ok.. had to leave for a few.. once i got back Malwarebytes' Anti-Malware completed it's scanning & found nothing. As you told me above, i ran ComboFix.. the log is below
ComboFix 08-05-01.3 - Scott Drummond 2008-05-03 17:23:50.1 -
FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.147 [GMT -4:00]
Running from: C:\Documents and Settings\Scott Drummond\Desktop\ComboFix.exe
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\start.exe
C:\WINDOWS\Web\default.htt
.
((((((((((((((((((((((((( Files Created from 2008-04-03 to 2008-05-03 )))))))))))))))))))))))))))))))
.
2008-05-03 17:23 . 2008-05-03 17:23 1,024 --ah----- C:\WINDOWS\SYSTEM32\config\systemprofile\ntuser.dat.LOG
2008-05-03 14:29 . 2008-05-03 14:29 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-03 14:29 . 2008-05-03 14:29 <DIR> d-------- C:\Documents and Settings\Scott Drummond\Application Data\Malwarebytes
2008-05-03 14:29 . 2008-05-03 14:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-03 14:28 . 2008-05-03 14:28 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-05-03 13:06 . 2008-05-03 13:06 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-03 13:04 . 2008-05-03 13:04 <DIR> d-------- C:\Program Files\Lavasoft
2008-05-03 12:19 . 2008-05-03 12:19 0 --a------ C:\WINDOWS\SYSTEM32\SDRemoveDB.db
2008-05-03 12:14 . 2008-04-15 10:29 12,752 --a------ C:\WINDOWS\SYSTEM32\SDEarlyDelete.exe
2008-05-03 12:14 . 2008-05-03 12:14 110 --a------ C:\WINDOWS\SYSTEM32\SDEarlyDelete.ini
2008-05-03 12:14 . 2008-05-03 12:14 63 --a------ C:\WINDOWS\SYSTEM\SysSD.dll
2008-05-03 12:12 . 2008-05-03 12:12 <DIR> d-------- C:\Program Files\SpywareDetector
2008-05-03 12:12 . 2008-04-24 11:48 839,680 --a------ C:\WINDOWS\SYSTEM32\CheckDll.dll
2008-05-03 11:02 . 2008-05-03 11:02 <DIR> d-------- C:\Documents and Settings\Scott Drummond\Application Data\iolo
2008-05-03 11:02 . 2008-05-03 11:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\iolo
2008-05-03 11:02 . 2008-05-03 11:02 406 --a------ C:\WINDOWS\SYSTEM32\ioloBootDefrag.cfg
2008-04-29 19:06 . 2008-04-29 19:06 <DIR> d-------- C:\Program Files\Microsoft ActiveSync
2008-04-29 19:06 . 2005-10-20 21:47 30,592 --------- C:\WINDOWS\SYSTEM32\DRIVERS\rndismpx.sys
2008-04-29 19:06 . 2005-10-20 21:47 12,800 --------- C:\WINDOWS\SYSTEM32\DRIVERS\usb8023x.sys
2008-04-29 19:05 . 2008-04-29 19:05 <DIR> d-------- C:\Program Files\Windows Mobile Device Handbook
2008-04-21 21:47 . 2008-04-21 21:47 <DIR> d-------- C:\Documents and Settings\Scott Drummond\Application Data\Move Networks
2008-04-19 21:25 . 2008-04-19 21:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Google Updater
2008-04-19 19:22 . 2008-03-05 16:03 238,088 --a------ C:\WINDOWS\SYSTEM32\xactengine3_0.dll
2008-04-19 19:22 . 2008-03-05 16:00 25,608 --a------ C:\WINDOWS\SYSTEM32\X3DAudio1_3.dll
2008-04-19 19:20 . 2006-09-28 16:05 2,414,360 --a------ C:\WINDOWS\SYSTEM32\d3dx9_31.dll
2008-04-13 12:15 . 2008-04-13 12:15 <DIR> d-------- C:\Documents and Settings\Maranda\Application Data\MySpace
2008-04-06 12:56 . 2008-04-06 12:56 <DIR> d-------- C:\Documents and Settings\Scott Drummond\Application Data\ApplicationHistory
