here it is, everything is still running great. Thanks!
ComboFix 08-04-26.5 - Erin and Charlie 2008-04-30 20:37:23.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.174 [GMT -5:00]
Running from: C:\Documents and Settings\Erin and Charlie\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Erin and Charlie\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2008-04-01 to 2008-05-01 )))))))))))))))))))))))))))))))
.
2008-04-29 19:45 . 2008-04-29 19:45 0 --a------ C:\Documents and Settings\Erin and Charlie\.exe
2008-04-29 12:50 . 2008-04-29 12:50 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-04-29 12:50 . 2008-04-29 12:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-04-28 13:31 . 2008-04-29 19:58 <DIR> d-------- C:\HJT
2008-04-27 22:16 . 2008-04-27 22:16 <DIR> d-------- C:\WINDOWS\ERUNT
2008-04-27 22:13 . 2008-04-27 22:44 <DIR> d-------- C:\SDFix
2008-04-27 22:03 . 2008-04-27 22:57 9,662 --a------ C:\WINDOWS\system32\ZoneAlarmIconFR.ico
2008-04-27 21:46 . 2008-04-27 21:51 <DIR> d-------- C:\fixwareout
2008-04-26 22:17 . 2008-04-26 22:17 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-04-26 22:17 . 2008-04-26 22:17 1,409 --a------ C:\WINDOWS\QTFont.for
2008-04-26 09:12 . 2008-04-26 09:12 <DIR> d-------- C:\Documents and Settings\Erin and Charlie\Application Data\Malwarebytes
2008-04-26 09:11 . 2008-04-26 09:11 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-26 09:11 . 2008-04-26 09:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-25 22:04 . 2008-04-25 22:04 <DIR> d-------- C:\Program Files\Panda Security
2008-04-25 22:04 . 2008-04-25 22:04 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-25 22:04 . 2008-04-25 22:04 <DIR> d-------- C:\Documents and Settings\sal\Application Data\TmpRecentIcons
2008-04-25 21:32 . 2008-04-25 21:32 <DIR> d-------- C:\Documents and Settings\sal\Application Data\Talkback
2008-04-25 20:29 . 2008-04-25 22:04 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Move Networks
2008-04-24 14:45 . 2008-04-24 14:45 10 --a------ C:\WINDOWS\wintst32.tmp
2008-04-24 09:29 . 2005-08-06 04:14 <DIR> d-------- C:\Documents and Settings\sal\Application Data\Symantec
2008-04-24 09:29 . 2005-08-06 04:06 <DIR> d-------- C:\Documents and Settings\sal\Application Data\Jasc Software Inc
2008-04-24 09:29 . 2005-08-06 03:58 <DIR> d-------- C:\Documents and Settings\sal\Application Data\Intel
2008-04-24 09:29 . 2008-04-24 11:28 <DIR> d-------- C:\Documents and Settings\sal
2008-04-24 09:29 . 2008-04-30 20:43 1,024 --ah----- C:\Documents and Settings\sal\ntuser.dat.LOG
2008-04-22 09:32 . 2008-04-22 09:37 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\eAcceleration
2008-04-21 16:46 . 2008-04-21 16:46 <DIR> d-------- C:\Documents and Settings\Erin and Charlie\Application Data\TmpRecentIcons
2008-04-21 15:17 . 2008-04-21 15:17 577,536 --a------ C:\WINDOWS\system32\user32.dll
2008-04-21 12:23 . 2008-04-26 10:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Common
2008-04-16 13:02 . 2008-03-10 20:14 100,696 --a------ C:\WINDOWS\system32\drivers\fwcore.sys
2008-04-16 13:01 . 2008-04-16 13:02 <DIR> d-------- C:\Program Files\Acceleration Software
2008-04-16 13:01 . 2008-04-16 13:02 <DIR> d-------- C:\Documents and Settings\Erin and Charlie\Application Data\eAcceleration
2008-04-16 12:52 . 2008-04-16 13:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\eAcceleration
2008-04-16 12:51 . 2008-04-16 13:02 <DIR> d-------- C:\Program Files\eAcceleration
2008-04-16 12:51 . 2008-04-16 14:20 <DIR> d-------- C:\Program Files\Common Files\eAcceleration
2008-04-09 21:07 . 2008-03-01 08:06 6,066,176 --------- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-04-09 21:07 . 2007-06-30 22:31 2,455,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-04-09 21:07 . 2007-06-30 22:36 991,232 --------- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-04-09 21:07 . 2008-03-01 08:06 459,264 --------- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-04-09 21:07 . 2008-03-01 08:06 383,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-04-09 21:07 . 2008-03-01 08:06 267,776 --------- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-04-09 21:07 . 2008-03-01 08:06 63,488 --------- C:\WINDOWS\system32\dllcache\icardie.dll
