Here's the ComboFix log:ComboFix 08-02-14.2 - User 2008-02-17 8:08:26.2 - NTFSx86
Running from: C:\Documents and Settings\User\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\User\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!FILE
C:\WINDOWS\pskt.ini
C:\WINDOWS\SYSTEM32\ahgadehe.ini
C:\WINDOWS\SYSTEM32\bacsqbvl.ini
C:\WINDOWS\SYSTEM32\bqybxfts.ini
C:\WINDOWS\SYSTEM32\cekynglm.ini
C:\WINDOWS\SYSTEM32\cqmlmuyw.ini
C:\WINDOWS\SYSTEM32\fgcmkjfi.ini
C:\WINDOWS\system32\gfvj.dll
C:\WINDOWS\SYSTEM32\hpfbymhy.ini
C:\WINDOWS\SYSTEM32\kjveqpph.ini
C:\WINDOWS\SYSTEM32\mmtcyqva.ini
C:\WINDOWS\SYSTEM32\mnbvbrmv.ini
C:\WINDOWS\SYSTEM32\nhcwcakb.ini
C:\WINDOWS\SYSTEM32\nkuihvgs.ini
C:\WINDOWS\SYSTEM32\opesoyry.ini
C:\WINDOWS\SYSTEM32\oxkhclmj.ini
C:\WINDOWS\SYSTEM32\pfuodtah.ini
C:\WINDOWS\SYSTEM32\prutfjrr.ini
C:\WINDOWS\SYSTEM32\rrjfturp.dll
C:\WINDOWS\SYSTEM32\snlnqush.ini
C:\WINDOWS\SYSTEM32\uibhgkpp.ini
C:\WINDOWS\SYSTEM32\umpdsqws.ini
C:\WINDOWS\SYSTEM32\umpdsqws.tmp
C:\WINDOWS\SYSTEM32\utpkonpo.ini
C:\WINDOWS\SYSTEM32\vsjxhotj.ini
C:\WINDOWS\SYSTEM32\vthaeduw.ini
C:\WINDOWS\SYSTEM32\xwwxlqkm.ini
C:\WINDOWS\SYSTEM32\ykvrxegc.ini
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\pskt.ini
C:\WINDOWS\SYSTEM32\ahgadehe.ini
C:\WINDOWS\SYSTEM32\bacsqbvl.ini
C:\WINDOWS\SYSTEM32\bqybxfts.ini
C:\WINDOWS\SYSTEM32\cekynglm.ini
C:\WINDOWS\SYSTEM32\cqmlmuyw.ini
C:\WINDOWS\SYSTEM32\fgcmkjfi.ini
C:\WINDOWS\SYSTEM32\hpfbymhy.ini
C:\WINDOWS\SYSTEM32\kjveqpph.ini
C:\WINDOWS\SYSTEM32\mmtcyqva.ini
C:\WINDOWS\SYSTEM32\mnbvbrmv.ini
C:\WINDOWS\SYSTEM32\nhcwcakb.ini
C:\WINDOWS\SYSTEM32\nkuihvgs.ini
C:\WINDOWS\SYSTEM32\opesoyry.ini
C:\WINDOWS\SYSTEM32\oxkhclmj.ini
C:\WINDOWS\SYSTEM32\pfuodtah.ini
C:\WINDOWS\SYSTEM32\prutfjrr.ini
C:\WINDOWS\SYSTEM32\rrjfturp.dll
C:\WINDOWS\SYSTEM32\snlnqush.ini
C:\WINDOWS\SYSTEM32\uibhgkpp.ini
C:\WINDOWS\SYSTEM32\umpdsqws.ini
C:\WINDOWS\SYSTEM32\umpdsqws.tmp
C:\WINDOWS\SYSTEM32\utpkonpo.ini
C:\WINDOWS\SYSTEM32\vsjxhotj.ini
C:\WINDOWS\SYSTEM32\vthaeduw.ini
C:\WINDOWS\SYSTEM32\xwwxlqkm.ini
C:\WINDOWS\SYSTEM32\ykvrxegc.ini
.
