ok here's the log for the combofix.txt:
ComboFix 08-05-21.2 - Timmayy 2008-05-22 18:34:39.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2896 [GMT -7:00]
Running from: C:\Documents and Settings\Timmayy\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Timmayy\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!FILE ::
C:\WINDOWS\system32\blackster.scr
C:\WINDOWS\system32\bmf.cs
C:\WINDOWS\system32\ccs.so
C:\WINDOWS\system32\gh.l
C:\WINDOWS\system32\hljwugsf.bin
C:\WINDOWS\system32\kr_done1de
C:\WINDOWS\system32\mn.n
C:\WINDOWS\system32\yl.po
F:\autorun.exe
F:\setup.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\blackster.scr
C:\WINDOWS\system32\bmf.cs
C:\WINDOWS\system32\ccs.so
C:\WINDOWS\system32\gh.l
C:\WINDOWS\system32\hljwugsf.bin
C:\WINDOWS\system32\kr_done1de
C:\WINDOWS\system32\mn.n
C:\WINDOWS\system32\yl.po
.
((((((((((((((((((((((((( Files Created from 2008-04-23 to 2008-05-23 )))))))))))))))))))))))))))))))
.
2008-05-20 21:10 . 2008-05-20 21:21 <DIR> d-------- C:\Program Files\Eusing Free Registry Cleaner
2008-05-20 21:08 . 2008-05-20 21:08 <DIR> d--h----- C:\$AVG8.VAULT$
2008-05-20 20:58 . 2008-05-22 06:39 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-05-20 20:58 . 2008-05-20 20:58 <DIR> d-------- C:\Program Files\AVG
2008-05-20 20:58 . 2008-05-20 20:58 <DIR> d-------- C:\Documents and Settings\Timmayy\Application Data\AVGTOOLBAR
2008-05-20 20:58 . 2008-05-20 20:58 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-05-20 20:58 . 2008-05-20 20:58 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-05-20 20:58 . 2008-05-20 20:58 75,272 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-05-20 20:58 . 2008-05-20 20:58 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-05-20 19:36 . 2008-05-20 19:36 <DIR> d-------- C:\Deckard
2008-05-20 19:12 . 2008-05-20 19:12 <DIR> d-------- C:\WINDOWS\ERUNT
2008-05-20 19:08 . 2008-05-20 19:31 <DIR> d-------- C:\SDFix
2008-05-20 07:13 . 2008-05-20 07:13 <DIR> d-------- C:\Program Files\Lavasoft
2008-05-19 22:34 . 2008-05-19 22:34 <DIR> d-------- C:\Documents and Settings\Everyone Else\Application Data\TmpRecentIcons
2008-05-18 17:15 . 2008-05-20 21:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-18 00:45 . 2008-05-20 22:50 <DIR> d-------- C:\Program Files\DCPFLICS
2008-05-17 16:14 . 2008-05-19 23:51 <DIR> d-------- C:\Documents and Settings\Timmayy\Application Data\TmpRecentIcons
2008-05-17 15:55 . 2007-07-19 18:14 3,727,720 --a------ C:\WINDOWS\system32\d3dx9_35.dll
2008-05-17 15:55 . 2007-07-19 18:14 1,358,192 --a------ C:\WINDOWS\system32\D3DCompiler_35.dll
2008-05-17 15:55 . 2007-07-19 18:14 444,776 --a------ C:\WINDOWS\system32\d3dx10_35.dll
2008-05-17 15:55 . 2007-04-04 18:53 81,768 --a------ C:\WINDOWS\system32\xinput1_3.dll
2008-05-17 15:53 . 2008-05-17 15:53 <DIR> d-------- C:\Program Files\Electronic Arts
2008-05-17 15:45 . 2008-05-17 15:45 <DIR> d--h----- C:\WINDOWS\PIF
2008-05-17 14:30 . 2008-05-17 15:08 16,768 --a------ C:\WINDOWS\system32\tcpip_patcher.sys
2008-05-17 14:02 . 2008-05-18 16:36 <DIR> d-------- C:\Temp
2008-05-17 13:45 . 2008-05-17 13:45 <DIR> d-------- C:\Documents and Settings\All Users\temp
