These scans took so long to complete but hopefully this is what you were after
Thankyou
ComboFix 08-05-21.3 - Lil L 2008-05-24 9:17:24.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.406 [GMT 10:00]
Running from: C:\Documents and Settings\Lil L\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Lil L\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!FILE ::
C:\WINDOWS\rproxy32.exe
C:\WINDOWS\slog.dll
C:\WINDOWS\system32\ccRSpool\ccSvcHst.exe
C:\WINDOWS\system32\muzika.xm
C:\WINDOWS\xpsm.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\rproxy32.exe
C:\WINDOWS\slog.dll
C:\WINDOWS\system32\muzika.xm
C:\WINDOWS\xpsm.exe
.
((((((((((((((((((((((((( Files Created from 2008-04-23 to 2008-05-23 )))))))))))))))))))))))))))))))
.
2008-05-24 08:07 . 2008-05-24 09:16 <DIR> d-------- C:\Documents and Settings\Lil L\.SunDownloadManager
2008-05-24 01:42 . 2008-05-24 01:42 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-24 01:42 . 2008-05-24 01:42 <DIR> d-------- C:\Documents and Settings\Lil L\Application Data\Malwarebytes
2008-05-24 01:42 . 2008-05-24 01:42 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-24 01:42 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-24 01:42 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-05-23 23:11 . 2008-05-23 23:11 <DIR> d-------- C:\WINDOWS\ERUNT
2008-05-23 23:04 . 2008-05-23 23:34 <DIR> d-------- C:\SDFix
2008-05-23 22:01 . 2008-05-23 22:01 <DIR> d-------- C:\Deckard
2008-05-23 18:58 . 2008-05-23 19:06 <DIR> d-------- C:\MSNCleaner
2008-05-21 22:37 . 2007-12-07 12:21 6,066,176 --------- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-05-21 22:37 . 2007-04-17 19:32 2,455,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-05-21 22:37 . 2007-03-08 15:10 991,232 --------- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-05-21 22:37 . 2007-12-07 12:21 459,264 --------- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-05-21 22:37 . 2007-12-07 12:21 383,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-05-21 22:37 . 2007-12-07 12:21 267,776 --------- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-05-21 22:37 . 2007-12-07 12:21 63,488 --------- C:\WINDOWS\system32\dllcache\icardie.dll
2008-05-21 22:37 . 2007-12-07 12:21 52,224 --------- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-05-21 22:37 . 2007-12-06 21:00 13,824 --------- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-05-21 22:31 . 2007-08-13 18:54 33,792 --a------ C:\WINDOWS\system32\dllcache\custsat.dll
2008-05-21 22:16 . 2008-05-21 22:38 1,374 --a------ C:\WINDOWS\imsins.BAK
2008-05-20 04:12 . 2008-05-20 04:12 135,168 --a------ C:\WINDOWS\msmgr.exe
2008-05-19 23:59 . 2008-05-23 23:55 <DIR> d--h----- C:\$AVG8.VAULT$
2008-05-19 23:26 . 2008-05-19 23:26 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-05-19 23:26 . 2008-05-19 23:26 75,272 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-05-19 23:26 . 2008-05-19 23:26 12,424 --a------ C:\WINDOWS\system32\drivers\avgrkx86.sys