((((((((((((((((((((((((( Files Created from 2008-01-17 to 2008-02-17 )))))))))))))))))))))))))))))))
.
2008-02-17 05:09 . 2008-02-17 05:12 <DIR> d-------- C:\Program Files\Yahoo!
2008-02-15 23:40 . 2008-02-15 23:40 <DIR> d-------- C:\Norton
2008-02-15 23:09 . 2008-02-15 23:09 <DIR> d-------- C:\Program Files\Trend Micro
2008-02-15 19:43 . 2008-02-16 10:26 12,830 --a------ C:\WINDOWS\BMfb20b004.xml
2008-02-15 17:10 . 2008-02-15 17:10 <DIR> d-------- C:\WINDOWS\ERUNT
2008-02-15 00:38 . 2008-02-15 19:23 <DIR> d-------- C:\SDFix
2008-02-09 23:33 . 2008-02-09 23:33 <DIR> d-------- C:\Intel
2008-02-09 23:17 . 2007-12-05 02:53 356,352 --a------ C:\WINDOWS\SYSTEM32\NVUNINST.EXE
2008-02-09 23:13 . 2008-02-09 23:13 <DIR> d-------- C:\NVIDIA
2008-02-09 23:10 . 2007-10-12 15:14 3,734,536 --a------ C:\WINDOWS\SYSTEM32\d3dx9_36.dll
2008-02-09 23:10 . 2007-10-12 15:14 1,374,232 --a------ C:\WINDOWS\SYSTEM32\D3DCompiler_36.dll
2008-02-09 23:10 . 2007-10-02 09:56 444,776 --a------ C:\WINDOWS\SYSTEM32\d3dx10_36.dll
2008-02-09 23:10 . 2007-10-22 03:39 267,272 --a------ C:\WINDOWS\SYSTEM32\xactengine2_10.dll
2008-02-09 23:10 . 2007-07-20 00:57 267,112 --a------ C:\WINDOWS\SYSTEM32\xactengine2_9.dll
2008-02-09 23:09 . 2007-07-19 18:14 3,727,720 --a------ C:\WINDOWS\SYSTEM32\d3dx9_35.dll
2008-02-09 23:09 . 2007-05-16 16:45 3,497,832 --a------ C:\WINDOWS\SYSTEM32\d3dx9_34.dll
2008-02-09 23:09 . 2007-07-19 18:14 1,358,192 --a------ C:\WINDOWS\SYSTEM32\D3DCompiler_35.dll
2008-02-09 23:09 . 2007-05-16 16:45 1,124,720 --a------ C:\WINDOWS\SYSTEM32\D3DCompiler_34.dll
2008-02-09 23:09 . 2007-07-19 18:14 444,776 --a------ C:\WINDOWS\SYSTEM32\d3dx10_35.dll
2008-02-09 23:09 . 2007-05-16 16:45 443,752 --a------ C:\WINDOWS\SYSTEM32\d3dx10_34.dll
2008-02-09 23:09 . 2007-06-20 20:46 266,088 --a------ C:\WINDOWS\SYSTEM32\xactengine2_8.dll
2008-02-09 23:09 . 2007-10-22 03:37 17,928 --a------ C:\WINDOWS\SYSTEM32\X3DAudio1_2.dll
2008-02-09 23:08 . 2007-03-12 16:42 1,123,696 --a------ C:\WINDOWS\SYSTEM32\D3DCompiler_33.dll
2008-02-09 23:08 . 2007-03-15 16:57 443,752 --a------ C:\WINDOWS\SYSTEM32\d3dx10_33.dll
2008-02-09 23:08 . 2007-04-04 18:55 261,480 --a------ C:\WINDOWS\SYSTEM32\xactengine2_7.dll
2008-02-09 23:08 . 2007-04-04 18:53 81,768 --a------ C:\WINDOWS\SYSTEM32\xinput1_3.dll
2008-02-09 23:07 . 2007-03-12 16:42 3,495,784 --a------ C:\WINDOWS\SYSTEM32\d3dx9_33.dll
2008-02-09 23:07 . 2006-11-29 13:06 3,426,072 --a------ C:\WINDOWS\SYSTEM32\d3dx9_32.dll
2008-02-09 23:07 . 2006-09-28 16:05 2,414,360 --a------ C:\WINDOWS\SYSTEM32\d3dx9_31.dll
2008-02-09 23:07 . 2007-01-24 15:27 255,848 --a------ C:\WINDOWS\SYSTEM32\xactengine2_6.dll
2008-02-09 23:07 . 2006-12-08 12:02 251,672 --a------ C:\WINDOWS\SYSTEM32\xactengine2_5.dll
2008-02-09 23:07 . 2006-09-28 16:05 237,848 --a------ C:\WINDOWS\SYSTEM32\xactengine2_4.dll
2008-02-09 23:07 . 2006-07-28 09:30 236,824 --a------ C:\WINDOWS\SYSTEM32\xactengine2_3.dll
2008-02-09 23:07 . 2007-03-05 12:42 15,128 --a------ C:\WINDOWS\SYSTEM32\x3daudio1_1.dll
2008-02-09 21:53 . 2008-02-09 21:53 <DIR> d-------- C:\Documents and Settings\User\Builds