2008-05-17 13:45 . 2008-05-17 13:45 <DIR> d-------- C:\Documents and Settings\All Users\Gamespot
2008-05-17 13:22 . 2008-05-17 13:22 <DIR> d-------- C:\WINDOWS\nvidia icons
2008-05-17 13:22 . 2008-05-17 13:22 <DIR> d-------- C:\NVIDIA
2008-05-17 13:22 . 2008-05-02 22:46 442,368 --a------ C:\WINDOWS\system32\nvudisp.exe
2008-05-17 13:22 . 2008-05-22 18:30 182,441 --a------ C:\WINDOWS\system32\nvapps.xml
2008-05-17 13:22 . 2008-05-02 22:46 181,895 --a------ C:\WINDOWS\system32\nvdsp.chm
2008-05-17 13:22 . 2008-05-02 22:46 116,384 --a------ C:\WINDOWS\system32\nv3d.chm
2008-05-17 13:22 . 2008-05-02 22:46 54,988 --a------ C:\WINDOWS\system32\nvmob.chm
2008-05-17 13:22 . 2008-05-02 22:46 18,070 --a------ C:\WINDOWS\system32\nvdisp.nvu
2008-05-17 12:57 . 2008-05-17 12:57 <DIR> d-------- C:\Program Files\Realtek
2008-05-17 12:56 . 2007-07-26 02:09 520,192 -r------- C:\WINDOWS\RtlExUpd.dll
2008-05-17 12:49 . 2008-05-17 12:49 <DIR> d-------- C:\Program Files\NVIDIA Corporation
2008-05-17 12:46 . 2008-05-17 12:46 <DIR> dr------- C:\WINDOWS\AsDmiHtm
2008-05-17 12:18 . 2008-05-17 12:18 <DIR> d-------- C:\Program Files\RegCleaner
2008-05-17 11:44 . 2008-05-17 11:48 <DIR> d-------- C:\WINDOWS\NV38523848.TMP
2008-05-17 11:31 . 2008-05-17 11:37 <DIR> d-------- C:\WINDOWS\NV28322484.TMP
2008-05-17 03:48 . 2008-05-17 11:21 <DIR> d-------- C:\WINDOWS\NV28122816.TMP
2008-05-17 03:38 . 2008-05-17 03:38 <DIR> d-------- C:\WINDOWS\system32\Lang
2008-05-17 03:38 . 2008-05-17 03:38 940,794 --a------ C:\WINDOWS\system32\LoopyMusic.wav
2008-05-17 03:38 . 2008-05-17 03:38 146,650 --a------ C:\WINDOWS\system32\BuzzingBee.wav
2008-05-17 03:36 . 2008-05-17 12:27 <DIR> d-------- C:\Program Files\ASUS
2008-05-17 03:36 . 2006-01-10 01:50 24,576 -ra------ C:\WINDOWS\system32\AsIO.dll
2008-05-17 03:36 . 2006-10-18 12:12 12,664 -ra------ C:\WINDOWS\system32\drivers\AsIO.sys
2008-05-17 03:36 . 2008-05-17 03:36 666 --a------ C:\WINDOWS\setup.iss
2008-05-17 03:32 . 2008-05-17 12:57 <DIR> d-------- C:\WINDOWS\system32\RTCOM
2008-05-17 03:31 . 2008-05-17 03:31 315,392 --a------ C:\WINDOWS\HideWin.exe
2008-05-17 03:24 . 2008-05-17 03:24 <DIR> d-------- C:\WINDOWS\ASUSInstAll
2008-05-17 03:21 . 2007-08-08 20:03 353,280 -ra------ C:\WINDOWS\system32\idecoiins.dll
2008-05-17 03:21 . 2007-10-12 01:14 194,048 -ra------ C:\WINDOWS\system32\fdco1ins.dll
2008-05-17 03:21 . 2007-08-08 20:11 102,400 -ra------ C:\WINDOWS\system32\drivers\nvgts.sys
2008-05-17 03:21 . 2007-10-12 01:01 3,276 -ra------ C:\WINDOWS\system32\drivers\nvphy.bin
2008-05-17 03:20 . 2008-05-17 12:57 15,746 --a------ C:\WINDOWS\Ascd_log.ini
2008-05-17 03:20 . 2007-10-12 01:14 9,216 -ra------ C:\WINDOWS\system32\bdco1ins.dll
2008-05-17 03:19 . 2004-08-03 23:10 61,056 --a------ C:\WINDOWS\system32\drivers\ohci1394.sys
2008-05-17 03:19 . 2004-08-03 23:10 61,056 --a--c--- C:\WINDOWS\system32\dllcache\ohci1394.sys
2008-05-17 03:19 . 2004-08-03 23:10 53,248 --a------ C:\WINDOWS\system32\drivers\1394bus.sys
2008-05-17 03:19 . 2004-08-03 23:10 53,248 --a--c--- C:\WINDOWS\system32\dllcache\1394bus.sys
2008-05-17 03:19 . 2001-08-17 13:46 6,400 --a------ C:\WINDOWS\system32\drivers\enum1394.sys