2008-05-19 23:26 . 2008-05-19 23:26 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-05-19 23:25 . 2008-05-24 05:41 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-05-19 23:25 . 2008-05-19 23:25 <DIR> d-------- C:\Program Files\AVG
2008-05-19 23:25 . 2008-05-23 19:15 <DIR> d-------- C:\Documents and Settings\Lil L\Application Data\AVGTOOLBAR
2008-05-19 23:25 . 2008-05-19 23:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-05-19 23:25 . 2008-05-19 23:25 45,568 --a------ C:\WINDOWS\system32\avgfwdx.dll
2008-05-19 23:25 . 2008-05-19 23:25 22,528 --a------ C:\WINDOWS\system32\drivers\avgfwdx.sys
2008-05-19 21:25 . 2008-05-19 21:25 <DIR> d-------- C:\Program Files\Innovative Solutions
2008-05-19 19:26 . 2008-05-19 19:46 <DIR> d-------- C:\WINDOWS\ScreenShots
2008-05-19 19:06 . 2008-05-19 19:06 4,288 --a------ C:\WINDOWS\wanzip.ico
2008-05-19 19:06 . 2008-05-19 19:06 2,240 --a------ C:\WINDOWS\wapg.ico
2008-05-19 19:06 . 2008-05-19 19:06 2,240 --a------ C:\WINDOWS\wailes.ico
2008-05-19 18:29 . 2008-05-19 19:44 <DIR> d-------- C:\WINDOWS\msndebug
2008-05-19 18:29 . 2008-05-19 17:58 36,864 --a------ C:\WINDOWS\ompx.exe
2008-05-19 15:26 . 2008-05-19 19:06 2,240 --a------ C:\WINDOWS\2wapg.ico
2008-05-19 15:26 . 2008-05-19 19:06 2,240 --a------ C:\WINDOWS\2wanzip.ico
2008-05-19 15:25 . 2008-05-19 20:06 <DIR> d-------- C:\Program Files\Accessories
2008-05-19 00:38 . 2008-05-19 00:38 <DIR> d-------- C:\Documents and Settings\Lil L\Application Data\Grisoft
2008-05-19 00:38 . 2007-05-30 22:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-05-19 00:20 . 2008-05-19 00:23 <DIR> d-------- C:\Program Files\Privacy Guardian
2008-05-19 00:20 . 2004-03-09 00:00 224,016 --a------ C:\WINDOWS\system32\TABCTL32.OCX
2008-05-18 22:26 . 2008-05-18 22:27 <DIR> d-------- C:\Program Files\Panda Security
2008-05-18 18:57 . 2008-05-18 19:06 <DIR> d-------- C:\WINDOWS\system32\NtmsData
2008-05-18 15:51 . 2008-05-18 15:51 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-05-18 15:51 . 2008-05-18 15:51 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-18 15:14 . 2008-05-18 15:14 <DIR> d-------- C:\Documents and Settings\Lil L\IGC
2008-05-18 14:14 . 2008-05-18 14:14 <DIR> d-------- C:\Program Files\IGC
2008-05-18 12:09 . 2008-05-18 12:09 <DIR> d-------- C:\Program Files\OTS Software
2008-05-18 11:45 . 2008-05-18 11:45 <DIR> d-------- C:\Program Files\Dopewars
2008-05-18 11:28 . 1997-09-23 14:01 17,410,851 --a------ C:\WINDOWS\SHARE.SHR
2008-05-18 11:28 . 1997-02-27 15:13 19,431 --a------ C:\WINDOWS\MONO320.PCX
2008-05-18 11:15 . 2008-05-18 11:15 0 --a------ C:\WINDOWS\BABY_FRG.SLD
2008-05-16 23:53 . 2008-05-17 00:03 <DIR> d-------- C:\Program Files\Diji Album
2008-05-11 20:12 . 2008-05-11 20:12 <DIR> d-------- C:\!KillBox
2008-05-11 15:22 . 2008-05-11 15:22 <DIR> d-------- C:\Program Files\ID Security Suite
2008-05-10 20:32 . 2008-05-10 20:32 <DIR> d-------- C:\WINDOWS\.jagex_cache_32
2008-05-10 20:14 . 2008-05-10 20:14 <DIR> d-------- C:\Documents and Settings\Lil L\Application Data\Yahoo!