2008-02-09 21:34 . 2008-02-10 23:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Outspark
2008-02-08 04:04 . 2008-02-09 03:16 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-02-08 04:04 . 2008-02-08 04:04 <DIR> d-------- C:\Documents and Settings\User\Application Data\SUPERAntiSpyware.com
2008-02-08 04:04 . 2008-02-08 04:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-02-06 19:16 . 2008-02-06 19:16 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-30 18:08 . 2008-01-30 19:44 <DIR> d-------- C:\VundoFix Backups
2008-01-29 21:45 . 2008-01-29 22:52 50 --a------ C:\WINDOWS\MegaManager.INI
2008-01-29 21:33 . 2008-01-29 21:33 <DIR> d-------- C:\Documents and Settings\User\Application Data\Megaupload
2008-01-29 21:28 . 2008-02-15 00:01 <DIR> d-------- C:\Documents and Settings\User\Application Data\MegauploadToolbar
2008-01-27 02:14 . 2008-01-27 02:14 23,392 --a------ C:\WINDOWS\SYSTEM32\nscompat.tlb
2008-01-27 02:14 . 2008-01-27 02:14 16,832 --a------ C:\WINDOWS\SYSTEM32\amcompat.tlb
2008-01-27 01:57 . 1998-09-02 00:28 38,160 --a------ C:\WINDOWS\SYSTEM32\LMRTREND.dll
2008-01-27 01:56 . 1998-08-20 03:02 140,800 --a------ C:\WINDOWS\SYSTEM32\tm20dec.ax
2008-01-27 01:55 . 1998-08-26 20:51 182,032 --a------ C:\WINDOWS\SYSTEM32\dxtmsft3.dll
2008-01-27 01:52 . 1998-09-02 00:28 63,488 --a------ C:\WINDOWS\SYSTEM32\unam4ie.exe
2008-01-27 01:51 . 1998-09-02 00:02 194,320 --a------ C:\WINDOWS\SYSTEM32\qcut.dll
2008-01-27 01:51 . 1998-08-17 01:21 11,776 --a------ C:\WINDOWS\SYSTEM32\mciqtz.drv
2008-01-27 01:51 . 1998-08-17 01:21 10,240 --a------ C:\WINDOWS\SYSTEM32\vidx16.dll
2008-01-27 01:51 . 1998-08-17 01:21 5,672 --a------ C:\WINDOWS\SYSTEM32\quartz.vxd
2008-01-27 01:50 . 2008-01-27 01:50 4,608 --a------ C:\WINDOWS\SYSTEM32\w95inf32.dll
2008-01-27 01:50 . 2008-01-27 01:50 2,272 --a------ C:\WINDOWS\SYSTEM32\w95inf16.dll
2008-01-27 01:30 . 2008-01-27 01:30 <DIR> d-------- C:\Documents and Settings\User\Application Data\DAEMON Tools
2008-01-27 01:29 . 2008-02-17 08:08 <DIR> d-------- C:\Program Files\DAEMON Tools Lite
2008-01-26 23:52 . 2008-01-26 23:52 15,360 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\ctfmon.exe
2008-01-26 23:52 . 2008-01-26 23:52 15,360 --a------ C:\WINDOWS\SYSTEM32\ctfmon.exe
2008-01-26 23:51 . 2008-01-27 21:01 455,168 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\tintsetp.exe
2008-01-26 23:51 . 2008-01-27 21:01 208,952 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\imjpmig.exe
2008-01-26 23:51 . 2008-01-27 21:01 59,392 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\imscinst.exe
2008-01-26 23:51 . 2008-01-27 21:01 44,032 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\imekrmig.exe
2008-01-26 09:05 . 2008-01-26 09:08 8,628 --ah----- C:\TLOVE.GID
2008-01-26 04:08 . 2008-01-26 04:08 94,208 --a------ C:\WINDOWS\SM1BG.EXE
2008-01-26 03:41 . 2008-01-26 03:41 <DIR> d-------- C:\Documents and Settings\User\Application Data\Fujitsu
2008-01-26 03:39 . 2008-01-26 03:39 256 --ah----- C:\WINDOWS\SYSTEM32\LTAW14FN.BIN