2008-05-17 03:19 . 2001-08-17 13:46 6,400 --a--c--- C:\WINDOWS\system32\dllcache\enum1394.sys
2008-05-17 03:18 . 2008-05-17 12:46 15,498 --a------ C:\WINDOWS\Ascd_tmp.ini
2008-05-17 03:18 . 2007-07-31 20:39 12,536 --a------ C:\WINDOWS\system32\drivers\ASUSHWIO.SYS
2008-05-17 03:18 . 2004-08-12 19:56 5,810 -ra------ C:\WINDOWS\system32\drivers\ASACPI.sys
2008-05-11 17:12 . 2008-05-11 17:12 <DIR> d-------- C:\Program Files\Linksys
2008-05-11 17:12 . 2008-05-11 17:12 <DIR> d-------- C:\Documents and Settings\Timmayy\Application Data\InstallShield
2008-05-02 22:46 . 2008-05-02 22:46 13,529,088 --a------ C:\WINDOWS\system32\nvcpl.dll
2008-04-28 17:12 . 2008-04-28 17:12 <DIR> d-------- C:\Documents and Settings\Everyone Else\Application Data\Nero
2008-04-28 17:10 . 2008-05-20 20:58 <DIR> d-------- C:\Documents and Settings\Everyone Else
2008-04-28 06:59 . 2008-04-28 06:59 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-04-28 06:48 . 2008-04-28 06:48 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Roxio
2008-04-28 06:48 . 2008-04-19 17:22 182 --a------ C:\WINDOWS\NeroDigital.ini
2008-04-28 06:47 . 2008-04-02 22:17 <DIR> d-------- C:\Documents and Settings\Timmayy\Application Data\Roxio
2008-04-28 06:44 . 2008-04-28 06:59 256 --a------ C:\Documents and Settings\Timmayy\pool.bin
2008-04-28 06:43 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-04-28 06:43 . 2004-08-03 23:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-04-28 06:41 . 2007-07-27 05:00 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-04-28 06:09 . 2008-04-28 06:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Sonic
2008-04-28 06:09 . 2008-04-28 06:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\InstallShield
2008-04-28 06:07 . 2008-04-28 06:08 <DIR> d-------- C:\Program Files\Roxio
2008-04-28 06:07 . 2008-04-28 06:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Roxio
2008-04-28 06:06 . 2007-01-18 10:24 26,496 -ra------ C:\WINDOWS\system32\drivers\RimSerial.sys
2008-04-28 06:05 . 2008-04-28 06:05 <DIR> d-------- C:\Program Files\Research In Motion
2008-04-27 23:55 . 2008-04-27 23:55 <DIR> d-------- C:\Documents and Settings\Timmayy\Application Data\Research In Motion
2008-04-27 22:33 . 2008-04-27 22:33 <DIR> d-------- C:\WINDOWS\system32\Adobe
2008-04-27 22:33 . 2008-04-27 22:33 <DIR> d-------- C:\Documents and Settings\Timmayy\Application Data\Apple Computer
2008-04-27 22:27 . 2008-04-27 22:27 <DIR> d-------- C:\Program Files\Apple Software Update
2008-04-27 22:27 . 2008-04-27 22:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-04-27 22:26 . 2008-05-20 23:26 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-04-27 22:26 . 2008-04-22 22:50 1,409 --a------ C:\WINDOWS\QTFont.for
2008-04-27 22:25 . 2008-04-27 22:25 <DIR> d-------- C:\Program Files\QuickTime
2008-04-27 22:25 . 2008-04-27 22:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-04-27 22:15 . 2005-11-18 16:07 3,272,704 --a------ C:\WINDOWS\system32\sapphire_ae.old
2008-04-27 22:15 . 2005-11-20 20:42 3,272,704 --a------ C:\WINDOWS\system32\sapphire_ae.dll
2008-04-27 22:14 . 2008-04-27 22:14 <DIR> d-------- C:\Program Files\GenArts