2008-04-09 21:07 . 2008-03-01 08:06 52,224 --------- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-04-09 21:07 . 2008-02-22 05:00 13,824 --------- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-04-08 19:26 . 2008-04-21 08:45 <DIR> d-------- C:\Documents and Settings\cs\Application Data\eAcceleration
2008-04-08 18:37 . 2008-04-08 18:37 <DIR> d-------- C:\Registry Mechanic 5
2008-04-08 18:35 . 2008-04-08 18:37 <DIR> d-------- C:\Documents and Settings\Erin and Charlie\Application Data\U3
2008-04-08 09:28 . 2008-04-08 09:28 <DIR> d-------- C:\Documents and Settings\Erin and Charlie\Application Data\SUPERAntiSpyware.com
2008-04-07 20:36 . 2008-04-07 20:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-04-07 20:33 . 2008-04-07 20:33 <DIR> d-------- C:\Documents and Settings\cs\Application Data\SUPERAntiSpyware.com
2008-04-07 20:19 . 2008-04-07 20:19 <DIR> d-------- C:\Documents and Settings\cs\Application Data\Grisoft
2008-04-07 18:12 . 2008-04-07 18:12 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Grisoft
2008-04-07 18:09 . 2008-04-07 18:09 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Talkback
2008-04-07 18:06 . 2005-08-06 04:14 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec
2008-04-07 18:06 . 2005-08-06 04:06 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2008-04-07 18:06 . 2005-08-06 03:58 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Intel
2008-04-07 18:06 . 2008-04-25 12:53 <DIR> d-------- C:\Documents and Settings\Administrator
2008-04-07 18:06 . 2008-04-07 20:08 786,432 --ah----- C:\Documents and Settings\Administrator\ntuser.dat.rmbak
2008-04-07 18:06 . 2008-04-30 12:42 1,024 --ah----- C:\Documents and Settings\Administrator\ntuser.dat.LOG
2008-04-07 17:27 . 2008-04-07 17:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-04-05 17:06 . 2008-04-05 17:05 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-04-05 17:00 . 2008-04-05 17:18 <DIR> d-------- C:\Documents and Settings\Erin and Charlie\.housecall6.6
2008-04-05 10:58 . 2008-04-08 09:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-05 10:32 . 2008-04-05 10:32 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-04-05 10:32 . 2008-04-05 10:33 <DIR> d-------- C:\Documents and Settings\Erin and Charlie\Application Data\AVG7
2008-04-05 10:31 . 2008-04-26 11:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-04-05 10:06 . 2008-04-28 08:43 1,695 --a------ C:\WINDOWS\system32\clbcfg.dat
2008-04-05 09:51 . 2004-08-04 05:00 4,224 --a------ C:\WINDOWS\system32\beep.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-28 15:09 --------- d-----w C:\Program Files\FriendBlasterPro
2008-04-16 04:27 --------- d-----w C:\Documents and Settings\Erin and Charlie\Application Data\AdobeUM
2008-04-16 03:38 --------- d-----w C:\Program Files\Java
2008-04-08 21:01 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-04-08 21:00 --------- d-----w C:\Program Files\Dell
2008-04-08 20:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-04-08 14:29 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-08 14:19 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-08 14:19 --------- d-----w C:\Program Files\Bonjour
2008-04-08 14:10 --------- d-----w C:\Program Files\MySpace
2008-04-02 20:28 --------- d-----w C:\Documents and Settings\cs\Application Data\Symantec
2008-03-20 21:20 --------- d-----w C:\Documents and Settings\Erin and Charlie\Application Data\LimeWire
2008-03-16 02:47 --------- d-----w C:\Program Files\Netflix
2008-03-13 19:33 --------- d-----w C:\Program Files\Dl_cats
2008-01-29 04:06 13 ---h--w C:\Documents and Settings\All Users\Application Data\ys.sys
2006-04-14 04:13 8 ----a-w C:\Documents and Settings\Erin and Charlie\Application Data\usb.dat.bin