2008-01-26 03:39 . 2008-01-26 03:39 256 --ah----- C:\WINDOWS\SYSTEM32\FJLTAFOU.BIN
2008-01-26 02:02 . 2008-02-14 23:26 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-26 02:02 . 2008-01-26 02:02 1,409 --a------ C:\WINDOWS\QTFont.for
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-17 16:08 --------- d-----w C:\Program Files\VoloMedia
2008-02-17 16:08 --------- d-----w C:\Program Files\QuickTime
2008-02-17 16:08 --------- d-----w C:\Program Files\MSN Messenger
2008-02-17 16:08 --------- d-----w C:\Program Files\Lexmark 2200 Series
2008-02-17 16:08 --------- d-----w C:\Program Files\iTunes
2008-02-17 16:08 --------- d-----w C:\Program Files\Chikka
2008-02-17 16:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-02-16 09:13 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-02-16 09:13 60,800 ----a-w C:\WINDOWS\SYSTEM32\S32EVNT1.DLL
2008-02-16 09:13 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-02-16 09:13 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-02-16 09:13 --------- d-----w C:\Program Files\Symantec
2008-02-16 06:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-16 05:58 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-02-16 05:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kodak
2008-02-15 03:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-02-13 07:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-02-10 19:22 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-02 06:04 --------- d-----w C:\Program Files\DivX
2008-01-30 04:31 --------- d-----w C:\Program Files\Eraser
2008-01-27 07:45 716,272 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-01-26 14:41 --------- d-----w C:\Program Files\Anvil Studio
2008-01-12 00:52 --------- d-----w C:\Program Files\PodBridge
2008-01-12 00:52 --------- d-----w C:\Documents and Settings\User\Application Data\Podbridge Service
2008-01-04 21:59 524,288 ----a-w C:\WINDOWS\SYSTEM32\DivXsm.exe
2008-01-04 21:58 43,528 ----a-w C:\WINDOWS\system32\drivers\PxHelp20.sys
2008-01-04 21:58 3,596,288 -c--a-w C:\WINDOWS\SYSTEM32\qt-dx331.dll
2008-01-04 21:58 200,704 ----a-w C:\WINDOWS\SYSTEM32\ssldivx.dll
2008-01-04 21:58 129,784 -c--a-w C:\WINDOWS\SYSTEM32\pxafs.dll
2008-01-04 21:58 120,056 -c--a-w C:\WINDOWS\SYSTEM32\pxcpyi64.exe
2008-01-04 21:58 118,520 -c--a-w C:\WINDOWS\SYSTEM32\pxinsi64.exe
2008-01-04 21:58 1,044,480 ----a-w C:\WINDOWS\SYSTEM32\libdivx.dll
2008-01-04 21:57 823,296 ----a-w C:\WINDOWS\SYSTEM32\divx_xx0c.dll
2008-01-04 21:57 823,296 ----a-w C:\WINDOWS\SYSTEM32\divx_xx07.dll
2008-01-04 21:57 81,920 -c--a-w C:\WINDOWS\SYSTEM32\dpl100.dll
2008-01-04 21:57 802,816 ----a-w C:\WINDOWS\SYSTEM32\divx_xx11.dll
2008-01-04 21:57 682,496 ----a-w C:\WINDOWS\SYSTEM32\DivX.dll
2008-01-04 21:57 593,920 -c--a-w C:\WINDOWS\SYSTEM32\dpuGUI11.dll
2008-01-04 21:57 57,344 -c--a-w C:\WINDOWS\SYSTEM32\dpv11.dll
2008-01-04 21:57 53,248 -c--a-w C:\WINDOWS\SYSTEM32\dpuGUI10.dll
2008-01-04 21:57 344,064 -c--a-w C:\WINDOWS\SYSTEM32\dpus11.dll
2008-01-04 21:57 294,912 -c--a-w C:\WINDOWS\SYSTEM32\dpu11.dll
