This is the copy of the Combofix log
ComboFix 08-04-20.5 - T. Tisdale 2008-04-22 9:39:29.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.429 [GMT -5:00]
Running from: C:\Documents and Settings\T. Tisdale\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\J. Tisdale\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\Program Files\FunWebProducts
C:\Program Files\MyWebSearch
C:\Program Files\MyWebSearch\bar\History\search2
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat
C:\Program Files\MyWebSearch\bar\Settings\setting2.htm
C:\Program Files\MyWebSearch\bar\Settings\settings.dat
C:\WINDOWS\dat.txt
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\srr.sys
C:\WINDOWS\system32\pac.txt
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_srr
-------\Legacy_srr
-------\Service_srr
((((((((((((((((((((((((( Files Created from 2008-03-22 to 2008-04-22 )))))))))))))))))))))))))))))))
.
2008-04-21 23:16 . 2008-04-21 23:26 <DIR> d----c--- C:\Documents and Settings\T. Tisdale\DoctorWeb
2008-04-01 13:11 . 2008-04-01 13:11 <DIR> d--h-c--- C:\WINDOWS\system32\Settings
2008-04-01 11:43 . 2008-04-21 12:57 840 --a--c--- C:\Settings.ini
2008-03-30 16:22 . 2008-03-30 16:22 <DIR> d----c--- C:\Documents and Settings\T. Tisdale\Application Data\1&1
2008-03-28 11:29 . 2008-03-28 11:51 <DIR> d----c--- C:\Documents and Settings\T. Tisdale\.roescache
2008-03-22 14:48 . 2008-04-21 20:11 <DIR> d----c--- C:\Documents and Settings\T. Tisdale\Application Data\LumaPix
2008-03-22 14:47 . 2008-03-22 14:47 255,235 --a--c--- C:\WINDOWS\FotoFusionV4 Uninstaller.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-22 11:36 --------- dc----w C:\Program Files\Common Files\Scanner
2008-04-22 01:02 --------- dc----w C:\Program Files\CleanUp!
2008-04-21 15:40 --------- dc----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-04-15 14:35 --------- dc----w C:\Program Files\WordPerfect Office 12
2008-04-15 14:30 --------- dc----w C:\Program Files\My Photo Calendars and Cards
2008-04-15 14:21 --------- dc----w C:\Program Files\Common Files\Sonic Shared
2008-04-15 00:12 --------- dc----w C:\Program Files\Picasa2
2008-04-14 21:57 --------- dc-h--w C:\Documents and Settings\All Users\Application Data\GTek
2008-03-30 21:22 --------- dc----w C:\Program Files\1&1
2008-03-19 09:47 1,845,248 -c----w C:\WINDOWS\system32\win32k.sys
2008-03-17 15:11 --------- dc----w C:\Program Files\SUPERAntiSpyware
2008-03-14 01:40 7,674 -c--a-w C:\WINDOWS\system32\KGyGaAvL.sys
2008-03-09 17:04 --------- dc----w C:\Program Files\Lavasoft
2008-03-09 17:04 --------- dc----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-09 17:03 --------- dc----w C:\Program Files\Common Files\Wise Installation Wizard
2008-03-09 15:19 10,752 -c--a-w C:\WINDOWS\DCEBoot.exe
2008-03-09 02:47 5,753 -c--a-w C:\WINDOWS\system32\vljffntg.dll
2008-03-08 23:59 --------- dc----w C:\Documents and Settings\Administrator\Application Data\SUPERAntiSpyware.com
2008-03-08 22:23 --------- dc----w C:\Documents and Settings\T. Tisdale\Application Data\SUPERAntiSpyware.com
2008-03-08 22:23 --------- dc----w C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-03-04 17:56 --------- dc----w C:\Program Files\Common Files\Adobe
2008-02-20 06:51 282,624 -c--a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 -c--a-w C:\WINDOWS\system32\dnsrslvr.dll
2007-03-13 19:59 251 -c--a-w C:\Program Files\wt3d.ini
2007-01-24 22:08 55,360 -c--a-w C:\Documents and Settings\T. Tisdale\Application Data\GDIPFONTCACHEV1.DAT
2006-07-10 15:17 88 -csh--r C:\WINDOWS\system32\513B09C918.sys
2006-07-10 21:27 88 -csh--r C:\WINDOWS\system32\EE77FBDEC7.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UfSeAgnt.exe"="C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe" [2008-02-16 00:56 1398024]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-10-18 17:58 696320]
