ok heres what you asked me....
HJT logfile
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:43:58 AM, on 1/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\SYSTEM32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
D:\Program Files\Alwil Software\Avast4\ashServ.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
D:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
d:\program files\common files\mcafee\mna\mcnasvc.exe
d:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
d:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
D:\Program Files\McAfee\MPF\MPFSrv.exe
D:\Program Files\McAfee\MSK\MskSrver.exe
D:\Program Files\SiteAdvisor\6253\SAService.exe
d:\PROGRA~1\mcafee.com\agent\mcagent.exe
D:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
D:\Program Files\SiteAdvisor\6253\SiteAdv.exe
D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
D:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
D:\WINDOWS\system32\ctfmon.exe
D:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
D:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\explorer.exe
D:\WINDOWS\system32\notepad.exe
D:\Program Files\internet explorer\iexplore.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://google.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.yahoo.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.comR3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: (no name) - {0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2} - D:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - D:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - D:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - D:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - D:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - D:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - D:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - D:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
O3 - Toolbar: (no name) - {a33fa729-d155-4b23-842b-2c665ecabdb6} - (no file)
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - D:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SiteAdvisor] "D:\Program Files\SiteAdvisor\6253\SiteAdv.exe"
O4 - HKLM\..\Run: [McENUI] "D:\PROGRA~1\McAfee\MHN\McENUI.exe" /hide
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avast!] D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [ZoneAlarm Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [DAEMON Tools] "D:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O4 - HKCU\..\Run: [SUPERAntiSpyware] D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: MagicDisc.lnk = D:\Program Files\MagicDisc\MagicDisc.exe
O8 - Extra context menu item: &Windows Live Search - res://D:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites -
http://favorites.liv...m/quickadd.aspxO8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) -
http://lads.myspace....ploader1005.cabO16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) -
http://www.systemreq.../sysreqlab2.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cabO16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) -
http://www.crucial.c.../cpcScanner.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{30E3C4DC-4760-462A-BC98-06B48C9FF6A5}: NameServer = 192.168.1.254
O17 - HKLM\System\CS1\Services\Tcpip\..\{30E3C4DC-4760-462A-BC98-06B48C9FF6A5}: NameServer = 192.168.1.254
O17 - HKLM\System\CS2\Services\Tcpip\..\{30E3C4DC-4760-462A-BC98-06B48C9FF6A5}: NameServer = 192.168.1.254
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: !SASWinLogon - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: McAfee Application Installer Cleanup (0056231199599504) (0056231199599504mcinstcleanup) - Unknown owner - D:\WINDOWS\TEMP\005623~1.EXE (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - D:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - D:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - D:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: iPod Service - Apple Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - D:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - d:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - D:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - d:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - d:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - D:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - D:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - D:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee, Inc. - D:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: SiteAdvisor Service - Unknown owner - D:\Program Files\SiteAdvisor\6253\SAService.exe
--
End of file - 9952 bytes
Combofix logfile
ComboFix 08-01-04.1 - Ezequiel 2008-01-06 6:57:16.1 - NTFSx86
Running from: D:\Documents and Settings\Ezequiel\Local Settings\Temporary Internet Files\Content.IE5\4D5VN2VT\ComboFix[1].exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
D:\Program Files\ContextTool
D:\Program Files\ContextTool\pcre3.dll
D:\Program Files\ContextTool\uninstall.exe
.
((((((((((((((((((((((((( Files Created from 2007-12-06 to 2008-01-06 )))))))))))))))))))))))))))))))
.