2006-07-17 03:52 56 --sh--r C:\WINDOWS\system32\6C8C8E3348.sys
2006-07-17 03:52 1,890 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
Infected C:\WINDOWS\system32\user32.dll hex repaired------- Sigcheck -------
2008-04-26 10:46 17408 d68cfcdab7de1e0bcb0df405fbdca59d C:\WINDOWS\system32\svchost.exe
2005-05-25 14:07 359936 63fdfea54eb53de2d863ee454937ce1e C:\WINDOWS\$hf_mig$\KB893066\SP2QFE\tcpip.sys
2006-01-13 12:07 360448 5562cc0a47b2aef06d3417b733f3c195 C:\WINDOWS\$hf_mig$\KB913446\SP2QFE\tcpip.sys
2006-04-20 07:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2007-10-30 11:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2004-08-04 05:00 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\$NtUninstallKB893066$\tcpip.sys
2005-05-25 14:04 359808 88763a98a4c26c409741b4aa162720c9 C:\WINDOWS\$NtUninstallKB913446$\tcpip.sys
2006-01-12 21:28 359808 583e063fdc888ca30d05c2724b0d7ef4 C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys
2006-04-20 06:51 359808 1dbf125862891817f374f407626967f4 C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
2007-10-30 12:20 360064 ecf02439fd31bbd0dbc2ec05600cf08a C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-30 12:20 360064 ecf02439fd31bbd0dbc2ec05600cf08a C:\WINDOWS\system32\drivers\tcpip.sys
2004-08-04 05:00 506368 20f8e68d0b7689804b92ce746277f57f C:\WINDOWS\system32\winlogon.exe
2007-06-13 05:23 1035776 b59f5f910bab2cbd69527f11c6997a1a C:\WINDOWS\explorer.exe
2007-06-13 06:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2004-08-04 05:00 1032192 a0732187050030ae399b241436565e64 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
.
((((((((((((((((((((((((((((( snapshot@2008-04-27_23.23.19.10 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-07-26 04:20:23 110,080 ----a-w C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\clbcatex.dll
+ 2005-07-26 04:20:24 498,688 ----a-w C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\clbcatq.dll
+ 2004-08-04 10:00:00 110,080 -c----w C:\WINDOWS\$NtUninstallKB902400$\clbcatex.dll
+ 2004-08-04 10:00:00 501,248 -c----w C:\WINDOWS\$NtUninstallKB902400$\clbcatq.dll
- 2008-04-28 04:14:14 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-01 01:43:22 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2004-08-04 10:00:00 10,752 ----a-w C:\WINDOWS\system32\clb.dll
+ 2005-07-26 04:39:43 110,080 ----a-w C:\WINDOWS\system32\clbcatex.dll
+ 2005-07-26 04:39:43 498,688 ----a-w C:\WINDOWS\system32\clbcatq.dll
- 2008-04-28 04:14:16 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-04-28 13:41:30 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-04-28 04:14:16 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-04-28 13:41:30 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-04-28 04:14:16 65,536 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-04-28 13:41:30 65,536 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2005-05-24 17:27:16 213,048 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 20:47:20 94,208 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 20:49:54 950,272 ----a-w C:\WINDOWS\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-18 19:39 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-09-13 16:33 155648]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-02-15 15:02 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-02-15 15:02 126976]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 14:59 385024]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2004-04-11 20:15 290816]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 16:19 53248]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41 282624]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 16:50 221184]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 16:50 81920]
"Dell Photo AIO Printer 922"="C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe" [2004-11-10 14:36 290816]
"DLBTCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll" [2004-11-09 16:41 69632]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-11-23 16:05 180269]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2005-05-31 06:33 122941]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-04-27 11:25 257088]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 10:24 16384]
"RegistryMechanic"="" []
"SoftwareStation"="C:\Program Files\eAcceleration\Station\station.exe" [2008-03-24 18:10 173392]
"StopSignSsTsMon"="C:\Program Files\Acceleration Software\Anti-Virus\sstsmon.dll" [2007-12-10 21:13 152976]
"StopSignSsSsMon"="C:\Program Files\Acceleration Software\Anti-Virus\ssssmon.dll" [2007-12-19 14:50 140696]
"webscan"="C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe" [2007-12-19 21:20 771504]
"StopSignSsFwMon"="C:\Program Files\eAcceleration\Firewall\ssfwmon.dll" [2008-03-05 15:41 222544]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"StopSignSsSsMon"="C:\Program Files\Acceleration Software\Anti-Virus\ssssmon.dll" [2007-12-19 14:50 140696]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-09-27 20:17 443968]
"InetChk"="C:\WINDOWS\TEMP\ms1209599565.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-04 05:00 53760 C:\WINDOWS\system32\narrator.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06 29696]
America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0\aoltray.exe [2005-08-06 04:08:57 156784]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 11:59:36 806912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"kRnvR"= {E8B12EF5-421B-845F-A444-6EFABDEE9A4C} - C:\WINDOWS\system32\vk.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 16:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"=
"C:\\Program Files\\America Online 9.0\\waol.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\FriendBlasterPro\\FriendBlasterPro.exe"=
"C:\\Program Files\\Kontiki\\KService.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8925:TCP"= 8925:TCP:BitComet 8925 TCP
"8925:UDP"= 8925:UDP:BitComet 8925 UDP
R0 fwcore;Fwcore Filter;C:\WINDOWS\system32\drivers\fwcore.sys [2008-03-10 20:14]
R2 eac_notifysvc;eAcceleration Notification Service;"C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_svc.exe" [2008-03-24 18:46]
R2 eac_productsvc;eAcceleration Product Manager Service;"C:\PROGRA~1\EACCEL~1\FRAMEW~1\eac_productsvc.exe" [2008-03-24 18:46]
R2 FWService;FWService;C:\Program Files\eAcceleration\Firewall\FWService.exe [2008-03-10 20:14]
R2 OpenCASE Media Agent;OpenCASE Media Agent;"C:\Program Files\OpenCASE\OpenCASE Media Agent\MediaAgent.exe" [2007-11-06 18:04]
S2 wzcsvcrasauto;Wireless Zero Configuration WZCSVCRasAuto;C:\WINDOWS\system32\6C8C8E3348v.exe []
S3 EraserUtilDrv10501;EraserUtilDrv10501;C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv10501.sys []
S3 PTDCBus;PANTECH PC Card Composite Device Driver (UDP);C:\WINDOWS\system32\DRIVERS\PTDCBus.sys [2007-01-11 03:30]
S3 PTDCMdm;PANTECH PC Card Drivers (UDP);C:\WINDOWS\system32\DRIVERS\PTDCMdm.sys [2007-01-11 03:30]
S3 PTDCVsp;PANTECH PC Card Diagnostic Serial Port (UDP);C:\WINDOWS\system32\DRIVERS\PTDCVsp.sys [2007-01-11 03:30]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
"2008-05-01 01:56:00 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDetect.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-04-30 20:46:05
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe
C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
C:\Program Files\Apoint\ApntEx.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\eAcceleration\Station\station_bk.exe
.
**************************************************************************
.
Completion time: 2008-04-30 20:57:06 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-01 01:56:21
ComboFix2.txt 2008-04-29 17:36:14
ComboFix3.txt 2008-04-28 22:05:41
ComboFix4.txt 2008-04-28 18:53:24
ComboFix5.txt 2008-04-28 04:24:27
Pre-Run: 36,889,866,240 bytes free
Post-Run: 36,913,967,104 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
265 --- E O F --- 2008-04-16 03:22:17