My computer is running a lot faster now thanks a lot!
heres the log file for ComboFix
ComboFix 08-01-13.1 - Saetern 2008-01-13 12:17:31.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.264 [GMT -8:00]
Running from: C:\Documents and Settings\Saetern\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\QdrDrive
C:\WINDOWS\system32\ctfmon.exe.tmp
C:\WINDOWS\system32\mcrh.tmp
.
((((((((((((((((((((((((( Files Created from 2007-12-13 to 2008-01-13 )))))))))))))))))))))))))))))))
.
2008-01-13 12:16 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-13 01:23 . 2008-01-13 01:23 <DIR> d-------- C:\Documents and Settings\Saetern\Application Data\acccore
2008-01-13 01:19 . 2008-01-13 01:19 <DIR> d-------- C:\Program Files\Viewpoint
2008-01-13 01:19 . 2008-01-13 01:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-01-13 01:19 . 2008-01-13 01:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-01-13 01:18 . 2008-01-13 01:22 <DIR> d-------- C:\Program Files\AIM6
2008-01-13 00:31 . 2008-01-13 00:31 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-13 00:19 . 2008-01-13 00:19 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2008-01-13 00:02 . 2008-01-13 00:02 <DIR> d-------- C:\VundoFix Backups
2008-01-12 03:44 . 2008-01-12 03:44 <DIR> d-------- C:\Documents and Settings\Saetern\Application Data\Lavasoft
2008-01-12 03:43 . 2008-01-12 03:43 <DIR> d-------- C:\Program Files\Lavasoft
2008-01-09 00:41 . 2008-01-09 01:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-09 00:16 . 2005-11-14 17:01 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\You've Got Pictures Screensaver
2008-01-09 00:16 . 2005-11-14 16:29 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\toshiba
2008-01-09 00:16 . 2005-11-14 16:44 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Intuit
2008-01-09 00:16 . 2005-11-14 17:51 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\InterVideo
2008-01-09 00:16 . 2007-12-10 21:12 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AOL
2008-01-08 22:44 . 2008-01-08 22:44 <DIR> d-------- C:\Documents and Settings\Saetern\Application Data\ESET
2007-12-30 21:58 . 2008-01-13 01:27 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-12-30 21:58 . 2007-12-30 21:58 1,409 --a------ C:\WINDOWS\QTFont.for
2007-12-30 21:53 . 2007-12-30 21:53 <DIR> d-------- C:\Documents and Settings\Saetern\Application Data\Apple Computer
2007-12-30 21:52 . 2008-01-08 20:18 <DIR> d-------- C:\Program Files\iTunes
2007-12-30 21:52 . 2007-12-30 21:52 <DIR> d-------- C:\Program Files\iPod
2007-12-30 21:49 . 2007-12-31 03:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-12-30 21:48 . 2007-12-30 21:48 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-12-30 21:48 . 2007-12-30 21:48 <DIR> d-------- C:\Program Files\Apple Software Update
2007-12-30 21:48 . 2007-10-31 14:09 30,464 --a------ C:\WINDOWS\system32\drivers\usbaapl.sys
2007-12-30 21:46 . 2007-12-30 21:46 <DIR> d-------- C:\Program Files\Common Files\Apple
2007-12-30 21:46 . 2007-12-30 21:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2007-12-30 18:30 . 2007-12-30 18:30 <DIR> d-------- C:\Program Files\RcvSystem
2007-12-30 00:04 . 2008-01-12 00:23 15,360 --a------ C:\WINDOWS\system32\ctfmon .exe
2007-12-29 11:10 . 2007-12-29 11:10 32,764 --a------ C:\WINDOWS\17PHolmes11.exe
2007-12-28 11:26 . 2007-12-28 11:26 <DIR> d-------- C:\WINDOWS\Sun
2007-12-24 15:02 . 2007-12-24 15:02 <DIR> d-------- C:\Documents and Settings\Saetern\Application Data\Sonic
2007-12-23 01:06 . 2007-12-23 01:06 <DIR> d-------- C:\Program Files\DivX
2007-12-22 23:29 . 2007-12-22 23:29 <DIR> d-------- C:\Documents and Settings\Saetern\Application Data\Nexon
2007-12-22 23:28 . 2003-07-20 10:17 5,174 --a------ C:\WINDOWS\system32\nppt9x.vxd
2007-12-22 23:28 . 2005-01-04 01:43 4,682 --a------ C:\WINDOWS\system32\npptNT2.sys
2007-12-22 23:23 . 2007-12-22 23:23 <DIR> d-------- C:\Nexon
2007-12-21 08:21 . 2007-12-21 08:21 71,176 --a------ C:\WINDOWS\system32\drivers\epfw.sys
2007-12-21 08:21 . 2007-12-21 08:21 53,768 --a------ C:\WINDOWS\system32\drivers\epfwtdi.sys
2007-12-21 08:21 . 2007-12-21 08:21 30,728 --a------ C:\WINDOWS\system32\drivers\epfwndis.sys
2007-12-21 08:20 . 2007-12-21 08:20 30,216 --a------ C:\WINDOWS\system32\drivers\easdrv.sys
2007-12-21 08:19 . 2007-12-21 08:19 39,944 --a------ C:\WINDOWS\system32\drivers\eamon.sys
2007-12-18 15:42 . 2001-08-17 13:56 7,552 --a------ C:\WINDOWS\system32\drivers\SONYPVU1.SYS
2007-12-18 15:42 . 2001-08-17 13:56 7,552 --a--c--- C:\WINDOWS\system32\dllcache\sonypvu1.sys
