here they are!
ComboFix 08-07-31.01 - angela 2008-08-01 19:11:06.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.208 [GMT -7:00]
Running from: C:\Documents and Settings\angela\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\angela\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2008-07-02 to 2008-08-02 )))))))))))))))))))))))))))))))
.
2008-07-31 20:30 . 2008-07-31 20:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Gogii
2008-07-29 20:48 . 2008-07-29 20:48 <DIR> d-------- C:\Documents and Settings\angela\Application Data\Malwarebytes
2008-07-29 20:48 . 2008-07-29 20:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-28 09:15 . 2008-07-28 09:15 <DIR> d-------- C:\WINDOWS\system32\Adobe
2008-07-28 03:05 . 2008-07-28 03:05 <DIR> d-------- C:\Deckard
2008-07-21 12:57 . 2008-07-21 12:56 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-07-21 12:56 . 2008-07-21 13:34 <DIR> d-------- C:\Documents and Settings\angela\.housecall6.6
2008-07-21 12:49 . 2008-07-22 15:55 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-20 15:41 . 2008-07-20 15:41 <DIR> d-------- C:\Documents and Settings\angela\Application Data\Ahead
2008-07-20 15:41 . 2008-07-20 15:41 0 --a------ C:\WINDOWS\Irremote.ini
2008-07-20 15:01 . 2008-07-20 15:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Ahead
2008-07-20 14:34 . 2008-07-20 14:34 <DIR> d-------- C:\Program Files\Nero
2008-07-20 14:34 . 2008-07-21 09:51 <DIR> d-------- C:\Program Files\Common Files\Ahead
2008-07-20 14:34 . 2008-07-20 14:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-07-19 11:08 . 2008-07-20 09:29 <DIR> d-------- C:\Documents and Settings\angela\Application Data\muvee Technologies
2008-07-18 10:14 . 2008-07-31 07:03 <DIR> d--h----- C:\$AVG8.VAULT$
2008-07-18 10:00 . 2008-07-18 10:00 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-07-18 08:12 . 2008-08-01 17:05 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-07-18 08:12 . 2008-07-18 10:00 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-07-18 08:12 . 2008-07-18 10:01 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-07-18 08:11 . 2008-07-18 08:11 <DIR> d-------- C:\Program Files\AVG
2008-07-18 08:11 . 2008-07-18 08:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-07-17 21:05 . 2008-07-18 07:52 <DIR> d--hs---- C:\WINDOWS\ZGF5
2008-07-17 10:48 . 2008-07-17 10:48 149 --a------ C:\WINDOWS\wininit.ini
2008-07-17 09:56 . 2008-07-18 14:59 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-07-17 09:56 . 2008-07-18 15:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-17 08:45 . 2008-07-17 09:24 <DIR> d---s---- C:\Documents and Settings\Administrator
2008-07-16 08:48 . 2008-07-16 08:40 109,568 --a------ C:\WINDOWS\system32\pxinsi64.exe
2008-07-16 08:48 . 2008-07-16 08:40 108,544 --a------ C:\WINDOWS\system32\pxcpyi64.exe
2008-07-14 17:24 . 2008-07-14 17:25 <DIR> d-------- C:\Documents and Settings\angela\Application Data\gtk-2.0
2008-07-14 17:23 . 2008-07-14 17:26 <DIR> d-------- C:\Documents and Settings\angela\.gimp-2.4
2008-07-14 14:36 . 2008-07-14 14:36 <DIR> d-------- C:\Program Files\Aurora Digital Imaging
2008-07-14 14:34 . 2008-07-14 14:34 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-07-14 09:10 . 2008-07-14 09:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-14 07:32 . 2008-07-14 07:32 <DIR> d-------- C:\Program Files\Windows Defender
2008-07-14 06:27 . 2008-07-14 06:27 <DIR> d-------- C:\WINDOWS\system32\URTTEMP
2008-07-14 06:18 . 2008-07-14 13:54 2,582 --ahs---- C:\WINDOWS\system32\cffMVvut.ini
2008-07-14 06:13 . 2008-07-15 05:28 <DIR> d-------- C:\WINDOWS\system32\olixds18
2008-07-14 06:13 . 2008-07-31 19:24 <DIR> d-------- C:\Temp
2008-07-13 14:18 . 2008-07-13 14:18 <DIR> d-------- C:\Documents and Settings\angela\Application Data\FastStone
2008-07-10 22:12 . 2008-07-10 22:12 <DIR> d-------- C:\Program Files\iPod
2008-07-10 21:54 . 2008-07-10 21:54 <DIR> d-------- C:\Program Files\Safari
2008-07-02 12:28 . 2008-07-02 12:28 <DIR> d-------- C:\Program Files\DVDVideoSoft
2008-07-02 12:28 . 2008-07-14 10:42 <DIR> d-------- C:\Program Files\Common Files\DVDVideoSoft
2008-07-02 12:28 . 2008-07-02 16:14 <DIR> d-------- C:\DVDVideoSoft
2008-07-02 12:28 . 2002-01-05 15:37 344,064 --a------ C:\WINDOWS\system32\msvcr70.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-08-02 02:14 --------- d-----w C:\Documents and Settings\angela\Application Data\Skype
2008-07-22 16:29 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-21 23:45 --------- d-----w C:\Program Files\Picasa2