2008-01-04 21:57 294,912 -c--a-w C:\WINDOWS\SYSTEM32\dpu10.dll
2008-01-04 21:57 196,608 -c--a-w C:\WINDOWS\SYSTEM32\dtu100.dll
2008-01-04 21:56 156,992 ----a-w C:\WINDOWS\SYSTEM32\DivXCodecVersionChecker.exe
2008-01-04 21:56 12,288 ----a-w C:\WINDOWS\SYSTEM32\DivXWMPExtType.dll
2007-12-18 09:51 179,584 ----a-w C:\WINDOWS\system32\drivers\mrxdav.sys
2007-12-18 09:51 179,584 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\mrxdav.sys
2007-12-07 14:37 3,059,200 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtml.dll
2007-12-07 01:07 96,256 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\inseng.dll
2007-12-07 01:07 659,456 ----a-w C:\WINDOWS\SYSTEM32\wininet.dll
2007-12-07 01:07 659,456 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\wininet.dll
2007-12-07 01:07 615,424 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\urlmon.dll
2007-12-07 01:07 55,808 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\extmgr.dll
2007-12-07 01:07 532,480 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\mstime.dll
2007-12-07 01:07 474,112 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\shlwapi.dll
2007-12-07 01:07 449,024 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtmled.dll
2007-12-07 01:07 39,424 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\pngfilt.dll
2007-12-07 01:07 357,888 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\dxtmsft.dll
2007-12-07 01:07 251,392 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\iepeers.dll
2007-12-07 01:07 205,312 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\dxtrans.dll
2007-12-07 01:07 16,384 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\jsproxy.dll
2007-12-07 01:07 151,040 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\cdfview.dll
2007-12-07 01:07 146,432 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\msrating.dll
2007-12-07 01:07 1,494,528 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\shdocvw.dll
2007-12-07 01:07 1,054,208 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\danim.dll
2007-12-07 01:07 1,023,488 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\browseui.dll
2007-12-06 13:07 18,432 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\iedw.exe
2007-12-04 18:38 550,912 ----a-w C:\WINDOWS\SYSTEM32\oleaut32.dll
2007-12-04 18:38 550,912 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\oleaut32.dll
2007-10-27 23:53 81,920 ----a-w C:\Documents and Settings\User\Application Data\ezpinst.exe
2007-10-27 23:53 47,360 -c--a-w C:\Documents and Settings\User\Application Data\pcouffin.sys
2007-07-28 23:11 83,008 -c--a-w C:\Documents and Settings\User\Application Data\GDIPFONTCACHEV1.DAT
2006-12-30 20:19 491,008 -c--a-w C:\Program Files\New_Year_Prayer.pps
2006-12-04 17:07 218,306,392 -c--a-w C:\Program Files\Accounting Express.exe
2003-08-27 22:19 36,963 -c--a-r C:\Program Files\Common Files\SM1updtr.dll
2001-07-17 11:08 65,536 -c----w C:\WINDOWS\INF\copyinf.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-C4DC-6BA49CE16884}]
