:51 . 2008-08-28 09:51 <DIR> d-------- C:\WINDOWS\SYSTEM32\wTR19
2008-08-28 09:51 . 2008-08-28 09:51 <DIR> d-------- C:\Temp\dax41
2008-08-28 09:51 . 2008-08-28 12:12 422 --a------ C:\WINDOWS\VRM_Free.exe.ini
2008-08-22 20:17 . 2008-08-22 20:17 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-08-22 20:12 . 2008-08-22 20:12 <DIR> d-------- C:\Documents and Settings\Twan\Application Data\DivX
2008-08-21 22:53 . 2001-03-30 14:24 181,760 --a------ C:\WINDOWS\patchw32.dll
2008-08-21 22:44 . 2008-08-21 22:44 <DIR> d-------- C:\Program Files\McAfee UnInstaller 6.5 Demo English
2008-08-21 15:16 . 2008-08-21 15:16 <DIR> d-------- C:\Documents and Settings\Brian\Application Data\Malwarebytes
2008-08-20 21:34 . 2008-08-20 21:34 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-08-20 21:34 . 2008-08-20 21:34 <DIR> d-------- C:\Documents and Settings\Twan\Application Data\Malwarebytes
2008-08-20 21:34 . 2008-08-20 21:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-20 21:34 . 2008-08-17 15:01 38,472 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mbamswissarmy.sys
2008-08-20 21:34 . 2008-08-17 15:01 17,144 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mbam.sys
2008-08-19 23:23 . 2008-08-19 23:23 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-19 22:55 . 2008-08-19 22:55 <DIR> d-------- C:\Program Files\Avira
2008-08-19 22:55 . 2008-08-19 22:55 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-08-12 17:10 . 2005-06-21 23:43 163,840 --a------ C:\WINDOWS\SYSTEM32\igfxres.dll
2008-08-12 17:03 . 2005-06-22 00:04 61,440 --a------ C:\WINDOWS\SYSTEM32\iAlmCoIn_v4342.dll
2008-08-12 15:27 . 2004-08-04 07:00 28,288 --a--c--- C:\WINDOWS\SYSTEM32\DLLCACHE\xjis.nls
2008-08-12 15:25 . 2004-08-04 07:00 1,875,968 --a--c--- C:\WINDOWS\SYSTEM32\DLLCACHE\msir3jp.lex
2008-08-12 15:24 . 2004-08-04 07:00 13,463,552 --a--c--- C:\WINDOWS\SYSTEM32\DLLCACHE\hwxjpn.dll
2008-08-12 15:23 . 2004-08-04 07:00 1,677,824 --a--c--- C:\WINDOWS\SYSTEM32\DLLCACHE\chsbrkr.dll
2008-08-12 15:22 . 2004-08-04 07:00 2,134,528 --a--c--- C:\WINDOWS\SYSTEM32\DLLCACHE\smtpsnap.dll
2008-08-12 15:18 . 2008-08-12 15:18 749 -rah----- C:\WINDOWS\WindowsShell.Manifest
2008-08-12 15:18 . 2008-08-12 15:18 749 -rah----- C:\WINDOWS\SYSTEM32\wuaucpl.cpl.manifest
2008-08-12 15:18 . 2008-08-12 15:18 749 -rah----- C:\WINDOWS\SYSTEM32\sapi.cpl.manifest
2008-08-12 15:18 . 2008-08-12 15:18 749 -rah----- C:\WINDOWS\SYSTEM32\nwc.cpl.manifest
2008-08-12 15:18 . 2008-08-12 15:18 749 -rah----- C:\WINDOWS\SYSTEM32\ncpa.cpl.manifest
2008-08-12 15:18 . 2008-08-12 15:18 488 -rah----- C:\WINDOWS\SYSTEM32\logonui.exe.manifest
2008-08-12 15:17 . 2004-08-04 07:00 16,384 --a--c--- C:\WINDOWS\SYSTEM32\DLLCACHE\isignup.exe
2008-08-12 15:15 . 2004-08-04 07:00 358,912 --a--c--- C:\WINDOWS\SYSTEM32\DLLCACHE\wmic.exe
2008-08-12 15:15 . 2004-08-04 07:00 92,672 --a--c--- C:\WINDOWS\SYSTEM32\DLLCACHE\policman.dll
2008-08-09 12:56 . 2008-08-09 13:09 <DIR> d-------- C:\WINDOWS\SYSTEM32\CatRoot_bak
2008-08-09 11:30 . 2008-08-09 11:30 <DIR> d-------- C:\Documents and Settings\Lil Brian\Application Data\Nero
2008-08-02 23:34 . 2008-08-02 23:34 <DIR> d-------- C:\WINDOWS\SYSTEM32\scripting
2008-08-02 23:34 . 2008-08-02 23:34 <DIR> d-------- C:\WINDOWS\l2schemas
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-08-28 15:10 --------- d-s---w C:\Program Files\mIRC Power Pack
2008-08-28 14:39 --------- d-----w C:\Documents and Settings\Brian\Application Data\HPAppData
2008-08-28 04:22 --------- d-----w C:\Documents and Settings\Twan\Application Data\HPAppData
2008-08-26 23:10 --------- d-----w C:\Program Files\McAfee.com
2008-08-22 03:46 --------- d-----w C:\Program Files\McAfee
2008-08-21 21:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-08-20 01:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-20 00:53 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-08-15 18:44 --------- d-----w C:\Documents and Settings\Brian\Application Data\phpDesigner 2008
2008-08-12 22:36 --------- d-----w C:\Program Files\Yahoo!