"WinPatrol"="C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [2007-04-19 13:33 271936]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 0 (0x0)
"NoFileAssociate"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Intel\\Wireless\\Drivers\\iProDifX.exe"=
S0 ntcdrdrv;ntcdrdrv;C:\WINDOWS\system32\DRIVERS\ntcdrdrv.sys []
S3 m4301a;Linksys Wireless-B USB Network Adapter v4.0 Driver;C:\WINDOWS\system32\DRIVERS\m4301A.sys [2005-03-09 06:11]
S3 MovRSDrv32;MovRSDrv32;C:\WINDOWS\system32\drivers\MovRSDrv32.sys [2007-05-10 11:34]
S3 MovRVDrv32;MovRVDrv32;C:\WINDOWS\system32\DRIVERS\MovRVDrv32.sys [2007-05-10 13:01]
S3 SndTDriverV32;SndTDriverV32;C:\WINDOWS\system32\drivers\SndTDriverV32.sys [2006-08-11 15:56]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{66e1c5ec-85be-11dc-89a4-00130222578f}]
\Shell\AutoRun\command - E:\LinksysConnectPC.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bce60113-f5b8-11dc-8a56-00130222578f}]
\shell\play\command - "C:\Program Files\Real\RealPlayer\RealPlay.exe" /dvd %1
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-04-22 09:52:55
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\Documents and Settings\T. Tisdale\Application Data\Macromedia\Flash Player\#SharedObjects\DKFEZ7WQ\assets.espn.go.com\ivp\player
C:\Documents and Settings\T. Tisdale\Application Data\Macromedia\Flash Player\#SharedObjects\DKFEZ7WQ\assets.espn.go.com\ivp\player\player154.swf
C:\Documents and Settings\T. Tisdale\Application Data\Macromedia\Flash Player\#SharedObjects\DKFEZ7WQ\assets.espn.go.com\motion\fsp\FSPRoot\espnmotion13_cv.swf\fspSettings.sol 55 bytes
C:\Documents and Settings\T. Tisdale\Application Data\Macromedia\Flash Player\#SharedObjects\DKFEZ7WQ\assets.espn.go.com\motion\fsp\FSPRoot\espnmotion1_cv.swf
C:\Documents and Settings\T. Tisdale\Application Data\Macromedia\Flash Player\#SharedObjects\DKFEZ7WQ\atv.disney.go.com\hsm2DownloadPointsLSO.sol 61 bytes
C:\Documents and Settings\T. Tisdale\Application Data\Macromedia\Flash Player\#SharedObjects\DKFEZ7WQ\s7d1.scene7.com\is-viewers\flash\genericbrochureviewer.swf\#anntaylorloft\March2008Mailer_init.sol 235 bytes
C:\Documents and Settings\T. Tisdale\Application Data\Macromedia\Flash Player\#SharedObjects\DKFEZ7WQ\s7d1.scene7.com\is-viewers\flash\genericbrochureviewer.swf\#anntaylorloft\March2008Mailer_stickyNotes.sol 82 bytes
C:\Documents and Settings\T. Tisdale\Application Data\Macromedia\Flash Player\#SharedObjects\DKFEZ7WQ\s7d1.scene7.com\s7_anntaylorloft.sol 85 bytes
C:\Documents and Settings\T. Tisdale\Application Data\Macromedia\Flash Player\#SharedObjects\DKFEZ7WQ\sears.shoplocal.com\global282024.sol 147 bytes
C:\Documents and Settings\T. Tisdale\Application Data\Macromedia\Flash Player\#SharedObjects\DKFEZ7WQ\slide.com\ratings.sol 51 bytes
C:\Documents and Settings\T. Tisdale\Application Data\Macromedia\Flash Player\#SharedObjects\DKFEZ7WQ\slide.com\widgets
C:\Documents and Settings\T. Tisdale\Application Data\Macromedia\Flash Player\#SharedObjects\DKFEZ7WQ\slide.com\widgets\packages
C:\Documents and Settings\T. Tisdale\Application Data\Macromedia\Flash Player\#SharedObjects\DKFEZ7WQ\spe.atdmt.com\lp\fsi
C:\Documents and Settings\T. Tisdale\Application Data\Macromedia\Flash Player\#SharedObjects\DKFEZ7WQ\spe.atdmt.com\lp\fsi\swf\funshipisland.swf
C:\Documents and Settings\T. Tisdale\Application Data\Macromedia\Flash Player\#SharedObjects\DKFEZ7WQ\spe.atdmt.com\lp\fsi\swf\funshipisland.swf\funshipisland.sol 132 bytes
C:\Program Files\Common Files\Adobe\Launch\helpcenter\2.0\Adobe Help Center.lnk 1722 bytes
scan completed successfully
hidden files: 34
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
.
**************************************************************************
.
Completion time: 2008-04-22 10:06:35 - machine was rebooted
ComboFix-quarantined-files.txt 2008-04-22 15:06:18
Pre-Run: 6,869,372,928 bytes free
Post-Run: 6,780,862,464 bytes free
160 --- E O F --- 2008-04-11 03:10:40