2007-10-18 12:25 1938232 --a------ C:\PROGRA~1\multiply\multiply.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88}
{2318C2B1-4965-11D4-9B18-009027A5CD4F}
{A057A204-BACC-4D26-C4DC-6BA49CE16884}
{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-c4dc-6ba49ce16884}]
[HKEY_CLASSES_ROOT\multiply.MULTIPLY]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A057A204-BACC-4D26-C4DC-6BA49CE16884}"= C:\PROGRA~1\multiply\multiply.dll [2007-10-18 12:25 1938232]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-c4dc-6ba49ce16884}]
[HKEY_CLASSES_ROOT\multiply.MULTIPLY]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\Money Express.exe" [ ]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" [ ]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2008-01-27 21:03 6049792]
"Eraser"="C:\Program Files\Eraser\Eraser .exe" [ ]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-01-27 21:02 486856]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [ ]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"ypagerps3"="cmd.exe" [2004-08-03 23:56 388608 C:\WINDOWS\SYSTEM32\cmd.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [ ]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [ ]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [ ]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk
backup=C:\WINDOWS\pss\Microsoft Works Calendar Reminders.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
--a------ 2001-09-04 13:31 655360 C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LXSUPMON]
--a--c--- 2001-10-09 14:06 818688 C:\WINDOWS\System32\LXSUPMON.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2003-08-05 20:29 1578160 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
--a------ 2004-09-13 11:27 204845 C:\Program Files\Real\RealPlayer\RealPlay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Weather]
C:\PROGRA~1\AWS\WEATHE~1\Weather.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe
R3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\wg111v2.sys [2006-03-27 16:53]
S2 Norton LiveConnect Service;Norton LiveConnect Service;"C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" []
S2 pifCore;Norton LiveConnect Service Ex;"C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" [2007-06-04 18:05]
S3 ati2mpaa;ati2mpaa;C:\WINDOWS\system32\DRIVERS\ati2mpaa.sys [2001-08-17 10:48]
S3 ati2mtaa;ati2mtaa;C:\WINDOWS\system32\DRIVERS\ati2mtaa.sys [2004-08-03 21:29]
S3 DCamUSBGrandTek;Clever Cam 360 PC Camera;C:\WINDOWS\system32\Drivers\ClC360x1.SYS [2001-04-27 04:03]
S3 SUNPLUS;SightCAM PC-100p;C:\WINDOWS\system32\Drivers\SPIXNEW.SYS [2002-03-07 17:21]
S3 WebSTARNdis;WebSTAR DPX USB Cable Modem Adapter;C:\WINDOWS\system32\DRIVERS\WebSTAR.sys []
S4 hpt3xx;hpt3xx;C:\WINDOWS\system32\DRIVERS\hpt3xx.sys [2001-08-17 11:52]
.
Contents of the 'Scheduled Tasks' folder
"2008-01-28 14:57:46 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-02-17 08:16:35
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\RtlGina2.dll
.
Completion time: 2008-02-17 8:21:09
ComboFix-quarantined-files.txt 2008-02-17 16:20:38
ComboFix2.txt 2008-02-16 19:11:37
.