2008-08-12 22:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-08-09 16:59 29,184 ----a-w C:\WINDOWS\system32\drivers\goprot51.sys
2008-08-09 04:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-08-08 22:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\yahoo!
2008-07-22 15:40 --------- d-----w C:\Documents and Settings\Brian\Application Data\Yahoo!
2008-07-13 05:36 --------- d-----w C:\Documents and Settings\Brian\Application Data\Nero8
2008-07-11 18:28 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-07-03 05:10 --------- d-----w C:\Program Files\MagicISO
2008-07-03 04:41 47,360 ----a-w C:\Documents and Settings\Brian\Application Data\pcouffin.sys
2008-07-03 04:41 --------- d-----w C:\Documents and Settings\Brian\Application Data\Vso
2008-07-03 04:34 87,608 ----a-w C:\Documents and Settings\Brian\Application Data\ezpinst.exe
2008-07-03 04:25 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-02 23:12 --------- d-----w C:\Documents and Settings\Twan\Application Data\Nero
2008-07-02 17:36 --------- d-----w C:\Documents and Settings\Brian\Application Data\Nero
2008-07-02 17:33 --------- d-----w C:\Program Files\Common Files\Nero
2008-07-02 17:27 --------- d-----w C:\Program Files\Nero
2008-07-02 17:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2008-07-02 17:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\LightScribe
2008-07-02 16:42 --------- d-----w C:\Program Files\Ahead
2008-07-02 16:41 --------- d-----w C:\Program Files\Common Files\Ahead
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\SYSTEM32\mswsock(3).dll
2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\SYSTEM32\dnsapi(3).dll
2006-11-25 00:57 9,583,328 ----a-w C:\Documents and Settings\Lil Brian\DesktopDoctor1.5.4.exe
2006-03-03 23:49 284 ----a-w C:\Documents and Settings\Brian\Application Data\ViewerApp.dat
2005-07-16 20:29 3,932 ----a-w C:\Documents and Settings\Twan\Application Data\LMLayout.dat
2005-07-16 20:29 268 ----a-w C:\Documents and Settings\Twan\Application Data\LMCPaper.dat
2005-05-09 18:20 3,932 -c--a-w C:\Documents and Settings\Brian\Application Data\LMLayout.dat
2005-05-09 18:20 268 ----a-w C:\Documents and Settings\Brian\Application Data\LMCPaper.dat
2002-01-18 12:52 3,932 -c----w C:\Documents and Settings\LocalService\Application Data\LMLayout.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00 15360]
"EasyLinkAdvisor"="C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe" [2006-04-02 20:07 389120]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 09:42 2156368]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\RunOnce]
"DelayShred"="C:\Program Files\McAfee\McAfee Shared Components\Shredder 5\SHRED32.EXE" [2004-08-15 17:10 57344]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"DwlClient"="C:\Program Files\Common Files\Dell\EUSW\Support.exe" [2004-05-27 20:05 323584]
"BJCFD"="C:\Program Files\BroadJump\Client Foundation\CFD.exe" [2002-09-10 21:26 368706]
"ddoctorv2"="C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" [2007-04-19 14:21 198184]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-05-19 18:51 185896]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 21:17 49152]
"hpqSRMon"="C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 16:31 80896]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-06-21 23:48 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-06-21 23:44 126976]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 14:28 266497]
"MCUpdateExe"="c:\PROGRA~1\mcafee.com\agent\mcupda te.exe" [2006-01-11 12:05 212992]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-11-15 00:43 286720]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 03:59 122880 C:\WINDOWS\BCMSMMSG.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 20:38:52 214360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.CTRX"= ctrxvid.drv
"vidc.xvid"= xvid.dll
"VIDC.PIXL"= pclepixl.dll
"VIDC.NTN1"= NUVision.ax
"msacm.dvacm"= C:\PROGRA~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm
"VIDC.MJPG"= pvmjpg21.dll