2008-05-10 01:20 . 2008-05-10 01:20 <DIR> d-------- C:\Program Files\EyetoyOnComputer Project
2008-05-04 00:17 . 2008-05-04 00:17 <DIR> d-------- C:\Program Files\Microsoft Silverlight
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-21 11:25 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-05-19 16:54 180,224 ---ha-w C:\WINDOWS\hpreg.dll
2008-05-19 13:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-05-19 13:22 --------- d-----w C:\Documents and Settings\Lil L\Application Data\uTorrent
2008-05-19 04:09 --------- d-----w C:\Program Files\Modem Helper
2008-05-18 04:14 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-17 11:34 --------- d-----w C:\Program Files\mIRC
2008-05-15 10:07 --------- d-----w C:\Documents and Settings\Lil L\Application Data\Image Zone Express
2008-05-10 10:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-05-07 15:39 --------- d-----w C:\Program Files\PartyGaming
2008-05-03 18:55 50,968 ----a-w C:\Documents and Settings\Lil L\Application Data\GDIPFONTCACHEV1.DAT
2008-04-15 19:43 78,848 ----a-w C:\WINDOWS\system32\svers.dll
2008-04-13 03:04 --------- d-----w C:\Program Files\MSN Messenger
2008-04-07 13:30 --------- d-----w C:\Program Files\Windows Live
2008-04-06 15:18 --------- d-----w C:\Program Files\MessengerDiscovery
2008-04-06 12:46 --------- d-----w C:\Program Files\McAfee.com
2008-04-06 12:46 --------- d-----w C:\Program Files\McAfee
2008-04-06 12:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-04-05 16:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-04-05 16:04 --------- d-----w C:\Program Files\Google
2008-04-05 11:18 691,545 ----a-w C:\WINDOWS\unins000.exe
2008-04-05 11:13 --------- d-----w C:\Program Files\SpywareBlaster
2008-04-02 01:27 --------- d-----w C:\Program Files\VirtualDJ
2008-03-27 09:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-27 08:12 151,583 ------w C:\WINDOWS\system32\dllcache\msjint40.dll
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-19 09:47 1,845,248 ------w C:\WINDOWS\system32\dllcache\win32k.sys
2007-09-02 05:00 24,192 ----a-w C:\Documents and Settings\Lil L\usbsermptxp.sys
2007-09-02 05:00 22,768 ----a-w C:\Documents and Settings\Lil L\usbsermpt.sys
2007-09-02 04:48 92,064 ----a-w C:\Documents and Settings\Lil L\mqdmmdm.sys
2007-09-02 04:48 9,232 ----a-w C:\Documents and Settings\Lil L\mqdmmdfl.sys
2007-09-02 04:48 79,328 ----a-w C:\Documents and Settings\Lil L\mqdmserd.sys
2007-09-02 04:48 66,656 ----a-w C:\Documents and Settings\Lil L\mqdmbus.sys
2007-09-02 04:48 6,208 ----a-w C:\Documents and Settings\Lil L\mqdmcmnt.sys
2007-09-02 04:48 5,936 ----a-w C:\Documents and Settings\Lil L\mqdmwhnt.sys
2007-09-02 04:48 4,048 ----a-w C:\Documents and Settings\Lil L\mqdmcr.sys
2007-07-29 05:17 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2007-01-18 13:53 126 ----a-w C:\Documents and Settings\Lil L\Application Data\wklnhst.dat
.
