Hi I hope you are felling better. I renamed Combofix and ran it per your instructions. Enclosed are the logs. Only one thing, after running the combofix I have not been able to access yahoo.com through Internet Explorer. I can access every other website except yahoo. However when I use Firefox I have no problems getting to yahoo. Any thoughts?
Thanks again.
ComboFix 08-06-16.5 - Owner 2008-06-21 10:22:02.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.236 [GMT -4:00]
Running from: C:\Documents and Settings\Owner.MARY_LAP\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner.MARY_LAP\Desktop\CFScript.txt
* Created a new restore point
FILE ::
C:\Fix.exe
C:\WINDOWS\portsv.exe
C:\WINDOWS\system32\ahuiy.xe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Fix.exe
C:\WINDOWS\system32\2304
C:\WINDOWS\system32\2304\~!1094p.spt
C:\WINDOWS\system32\2304\~!20751p.spt
C:\WINDOWS\system32\2304\~!41p.spt
C:\WINDOWS\system32\ahuiy.xe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CLBDRIVER
-------\Legacy_PLUGPLAYRPC
-------\Service_PlugPlayRPC
((((((((((((((((((((((((( Files Created from 2008-05-21 to 2008-06-21 )))))))))))))))))))))))))))))))
.
2008-06-24 19:18 . 2008-06-24 19:18 <DIR> d--hs---- C:\found.000
2008-06-22 23:01 . 2008-05-31 11:48 37 --a------ C:\WINDOWS\ipixActivex.ini
2008-06-19 21:46 . 2008-06-19 21:47 <DIR> d-------- C:\Combo-Fix
2008-06-17 21:02 . 2008-06-17 21:02 <DIR> d-------- C:\Deckard
2008-06-17 20:07 . 2008-06-17 20:07 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-17 20:07 . 2008-06-17 20:07 <DIR> d-------- C:\Documents and Settings\Owner.MARY_LAP\Application Data\Malwarebytes
2008-06-17 20:07 . 2008-06-17 20:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-17 20:07 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-17 20:07 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-15 20:08 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-06-15 20:08 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-06-15 20:08 . 2008-05-29 09:35 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-06-15 20:08 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-06-15 20:08 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\404Fix.exe
2008-06-15 20:08 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-06-15 20:08 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-06-15 20:08 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-06-12 21:38 . 2008-06-15 09:11 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\HouseCall 6.6
2008-06-12 21:38 . 2007-12-24 17:37 138,384 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-06-12 21:14 . 2008-06-12 21:14 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AVGTOOLBAR
2008-06-12 21:13 . 2008-06-11 19:15 47,787,248 --a------ C:\avg_free_stf_en_8_100a1295.exe
2008-06-12 20:22 . 2008-06-15 19:37 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-06-12 20:22 . 2008-06-12 20:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-12 19:40 . 2008-06-15 21:03 2,088 --a------ C:\WINDOWS\system32\tmp.reg
2008-06-03 14:14 . 2008-06-03 14:14 <DIR> d-------- C:\WINDOWS\ERUNT
2008-06-03 14:14 . 2008-06-03 14:14 <DIR> d-------- C:\fix
2008-06-03 13:39 . 2008-06-03 13:39 <DIR> d-------- C:\Program Files\InterMute
2008-06-03 11:32 . 2008-06-03 11:32 <DIR> d-------- C:\ERDNT
2008-06-02 21:38 . 2008-06-02 21:38 24,576 --------- C:\WINDOWS\system32\userinit.exe
2008-06-01 19:47 . 2008-06-01 19:47 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2008-06-01 19:29 . 2008-06-01 20:16 <DIR> d-------- C:\Documents and Settings\Owner.MARY_LAP\.housecall6.6
2008-06-01 19:22 . 2008-06-21 10:16 2,206 --a------ C:\WINDOWS\system32\wpa.dbl
2008-06-01 18:58 . 2008-06-01 18:58 <DIR> d-------- C:\Documents and Settings\Owner.MARY_LAP\Application Data\Uniblue
2008-06-01 17:13 . 2008-06-15 21:08 <DIR> d-------- C:\SmitfraudFix
2008-06-01 16:30 . 2008-06-01 16:30 <DIR> d-------- C:\Program Files\Lavasoft