2008-07-20 20:50 --------- d-----w C:\Program Files\Ahead
2008-07-20 13:33 --------- d-----w C:\Program Files\Incomplete
2008-07-16 16:42 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-14 22:18 129 ----a-w C:\WINDOWS\Fonts\1001freefonts.txt
2008-07-14 20:36 --------- d-----w C:\Program Files\Java
2008-07-13 14:03 --------- d-----w C:\Documents and Settings\angela\Application Data\Apple Computer
2008-07-11 05:12 --------- d-----w C:\Program Files\iTunes
2008-07-11 05:08 --------- d-----w C:\Program Files\QuickTime
2008-07-10 16:35 32,000 ----a-w C:\WINDOWS\system32\drivers\usbaapl.sys
2008-07-02 23:16 --------- d-----w C:\Program Files\Flypaper Beta
2008-07-02 00:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\IsolatedStorage
2008-07-02 00:24 --------- d-----w C:\Program Files\MSBuild
2008-07-02 00:23 --------- d-----w C:\Program Files\Reference Assemblies
2008-07-02 00:17 --------- d-----w C:\Program Files\MSXML 6.0
2008-06-29 04:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-19 23:02 --------- d-----w C:\Documents and Settings\Jen\Application Data\Apple Computer
2008-06-13 13:10 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-10 10:04 --------- d-----w C:\Program Files\Microsoft Works
2008-06-08 17:38 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-05-13 16:12 33,280 ----a-w C:\WINDOWS\system32\HUFFYUV.DLL
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-07 20:00 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2008-04-07 00:38 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2006-09-29 17:25 21871656]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2008-02-25 18:23 443968]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 09:47 116040]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 10:50 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-10 10:51 289064]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-18 10:01 1232152]
"MSConfig"="C:\WINDOWS\pchealth\helpctr\Binaries\M SCONFIG.EXE" [2004-08-04 05:00 158208]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 57344 C:\WINDOWS\Alcxmntr.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1 \DW\dwtrig20.exe" [2007-03-22 19:29 39264]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.HFYU"= huffyuv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
--------- 2008-07-07 09:42 2156368 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\ \SAGENT4.EXE"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-18 10:00]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-07-18 10:00]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-18 10:00]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-18 10:01]
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{9ef3de30-ff49-11dc-9a4a-806d6172696f}]
\Shell\AutoRun\command - E:\Info.exe folder.htt 480 480
.
Contents of the 'Scheduled Tasks' folder
2008-07-19 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]
2008-08-02 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
2008-08-01 C:\WINDOWS\Tasks\MP Scheduled Scan.job
- C:\Program Files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.
.
------- Supplementary Scan -------
.
O8 -: &Windows Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 -: Add to Windows &Live Favorites -
Add to Windows Live Favorites
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O18 -: Handler: trendprotect - {BC3A5F6F-12A0-4B14-A184-32939F413823} - C:\Program Files\Trend Micro\TrendProtect\MSIE\WRS.dll
************************************************** ************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-08-01 19:14:59
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
Completion time: 2008-08-01 19:29:03
ComboFix-quarantined-files.txt 2008-08-02 02:28:58
ComboFix2.txt 2008-08-01 15:13:12
ComboFix3.txt 2008-08-01 02:53:10
ComboFix4.txt 2008-07-31 06:35:11
Pre-Run: 9,740,943,360 bytes free
Post-Run: 9,714,749,440 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOW S
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Micro soft Windows XP Home Edition" /noexecute=optin /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
177 --- E O F --- 2008-08-01 10:03:02
ComboFix 08-07-31.01 - angela 2008-08-01 19:11:06.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.208 [GMT -7:00]
Running from: C:\Documents and Settings\angela\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\angela\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2008-07-02 to 2008-08-02 )))))))))))))))))))))))))))))))
.