((((((((((((((((((((((((((((( snapshot@2008-05-24_ 0.11.36.51 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-23 13:20:51 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-23 20:57:15 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2005-10-20 10:02:28 163,328 ----a-w C:\WINDOWS\ERDNT\subs\ERDNT.EXE
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
2008-05-19 23:25 2051328 --a------ C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= "C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL" [2008-05-19 23:25 2051328]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-05-19 23:25 2051328]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 10:34 5724184]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-11-16 18:04 139264]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-08-30 17:43 4670704]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 07:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-05-15 11:03 1831936]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 14:40 155648]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 07:00 455168]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 07:00 455168]
"SigmatelSysTrayApp"="stsystra.exe" [2006-07-24 19:20 282624 C:\WINDOWS\stsystra.exe]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2006-07-22 01:47 81920]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 18:50 81920]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 18:50 221184]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 07:00 208952]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2006-07-22 01:48 98304]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-07-06 09:15 151552]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 01:41 49152]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2006-07-22 01:50 86016]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 05:12 94208]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-09-08 07:20 122940]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe" [2006-11-09 14:07 49263]
"SnoopFreeUI"="SnoopFreeUI.exe" [2007-07-08 00:14 221184 C:\WINDOWS\SnoopFreeUI.exe]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 19:25 6731312]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-05-19 23:25 1177368]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-13 15:38 39264]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-22 23:01:50 734872]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-11-29 14:01:23 24576]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 03:21:22 288472]
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2007-06-21 21:56:14 282624]
KODAK Software Updater.lnk - C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-02-13 13:12:08 16423]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04 83360]
[HKLM\~\startupfolder\C:^Documents and Settings^Lil L^Start Menu^Programs^Startup^Tycoon City_ New York Registration.lnk]
backup=C:\WINDOWS\pss\Tycoon City_ New York Registration.lnkStartup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"C:\\Program Files\\uTorrent\\utorrent.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\MSN BackUp\\MSNBackup.exe"=
"C:\\Program Files\\Microsoft Office\\Office10\\FRONTPG.EXE"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\WINDOWS\\msndebug\\lsass.exe"=
"C:\\WINDOWS\\msndebug\\cmss.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R0 AvgRkx86;avgrkx86.sys;C:\WINDOWS\system32\Drivers\avgrkx86.sys [2008-05-19 23:26]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-05-19 23:26]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-05-19 23:25]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-05-19 23:25]
R2 avgfws8;AVG8 Firewall;C:\PROGRA~1\AVG\AVG8\avgfws8.exe [2008-05-19 23:25]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-05-19 23:26]
R3 Avgfwdx;Avgfwdx;C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2008-05-19 23:25]
S3 Avgfwfd;AVG network filter service;C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2008-05-19 23:25]
S3 k600bus;Sony Ericsson 600i driver (WDM);C:\WINDOWS\system32\DRIVERS\k600bus.sys [2005-03-04 18:08]
S3 NPF;WinPcap Packet Driver (NPF);C:\WINDOWS\system32\drivers\NPF.sys [2007-01-26 03:31]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dc05b2bb-1c4b-11dd-93ef-001676d9ef7e}]
\Shell\1\Command - E:\.\readme.txt.exe
\Shell\2\Command - E:\.\readme.txt.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\readme.txt.exe
.
Contents of the 'Scheduled Tasks' folder
"2008-05-23 22:28:00 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2008-05-17 04:36:02 C:\WINDOWS\Tasks\EasyShare Registration Task.job"
- C:\WINDOWS\system32\rundll32.exelC:\DOCUME~1\ALLUSE~1\APPLIC~1\Kodak\EasyShareSetup\$REGIS~1\Registration_7.4.20.2.sxt _RegistrationOffer@16
"2008-05-23 21:00:27 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-05-24 09:19:07
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-05-24 9:20:34
ComboFix-quarantined-files.txt 2008-05-23 23:20:03
ComboFix2.txt 2008-05-23 21:08:17
ComboFix3.txt 2008-05-23 14:12:55
Pre-Run: 26,205,839,360 bytes free
