Combofix log:
ComboFix 08-05-01.3 - Mr.Joe L 2008-05-04 13:16:44.6 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.876 [GMT -4:00]
Running from: C:\Documents and Settings\Mr.Joe L\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((( Files Created from 2008-04-04 to 2008-05-04 )))))))))))))))))))))))))))))))
.
2008-05-04 13:14 . 2008-05-04 13:14 <DIR> d-------- C:\_OTMoveIt
2008-05-01 17:26 . 2007-11-28 11:49 104,217 --------- C:\WINDOWS\hpoins04.dat.temp
2008-05-01 17:26 . 2004-06-22 09:04 17,176 --------- C:\WINDOWS\hpomdl04.dat.temp
2008-05-01 14:32 . 2008-05-01 14:32 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-01 14:32 . 2008-05-01 14:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-01 13:19 . 2008-05-01 13:19 <DIR> d-------- C:\Documents and Settings\Mr.Joe L\Application Data\Malwarebytes
2008-05-01 13:19 . 2008-05-01 13:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-01 13:18 . 2008-05-01 14:19 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-30 20:57 . 2008-04-30 20:57 <DIR> d-------- C:\Documents and Settings\Mr.Joe L\Application Data\Ulead Systems
2008-04-30 20:28 . 2008-04-30 20:29 <DIR> d-------- C:\Program Files\Common Files\Ulead Systems
2008-04-30 20:28 . 2008-04-30 20:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Ulead Systems
2008-04-30 19:58 . 2008-04-30 19:58 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
2008-04-30 19:58 . 2008-04-30 19:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Adobe Systems
2008-04-25 04:58 . 2008-04-25 21:17 385 --a------ C:\WINDOWS\BeatBox.INI
2008-04-25 04:58 . 2008-04-25 21:16 376 --a------ C:\WINDOWS\Sampler.INI
2008-04-25 04:58 . 2008-04-25 21:16 28 --a------ C:\WINDOWS\Robota.INI
2008-04-25 04:36 . 2006-07-18 00:03 49,152 --a------ C:\WINDOWS\system32\mgxasio2.dll
2008-04-21 19:37 . 2008-04-21 20:01 <DIR> d-------- C:\Program Files\EPSON
2008-04-21 19:37 . 2001-03-05 11:15 61,598 --a------ C:\WINDOWS\system32\E_SL2352.DLL
2008-04-21 19:37 . 2000-06-07 10:01 34,304 --a------ C:\WINDOWS\system32\EBPCHP.DLL
2008-04-21 19:37 . 2000-06-26 11:20 32,768 --a------ C:\WINDOWS\system32\ECBTEG.DLL
2008-04-21 19:37 . 2000-09-14 11:03 145 --a------ C:\WINDOWS\system32\EBPPORT.DAT
2008-04-20 00:33 . 2008-04-26 01:34 <DIR> d-------- C:\Program Files\SpywareBlaster
2008-04-20 00:33 . 2008-04-30 19:31 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-18 13:36 . 2008-04-21 09:43 1,704 --a------ C:\WINDOWS\system32\tmp.reg
2008-04-16 09:53 . 2008-04-20 23:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\cbwvufqb
2008-04-10 13:56 . 2005-09-20 10:31 135,168 --a------ C:\WINDOWS\system32\igfxres.dll
2008-04-10 13:49 . 2005-09-20 10:36 114,688 --a------ C:\WINDOWS\system32\igfxpers.exe
2008-04-10 13:49 . 2005-09-20 10:35 94,208 --a------ C:\WINDOWS\system32\igfxtray.exe
2008-04-10 13:49 . 2005-09-20 10:32 77,824 --a------ C:\WINDOWS\system32\hkcmd.exe
2008-04-08 22:19 . 2002-07-07 18:14 1,294,336 --a------ C:\WINDOWS\system32\vorbis.acm
2008-04-08 22:19 . 2006-03-30 18:39 368,640 --a------ C:\WINDOWS\system32\ReWire.dll
2008-04-04 10:04 . 2008-05-03 23:09 <DIR> d-------- C:\Program Files\PeerGuardian2
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-04 04:41 --------- d-----w C:\Documents and Settings\Mr.Joe L\Application Data\Vso
2008-05-04 03:09 --------- d-----w C:\Documents and Settings\Mr.Joe L\Application Data\uTorrent
2008-05-02 04:26 --------- d-----w C:\Program Files\DesignPro
2008-05-01 00:30 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-01 00:06 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-27 02:44 --------- d-----w C:\Program Files\HP
2008-04-25 08:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\MAGIX
2008-04-25 08:42 --------- d-----w C:\Program Files\Common Files\MAGIX Shared
2008-04-21 16:32 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-04-21 16:06 --------- d-----w C:\Documents and Settings\Mr.Joe L\Application Data\LimeWire
2008-04-21 14:19 --------- d-----w C:\Program Files\Java
2008-04-10 16:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-04-05 04:44 --------- d-----w C:\Documents and Settings\Mr.Joe L\Application Data\SprillBermudeEng
2008-04-01 18:43 --------- d-----w C:\Documents and Settings\Mr.Joe L\Application Data\Sahmon Games
2008-03-31 06:12 --------- d-----w C:\Documents and Settings\Mr.Joe L\Application Data\ViquaSoft
2008-03-29 15:12 --------- d-----w C:\Program Files\DVDInfoPro
2008-03-22 20:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\SlySoft
2008-03-21 04:54 --------- d-----w C:\Documents and Settings\Mr.Joe L\Application Data\GetRightToGo
2008-03-20 21:13 23,600 ----a-w C:\WINDOWS\system32\drivers\TVICHW32.SYS
2008-03-20 00:23 --------- d-----w C:\Program Files\MagicISO
2008-03-19 09:40 1,845,888 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-14 03:45 --------- d-----w C:\Program Files\Easy Video Joiner
2008-03-13 18:31 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-03-10 06:01 --------- d-----w C:\Program Files\QuickTime