2008-02-13 08:02:36 --- E O F ---
Here's the hijackthis log:Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:24:30 AM, on 2/17/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\ScsiAccess.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\conime.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll (file missing)
O2 - BHO: Multiply Toolbar - {A057A204-BACC-4D26-C4DC-6BA49CE16884} - C:\PROGRA~1\multiply\multiply.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll (file missing)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll (file missing)
O3 - Toolbar: Multiply Toolbar - {A057A204-BACC-4D26-C4DC-6BA49CE16884} - C:\PROGRA~1\multiply\multiply.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL (file missing)
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\Eraser .exe -hide
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: BitTorrent.lnk = C:\Program Files\BitTorrent\bittorrent.exe
O4 - Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: GetRight Monitor.lnk = C:\Program Files\GetRight\getright.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: NETGEAR WG111v2 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Post Image to Blog - res://C:\WINDOWS\ImageShackToolbar\ImageShackToolbar.dll/5003
O8 - Extra context menu item: Refresh Pa&ge with Full Quality - C:\Program Files\EarthLink TotalAccess\Accelerator\\pac-page.html
O8 - Extra context menu item: Refresh Pi&cture with Full Quality - C:\Program Files\EarthLink TotalAccess\Accelerator\\pac-image.html
O8 - Extra context menu item: Tag This Image - res://C:\WINDOWS\ImageShackToolbar\ImageShackToolbar.dll/5002
O8 - Extra context menu item: Transload Image to ImageShack - res://C:\WINDOWS\ImageShackToolbar\ImageShackToolbar.dll/5004
O8 - Extra context menu item: Upload All Images to ImageShack - res://C:\WINDOWS\ImageShackToolbar\ImageShackToolbar.dll/5000
O8 - Extra context menu item: Upload Image to ImageShack - res://C:\WINDOWS\ImageShackToolbar\ImageShackToolbar.dll/5001
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.chikka.com
O15 - Trusted Zone:
http://toolbar.imageshack.usO15 - ESC Trusted Zone:
http://*.update.microsoft.comO16 - DPF: {01111E00-3E00-11D2-8470-0060089874ED} (Support.com SmartIssue) -
http://support.chart...oad/tgctlsi.cabO16 - DPF: {01111F00-3E00-11D2-8470-0060089874ED} (Support.com Installer) -
http://support.chart...ad/tgctlins.cabO16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) -
http://support.chart...oad/tgctlcm.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) -
http://picasaweb.goo...6/uploader2.cabO16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) -
https://www.e-games....GamesPlugin.cabO16 - DPF: {53B8B406-42E4-4DD3-96E7-9DEC8CEB3DD8} (ICQVideoControl Class) -
http://xtraz.icq.com...ideoControl.cabO16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) -
http://www.slide.com...ageUploader.cabO16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.syma...n/bin/cabsa.cabO16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) -
https://webdl.symant...ex/symdlmgr.cabO16 - DPF: {6BB594E2-6E4D-4CC9-98B0-931C323F9165} (DepHlp Control) -
http://mirror.worldw...ared/dephlp.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1130465459201O16 - DPF: {76D90D08-EAB7-46D8-BF99-87445BF59E72} (SystemInfo Class) -
http://directv.direc.../dpcsysinfo.cabO16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) -
http://chat.yahoo.com/cab/yuplapp.cabO16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) -
http://www.napster.c...ient/isetup.cabO16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) -
http://web1.shutterf...ds/Uploader.cabO16 - DPF: {CA797B15-445F-4AA9-9828-8A88502F560F} (Uninstall Control) -
http://www.worldwinn...d/uninstall.cabO16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) -
http://gamedownload....GPlugin9USA.cabO16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} (Zylom Loader Object) -
http://eu.download.g...zylomloader.cabO16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) -
http://www.adobe.com...obat/nos/gp.cabO16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
http://download.game...aploader_v6.cabO16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) -
http://www2.incredim...er/imloader.cabO20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Unknown owner - C:\Program Files\Norton AntiVirus\isPwdSvc.exe (file missing)
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (file missing)
O23 - Service: Norton LiveConnect Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (file missing)
O23 - Service: Norton LiveConnect Service Ex (pifCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\system32\ScsiAccess.EXE
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
--
End of file - 12870 bytes
Once again, I really appreciate you helping me, kahdah.