Post-Run: 26,192,121,856 bytes free
262 --- E O F --- 2008-05-21 12:38:36
Saturday, May 24, 2008 12:55:15 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 23/05/2008
Kaspersky Anti-Virus database records: 799423
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
A:\
C:\
D:\
F:\
Scan Statistics
Total number of scanned objects 122658
Number of viruses found 14
Number of infected objects 24
Number of suspicious objects 0
Duration of the scan process 02:27:53
Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\avg8\AvgAm\avgam.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\emc\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgam.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgcore.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avglng.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgns.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgrs.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgsched.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgsrm.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\avgwd.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\commonpriv.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\avg8\Log\commonpub.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-06192007-131539.log Object is locked skipped
C:\Documents and Settings\Lil L\Application Data\Mozilla\Firefox\Profiles\rjwvav6k.default\cert8.db Object is locked skipped
C:\Documents and Settings\Lil L\Application Data\Mozilla\Firefox\Profiles\rjwvav6k.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\Lil L\Application Data\Mozilla\Firefox\Profiles\rjwvav6k.default\history.dat Object is locked skipped
C:\Documents and Settings\Lil L\Application Data\Mozilla\Firefox\Profiles\rjwvav6k.default\key3.db Object is locked skipped
C:\Documents and Settings\Lil L\Application Data\Mozilla\Firefox\Profiles\rjwvav6k.default\parent.lock Object is locked skipped
C:\Documents and Settings\Lil L\Application Data\Mozilla\Firefox\Profiles\rjwvav6k.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Lil L\Application Data\Mozilla\Firefox\Profiles\rjwvav6k.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Lil L\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Lil L\Desktop\DESKTOP\Desktop Download Crap\mirc621.exe/stream/data0008 Infected: not-a-virus:Client-IRC.Win32.mIRC.621 skipped
C:\Documents and Settings\Lil L\Desktop\DESKTOP\Desktop Download Crap\mirc621.exe/stream Infected: not-a-virus:Client-IRC.Win32.mIRC.621 skipped
C:\Documents and Settings\Lil L\Desktop\DESKTOP\Desktop Download Crap\mirc621.exe NSIS: infected - 2 skipped
C:\Documents and Settings\Lil L\Local Settings\Application Data\Ahead\Nero Home\bl.db Object is locked skipped
C:\Documents and Settings\Lil L\Local Settings\Application Data\Ahead\Nero Home\bl.db-journal Object is locked skipped
C:\Documents and Settings\Lil L\Local Settings\Application Data\Ahead\Nero Home\is2.db Object is locked skipped
C:\Documents and Settings\Lil L\Local Settings\Application Data\Ahead\Nero Home\is2.db-journal Object is locked skipped
C:\Documents and Settings\Lil L\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\Logs\Dfsr00005.log Object is locked skipped
C:\Documents and Settings\Lil L\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\pending.dat Object is locked skipped
C:\Documents and Settings\Lil L\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\Working\database_C440_4630_4046_298E\dfsr.db Object is locked skipped
C:\Documents and Settings\Lil L\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\Working\database_C440_4630_4046_298E\fsr.log Object is locked skipped
C:\Documents and Settings\Lil L\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\Working\database_C440_4630_4046_298E\fsrtmp.log Object is locked skipped
C:\Documents and Settings\Lil L\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\Working\database_C440_4630_4046_298E\tmp.edb Object is locked skipped
C:\Documents and Settings\Lil L\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst/Personal Folders/Inbox/05 Dec 2006 07:56 from jerry:test/data.txt.cmd Infected: Email-Worm.Win32.Warezov.fb skipped
C:\Documents and Settings\Lil L\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst MailMSMaill: infected - 1 skipped
C:\Documents and Settings\Lil L\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Lil L\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Lil L\Local Settings\Application Data\Microsoft\Windows Live Contacts\
[email protected]\real\members.stg Object is locked skipped
C:\Documents and Settings\Lil L\Local Settings\Application Data\Microsoft\Windows Live Contacts\
[email protected]\shadow\members.stg Object is locked skipped
C:\Documents and Settings\Lil L\Local Settings\Application Data\Mozilla\Firefox\Profiles\rjwvav6k.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Lil L\Local Settings\Application Data\Mozilla\Firefox\Profiles\rjwvav6k.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Lil L\Local Settings\Application Data\Mozilla\Firefox\Profiles\rjwvav6k.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Lil L\Local Settings\Application Data\Mozilla\Firefox\Profiles\rjwvav6k.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Lil L\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Lil L\Local Settings\History\History.IE5\MSHist012008052420080525\index.dat Object is locked skipped