2008-04-06 03:54 . 2008-04-06 03:54 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-04-06 03:05 . 2008-04-06 03:05 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-05 16:52 . 2008-04-05 16:52 <DIR> d-------- C:\baccb9a0987cc2f8722ee6
2008-04-05 16:52 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\SYSTEM32\spmsg2.dll
2008-04-05 16:46 . 2008-04-05 16:46 <DIR> d-------- C:\WINDOWS\SYSTEM32\URTTEMP
2008-04-05 15:20 . 2008-03-13 23:11 75,248 --a------ C:\WINDOWS\zllsputility.exe
2008-04-05 14:25 . 2008-04-05 14:25 <DIR> d-------- C:\Documents and Settings\Scott Drummond\Apps
2008-04-05 11:46 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\SYSTEM32\mucltui.dll
2008-04-05 11:46 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\SYSTEM32\muweb.dll
2008-04-05 00:26 . 2008-04-05 00:26 <DIR> d-------- C:\Program Files\Zone Labs
2008-04-04 22:59 . 2008-04-04 22:59 <DIR> d--hs---- C:\FOUND.032
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-19 21:41 1,426,944 ------w C:\WINDOWS\Internet Logs\xDB2.tmp
2008-04-13 07:34 1,413,632 ------w C:\WINDOWS\Internet Logs\xDB6.tmp
2008-04-07 02:18 17,144 ----a-w C:\Documents and Settings\Scott Drummond\Application Data\GDIPFONTCACHEV1.DAT
2008-04-01 05:05 --------- d-----w C:\Program Files\MSXML 6.0
2008-04-01 04:29 --------- d-----w C:\Program Files\Google
2008-03-31 03:42 --------- d-----w C:\Program Files\MSBuild
2008-03-31 03:29 --------- d-----w C:\Program Files\Reference Assemblies
2008-03-30 05:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\Azureus
2008-03-30 05:49 --------- d-----w C:\Documents and Settings\Scott Drummond\Application Data\Azureus
2008-03-30 05:41 --------- d-----w C:\Program Files\Azureus(2)
2008-03-29 19:58 --------- d-----w C:\Program Files\SUPERAntiSpyware
2008-03-29 19:58 --------- d-----w C:\Documents and Settings\Scott Drummond\Application Data\SUPERAntiSpyware.com
2008-03-29 16:55 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-03-29 16:50 --------- d-----w C:\Program Files\Microsoft SQL Server Compact Edition
2008-03-29 16:07 --------- d-----w C:\Program Files\Windows Live
2008-03-29 16:07 --------- d-----w C:\Program Files\Common Files\WindowsLiveInstaller
2008-03-29 16:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-03-29 08:37 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-03-29 08:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-27 00:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\SecTaskMan
2008-03-27 00:24 --------- d-----w C:\Program Files\Security Task Manager
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\SYSTEM32\win32k.sys
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\SYSTEM32\win32k(2)(2).sys
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\SYSTEM32\dllcache\win32k.sys
2008-03-16 22:11 --------- d-----w C:\Documents and Settings\Scott Drummond\Application Data\ZoomBrowser EX
2008-03-16 21:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2008-03-16 20:50 --------- d-----w C:\Program Files\Common Files\Canon
2008-03-16 18:33 --------- d--h--w C:\Documents and Settings\Scott Drummond\Application Data\yahoo!
2008-03-15 18:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-03-15 18:25 --------- d-----w C:\Program Files\Yahoo!