2008-07-31 20:30 . 2008-07-31 20:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Gogii
2008-07-29 20:48 . 2008-07-29 20:48 <DIR> d-------- C:\Documents and Settings\angela\Application Data\Malwarebytes
2008-07-29 20:48 . 2008-07-29 20:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-28 09:15 . 2008-07-28 09:15 <DIR> d-------- C:\WINDOWS\system32\Adobe
2008-07-28 03:05 . 2008-07-28 03:05 <DIR> d-------- C:\Deckard
2008-07-21 12:57 . 2008-07-21 12:56 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-07-21 12:56 . 2008-07-21 13:34 <DIR> d-------- C:\Documents and Settings\angela\.housecall6.6
2008-07-21 12:49 . 2008-07-22 15:55 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-20 15:41 . 2008-07-20 15:41 <DIR> d-------- C:\Documents and Settings\angela\Application Data\Ahead
2008-07-20 15:41 . 2008-07-20 15:41 0 --a------ C:\WINDOWS\Irremote.ini
2008-07-20 15:01 . 2008-07-20 15:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Ahead
2008-07-20 14:34 . 2008-07-20 14:34 <DIR> d-------- C:\Program Files\Nero
2008-07-20 14:34 . 2008-07-21 09:51 <DIR> d-------- C:\Program Files\Common Files\Ahead
2008-07-20 14:34 . 2008-07-20 14:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-07-19 11:08 . 2008-07-20 09:29 <DIR> d-------- C:\Documents and Settings\angela\Application Data\muvee Technologies
2008-07-18 10:14 . 2008-07-31 07:03 <DIR> d--h----- C:\$AVG8.VAULT$
2008-07-18 10:00 . 2008-07-18 10:00 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-07-18 08:12 . 2008-08-01 17:05 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-07-18 08:12 . 2008-07-18 10:00 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-07-18 08:12 . 2008-07-18 10:01 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-07-18 08:11 . 2008-07-18 08:11 <DIR> d-------- C:\Program Files\AVG
2008-07-18 08:11 . 2008-07-18 08:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-07-17 21:05 . 2008-07-18 07:52 <DIR> d--hs---- C:\WINDOWS\ZGF5
2008-07-17 10:48 . 2008-07-17 10:48 149 --a------ C:\WINDOWS\wininit.ini
2008-07-17 09:56 . 2008-07-18 14:59 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-07-17 09:56 . 2008-07-18 15:10 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-17 08:45 . 2008-07-17 09:24 <DIR> d---s---- C:\Documents and Settings\Administrator
2008-07-16 08:48 . 2008-07-16 08:40 109,568 --a------ C:\WINDOWS\system32\pxinsi64.exe
2008-07-16 08:48 . 2008-07-16 08:40 108,544 --a------ C:\WINDOWS\system32\pxcpyi64.exe
2008-07-14 17:24 . 2008-07-14 17:25 <DIR> d-------- C:\Documents and Settings\angela\Application Data\gtk-2.0
2008-07-14 17:23 . 2008-07-14 17:26 <DIR> d-------- C:\Documents and Settings\angela\.gimp-2.4
2008-07-14 14:36 . 2008-07-14 14:36 <DIR> d-------- C:\Program Files\Aurora Digital Imaging
2008-07-14 14:34 . 2008-07-14 14:34 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-07-14 09:10 . 2008-07-14 09:12 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-14 07:32 . 2008-07-14 07:32 <DIR> d-------- C:\Program Files\Windows Defender
2008-07-14 06:27 . 2008-07-14 06:27 <DIR> d-------- C:\WINDOWS\system32\URTTEMP
2008-07-14 06:18 . 2008-07-14 13:54 2,582 --ahs---- C:\WINDOWS\system32\cffMVvut.ini
2008-07-14 06:13 . 2008-07-15 05:28 <DIR> d-------- C:\WINDOWS\system32\olixds18
2008-07-14 06:13 . 2008-07-31 19:24 <DIR> d-------- C:\Temp
2008-07-13 14:18 . 2008-07-13 14:18 <DIR> d-------- C:\Documents and Settings\angela\Application Data\FastStone
2008-07-10 22:12 . 2008-07-10 22:12 <DIR> d-------- C:\Program Files\iPod
2008-07-10 21:54 . 2008-07-10 21:54 <DIR> d-------- C:\Program Files\Safari
2008-07-02 12:28 . 2008-07-02 12:28 <DIR> d-------- C:\Program Files\DVDVideoSoft
2008-07-02 12:28 . 2008-07-14 10:42 <DIR> d-------- C:\Program Files\Common Files\DVDVideoSoft
2008-07-02 12:28 . 2008-07-02 16:14 <DIR> d-------- C:\DVDVideoSoft
2008-07-02 12:28 . 2002-01-05 15:37 344,064 --a------ C:\WINDOWS\system32\msvcr70.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-08-02 02:14 --------- d-----w C:\Documents and Settings\angela\Application Data\Skype
2008-07-22 16:29 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-21 23:45 --------- d-----w C:\Program Files\Picasa2