2008-03-04 01:41 --------- d-----w C:\Program Files\SystemRequirementsLab
2008-03-02 17:17 47,360 -c--a-w C:\Documents and Settings\Mr.Joe L\Application Data\pcouffin.sys
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-20 18:49 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-20 06:52 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-01-18 06:48 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
<pre>
----a-w 39,792 2007-12-23 06:19:57 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl .exe
-c--a-w 94,208 2007-12-23 13:08:59 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor .exe
-c--a-w 579,072 2007-12-23 13:53:39 C:\Program Files\Grisoft\AVG7\avgcc .exe
----a-w 49,152 2007-12-23 13:53:47 C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe
-c--a-w 241,664 2007-12-23 13:53:55 C:\Program Files\HP\hpcoretech\hpcmpmgr .exe
-c--a-w 31,016 2007-12-23 13:54:08 C:\Program Files\Microsoft Office\Office12\GrooveMonitor .exe
----a-w 200,704 2008-01-23 16:32:02 C:\Program Files\PowerISO\PWRISOVM .EXE
-c--a-w 282,624 2008-02-23 03:31:21 C:\Program Files\QuickTime\qttask .exe
----a-w 15,360 2007-12-23 13:54:14 C:\WINDOWS\system32\ctfmon .exe
----a-w 114,688 2007-12-23 13:53:47 C:\WINDOWS\system32\igfxpers .exe
----a-w 94,208 2007-12-23 13:53:41 C:\WINDOWS\system32\igfxtray .exe
</pre>
------- Sigcheck -------
2007-10-30 12:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2007-12-26 23:29 360576 87b872f35f67bd199e0a93812673ed5b C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
2008-02-18 00:35 360064 482ab7f9cd41702e8f856c11cfefb02d C:\WINDOWS\system32\dllcache\tcpip.sys
2008-02-18 00:34 360064 482ab7f9cd41702e8f856c11cfefb02d C:\WINDOWS\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [ ]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-03-29 14:37 79224]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 10:35 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 10:32 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 10:36 114688]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"Ulead AutoDetector v2"="C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe" [2007-08-02 21:08 95504]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL 2008-03-09 12:14 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
"msacm.ac3filter"= ac3filter.acm
"msacm.fraunhoferacm"= l3codecp.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=C:\WINDOWS\pss\HP Image Zone Fast Start.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Mr.Joe L^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=C:\Documents and Settings\Mr.Joe L\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=C:\WINDOWS\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyDVD]
--a------ 2008-01-23 13:04 89024 C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FAST Defrag]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 11:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
C:\Program Files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a--c--- 2008-02-22 23:31 282624 C:\Program Files\QuickTime\qttask .exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-08-30 18:43 4670704 C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Microsoft Office Groove Audit Service"=3 (0x3)
"FirebirdServerMAGIXInstance"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 14:31]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 14:35]
R2 HWiNFO32;HWiNFO32 Kernel Driver;C:\Program Files\HWiNFO32\HWiNFO32.SYS [2007-09-14 15:15]
R3 Envy24HFS;ICE Envy24 Family Audio Controller WDM;C:\WINDOWS\system32\drivers\Envy24HF.sys [2004-11-25 22:55]
R3 uscbs109;uscbs109;C:\WINDOWS\system32\DRIVERS\uscbs109.sys [2005-03-22 01:00]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;F:\Program Files\Common\Database\bin\fbserver.exe []
S3 UPnPService;UPnPService;C:\Program Files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe [2006-12-14 16:00]
S3 uscsc109;uscsc109;C:\WINDOWS\system32\DRIVERS\uscsc109.sys [2005-03-22 01:00]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\start.exe /checksection
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\Shell\AutoRun\command - H:\Setup.exe -auto
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4bb40058-da94-11dc-b41e-89e9512d523d}]
\Shell\AutoRun\command - H:\Launch.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-05-04 13:18:05
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2008-05-04 13:21:11
ComboFix-quarantined-files.txt 2008-05-04 17:20:06
ComboFix2.txt 2008-04-30 23:27:50
ComboFix3.txt 2008-04-18 18:12:02
ComboFix4.txt 2008-03-15 04:32:02
ComboFix5.txt 2008-02-18 02:58:17
Pre-Run: 29,521,272,832 bytes free
Post-Run: 29,513,121,792 bytes free
183 --- E O F --- 2008-04-10 16:47:41
Also the OT log:
OT log:
File/Folder C:\Documents and Settings\Mr.Joe L\My Documents\Misc\Windows Keygen and WgaPatcher\keyfinder.exe not found.
OTMoveIt2 by OldTimer - Version 1.0.4.1 log created on 05042008_131403
I'm sorry i deleted that folder last night. Thanks.