2008-04-27 21:31 . 2008-04-27 22:23 <DIR> d-------- C:\Program Files\Winamp Remote
2008-04-27 21:31 . 2008-04-06 11:57 <DIR> d-------- C:\Program Files\Winamp
2008-04-27 21:31 . 2008-04-06 15:26 <DIR> d-------- C:\Documents and Settings\Timmayy\Application Data\Winamp
2008-04-27 21:31 . 2008-04-27 22:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\OrbNetworks
2008-04-27 20:52 . 2008-04-27 20:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Adobe Systems
2008-04-27 19:33 . 2008-04-27 19:33 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-04-27 12:34 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-04-27 12:34 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-04-27 12:34 . 2007-07-30 19:19 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-04-26 22:27 . 2008-04-26 22:27 <DIR> d-------- C:\Documents and Settings\Timmayy\Application Data\Nero
2008-04-26 22:25 . 2008-04-26 22:25 <DIR> d-------- C:\Program Files\Nero
2008-04-26 22:25 . 2008-04-26 22:26 <DIR> d-------- C:\Program Files\Common Files\Nero
2008-04-26 22:25 . 2008-04-26 22:25 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-04-26 22:04 . 2008-04-26 22:04 <DIR> d-------- C:\Program Files\Bonjour
2008-04-26 21:57 . 2008-04-26 21:57 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared
2008-04-26 21:50 . 2008-04-26 21:50 4 --a------ C:\WINDOWS\system32\ulfconfig0103.ulf
2008-04-26 21:48 . 2008-04-26 21:48 <DIR> d-------- C:\WINDOWS\Downloaded Installations
2008-04-26 21:33 . 2008-04-26 21:33 <DIR> d-------- C:\Program Files\PowerISO
2008-04-26 21:04 . 2008-04-26 21:04 <DIR> d-------- C:\WINDOWS\system32\LogFiles
2008-04-26 20:46 . 2008-05-19 22:48 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-04-26 20:46 . 2008-04-26 20:46 <DIR> d-------- C:\WINDOWS\system32\bits
2008-04-26 20:45 . 2007-03-29 05:56 7,168 -----c--- C:\WINDOWS\system32\dllcache\bitsprx4.dll
2008-04-26 20:45 . 2007-03-29 05:56 7,168 --a------ C:\WINDOWS\system32\bitsprx4.dll
2008-04-25 23:55 . 2004-08-03 23:08 26,496 --a--c--- C:\WINDOWS\system32\dllcache\usbstor.sys
2008-04-25 21:36 . 2008-05-19 21:03 <DIR> d-------- C:\Documents and Settings\Timmayy\Application Data\Azureus
2008-04-25 21:36 . 2008-04-25 21:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Azureus
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-23 01:30 --------- d-----w C:\Documents and Settings\Timmayy\Application Data\WTablet
2008-05-23 01:30 --------- d-----w C:\Documents and Settings\LocalService\Application Data\WTablet
2008-05-21 05:43 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-17 21:30 577,536 ----a-w C:\WINDOWS\system32\user32.DLL
2008-05-17 20:45 5,939 ----a-w C:\Program Files\install.log
2008-05-01 00:27 442,368 ----a-w C:\WINDOWS\system32\NVUNINST.EXE
2008-04-28 13:09 --------- d-----w C:\Program Files\Common Files\Sonic Shared
2008-04-28 13:06 --------- d-----w C:\Program Files\Common Files\Research In Motion
2008-04-23 02:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Autodesk
2008-04-20 02:11 --------- d-----w C:\Documents and Settings\Timmayy\Application Data\AdobeUM
2008-04-19 23:02 --------- d-----w C:\Program Files\AviSynth 2.5