2008-01-06 06:54 . 2000-08-31 08:00 51,200 --a------ D:\WINDOWS\NirCmd.exe
2008-01-06 01:49 . 2008-01-06 01:49 <DIR> d-------- D:\Program Files\Common Files\TI Shared
2008-01-06 01:49 . 2004-02-04 11:27 49,536 --a------ D:\WINDOWS\system32\drivers\tiehdusb.sys
2008-01-06 01:49 . 2003-11-14 15:53 11,520 --a------ D:\WINDOWS\system32\drivers\wdmstub.sys
2008-01-06 01:48 . 2007-06-08 13:15 194,362 --a------ D:\WINDOWS\system32\drivers\windrvr6.sys
2008-01-06 01:48 . 2007-06-08 13:15 102,400 --a------ D:\WINDOWS\system32\wdapi811.dll
2008-01-06 01:48 . 2007-01-10 13:23 17,424 --a------ D:\WINDOWS\system32\drivers\ezusb.sys
2008-01-06 01:47 . 2008-01-06 01:48 <DIR> d-------- D:\Program Files\Common Files\Vernier Software
2008-01-06 01:46 . 2008-01-06 01:46 <DIR> d-------- D:\Program Files\Vernier Software
2008-01-06 01:46 . 2008-01-06 01:46 <DIR> d--h----- D:\Program Files\InstallShield Installation Information
2008-01-06 01:45 . 2008-01-06 01:45 <DIR> d-------- D:\Documents and Settings\Ezequiel\Application Data\InstallShield
2008-01-05 12:04 . 2008-01-05 15:13 <DIR> d-------- D:\WINDOWS\system32\ActiveScan
2008-01-05 12:04 . 2008-01-06 01:49 <DIR> d-------- D:\WINDOWS\LastGood
2008-01-05 12:04 . 2008-01-05 12:04 30,590 --a------ D:\WINDOWS\system32\pavas.ico
2008-01-05 12:04 . 2008-01-05 12:04 2,550 --a------ D:\WINDOWS\system32\Uninstall.ico
2008-01-05 12:04 . 2008-01-05 12:04 1,406 --a------ D:\WINDOWS\system32\Help.ico
2008-01-02 12:24 . 2008-01-05 15:03 <DIR> d-------- D:\Program Files\SUPERAntiSpyware
2008-01-02 12:24 . 2008-01-02 12:24 <DIR> d-------- D:\Documents and Settings\Ezequiel\Application Data\SUPERAntiSpyware.com
2008-01-02 12:24 . 2008-01-02 12:24 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-01-02 12:23 . 2008-01-02 12:23 <DIR> d-------- D:\Program Files\Common Files\Wise Installation Wizard
2008-01-02 03:04 . 2008-01-02 03:04 <DIR> d-------- D:\Program Files\CCleaner
2007-12-31 09:58 . 2007-12-31 09:58 <DIR> d-------- D:\Documents and Settings\Ezequiel\Application Data\Grisoft
2007-12-31 09:57 . 2007-12-31 09:57 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-31 09:57 . 2007-05-30 07:10 10,872 --a------ D:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-12-30 23:45 . 2007-12-30 23:45 <DIR> d-------- D:\Program Files\Trend Micro
2007-12-30 01:47 . 2007-12-30 01:47 164 --a------ D:\install.dat
2007-12-30 01:44 . 2007-12-04 07:54 95,608 --a------ D:\WINDOWS\system32\AvastSS.scr
2007-12-30 01:44 . 2007-12-04 09:55 94,544 --a------ D:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-30 01:44 . 2007-12-04 09:56 93,264 --a------ D:\WINDOWS\system32\drivers\aswmon.sys
2007-12-30 01:44 . 2007-12-04 09:51 42,912 --a------ D:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-30 01:44 . 2007-12-04 09:49 26,624 --a------ D:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-30 01:44 . 2007-12-04 09:53 23,152 --a------ D:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-30 01:42 . 2007-12-30 01:42 <DIR> d-------- D:\Program Files\Alwil Software
2007-12-30 01:42 . 2003-03-18 16:20 1,060,864 --a------ D:\WINDOWS\system32\MFC71.dll
2007-12-30 01:42 . 2007-12-04 08:04 837,496 --a------ D:\WINDOWS\system32\aswBoot.exe
2007-12-30 01:42 . 2004-01-09 04:13 380,928 --a------ D:\WINDOWS\system32\actskin4.ocx
2007-12-30 01:37 . 2007-12-30 01:50 <DIR> d-------- D:\Documents and Settings\Ezequiel\Application Data\GetRightToGo