2008-07-20 20:50 --------- d-----w C:\Program Files\Ahead
2008-07-20 13:33 --------- d-----w C:\Program Files\Incomplete
2008-07-16 16:42 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-14 22:18 129 ----a-w C:\WINDOWS\Fonts\1001freefonts.txt
2008-07-14 20:36 --------- d-----w C:\Program Files\Java
2008-07-13 14:03 --------- d-----w C:\Documents and Settings\angela\Application Data\Apple Computer
2008-07-11 05:12 --------- d-----w C:\Program Files\iTunes
2008-07-11 05:08 --------- d-----w C:\Program Files\QuickTime
2008-07-10 16:35 32,000 ----a-w C:\WINDOWS\system32\drivers\usbaapl.sys
2008-07-02 23:16 --------- d-----w C:\Program Files\Flypaper Beta
2008-07-02 00:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\IsolatedStorage
2008-07-02 00:24 --------- d-----w C:\Program Files\MSBuild
2008-07-02 00:23 --------- d-----w C:\Program Files\Reference Assemblies
2008-07-02 00:17 --------- d-----w C:\Program Files\MSXML 6.0
2008-06-29 04:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-19 23:02 --------- d-----w C:\Documents and Settings\Jen\Application Data\Apple Computer
2008-06-13 13:10 272,128 ----a-w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-10 10:04 --------- d-----w C:\Program Files\Microsoft Works
2008-06-08 17:38 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-05-13 16:12 33,280 ----a-w C:\WINDOWS\system32\HUFFYUV.DLL
2008-05-07 05:18 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-07 20:00 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2008-04-07 00:38 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2006-09-29 17:25 21871656]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2008-02-25 18:23 443968]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 09:47 116040]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 10:50 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-10 10:51 289064]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-18 10:01 1232152]
"MSConfig"="C:\WINDOWS\pchealth\helpctr\Binaries\M SCONFIG.EXE" [2004-08-04 05:00 158208]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 13:47 57344 C:\WINDOWS\Alcxmntr.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1 \DW\dwtrig20.exe" [2007-03-22 19:29 39264]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.HFYU"= huffyuv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
--------- 2008-07-07 09:42 2156368 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\ \SAGENT4.EXE"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-18 10:00]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-07-18 10:00]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-18 10:00]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-07-18 10:01]
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{9ef3de30-ff49-11dc-9a4a-806d6172696f}]
\Shell\AutoRun\command - E:\Info.exe folder.htt 480 480
.
Contents of the 'Scheduled Tasks' folder
2008-07-19 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]
2008-08-02 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
2008-08-01 C:\WINDOWS\Tasks\MP Scheduled Scan.job
- C:\Program Files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.
.
------- Supplementary Scan -------
.
O8 -: &Windows Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 -: Add to Windows &Live Favorites -
Add to Windows Live Favorites
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O18 -: Handler: trendprotect - {BC3A5F6F-12A0-4B14-A184-32939F413823} - C:\Program Files\Trend Micro\TrendProtect\MSIE\WRS.dll
************************************************** ************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-08-01 19:14:59
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
Completion time: 2008-08-01 19:29:03
ComboFix-quarantined-files.txt 2008-08-02 02:28:58
ComboFix2.txt 2008-08-01 15:13:12
ComboFix3.txt 2008-08-01 02:53:10
ComboFix4.txt 2008-07-31 06:35:11
Pre-Run: 9,740,943,360 bytes free
Post-Run: 9,714,749,440 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOW S
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Micro soft Windows XP Home Edition" /noexecute=optin /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
177 --- E O F --- 2008-08-01 10:03:02