2008-06-01 16:30 . 2008-06-01 16:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-01 16:20 . 2008-06-01 16:20 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Uniblue
2008-06-01 15:53 . 2008-06-01 15:53 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-06-01 15:37 . 2008-06-12 21:12 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AVG7
2008-06-01 13:47 . 2004-08-10 15:00 4,224 --a------ C:\WINDOWS\system32\beep.sys
2008-06-01 13:46 . 2008-06-01 13:47 <DIR> d-------- C:\Program Files\uTorrent
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-28 03:34 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-15 13:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg7
2008-06-13 01:12 --------- d-----w C:\Documents and Settings\Owner.MARY_LAP\Application Data\AVG7
2008-05-31 02:52 --------- d-----w C:\Documents and Settings\Owner.MARY_LAP\Application Data\LimeWire
2008-05-12 03:10 --------- d-----w C:\Program Files\Apple Software Update
2008-05-12 03:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2008-05-12 02:48 --------- d-----w C:\Program Files\LimeWire
2008-04-29 15:20 15,648 ----a-w C:\WINDOWS\system32\drivers\NSDriver.sys
2008-04-29 15:19 15,648 ----a-w C:\WINDOWS\system32\drivers\Awrtrd.sys
2008-04-29 15:19 12,960 ----a-w C:\WINDOWS\system32\drivers\Awrtpd.sys
2007-11-26 23:13 35,768 ----a-w C:\Documents and Settings\Owner.MARY_LAP\Application Data\GDIPFONTCACHEV1.DAT
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of C:\fix ----
2008-06-03 16:00 37173 --a------ C:\fix\SDFix\backups\backupreg.zip
2008-06-03 16:00 353 --a------ C:\fix\SDFix\backups\backups.zip
2008-06-03 16:00 161589 --a------ C:\fix\SDFix\Report.txt
2008-06-03 14:51 202008 --a------ C:\fix\SDFix\SystemReport.txt
2008-06-03 14:25 686 --a------ C:\fix\SDFix\backups\HOSTS
2008-06-03 14:24 377 --a------ C:\fix\SDFix\Report_old_1.txt
2008-06-03 11:36 8 --a------ C:\fix\SDFix\backups_old\megavid.cdt
2008-06-03 11:34 78378 --a------ C:\fix\SDFix\backups_old\spywarewarning2.mht
2008-06-03 11:34 33 --a------ C:\fix\SDFix\backups_old\muotr.so
2008-06-01 19:12 98816 --a------ C:\fix\SDFix\apps\sed.exe
2008-06-01 19:12 94208 --a------ C:\fix\SDFix\apps\Replace\XP.exe
2008-06-01 19:12 94208 --a------ C:\fix\SDFix\apps\Replace\W2K.exe
2008-06-01 19:12 932 --a------ C:\fix\SDFix\apps\FixWebCheck.reg
2008-06-01 19:12 826 --a------ C:\fix\SDFix\apps\FixSchedule.reg
2008-06-01 19:12 8192 --a------ C:\fix\SDFix\apps\RestartIt!.exe
2008-06-01 19:12 814 --a------ C:\fix\SDFix\apps\HPFix.reg
2008-06-01 19:12 80412 --a------ C:\fix\SDFix\apps\grep.exe
2008-06-01 19:12 76568 --a------ C:\fix\SDFix\apps\FIXLM.reg
2008-06-01 19:12 727 --a------ C:\fix\SDFix\apps\srv2bk.txt
2008-06-01 19:12 727 --a------ C:\fix\SDFix\apps\srv2.txt
2008-06-01 19:12 703276 --a------ C:\fix\SDFix\RunThis.bat
2008-06-01 19:12 690 --a------ C:\fix\SDFix\apps\HPFix5.reg
2008-06-01 19:12 6656 --a------ C:\fix\SDFix\apps\MD5File.exe
2008-06-01 19:12 6302 --a------ C:\fix\SDFix\apps\svcbk.txt
2008-06-01 19:12 6302 --a------ C:\fix\SDFix\apps\svc.txt
2008-06-01 19:12 61440 --a------ C:\fix\SDFix\apps\psservice.exe
2008-06-01 19:12 61440 --a------ C:\fix\SDFix\apps\download.exe
2008-06-01 19:12 591 --a------ C:\fix\SDFix\apps\FixRedir.reg
2008-06-01 19:12 5768 --a------ C:\fix\SDFix\apps\Restore_SharedAccess.reg
2008-06-01 19:12 53248 --a------ C:\fix\SDFix\apps\Process.exe
2008-06-01 19:12 49152 --a------ C:\fix\SDFix\apps\vfind.exe
2008-06-01 19:12 49152 --a------ C:\fix\SDFix\apps\SF.exe
2008-06-01 19:12 49152 --a------ C:\fix\SDFix\apps\LS.exe
2008-06-01 19:12 4510 --a------ C:\fix\SDFix\apps\fix.reg
2008-06-01 19:12 438 --a------ C:\fix\SDFix\apps\Rem2.txt
2008-06-01 19:12 4224 --a------ C:\fix\SDFix\apps\Replace\xp\beep.sys
2008-06-01 19:12 41472 --a------ C:\fix\SDFix\apps\WINMSG.EXE
2008-06-01 19:12 40995 --a------ C:\fix\SDFix\apps\FIXCU.reg
2008-06-01 19:12 40960 --a------ C:\fix\SDFix\apps\swsc.exe
2008-06-01 19:12 4090 --a------ C:\fix\SDFix\apps\ERUNT.LOC
2008-06-01 19:12 4080 --a------ C:\fix\SDFix\apps\Replace\w2k\beep.sys