"VIDC.PIM1"= pclepim1.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\contro l\securityproviders]
SecurityProviders msapsspc.dllschannel.dlldigest.dllmsnsspc.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Picture Package Menu.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Picture Package Menu.lnk
backup=C:\WINDOWS\pss\Picture Package Menu.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Picture Package VCD Maker.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Picture Package VCD Maker.lnk
backup=C:\WINDOWS\pss\Picture Package VCD Maker.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Brian^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\Brian\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Twan^Start Menu^Programs^Startup^PowerReg Scheduler V3.exe]
path=C:\Documents and Settings\Twan\Start Menu\Programs\Startup\PowerReg Scheduler V3.exe
backup=C:\WINDOWS\pss\PowerReg Scheduler V3.exeStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-11-15 14:11 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
--a------ 2005-01-18 16:07 196608 C:\Program Files\Logitech\Video\ManifestEngine.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
--a------ 2005-01-18 16:47 458752 C:\Program Files\Logitech\Video\ISStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
--a------ 2005-01-18 16:37 217088 C:\Program Files\Logitech\Video\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\McAfee QuickClean Imonitor]
--a------ 2004-08-25 05:00 94208 C:\Program Files\McAfee\McAfee QuickClean\PlgUni.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCAgentExe]
--a------ 2005-09-22 18:29 303104 c:\PROGRA~1\McAfee.com\Agent\mcagent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe]
--a------ 2006-01-11 12:05 212992 C:\PROGRA~1\McAfee.com\Agent\mcupdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
--a--c--- 2004-01-26 10:46 53248 C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
--a--c--- 2003-06-18 12:00 200704 C:\Program Files\Microsoft Money\System\mnyexpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 11:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
--a------ 2007-08-08 09:25 1828136 C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 15:57 153136 C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-11-15 00:43 286720 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
--a------ 2007-04-23 11:43 228088 C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-05-19 18:51 185896 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
--a--c--- 2003-08-19 01:01 110592 C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2006-06-16 13:37 3334144 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\mIRC\\mirc.exe"=
"C:\\Program Files\\mIRC Power Pack\\mirc.exe"=
"C:\\Program Files\\Roxio\\Media Manager 9\\MediaManager9.exe"=
"C:\\Program Files\\Roxio\\Digital Home 9\\RoxioUPnPRenderer9.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Roxio\\Digital Home 9\\RoxioUpnpService9.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\FileZilla\\FileZilla.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
S3 ACCSKMD;Canon Camera Storage Device;C:\WINDOWS\system32\DRIVERS\accskmd.sys [2002-06-26 21:44]
S3 NUVision;Pinnacle DVC 80 Video;C:\WINDOWS\system32\DRIVERS\nuvvid2.sys [2001-12-03 11:55]
S3 RimSerPort;RIM Virtual Serial Port;C:\WINDOWS\system32\DRIVERS\RimSerial.sys [2007-01-18 10:24]
S3 SNDP610;Dual Mode Camera;C:\WINDOWS\system32\DRIVERS\sndp610.sys [2005-09-27 21:48]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{3e59f94f-6f71-11dc-9913-000bdbc30874}]
\Shell\AutoRun\command - H:\setup.exe
.
Contents of the 'Scheduled Tasks' folder
2008-09-02 C:\WINDOWS\Tasks\A91B0D959184854D.job
- c:\progra~1\messvi~1\defy list extra.exe []
2008-09-02 C:\WINDOWS\Tasks\AEDD15C0930E88D8.job
- c:\progra~1\messvi~1\defy list extra.exe []
2008-08-20 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]
2008-09-02 C:\WINDOWS\Tasks\User_Feed_Synchronization-{712559F0-C4DB-4491-91AF-E57B2F42A15F}.job
- C:\WINDOWS\system32\msfeedssync.exe [2007-08-13 18:36]
.