2007-12-29 13:07 . 2007-12-29 13:10 <DIR> d-------- D:\Program Files\QuickTime
2007-12-27 21:38 . 2008-01-05 11:32 6,308 --a------ D:\WINDOWS\system32\Config.MPF
2007-12-27 21:29 . 2007-12-27 21:29 <DIR> d-------- D:\WINDOWS\system32\config\systemprofile\Application Data\SiteAdvisor
2007-12-27 21:29 . 2007-12-29 01:45 <DIR> d-------- D:\Program Files\SiteAdvisor
2007-12-27 21:29 . 2007-12-28 21:31 <DIR> d-------- D:\Documents and Settings\Ezequiel\Application Data\SiteAdvisor
2007-12-27 21:29 . 2007-12-27 21:29 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\SiteAdvisor
2007-12-27 21:20 . 2007-12-27 21:20 <DIR> d-------- D:\Program Files\Common Files\Adobe
2007-12-27 19:09 . 2006-03-03 11:07 143,360 --a------ D:\WINDOWS\system32\dunzip32.dll
2007-12-27 19:08 . 2007-07-21 09:08 201,288 --a------ D:\WINDOWS\system32\drivers\mfehidk.sys
2007-12-27 19:08 . 2007-07-13 09:20 113,952 --a------ D:\WINDOWS\system32\drivers\Mpfp.sys
2007-12-27 19:08 . 2007-07-24 07:40 79,304 --a------ D:\WINDOWS\system32\drivers\mfeavfk.sys
2007-12-27 19:08 . 2007-07-21 09:08 40,488 --a------ D:\WINDOWS\system32\drivers\mfesmfk.sys
2007-12-27 19:08 . 2007-07-21 09:08 35,240 --a------ D:\WINDOWS\system32\drivers\mfebopk.sys
2007-12-27 19:08 . 2007-07-24 12:02 33,800 --a------ D:\WINDOWS\system32\drivers\mferkdk.sys
2007-12-27 19:06 . 2007-12-27 20:18 <DIR> d-------- D:\Program Files\McAfee.com
2007-12-27 19:06 . 2007-12-27 21:29 <DIR> d-------- D:\Program Files\McAfee
2007-12-27 19:06 . 2007-12-27 21:27 <DIR> d-------- D:\Program Files\Common Files\McAfee
2007-12-27 18:51 . 2007-12-27 21:37 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\McAfee
2007-12-27 12:40 . 2007-12-27 12:40 0 --a------ D:\rollback.ini
2007-12-27 12:33 . 2007-12-27 19:27 2,933,536 --ahs---- D:\WINDOWS\system32\drivers\fidbox.dat
2007-12-27 12:33 . 2007-12-27 19:27 13,856 --ahs---- D:\WINDOWS\system32\drivers\fidbox2.dat
2007-12-27 12:33 . 2007-12-27 12:33 32 --ahs---- D:\WINDOWS\system32\drivers\fidbox2.idx
2007-12-27 12:33 . 2007-12-27 12:33 32 --ahs---- D:\WINDOWS\system32\drivers\fidbox.idx
2007-12-26 23:21 . 2004-04-27 04:40 11,264 --a------ D:\WINDOWS\system32\SpOrder.dll
2007-12-26 23:21 . 2007-12-27 12:58 4,212 ---h----- D:\WINDOWS\system32\zllictbl.dat
2007-12-26 23:20 . 2007-12-27 20:18 <DIR> d-------- D:\WINDOWS\Internet Logs
2007-12-26 21:54 . 2007-12-26 22:19 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-26 17:41 . 2007-12-26 17:41 <DIR> d-------- D:\Program Files\Conduit
2007-12-26 16:21 . 2007-12-26 16:21 <DIR> d-------- D:\Program Files\AskSBar
2007-12-25 22:45 . 2007-12-26 02:58 <DIR> d-------- D:\Documents and Settings\Ezequiel\Contacts
2007-12-25 21:27 . 2007-12-25 21:28 <DIR> d-------- D:\Program Files\DivX
2007-12-24 13:50 . 2007-12-24 13:56 34,825 --a------ D:\WINDOWS\DIIUnin.dat
2007-12-24 13:49 . 2007-12-24 13:49 94,208 --a------ D:\WINDOWS\DIIUnin.exe
2007-12-24 13:49 . 2007-12-24 13:49 2,829 --a------ D:\WINDOWS\DIIUnin.pif
2007-12-24 13:46 . 2007-12-29 01:21 <DIR> d-------- D:\Program Files\Diablo II
2007-12-23 04:07 . 2007-04-04 17:39 442,368 -ra------ D:\WINDOWS\system32\vp6vfw.dll
2007-12-22 10:16 . 2007-12-22 10:16 <DIR> d-------- D:\Program Files\Common Files\Blizzard Entertainment
2007-12-17 11:00 . 2007-12-17 11:00 <DIR> d-------- D:\Program Files\Yahoo!