2008-03-15 17:48 --------- d-----w C:\Documents and Settings\Scott Drummond\Application Data\MySpace
2008-03-15 17:47 --------- d-----w C:\Program Files\MySpace
2008-03-15 00:25 --------- d-----w C:\Program Files\Java
2008-03-15 00:24 --------- d-----w C:\Program Files\Common Files\Java
2008-03-14 05:43 --------- d-----w C:\Program Files\Winamp
2008-03-14 05:43 --------- d-----w C:\Documents and Settings\Scott Drummond\Application Data\Winamp
2008-03-14 03:11 1,086,952 ----a-w C:\WINDOWS\SYSTEM32\zpeng24.dll
2008-03-12 23:58 --------- d-----w C:\Program Files\NoAds
2008-03-12 23:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-12 01:59 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-03-12 00:57 --------- d-----w C:\Documents and Settings\Guest\Application Data\Talkback
2008-03-12 00:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-11 22:40 --------- d-----w C:\Documents and Settings\Scott Drummond\Application Data\Talkback
2008-03-11 21:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-03-05 19:56 3,786,760 ----a-w C:\WINDOWS\SYSTEM32\D3DX9_37.dll
2008-03-05 19:56 1,420,824 ----a-w C:\WINDOWS\SYSTEM32\D3DCompiler_37.dll
2008-03-01 22:36 3,591,680 ------w C:\WINDOWS\SYSTEM32\dllcache\mshtml.dll
2008-02-29 08:55 70,656 ------w C:\WINDOWS\SYSTEM32\dllcache\ie4uinit.exe
2008-02-29 08:55 625,664 ------w C:\WINDOWS\SYSTEM32\dllcache\iexplore.exe
2008-02-22 10:00 13,824 ------w C:\WINDOWS\SYSTEM32\dllcache\ieudinit.exe
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\SYSTEM32\gdi32.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\SYSTEM32\gdi32(2)(2).dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\SYSTEM32\dllcache\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\SYSTEM32\dnsrslvr.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\SYSTEM32\dnsrslvr(2)(2).dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\SYSTEM32\dllcache\dnsrslvr.dll
2008-02-20 05:32 148,992 ----a-w C:\WINDOWS\SYSTEM32\dnsapi(2)(2).dll
2008-02-20 05:32 148,992 ----a-w C:\WINDOWS\SYSTEM32\dllcache\dnsapi.dll
2008-02-15 05:44 161,792 ------w C:\WINDOWS\SYSTEM32\dllcache\ieakui.dll
2008-02-06 03:07 462,864 ----a-w C:\WINDOWS\SYSTEM32\d3dx10_37.dll
2007-11-16 22:08 271 --sh--w C:\Program Files\desktop.ini
2007-11-16 22:08 23,357 ---h--w C:\Program Files\folder.htt
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NoAds"="C:\Program Files\NoAds\NoAds.exe" [2008-03-12 19:58 151552]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 12:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-19 21:25 68856]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 13:39 1289000]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SystemTray"="SysTray.Exe" [2004-08-04 12:00 3072 C:\WINDOWS\SYSTEM32\systray.exe]
"LVCOMS"="C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE" [2002-12-10 17:54 127022]
"PDUiP6220DMon"="C:\Program Files\Canon\Memory Card Utility\iP6220D\PDUiP6220DMon.exe" [2005-05-06 18:17 69632]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-18 21:39 579584]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-03-13 23:11 919016]
"SystemTraySD"="C:\Program Files\SpywareDetector\SDSystemTray.exe" [2008-04-16 17:52 2090448]
"SDAutoLiveupdate"="C:\Program Files\SpywareDetector\LiveUpdateSD.exe" [2008-04-24 10:55 1598928]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-03-11 20:18 219136]
"MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2008-02-01 16:32 8699904]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 15:05:56 65588]
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-04-19 21:25:27 124400]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 12:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SDNotify]
C:\Program Files\SpywareDetector\SDNotify.dll 2008-04-16 17:04 446464 C:\Program Files\SpywareDetector\SDNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.VDOM"= vdowave.drv
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"HydarVisionDesktopManager"=desk98.exe
"AtiPTA"=atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R3 ES1370;Creative AudioPCI (ES1370), SB PCI 64/128 (WDM);C:\WINDOWS\system32\drivers\ES1370MP.sys [2002-08-05 11:17]
S3 NtApm;NT Apm/Legacy Interface Driver;C:\WINDOWS\system32\DRIVERS\NtApm.sys [2001-08-17 13:47]
*Newly Created Service* - AAWSERVICE
*Newly Created Service* - CATCHME
*Newly Created Service* - SDSERVICE
.
Contents of the 'Scheduled Tasks' folder
"2008-05-03 18:00:02 C:\WINDOWS\Tasks\Tune-up Application Start.job"
"2008-05-03 21:31:04 C:\WINDOWS\Tasks\PCHealth Scheduler for Data Collection.job"
- C:\WINDOWS\PCHEALTH\SUPPORT\PCHSCHD.EXE
"2008-05-03 21:16:02 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-05-03 17:30:29
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-05-03 17:32:46
ComboFix-quarantined-files.txt 2008-05-03 21:32:38
Pre-Run: 97,399,832,576 bytes free
Post-Run: 99,221,667,840 bytes free
204 --- E O F --- 2008-04-19 03:33:01