2008-06-01 19:12 376 --a------ C:\fix\SDFix\apps\FixXPsp2.reg
2008-06-01 19:12 374 --a------ C:\fix\SDFix\apps\MyGcpvFix.reg
2008-06-01 19:12 3654 --a------ C:\fix\SDFix\apps\Restore_SecurityCenter.reg
2008-06-01 19:12 344 --a------ C:\fix\SDFix\apps\Enable_Command_Prompt.reg
2008-06-01 19:12 33280 --a------ C:\fix\SDFix\apps\isadmin.exe
2008-06-01 19:12 3275 --a------ C:\fix\SDFix\apps\ERDNTWIN.LOC
2008-06-01 19:12 31232 --a------ C:\fix\SDFix\apps\sc.exe
2008-06-01 19:12 304 --a------ C:\fix\SDFix\apps\winsec.reg
2008-06-01 19:12 299 --a------ C:\fix\SDFix\apps\Rem.txt
2008-06-01 19:12 2969 --a------ C:\fix\SDFix\apps\legacybk.txt
2008-06-01 19:12 2969 --a------ C:\fix\SDFix\apps\legacy.txt
2008-06-01 19:12 2944 --a------ C:\fix\SDFix\apps\Replace\xp\null.sys
2008-06-01 19:12 2815 --a------ C:\fix\SDFix\apps\ERDNTDOS.LOC
2008-06-01 19:12 2800 --a------ C:\fix\SDFix\apps\Replace\w2k\null.sys
2008-06-01 19:12 278016 --a------ C:\fix\SDFix\apps\swreg.exe
2008-06-01 19:12 27136 --a------ C:\fix\SDFix\apps\FixPath.exe
2008-06-01 19:12 2456 --a------ C:\fix\SDFix\apps\HPFix7.reg
2008-06-01 19:12 231930 --a------ C:\fix\SDFix\apps\FixBH.reg
2008-06-01 19:12 2286 --a------ C:\fix\SDFix\apps\MyGkFix2.reg
2008-06-01 19:12 2247 --a------ C:\fix\SDFix\XP_CodecRepair.inf
2008-06-01 19:12 202 --a------ C:\fix\SDFix\apps\leg2.txt
2008-06-01 19:12 2010 --a------ C:\fix\SDFix\apps\FixComponents.reg
2008-06-01 19:12 19456 --a------ C:\fix\SDFix\apps\shutdown.exe
2008-06-01 19:12 189 --a------ C:\fix\SDFix\SDFIX_ReadMe_Online.url
2008-06-01 19:12 1716 --a------ C:\fix\SDFix\apps\HPFix3.reg
2008-06-01 19:12 167936 --a------ C:\fix\SDFix\apps\unzip.exe
2008-06-01 19:12 16414 --a------ C:\fix\SDFix\apps\procs.exe
2008-06-01 19:12 163328 --a------ C:\fix\SDFix\apps\ERDNT.E_E
2008-06-01 19:12 1582 --a------ C:\fix\SDFix\apps\fixXP.reg
2008-06-01 19:12 157696 --a------ C:\fix\SDFix\apps\ERUNT.EXE
2008-06-01 19:12 157 --a------ C:\fix\SDFix\apps\HPFix2.reg
2008-06-01 19:12 146432 --a------ C:\fix\SDFix\apps\Replace\regedit.exe
2008-06-01 19:12 145920 --a------ C:\fix\SDFix\catchme.exe
2008-06-01 19:12 1400 --a------ C:\fix\SDFix\apps\HPFix4.reg
2008-06-01 19:12 1360 --a------ C:\fix\SDFix\apps\HPFix8.reg
2008-06-01 19:12 126976 --a------ C:\fix\SDFix\apps\zip.exe
2008-06-01 19:12 1228 --a------ C:\fix\SDFix\apps\HPFix6.reg
2008-06-01 19:12 1218 --a------ C:\fix\SDFix\apps\assosfix.reg
2008-06-01 19:12 1181 --a------ C:\fix\SDFix\W2K_CodecRepair.inf
2008-06-01 19:12 11254 --a------ C:\fix\SDFix\apps\locate.com
2008-06-01 19:12 1110 --a------ C:\fix\SDFix\apps\HPFix9.reg
2008-06-01 19:12 106 --a------ C:\fix\SDFix\apps\Reset_AppInit_DLLs.reg
2008-06-01 19:12 10240 --a------ C:\fix\SDFix\apps\cliptext.exe
2008-06-01 19:12 1024 --ah----- C:\fix\SDFix\dummy.sys
2008-06-01 19:12 1024 --a------ C:\fix\SDFix\apps\dummy.sys
2007-09-23 20:05 279600 --a------ C:\fix\SDFix\backups_old\pac.txt
((((((((((((((((((((((((((((( snapshot@2008-06-18_22.00.01.95 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-19 01:56:31 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-21 14:26:58 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-15 23:24:43 1,152,888 ----a-w C:\WINDOWS\system32\aswBoot.exe
+ 2008-05-15 23:12:36 95,608 ----a-w C:\WINDOWS\system32\AvastSS.scr
+ 2008-05-15 23:13:26 26,944 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
+ 2008-05-15 23:16:06 20,560 ----a-w C:\WINDOWS\system32\drivers\aswFsBlk.sys
+ 2008-01-17 16:34:01 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
+ 2008-05-15 23:18:33 94,416 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
+ 2008-05-15 23:15:29 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
+ 2008-05-15 23:20:32 78,416 ----a-w C:\WINDOWS\system32\drivers\aswSP.sys
+ 2008-05-15 23:14:11 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