2007-12-17 11:00 . 2007-12-17 11:00 <DIR> d-------- D:\Documents and Settings\Ezequiel\Application Data\Yahoo!
2007-12-17 11:00 . 2007-12-17 11:00 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-12-17 10:59 . 2007-12-17 10:59 <DIR> d-------- D:\WINDOWS\cache
2007-12-14 22:49 . 2007-12-14 22:49 268 --ah----- D:\sqmdata00.sqm
2007-12-14 22:49 . 2007-12-14 22:49 244 --ah----- D:\sqmnoopt00.sqm
2007-12-14 22:43 . 2008-01-05 15:04 <DIR> d-------- D:\Program Files\Windows Live Toolbar
2007-12-14 22:43 . 2007-12-14 22:43 <DIR> d-------- D:\Program Files\Windows Live Favorites
2007-12-14 22:27 . 2007-12-14 22:40 <DIR> d-------- D:\Program Files\Windows Live
2007-12-14 22:27 . 2007-12-14 22:39 <DIR> d--hsc--- D:\Program Files\Common Files\WindowsLiveInstaller
2007-12-14 22:20 . 2007-12-14 22:27 <DIR> d-------- D:\Documents and Settings\All Users\Application Data\WLInstaller
2007-12-11 10:57 . 2007-12-11 10:57 65,536 --a------ D:\WINDOWS\system32\QuickTimeVR.qtx
2007-12-11 10:57 . 2007-12-11 10:57 49,152 --a------ D:\WINDOWS\system32\QuickTime.qts
2007-12-09 20:57 . 2007-12-09 20:57 56,664 --ah----- D:\WINDOWS\system32\mlfcache.dat
2007-12-09 20:52 . 2007-12-09 20:52 <DIR> d-------- D:\Program Files\Safari
2007-12-09 20:18 . 2004-08-03 23:08 31,616 --a------ D:\WINDOWS\system32\drivers\usbccgp.sys
2007-12-09 20:18 . 2004-08-03 23:08 31,616 --a--c--- D:\WINDOWS\system32\dllcache\usbccgp.sys
2007-12-09 20:18 . 2004-08-04 00:56 21,504 --a------ D:\WINDOWS\system32\hidserv.dll
2007-12-09 20:18 . 2004-08-04 00:56 21,504 --a--c--- D:\WINDOWS\system32\dllcache\hidserv.dll
2007-12-09 20:18 . 2004-08-03 22:58 14,848 --a------ D:\WINDOWS\system32\drivers\kbdhid.sys
2007-12-09 20:18 . 2004-08-03 22:58 14,848 --a--c--- D:\WINDOWS\system32\dllcache\kbdhid.sys
2007-12-09 20:18 . 2001-08-17 14:02 9,600 --a------ D:\WINDOWS\system32\drivers\hidusb.sys
2007-12-09 20:18 . 2001-08-17 14:02 9,600 --a--c--- D:\WINDOWS\system32\dllcache\hidusb.sys
2007-12-06 23:29 . 2007-12-09 21:31 <DIR> d-------- D:\Program Files\DriverGuide Toolkit
2007-12-06 22:24 . 2007-12-06 22:24 <DIR> d-------- D:\Program Files\SystemRequirementsLab
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-04 18:24 --------- d-----w D:\Documents and Settings\Ezequiel\Application Data\uTorrent
2007-12-30 07:02 --------- d-----w D:\Program Files\MSTpscre
2007-12-28 01:18 --------- d-----w D:\Program Files\PlayMP3z
2007-12-27 17:31 --------- d-sh--w D:\Documents and Settings\Ezequiel\Application Data\.#
2007-12-27 17:31 --------- d---a-w D:\Documents and Settings\All Users\Application Data\TEMP
2007-12-26 21:22 --------- d-----w D:\Program Files\FrostWire
2007-12-24 18:56 21,840 ----atw D:\WINDOWS\system32\SIntfNT.dll
2007-12-24 18:56 17,212 ----atw D:\WINDOWS\system32\SIntf32.dll
2007-12-24 18:56 12,067 ----atw D:\WINDOWS\system32\SIntf16.dll
2007-12-23 23:32 --------- d-----w D:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-12-14 01:49 --------- d-----w D:\Documents and Settings\All Users\Application Data\Apple Computer
2007-12-10 23:30 --------- d-----w D:\Program Files\Common Files\InstallShield
2007-12-10 01:52 --------- d-----w D:\Documents and Settings\Ezequiel\Application Data\Apple Computer
2007-12-10 01:30 --------- d-----w D:\Documents and Settings\Ezequiel\Application Data\FrostWire
2007-12-05 19:07 --------- d-----w D:\Program Files\Azureus
2007-12-05 11:36 --------- d-----w D:\Documents and Settings\Ezequiel\Application Data\Azureus
