here is the combo fix log
ComboFix 08-01-21.7 - Kyle 2008-01-23 17:57:43.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.284 [GMT -6:00]
Running from: C:\Documents and Settings\Kyle.DB4XPK81\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\temp\tn3
C:\WINDOWS\system32\drivers\core.cache.dsk . . . . failed to delete
.
((((((((((((((((((((((((( Files Created from 2007-12-24 to 2008-01-24 )))))))))))))))))))))))))))))))
.
2008-01-23 18:00 . 2008-01-23 18:00 <DIR> d-------- C:\Temp\tn3
2008-01-23 01:23 . 2008-01-23 18:01 58,883 --------- C:\WINDOWS\system32\drivers\core.cache.dsk
2008-01-23 00:58 . 2008-01-23 00:58 <DIR> d-------- C:\WINDOWS\ERUNT
2008-01-23 00:49 . 2008-01-23 00:49 10,344 --a------ C:\WINDOWS\system32\drivers\symlcbrd.sys
2008-01-22 09:42 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\Nircmd.exe
2008-01-21 21:53 . 2007-10-10 17:55 459,264 --------- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-01-21 21:53 . 2007-10-10 17:55 52,224 --------- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-01-21 21:52 . 2007-10-10 17:55 6,065,664 --------- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-01-21 21:52 . 2007-06-30 21:31 2,455,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-01-21 21:52 . 2007-06-30 21:36 991,232 --------- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-01-21 21:52 . 2007-10-10 17:55 383,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-01-21 21:52 . 2007-10-10 17:55 267,776 --------- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-01-21 21:52 . 2007-10-10 17:55 63,488 --------- C:\WINDOWS\system32\dllcache\icardie.dll
2008-01-21 21:52 . 2007-10-10 04:59 13,824 --------- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-01-19 07:02 . 2008-01-19 07:02 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-19 07:02 . 2008-01-19 07:02 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-16 22:29 . 2008-01-16 22:42 <DIR> d-------- C:\N360_BACKUP
2008-01-16 22:07 . 2008-01-16 22:25 <DIR> d-------- C:\Program Files\Norton 360
2008-01-16 22:06 . 2008-01-16 22:19 <DIR> d-------- C:\Program Files\Symantec
2008-01-16 22:06 . 2008-01-16 22:18 115,000 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-01-16 22:06 . 2008-01-16 22:18 48,776 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-01-16 22:06 . 2008-01-16 22:18 8,014 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-01-16 22:06 . 2008-01-16 22:18 806 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-01-16 21:01 . 2008-01-21 22:47 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-01-16 19:32 . 2008-01-16 19:32 <DIR> d-------- C:\WINDOWS\system32\
0B131214110F18
2008-01-16 19:32 . 2007-12-14 06:40 120,832 --a------ C:\WINDOWS\system32\D5DDDCDEDBD9E2.exe
2008-01-16 18:03 . 2008-01-16 18:03 <DIR> d-------- C:\Program Files\Lavasoft
2008-01-16 18:02 . 2008-01-21 22:47 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-16 16:51 . 2008-01-20 16:45 <DIR> d-------- C:\Program Files\CA Yahoo! Anti-Spy
2008-01-16 07:02 . 2008-01-16 07:02 1,061,376 ---hs---- C:\WINDOWS\system32\arbilbfa.ini
2008-01-16 06:53 . 2008-01-16 16:26 15,677 --a------ C:\WINDOWS\BM872575f2.xml
2008-01-16 06:53 . 2008-01-16 06:53 22 --a------ C:\WINDOWS\pskt.ini
2008-01-15 06:45 . 2008-01-15 06:45 86,016 --a------ C:\WINDOWS\system32\drivers\atmarpcc.sys
2008-01-15 06:44 . 2008-01-16 21:57 <DIR> d-------- C:\WINDOWS\system32\edcA01
2008-01-15 06:44 . 2008-01-15 06:45 <DIR> d-------- C:\Temp\Ryuan1
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
2008-01-23 21:05 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-01-22 04:26 --------- d-----w C:\Program Files\Java
2008-01-16 22:51 --------- d-----w C:\Program Files\Common Files\Scanner
2008-01-16 22:50 --------- d-----w C:\Program Files\Yahoo!