+ 2008-06-21 14:27:09 16,384 ----atw C:\WINDOWS\TEMP\Perflib_Perfdata_6b8.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 18:43 4670704]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 19:24 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-11-23 06:45 98304]
"Lexmark 1200 Series"="C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe" [2006-07-13 01:22 57344]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 11:09 63712]
"RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-04-23 12:43 228088]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"combofix"="C:\WINDOWS\system32\CF2600.exe" [2004-08-10 15:00 388608]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.clmp3enc"= C:\PROGRA~1\CYBERL~1\Power2Go\CLMP3Enc.ACM
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BigFix.lnk
backup=C:\WINDOWS\pss\BigFix.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
--a------ 2008-05-15 19:19 79224 C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
--ah----- 2005-08-05 23:56 64512 C:\WINDOWS\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
--a------ 2005-10-12 16:30 139264 C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
--a------ 2006-03-23 16:13 77824 C:\WINDOWS\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
--a------ 2006-03-23 16:17 118784 C:\WINDOWS\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
--a------ 2006-03-23 16:17 94208 C:\WINDOWS\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]
--a------ 2006-08-02 04:32 696320 C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelZeroConfig]
--a------ 2006-08-02 04:38 802816 C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCAgentExe]
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe]
C:\PROGRA~1\McAfee.com\Agent\McUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MPFExe]
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKDetectorExe]
C:\Program Files\McAfee\SpamKiller\MSKDetct.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 19:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Power2GoExpress]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2006-11-23 06:45 98304 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
%WINDIR%\SMINST\RECGUARD.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Reminder]
%WINDIR%\Creator\Remind_XP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
--ah----- 2005-12-27 14:20 413696 C:\WINDOWS\stsystra.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
--a------ 2006-05-23 23:22 573440 C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
--a------ 2004-11-05 11:47 688218 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
--a------ 2004-11-05 11:47 98394 C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2007-08-30 18:43 4670704 C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZoneAlarm Client]
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"MpfService"=2 (0x2)
"mcupdmgr.exe"=3 (0x3)
"McTskshd.exe"=2 (0x2)
"McDetect.exe"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"C:\\Program Files\\America Online 9.0\\waol.exe"=
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
"C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
"C:\\Program Files\\Common Files\\AOL\\1164278689\\EE\\AOLServiceHost.exe"=
"C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\AOLSP Scheduler.exe"=
"C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\asp.exe"=
"C:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\WINDOWS\\system32\\LEXPPS.EXE"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-15 19:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-15 19:16]
.
Contents of the 'Scheduled Tasks' folder
"2008-05-12 03:10:27 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-06-21 10:27:18
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Lexmark 1200 Series\lxczbmon.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2008-06-21 10:31:53 - machine was rebooted [Owner]
ComboFix-quarantined-files.txt 2008-06-21 14:31:49
ComboFix2.txt 2008-06-19 02:00:16
Pre-Run: 57,246,306,304 bytes free
Post-Run: 57,323,937,792 bytes free
338 --- E O F --- 2008-05-16 22:25:20