2007-12-04 21:28 --------- d-----w D:\Program Files\uTorrent
2007-12-04 01:33 823,296 ----a-w D:\WINDOWS\system32\divx_xx0c.dll
2007-12-04 01:33 823,296 ----a-w D:\WINDOWS\system32\divx_xx07.dll
2007-12-04 01:33 802,816 ----a-w D:\WINDOWS\system32\divx_xx11.dll
2007-12-04 01:33 682,496 ----a-w D:\WINDOWS\system32\DivX.dll
2007-12-03 05:27 --------- d-----w D:\Program Files\Microsoft Games
2007-12-03 02:25 --------- d-----w D:\Program Files\MSXML 4.0
2007-11-29 22:30 524,288 ----a-w D:\WINDOWS\system32\DivXsm.exe
2007-11-29 22:30 3,596,288 ----a-w D:\WINDOWS\system32\qt-dx331.dll
2007-11-29 22:28 81,920 ----a-w D:\WINDOWS\system32\dpl100.dll
2007-11-28 21:55 156,992 ----a-w D:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-11-28 21:52 12,288 ----a-w D:\WINDOWS\system32\DivXWMPExtType.dll
2007-11-24 17:44 --------- d-----w D:\Program Files\Xvid
2007-11-22 03:05 --------- d-----w D:\Program Files\iTunes
2007-11-22 03:05 --------- d-----w D:\Program Files\iPod
2007-11-22 02:56 --------- d-----w D:\Program Files\Apple Software Update
2007-11-22 02:52 --------- d-----w D:\Program Files\Common Files\Apple
2007-11-22 02:51 --------- d-----w D:\Documents and Settings\All Users\Application Data\Apple
2007-11-21 01:02 --------- d-----w D:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2007-11-21 00:01 --------- d-----w D:\Program Files\MSBuild
2007-11-21 00:01 --------- d-----w D:\Program Files\Microsoft Works
2007-11-20 23:46 --------- d-----w D:\Program Files\MagicDisc
2007-11-18 21:53 --------- d-----w D:\Documents and Settings\Ezequiel\Application Data\LimeWire
2007-11-18 21:31 --------- d-----w D:\Program Files\Common Files\Java
2007-11-18 21:11 --------- d-----w D:\Documents and Settings\All Users\Application Data\Azureus
2007-11-18 21:10 685,816 ----a-w D:\WINDOWS\system32\drivers\sptd.sys
2007-11-18 20:02 --------- d-----w D:\Program Files\Common Files\Motive
2007-11-18 07:09 --------- d-----w D:\Program Files\Java
2007-11-18 07:02 --------- d-----w D:\Program Files\DAEMON Tools
2007-11-17 08:55 --------- d-----w D:\Program Files\microsoft frontpage
2007-11-13 10:25 20,480 ----a-w D:\WINDOWS\system32\drivers\secdrv.sys
2007-10-31 18:03 245,408 ----a-w D:\WINDOWS\system32\unicows.dll
2007-10-29 22:43 1,287,680 ----a-w D:\WINDOWS\system32\quartz.dll
2007-10-27 22:39 230,912 ----a-w D:\WINDOWS\system32\wmasf.dll
2007-10-18 16:31 51,224 ----a-w D:\WINDOWS\system32\sirenacm.dll
2007-10-17 11:24 2,526,800 ----a-w D:\WINDOWS\Install_B4Playing.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}]
2007-12-26 16:21 66912 --a------ D:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0D39A900-0F3A-4C29-A254-3E65244FDC34}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a33fa729-d155-4b23-842b-2c665ecabdb6}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}]
2007-12-26 16:21 267592 --a------ D:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}
{EF99BD32-C1FB-11D2-892F-0090271D4F88}
{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}
{A33FA729-D155-4B23-842B-2C665ECABDB6}
{0BF43445-2F28-4351-9252-17FE6E806AA0}
[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= D:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL [2007-12-26 16:21 267592]
[HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools"="D:\Program Files\DAEMON Tools\daemon.exe" [2007-11-17 06:53 171464]
"ctfmon.exe"="D:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360]