2008-01-15 15:09 --------- d-----w C:\Program Files\MUSICMATCH
2008-01-10 01:14 --------- d-----w C:\Program Files\Dl_cats
2007-12-18 01:27 --------- d-----w C:\Program Files\XoftSpySE
2007-12-17 22:22 --------- d-----w C:\Program Files\Windows Live Safety Center
2007-12-14 17:32 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2007-12-01 05:57 43,696 ----a-w C:\WINDOWS\system32\drivers\srtspx.sys
2007-12-01 05:57 317,616 ----a-w C:\WINDOWS\system32\drivers\srtspl.sys
2007-12-01 05:57 279,088 ----a-w C:\WINDOWS\system32\drivers\srtsp.sys
2007-12-01 05:57 10,549 ----a-w C:\WINDOWS\system32\drivers\srtspx.cat
2007-12-01 05:57 10,549 ----a-w C:\WINDOWS\system32\drivers\srtspl.cat
2007-12-01 05:57 10,545 ----a-w C:\WINDOWS\system32\drivers\srtsp.cat
2007-12-01 05:57 1,430 ----a-w C:\WINDOWS\system32\drivers\srtspl.inf
2007-12-01 05:57 1,421 ----a-w C:\WINDOWS\system32\drivers\srtspx.inf
2007-12-01 05:57 1,415 ----a-w C:\WINDOWS\system32\drivers\srtsp.inf
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:26 721,920 ------w C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-10-31 19:03 245,408 ----a-w C:\WINDOWS\system32\unicows.dll
2007-10-31 11:12 3,590,656 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-30 17:20 360,064 ------w C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-29 22:43 1,287,680 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 ------w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-27 23:40 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 23:40 222,720 ----a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
.
((((((((((((((((((((((((((((( snapshot@2008-01-22_ 9.52.25.71 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-01-22 10:53:33 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-01-23 06:58:49 2,224,128 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\
00000001\NTUSER.DAT
+ 2008-01-23 06:58:49 151,552 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\
00000002\UsrClass.dat
+ 2008-01-22 10:53:33 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-01-23 06:58:39 2,224,128 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\
00000001\NTUSER.DAT
+ 2008-01-23 06:58:39 151,552 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\
00000002\UsrClass.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [2007-09-05 15:23 221184]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 05:24 286720]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-07-17 19:54 116072]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Kyle.DB4XPK81^Start Menu^Programs^Startup^MEMonitor.lnk.lnk]
path=C:\Documents and Settings\Kyle.DB4XPK81\Start Menu\Programs\Startup\MEMonitor.lnk.lnk
backup=C:\WINDOWS\pss\MEMonitor.lnk.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMXLauncher]
--a------ 2007-09-05 15:23 86016 C:\Program Files\Dell\Media Experience\DMXLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
--------- 2005-02-23 15:19 53248 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
--a------ 2004-07-27 15:50 221184 C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
--a------ 2004-07-27 15:50 81920 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2005-12-20 19:54 278528 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 10:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QBReminderFlash]
--a------ 2004-11-11 09:26 26112 C:\Program Files\Intuit\QuickBooks 2005\Atom\QBReminder.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-06-29 05:24 286720 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
--a------ 2005-09-28 18:41 26112 C:\Program Files\Real\RealPlayer\RealPlay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
--a------ 2007-09-05 15:23 1404928 C:\Program Files\Analog Devices\Core\smax4pnp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-12-16 17:54 32768 C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
R1 atmarpcc;atmarpcc;C:\WINDOWS\system32\drivers\atma rpcc.sys [2008-01-15 06:45]
S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\WINDOWS\system32\DRIVERS\SymIM.sys []
S3 SymIMMP;SymIMMP;C:\WINDOWS\system32\DRIVERS\SymIM. sys []
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-01-23 17:20:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
************************************************** ************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-23 18:15:35
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
************************************************** ************************
.
Completion time: 2008-01-23 18:17:33 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-24 00:17:11
ComboFix2.txt 2008-01-23 06:55:38
ComboFix3.txt 2008-01-22 15:52:47
.
2008-01-22 09:01:10 --- E O F ---