- - - - ORPHANS REMOVED - - - -
BHO-{8009FB22-1663-4A8C-9EDC-442B1D141218} - (no file)
BHO-{AEA4DE5E-37ED-4A91-A883-6D8953A84614} - (no file)
BHO-{B7E90E0E-0CCC-4D48-957F-6B3766D0D928} - (no file)
MSConfigStartUp-Filmatom - C:\PROGRA~1\MESSVI~1\AudioSect.exe
MSConfigStartUp-KAZAA - C:\Program Files\Kazaa\kazaa.exe
MSConfigStartUp-LDM - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
MSConfigStartUp-LightScribe Control Panel - C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
MSConfigStartUp-MPFExe - C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
MSConfigStartUp-MsnMsgr - C:\Program Files\MSN Messenger\msnmsgr.exe
MSConfigStartUp-MySpaceIM - C:\Program Files\MySpace\IM\MySpaceIM.exe
MSConfigStartUp-VirusScan Online - c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
MSConfigStartUp-VSOCheckTask - c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe
MSConfigStartUp-WatchDog - C:\Program Files\mobile PhoneTools\WatchDog.exe
MSConfigStartUp-WinampAgent - C:\Program Files\Winamp\winampa.exe
MSConfigStartUp-POINTER - point32.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source? }
R0 -: HKCU-Main,Start Page = hxxp://www.yahoo.com
R0 -: HKLM-Main,Start Page = hxxp://www.yahoo.com
R0 -: HKLM-Main,Window Title = Windows Internet Explorer provided by Comcast
R1 -: HKCU-Internet Settings,ProxyOverride = localhost
O9 -: {669B269B-0D4E-41FB-A3D8-FD67CA94F646} -
Comcast.net Home
O9 -: {8828075D-D097-4055-AA02-2DBFA9D85E8A} -
Comcast Help & Support
O9 -: {97809617-3937-4F84-B335-9BB05EF1A8D4} -
Comcast Help & Support
O15 -: Trusted Zone: *.avsystemcare.com
O15 -: Trusted Zone: *.onerateld.com
O15 -: Trusted Zone: *.safetydownload.com
O15 -: Trusted Zone: *.trustedantivirus.com
O15 -: Trusted Zone: *.virusschlacht.com
O18 -: Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O16 -: Microsoft XML Parser for Java - file://C:\WINDOWS\Java\classes\xmldso.cab
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
O16 -: Starfield Technologies - hxxp://video.secureserver.net/plugins/starfield_technologies.CAB
C:\WINDOWS\Downloaded Program Files\starfield_technologies.OSD
C:\WINDOWS\Downloaded Program Files\starfield_technologies.dll
O16 -: {42D06124-98A2-47EC-8098-3778B58CE7D5} - hxxps://actsvr.comcastonline.com/techtools/dl/Comcast%20Activation%20Controls.cab
C:\WINDOWS\Downloaded Program Files\sprtexternal.inf
C:\Program Files\Support.com\bin\65\tgctlsi.dll
C:\WINDOWS\Downloaded Program Files\sprtexternal.dll
O16 -: {475DF11A-2BC2-41A9-8A97-E989E023E517} - hxxp://gw.us.hanjin.com/ezIcd.cab
C:\WINDOWS\Downloaded Program Files\ezIcd_dll.inf
C:\WINDOWS\Downloaded Program Files\ez3DES.dll
C:\WINDOWS\Downloaded Program Files\ezIcd.dll
.
.
------- File Associations (Beta) -------
.
regfile=regedit.exe "%1" %*
.
************************************************** ************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-09-01 20:51:24
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\McAfee.com\Agent\Mcdetect.exe
C:\PROGRA~1\McAfee.com\Agent\McTskshd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\WINDOWS\SYSTEM32\wscntfy.exe
C:\WINDOWS\SYSTEM32\msiexec.exe
C:\WINDOWS\SYSTEM32\msiexec.exe
.
************************************************** ************************
.
Completion time: 2008-09-01 21:14:08 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-02 02:13:44
ComboFix2.txt 2007-05-27 03:16:46
Pre-Run: 7,345,688,576 bytes free
Post-Run: 11,401,531,392 bytes free
424 --- E O F --- 2008-09-02 02:01:22