C:\Documents and Settings\Lil L\Local Settings\Temp\hpodvd09.log Object is locked skipped
C:\Documents and Settings\Lil L\Local Settings\Temp\~DF5AE8.tmp Object is locked skipped
C:\Documents and Settings\Lil L\Local Settings\Temp\~DF5B5D.tmp Object is locked skipped
C:\Documents and Settings\Lil L\Local Settings\Temp\~DF6F52.tmp Object is locked skipped
C:\Documents and Settings\Lil L\Local Settings\Temp\~DF6F63.tmp Object is locked skipped
C:\Documents and Settings\Lil L\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Lil L\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Lil L\My Documents\My Received Files\MsnMsgr.txt Object is locked skipped
C:\Documents and Settings\Lil L\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Lil L\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Lil L\Shared\Rare Recording.wma Infected: Trojan-Downloader.WMA.Wimad.k skipped
C:\Documents and Settings\Lil L\Shared\the bump and grind.wm Infected: Trojan-Downloader.WMA.Wimad.m skipped
C:\Documents and Settings\Lil L\UserData\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\MSNCleaner\BackUpMSNCleaner\msn.exe.vir Infected: Trojan-Spy.Win32.WinSpy.me skipped
C:\Program Files\Kodak\Kodak EasyShare software\bin\Catalog\EasyShare.me Object is locked skipped
C:\Program Files\Kodak\Kodak EasyShare software\bin\Catalog\EasyShare.mm Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\BWKDLogs\BWTargetInf.log Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\chandir.dat Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\chandir.idx Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\chn.dat Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\chn.idx Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\D0000000.FCS Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\inuse.txt Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\L0000066.FCS Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\main.log Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs.dat Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs.idx Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_die.dat Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_die.idx Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_dnd.dat Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_dnd.idx Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_ext.dat Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_ext.idx Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_rcv.dat Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_rcv.idx Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\storydb.dat Object is locked skipped
C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\storydb.idx Object is locked skipped
C:\Program Files\LimeWire\.NetworkShare\(full version) dancelife theme song 19.wma Infected: Trojan-Downloader.WMA.Wimad.d skipped
C:\Program Files\Mozilla Firefox\plugins\NPMyWebS.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.i skipped
C:\Program Files\MSN Messenger\riched20.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP426\A0058613.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.621 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP431\A0058809.exe/WISE0060.BIN Infected: not-a-virus:AdWare.Win32.Gator.3013 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP431\A0058809.exe WiseSFX: infected - 1 skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP431\A0058813.DLL Infected: not-a-virus:AdTool.Win32.MyWebSearch.a skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP433\A0058875.exe Infected: Trojan-Spy.Win32.WinSpy.ql skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP433\A0058883.dll Infected: not-a-virus:Monitor.Win32.WinSpy.bj skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP433\A0058884.dll Infected: not-a-virus:Monitor.Win32.WinSpy.bj skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP441\A0061535.exe Infected: Trojan-Spy.Win32.WinSpy.me skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP442\A0061544.exe Infected: Trojan-Spy.Win32.WinSpy.ql skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP444\A0061669.dll Infected: not-a-virus:Monitor.Win32.WinSpy.bj skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP445\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\msndebug\lsass.exe Infected: Trojan-Proxy.Win32.VB.az skipped
C:\WINDOWS\ompx.exe Infected: Trojan-Spy.Win32.WinSpy.qr skipped
C:\WINDOWS\pfirewall.log Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\SnopFree.sys Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\drivers\sptd0749.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\svers.dll Infected: not-a-virus:Monitor.Win32.WinSpy.bj skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.