2007-12-15 09:51 . 2007-12-15 09:51 <DIR> d-------- C:\Documents and Settings\Saetern\Application Data\AdobeUM
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-13 09:19 --------- d-----w C:\Program Files\Common Files\AOL
2008-01-13 09:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL
2008-01-13 09:15 --------- d-----w C:\Program Files\AIM
2008-01-13 09:15 --------- d-----w C:\Documents and Settings\Saetern\Application Data\Aim
2008-01-12 11:30 --------- d-----w C:\Documents and Settings\Saetern\Application Data\U3
2008-01-09 06:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\ESET
2008-01-09 06:40 --------- d-----w C:\Program Files\QuickTime
2007-12-31 11:06 --------- d-----w C:\Documents and Settings\Saetern\Application Data\Azureus
2007-12-31 02:40 --------- d-----w C:\Program Files\Toshiba
2007-12-24 23:05 --------- d-----w C:\Program Files\Azureus
2007-12-13 04:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-12-13 04:24 --------- d-----w C:\Program Files\Common Files\Adobe
2007-12-13 04:24 --------- d-----w C:\Program Files\Bonjour
2007-12-13 04:17 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
2007-12-11 09:37 --------- d-----w C:\Program Files\Google
2007-12-11 09:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee.com
2007-12-11 09:31 --------- d-----w C:\Program Files\Common Files\Real
2007-12-11 05:14 --------- d-----w C:\Program Files\Pure Networks
2007-12-11 05:12 --------- d-----w C:\Documents and Settings\Saetern\Application Data\AOL
2007-12-11 04:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip
2007-12-11 04:42 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-11 02:04 --------- d-----w C:\Documents and Settings\Saetern\Application Data\Winamp
2007-12-11 00:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Azureus
2007-12-10 08:35 --------- d-----w C:\Program Files\AOD
2007-12-10 08:29 --------- d-----w C:\Program Files\Winamp
2007-12-10 08:27 --------- d-----w C:\Program Files\MSXML 4.0
2007-12-10 08:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-12-10 08:18 --------- d-----w C:\Program Files\MSBuild
2007-12-10 08:18 --------- d-----w C:\Program Files\Microsoft Works
2007-12-10 08:17 --------- d-----w C:\Program Files\Microsoft.NET
2007-12-10 08:00 --------- d-----w C:\Program Files\Metamail Inc
2007-12-10 07:43 17,801 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys
2007-12-10 07:43 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-10 07:43 --------- d-----w C:\Program Files\Atheros
.
<pre>
----a-w 267,048 2008-01-09 04:18:31 C:\Program Files\iTunes\iTunesHelper .exe
----a-w 286,720 2008-01-09 06:40:25 C:\Program Files\QuickTime\QTTask .exe
----a-w 286,720 2008-01-12 16:16:10 C:\Program Files\QuickTime\QTTask .exe
----a-w 286,720 2008-01-13 20:19:38 C:\Program Files\QuickTime\QTTask .exe
----a-w 286,720 2008-01-12 16:16:12 C:\Program Files\QuickTime\QTTask .exe
----a-w 286,720 2008-01-12 16:16:12 C:\Program Files\QuickTime\QTTask .exe
----a-w 286,720 2008-01-12 16:16:12 C:\Program Files\QuickTime\QTTask .exe
----a-w 286,720 2008-01-12 16:16:14 C:\Program Files\QuickTime\QTTask .exe
----a-w 286,720 2008-01-12 16:16:14 C:\Program Files\QuickTime\QTTask .exe
----a-w 286,720 2008-01-12 16:16:14 C:\Program Files\QuickTime\QTTask .exe
----a-w 286,720 2008-01-12 16:16:14 C:\Program Files\QuickTime\QTTask .exe
----a-w 286,720 2008-01-12 16:16:17 C:\Program Files\QuickTime\QTTask .exe
----a-w 286,720 2008-01-12 16:16:17 C:\Program Files\QuickTime\QTTask .exe
----a-w 286,720 2008-01-12 16:16:19 C:\Program Files\QuickTime\QTTask .exe
----a-w 286,720 2008-01-12 16:16:18 C:\Program Files\QuickTime\QTTask .exe
----a-w 286,720 2008-01-12 16:16:21 C:\Program Files\QuickTime\QTTask .exe
----a-w 286,720 2008-01-12 16:16:21 C:\Program Files\QuickTime\QTTask .exe
----a-w 286,720 2008-01-13 20:19:40 C:\Program Files\QuickTime\QTTask .exe
----a-w 286,720 2008-01-12 16:16:21 C:\Program Files\QuickTime\QTTask .exe
----a-w 1,460,560 2008-01-09 23:01:39 C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe
----a-w 15,872 2008-01-12 08:23:43 C:\Program Files\Unlocker\UnlockerAssistant .exe
----a-w 158,208 2008-01-12 07:42:26 C:\WINDOWS\pchealth\helpctr\binaries\MSConfig .exe
----a-w 15,360 2008-01-12 08:23:45 C:\WINDOWS\system32\ctfmon .exe
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{36330701-32d7-4158-9a9d-6b1211d92c63}]
C:\WINDOWS\system32\ysmhwkvc.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D9854EAD-3448-412E-BD3A-7FD01BB49812}]
C:\WINDOWS\system32\vtutt.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-01-12 23:54 15360]