2008-04-19 23:00 --------- d-----w C:\Program Files\eRightSoft
2008-04-19 22:25 --------- d-----w C:\Program Files\Common Files\Adobe
2008-04-19 20:58 --------- d-----w C:\Documents and Settings\Timmayy\Application Data\Autodesk
2008-04-19 20:38 --------- d-----w C:\Program Files\Common Files\Autodesk Shared
2008-04-19 20:38 --------- d-----w C:\Program Files\Autodesk
2008-04-12 23:41 --------- d-----w C:\Program Files\Tablet
2008-04-12 22:04 --------- d-----w C:\Program Files\Handbrake
2008-04-12 21:56 --------- d-----w C:\Program Files\DVD Decrypter
2008-04-12 21:54 --------- d-----w C:\Program Files\DVD Shrink
2008-04-12 21:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-04-12 21:18 --------- d-----w C:\Documents and Settings\Timmayy\Application Data\Nero8
2008-04-12 18:29 --------- d-----w C:\Documents and Settings\Timmayy\Application Data\dvdcss
2008-04-10 06:00 --------- d-----w C:\Documents and Settings\Timmayy\Application Data\Ahead
2008-04-07 04:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-04-07 04:17 --------- d-----w C:\Documents and Settings\Timmayy\Application Data\vlc
2008-04-07 04:15 --------- d-----w C:\Program Files\VideoLAN
2008-04-07 03:24 --------- d-----w C:\Documents and Settings\Timmayy\Application Data\Intuit
2008-04-07 03:14 --------- d-----w C:\Program Files\Common Files\AnswerWorks 4.0
2008-04-07 03:12 --------- d-----w C:\Program Files\Common Files\Intuit
2008-04-07 03:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Intuit
2008-04-07 03:11 --------- d-----w C:\Program Files\TurboTax
2008-03-30 21:00 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-03-27 08:12 151,583 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-25 16:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-03-23 18:11 --------- d-----w C:\Program Files\Common Files\xing shared
2008-03-23 18:11 --------- d-----w C:\Program Files\Common Files\Sony Shared
2008-03-23 18:11 --------- d-----w C:\Program Files\Common Files\Softimage
2008-03-23 17:17 --------- d-----w C:\Program Files\Common Files\ScanSoft Shared
2008-03-23 17:16 --------- d-----w C:\Program Files\Common Files\Roxio Shared
2008-03-23 17:16 --------- d-----w C:\Program Files\Common Files\Real
2008-03-23 17:16 --------- d-----w C:\Program Files\Common Files\Nullsoft
2008-03-23 17:16 --------- d-----w C:\Program Files\Common Files\NSV
2008-03-23 16:45 --------- d-----w C:\Program Files\Common Files\Macromedia
2008-03-23 16:45 --------- d-----w C:\Program Files\Common Files\Java
2008-03-23 16:45 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-03-23 16:44 --------- d-----w C:\Program Files\Common Files\element5 Shared
2008-03-23 16:44 --------- d-----w C:\Program Files\Common Files\Corel
2008-03-23 16:44 --------- d-----w C:\Program Files\Common Files\AOL
2008-03-23 16:44 --------- d-----w C:\Program Files\Common Files\Alias Shared
2008-03-23 16:44 --------- d-----w C:\Program Files\Common Files\Ahead
2008-03-23 16:44 --------- d-----w C:\Program Files\Common Files\Adobe Systems Shared
2008-03-23 16:41 --------- d-----w C:\Program Files\Ahead
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
.