"SpybotSD TeaTimer"="D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
"SUPERAntiSpyware"="D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-02-27 11:39 1310720]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="D:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 04:11 132496]
"SiteAdvisor"="D:\Program Files\SiteAdvisor\6253\SiteAdv.exe" [2007-06-21 18:12 36640]
"McENUI"="D:\PROGRA~1\McAfee\MHN\McENUI.exe" [2007-07-22 20:29 1160480]
"QuickTime Task"="D:\Program Files\QuickTime\qttask.exe" [2007-12-11 10:56 286720]
"avast!"="D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 08:00 79224]
"!AVG Anti-Spyware"="D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25 6731312]
"ZoneAlarm Client"="D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [ ]
D:\Documents and Settings\Ezequiel\Start Menu\Programs\Startup\
MagicDisc.lnk - D:\Program Files\MagicDisc\MagicDisc.exe [2007-11-20 18:46:35]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= D:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
D:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-02-27 11:39 282624 D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^Ezequiel^Start Menu^Programs^Startup^Microsoft Office Groove.lnk]
path=D:\Documents and Settings\Ezequiel\Start Menu\Programs\Startup\Microsoft Office Groove.lnk
backup=D:\WINDOWS\pss\Microsoft Office Groove.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\D:^Documents and Settings^Ezequiel^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=D:\Documents and Settings\Ezequiel\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=D:\WINDOWS\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-27 00:47 31016 --a------ D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
R3 USB_RNDIS_XP;Westell WireSpeed Dual Connect Modem;D:\WINDOWS\system32\DRIVERS\usb8023.sys [2004-08-03 22:04]
R3 WinDriver6;WinDriver6;D:\WINDOWS\system32\drivers\windrvr6.sys [2007-06-08 13:15]
S2 0056231199599504mcinstcleanup;McAfee Application Installer Cleanup (0056231199599504);D:\WINDOWS\TEMP\
005623~1.EXE D:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog []
S3 pnicII;Linksys Fast Ethernet PCI Card;D:\WINDOWS\system32\DRIVERS\lne100.SYS [2001-08-17 15:12]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5d796344-9c9e-11dc-b27e-00183af4f9c5}]
\Shell\AutoRun\command - I:\SETUP.EXE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6ea1ba43-6c1f-1014-85c4-b9f2c719bf38}]
\Shell\Auto\command - Setup.exe
\Shell\AutoRun\command - D:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Setup.exe
*Newly Created Service* - PROCEXP90
*Newly Created Service* - PWISQORDKAEM
*Newly Created Service* - RKPAVPROC
*Newly Created Service* - SDTHOOK
.
Contents of the 'Scheduled Tasks' folder
"2008-01-06 00:59:08 D:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- D:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-01-06 11:45:06 D:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- D:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2007-12-28 00:07:24 D:\WINDOWS\Tasks\McDefragTask.job"
- d:\program files\mcafee\mqc\QcConsol.exe'
"2007-12-28 00:07:21 D:\WINDOWS\Tasks\McQcTask.job"
- d:\program files\mcafee\mqc\QcConsol.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-01-06 07:03:31
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-06 7:05:27
ComboFix-quarantined-files.txt 2008-01-06 12:05:11
.
2007-12-23 23:33:49 --- E O F ---