"Aim6"="" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="C:\Program Files\ESET\ESET Smart Security\egui.exe" [2007-12-21 08:21 1443072]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-12 08:16 286720]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wvututt]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^RAMASST.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\RAMASST.lnk
backup=C:\WINDOWS\pss\RAMASST.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Saetern^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=C:\Documents and Settings\Saetern\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=C:\WINDOWS\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\
000StTHK]
--a------ 2001-06-23 04:28 24576 C:\WINDOWS\system32\
000StTHK.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\
00THotkey]
--a------ 2005-03-01 00:43 245760 C:\WINDOWS\system32\
00THotkey.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
--a------ 2005-04-12 16:17 88358 C:\WINDOWS\agrsmmsg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
--a------ 2004-03-23 22:40 196608 C:\Program Files\Apoint2K\Apoint.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2008-01-12 23:54 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
--a------ 2005-05-31 05:33 122941 C:\WINDOWS\system32\dla\tfswctrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
--a------ 2006-10-27 00:47 31016 C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
--a------ 2005-06-08 10:59 77824 C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
--a------ 2005-06-08 11:02 94208 C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-01-08 23:53 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
C:\WINDOWS\system32\vtutt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LtMoh]
--a------ 2005-04-12 16:18 184320 C:\Program Files\ltmoh\Ltmoh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCAgentExe]
c:\PROGRA~1\mcafee.com\agent\McAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\McRegWiz]
C:\PROGRA~1\McAfee.com\Agent\mcregwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe]
c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 08:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NDSTray.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OASClnt]
C:\Program Files\McAfee.com\VSO\oasclnt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
--a------ 2005-06-08 11:03 114688 C:\WINDOWS\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pinger]
--a------ 2005-03-17 17:37 151552 c:\toshiba\ivp\ism\pinger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QdrModule11]
C:\Program Files\QdrModule\QdrModule11.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QdrPack11]
C:\Program Files\QdrPack\QdrPack11.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-01-08 22:40 286720 C:\Program Files\QuickTime\QTTask .exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmoothView]
--a------ 2005-04-26 16:13 122880 C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
--a------ 2008-01-09 20:26 1460560 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TFncKy]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TFNF5]
--a------ 2004-12-15 10:02 73728 C:\WINDOWS\system32\TFNF5.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TOSCDSPD]
--a------ 2008-01-09 20:43 65536 C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TouchED]
--a------ 2005-06-28 20:43 126976 C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPSMain]
--a------ 2005-08-09 19:22 315392 C:\WINDOWS\system32\TPSMain.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPSODDCtl]
--a------ 2005-08-09 19:22 110592 C:\WINDOWS\system32\TPSODDCtl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
--a------ 2008-01-12 00:23 15872 C:\Program Files\Unlocker\UnlockerAssistant .exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirusScan Online]
c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VSOCheckTask]
C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"iPod Service"=3 (0x3)
"FLEXnet Licensing Service"=3 (0x3)
"Bonjour Service"=2 (0x2)
"Apple Mobile Device"=2 (0x2)
"Swupdtmr"=2 (0x2)
"ekrn"=2 (0x2)
"EhttpSrv"=3 (0x3)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eb529ff4-a6f5-11dc-a0bd-00038a000015}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
"2007-12-31 05:49:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-01-13 12:21:28
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-13 12:23:18 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-13 20:23:15
.
2007-12-11 05:12:57 --- E O F ---