C:\WINDOWS\system32\user32.dll ... is infected !! (additional data below) 577,024 2005-03-02 18:19:56 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
578,048 2007-03-08 15:48:36 C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
577,024 2007-07-27 12:00:00 C:\WINDOWS\$NtUninstallKB890859$\user32.dll
577,024 2005-03-02 18:09:30 C:\WINDOWS\$NtUninstallKB925902$\user32.dll
577,024 2005-03-02 18:09:30 C:\WINDOWS\$NtUninstallKB925902$\user32.dll.000
577,536 2008-05-17 21:30:32 C:\WINDOWS\system32\user32.DLL
577,536 2008-05-17 21:30:32 C:\WINDOWS\system32\dllcache\user32.dll
------- Sigcheck -------
2005-03-02 11:19 577024 1800f293bccc8ede8a70e12b88d80036 C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll
2007-03-08 08:48 578048 7aa4f6c00405dfc4b70ed4214e7d687b C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll
2007-07-27 05:00 577024 c72661f8552ace7c5c85e16a3cf505c4 C:\WINDOWS\$NtUninstallKB890859$\user32.dll
2005-03-02 11:09 577024 de2db164bbb35db061af0997e4499054 C:\WINDOWS\$NtUninstallKB925902$\user32.dll
2008-05-17 14:30 577536 eda96cb1c2a0aff31ae322e53ada2552 C:\WINDOWS\system32\user32.DLL
2008-05-17 14:30 577536 eda96cb1c2a0aff31ae322e53ada2552 C:\WINDOWS\system32\dllcache\user32.dll
.
((((((((((((((((((((((((((((( snapshot@2008-05-22_ 6.53.45.40 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-22 13:38:05 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-23 01:29:58 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
2008-05-20 20:58 2050816 --a------ C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= "C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL" [2008-05-20 20:58 2050816]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A057A204-BACC-4D26-9990-79A187E2698E}"= C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-05-20 20:58 2050816]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-9990-79a187e2698e}]
[HKEY_CLASSES_ROOT\avgtoolbar.AVGTOOLBAR]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2007-07-27 05:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-02 22:46 13529088]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-05-20 20:58 1177368]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2008-04-27 20:57:56 25214]
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [1999-04-09 13:57:54 110592]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\nnnnoffc]
nnnnOffc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i420vfw.dll
"vidc.yv12"= yv12vfw.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"D:\\TMH\\Bit_Torrent\\Azureus\\Azureus\\Azureus.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Adobe\\Adobe Version Cue CS2\\bin\\VersionCueCS2.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"D:\\Games\\HellgateLondon\\Launcher.exe"=
"C:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
"C:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
"C:\\Program Files\\Autodesk\\Backburner\\server.exe"=
"C:\\Program Files\\Autodesk\\3ds Max 2008\\3dsmax.exe"=
"C:\\Program Files\\Electronic Arts\\Crytek\\Crysis SP Demo\\Bin32\\Crysis.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"60614:TCP"= 60614:TCP:@xpsp2res.dll,-22005
"63893:TCP"= 63893:TCP:@xpsp2res.dll,-22005
"18832:TCP"= 18832:TCP:@xpsp2res.dll,-22005
"19535:TCP"= 19535:TCP:@xpsp2res.dll,-22005
R0 nvgts;nvgts;C:\WINDOWS\system32\DRIVERS\nvgts.sys [2007-08-08 20:11]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-05-20 20:58]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-05-20 20:58]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-05-20 20:58]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-05-20 20:58]
R3 wacommousefilter;Wacom Mouse Filter Driver;C:\WINDOWS\system32\DRIVERS\wacommousefilter.sys [2007-02-16 11:12]
R3 wacomvhid;Wacom Virtual Hid Driver;C:\WINDOWS\system32\DRIVERS\wacomvhid.sys [2007-02-16 10:30]
R3 WacomVKHid;Virtual Keyboard Driver;C:\WINDOWS\system32\DRIVERS\WacomVKHid.sys [2007-02-15 16:11]
R3 WMP300Nv1;Linksys Wireless-N PCI Adapter WMP300N Driver;C:\WINDOWS\system32\DRIVERS\WMP300Nv1.sys [2007-10-18 06:17]
S2 WMP300NSvc;WMP300NSvc;"C:\Program Files\Linksys\WMP300N\WLService.exe" "WMP300N.exe" []
.
Contents of the 'Scheduled Tasks' folder
"2008-04-28 05:27:14 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-05-22 18:36:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-05-22 18:37:14
ComboFix-quarantined-files.txt 2008-05-23 01:36:43
ComboFix2.txt 2008-05-22 13:54:18
Pre-Run: 428,882,989,056 bytes free
Post-Run: 428,860,047,360 bytes free
320 --- E O F --- 2008-05-17 20:52:00